Trust & Security
Dayze holds relationships, finances, and memories. Here is how we treat that responsibility — today and as we scale.
Principles
No ads · no data sales
We monetize subscriptions, premium handles, and optional developer APIs — not by selling your attention or your life graph.
No third-party model training
AI providers process request context to run Dayze Agent. We do not allow your Dayze data to train their models.
Portable
Pro and Family can export JSON/CSV from Settings. Anyone can delete their account and data.
You control connectors
Calendars, health, messaging, and location are opt-in. Disconnect anytime.
Subprocessors (high level)
Dayze uses vetted infrastructure and AI providers to operate the product. Categories (not an exhaustive legal schedule — see the Privacy Policy for the full framing):
- Database, auth, storage — Supabase (AWS-hosted)
- Hosting / CDN — Netlify (and related edge delivery)
- Payments — Stripe (card data stays with Stripe)
- AI model APIs — one or more third-party model providers for Dayze Agent chat/voice (providers may change; we do not brand a single vendor in product UI)
- Email / messaging delivery — transactional providers for auth links and notifications
- Integrations you connect — Google, Apple, Spotify, etc., under the scopes you authorize
Security controls today
- HTTPS/TLS in transit; encryption at rest via infrastructure providers
- Authenticated APIs; row-level access patterns for user data
- Secrets kept in environment config — not in client bundles
- Account deletion cascade for profile + life data
Maturity roadmap
Before scaling paid family/Teams and enterprise-style trust asks, we plan:
- Keep legal + Trust pages product-accurate (current focus)
- Independent penetration test of critical auth and export paths
- SOC 2 Type I (or equivalent) when recurring revenue and customer demand justify it
- Formal incident-response runbook shared in the investor data room