DaychekOpen web app

Updated 27 September 2026

Privacy policy

Daychek keeps your lists, habits, money, home, wardrobe and wellbeing notes in one app. This page says exactly what we store, where it goes, how long we keep it and how you control it.

The short version

  • We store what you put into Daychek so it syncs between your devices, plus the few technical details listed below.
  • No ads, no analytics or tracking tools, no crash-reporting services. We don't sell or share your data for marketing.
  • Mood and cycle data is health data. We store it only after you say yes, and you can take that back at any time, which deletes it.
  • Sharing prices with the community is off until you switch it on. Shared prices are anonymous: other people see only combined prices, never who reported them.
  • You can download everything we hold (Settings → Privacy → Export my data) and delete your account in the app or on this page.

Who is responsible

The controller of your personal data is [CONTROLLER NAME / ADDRESS]. Contact: [CONTACT EMAIL].

What we store, feature by feature

When you use Daychek with an account, the app keeps your data on your device and syncs it to our server. On the web, the device copy lives in your browser's storage.

Feature What our server stores
Account Email address, display name, how you sign in (email, Google, Apple or guest), a one-way hash of your password (bcrypt, email accounts only), your plan (Free, Premium or Family, and its end date), your app settings (what you track, base currency, app language, first-run answers) and when these were created or changed.
Email accounts Whether you confirmed your email address, and when. The confirmation link we email works for 1 hour, once; we keep only a one-way hash of it.
Sign in with Google We check Google's sign-in token on our server and keep the verified email address, your name and Google's id for your account (so a changed email still finds you).
Sign in with Apple We check Apple's sign-in token on our server and keep the email it contains (this can be an Apple private relay address). If Apple sends no email, we make a stand-in address from Apple's id for you. We keep Apple's id for your account, and the name only if you share it.
Guest An account without email or name. What you add syncs to our server under that account. If our server can't be reached, the guest stays on your device only.
Profile picture The picture you upload, redrawn by our server (which drops hidden data such as the photo's location) and stored under a random name. It is only sent to people signed in to Daychek who have its link.
Lists and templates Titles, items, quantities, units, prices, due dates, repeats and the store they belong to.
Shared lists Who is a member and their role. Members see each other's display names; the list owner also sees members' email addresses. If you make a share link, anyone who has the link can open the list (and change it, for an edit link) until you revoke it.
Family If you're in a Family plan: who owns it, who is a member and when they joined, and open invites (an invite code or link lasts 7 days and is stored only as a hash; an email invite keeps the email address the owner typed until it is accepted, declined or cancelled, or the family ends; it can be accepted for 30 days). Members see the owner's display name; the owner sees members' display names and email addresses. Leaving, being removed or deleting your account ends your membership; if the owner deletes their account, the family ends and members go back to the free plan.
Catalog Products (name, brand, barcode, price, picture link), categories, stores (name, the location text and website you enter) and the prices you log.
Community prices Only if you switch on sharing (Settings → Privacy → Share my prices with the community): when you log a price for a product with a barcode at one of your stores that you linked to a shop, our server records the barcode, the shop, the price, its currency and country, the date, and whether it came from a receipt. Everyone sees only the combined price per shop and chain, how many reports it rests on and when the latest was made, never who reported it. We keep which account sent each report, shown to no one, to allow one report per product, shop and day, to stop abuse and to give more weight to people whose prices usually match what others report. Reports from Premium and Family accounts count a little more. The link between your store and a shop, and pack sizes you suggest for a product, are stored with your account. Shop names and places come from OpenStreetMap (© OpenStreetMap contributors); searching them doesn't contact OpenStreetMap.
Habits Habits and the days you log them.
Money Expenses and income: title or source, amount, currency, date, category, whether it repeats.
Home Homes (name and the address if you enter one), rooms, cleaning tasks and schedules, laundry.
Wardrobe Clothes (name, brand, type, colours, seasons, notes), outfits, the days you wear them, and the photos you add. Photos are stored as files on our server and are only ever sent back to you when you are signed in. Background removal runs on our own server, so your photos never go to another company.
Mood and cycle Only with your consent (below): mood scores and notes; cycle start and end dates, lengths, daily flow, symptoms, mood and notes.
Sync A record of which item changed and when, so your other devices can catch up. When you delete something, a marker with only the item's type and id (no content) stays for up to 90 days so your other devices delete it too.
Plan management The service owner can see account emails, how each account signs in and its plan in an admin view, to give or remove Premium or Family and to handle account requests. The admin view also shows whether an account owns or belongs to a family. Each such change, and each promo code you redeem (the code and when), is logged with the time.

Reminders are scheduled on your device and shown as local notifications; they are not sent through our server.

Health data: mood and cycle

Mood and menstrual-cycle entries are health data, a special category under the GDPR (Art. 9). Before the first mood or cycle entry is saved, Daychek asks for your explicit consent and explains what is stored. Our server refuses mood and cycle entries from an account that has not consented.

We use this data only to show it back to you, on your devices. You can delete single entries at any time. Withdrawing consent (Settings → Privacy → Health data) deletes every mood and cycle entry on your device and on our server, and stops syncing it.

Cycle estimates in the app are simple averages of your own entries. They are not medical advice and not a method of contraception.

Sharing prices with the community

Sharing is off by default. The app asks once, the first time you log a price at a linked shop, and you can change your answer at any time in Settings → Privacy. Guest accounts can't share. Switching sharing off stops new reports at once. Reports you already shared stay part of the combined prices, still without your name. Deleting a price you logged also deletes its report. When you delete your account, the link between your reports and your account is removed, so they become fully anonymous. Reports are deleted one year after the day they describe.

Who else handles data

Who When What they receive
Hetzner Online GmbH (data centre in Nuremberg, Germany) Always: hosts our server, database, photo files and backups. Everything our server stores, as our processor.
Google If you sign in with Google. On the web app, your browser also loads Google Fonts and Google's sign-in script from Google. Your Google sign-in happens with Google. When the web app loads, Google receives your IP address and browser details.
Apple If you sign in with Apple on iPhone. Your Apple sign-in happens with Apple.
Apple App Store, Google Play and RevenueCat If you buy Premium or Family on iPhone or Android. The store handles the payment. RevenueCat checks your purchase for the app. When you are signed in, the app identifies you to RevenueCat by your Daychek account id (a random id, not your email or name), and RevenueCat tells our server which plan the purchase gives and when it ends, so your plan follows your account on every device and a Family owner can invite people.
LemonSqueezy If you buy Premium or Family on the web or desktop. Checkout opens on LemonSqueezy, which collects your payment details as the seller of record. It then tells our server your account id or email so we can switch Premium on.
Open Food Facts When you look up a barcode. The barcode number, sent from your device (and, for lookups through our server and for barcodes shared with the community, from our server, which caches the product details without linking them to you). Open Food Facts sees the IP address of whoever asks.
ExchangeRate-API (open.er-api.com) When the app refreshes currency rates. A currency code, from your device, and your IP address. Our server also fetches rates with its own key, without any user data.
Open-Meteo When Wardrobe suggests outfits. A request for the weather at a fixed place set in the app (not your location), and your IP address.
[EMAIL PROVIDER] If you ask for a password reset, or sign up with email. Your email address and the reset or confirmation link.

Some of these companies are outside the European Economic Area and handle data under their own terms and safeguards. We use no other services with your data.

Why we may use it (legal bases)

How long we keep it

Data Kept
Your account and everything in it Until you delete it, or delete the account.
Deletion markers (type and id only) Up to 90 days.
Nightly backups of the database and photo files Deleted after 14 days. They are stored on the same server provider.
Password reset links 1 hour, kept in memory only, single use.
Email confirmation links 1 hour, single use.
Sign-in sessions 1 hour, renewable for up to 30 days; every renewal replaces the old renewal key. Logging out or changing your password ends every session at once.
Community price reports Deleted 1 year after the day they describe. The link to your account is removed when you delete the account.
Rate-limit counters (IP address, email) A few minutes, in memory only.

We don't keep an access log of requests to Daychek. The server keeps technical error logs to fix problems.

When you delete your account, every row it owns is deleted in one step, together with your profile picture and wardrobe photos. Community price reports you shared stay, without any link to you. Copies in backups disappear when those backups expire (14 days).

How we protect it

Your rights

Children

Daychek is not meant for children under [MINIMUM AGE].

Changes

When this policy changes, the date at the top of this page changes with it.