How we handle legal requests

Our policies for responding to government and legal demands for user data.

What we can and cannot provide

We would rather tell you the uncomfortable version than the flattering one. Your entries are stored in readable form and could be produced if we were legally compelled. What limits disclosure here is our process and the law, not a cryptographic guarantee.

What we can provide

  • Account email address

    The email used to create the account

  • Account creation date

    When the account was first registered

  • Last login timestamp

    When the account was last accessed

  • Device information

    Basic device identifiers used for sync

  • Journal entries and check-in notes

    Entries are stored on our servers in readable form and could be produced in readable form if legally compelled

  • AI-generated narratives, summaries, and metrics

    These are stored in readable form because the app needs them to be, and could be produced if legally compelled

  • Journal and legacy vault records held by Daylogue

    Do not assume an additional encryption copy places server-readable content beyond Daylogue access or valid legal process

What we cannot provide

  • Any emotion recognition run on your face or the tone of your voice

    Daylogue does not generate this data, so there is nothing to hand over

  • Provider records Daylogue does not hold

    Daylogue can respond only for records it controls. Provider handling follows the current written terms listed in our subprocessor policy.

Our process for legal requests

We take every legal request seriously and follow a careful process to protect your rights.

01

Verify validity

We verify that any legal request is valid, properly served, and legally enforceable in our jurisdiction.

02

Evaluate scope

We push back on overly broad requests and work to narrow the scope to what is legally required.

03

Notify user

Unless legally prohibited, we notify affected users before disclosing any information so they can seek legal counsel.

04

Provide minimum required

We provide only what is legally compelled, nothing more. Where a request can be satisfied with metadata rather than entry content, we push for metadata.

Transparency reporting

We believe in accountability. Here is what we commit to publishing.

Annual reports

Published yearly with total number of requests received

Request types

Breakdown by type: subpoenas, court orders, national security

Compliance rate

How many requests we complied with, challenged, or rejected

Warrant Canary

As of January 17, 2026, we have not received any National Security Letters, FISA court orders, gag orders preventing disclosure of legal requests, or any request to insert backdoors into our encryption.

This statement is updated with each transparency report. If this statement is removed or not updated, users should assume we may have received such a request.

What protects you here is policy, not mathematics. We will not pretend otherwise.

Entries, narratives, summaries, and metrics can be stored in readable form and may be subject to valid legal process. Some legacy account and vault paths contain additional encryption components, but coverage and key custody are under review and should not be treated as immunity from legal process. Any response is governed by applicable law and the facts of the request; this page does not promise notice or a result where the law prohibits it.

Your own protection

While we protect your data on our end, here is what you can do to strengthen your security.

Use a strong, unique password

A compromised password elsewhere should not affect your Daylogue account.

Keep your devices secure

A device someone else can unlock is an account someone else can read. Screen lock, full-disk encryption, no shared logins.

Store your recovery phrase safely

If you were shown a recovery phrase during setup, store it securely offline. It is what rewraps your key if you ever reset your password.

Enable two-factor authentication

Add an extra layer of protection to your account access.

The version we would rather tell you

You should know what a company can hand over before you decide to write anything down in it.