Skip to main content
๐Ÿ”

Trust & Security

Dayze holds relationships, finances, and memories. Here is how we treat that responsibility โ€” today and as we scale.

Principles

๐Ÿšซ

No ads ยท no data sales

We monetize subscriptions, premium handles, and optional developer APIs โ€” not by selling your attention or your life graph.

๐Ÿง 

No third-party model training

AI providers process request context to run Dayze Agent. We do not allow your Dayze data to train their models.

๐Ÿ”’

AI writes are private, attributed and mostly undoable

ChatGPT, Claude, Cursor, and Gemini connect via MCP to read your life graph with sources. A connection you grant write access can also add and edit records, kept private by default. Every change is attributed to the app that made it: a record shows who added and changed it, and most changes can be undone for 30 days, unless the record changed since. Removals are previewed or archived. They never buy or send for you.

๐Ÿ—๏ธ

Each AI gets only the access you give it

A new connection from Claude, Cursor, Gemini or another AI app can read and add to your records. Removing records, reading your Gmail and sensitive details (contact details, booking references, financial details) stay off until you allow them for that app, when you connect or later in Settings โ†’ Agent access, where you can also take access away. API keys hold only the permissions you pick when you create them. ChatGPT keeps the permissions of Dayze's reviewed ChatGPT connectors.

๐Ÿ“ฆ

Portable

Pro and Family can export JSON/CSV from Settings. Anyone can delete their account and data.

๐ŸŽ›๏ธ

You control connectors

Calendars, health, messaging, and location are opt-in. Disconnect anytime.

Subprocessors (high level)

Dayze uses vetted infrastructure and AI providers to operate the product. Categories (not an exhaustive legal schedule โ€” see the Privacy Policy for the full framing):

  • Database, auth, storage โ€” Supabase (AWS-hosted)
  • Hosting / CDN โ€” Netlify (and related edge delivery)
  • Payments (web) โ€” Stripe (card data stays with Stripe)
  • Payments (apps) โ€” Apple App Store and Google Play in-app purchases when you subscribe on a device
  • AI model APIs โ€” one or more third-party model providers for Dayze Agent chat/voice (providers may change; we do not brand a single vendor in product UI)
  • Product analytics โ€” Google Analytics and PostHog, for usage counts and app errors only (no message, email, or note content)
  • Email / messaging delivery โ€” transactional providers for auth links and notifications
  • Integrations you connect โ€” Google, Apple, Spotify, etc., under the scopes you authorize
Note: Security and privacy questions: privacy@dayze.com. Product support: support@dayze.com.

Retention

  • Active account โ€” We keep your life-graph data while the account exists (see the Privacy Policy).
  • Account deletion โ€” After you delete your account, we target removing personal data from production within 30 days, subject to legal retention, billing and tax records, dispute and security needs, and infrastructure backups (see Privacy Policy ยง9 (Retention)). Backup retention periods and tool-call log retention are not published as fixed SLAs.

Security controls today

  • HTTPS/TLS in transit; encryption at rest via infrastructure providers
  • Authenticated APIs; row-level access patterns for user data
  • Secrets kept in environment config โ€” not in client bundles
  • Account deletion cascade for profile + life data
Note: No independent security certification (such as SOC 2) has been completed yet. SOC 2 Type I remains a roadmap item only โ€” we do not display certification badges.

Maturity roadmap

Before scaling paid family/Teams and enterprise-style trust asks, we plan:

  1. Keep legal + Trust pages product-accurate (current focus)
  2. Independent penetration test of critical auth and export paths
  3. SOC 2 Type I (or equivalent) when recurring revenue and customer demand justify it
  4. Formal incident-response runbook for internal operations
Tip: Legal policies: Privacy Policy ยท Terms of Service ยท AI Governance ยท Privacy & Data