Privacy Notice
Version [0.1] — effective [date]. Previous versions: [URL]. This is our privacy policy under the Information Technology Act's SPDI Rules 2011, and our notice under the Digital Personal Data Protection Act 2023 and its Rules 2025, whose duties apply from 13 May 2027.
1. In short
- DayScribe holds three kinds of personal data about you: your account (an email address and a random id), your content (what you log), and traces of running the service (short-lived sign-in codes, hashed session tokens, rate-limit counters, server logs, backups).
- We use them for one purpose: to run DayScribe for you. No telemetry, no analytics, no advertising, no profiling, no selling, no training of AI models on your content, on any plan.
- Your content can reveal sensitive things about you — your health, your beliefs, your relationships. We ask for your consent once, after your first sign-in and before you start, and you withdraw it by deleting your account.
- Your data is stored in India, and your content never leaves our servers unless you turn on the Telegram bot's AI reading. Then only the text of a message our parser could not read, plus your category names, goes to the named provider. The companies that run parts of the service for us see only what their job needs (§6).
- You can export everything and delete your account yourself, at any time, from the app.
- Deleted data leaves our live systems at once and our encrypted backups within 12 months.
2. Who is responsible for your data
The Data Fiduciary — the party that decides why and how your personal data is processed — is [legal name of the operator], [postal address], India.
- For questions about how we process your personal data: [name or role], [privacy@dayscribe.in], [phone].
- For grievances: the Grievance Officer named in the Terms, §1.
We have not been notified as a Significant Data Fiduciary, so we have not appointed a Data Protection Officer. The contact above answers for us.
3. What we collect, why, and on what basis
| What | Why | Basis (DPDP Act) | Kept |
|---|---|---|---|
| Your email address when you ask for a sign-in code | To email you the code | Legitimate use: you gave it to us for this (s. 7(a)) | The code record is deleted 30 days after it expires or is used |
| Your IP address, checked against a list of Indian address ranges, when a sign-in would create a new account | To offer DayScribe only in India (Terms §2) | Legitimate use (s. 7(a)) | The check keeps nothing; the request is in the logs below |
| Your account: the email address, a random account id, the date the account was created, and the date and version of the notice you consented to | To keep your account, to prove your consent, and to email you the service notices the Terms require (renewals, changes, security) | Consent (s. 6) | Until you delete the account |
| Session tokens, stored as a one-way hash with their first eight characters, and when each was created and last used | To keep a device signed in until it signs out | Consent | Up to 90 days, or until you sign out; the record is deleted 30 days after that |
| Your content: time entries, tallies, notes, tasks, journal pages, habits and ticks, calendar items, categories and labels, and their timestamps, including records you deleted | To store, sync, back up and show it to you: the service itself | Consent | Until you delete the account (deleted records are kept as tombstones until then) |
| Sync metadata: a random id per device, revision numbers, sync timestamps | To sync correctly between your devices and resolve conflicts | Consent | Until you delete the account |
| Plan and payment status: which plan, active or lapsed, a payment reference, and the invoice | To give you the plan you paid for, and to keep the tax records the law requires | Consent; and required by GST law for the invoice | Plan status until you delete the account; invoices for the period GST law sets |
| The Telegram link (your Telegram user id and chat id) and the messages and voice-note transcripts you send the bot, with the ids of the records each created | To run the bot you connected, and to show you what it did so you can undo it | Consent, given when you connect the bot | Until you delete the account (Part E proposes deleting them on unlink) |
| Text sent to an AI provider when you have turned on the AI reading: the one message and your category names | To interpret a message our parser cannot | Consent, given when you turn it on | Not stored by us beyond the message row above; the provider's own retention is in §6 |
| Application log: for every request to the service, its time, route, status and duration, the random id of the account making it, and its IP address; for sign-in events, a keyed digest of the email address, never the address; error details | Security, abuse prevention, debugging, and the security logs the law requires | Consent; and required by the CERT-In directions and the DPDP Rules' security safeguards | [One year] (§8) |
| Proxy access log: for every request, its time, IP address, method, path without its query string, status, and your browser's identification string (user agent) | As above | As above | [One year] (§8) |
| Rate-limit counters per IP address and per email address | To stop abuse of sign-in and sync | Consent | Minutes to an hour, in memory only |
| Backups of all of the above, encrypted | To recover from loss or damage | Consent | Rolling: 14 daily, 8 weekly, 12 monthly |
| Support email you send us | To help you | Consent, by writing to us | [12 months] after the thread closes |
We do not collect your phone number, location, contacts or any device identifier beyond the random sync id, and we keep no name. The one use we make of where you are is the check in the second row, at the moment an account would be created. There is no advertising identifier and no analytics. Beyond the two logs above, we record nothing about how you use the app.
Automated decisions. We make no decision about you by automated means that has a legal or similarly significant effect. The AI reading turns a message into records you can see and undo; it decides nothing about you. The India check decides only whether a new account can be created.
4. Sensitive information, and why we ask explicitly
DayScribe comes with no categories: you create your own. Whatever you call them, a log of your day can reveal your health, your beliefs and your intimate life. Indian law treats information about health, medical history and sexual orientation as sensitive personal data. That is why we ask for your consent explicitly, with an unticked box, at the consent step in Part C.2, rather than folding it into the Terms.
- The box is not pre-ticked, and the app does not open until you tick it.
- We use sensitive content for exactly what we use every record for: storing, syncing, backing up and showing it to you. Never for anything else.
- You withdraw consent by deleting your account. Withdrawing does not affect what was lawfully done before it, and it ends our processing except what the law makes us keep (§8).
- If you do not consent, you cannot use DayScribe, because a log you write freely cannot keep sensitive entries out.
5. What we store on your device, and why there are no cookies
DayScribe keeps on your device only what the service needs to work:
- your records, in the browser's database, so the app works offline;
- your session token, your preferences (theme, clock format) and a copy of your consent, in local storage;
- the app's own files, in the service-worker cache, so it opens without a network.
All three sit under names beginning dailyscribe, and all exist solely to provide the service you asked for. DayScribe sets no cookies. Signing out removes the token; clearing site data in your browser removes everything, and your account on the server is unaffected.
6. Who else sees your data
We share personal data only with the companies that run parts of the service for us (Data Processors, bound by contract to act only on our instructions, as the DPDP Act s. 8(2) requires), with the parties below that act on their own account, and with authorities when the law compels us. We never sell personal data.
| Who | What they process | Where | Why |
|---|---|---|---|
| [Hosting provider — Hostinger, legal name] | Everything on the server | India, [data centre] | Runs the server and database |
| [Backup storage provider] | Encrypted backup snapshots (they cannot read them) | [India / country] | Off-site backups |
| [Email provider] | Your email address and the sign-in code or notice sent to it | [India / country] | Sends email on our behalf |
| [Razorpay / Cashfree] — only if you buy a plan, as a separate Data Fiduciary under its own notice and the RBI's rules | Your payment details and the payment | India | Takes the payment |
| Telegram (Telegram FZ-LLC) — only if you connect the bot, under its own terms | The messages you send the bot, your Telegram account | [Telegram's own locations] | It is the messenger you chose |
| [AI text provider: Sarvam AI (India) or OpenRouter, Inc. (United States)] — only if you turn on the AI reading | The text of a message our parser cannot read, and your category names | India / United States, as configured | Interprets the message |
| [Transcription provider: Sarvam AI (India), Groq, Inc. or OpenAI (United States)] — only if you send the bot voice notes with the AI reading on | The audio, transcribed and then discarded | India / United States, as configured | Transcribes the voice note |
A current list, with each provider's location and the date it was added, is kept at [URL] and we update it before a change takes effect.
7. Where your data is stored
Your data is stored on servers in India, at [the hosting provider's data centre in (city)], and backed up to [India / country]. We operate DayScribe from India.
Personal data leaves India only in these cases, and only for the purpose stated in §6: [the AI reading, when you have turned it on and the configured provider is outside India]; [the email provider, if outside India]; [backup storage, if outside India]. The DPDP Act allows these transfers except to a country the Central Government restricts (s. 16), and we do not send data to one.
8. How long we keep things
Section 3 gives the period for each kind of data. Four things sit behind those periods:
- Deletion is immediate in our live systems. Deleting your account erases the account, your records, your sessions and your bot data at once.
- Backups expire on a schedule; they are not edited. Our backups are encrypted snapshots kept for 14 days (daily), 8 weeks (weekly) and 12 months (monthly). A copy of deleted data can therefore exist in a backup for up to 12 months, unreadable without our keys, and is used for nothing but restoring the service after a loss. If we ever restore from a backup, we re-apply deletions made since it was taken.
- Logs are kept for the period the law requires, and no longer. Both logs in §3 are kept for [one year], in India, and then deleted. They hold your IP address and account id, never your content or your email address.
- Records the law requires, such as invoices under GST law, are kept for the period that law sets, even after you delete your account, and used for nothing else.
- From 13 May 2027, the DPDP Rules require a one-year copy. For one year from each time your data is processed, we must keep that personal data, its traffic data and the related logs, even after you delete your account, for the purposes the Rules list, such as a lawful request from the Government. We keep this copy [sealed and apart from the service], use it for nothing else, and erase it when its year ends.
9. How we protect it
- Every connection is encrypted in transit (TLS). Sign-in uses one-time codes, and codes and session tokens are stored as one-way hashes, so a copy of our database does not contain a usable one.
- Each account's rows are isolated by the database itself (row-level security), not only by application code: a bug in the application cannot read another account's data.
- Sign-in and sync are rate-limited and repeated failed sign-ins lock the address for a time.
- Secrets never reach logs; email addresses are replaced in logs by a keyed digest.
- Backups are encrypted before they leave the server.
- We can read your content on the server, because syncing it requires that. We do not encrypt it end-to-end today. We access it only as the Terms §6 describe. If that changes we will say so here in exact words, not before.
- If a breach affects your personal data, we tell you without delay: what happened and when, what it may mean for you, what we are doing about it, and what you can do. We report it to the Data Protection Board of India, and we report a cyber-security incident to CERT-In, within the times the law sets.
10. Your rights, and how to use them
Most of these you can use yourself, in the app, without asking us:
| Right (DPDP Act) | In the app | Or ask us |
|---|---|---|
| Access: a summary of what we hold and how we process it, and who we share it with (s. 11) | Backup & sync → Export backup holds every record; Settings shows your account; §6 names every recipient | [privacy@dayscribe.in] for anything the export does not show: logs, plan status, the consent record |
| Correction, completion and updating (s. 12) | Edit any record | Write to us to change the email address on your account |
| Erasure (s. 12) | Delete any record; Backup & sync → Delete account erases everything | — |
| Withdraw consent, as easily as you gave it (s. 6(4)) | Backup & sync → Delete account; turn off the AI reading; unlink Telegram | — |
| Nominate someone to use these rights if you die or cannot act (s. 14) | — | Write to [privacy@dayscribe.in] with the person's name and email |
| Grievance redressal (s. 13) | — | The Grievance Officer (Terms §1), who acknowledges within 24 hours and resolves within 7 days |
| Complain to the Data Protection Board of India | — | After the Grievance Officer has answered you, or if they have not answered in time |
Take it with you, too: export is always available (Terms §6), although Indian law does not require it. To use a right, write from the email address on your account, or sign in and ask. We may ask you to confirm it is you. We answer every request within [7 days], we do not charge for one, and we tell you why if we refuse one.
11. Children
DayScribe is for adults. We do not knowingly hold an account for anyone under 18, and we delete one when we learn of it; write to [privacy@dayscribe.in]. We do not track, profile or advertise to anyone, of any age.
12. Languages
This notice is available in English and [Hindi]. You can ask for it in any other language listed in the Eighth Schedule to the Constitution of India by writing to [privacy@dayscribe.in], and we will send it to you.
13. Changes to this notice
We change this notice when the facts change: a new provider, a new feature, a new retention period. We email you and show a notice in the app at least 30 days before a change that affects you. We never turn on a new use of your data without asking for your consent to it first. Previous versions stay at [URL].
14. Contact
[privacy@dayscribe.in] · [phone] · [postal address] · Grievance Officer: [name], [email].