Legal
Privacy Policy
- Last updated
- Effective
This policy applies to the Day Pal mobile apps, the getdaypal.com website and any related services.
Plain-English summary
We’re building a calorie tracker, not a data broker. Here’s the short version; the rest of the page is the formal detail.
- We collect the minimum data needed to run the app.
- Before a photo leaves your phone, the app re-encodes it, which removes EXIF, GPS and all other metadata.
- Meal photos are saved on your phone and stay there until you delete them. The copy sent for analysis is discarded once the AI answers: we store no image bytes on our servers, on any plan.
- Progress photos never leave your device. The app sends us a fingerprint and a timestamp, never the image.
- Voice logging uses on-device speech recognition. No audio is recorded or uploaded; only the resulting text is sent.
- We never sell your data or use it for ad targeting. The app does not track you across other companies’ apps and does not use your device’s advertising ID.
- We never send your name or email to AI providers.
- You can export your data, or delete your account and the data tied to it, at any time. Deletion takes effect immediately.
Who we are
Day Pal is operated by the Day Pal team (“Day Pal”, “we”, “us”). For privacy questions, email hello@getdaypal.com. If you are in the EU or UK, data-protection requests go to the same address.
Data we collect
What we collect depends on the features you use. We never collect more than we need.
Account data
RequiredAccount ID, sign-up date and, if you create an account rather than use the app as a guest: your email address, an optional display name, and a password hash or an Apple or Google sign-in token.
Profile data
RequiredHeight, weight, sex, date of birth, activity level, goal (lose, maintain or gain), dietary style, allergies and foods you dislike.
Food log data
RequiredWhat you logged and when, its calories, macros and micronutrients, how you logged it (photo, voice, text or manual), and the text you typed or dictated.
Device identity and security
RequiredAn install ID the app creates (on Android, the Android ID), which we store only as a SHA-256 hash, and the result of a device check by Apple (DeviceCheck / App Attest) or Google (Play Integrity). This is how each device gets its 20 free AI actions once, and how we stop that allowance from being abused.
Body and workout data
OptionalWeight and water history, workouts and sets, and the fact that you took a progress photo. The image itself stays on your device: we receive a SHA-256 fingerprint and a timestamp, nothing more.
Coach conversations
OptionalThe questions you send to the coach and its answers, so the conversation is there when you come back.
Photos for AI scan
OptionalMeal photos you choose to scan. They are analysed and discarded: we store no image bytes. See “Photos and AI processing” below.
Subscription data
OptionalWhether you have Day Pal Pro, which plan, its renewal or expiry date, and your purchase history. Payment is handled entirely by Apple or Google, so we never see card details.
Notifications
OptionalIf you allow notifications: your device’s push token and the notifications we send you, which also appear in the app’s inbox.
Device and diagnostic data
OptionalApp version, OS version, device model, language, crash reports and performance traces. Email, IP address and username are removed from crash reports before they are sent, and they are not linked to your account.
Product analytics
OptionalEvents that tell us which features are used (for example “diary entry added”), linked to your Day Pal account ID. No event contains your photos, the content of your food log, or your email, and no advertising ID is collected.
How we use your data
- To run the app. Sign you in, save your food log and workouts, and calculate your daily targets.
- To deliver the AI features you use. Photo recognition, text and voice logging, and the coach.
- To manage your subscription. Confirm with Apple or Google, through RevenueCat, whether you have Day Pal Pro.
- To send you things you asked for. Meal and check-in reminders and other notifications you turned on.
- To keep things safe and working. Give each device its free AI actions once, detect abuse and fraud, and fix crashes.
- To improve the app. Product analytics show us which features work and which do not.
- To meet legal obligations. Respond to lawful requests and consumer-rights requests.
We do not sell your data, share it with advertisers, or use it for cross-app behavioural ads.
Legal bases (GDPR)
If you are in the EU or UK, we rely on the following legal bases:
- Contract: to provide the service you signed up for (account, sync, AI features, Day Pal Pro).
- Consent: for optional features such as push notifications. You can withdraw consent at any time.
- Legitimate interests: for product analytics, device checks that prevent abuse of the free allowance, and crash reporting, balanced against your rights and freedoms.
- Legal obligation: to respond to lawful requests and keep records the law requires.
Photos and AI processing
Photo logging is at the core of Day Pal, so we treat it with extra care.
- Metadata removed on your device. Before any photo leaves your phone, the app decodes it and saves a fresh JPEG, so no EXIF, GPS or camera data survives. Our server checks the file it receives as well.
- Kept on your phone, never on ours. Every meal photo you take or choose is saved in the app’s private storage on your device and stays there until you delete it, on every plan. The copy sent for analysis is dropped as soon as the AI returns a result; our servers store no image bytes at all.
- Progress photos never reach us. They are not uploaded, encrypted or otherwise. The app sends a SHA-256 fingerprint and a timestamp so it can show you a timeline; the image stays on your device.
- Voice stays on your device. Speech is recognised by your phone’s on-device recogniser. No audio is recorded or uploaded, and where on-device recognition is not available the microphone button is not shown.
- AI providers see your meal, not you. Meal photos, the text you log and your questions to the coach are processed by OpenAI, our current AI provider, together with the nutrition context the answer needs (such as your targets and today’s log). We never send your name, email or any other identifier with them. Under OpenAI’s API terms this data is not used to train its models, and OpenAI may keep it for up to 30 days to monitor abuse. If we switch to another provider, we will update this list first.
- No training on your photos. We do not train AI models on your photos.
How long we keep data
- Account, profile and logs: for as long as your account exists.
- Meal photos: we keep none. The image is dropped the moment the AI answers; your own copy stays on your phone until you delete it.
- Progress photos: we keep none. Only a fingerprint and a timestamp ever reach us.
- Data export files: deleted 24 hours after they are created, and at once if you delete your account.
- Notification inbox: 90 days.
- Crash reports: up to 90 days.
- Product-analytics events: up to 14 months.
- Free AI allowance: a hashed device key and the number of free AI actions it has used are kept after your account is deleted, with no link to you, so deleting and re-creating an account does not reset the allowance.
- After account deletion: your account and the data tied to it are deleted from our database immediately, and your RevenueCat customer record is deleted too. Backups are purged within 30 days. Apple and Google keep their own purchase records.
Security
- Encrypted in transit (TLS) and at rest.
- Sign-in tokens are stored in the iOS Keychain or Android Keystore, never in plain app storage.
- Progress photos never reach our servers at all: only a SHA-256 fingerprint and a timestamp do, so there is no photo file for anyone to read.
- We will notify you and the relevant supervisory authority within 72 hours of becoming aware of a personal-data breach affecting you, as GDPR Article 33 requires.
International transfers
Our servers are run by DigitalOcean and our database by Supabase, and several of the providers listed above (including OpenAI, Google, Sentry, RevenueCat and Vercel) process data in the United States. When EU or UK data is transferred to the US, we rely on the EU-US Data Privacy Framework where the recipient is certified, and on Standard Contractual Clauses otherwise. You can ask for a copy of these safeguards at hello@getdaypal.com.
Your rights
Wherever you live, you can:
- Access a copy of the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Delete your account and personal data.
- Export your data in a portable format (a ZIP of JSON and CSV files).
- Object to or restrict certain processing.
- Withdraw consent for optional features at any time, for example by turning notifications off.
- Complain to a supervisory authority (in the EU, your local data protection authority; in the UK, the ICO).
EU and UK residents have these rights under the GDPR. California residents have rights under the CCPA / CPRA, including the right to know, delete and correct, and to opt out of the sale or sharing of personal data. We do not sell or share data for cross-context behavioural advertising in any case, and we will not treat you differently for exercising any of these rights.
To exercise a right, use You → Export data or You → Delete account in the app, or email hello@getdaypal.com. An export file is kept for 24 hours. We reply within 30 days.
Children
Day Pal is not intended for children under 16, and we do not knowingly collect data from them. If you believe a child has signed up, contact us and we will delete the account.
Changes to this policy
We update the “Last updated” date at the top whenever we change this policy. For material changes we will also tell you in the app or by email at least 14 days before they take effect, so you can decide whether to keep using the service.
Contact us
Privacy questions, data requests, or anything else: hello@getdaypal.com.