Legal

Privacy Policy

Last updated
Effective

This policy applies to the Day Pal mobile apps, the getdaypal.com website and any related services.

Plain-English summary

We’re building a calorie tracker, not a data broker. Here’s the short version; the rest of the page is the formal detail.

  • We collect the minimum data needed to run the app.
  • Before a photo leaves your phone, the app re-encodes it, which removes EXIF, GPS and all other metadata.
  • Meal photos are saved on your phone and stay there until you delete them. The copy sent for analysis is discarded once the AI answers: we store no image bytes on our servers, on any plan.
  • Progress photos never leave your device. The app sends us a fingerprint and a timestamp, never the image.
  • Voice logging uses on-device speech recognition. No audio is recorded or uploaded; only the resulting text is sent.
  • We never sell your data or use it for ad targeting. The app does not track you across other companies’ apps and does not use your device’s advertising ID.
  • We never send your name or email to AI providers.
  • You can export your data, or delete your account and the data tied to it, at any time. Deletion takes effect immediately.

Who we are

Day Pal is operated by the Day Pal team (“Day Pal”, “we”, “us”). For privacy questions, email hello@getdaypal.com. If you are in the EU or UK, data-protection requests go to the same address.

Data we collect

What we collect depends on the features you use. We never collect more than we need.

Account data

Required

Account ID, sign-up date and, if you create an account rather than use the app as a guest: your email address, an optional display name, and a password hash or an Apple or Google sign-in token.

Profile data

Required

Height, weight, sex, date of birth, activity level, goal (lose, maintain or gain), dietary style, allergies and foods you dislike.

Food log data

Required

What you logged and when, its calories, macros and micronutrients, how you logged it (photo, voice, text or manual), and the text you typed or dictated.

Device identity and security

Required

An install ID the app creates (on Android, the Android ID), which we store only as a SHA-256 hash, and the result of a device check by Apple (DeviceCheck / App Attest) or Google (Play Integrity). This is how each device gets its 20 free AI actions once, and how we stop that allowance from being abused.

Body and workout data

Optional

Weight and water history, workouts and sets, and the fact that you took a progress photo. The image itself stays on your device: we receive a SHA-256 fingerprint and a timestamp, nothing more.

Coach conversations

Optional

The questions you send to the coach and its answers, so the conversation is there when you come back.

Photos for AI scan

Optional

Meal photos you choose to scan. They are analysed and discarded: we store no image bytes. See “Photos and AI processing” below.

Subscription data

Optional

Whether you have Day Pal Pro, which plan, its renewal or expiry date, and your purchase history. Payment is handled entirely by Apple or Google, so we never see card details.

Notifications

Optional

If you allow notifications: your device’s push token and the notifications we send you, which also appear in the app’s inbox.

Device and diagnostic data

Optional

App version, OS version, device model, language, crash reports and performance traces. Email, IP address and username are removed from crash reports before they are sent, and they are not linked to your account.

Product analytics

Optional

Events that tell us which features are used (for example “diary entry added”), linked to your Day Pal account ID. No event contains your photos, the content of your food log, or your email, and no advertising ID is collected.

How we use your data

  • To run the app. Sign you in, save your food log and workouts, and calculate your daily targets.
  • To deliver the AI features you use. Photo recognition, text and voice logging, and the coach.
  • To manage your subscription. Confirm with Apple or Google, through RevenueCat, whether you have Day Pal Pro.
  • To send you things you asked for. Meal and check-in reminders and other notifications you turned on.
  • To keep things safe and working. Give each device its free AI actions once, detect abuse and fraud, and fix crashes.
  • To improve the app. Product analytics show us which features work and which do not.
  • To meet legal obligations. Respond to lawful requests and consumer-rights requests.

We do not sell your data, share it with advertisers, or use it for cross-app behavioural ads.

Photos and AI processing

Photo logging is at the core of Day Pal, so we treat it with extra care.

  1. Metadata removed on your device. Before any photo leaves your phone, the app decodes it and saves a fresh JPEG, so no EXIF, GPS or camera data survives. Our server checks the file it receives as well.
  2. Kept on your phone, never on ours. Every meal photo you take or choose is saved in the app’s private storage on your device and stays there until you delete it, on every plan. The copy sent for analysis is dropped as soon as the AI returns a result; our servers store no image bytes at all.
  3. Progress photos never reach us. They are not uploaded, encrypted or otherwise. The app sends a SHA-256 fingerprint and a timestamp so it can show you a timeline; the image stays on your device.
  4. Voice stays on your device. Speech is recognised by your phone’s on-device recogniser. No audio is recorded or uploaded, and where on-device recognition is not available the microphone button is not shown.
  5. AI providers see your meal, not you. Meal photos, the text you log and your questions to the coach are processed by OpenAI, our current AI provider, together with the nutrition context the answer needs (such as your targets and today’s log). We never send your name, email or any other identifier with them. Under OpenAI’s API terms this data is not used to train its models, and OpenAI may keep it for up to 30 days to monitor abuse. If we switch to another provider, we will update this list first.
  6. No training on your photos. We do not train AI models on your photos.

Sharing and subprocessors

We share data only with providers who run parts of the service for us, under their data-processing terms:

ProviderPurposeData
DigitalOceanApplication serversAll app data while a request is processed
SupabaseDatabase hostingAccount, profile, logs and other stored data (encrypted at rest)
OpenAIAI analysis of photos and textMeal photos without metadata, logged text, coach questions, nutrition context. No name or email.
Apple, GoogleIn-app purchase, Sign in with Apple / Google, device checksPurchases (we never see card data), sign-in token, device check result
RevenueCatSubscription managementDay Pal account ID (a number), purchase history and receipts
Google FirebasePush notifications (Cloud Messaging) and product analytics (Analytics)Push token, notification text, usage events, Day Pal account ID
SentryCrash and performance reportsStack traces, app and device version, with email, IP and username removed
Vercel Inc.Website hosting and delivery (CDN)IP address and request logs, to serve the website. Processed in the United States.
CloudflareDNS for our domain; exercise images and videos (R2)No personal data. The exercise media bucket holds no user data.
Email delivery providerPassword-reset emailsYour email address and the reset code

We may also disclose data when the law requires it (for example a valid court order), to protect rights and safety, or in connection with a corporate event such as a merger, in which case we will tell you and give you a meaningful chance to delete your account first.

How long we keep data

  • Account, profile and logs: for as long as your account exists.
  • Meal photos: we keep none. The image is dropped the moment the AI answers; your own copy stays on your phone until you delete it.
  • Progress photos: we keep none. Only a fingerprint and a timestamp ever reach us.
  • Data export files: deleted 24 hours after they are created, and at once if you delete your account.
  • Notification inbox: 90 days.
  • Crash reports: up to 90 days.
  • Product-analytics events: up to 14 months.
  • Free AI allowance: a hashed device key and the number of free AI actions it has used are kept after your account is deleted, with no link to you, so deleting and re-creating an account does not reset the allowance.
  • After account deletion: your account and the data tied to it are deleted from our database immediately, and your RevenueCat customer record is deleted too. Backups are purged within 30 days. Apple and Google keep their own purchase records.

Security

  • Encrypted in transit (TLS) and at rest.
  • Sign-in tokens are stored in the iOS Keychain or Android Keystore, never in plain app storage.
  • Progress photos never reach our servers at all: only a SHA-256 fingerprint and a timestamp do, so there is no photo file for anyone to read.
  • We will notify you and the relevant supervisory authority within 72 hours of becoming aware of a personal-data breach affecting you, as GDPR Article 33 requires.

International transfers

Our servers are run by DigitalOcean and our database by Supabase, and several of the providers listed above (including OpenAI, Google, Sentry, RevenueCat and Vercel) process data in the United States. When EU or UK data is transferred to the US, we rely on the EU-US Data Privacy Framework where the recipient is certified, and on Standard Contractual Clauses otherwise. You can ask for a copy of these safeguards at hello@getdaypal.com.

Your rights

Wherever you live, you can:

  • Access a copy of the personal data we hold about you.
  • Correct inaccurate or incomplete data.
  • Delete your account and personal data.
  • Export your data in a portable format (a ZIP of JSON and CSV files).
  • Object to or restrict certain processing.
  • Withdraw consent for optional features at any time, for example by turning notifications off.
  • Complain to a supervisory authority (in the EU, your local data protection authority; in the UK, the ICO).

EU and UK residents have these rights under the GDPR. California residents have rights under the CCPA / CPRA, including the right to know, delete and correct, and to opt out of the sale or sharing of personal data. We do not sell or share data for cross-context behavioural advertising in any case, and we will not treat you differently for exercising any of these rights.

To exercise a right, use You → Export data or You → Delete account in the app, or email hello@getdaypal.com. An export file is kept for 24 hours. We reply within 30 days.

Children

Day Pal is not intended for children under 16, and we do not knowingly collect data from them. If you believe a child has signed up, contact us and we will delete the account.

Cookies and analytics on this website

getdaypal.com has no analytics and no advertising cookies. If you pick a language, a cookie remembers it, and your theme choice and a dismissed app banner are remembered in your browser’s local storage. Our website host, Vercel, processes your IP address and request logs to serve the site. Cloudflare only answers DNS lookups for our domain.

Changes to this policy

We update the “Last updated” date at the top whenever we change this policy. For material changes we will also tell you in the app or by email at least 14 days before they take effect, so you can decide whether to keep using the service.

Contact us

Privacy questions, data requests, or anything else: hello@getdaypal.com.

Privacy Policy · Day Pal