Legal

Privacy policy

day·lı is a private daily task manager. This policy explains how the day·lı web app and Dayli browser extension handle your data.

Effective and last updated: August 29, 2026

Information we handle

We handle only the information needed to provide and secure day·lı:

  • Account information. Your name, if you provide one, email address, user ID, and authentication session are managed through Neon Auth. day·lı does not store your password in its task or preference data.
  • Task content. Task titles, optional descriptions, scheduling information, Inbox-entry dates, status, completion timestamps, and archive timestamps that you add to the service.
  • Preferences. Your appearance, day structure, and Inbox archival preferences, and whether you completed the product tour.
  • Browser and device data. The web app keeps an account-scoped local working copy of Inbox and scheduled tasks, pending changes, preferences, and sync timestamps. Your browser’s IANA time zone is sent with time-sensitive requests so day boundaries are calculated correctly.
  • Basic service data. Our hosting and authentication providers may process IP addresses, browser details, request timestamps, and errors to deliver, protect, and maintain the service.

We do not add advertising trackers or third-party analytics to day·lı. We do not collect your browsing history, the contents of other webpages, precise location, contacts, or financial information.

How the extension uses data

Dayli: Your Tasks in Focus replaces the browser’s New Tab page. It uses the browser’s storage permission and has access only to the day·lı service at https://day-li.vercel.app.

The extension receives only your scheduled tasks—not your Inbox, Archive, or completed-task titles—and only the task fields needed to show and complete them: titles, optional descriptions, schedule details, and opaque task IDs. It also receives a yes-or-no indicator of whether you planned anything for today, plus your day structure and appearance preferences, so it can avoid repeating the morning planning prompt and match the web app. It keeps an account-scoped copy of those tasks, preferences, that indicator, a last sync time, and any pending task completions in temporary extension session storage. This information is cleared when the browser session ends. The extension uses your existing signed-in day·lı session only to synchronize with the service and sends your browser time zone with sync requests. A new tab verifies the active account before displaying any cached tasks. An authentication failure clears the task cache, and an account change discards the previous account’s cache before displaying the new account’s tasks. The temporary cache lets an already-open page queue a completion if its connection drops. The extension stores only its onboarding decision in persistent extension storage. This information is not used for advertising, profiling, credit decisions, or any purpose unrelated to day·lı.

How we use information

We use the information described above to:

  • create and authenticate your account;
  • store, display, synchronize, and update your tasks;
  • remember your preferences and tolerate short connection interruptions;
  • protect the service, diagnose failures, and prevent abuse; and
  • comply with applicable legal obligations.

Chrome Web Store Limited Use

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements. We use this information only to provide or improve the extension’s single purpose: showing and completing your day·lı tasks from the browser’s New Tab page.

We transfer this information only when necessary to provide or improve that purpose, comply with applicable law, protect against fraud, abuse, or security threats, or as part of a merger, acquisition, or sale after obtaining any required prior consent. We do not use or transfer it for personalized advertising, profiling, credit decisions, or sale to data brokers.

Humans do not read your task information unless you give explicit consent for specific support, access is necessary for security, access is required by law, or the information has been aggregated and anonymized for lawful internal operations.

Sharing and service providers

We do not sell or rent personal information. We do not share it for personalized advertising. The hosted day·lı service uses Neon for authentication and database storage and Vercel for application hosting. These providers process data needed to operate the service under their own security and privacy commitments.

If you use an independently hosted day·lı deployment, its operator controls that deployment’s task storage, backups, and operational records. Contact that operator about its privacy and retention practices.

We may disclose information if required by law or when reasonably necessary to protect users, the service, or others from fraud, abuse, or security threats.

Storage, retention, and deletion

Task data and preferences are kept in server storage so they remain available across signed-in devices. Tasks left in Inbox are moved to Archive after your selected quiet period and remain stored until you restore or delete them. Archival is not data erasure. A task you delete is removed from the live day·lı dataset.

The web app’s account-scoped local working copy remains on a device until you clear day·lı site data in that browser. Signing out prevents it from being displayed to another account but does not by itself erase that local copy. The extension’s task cache and pending completions are cleared when the browser session ends, the extension is disabled or updated, or the extension is removed. Its non-sensitive onboarding decision remains until extension data is cleared or the extension is removed.

Authentication records and limited operational records may be retained as needed for security, legal compliance, and reliable operation. Service providers may also retain backups or logs according to their own retention requirements.

You can delete tasks in the app, clear day·lı site data in your browser, or uninstall the extension. To request deletion of your account and associated server data, contact us using the method below.

Security

We use access controls, encrypted HTTPS connections, secure session cookies, and account-scoped storage to protect data. No method of electronic storage or transmission is completely secure, so we cannot guarantee absolute security.

Your choices

You may view your task data in day·lı, change its schedule or status where the app allows, delete individual tasks, sign out, clear local browser data, or uninstall the extension. Task titles and descriptions cannot be edited after creation. You may also contact us to ask for a copy of, a correction to, or deletion of personal information associated with your account.

Changes to this policy

We may update this policy when day·lı or its legal obligations change. The date at the top of this page will identify the latest version.

Contact

For privacy questions or data requests, email the day·lı maintainer at hello.bonsaiapps@gmail.com. Do not send your password or task contents.