Diverse people representing the range of Daylogue users who trust the platform with their personal reflections

Security & Trust

Trust & Security at Daylogue

How we protect your data and the commitments we make to keep it safe.

No data salesNo model trainingSOC 2 readinessHuman-safe AI

What Daylogue Is

Daylogue is a pattern journal. It reads the patterns across your check-in entries over time and surfaces them back to you. It does not assess emotions, produce clinical evaluations, or tell you or anyone else what you are feeling.

Daylogue is not therapy and is not a replacement for professional care.

AI Safety Guardrails

Daylogue operates under eight product-level guardrails that govern what the AI can and cannot do:

  • 1No emotion labels appear in reports to employer-context organization administrators.
  • 2Administrators see participation rates and reported themes only. Numeric mood or stress scores are never surfaced to employers.
  • 3Voice check-in includes an explicit disclosure of the data flow before activation.
  • 4Individual emotion scores are never shared with employer-context administrators, regardless of any sharing preference.
  • 5Numeric mood scores do not appear in employer-facing interfaces.
  • 6AI output in administrator-facing contexts uses behavioral and thematic language only, not emotional assessments.
  • 7Organization members see a disclosure of exactly what their administrator can and cannot see before their first check-in contributes to team data. Clients of a solo Collab practice see a separate written authorization naming their provider and every signal it releases.
  • 8Organization administrators acknowledge a no-coercion policy before activating member invitations.

Full documentation: AI Safety.

SOC 2 Readiness

In Progress

Daylogue is pursuing SOC 2 Type I certification, with the assessment scheduled for Q2 2026. We are working with an accredited auditor across availability, confidentiality, and privacy trust service criteria. The attestation report will be published on completion.

Our AI safety practices align with ISO 42001 (AI management system standard). The full AI safety policy pack is available to enterprise procurement teams on request.

Encryption

At restDisk-level AES-256 at the hosting provider. This protects a stolen disk or a raw backup. It does not put entry text beyond Daylogue’s reach — see the journal-entry row below, which is the answer to the question most reviewers are actually asking.
In transitTLS 1.3
Journal entriesTLS in transit, with per-user access controls in the database. Vault entries use AES-256-GCM where an account has a key, which is not a guarantee that we can never decrypt them. Not end-to-end encrypted: our servers read entry text to write narratives and surface patterns.
VoiceDaylogue does not intentionally persist the raw audio recording. Deepgram processes audio under the current terms and configuration listed on our subprocessor page. The transcript is persisted: spoken words become the text of the check-in or reflection they belong to, and from that point they are stored exactly like typed entries, in the row above. No employer access at any point.

Data Residency

All data is stored and processed in the United States. Infrastructure runs on AWS us-east-1 and us-west-2. EU data residency is not currently available. Organizations with specific residency requirements should contact security@daylogue.io.

HIPAA-Aligned Practices

Daylogue follows HIPAA-aligned practices for technical security: access controls, audit logging, and integrity verification. Daylogue does not claim HIPAA compliance as a covered entity and does not hold Business Associate Agreements for general customers.

Healthcare customers with BAA requirements should contact security@daylogue.io.

AI Infrastructure

All AI inference routes through AWS Bedrock. It does not run emotion recognition on your face or on the tone of your voice.

  • AWS Bedrock processes requests under the current terms and configuration documented on our subprocessor page
  • Model-provider access and retention are governed by the current AWS service architecture and written terms
  • Voice transcription uses Deepgram under the current written terms and configuration
  • EU AI Act Article 50 disclosure: Daylogue's check-in conversations are AI-generated. Users interact with an AI system, not a human. This is disclosed in the product.

Full AI safety documentation

Consumer Health Data (WA / NV / CT)

Users in Washington State, Nevada, and Connecticut have additional rights under state consumer health data laws (Washington My Health MY Data Act, Nevada SB 370, Connecticut SB 3). Your check-in data, voice transcripts, and AI-generated wellness narratives are classified as consumer health data under these laws.

Consumer health data rights and policy

Subprocessors

Daylogue uses the following sub-processors. All are bound by written confidentiality and security obligations and process data on Daylogue's instructions. Material changes are posted here at least 30 days before they take effect.

SupabaseDatabase, authentication, file storageUS
AWS BedrockAI inference under current service terms and configurationus-east-1, us-west-2
DeepgramVoice-to-text under current service terms and configurationUS
ElevenLabsConversational voice processing under current service terms and configurationUS
ResendTransactional emailUS
StripePayment processingUS
VercelApplication hosting and edge deliveryUS
SentryError and performance monitoring (PHI scrubbed before send; see Logging & Telemetry)US

Authentication

  • Password minimum 12 characters; common-password and breach-password rejection enabled (HIBP).
  • TOTP-based MFA available for all users; required for organization administrators.
  • Refresh-token rotation with reuse detection; sessions revoked on password change.
  • Row-Level Security on every Supabase table; service-role keys never exposed to clients.
  • Aligned with NIST SP 800-63B Rev 4 AAL2 for administrators.

Logging & Telemetry

Logs capture access events, API calls, authentication events, and admin actions. Logs do not contain check-in text, voice transcripts, journal vault content, or numeric mood scores. Sentry error reports run through a PHI/PII scrubber (scrubPhiFromObject) before send. Operational logs are retained for 90 days; authentication and admin audit logs are retained for 12 months in a tamper-resistant store.

No log content is used to train any AI model. See the AI Training Transparency page and the AI Trust Layer page.

Backup & Disaster Recovery

Daily encrypted backups with 30-day point-in-time recovery on the primary database. Recovery Time Objective (RTO): 4 hours. Recovery Point Objective (RPO): 1 hour. Restore drills run at least twice per year per the DR Restore Test runbook.

Incident Response & Status

Daylogue maintains a written Incident Response Plan and runs tabletop exercises at least annually. We commit to the following breach-notification windows where applicable:

  • Within 60 days under the FTC Health Breach Notification Rule.
  • Within 72 hours of awareness under GDPR Article 33 (where applicable).
  • Within the windows set by Washington (My Health My Data Act), Nevada SB 370, Connecticut SB 3, California (CCPA/CPRA), and other state breach laws as applicable.

Service availability is monitored externally; the public status page will be linked here once published.

Your Data Rights

You can access or delete your data at any time from Settings → Data & Privacy, or by emailing privacy@daylogue.com. Active records are removed immediately on deletion; backups are purged within 30 days. Verified requests are completed within 45 days (with one 45-day extension where permitted).

Detail and state-specific rights: Consumer Health Data Privacy and Privacy Policy.

Children's Data

Daylogue is not directed to children under 13 and does not knowingly collect personal information from children under 13 (COPPA). The product is intended for users 18 and older. If we learn we have collected data from a child under 13 without verifiable parental consent, we will delete it.

Vulnerability Disclosure

To report a security vulnerability, email security@daylogue.io. We acknowledge reports within 24 hours and respond with a resolution timeline within 5 business days. Machine-readable contact information is published at /.well-known/security.txt (RFC 9116).

In scope

  • The Daylogue web application at daylogue.com and its public APIs.
  • The Daylogue iOS application and web app. Android production builds will enter scope when Google Play is enabled.
  • Authentication, session management, and account-recovery flows.
  • Data isolation between users and between organizations (RLS bypass, IDOR, tenant escape).

Out of scope

  • Findings against third-party infrastructure we do not control (Supabase platform, Vercel platform, AWS, Stripe, Deepgram). Report those directly to the vendor.
  • Reports requiring physical access, social engineering of Daylogue staff, or denial-of-service.
  • Missing security headers, rate-limit hardening suggestions, and best-practice recommendations without a demonstrated impact.
  • Self-XSS, clickjacking on pages without sensitive actions, and version-disclosure findings.
  • Automated scanner output without proof of exploitation.

Safe harbor

Daylogue will not pursue legal action or contact law enforcement against researchers who, in good faith, follow this policy: report promptly, do not access more data than is necessary to demonstrate the issue, do not modify or delete data, do not degrade the service for others, do not publicly disclose before we have remediated (we follow a 90-day coordinated disclosure norm), and do not violate any applicable law beyond the authorization granted here. This safe harbor does not extend to third-party services listed as out of scope.

Bug bounty

Daylogue does not currently operate a paid bug bounty program. Researchers who follow this policy are recognized below with their permission.

Acknowledgments

No public acknowledgments to date. Researchers credited here with their permission as reports are received and validated.

Security Questionnaire

Need to complete a vendor security review? Submit your questionnaire below and we'll respond within 5 business days.