Daylit
Legal

Privacy Policy

Effective 2026-08-18. Last updated 2026-08-18.

Short version
  • Your data is yours. We store it so you can sync it. That's it.
  • No ads, no third-party analytics, nothing sold on.
  • Delete your account whenever. Server data is gone within 30 days.

1. What we collect

  • Account info: your email address and password hash (or Google account identifier).
  • App content: the classes, assignments, grades, tasks, and settings you enter.
  • Server logs: IP address and timestamp of requests, kept up to 30 days to spot abuse.

We do not fingerprint your device, run third-party analytics, embed ad trackers, or follow you around other sites.

2. How we use it

Your account info signs you in. Your app content is stored so we can show it back to you and sync it across your devices. Server logs are used only to keep the service safe and running.

3. Who we share it with

We share your data with the small set of vendors we need to run Daylit:
  • Supabase, our database and auth provider. Your data lives on their infrastructure.
  • Google, only if you choose “Continue with Google.” They see the request came from Daylit.

We don’t sell your data. We don’t train machine-learning models on it. We don’t share it with your school, your parents, or anyone else, unless the law requires it (a valid subpoena), and even then we’ll tell you first if we’re allowed to.

4. Your controls

  • Access: everything we have about you is right there in the app.
  • Export: email us and we’ll send you a JSON dump within 30 days.
  • Delete: hit “Reset local data” on Customize, or email us to wipe your server account within 30 days.

5. Kids under 13 (COPPA)

Daylit is meant to be safe for middle-school students, but if you’re under 13 a parent or guardian needs to help set up the account. If we find out we’ve collected data from a child under 13 without a parent’s okay, we’ll delete it. Parents can email us any time to review or delete their kid’s data.

6. Security

Data in transit uses HTTPS. Data at rest is encrypted by Supabase. Row-level security makes sure each account can only read and write its own rows. We use strong password hashing and never see your plaintext password. No system is bulletproof, though. If we learn about a breach that affects your data, we’ll email you within 72 hours.

7. International users

Servers are in the United States. Using Daylit means you’re okay with your data being processed there.

8. Changes

Any change to this policy shows up here with an updated “Last updated” date. Big changes get announced by email or in the app at least 14 days before they kick in.

9. Contact

Questions or requests: hi@daylit.net.