Privacy at Daylune

Effective date: [date] · Last updated: [date]

Who we are

Daylune ("Daylune", "we", "us") is a mood and life-tracking journal app operated by Nexify Labs Pty Ltd (ACN 699 587 589, ABN 79 699 587 589), an Australian company based in Brisbane, Queensland, Australia. We decide how and why your personal information is handled, so we are the data controller (and, under some laws, the regulated entity) for the information described here.

Contact: [privacy@yourdomain] · [postal address].

Daylune is a lifestyle and wellbeing product. It is NOT a medical or clinical service. It does not provide medical, psychological, or mental-health advice, diagnosis, or treatment, and is not a substitute for professional care.

Daylune is currently available in Australia, the United States, Japan, Singapore, India, and New Zealand. Daylune is not currently offered in the EU or UK.

Plain-English summary

  • Your data is stored in the cloud (in Japan) and tied to your account — Daylune is not a local-only app.

  • We never sell your data, never show ads, and never share your entries with advertising or analytics companies.

  • Your free-text notes never leave Daylune for any AI or cross-user process.

  • AI insights are off by default and only run after you separately turn them on.

  • You can delete your account and entries permanently from inside the app at any time.

  • Full detail is below; this summary doesn't replace it.

What we never do (so our promises match reality)

We list this plainly because the biggest privacy failures in our category have been apps that said one thing and did another.

  • We do not sell your personal information or health data, and we do not "share" it for cross-context behavioural advertising.

  • We do not embed advertising SDKs, marketing pixels, or social-media trackers (e.g. Meta, Google Ads, TikTok) in the app.

  • We do not send your data to advertising platforms, data brokers, or for ad targeting or re-targeting.

  • We do not use your mood, journal, or health data to train AI models, and we do not allow our providers to do so.

  • We do not claim to be "HIPAA compliant" — Daylune is not a HIPAA-covered entity, and we won't display seals or claims implying otherwise.

  • We will not repurpose your data for a new use, a separate product, or population-level analytics without first asking you for fresh, specific consent (see "Limits on how we reuse data").

What we collect

  • Account data: your email address and authentication details.

  • Profile data: your display name, and your custom mood labels and activities.

  • Journal / health-related content: your mood ratings, tracked metrics (sleep, energy, focus, exercise, social, nutrition), activities, optional free-text notes, important days, and entry dates. These entries are treated as sensitive / health-related information (see the jurisdiction sections and our Consumer Health Data Privacy Policy).

  • Subscription data (only if you subscribe): purchase and entitlement status, handled by Apple, Google, and RevenueCat — we never receive your card details.

  • Technical/diagnostic data: app version, device type, and crash/diagnostic logs needed to run and secure the service. We configure these so they do not capture the content of your entries.

We do not collect more than we need. Free-text notes are optional. We do not ask for your name, gender, or other identifiers we don't need.

Your consent for health-related data

Because your entries are health-related, we ask for your explicit, separate consent to process them — this is not bundled into accepting this policy or the Terms. You can withdraw that consent at any time in the app or by emailing us; withdrawal doesn't affect processing already carried out.

How we use your information

  • To run the core app: logging, calendar, statistics, and Smart Insights (patterns, correlations, and trends computed from your numeric data on our systems).

  • For AI-assisted insights — opt-in, off by default: only after you give separate, explicit consent, we send numeric and structured data only (mood, metrics, activities, dates) — never your free-text notes — to our AI provider to generate plain-language observations, which we then cache. AI-generated observations are labelled as AI-generated in the app, may be imperfect, and are informational only. They are suggestions, not automated decisions that produce legal or similarly significant effects about you.

  • To manage your account, subscriptions, and support requests, and to keep the service secure and lawful.

  • We only send service and transactional messages (e.g. verification, security, support). We won't send marketing or promotional messages without your separate opt-in, which you can withdraw anytime.

  • We do not use your data for advertising and we do not sell it.

Who we share data with (sub-processors)

We share the minimum necessary with vetted providers acting only on our instructions under data-processing agreements:

  • Supabase / Lovable Cloud (data hosted in Japan) — secure cloud database, authentication, and hosting.

  • Anthropic (United States) — AI provider for the opt-in AI insights feature (numeric data only; only if you opt in). Our AI provider does not train its models on data we send through its API.

  • Apple, Google, and RevenueCat (United States / global) — subscription billing and entitlement (only if you subscribe).

  • [email/auth provider] ([region]) — sign-in and transactional email.

We do not sell data or share it with advertisers. We may disclose data only where required by law, or where strictly necessary to protect rights, safety, or the security of the service. A current list of sub-processors is available on request at [privacy@yourdomain].

Government and law-enforcement requests

We don't volunteer your data to anyone. We disclose personal information to a government body or law-enforcement agency only when we're satisfied there is a valid legal basis (such as a binding order under applicable law), and even then we disclose only the minimum necessary and challenge requests that are overbroad. Where we are legally permitted to, we will notify you before disclosing. Because we are an Australian company and your data is hosted in Japan, foreign legal demands generally have to go through proper cross-border legal channels rather than compelling us directly.

Limits on how we reuse data (purpose limitation)

We use your data only for the purposes set out above. In particular:

  • We will not use your data to train AI/ML models.

  • We will not reuse your data for a new purpose, a separate or future app, or population-level / cross-product analytics unless we first ask you for fresh, specific opt-in consent for that use and update this policy.

  • If we ever introduce aggregate or population analytics, our stated direction is to use aggregate-only and privacy-preserving methods (such as aggregation, de-identification, or on-device/federated approaches) rather than building an identifiable data pile, and to notify and re-consent you where the law requires.

International transfers

Your account and journal data is stored in Japan (AWS Asia Pacific, Tokyo), in a single region. For Australian users this is a cross-border disclosure handled under APP 8; for New Zealand users, under IPP 12 — in both cases we take reasonable steps to ensure comparable protection. If you opt into AI insights, numeric data only is sent to Anthropic in the United States. Subscription billing is handled by Apple, Google, and RevenueCat.

Storage, security, and retention

Data is stored in the cloud with per-user access controls (row-level security) and is encrypted in transit and at rest. Access by our personnel and processors is restricted and subject to confidentiality. We keep your data while your account is active. You can delete your account at any time in More → Delete account, which permanently erases your entries and profile from our live database. Backups and diagnostic logs are purged on a rolling basis (typically within [30] days).

Passwords are stored using one-way hashing — we never hold your password in plain text. No method of storage or transmission is ever completely secure, so while we work hard to protect your data we can't promise absolute security. We recommend protecting your device with a passcode or biometric lock.

Your rights

Depending on where you live, you may have the right to access, correct, delete, port, restrict, or object to processing, and to withdraw consent. To exercise these, email [privacy@yourdomain]; you can also delete most data yourself in-app. We respond within the time your law requires (generally 30 days in Australia and New Zealand; 45 days under US state laws, extendable where permitted). We will not discriminate against you for exercising your rights, and we offer an appeal path where required.

Australia (Privacy Act 1988 / Australian Privacy Principles)

We handle "sensitive information" (your mood/health entries) only with your consent and for the purposes above. We follow the Australian Privacy Principles, take reasonable technical and organisational steps to protect your information (APP 11), and notify eligible data breaches under the Notifiable Data Breaches scheme. You can complain to us first, then to the Office of the Australian Information Commissioner (OAIC).

New Zealand (Privacy Act 2020)

We handle your personal information in line with New Zealand's Information Privacy Principles (IPPs). You can ask to access and correct your information, and complain to the Office of the Privacy Commissioner (OPC). Because your data is stored in Japan, this is a cross-border disclosure under IPP 12, and we take reasonable steps to ensure comparable protection. We notify the OPC and affected individuals of any privacy breach likely to cause serious harm.

United States — all states

We do not sell or "share" (for cross-context behavioural advertising) your personal information, and we treat your mood/health entries as sensitive data requiring opt-in consent. Wherever your state grants them, you may confirm, access, correct, delete, and obtain a portable copy of your data, opt out of sale/share/targeted advertising and certain profiling, and limit use of sensitive data. Where technically applicable to the app, we honour recognised universal opt-out signals (such as Global Privacy Control). To exercise any right, email [privacy@yourdomain].

United States, California (CCPA/CPRA)

We do not sell or "share" personal information. You may request to know, access, delete, and correct your information and to limit the use of sensitive personal information. We do not discriminate against you for exercising these rights.

United States, consumer health data (Washington, Nevada, Connecticut, Maryland, and similar)

Your mood and wellbeing entries are consumer health data. We collect them only with your affirmative opt-in consent, we obtain separate consent before sharing them with anyone other than the service providers listed above, and we never sell consumer health data. You may withdraw consent, request a list of any third parties we've shared your consumer health data with, and request deletion at [privacy@yourdomain]. We do not use geofencing around any health facility. Washington residents: see our separate Consumer Health Data Privacy Policy as required by the My Health My Data Act.

Japan (APPI), Singapore (PDPA), India (DPDP Act)

We process your data with your consent and for the stated purposes, honour access/correction/withdrawal requests, and notify you and regulators of eligible data breaches as required. Under India's DPDP Act, users under 18 are treated as children; see "Children" below.

Children

Daylune is intended for users aged 18 and over. We do not knowingly collect personal information from anyone under 18. If you believe someone under 18 has provided us data, contact [privacy@yourdomain] and we will delete it. (We have set the minimum age at 18 because Daylune handles sensitive mental-health data and several markets — including Australia's forthcoming Children's Online Privacy Code and India's DPDP Act — treat under-18s as children with heightened protections.)

Changes to this policy

We'll post changes here and update the date. For material changes affecting your sensitive data, we'll notify you in-app and, where the law requires, ask you to re-consent before the change applies to you.

Contact

[privacy@yourdomain] — Nexify Labs Pty Ltd, Brisbane, Queensland, Australia.

Create a free website with Framer, the website builder loved by startups, designers and agencies.