Privacy Policy
Last updated: October 10, 2026
Who we are
Dayli (a calendar journal for iOS and Android) is developed and maintained by Apprelium — individual developer Anna Stepanytska, Georgia. We are the controller of your data under the GDPR.
Contact for privacy questions and bug reports: support@apprelium.app (in the app: Menu → “Found a bug?”).
In short
- Without Dayli Plus, your entries, stickers, cycle data and photos are stored only on your phone. Our server holds only your account and your encryption key, itself encrypted with your password.
- With Dayli Plus, your data syncs across your devices. Cycle data, your photos and images are end-to-end encrypted on your phone: the server stores them but cannot read them — neither can we or our hosting provider.
- The free version shows Google AdMob ads. Personalized ads only with your consent. Nothing from the app is ever shared with advertisers: no entries, no stickers, no cycle data. With Dayli Plus there are no ads and the ad module is never started.
- No analytics. Health data is never used for ads or for anything other than running the app, and is never shared.
- You can delete your account and all data in the app: Menu → Account → Delete account. If the account was created with Apple, we also revoke Sign in with Apple when you delete it. Deleting your account does not cancel a Dayli Plus subscription — cancel it in the App Store or Google Play ("Manage subscription" in Account).
What data we process
Account
- Email address and password (the password is stored only as a hash by our sign-in provider).
- If you sign in with Apple or Google — the identifier and email that service provides (Apple lets you hide your email). We don't ask for your name. If you later create a password, it becomes your account password (stored only as a hash) and the password for your encryption key.
- An internal account ID.
- Your chosen app language — so that emails with codes arrive in your language.
Why: sign-in, confirmation code emails, linking purchases to your account, sync (with Dayli Plus). Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
Journal entries, stickers and settings
Dates, titles and texts of entries, which photo is set for a day, entry styling, favorites, custom month colors and fonts, your sticker catalog (shape, colors, icon, label, name), stickers on days, sticker goals, and time and comments for day stickers.
- Without Dayli Plus this data stays on your device only and is never sent to the server. You can move it to another device with a backup. If you sign in to a different account on the same phone, the previous account's data stays on the phone, set aside, and comes back when you sign in to that account again.
- With Dayli Plus it syncs through our server so your entries appear on all your devices. Legal basis: performance of a contract. This data is protected in transit (TLS) and at rest by our provider, but is not end-to-end encrypted.
Health data (cycle) — only with your consent
Period start and end marks, and the start date, cycle length and period length you enter.
- Off by default. Turned on only after a separate consent screen.
- Legal basis: your explicit consent (Art. 9(2)(a) GDPR). You can withdraw it at any time: Menu → Cycle → turn off tracking (with or without deleting the data).
- The data is encrypted on your device (XChaCha20-Poly1305). Without Dayli Plus it stays on the device. With Dayli Plus only encrypted text is sent to the server: marks are stored as encrypted yearly blocks, so the server sees neither the dates nor even the year. Without the key, nobody can read this data — including us.
- Health data is never used for ads or analytics and never shared with the ad network.
- Cycle phase predictions are approximate. The app is not a medical device and is not suitable for contraception.
Your photos, month backgrounds and sticker images
Photos and images are compressed (WebP) and stored on your device. With Dayli Plus they sync across your devices: they are encrypted on your phone with the same key as your cycle data and only then stored in private storage. Neither the server nor we can view them.
Encryption key and passcode
The key to your encrypted data is stored on the server only encrypted with your account password (scrypt; if you sign in with Apple or Google — the password you created in the app) — for every account, so that after you get Dayli Plus your encrypted data opens on your other devices. It cannot be opened without your password. If your password is reset and you have no other device or backup, encrypted data cannot be recovered.
The app passcode is stored on your phone as a hash; with Dayli Plus it syncs to your other devices in encrypted form. Face ID / fingerprint is handled by your phone's system — the app never receives it.
Dayli Plus subscription
Payments are processed by Apple (App Store) or Google (Google Play) — we never receive your card details. Purchases are verified with RevenueCat: it receives your internal account ID and purchase details from the store (product, date, term, cancellation or refund) and tells our server whether Dayli Plus is active. We store only whether Dayli Plus is active, the product and the expiry date. Legal basis: performance of a contract.
Ads (free version only)
The free version shows Google AdMob ads: a banner at the bottom of the calendar and journal, and rewarded ads that you start yourself (a month background image, a PDF export).
- Google AdMob receives device data: the advertising identifier (IDFA on iPhone — only if you allow tracking; advertising ID on Android), IP address, device type and OS version, language, approximate location based on IP, and ad impressions and clicks.
- Personalized ads only with your consent: in the EU, UK and Switzerland Google's consent form asks you; on iPhone the system tracking prompt asks you. Without consent you see non-personalized ads. You can change your choice in your phone settings (on iPhone: Settings → Privacy → Tracking).
- Nothing from the app is shared with ads: no entries, stickers, photos or cycle data, and no keywords or topics from your entries.
- With Dayli Plus the ad module is never started and receives no data.
- Legal basis: your consent (for personalization and tracking) and our legitimate interest in showing ads that keep the free version free (Art. 6(1)(a), 6(1)(f) GDPR). How Google uses data: policies.google.com/technologies/partner-sites.
What we don't do
- No analytics; we don't sell your data or share it for marketing.
- We never share anything from your entries, stickers, photos or health data with advertisers.
- We don't read your cycle data or photos — we technically can't.
Who we share data with (processors)
- Supabase — database, sign-in and storage hosting; servers in the EU (Frankfurt, Germany).
- Resend — sends sign-up and password reset code emails; receives only your email address and the email with a one-time code; servers in Japan (Tokyo).
- RevenueCat (USA) — Dayli Plus purchase verification.
- Google AdMob (Google) — ads in the free version; an independent controller of ad data.
- Apple, Google — sign-in (if you choose it; when you delete an account created with Apple, we ask Apple to revoke the sign-in), payments, app stores.
Where a processor is outside the EU, transfers rely on the EU Standard Contractual Clauses or an adequacy decision.
How long we keep data
- Your account and server data — for as long as you have an account. After you delete your account, data is deleted from the server immediately and from provider backups within 7 days.
- After a subscription ends, data on the server is kept (so sync can continue if you subscribe again) until you delete your account.
- Purchase records at RevenueCat, Apple and Google — under their rules and legal requirements.
Your rights
You can access, correct and delete your data, restrict or port its processing, object to it, and withdraw consent (to health data processing and to personalized ads). Much of this is available in the app: account deletion, turning off and deleting cycle data, PDF export, backups. For anything else, write to support@apprelium.app — we reply within 30 days. You can also complain to your local data protection authority.
Backups and PDFs
A backup archive is encrypted with a password you set when creating it: it can't be opened without the password, and a forgotten password can't be recovered. PDFs you create are not encrypted. Both files are saved wherever you choose (for example, Files or Google Drive).
Children
The app is not intended for children under 16.
Changes to this policy
We will tell you about significant changes in the app. The current version is always on this page.