Last updated: June 16, 2026 · Effective date: June 16, 2026
Operator: Silica Sites · App: DayLeaf (com.silicasites.dayleaf)
This Privacy Policy explains how DayLeaf handles information when you use our journaling application on Android, iOS, Windows, and other supported platforms. DayLeaf is local-first: your journal is stored on your device and works offline. When you are signed in, the app also syncs selected journal data to your account on our servers so you can back up and access entries across devices. We do not sell your data, run advertising SDKs, or use third-party analytics trackers.
| Topic | Practice |
|---|---|
| Account required? | Yes — email sign-in to use the app |
| Journal storage | On your device (local database) and, when signed in, on our servers (cloud sync) |
| Cloud journal backup? | Yes — automatic sync when signed in; manual Sync now in Settings → Account; optional ZIP export in Settings |
| Analytics trackers? | None |
| Ads? | None |
| Payments | Google Play (Android Premium subscriptions) |
| Server data | Account profile, synced journal data, app settings, and subscription verification (via Supabase) |
We collect only what is needed to operate the app. Categories below describe data on your device, data stored on our servers, and data you choose to share.
When you use DayLeaf, the following may be stored locally in the app's database or file storage:
When you are signed in and use the app (including when sync runs automatically or you tap Sync now), we store the following in your account on Supabase (our hosting provider), linked to your user ID:
Cloud sync requires an internet connection. If you are signed out, new changes remain on your device until you sign in again.
We do not upload voice note audio files, PIN codes, or in-app analytics session logs to our servers.
When you create an account or sign in, we collect and store:
This information is used to authenticate you, display your account in Settings, sync your journal, and verify Premium subscriptions.
The app may request device permissions only when needed for features you use:
| Permission / access | Purpose |
|---|---|
| Microphone | Voice notes and optional speech-to-text dictation |
| Notifications | Local reminders and inactivity nudges you enable |
| Exact alarms (Android) | Deliver scheduled reminders at times you set |
| Internet / network | Account sign-in, cloud journal sync, Google Play billing, subscription verification (HTTPS to Supabase), optional font delivery |
| Camera / photos | Attach images to entries (via system picker) |
| Storage (older Android) | Access attachments where required by OS version |
Speech-to-text: If you use dictation, audio is processed by your device's platform speech recognition service (e.g., Google on Android, Apple on iOS). That processing is governed by the platform provider's policies, not stored on our servers.
If you subscribe to DayLeaf Premium on Android: Google Play processes payment and provides purchase tokens. We do not receive your payment card number. Our verification backend (hosted on Supabase) stores: obfuscated Play account identifier, purchase token, product ID, subscription status, expiry time, and last-updated timestamp — only to verify Premium access and process renewal/cancellation events from Google Play.
If you email info@silicasites.com, we receive the content of your message and your email address so we can respond.
The app may download font files from Google Fonts servers when certain typefaces are first displayed. This can involve your IP address and basic request metadata handled by Google. See Google's Privacy Policy.
We use information solely to:
We do not use your journal for advertising, profiling, or automated decision-making that produces legal or similarly significant effects.
Where GDPR or similar laws apply, we rely on:
You may withdraw permission-based processing via device settings; some features may not work without optional permissions.
We do not sell personal information. We share data only as follows:
| Recipient | What is shared | Why |
|---|---|---|
| Supabase (our processor) | Account email, display name, user ID, auth tokens; synced journals, entries, and settings; subscription verification records | Authentication, cloud sync, profiles, Premium entitlement |
| Google Play | Purchase flow, tokens | Subscription billing |
| Platform speech providers | Audio during dictation (if you use it) | Speech-to-text |
| Font requests (if applicable) | Typography delivery | |
| Law enforcement / regulators | As required | Legal compliance |
We require service providers to handle data only for authorized purposes. Your journal and account data are not exposed to other DayLeaf users.
Account, subscription, and cloud-synced journal data may be processed in countries where Supabase or its infrastructure operates (including the United States). Where required, we rely on appropriate safeguards such as standard contractual clauses offered by our providers.
| Data type | Retention |
|---|---|
| Journal content (device) | On your device until you delete entries, export, or uninstall |
| Journal content (cloud) | While your account is active and entries are not deleted; removed when you delete entries (synced deletion) or delete your account |
| Account (email, profile) | Until you delete your account or we no longer need it for the Service |
| Synced app settings | Until updated, deleted with your account, or removed per your request |
| PIN hash | On your device until you disable PIN lock or uninstall — never stored on our servers |
| Subscription records | While needed to verify Premium and comply with tax/accounting obligations; updated on Play renewal/cancel events; removed when you delete your account (Google Play billing may continue until you cancel there) |
| Support emails | As long as needed to resolve your request, then deleted or archived per our records policy |
We use reasonable technical measures (HTTPS for server calls, hashed PIN storage locally, row-level security so each user can access only their own cloud data, no direct public database access to subscription tables). No method is 100% secure. You are responsible for device security (screen lock, OS updates, and who can access your device) and for keeping your account password confidential.
You may have rights to access, rectify, erase, restrict, object, and data portability regarding personal data we control (including cloud-synced journal content). You may lodge a complaint with your local supervisory authority. Contact us first so we can help.
We do not sell or share personal information for cross-context behavioral advertising. California residents may request disclosure or deletion of personal information we collect (account data, cloud-synced journal content, subscription verification, and support emails). We will not discriminate against you for exercising these rights.
Where state privacy laws grant similar rights, contact info@silicasites.com with your request and jurisdiction.
We aim to respond within 30 days.
DayLeaf is not directed to children under 13 (or the age of digital consent in your region). We do not knowingly collect personal information from children. If you believe a child provided us information, contact info@silicasites.com and we will delete it.
We may update this policy to reflect app or legal changes. We will update the “Last updated” date and, for material changes, provide notice in-app when practicable. Continued use after the effective date constitutes acceptance where permitted by law.
Silica Sites
Email: info@silicasites.com
For privacy requests, include “Privacy Request” in the subject line and your platform (e.g., Android) and jurisdiction if relevant.
© 2026 Silica Sites. All rights reserved.