
Legal
Privacy Policy
How Daylogue protects your entries, AI processing, and privacy controls.
Last updated: August 18, 2026
Privacy is the foundation Daylogue is built on. This document explains exactly what data we collect, how we protect it, and what rights you have. We believe you should know precisely how your most personal thoughts are handled.
1. Information We Collect
We collect only what's necessary to provide our service. Here's exactly what we store:
Account Information: Your email address and authentication credentials. This is stored in plaintext so we can send you notifications and help you recover your account.
Journal Entries & Check-in Notes: Your journal entries and check-in notes are stored on our servers in readable form, protected in transit by TLS and by per-user access controls in the database. Daylogue reads them to write your narratives and surface your patterns. That is how the product works, and we would rather say so than imply otherwise.
Journal Vault Entries: Where an account holds an encryption key, entries written to the journal vault are additionally stored as AES-256-GCM ciphertext. Not every account holds one, and there is no setting that turns this on or off. Check-in fields including gratitude, wins, and challenges are always stored in readable form.
AI-Generated Summaries & Insights: When you use AI features, Daylogue generates summaries, narratives, and pattern insights from your check-ins. These AI-generated outputs are always stored in readable form, not encrypted, because they power features like your daily narrative, weekly insights, and pattern detection.
Structured Metrics & Metadata: Mood scores, energy levels, stress ratings, sleep data, tags, timestamps, and device identifiers. This structured data powers your dashboards, trends, and AI features. It is protected by per-user access controls and row-level security, and it is stored in readable form.
Encryption Keys: Where an account has an encryption key, that key is generated on your device and a wrapped copy is stored on our servers. Depending on how the account was set up, we may also be able to unwrap it. Vault encryption protects those entries from routine staff access and from most data breaches, but it is not a guarantee that we can never access or reconstruct your content, and you should not treat it as one.
2. How We Use Your Information
We use your information to:
- Provide the core journaling and check-in experience
- Generate AI-powered insights and pattern detection
- Send reminders and notifications (with your permission)
- Respond to support requests
- Improve and maintain our services
- Prevent abuse and ensure security
**We never use your data for:** - Advertising or ad targeting - Selling to third parties - Training AI models - Any purpose you haven't consented to
3. Encryption & Security
Your privacy is protected by several concrete controls:
Vault Encryption: Where an account has an encryption key, journal vault entries are encrypted on your device with AES-256-GCM before transmission, and that key is wrapped using PBKDF2-SHA256 at 600,000 iterations. This is not end-to-end encryption, and it is not a guarantee that we can never decrypt this content.
What Our Servers Read: Daylogue reads your entries to write your narratives, detect patterns, and generate summaries. That processing happens on our servers. AI-generated summaries, narratives, and structured metrics are stored in readable form because the features you use depend on them.
No Emotion Inference: Daylogue does not run emotion recognition on your face or on the tone of your voice. It works only from what you choose to share.
Transmission Security: All data in transit is protected by TLS.
Log Redaction: Entry text is kept out of Daylogue's application logs and error reports.
HIPAA-Aligned Safeguards: Our technical security measures follow HIPAA Security Rule principles, including access controls, audit logging, and integrity verification. Note: We are not HIPAA compliant and do not offer Business Associate Agreements.
4. AI Features & Your Data
AI is core to Daylogue's insights. Here's exactly how it works:
How AI Processing Works: 1. When you use AI features, your content is sent to our AI provider (AWS Bedrock) for processing 2. AI generates insights, summaries, and narratives 3. AI-generated summaries are stored server-side to power features like your daily narrative, pattern detection, and insights 4. Your entries stay on our servers: in readable form for most accounts, and additionally as vault ciphertext where an encryption key exists
Important Disclosures: - During AI processing, your content briefly exists as readable text at AWS Bedrock - Daylogue does not use personal entries to train AI models. Provider handling is governed by the current service configuration, written terms, and our subprocessor agreements - Voice check-ins use Deepgram for speech-to-text, ElevenLabs for conversational voice, and AWS Bedrock for AI processing under the retention settings and agreements listed on our subprocessor page - AI-generated summaries are stored in readable form, because they are needed server-side for features you use - Daylogue does not run emotion recognition on your face or on the tone of your voice. It works only from what you choose to share
No AI mode: On supported accounts and platforms, No AI mode prevents newly submitted content from being sent to Daylogue's AI and voice services. It is not a local-only or end-to-end-encrypted mode: entries still sync to and are stored by Daylogue on the terms described above. Rules-based patterns require a separate choice, use structured fields and eligible accepted manual tags, and omit sensitive tags. Turning AI features back on applies only to future content; protected content is not backfilled.
6. Enterprise & Organization Features
Daylogue offers optional organization and team features for workplaces, sports teams, and other groups. Here is how your data is handled in those contexts.
Aggregate Data Access: Organization administrators can view aggregate (anonymized) wellness data about their members through a dashboard and API. Individual data is never included in these aggregates. We require a minimum of 5 active members before any aggregate metrics are shown, so no individual can be identified through small group sizes (this is called k-anonymity).
Individual Score Sharing: Members who join an organization can optionally choose to share their individual wellness scores (mood, energy, stress) with organization leaders. This sharing is: - Entirely voluntary and opt-in - Controllable per metric (you can share mood but not stress, for example) - Revocable at any time through your settings - Limited to the past 7 days of scores (leaders cannot see historical data, written reflections, or voice entries) - In a Collab solo practice, the same controls also cover theme words drawn from a fixed vocabulary we maintain, and a count of check-ins since your last session. A provider never receives a check-in date or time, and never your own wording.
API Access: Enterprise organizations may access aggregate data and, where members have opted in, individual scores through authenticated API endpoints. All API access is: - Authenticated via organization-specific API keys - Rate-limited and monitored for abuse - Logged for compliance auditing - Scoped to specific data types (an API key cannot access more than what was granted)
Webhook Data Transfers: Organizations may configure webhooks to receive automated notifications about organizational events (such as wellness alerts or weekly report availability). Webhook data: - Contains aggregate information only (no individual data is sent via webhooks) - Is signed with HMAC-SHA256 so the receiving server can verify authenticity - May be delivered to URLs specified by the organization administrator - Delivery is logged for audit purposes
API Request Logging: We log API request metadata including client IP addresses, user agent strings, and request timestamps for security monitoring, abuse prevention, and compliance auditing. These logs are retained for 90 days.
Peer Feedback (Appreciation, Constructive, Concern): Workplace organizations may enable peer feedback, which lets members send feedback to one another in three lanes. Each lane has a different visibility model: - **Appreciation** is private to the recipient by default. Designated reviewers and organization administrators are notified that a note was sent and can see the sender, recipient, lane, and date — but not the body. Senders can optionally choose at submission time to share an appreciation note with team admins, in which case admins can also read the body in their reviewer dashboard. - **Constructive feedback** is visible to the recipient and to designated reviewers (which typically includes organization owners, admins, and coaches). The body of the message is visible to those reviewers as part of the moderation flow. - **Concern reports** are visible to designated reviewers. The body is not shown to the recipient.
For all lanes, designated reviewers can read message bodies they are authorized to see, update case status, and (for constructive and concern) participate in a moderated thread with the sender. Anonymous submissions are supported where the lane allows it; anonymous senders are not linked to a user account in the submission record. Submissions are retained per lane for the period configured by the organization (defaults: appreciation 365 days, constructive 730 days, concern up to 7 years for compliance retention).
AI-Generated Content: Team narrative summaries provided through the API are generated by AI from anonymized aggregate data. They are not clinical assessments and should not be treated as medical, psychological, or diagnostic information.
7. If You Leave Your Organization
When you leave an organization (voluntarily, via admin removal, or via SCIM offboarding), your personal check-in history and account remain intact. Your past contributions to team aggregates are frozen in the historical windows they belonged to — they are not removed retroactively, to preserve the statistical integrity of those aggregates for the remaining team members. Going forward, your data no longer contributes to team averages. You can export your data at any time from Settings → Privacy → Export.
8. California Privacy Rights (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) give you specific rights regarding your personal information.
Right to Know: You have the right to request disclosure of what personal information we collect, use, disclose, and sell about you.
Right to Delete: You have the right to request deletion of personal information we have collected from you, subject to certain exceptions.
Right to Opt Out of Sale or Sharing: We do not sell or share your personal information for cross-context behavioral advertising. You can still record an opt-out through the "Do Not Sell or Share My Personal Information" footer link, which disables marketing tracking. We honor Global Privacy Control (GPC) signals as a valid opt-out request.
Right to Correct: You have the right to correct inaccurate personal information we hold about you.
Right to Limit the Use and Disclosure of Sensitive Personal Information: Under CPRA, you have the right to limit our use of sensitive personal information (SPI) to what is necessary to perform the service. Daylogue collects the following categories of SPI: (1) voice audio and transcripts from voice check-ins; (2) self-reported wellness data (mood, energy, stress, sleep) and AI-generated inferences derived from your check-ins, which may reveal information about your mental or physical condition; and (3) precise geolocation when used for weather and context personalization. We use this SPI solely to provide the service you signed up for. We do not use SPI to infer characteristics about you for any other purpose, and we do not sell or share SPI. To exercise the right to limit, email privacy@daylogue.com with "Limit Sensitive Personal Information" in the subject line, or use the "Limit the Use of My Sensitive Personal Information" link in our footer.
Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA/CPRA rights.
Rights of Minors (Ages 13–16): For California residents between the ages of 13 and 16, we do not sell or share your personal information without your opt-in consent. We do not knowingly collect personal information from users under 13 under any circumstances.
Data Retention: We retain personal information only as long as needed to provide the service or as required by law. Account information is retained while your account is active plus a 30-day deletion grace period; journal vault entries, encrypted check-in notes, AI-generated summaries, and structured metrics are retained while your account is active; API request logs are retained for 90 days. Voice providers process audio under the current terms and configuration listed on our subprocessor page. Backups are purged within 30 days of account deletion.
CA AB 2013 AI Transparency: Daylogue does not use your data to train Daylogue models. External inference is governed by the current provider terms and configuration listed on our subprocessor page.
How to Submit a Request: Use our privacy request form at /privacy/request, or email privacy@daylogue.com with "California Privacy Request" in the subject line. We will respond within 45 days.
9. Consumer Health Data (WA / NV / CT)
Users in Washington State, Nevada, and Connecticut have additional rights under state consumer health data laws.
Applicable laws: Washington My Health MY Data Act (WMHDA, RCW 19.373), Nevada SB 370 (NRS Chapter 629), Connecticut SB 3.
What qualifies as consumer health data in Daylogue: Self-reported check-in scores (mood, energy, stress), voice check-in transcripts, AI-generated wellness narratives, and pattern data derived from your check-in history.
Your rights (Washington WMHDA): - Right to access your consumer health data (within 45 days) - Right to deletion of consumer health data (within 30 days, independent of account deletion) - Right to withdraw consent to collection or sharing at any time - Right to know whether your consumer health data is shared with third parties
Your rights (Nevada SB 370): - Right to access, right to deletion (within 30 business days), right to opt out of sale
Your rights (Connecticut SB 3): - Right to access, right to deletion (within 60 days), right to portability, right to opt out of processing for non-service purposes
How we use consumer health data: Solely for service delivery. We never sell it, use it for advertising, or share it with employer-context administrators in any individually identifiable form. If you decline health data collection in-app, mood, energy, stress, and sleep scores will not be collected during check-ins, and voice check-ins will be unavailable while that preference is active. Your choice is remembered across sessions and can be changed at any time in Settings > Privacy & Security. Crisis resources remain available regardless of your consent state.
No AI mode and consumer health data: No AI mode is separate from collection consent. On supported accounts and platforms it prevents new content from being sent to Daylogue's AI and voice services, but it does not keep entries only on your device. Entries and structured fields still sync to and are stored by Daylogue. Rules-based patterns require a separate choice and omit sensitive manual tags. Turning AI back on does not backfill content protected while No AI mode was active.
To exercise these rights: Email privacy@daylogue.com with "Consumer Health Data Request" and your state of residence in the subject line.
Full policy: Consumer Health Data Privacy Policy (available at security@daylogue.io on request).
9a. GDPR and EU User Rights
If you are located in the European Economic Area, the United Kingdom, or Switzerland, the General Data Protection Regulation (GDPR) and applicable national law govern our processing of your personal data.
Legal basis for processing: We process your personal data on the basis of: - Your explicit consent (Article 6(1)(a)) for check-in data, AI processing, and optional features - Contract performance (Article 6(1)(b)) for account management and service delivery
Article 9 special-category data: Self-reported check-in scores and wellness narratives may qualify as data concerning health under GDPR Article 9. We process this data only with your explicit consent, which you give at the time you complete a check-in. You may withdraw this consent at any time in Settings > Privacy & Security.
EU AI Act Article 50 disclosure: Daylogue's check-in conversations are generated by an AI system. You are interacting with an AI, not a human. This disclosure is made before every check-in session.
Your GDPR rights: Right to access, right to rectification, right to erasure ("right to be forgotten"), right to restriction of processing, right to data portability, right to object, right not to be subject to solely automated decision-making.
How to exercise your rights: Email privacy@daylogue.com with "GDPR Data Request" in the subject line. We will respond within 30 days.
Data transfers: Your data is processed in the United States. We rely on standard contractual clauses (SCCs) where applicable for cross-border transfers.
10. Your Rights & Controls
You have complete control over your data:
Export: Download all your data in standard formats anytime from your account settings.
Delete: Request permanent deletion of your account and all associated data. Deletion requests are processed within a 30-day grace period, during which you can cancel the deletion. After 30 days, all data is permanently removed and cannot be recovered. One exception: if you shared signals with a licensed therapist through Collab Clinical, the specific entries you disclosed are held in your therapist's custody to a statutory retention date required by California law, and are not removed on this schedule. Nothing you never shared is affected, and you can see what is held and until when.
Access: Request a copy of all data we hold about you.
Correction: Update your account information at any time.
Opt-Out: Unsubscribe from marketing emails anytime. Essential service communications (security alerts, account issues) cannot be opted out of while your account is active.
To exercise these rights, email privacy@daylogue.com or use the in-app settings.
11. SMS Messaging
View SMS program details, opt-in flow, and sample messagesProgram Name: Daylogue SMS Check-ins
What It Is: When you opt in through the Daylogue app, we send text message check-in prompts to your phone number. You reply with how you're feeling, and your response is processed as a check-in. You can also opt in to SMS notifications (reminders, weekly summaries, and gentle nudges).
Message Frequency: Up to 5 messages per day (1 outbound prompt plus up to 4 conversational follow-ups per session). Notification texts are sent based on your chosen schedule.
Message and Data Rates: Standard message and data rates may apply depending on your mobile carrier plan.
Opt-In: You opt in to SMS check-ins exclusively through the Daylogue app settings by entering your phone number, verifying it with a one-time code, and toggling on SMS check-ins. SMS is off by default. No messages are sent until you explicitly opt in. There is no web form, keyword, or checkout-based enrollment.
Opt-Out: You can stop receiving messages at any time by replying **STOP** to any message, or by toggling off SMS check-ins in your Daylogue app settings.
Help: Reply **HELP** to any message for support information, or contact us at hello@daylogue.io.
Your Phone Number and Mobile Information: We store your phone number solely for delivering SMS check-ins. No mobile information, including phone numbers, SMS consent records, and opt-in/opt-out data, will be shared with or sold to third parties or affiliates for marketing or promotional purposes. Your number is stored securely and used only to deliver the messages you requested.
AI-Personalized Messages: Some SMS check-in messages are personalized using AI. When this occurs, aggregated data from your recent check-ins (mood trend, tags, check-in frequency) is processed by our AI provider to generate a contextually relevant opening message. This processing is ephemeral. No SMS content or AI inputs are stored by the AI provider. Approximately 40% of messages use standard templates with no AI personalization.
SMS conversations and crisis handling: If your SMS conversation is identified as containing signs of a crisis, such as thoughts of suicide, self-harm, or immediate danger, Daylogue is designed to pause its usual data capture. This detection is automated and may not identify every instance.
Detection of crisis content is performed automatically using a combination of keyword pattern matching and AI-assisted review. No human reviews your message content.
If a crisis is detected, we will send you crisis resource information: 988 Suicide and Crisis Lifeline (US), Crisis Text Line at 741741 (US), and findahelpline.com (international directory). The check-in session ends at that point. Daylogue does not provide crisis counseling or intervention, and does not contact emergency services, notify any third party, or take any action on your behalf in response to crisis content.
Service Provider: SMS messages are delivered through Twilio, our messaging infrastructure provider. Twilio processes your phone number and message content only as necessary to deliver the service.
Carriers: Supported on all major U.S. carriers. Carriers are not liable for delayed or undelivered messages.
13. Children's Privacy
Daylogue is not intended for children under 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such information, please contact us immediately at privacy@daylogue.com and we will delete it.
14. Policy Updates
We may update this policy to reflect changes in our practices or for legal reasons. When we make material changes:
- We'll post the updated policy here with a new "Last updated" date
- We'll notify you via email for significant changes
- Continued use after changes constitutes acceptance
We encourage you to review this policy periodically.
15. Contact Us
Questions about privacy? We're here to help.
Email: privacy@daylogue.com
Response Time: We aim to respond within 48 hours.
Data Protection: For data protection inquiries or to exercise your rights, email privacy@daylogue.com with "Data Request" in the subject line.
Address: Daylogue LLC Los Angeles, CA United States