Privacy policy
getdailyme is built on the idea that you decide who sees what. This page explains what data the app needs to work, who touches it, and how to get it back or delete it.
Last updated: August 10, 2026
The five-line summary
- We don't sell your data, we show no ads, and there are no third-party trackers.
- Every activity has its own visibility, and that rule is enforced in the database, not just on the screen.
- There's no people directory: without your exact username or your link, nobody can find you.
- Deleting your account really deletes everything, photos included, with no grace period. Here's how.
- You can write to hola@getdailyme.com about anything on this list.
This summary doesn't replace the text below; it's here so you don't have to read the whole thing to know what matters.
1. Who processes your data
The data controller is QALI-T, a company incorporated in Honduras, with registered address at Tegucigalpa, Honduras. You can reach us at hola@getdailyme.com or through qali-t.com.
The service is provided from Honduras and is aimed at Latin America and at whoever finds it. We do not specifically direct it at the European Economic Area: we don't advertise there, there are no prices in euros —there are no prices at all— there is no version tailored to any European country, and we have not appointed a representative in the Union.
Even so, this policy is written to the standard of Regulation (EU) 2016/679 (GDPR), the strictest one we know of, and we apply its rules to everyone by choice. We don't run two tiers of privacy depending on where you live: you can exercise the rights in section 10 from wherever you are, and we'll answer just the same.
2. What data we process
What you give us when creating the account
- Email address. It's the account identifier and the channel for the magic link and password reset.
- Display name and username. The username is how your friends find you. You can pick whatever you like: we don't check that it's your real name.
- Time zone and language. The time zone decides which day each entry belongs to, which is what makes streaks add up correctly.
- Profile photo, if you upload one or if you sign in with Google and choose to use theirs.
- Credentials. If you sign in with a password, it's stored encrypted and never in plain text. If you use a passkey, we store the public key; your fingerprint or your face never leaves your device. If you sign in with Google, we receive your email and your name, not your password.
- The record of what you accepted: the date and time you ticked the box at sign-up and the minimum age you declared. We don't store your date of birth —we don't ask for it— and this is all that remains of that declaration.
What you generate by using the app
- Activities: name, icon, color, unit, logging mode, goal and visibility.
- Entries: amount, date and time, and optionally a note and a photo.
- Relationships: friendships, requests, invitations, nudges, and who you share each custom-visibility activity with.
- Interactions: reactions and comments on your friends' activity.
- Events and their photos, with whatever caption you give them.
- Challenges: which challenge each of your activities is signed up to, and your total.
What gets generated on its own
- IP address. Every request to the server arrives with one, and it stays in the technical logs along with the date and the browser type. It's there to keep the service standing and to stop abuse —chained sign-in attempts, mostly— not to work out where you are.
- Push notification subscription, if you turn notifications on: an identifier issued by your browser that only serves to deliver the notification to you. It's deleted when you turn them off.
- Error reports: if something breaks, we store the message, the stack trace, the address of the screen where it happened and your browser's identifier, so we can fix it.
- Technical logs from the server and the database, which our providers keep for short periods.
What we don't process: we don't ask for location permission and we don't read your device's GPS —your IP reveals your city at most, and we don't use it for that—, we don't read your contacts, we don't access your photo library beyond the specific photo you choose to upload, and there's no behavioral analytics or advertising profiling.
3. What for, and on what legal basis
| What for | Legal basis |
|---|---|
| Creating and maintaining your account, and providing the service | Performance of the contract (Art. 6(1)(b) GDPR) |
| Showing what you log to the people you've chosen | Performance of the contract, driven by your visibility settings |
| Storing activities that reveal health data | Your explicit consent, revocable (Art. 9(2)(a)) |
| Sending you push notifications | Your consent, revocable at any time (Art. 6(1)(a)) |
| Sign-in emails: magic link and password reset | Performance of the contract |
| Diagnosing errors and keeping the service running | Legitimate interest in the app working (Art. 6(1)(f)) |
| Preventing abuse and responding to legal requests | Legitimate interest and legal obligation (Art. 6(1)(f) and 6(1)(c)) |
We don't process your data for advertising purposes, and we don't make automated decisions with legal effects on you.
4. Who sees what you log
This is the part that defines the product, so it's worth being explicit. Every one of your activities has a visibility, and all its entries inherit it:
- Private — only you. It doesn't appear in any feed, doesn't count toward any shared streak, and can't be fetched through the API.
- Friends — the people you've connected with, and nobody else.
- Custom — only the people you pick for that specific activity.
The filter isn't in the interface: it's PostgreSQL Row Level Security rules that discard the rows before they ever leave the server. Photos follow the same rule and are only served if the activity they belong to is visible to whoever is asking.
Your profile is private too. Only people with a friendship with you —accepted or pending— or who share an event with you can see it. Search works by exact username, so there's no directory to browse through.
In challenges, participants see your total, never your entries. A private activity can compete without ceasing to be private.
What you share with someone stays on their screen for as long as they have access. Nothing stops them taking a screenshot, just like in any conversation. Share with that in mind.
5. If you log health-related things
An activity can be anything, and some of the most common ones —hours of sleep, medication, therapy sessions, weight, menstrual cycle, alcohol— reveal health data. Article 9 GDPR treats these as a special category, under a stricter rule than the rest, so it's worth saying exactly how it works here:
- We never ask you for that kind of data. There's no health field and no category nudging you toward one: it only exists if you create the activity and give it that name.
- The legal basis is your explicit consent (Art. 9(2)(a)), which you give when you create that specific activity knowing what it holds. It doesn't extend to the rest of your data or to any other purpose.
- You can withdraw it whenever you want by deleting the activity, which takes all its entries with it. That doesn't affect what we did before you withdrew it, which was lawful.
- They get no special handling internally: they aren't analyzed, aggregated, cross-referenced with anything, or used to infer anything about you. To the system they're rows like any other, under the same visibility rule.
If you're going to log something sensitive, the practical advice is to leave that activity private. It's the default setting for any new activity, and with it the data never leaves the server for anyone but you.
6. Providers involved
We don't sell or hand over your data. For the service to work, these data processors are involved, each with its own contract and safeguards:
| Provider | What for | Where |
|---|---|---|
| Supabase | Database, authentication and photo storage | EU |
| Vercel | Application hosting and the scheduled reminders job | EU / US |
| Resend | Sending the sign-in emails | EU / US |
| Sign-in, only if you choose that route | US | |
| Your browser's push service | Delivering notifications, only if you turn them on | Depends on the browser |
None of them may use your data for their own purposes: they process it only on our instructions and only for what that table says.
7. Where your data lives
Your data is stored on servers in the European Union. When any of the providers above processes it outside the European Economic Area, the transfer is covered by the European Commission's Standard Contractual Clauses or by an adequacy decision.
There's one more transfer you have a right to know about, and we'd rather spell it out: the QALI-T team accesses the systems from Honduras to run the service and handle support. Honduras has no adequacy decision from the European Commission, so that access is an international transfer without that backing.
What that means in practice: Honduras authorities could in theory come to us with requests that don't carry the same judicial oversight as European ones, and from there enforcing your rights depends more on our response than on a regulator close to you. When you create the account you consent to that transfer with this information in front of you, which is the route under Article 49(1)(a) GDPR. You can withdraw that consent by deleting your account.
Access from Honduras is limited to what's needed to keep the service running, goes over encrypted connections and named accounts, and the visibility rules in section 4 apply to it too: nobody on the team gets to see your private entries just by working here.
8. How long it's kept
- While your account is open, everything you've logged stays there. That's the point of the app.
- When you delete your account, everything goes: profile, activities, entries, notes, photos, relationships, comments, reactions and notification subscriptions. No grace period.
- What you left in shared places —a comment on someone else's entry, a photo in an event album— is deleted too when you delete your account.
- Error reports are kept for at most 90 days and then deleted.
- Technical logs, IP address included, are kept for at most 30 days and then rotate out on their own.
- Our providers' backups may retain data for a few extra days through technical rotation, until the cycle overwrites them.
9. How to delete your account
There's a button under Profile → Delete account that does it on the spot, without going through us and with no grace period. If you've lost access, write to hola@getdailyme.com from the account's email address and we'll do it for you.
The full detail —what disappears, what survives a few days in backups, and what to do if you only want to delete part of it— is on a separate page: how to delete your account and data.
10. Your rights
You can exercise the rights the GDPR grants you at any time:
- Access: knowing what data we hold about you.
- Rectification: correcting anything that's wrong, which you can also do yourself from Profile.
- Erasure: there's a button in Profile that carries it out on the spot. You can also request it by email.
- Portability: receiving your data in a machine-readable format. JSON export from the app is on the way; until then, ask us for it by email.
- Restriction and objection to processing based on legitimate interest.
- Withdrawing consent for notifications, for health-related activities or for the transfer in section 7, without affecting prior processing.
Write to hola@getdailyme.com. We reply within one month at most, and we don't charge for it.
If you think we haven't handled it properly, you can lodge a complaint with the supervisory authority of your country of residence. In the European Economic Area, the list is on the European Data Protection Board's website; in the United Kingdom, with the ICO. If you live in Honduras, you can use the habeas data route recognized by the Constitution.
11. Security
- All traffic is encrypted with TLS, and data is encrypted at rest.
- Isolation between accounts is enforced in the database itself, and automated tests verify on every change that one account cannot read what isn't its own.
- Passwords are stored with key-derivation functions designed for the job.
- Team access to production systems requires two-factor authentication and is limited to whoever needs it for their work.
- If a breach ever put your rights at risk, we would notify you and report it to the supervisory authority within 72 hours.
No system is infallible. What we can promise is that our design decisions point toward storing the minimum and showing the minimum.
12. Minimum age
You need to be 16 to have an account. That's the ceiling set by Article 8 GDPR, and we apply it the same way everywhere instead of going country by country: that way no account depends on an age we couldn't verify.
We don't ask for documents to check it —doing so would mean collecting considerably more than we want to— but if we detect, or are told about, an account below that age, we delete it. If you're a parent or guardian and believe there is one, write to hola@getdailyme.com and we'll close it.
14. Changes to this policy
If anything relevant changes, we'll update this page and the date at the top. When a change substantially affects how we process your data, we'll let you know in the app or by email before it takes effect.