Privacy Policy
Last updated: 11 August 2026 · applies to the My Day iOS app and this website
In short: My Day keeps your tasks, events, habits and workouts on your device and — while you are signed in — in a database in the EU (Ireland). There is no advertising, no tracking and no analytics SDKs. AI features contact Google only at the moment you trigger an action. Purchases run through Apple; purchase and subscription events reach us via RevenueCat. Apple Health and your device calendar are only accessed after you grant permission; calendar events you edit or delete in My Day are written back to your device calendar. You can delete your account together with all of its data at any time, directly in the app.
1 · Controller
The controller for the processing described here, within the meaning of Art. 4(7) GDPR, is:
Tilmann Pheiler
Asbeckweg 43
48161 Münster, Germany
Email: tilmann.pheiler05@gmail.com
There is no statutory obligation to appoint a data protection officer. For any question about your data, write to the address above; the support page lists the same contact.
2 · Data in the app
2.1 Account
An account is required in order to use the app. For this we process your email address and your password, the latter stored only as a cryptographic hash — never in plain text. Sign-in data (session tokens) is kept on your device in the iOS Keychain.
If you request a password reset, a one-time link is sent to your email address so that you can set a new password. When you register and whenever you change your password, the password is additionally checked against a list of publicly known leaked passwords; how that check works is described in section 5 under Have I Been Pwned.
Purpose: creating and securing your account, signing in, synchronising your data across your devices. Legal basis: Art. 6(1)(b) GDPR (performance of a contract); for the password check Art. 6(1)(f) GDPR (our legitimate interest in account security).
2.2 Your content
Everything you create in the app: tasks, events, habits, workouts, recurring templates, saved routines and preferences, and your settings. This content is held locally on your device and — while you are signed in — stored on the server for synchronisation, technically as one JSON document per account.
Storage location: Supabase (see section 5), region EU (Ireland, eu-west-1). Transfer is exclusively TLS-encrypted; on the server side, access is isolated per account (Row Level Security), so one account can never read another account’s document.
Legal basis: Art. 6(1)(b) GDPR.
2.3 Subscription, entitlements and voucher codes
My Day is free to use; the optional Pro subscription is bought as an in-app purchase through the App Store. So that the app knows which functions are unlocked for you, we store on the server:
- your current plan and the sources it derives from (for example an active App Store subscription or a redeemed voucher code), together with the date on which it expires;
- your voucher redemptions, if you have redeemed a code;
- failed redemption attempts, in order to limit brute-force guessing of codes. These are deleted automatically after 24 hours (section 6).
We never see your payment details. Payment, invoicing, renewal and refunds are handled by Apple alone; see sections 3 and 5.
Legal basis: Art. 6(1)(b) GDPR; for the limit on failed attempts Art. 6(1)(f) GDPR (protection against abuse).
2.4 The website and the waiting list
This website is static. It sets no cookies and uses no analytics tools. Fonts and icons are served from our own server; nothing is loaded from third-party servers such as Google Fonts or a CDN. When the site is accessed, technically necessary server log data (for example IP address, time of the request) is produced at our hosting provider Vercel Inc. (see section 5.6); legal basis Art. 6(1)(f) GDPR.
If you enter your email address in the waiting list, we store it in the same EU database solely in order to notify you about the app. Legal basis: Art. 6(1)(a) GDPR (consent). You can withdraw at any time by an informal email, after which the entry is deleted.
2.5 No tracking, no advertising
The app contains no advertising, no tracking and no analytics or advertising SDKs. We do not build usage profiles, we do not track you across apps or websites, and nothing is sold to anyone. Accordingly, the app declares NSPrivacyTracking = false in its privacy manifest.
3 · Distribution channels (App Store and TestFlight)
My Day is distributed through Apple’s App Store. Download, the purchase of a Pro subscription, billing, renewal, cancellation and refunds all take place in your relationship with Apple; for that part Apple is the controller in its own right and Apple’s own privacy policy applies. We receive neither your payment details nor your Apple ID.
Pre-release versions are distributed through TestFlight. If you take part, Apple — and, in aggregated form, we — receive technical data such as crash reports, plus any feedback you choose to send. The details are governed by Apple’s privacy policy and by the notice shown inside TestFlight itself. A TestFlight build is a time-limited test version, not a substitute for the App Store release.
4 · AI features
The AI features are optional and are only ever triggered by you: nothing is sent while the app merely sits open. When you run an AI action — asking the assistant, planning the day, placing focus time, or generating the weekly review and tomorrow’s preview — the request goes to Google Gemini through a server function of ours. What leaves your device is:
- the text you entered or the action you triggered,
- a limited excerpt of the relevant day: tasks, events, habits and the preferences you have saved.
The API key for the AI provider is held exclusively on the server and is never present in the app. We do not store your conversations.
For quota and abuse control the server function keeps two things: a monthly usage counter per account, and short-lived technical request metadata without any content, which is deleted automatically after 48 hours (section 6). Which language model answers depends on your plan and is decided on the server: with Pro the stronger model is used, without Pro the smaller one.
Legal basis: Art. 6(1)(b) GDPR; as regards the transfer to a third country, additionally your consent through the deliberate use of an AI feature, Art. 49(1)(a) GDPR.
5 · Recipients and processors
We pass data on only where it is necessary to run the app, and only to the following recipients. There is no disclosure to anyone else, and no data is sold.
5.1 Supabase, Inc. — database, authentication, server functions
- Purpose: account and sign-in, storage and synchronisation of your content, entitlements, quota counting, waiting list.
- Data received: email address and password hash; your app state as one JSON document; the AI quota counter; short-lived AI request metadata; plan and its sources; voucher redemptions and failed redemption attempts; waiting-list entries.
- Legal basis: Art. 6(1)(b) GDPR; processing on our behalf under a data processing agreement pursuant to Art. 28 GDPR.
- Third country: the project runs in the EU region Ireland (eu-west-1), so the data is stored inside the EU. Supabase, Inc. is based in the USA; where access from the USA cannot be ruled out for support or operational purposes, it is covered by the EU standard contractual clauses agreed in that agreement.
5.2 Google LLC — Gemini (only on a triggered AI action)
- Purpose: generating the answer, plan, review or preview you asked for.
- Data received: only the request described in section 4 — your text plus the limited excerpt of the day. Nothing is transmitted unless you trigger an AI action.
- Legal basis: Art. 6(1)(b) GDPR; for the third-country transfer additionally Art. 49(1)(a) GDPR.
- Third country: USA. Google is certified under the EU-US Data Privacy Framework; Google’s privacy policy applies in addition.
5.3 Apple Inc. — App Store, TestFlight, notification delivery
- Purpose: distributing the app, selling and administering the subscription, delivering notifications, and — only with your permission — access to Apple Health and to the calendar on your device.
- Data received: whatever arises from your relationship with Apple when you download the app and buy a subscription (Apple ID, payment details, purchase history). We have no access to any of it. Health data and calendar entries stay on your device unless you import them into the app yourself.
- Legal basis: Art. 6(1)(b) GDPR for the contractual relationship; Apple acts as controller in its own right for the App Store.
- Third country: USA; see Apple’s privacy policy.
5.4 RevenueCat, Inc. — purchase and subscription events
- Purpose: establishing reliably whether an App Store subscription is active, so that Pro is unlocked on every one of your devices and expires when the subscription ends.
- Data received: the app passes your Supabase user ID as the „App User ID“. In return we receive the event type, that app user ID, the environment (production or sandbox), the expiry timestamp, the entitlement identifiers, an event ID and the time of the event. No payment details are involved on either side.
- Legal basis: Art. 6(1)(b) GDPR (performance of a contract), processing on our behalf under a data processing agreement.
- Third country: USA, on the basis of the EU standard contractual clauses agreed in that agreement.
5.5 Have I Been Pwned — api.pwnedpasswords.com
- Purpose: refusing passwords that are already known from public data breaches, when you register and when you change your password.
- Data received: only the first five characters of the SHA-1 hash of the password (k-anonymity). Neither the password nor its full hash ever leaves your device; the service returns a list of matching hash suffixes and the comparison happens locally on your device. From those five characters the service can identify neither you nor your password. If the request fails — for instance because you are offline — the check is simply skipped.
- Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the security of accounts and stored data).
- Third country: the service is operated outside the EU. Because no personal data and no usable password fragment is transmitted, the transfer is limited to the technical connection data of the request.
5.6 Vercel Inc. — hosting of this website
- What it receives: the server log data described in section 4 when this website is accessed — IP address, time of the request, the page requested. The app itself never contacts this service.
- Third country: Vercel Inc. is based in the USA. Where access from the USA cannot be ruled out for operational purposes, it is covered by the EU standard contractual clauses.
- Legal basis: Art. 6(1)(f) GDPR — secure and trouble-free operation of the website.
6 · Retention and deletion
Two categories are deleted automatically by a scheduled database job, whether or not you do anything:
- AI request metadata: 48 hours. The short-lived technical records described in section 4 are removed by a job that runs every hour, once they are older than 48 hours.
- Failed voucher redemption attempts: 24 hours. Likewise removed by an hourly job once they are older than 24 hours.
Everything else has no fixed retention period, because it exists for exactly as long as your account does. This applies to your email address and password hash, your app state document, the AI quota counter, your plan and the sources it derives from, and your voucher redemptions. We do not delete them on a timer — they live until the account is deleted, and they disappear with it. Waiting-list entries are deleted after launch or on request; data held only on your device disappears when you delete the app.
You can delete your account yourself at any time, in the app under Profile → Danger zone → Delete account. On the server this removes everything relating to you, permanently and in one step: the deletion cascades from the account through the app state, the quota counter, the entitlements and their sources, the redemptions and the remaining request metadata.
7 · Your rights
Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21), as well as the right to withdraw consent at any time (Art. 7(3)), without this affecting the lawfulness of the processing carried out until then. To exercise any of them, write to the email address in section 1 — no particular form is required.
Two of these you can exercise directly, without asking us: erasure through Profile → Danger zone → Delete account, and portability through the file export built into the app, which is available on every plan.
You may also lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), for example the authority responsible for the federal state in which you live, or the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia, which is the authority responsible for us.
8 · Permissions (Apple Health, calendar, notifications)
8.1 Apple Health (HealthKit)
Only if you actively enable the import and iOS grants permission does My Day read completed workouts from Apple Health: type of activity, duration, energy burned and date. My Day also reads your daily exercise minutes (the AppleExerciseTime HealthKit type) — one total per day, in minutes. From 30 exercise minutes onwards My Day records that day like a workout and ticks off the exercise habit; the number is counted and displayed, not evaluated. The first import covers the last 90 days; after that only new workouts and the exercise minutes of the last seven days are read. My Day has read access only and never writes anything into Apple Health.
- Health data is never used for advertising, never sold, and never passed to a third party.
- It is not part of the excerpt sent to the AI provider under section 4.
- You can stop the import at any time, in the app or under Settings → Privacy & Security → Health, and delete imported workouts in the app.
Legal basis: Art. 9(2)(a) GDPR (explicit consent, revocable at any time).
8.2 Device calendar
Only after you grant permission does the app access the calendar on your device, so that your appointments appear alongside your tasks. If you edit or delete one of those events in My Day, My Day writes that change back to your device calendar. This happens solely on your explicit input, never on its own and never through the AI features, and only for calendars that iOS allows to be modified — subscribed calendars such as public holidays stay unchangeable. If you create an event in My Day yourself, My Day writes it into the calendar you pick for it — only calendars that iOS allows to be modified are offered. My Day creates no new calendars, and there is no background synchronisation. Access happens on the device; iOS controls it and you can withdraw the permission at any time under Settings → Privacy & Security → Calendars. Legal basis: Art. 6(1)(a) GDPR.
8.3 Notifications
Reminders, the daily agenda and streak notices are scheduled on your device; delivery runs through Apple’s notification system. We operate no notification server of our own and do not build audiences from them. You can revoke the permission at any time under Settings → Notifications. Legal basis: Art. 6(1)(a) GDPR.
9 · Children
My Day is not directed at children and we do not knowingly process the data of children. Using the app requires an account, and creating one requires full legal capacity; if you are under 16, you may only create an account with the consent of a parent or guardian (Art. 8 GDPR). If you believe that a child has created an account without that consent, write to the address in section 1 and we will delete it.
10 · Changes
We adapt this policy when the app or the services behind it change — for example when a processor is added or replaced, or when a new feature processes new data. The version published here at the time is the one that applies; the date at the top of the page shows how current it is. Where a change requires your consent, we will ask for it before the processing begins.
11 · Legal notice (Impressum)
Information pursuant to § 5 DDG:
Tilmann Pheiler
Asbeckweg 43
48161 Münster, Germany
Email: tilmann.pheiler05@gmail.com
Responsible for the content: Tilmann Pheiler (address as above). The terms of use are set out separately in the Terms.
Last updated: 11 August 2026. This version replaces all earlier ones. The German version is the binding one; this English version is a translation for information.