Draft — pending legal review. This policy reflects how DailyOS works today and follows UK GDPR / Data Protection Act 2018 structure. It should still be reviewed by a UK solicitor before launch, and updated if DailyOS is incorporated as a company or starts charging.

Privacy Policy

Last updated: 6 July 2026

This policy explains how DailyOS collects, uses and protects your personal data, and your rights under UK data protection law.

1. Who we are

  • Trading name: DailyOS.
  • Operated by: the DailyOS team, currently as an individual rather than a registered company. If DailyOS is later incorporated, we’ll update these details.
  • Based in: the United Kingdom.
  • VAT: not registered.
  • Contact for privacy: support@dailyos.uk, or through our contact page.
  • Data Protection Officer: none appointed — we are not required to appoint one.

2. Our role

For personal accounts, DailyOS is the data controller — we decide how and why your data is processed (accounts, billing, support, analytics and app usage). If DailyOS is ever used on behalf of an organisation (a school, employer, family or team) we may act as a data processor for that organisation’s data under a separate Data Processing Agreement.

3. What we collect

  • Account information — email address, username, and login credentials (passwords are handled by our authentication provider and never stored by us in plain text).
  • Your content — tasks, notes, reminders, calendar events, routines, goals, preferences, Drop entries, uploaded files, and anything you type into DailyOS.
  • Usage data — features used, interactions, session times, device and browser type, IP address (and approximate location derived from it), error logs and performance data.
  • Payment & subscription data (when billing is live) — plan type, billing status, transaction and payment-processor customer IDs, and receipts. Full card numbers are handled by the payment processor, not by us.
  • Support & communications — messages, feedback, bug reports and survey responses you send us.
  • Referrals — if you refer a friend, we record your referral link and, when they sign up or subscribe, link their account (and the email address used) to your referral so we can issue and email both of you a reward code.
  • Marketing data (if introduced) — subscription status and preferences.
  • Cookies & local storage — see our Cookie Policy.

Special category (sensitive) data

DailyOS does not require you to provide sensitive data (such as health, religious or political information). Because DailyOS lets you type freely into notes and tasks, you could enter such data yourself — please only do so if you are comfortable. We do not intentionally offer features that require special category data.

4. Where we get data from

  • Directly from you, when you use DailyOS.
  • Automatically from your device and browser.
  • From our payment processor, when billing is live.
  • From third-party login or integration providers, only if you connect them.

5. Why we use it, and our lawful basis

PurposeLawful basis (UK GDPR)
Create and run your account; store and sync your content; deliver paid featuresContract
Authenticate you and keep the service secureLegitimate interests / Contract
Process subscriptions, payments and invoicesContract / Legal obligation (tax records)
Provide customer supportContract / Legitimate interests
Fix bugs, monitor performance, analyse usage to improve DailyOSLegitimate interests
Send service messages (password resets, security, billing)Contract / Legal obligation
Send marketing (if introduced)Consent
Prevent fraud, abuse and misuse; enforce our TermsLegitimate interests / Legal obligation
Optional (non-essential) cookiesConsent

Where we rely on legitimate interests (security, fraud prevention, analytics, product improvement, support and protecting our legal rights), we balance those interests against your rights.

6. AI features

Some features (organising your Drop, planning your day, suggesting ideas) use AI. When AI is enabled, only the specific text needed for that request is sent to a third-party, OpenAI-compatible model provider to extract details or generate suggestions.

The “Ask DailyOS” assistant works the same way, but to answer usefully it is also sent a short summary of your relevant DailyOS data — for example your upcoming tasks and events and a few recent notes — along with your message. This is used only to generate your answer for that request; it is not used to train any AI model.

We do not use your content to train our own or third parties’ AI models. AI output can be inaccurate — always review it (nothing is saved to your tasks, calendar or vault until you approve it). If no AI provider is configured, this processing happens on-device with built-in logic and nothing is sent externally.

7. Automated decision-making

DailyOS does not make decisions that produce legal or similarly significant effects about you using solely automated processing.

8. Who we share data with

We share personal data only with service providers who help us run DailyOS, and only as needed:

  • Hosting — Vercel.
  • Database, auth & file storage — Supabase.
  • AI provider — Groq, an OpenAI-compatible model provider, when AI features are enabled.
  • Payments (when live) — Stripe.
  • Email delivery (when live) — Resend.
  • Professional advisers, and regulators / courts / law enforcement where legally required.
  • A buyer or successor if DailyOS is sold or restructured.

An up-to-date sub-processor list will be maintained at launch.

9. International transfers

Some providers may process data outside the UK (for example in the US). Where they do, we rely on an approved safeguard such as UK adequacy regulations, the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses. We keep an up-to-date list of providers and their regions, available on request through our contact page.

10. How long we keep it

  • Account data and your content — while your account is active.
  • Deleted data / accounts — removed from live systems immediately on deletion, and purged from encrypted backups within 30 days.
  • Payment and tax records — as required by law (typically 6 years).
  • Support messages — up to 24 months; security and error logs — up to 12 months.

11. Security

We use encryption in transit, row-level security so you can only access your own data, private file storage, authentication controls, limited admin access, backups, and monitoring. No system is perfectly secure, but we take these safeguards seriously and have a process to detect, investigate and, where required, report personal data breaches to the ICO within 72 hours and to affected users.

12. Your rights

Under UK GDPR you have the right to: access; rectification; erasure; restriction; objection; data portability; to withdraw consent (where processing relies on consent); and rights relating to automated decision-making. You can view, edit and permanently delete your data from Settings, or contact us to make a request.

13. Children

DailyOS is intended for people aged 13 and over. If you are under 18, please use DailyOS with a parent or guardian’s involvement. We do not knowingly collect data from children under 13; if you believe a child under 13 has given us data, contact us and we’ll delete it.

14. Complaints

Please contact us first at support@dailyos.uk or through our contact page. You also have the right to complain to the Information Commissioner’s Office (ICO) at ico.org.uk.

15. Changes

We may update this policy as the product evolves; material changes will be reflected here with a new “last updated” date.