Last updated: July 23, 2026
Your agreement
By creating an account or using Dayforge, you agree to this Privacy Policy and our Terms of Service. If you don't agree, please don't use the app.
The short version
- You own your Memories. Your Brain Dumps, calendar blocks, and journal entries belong to you. We only process them to run the app for you.
- Local-first. Your data is stored on your device first (in a private on-device database). When you're signed in, it's mirrored to your account so you can access it across devices.
- Signed-out data never leaves your device. Guest and anonymous dumps stay in your browser's local storage. If you clear your browser, we can't recover them.
- We don't sell your data. No ads, no analytics cookies, no cross-site trackers, no data brokers.
- AI providers don't train on your inputs. Full detail below.
- Dayforge never receives raw voice audio. Speech-to-text happens inside your browser.
- Delete anytime. One button in Settings wipes your account within 30 days.
Who we are
Dayforge is operated by Dayforge by Cris Velk (Ohio, USA). For any privacy question or request, email cris@velkstudio.com.
Data ownership
You own 100% of your Memories and Brain Dumps. The raw text you dump, the calendar and task entries the AI creates from it, your journal history, and your check-in responses — all yours. We hold a narrow, revocable license to store, transmit, and process that content only to operate the Service for you (syncing across your devices, running AI organizing, showing you the results). We do not use your content for our own purposes, we do not sell or license it to anyone, and we do not train models on it. You can export or delete it at any time.
What we collect
- Account info. Your email address and a hashed (scrambled, one-way) copy of your password. If you sign in with a third-party provider, we also receive your name, profile picture URL, and that provider's user identifier.
- Your content. The brain dumps you type or dictate, the calendar and task entries the AI creates from them, your journal history, your check-in prompts and answers, and simple task completion counts.
- Plan & usage metadata. Your plan tier, your AI credit balance, refill balance, and subscription status so we can enforce your allowance and process billing.
- Support messages. Anything you send through the feedback form.
- Sign-in security logs. Our authentication layer keeps standard security records (approximate IP address, browser user-agent, sign-in timestamps) to protect your account from abuse.
- Admin action logs. If an operator ever takes a destructive action on an account, we record who did what and when, so we stay accountable.
- Signup attribution. If you visited our public homepage before creating an account, an anonymous 12-character visitor ID from that visit is saved onto your profile once, so we can measure how well our landing page converts. This ID is not shared with anyone, not sold, not linked to any third-party identifier, and is deleted when you delete your account.
What we don't collect
- No analytics or advertising cookies.
- No third-party trackers or cross-site profiles.
- No location or GPS data.
- No contacts, photos, or files from your device.
- No device fingerprinting.
- No raw voice audio — recordings never leave your browser.
- No payment card numbers. Our PCI-compliant payment processor handles card details directly; we only see whether the charge succeeded and the resulting plan state.
The Vault — how your data is protected
We call the storage layer "the Vault" because it's designed to hold your memory for the long run.
- On-device first. Brain Dumps, calendar events, and backlog items live in a private, per-account IndexedDB database inside your browser. Small metadata (sync timestamps, your device ID, check-in schedule) lives in local storage.
- Encryption in transit. Every request between your device, our Encrypted Database Host, our Secure AI Gateway, and our payment processor travels over HTTPS/TLS.
- Encryption at rest. Our cloud database and backups are encrypted at rest by our Secure Cloud Infrastructure.
- Per-account isolation (Row-Level Security). Every row in the cloud database carries your user ID and is gated by database-level policies so that only your account can read or modify your rows. Even if application code were to try to fetch someone else's row, the database refuses.
- Tombstoned deletes across devices. When you delete an item, a "tombstone" propagates to every device you're signed into so the deletion sticks and can't be resurrected by a stale offline copy.
- Password hygiene. Passwords are hashed by our authentication layer — we never see them in plain text — and new passwords are checked against an industry breach-corpus so you can't reuse a compromised one.
- Admin re-authentication. Sensitive operator actions require the operator to re-enter their password and are written to a permanent audit log.
Voice input — the honest version
When you tap the microphone, recording uses your browser's built-in speech recognition. That means Chrome routes the audio to Google and Safari routes it to Apple, under their own privacy policies. Dayforge never receives or stores the audio itself.
Once your browser converts speech to text, that text is:
- Saved on your device (in the Vault).
- Sent to our Secure AI Gateway (see below) so it can be turned into tasks and calendar entries.
- If you're signed in, mirrored to your account row of our Encrypted Database Host so it syncs across your devices.
AI processing (and retention)
The text of your dumps is sent through our Secure AI Gateway to third-party LLM providers, so it can be structured into tasks and calendar entries. Your "Tomorrow Story" audio is generated the same way by text-to-speech providers from the story text we send.
Based on the current published API terms of those providers:
- Your inputs are not used to train their general models.
- Providers may retain inputs for a short period (typically up to around 30 days) to detect abuse and enforce their safety policies, and then delete them.
- Providers do not receive your account email, password, payment details, or the identity of other users.
Gateway-side retention — honest current state (as of July 23, 2026). Our Secure AI Gateway always records summary metrics for each AI call (model, token counts, latency, cost, success/failure status). In addition, the gateway provider's default configuration currently also retains the content of prompts and model responses for up to 90 days for operational debugging on infrastructure we don't control. Dayforge does not use, review, or build features on top of that stored content — but we want to be transparent that it is technically present today.
We do not want this, and opt-out is in progress. We have formally requested that our AI infrastructure provider (1) never use Dayforge data for AI training or model evaluation, and (2) disable payload retention on the gateway so that only the summary metrics above are kept going forward. Until the provider confirms the change, treat this section as the accurate current state. We will update it with the effective date the moment the opt-out is applied.
Your data inside the Dayforge Vault — your entries, blocks, journal, and account — is unaffected by any of the above and continues to follow the retention rules described below. If provider terms or our gateway configuration change, we'll update this section and, for material changes, notify signed-in users.
Where your data lives
Cloud content lives in our Encrypted Database Host (United States). AI processing runs in the United States through our Secure AI Gateway. Payments run through a PCI-compliant payment processor. If you're located outside the US and use the Service, you consent to your data being processed in the US under appropriate legal safeguards.
Cookies & local storage
We only use what's needed to make the app work: a sign-in session token from our authentication layer, and browser storage (IndexedDB + local storage) for your offline content and app preferences. No advertising cookies. No analytics cookies. No third-party trackers.
How long we keep it
We keep your content until you delete it. Deleting an item in the app removes it from your device and marks it deleted in the cloud (a "tombstone" so other devices know to remove it too). Emptying Trash performs a hard database delete. Account deletion removes your account data from active systems within 30 days; encrypted backups rotate out on a similar schedule.
Your rights (GDPR, UK-GDPR, CCPA)
No matter where you live, you have the right to access, correct, export, or delete your personal data, and to object to certain processing. You can:
- See and edit your data at any time inside the app.
- Delete your entire account from Settings.
- Email cris@velkstudio.com for an export or any other request.
Subprocessors we rely on
- Secure Cloud Infrastructure & Encrypted Database Host — hosting, database, and authentication (United States).
- Secure AI Gateway → third-party LLM and text-to-speech providers — structures your text into tasks and generates story audio.
- PCI-compliant payment processor — billing. Receives your card details directly; they never touch our systems.
- Browser-native speech recognition (Google on Chrome, Apple on Safari) — engaged only when you tap the microphone.
Breach notification
If we ever discover a security incident that affects your personal data, we'll notify affected users without undue delay and, where required by law, within 72 hours of confirming the incident.
Children
Dayforge is not intended for children under 13 (or under 16 in the EU). Please don't use the app if you're below that age.
Changes to this policy
If we make material changes, we'll update the date above and notify signed-in users the next time they open the app.
Contact
Questions or requests: cris@velkstudio.com.