DaymadeBack to Daymade

Privacy notice, version 2

How Daymade handles personal data

Daymade is a private goal tracker. This notice explains what the service stores, why it stores it, and the choices available to you.

Controller: Kristjan Pikhof, Estonia
Privacy contact: kristjan@pikhof.eu

What Daymade stores

An access request contains your name and email. An account contains your name, email, preferences, sessions, and security records. If you give explicit consent, Daymade also stores your goal settings, notes, schedules, and progress entries.

Goal information can reveal health, religious, political, or other sensitive details. Daymade treats all goal and progress data as potentially sensitive. The service is for adults aged 18 or older.

Why the data is used

PurposeDataLegal basis
Review access and provide an accountName, email, account settingsSteps requested before a contract and performance of the service
Provide private goal trackingGoals, notes, schedules, progressExplicit consent, including GDPR Article 9 consent where needed
Protect the serviceSessions, short-lived IP pseudonyms, audit recordsLegitimate interests in security and abuse prevention
Measure public-page reliabilityCookieless Cloudflare Web AnalyticsLegitimate interests in measuring public-page reliability

Sensitive goal data and consent

Daymade does not use goal data until you confirm that you are an adult and give explicit consent. You can withdraw consent in Settings. Withdrawal deletes every goal, progress entry, and import record while leaving your account available.

A disconnected device may keep a dashboard copy for up to 30 days. The app deletes that copy when it expires or when the device reconnects after consent was withdrawn. This limitation is part of Daymade's data-protection impact assessment.

Retention

  • Pending access requests: up to 90 days.
  • Approved or dismissed access requests: 30 days after resolution.
  • Rate-limit records: 24 hours.
  • Sessions: 7 days, unless revoked sooner.
  • Offline dashboard copies: 30 days.
  • Administrative security records: 12 months.
  • Withdrawn consent evidence: 12 months while the account remains open.
  • Goal data: until consent is withdrawn or the account is deleted.
  • Public-page analytics: unsampled beacon data for 7 days and aggregate reports visible to Daymade for the previous 6 months.

Deleted data may remain in Cloudflare's protected backups until the provider's backup cycle expires. It is not restored into normal use after a valid deletion request.

Cloudflare and international transfers

Cloudflare provides the Worker runtime, D1 database, Turnstile security check, public-page analytics, logs, and network services. Cloudflare acts as a service provider under its data processing terms. Where data moves outside the European Economic Area, Daymade relies on the transfer safeguards recorded in its processor and subprocessor review. Network Error Logging is disabled where possible; if Cloudflare keeps it active at the network layer, its browser and network error metadata is covered by that review.

Turnstile receives the browser and network information needed to distinguish a person from automated abuse. It never receives your goal text from Daymade.

Cookies, local storage, and analytics

Daymade uses an essential secure session cookie after sign-in. The browser stores a user identifier and, when offline use is available, an expiring dashboard copy. Turnstile may use necessary browser storage for security.

Cloudflare Web Analytics loads only on the landing and privacy pages. It uses no cookies or fingerprinting and is never loaded in the signed-in app. Daymade respects Global Privacy Control, Do Not Track, and the preference below.

Public-page analytics

Daymade can use Cloudflare's cookieless analytics on the landing and privacy pages. Analytics stays off in the signed-in app.

Your rights

You can download your data and delete your account in Settings. You can also ask for access, correction, erasure, restriction, portability, or object to processing by emailing kristjan@pikhof.eu. You can withdraw consent at any time without changing the lawfulness of earlier processing.

You may complain to the Estonian Data Protection Inspectorate. Daymade does not sell personal data, publish goal profiles, or make automated decisions with legal or similarly significant effects.