Dayli

Privacy Policy

Last updated: October 10, 2026

Who we are

Dayli (a calendar journal for iOS and Android) is developed and maintained by Apprelium — individual developer Anna Stepanytska, Georgia. We are the controller of your data under the GDPR.

Contact for privacy questions and bug reports: support@apprelium.app (in the app: Menu → “Found a bug?”).

In short

What data we process

Account

Why: sign-in, confirmation code emails, linking purchases to your account, sync (with Dayli Plus). Legal basis: performance of a contract (Art. 6(1)(b) GDPR).

Journal entries, stickers and settings

Dates, titles and texts of entries, which photo is set for a day, entry styling, favorites, custom month colors and fonts, your sticker catalog (shape, colors, icon, label, name), stickers on days, sticker goals, and time and comments for day stickers.

Health data (cycle) — only with your consent

Period start and end marks, and the start date, cycle length and period length you enter.

Your photos, month backgrounds and sticker images

Photos and images are compressed (WebP) and stored on your device. With Dayli Plus they sync across your devices: they are encrypted on your phone with the same key as your cycle data and only then stored in private storage. Neither the server nor we can view them.

Encryption key and passcode

The key to your encrypted data is stored on the server only encrypted with your account password (scrypt; if you sign in with Apple or Google — the password you created in the app) — for every account, so that after you get Dayli Plus your encrypted data opens on your other devices. It cannot be opened without your password. If your password is reset and you have no other device or backup, encrypted data cannot be recovered.

The app passcode is stored on your phone as a hash; with Dayli Plus it syncs to your other devices in encrypted form. Face ID / fingerprint is handled by your phone's system — the app never receives it.

Dayli Plus subscription

Payments are processed by Apple (App Store) or Google (Google Play) — we never receive your card details. Purchases are verified with RevenueCat: it receives your internal account ID and purchase details from the store (product, date, term, cancellation or refund) and tells our server whether Dayli Plus is active. We store only whether Dayli Plus is active, the product and the expiry date. Legal basis: performance of a contract.

Ads (free version only)

The free version shows Google AdMob ads: a banner at the bottom of the calendar and journal, and rewarded ads that you start yourself (a month background image, a PDF export).

What we don't do

Who we share data with (processors)

Where a processor is outside the EU, transfers rely on the EU Standard Contractual Clauses or an adequacy decision.

How long we keep data

Your rights

You can access, correct and delete your data, restrict or port its processing, object to it, and withdraw consent (to health data processing and to personalized ads). Much of this is available in the app: account deletion, turning off and deleting cycle data, PDF export, backups. For anything else, write to support@apprelium.app — we reply within 30 days. You can also complain to your local data protection authority.

Backups and PDFs

A backup archive is encrypted with a password you set when creating it: it can't be opened without the password, and a forgotten password can't be recovered. PDFs you create are not encrypted. Both files are saved wherever you choose (for example, Files or Google Drive).

Children

The app is not intended for children under 16.

Changes to this policy

We will tell you about significant changes in the app. The current version is always on this page.