DayLeaf · Legal

Privacy Policy

Last updated: June 16, 2026 · Effective date: June 16, 2026

Operator: Silica Sites · App: DayLeaf (com.silicasites.dayleaf)

This Privacy Policy explains how DayLeaf handles information when you use our journaling application on Android, iOS, Windows, and other supported platforms. DayLeaf is local-first: your journal is stored on your device and works offline. When you are signed in, the app also syncs selected journal data to your account on our servers so you can back up and access entries across devices. We do not sell your data, run advertising SDKs, or use third-party analytics trackers.

01

Summary

TopicPractice
Account required?Yes — email sign-in to use the app
Journal storageOn your device (local database) and, when signed in, on our servers (cloud sync)
Cloud journal backup?Yes — automatic sync when signed in; manual Sync now in Settings → Account; optional ZIP export in Settings
Analytics trackers?None
Ads?None
PaymentsGoogle Play (Android Premium subscriptions)
Server dataAccount profile, synced journal data, app settings, and subscription verification (via Supabase)
02

Information We Collect

We collect only what is needed to operate the app. Categories below describe data on your device, data stored on our servers, and data you choose to share.

2.1 Journal and app content (on your device)

When you use DayLeaf, the following may be stored locally in the app's database or file storage:

  • Journal entries (text, titles, timestamps, mood tags, metadata)
  • Drawings, stickers, and attachments you add to entries
  • Voice note audio files you record (stored as files on your device)
  • Photos you attach via your device camera or photo library
  • Multiple journals, custom prompts, and custom color palettes (Premium)
  • Writing session statistics (e.g., word counts, session duration, mood distributions) used for in-app insights — processed and stored locally only
  • Optional PIN lock data (hashed locally; never sent to our servers)

2.2 Cloud-synced journal data (stored on our servers)

When you are signed in and use the app (including when sync runs automatically or you tap Sync now), we store the following in your account on Supabase (our hosting provider), linked to your user ID:

  • Journals — names, descriptions, color themes, and metadata
  • Journal entries — text, titles, timestamps, mood, tags, word counts, pin status, and display colors
  • Drawings and stickers — embedded with your entries (e.g., as encoded image data or structured metadata)
  • Voice note metadata — titles, duration, position, and timestamps (the audio files themselves stay on your device and are not uploaded)
  • App settings synced with your account — e.g., theme, notification preferences, current journal, custom prompts, favorite stickers, and custom color palettes (Premium)

Cloud sync requires an internet connection. If you are signed out, new changes remain on your device until you sign in again.

We do not upload voice note audio files, PIN codes, or in-app analytics session logs to our servers.

2.3 DayLeaf account (stored on our servers)

When you create an account or sign in, we collect and store:

  • Email address (required for sign-in)
  • Password — handled by our authentication provider (Supabase Auth). We do not store your password in plain text
  • Display name (optional, if you provide one at registration)
  • Account identifier (a unique user ID assigned by our auth system)
  • Account timestamps (e.g., when your account was created)

This information is used to authenticate you, display your account in Settings, sync your journal, and verify Premium subscriptions.

2.4 App settings and security data (stored on your device)

  • Theme, notification preferences, palette choices, and similar settings (a copy of selected settings may also sync — see Section 2.2)
  • Optional PIN lock: if enabled, your PIN is not stored in plain text. A salted cryptographic hash is stored locally only to verify unlock attempts
  • Failed unlock attempt counters and temporary lockout timestamps (local)
  • A randomly generated, obfuscated identifier used to link your device to Google Play subscription verification — stored locally
  • Authentication session tokens (stored securely on your device by the app)

2.5 Permissions and sensors

The app may request device permissions only when needed for features you use:

Permission / accessPurpose
MicrophoneVoice notes and optional speech-to-text dictation
NotificationsLocal reminders and inactivity nudges you enable
Exact alarms (Android)Deliver scheduled reminders at times you set
Internet / networkAccount sign-in, cloud journal sync, Google Play billing, subscription verification (HTTPS to Supabase), optional font delivery
Camera / photosAttach images to entries (via system picker)
Storage (older Android)Access attachments where required by OS version

Speech-to-text: If you use dictation, audio is processed by your device's platform speech recognition service (e.g., Google on Android, Apple on iOS). That processing is governed by the platform provider's policies, not stored on our servers.

2.6 Premium subscriptions (Google Play + verification service)

If you subscribe to DayLeaf Premium on Android: Google Play processes payment and provides purchase tokens. We do not receive your payment card number. Our verification backend (hosted on Supabase) stores: obfuscated Play account identifier, purchase token, product ID, subscription status, expiry time, and last-updated timestamp — only to verify Premium access and process renewal/cancellation events from Google Play.

2.7 Information you send us

If you email info@silicasites.com, we receive the content of your message and your email address so we can respond.

2.8 What we do not collect

  • No third-party advertising or behavioral analytics SDKs
  • No sale of personal information
  • No use of journal content to train AI models
  • No upload of voice note audio files to our servers (metadata only)
  • No upload of your PIN or PIN hash to our servers

2.9 Optional network requests to Google

The app may download font files from Google Fonts servers when certain typefaces are first displayed. This can involve your IP address and basic request metadata handled by Google. See Google's Privacy Policy.

03

How We Use Information

We use information solely to:

  • Create and manage your DayLeaf account and authenticate sign-in
  • Sync, back up, and restore your journals and entries across devices when you are signed in
  • Provide journaling, editing, export, PIN lock, reminders, and in-app statistics
  • Verify and restore Google Play Premium subscriptions (HTTPS to Supabase)
  • Respond to support requests and process account- and data-deletion requests
  • Comply with law and protect our rights

We do not use your journal for advertising, profiling, or automated decision-making that produces legal or similarly significant effects.

04

Legal Bases (EEA, UK, and Switzerland)

Where GDPR or similar laws apply, we rely on:

  • Contract / steps at your request: Providing the app, your account, cloud sync, and Premium features you purchase
  • Legitimate interests: Securing accounts and subscriptions, preventing fraud, and improving reliability — balanced against your rights
  • Consent: Where required for optional permissions (e.g., microphone, notifications) you grant in system dialogs
  • Legal obligation: When we must retain or disclose data under applicable law

You may withdraw permission-based processing via device settings; some features may not work without optional permissions.

05

How We Share Information

We do not sell personal information. We share data only as follows:

RecipientWhat is sharedWhy
Supabase (our processor)Account email, display name, user ID, auth tokens; synced journals, entries, and settings; subscription verification recordsAuthentication, cloud sync, profiles, Premium entitlement
Google PlayPurchase flow, tokensSubscription billing
Platform speech providersAudio during dictation (if you use it)Speech-to-text
GoogleFont requests (if applicable)Typography delivery
Law enforcement / regulatorsAs requiredLegal compliance

We require service providers to handle data only for authorized purposes. Your journal and account data are not exposed to other DayLeaf users.

06

International Data Transfers

Account, subscription, and cloud-synced journal data may be processed in countries where Supabase or its infrastructure operates (including the United States). Where required, we rely on appropriate safeguards such as standard contractual clauses offered by our providers.

07

Data Retention

Data typeRetention
Journal content (device)On your device until you delete entries, export, or uninstall
Journal content (cloud)While your account is active and entries are not deleted; removed when you delete entries (synced deletion) or delete your account
Account (email, profile)Until you delete your account or we no longer need it for the Service
Synced app settingsUntil updated, deleted with your account, or removed per your request
PIN hashOn your device until you disable PIN lock or uninstall — never stored on our servers
Subscription recordsWhile needed to verify Premium and comply with tax/accounting obligations; updated on Play renewal/cancel events; removed when you delete your account (Google Play billing may continue until you cancel there)
Support emailsAs long as needed to resolve your request, then deleted or archived per our records policy
08

Security

We use reasonable technical measures (HTTPS for server calls, hashed PIN storage locally, row-level security so each user can access only their own cloud data, no direct public database access to subscription tables). No method is 100% secure. You are responsible for device security (screen lock, OS updates, and who can access your device) and for keeping your account password confidential.

09

Your Rights and Choices

Everyone

  • Access / export: Settings → Export journal data (ZIP with JSON and attachments)
  • Delete local data: Delete entries in-app or uninstall to remove journal data stored on your device
  • Delete account (recommended): Settings → Account → Delete account. This permanently removes your account, all cloud-synced journals and entries, and journal data stored on this device. Premium access in the app ends when your account is deleted. This does not cancel a Google Play subscription — cancel in Google Play → Subscriptions to stop future charges. Subscription verification data we hold for your device is removed as part of account deletion where applicable. This cannot be undone
  • Delete cloud data (keep account): Email info@silicasites.com with subject "Data Deletion" from your registered email. Specify whether you want all cloud-synced journal data removed. We will process your request within a reasonable period, subject to legal retention requirements. Data on devices you control is your responsibility to delete separately
  • Sign out: Settings → Account → Sign out. Your journal remains on the device; cloud copies remain on our servers until you delete entries or your account
  • Delete account by email (alternative): Email info@silicasites.com with subject "Account Deletion" from the email address tied to your account if you cannot use the in-app option. We will delete your account, profile, and cloud-synced journal data within a reasonable period, subject to legal retention requirements
  • Notifications: Disable in Settings and system notification controls
  • Subscriptions: Manage or cancel in Google Play → Subscriptions
  • Server data: Email info@silicasites.com to request access to or correction of account or cloud journal data we hold

EEA / UK / Switzerland (GDPR)

You may have rights to access, rectify, erase, restrict, object, and data portability regarding personal data we control (including cloud-synced journal content). You may lodge a complaint with your local supervisory authority. Contact us first so we can help.

California (CCPA/CPRA)

We do not sell or share personal information for cross-context behavioral advertising. California residents may request disclosure or deletion of personal information we collect (account data, cloud-synced journal content, subscription verification, and support emails). We will not discriminate against you for exercising these rights.

Other U.S. states

Where state privacy laws grant similar rights, contact info@silicasites.com with your request and jurisdiction.

We aim to respond within 30 days.

10

Children's Privacy

DayLeaf is not directed to children under 13 (or the age of digital consent in your region). We do not knowingly collect personal information from children. If you believe a child provided us information, contact info@silicasites.com and we will delete it.

11

Changes to This Policy

We may update this policy to reflect app or legal changes. We will update the “Last updated” date and, for material changes, provide notice in-app when practicable. Continued use after the effective date constitutes acceptance where permitted by law.

12

Contact

Silica Sites

Email: info@silicasites.com

For privacy requests, include “Privacy Request” in the subject line and your platform (e.g., Android) and jurisdiction if relevant.

DayLeaf Terms of Service

© 2026 Silica Sites. All rights reserved.