Privacy Policy
Who we are
DayWell is provided by Tom Harris, trading as DayWell ("DayWell", "we", "us"), a sole trader based in the United Kingdom. For any question about this policy or your data, contact tomjohnharriscoaching@gmail.com.
DayWell is currently in closed beta. This policy describes how we handle your data during the beta and will keep applying as the product develops.
What we collect
We collect the information you give us directly, and a small amount collected automatically:
- Account details — your email address and password (stored securely by our authentication provider, never in plain text) and any display name you set.
- Household content — anything you or your household members add to organise your family's life: household name and location, events, tasks and reminders, shopping lists, meal plans, and household member names.
- Documents and Vault items — files you upload, including anything you choose to store in the Vault (our storage area for more sensitive documents, such as IDs or insurance papers). These are stored in a private, household-scoped location and are never shared outside your household except when you explicitly generate a share link.
- AI feature inputs — text you enter into Brain Dump, shopping-list parsing, or document extraction is sent to our AI provider to be interpreted (see "Who we share data with" below).
- Billing information — if you subscribe to a paid plan, our payment processor (Stripe) handles your card details directly. We never see or store your full card number; we only receive confirmation of your subscription status.
- Feedback and support — anything you submit through in-app Beta Feedback, including optional screenshots and basic device/browser diagnostics, so we can reproduce and fix issues.
- Technical data — standard server logs (IP address, timestamps, error details) and, in your browser, crash/error reports, so we can diagnose problems.
Children's data
DayWell is a family organisation tool, so household data may include the names or details of children as part of managing family life (for example, a "Children" life area). Accounts are only created by an adult household owner, who is responsible for what's added about other household members, including children. We don't knowingly allow anyone under 18 to create an account, and we don't use children's data for anything beyond providing the household organisation features you've set up.
Why we use your data
- To provide and maintain the DayWell service you've signed up for.
- To process payments and manage your subscription.
- To send service emails: account verification, household invites, and the reminder emails you've configured.
- To respond to support requests and beta feedback.
- To diagnose bugs and keep the service reliable and secure.
- To meet our legal and accounting obligations.
We don't sell your data, and we don't use your household content or documents to train AI models or for advertising.
Who we share data with
We use a small number of trusted service providers ("subprocessors") to run DayWell. Each only receives what it needs to do its job:
- Supabase — our database, authentication, and file storage provider. Holds your account, household content, and uploaded files.
- Stripe — handles payment processing and subscription billing. Receives your billing details and card information directly; we don't store card numbers ourselves.
- OpenAI — processes the text you submit to AI features (Brain Dump, shopping-list parsing, document extraction) to interpret it. Only the specific text/document you submit to that feature is sent, not your wider household data.
- Resend — delivers transactional emails (verification, invites, reminders) on our behalf.
- Sentry — receives anonymised crash/error reports from the app in your browser, to help us fix bugs.
- Vercel — hosts the application and processes standard web server logs.
Some of these providers may process data outside the UK or EEA (for example, in the United States). Where that happens, we rely on their standard contractual safeguards for international transfers. We otherwise only disclose your data if required by law.
How long we keep it
We keep your data for as long as your household exists. If you delete your household from Settings, your household's data — items, documents, Vault items, tasks, and reminders — is permanently deleted, along with the underlying files in storage. Deleting your household also cancels any active subscription. Some records (such as billing history) may be retained separately by Stripe as required for accounting and tax purposes.
How we protect it
- Documents and Vault items are stored in a private bucket, scoped to your household, and accessed only via short-lived signed links.
- Database access is governed by row-level security, so one household's data is never visible to another.
- Fields that control your subscription status can only be changed by our verified payment system, never by a client request.
- Passwords are checked against known breach databases at sign-up and change.
No system is perfectly secure, but we design DayWell to keep your household's data private by default.
Cookies and local storage
DayWell uses only the cookies and browser storage needed to keep you signed in and remember your preferences (such as light/dark theme). We don't use advertising or third-party tracking cookies.
Your rights
Under UK data protection law, you have the right to:
- Access the personal data we hold about you.
- Ask us to correct inaccurate data.
- Ask us to delete your data (you can also do this yourself via "Delete household" in Settings).
- Ask us to restrict or object to certain processing.
- Receive your data in a portable format.
To exercise any of these rights, email tomjohnharriscoaching@gmail.com. If you're unhappy with how we've handled your data, you also have the right to complain to the UK Information Commissioner's Office (ico.org.uk).
Changes to this policy
As DayWell moves from beta towards general availability, this policy may be updated. If we make a material change, we'll let you know by email or an in-app notice before it takes effect.