Privacy Policy
Last updated: October 4, 2026
DaySmith ("we", "us") is a daily planning service that builds a schedule from tools you choose to connect. This policy explains what we access, why, and what we do with it. The short version: we read only what's needed to build your plan, we don't sell or share your data, and you can disconnect any tool or delete your account at any time.
What we collect
- Account information. Your email address, a hashed password, your time zone and your working hours.
- Calendar data. When you connect Microsoft 365 or Google, we read the titles, start and end times, and free/busy status of events in your primary calendar for the current day, so meetings can be placed as fixed blocks.
- Email follow-ups. When you connect Microsoft 365 or Google, we read the subject lines of messages you have flagged (Outlook) or starred (Gmail), so they can appear as short reply blocks. We do not read message bodies, attachments, or any unflagged mail. When you mark a follow-up done in DaySmith, we clear the flag or star.
- Task data. When you connect Jira, Asana, monday.com or ClickUp, we read open items assigned to you: title, due date, priority and time estimate. When you mark an item done in DaySmith, we update it in that tool.
- Time tracking. When you connect Toggl Track, Clockify or Harvest, we read your currently running timer and start or stop timers when you ask us to.
- Device token. If you use the iPhone app and allow notifications, we store a push token so we can tell you when your plan changes.
How we use it
Only to build and update your daily plan, to carry out the actions you take (start a timer, mark something done), and to send you plan notifications you've opted into. We do not use your data for advertising, we do not sell it, and we do not share it with third parties other than the tool providers you connected, in order to read from and write to your own accounts there.
Google user data
DaySmith's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google Calendar data only to display your events in your plan, and Gmail data only to list your starred messages and remove the star when you mark one done. We do not transfer this data to others, use it for advertising, or allow humans to read it except with your consent, for security purposes, or to comply with law.
How we store it
Access tokens for connected tools are encrypted at rest with AES-256-GCM on our server. Your password is stored as a bcrypt hash. Your plan for the current day is stored so it loads instantly; past plans are not retained. The iPhone app keeps only a session token on your device, in the iOS Keychain.
Your choices
- Disconnect a tool at any time from Settings. We delete its tokens immediately and stop reading from it.
- Revoke access from the provider's side as well: your Google Account permissions page, Microsoft account privacy settings, or the equivalent in each tool.
- Delete your account by emailing privacy@getdaysmith.com. We remove your account, tokens, plans and device tokens within 30 days.
Retention
We keep your account data while your account is active. Connected-tool tokens are deleted when you disconnect the tool. Daily plans are overwritten each day.
Changes
If this policy changes in a way that matters, we'll update the date above and, for significant changes, notify you by email.
Contact
Questions about privacy: privacy@getdaysmith.com.