Skip to content
daili
Features Daili Plus Watch & widgets Blog Log in
EN
  • IDBahasa Indonesia
  • CSČeština
  • DADansk
  • DEDeutsch
  • ENEnglish
  • ESEspañol
  • FRFrançais
  • ITItaliano
  • NLNederlands
  • NBNorsk
  • PLPolski
  • PTPortuguês
  • RORomână
  • SKSlovenčina
  • FISuomi
  • SVSvenska
  • TRTürkçe
  • ELΕλληνικά
  • BGБългарски
  • RUРусский
  • UKУкраїнська
  • ARالعربية
  • HIहिन्दी
  • THไทย
  • KO한국어
  • JA日本語
  • ZH简体中文
  • ZH繁體中文
Download on theApp Store Get it onGoogle Play Open web app

Privacy Policy

Daili app, app.daili.app and daili.app · Last updated: 28 September 2026

Daili is a private family organizer. We built it so that your family's plans belong to your family: no ads, no tracking, no selling of data. This page explains, in plain language, what data the app needs, why, and what your rights are.

1. Who is responsible ("controller")

Ammar Khatib
Kajetan-Sweth-Straße 8, 6020 Innsbruck, Austria
E-mail: support@daili.app

2. This website

daili.app is a static website. It sets no cookies, uses no analytics and loads no third-party fonts or scripts. Our hosting provider automatically keeps short-lived server logs (IP address, time, requested page) for security; we do not use them for anything else. Legal basis: our legitimate interest in a secure website (Art. 6(1)(f) GDPR).

Apart from loading its pages, this site sends nothing on its own. Only two optional things you use yourself do: the newsletter form and the help center feedback below. The one form on this site is the newsletter sign-up under our blog posts: it sends the e-mail address you type to our own server (api.daili.app) and nothing else — see "Newsletter (optional)" in section 4.

Help center feedback (optional). If you tap "Was this helpful?" on a help article, or a search in the help center finds nothing, your browser sends an anonymous count to our own server (api.daili.app): which article and yes/no, or the search text. It contains no name, no account, no cookie and no device id. We don't store your IP address with it, only the date. We drop search texts that look like an e-mail address or a phone number, and we delete everything after 180 days. We use it only to improve the help articles. Legal basis: our legitimate interest in useful help pages (Art. 6(1)(f) GDPR).

3. The web app (app.daili.app)

Daili also runs in a browser at app.daili.app. It sets no cookies and uses no analytics. Fonts are served from our own server, so the web app loads no third-party fonts or scripts when it starts.

Instead of a cookie, your browser keeps your sign-in token in its own local storage. That token is what proves to our server that a request is yours, and signing out deletes it. Beside it the browser stores a handful of display settings so the app looks the same next time: your language and theme, the calendar view you last used, which tiles you show on the home screen, whether the sidebar is collapsed, and your default reminder time. Those settings stay on your device, are never sent to us, and remain until you clear your browser's site data. Everything kept here is either strictly necessary to sign you in or a preference you set yourself, which is why there is no cookie banner.

Sign in with Google or Apple (optional). Only if you choose social sign-in does a pop-up run through Firebase Authentication, exactly as in the phone app. If you sign in with an e-mail address and password, no Google or Apple code runs at all.

Browser notifications (optional). Only if you switch them on and your browser grants permission does the web app register a service worker and obtain a device token from Firebase Cloud Messaging. That token and its device number are then kept in local storage, and a copy of your sign-in token is kept in the browser's database (IndexedDB) so that the buttons on a notification still work when no Daili tab is open. Turning notifications off, or signing out, removes all of it.

4. Data the app processes

Account data. When you register we store your display name, e-mail address and password (stored only as a secure hash — we cannot read it). Optional: a profile picture and your language preference. Legal basis: performance of the contract with you (Art. 6(1)(b) GDPR).

Sign in with Google or Apple (optional). If you choose social sign-in, authentication runs through Firebase Authentication (Google Ireland Ltd.). We receive your name, e-mail address (Apple lets you hide it behind a relay address) and a technical user ID. We never see your Google or Apple password.

Family content. Everything your family creates in the app is stored on our server so your family members can see it: calendar events and reminders, shopping and to-do lists, recipes and meal plans, birthdays and celebrations, subscribed external calendar addresses, and family member profiles — including managed profiles for children (name, optional birthday, optional picture) that a parent creates and controls. This content is visible only to members of your family, never to other users and never publicly.

Connected calendars (optional). If you add your phone's calendar, those events are read and shown on your device only — they are never uploaded to our servers, and your family cannot see them. If you connect a Google or Outlook calendar, Daili reads the calendars you select (read-only) and stores their events on our server so you — and, only if you choose, your family — can see them in the family calendar. You can disconnect at any time; the synced events and access keys are then deleted. How Daili handles Google Calendar data — what it reads, with whom it is shared and how it is protected — is described in section 5.

AI features (optional). Some features ask Google's Gemini AI for help, only when you start them: turning a YouTube video, a photo or a screenshot into a recipe, reading dates from a photographed letter, and suggesting dinners for your week. For these, the video link, the photo, or — for suggestions — your recipe titles, your recent meals and the wish you typed are sent to Google (Google Ireland Ltd.) once and used only to answer. Photos are read once and never stored on our servers; Google does not use this data to train its models. Each family has a monthly number of AI actions; we count them, nothing else.

Contacts (optional). If you use "import birthdays", the app shows your address book on your device so you can pick entries; only the names and birthdays you tick are sent to our server. Your address book itself is never uploaded.

Photos & documents vault. Files in the vault are stored only on your device. They are never uploaded to our servers and are not part of any backup we hold.

Push notifications. To deliver reminders, the app registers a technical device token with Firebase Cloud Messaging (Google). You can turn notifications off at any time in the system settings; reminders then simply stop.

Wall display (optional). If someone in your family connects a TRMNL e-paper display to Daili, our server sends the display a summary of the next few days: events, to-dos, shopping items, meals and birthdays of your family. It is sent to TRMNL, the company that runs the display service, so the display can show it. Private events and calendars that are not shared with the family are never sent. Removing the Daili plugin in TRMNL stops it.

E-mails. We send account e-mails (verification, password reset, invitations) through Brevo, an EU e-mail provider.

Newsletter (optional). Only if you switch it on — in the app, in the web app, when you sign up, or with the form on our blog — do we send you a newsletter: about one e-mail a month with new features and tips. We store your e-mail address, your language, where you signed up and the date you agreed, as proof of your consent. The newsletter is sent through Brevo (Sendinblue SAS, France, EU), which processes this data on our behalf. If you sign up with the blog form, or have not confirmed your e-mail address yet, Brevo first sends a confirmation e-mail; nothing else is sent until you click it. Newsletter e-mails contain no tracking pixels and no tracked links. You can unsubscribe at any time — with the link in every newsletter, the switch in the app or web app, or by writing to us; you are then removed from the list. Deleting your account also deletes you from the newsletter. Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time without affecting e-mails already sent.

Help center feedback in the app (optional). The app's help center loads the help articles from our website (daili.app). If you tap "Was this helpful?" or a help search finds nothing, the app sends an anonymous count to our own server: which article and yes/no, or the search text, plus the app version, the platform (iOS/Android) and the language. It is sent without your account, without a device id and without a login token, so we can't link it to you. We delete it after 180 days. Legal basis: our legitimate interest in useful help (Art. 6(1)(f) GDPR).

What the app does not collect. No location. No advertising ID. No analytics or tracking tools inside the app. Your address book and your phone's calendar stay on your device.

5. Google user data

This section explains how Daili accesses, uses, stores, shares and protects Google user data: the data we receive from Google when you connect a Google Calendar, or when you sign in with Google.

What we access

Only if you tap "Connect Google Calendar" and agree on Google's consent screen, Daili gets read-only access with these permissions:

  • calendar.calendarlist.readonly — the list of your calendars (name and colour), so you can choose which calendars Daili shows;
  • calendar.events.readonly — the events of the calendars you chose;
  • openid and email — the e-mail address of the Google account, so you can see which account is connected.

Daili never creates, changes or deletes anything in your Google Calendar. If you sign in with Google (section 4), we receive only your name, e-mail address and a technical user ID, and use them only to sign you in.

How we use it

We use Google user data only to show the events of the calendars you chose inside Daili: in the family calendar of the app and the web app, in your home-screen widgets, in the morning and evening summary notifications if you switch them on, and on a family wall display if your family connects one. We do not use Google user data for advertising, we do not sell it, we do not use it to build profiles, and we do not use it to develop, improve or train artificial-intelligence or machine-learning models. Google Calendar data is never sent to the AI features described in section 4.

What we store

For each event: title, location, start and end time, whether it is all-day, and its time zone. For each chosen calendar: its name and colour. For the connection: the Google e-mail address and the access keys (OAuth tokens) that Google gives us. We do not store event descriptions, guests or attachments. This data is stored on the Daili server in the EU (section 7); the app keeps a copy on your device so your calendar also works offline.

With whom we share, transfer or disclose Google user data

We do not sell Google user data, and we do not share, transfer or disclose it to anyone, except in these cases:

  • Your family members — only the calendars you mark "Share with family". A calendar you keep private is visible only to you.
  • Service providers that run Daili for us — Host Europe GmbH (Germany), which hosts our server and database; and Google (Firebase Cloud Messaging), which delivers our notifications. If you switch on the summary notification, it contains the titles of that day's events. These providers process the data only on our behalf, to run Daili.
  • TRMNL — only if someone in your family connects a TRMNL e-paper display to Daili: events from calendars shared with the family are sent to TRMNL so the display can show them. Private calendars are never sent.
  • When the law requires it — for example a binding order from a court or an authority, and only as far as required.

We never give Google user data to advertisers, data brokers or AI companies, and we do not transfer or disclose it to third parties for any purpose other than the ones listed in this section.

How we protect Google user data

  • Encryption in transit: every connection between the app or web app, our server and Google uses HTTPS (TLS).
  • Encrypted access keys: the Google access keys (OAuth tokens) are encrypted in our database with AES-256. They never leave our server and are never sent to the app or the browser.
  • Access control: every request must be signed in. Before the server returns any event, it checks that you belong to the family and that the calendar is yours or shared with the family.
  • Least privilege: Daili asks only for read-only permissions and stores only the fields listed above.
  • Limited staff access: only the developer of Daili (section 1) has administrative access to the server and the database.

Section 6 describes the security measures that protect all your data.

How long we keep it and how to delete it

  • Daili refreshes the chosen calendars regularly. An event you delete in Google also disappears from Daili at the next refresh.
  • When you disconnect Google in Daili (Calendar → settings → the connected account → Disconnect), we revoke our access at Google and immediately delete the access keys, the calendar list and all synced events.
  • When you delete your Daili account, all Google user data is deleted with it, at the latest after the 30-day grace period (section 8).
  • You can also remove Daili's access at any time in your Google Account at myaccount.google.com/permissions. Daili then cannot read your calendar any more; disconnect in Daili as well to delete the copy we stored.

Limited Use

Daili's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

6. How we protect your data

We protect all data in Daili — including Google user data — with these measures:

  • Encryption in transit: the app, the web app and this website talk to our server only over HTTPS (TLS).
  • Passwords are stored only as a secure hash (bcrypt). Nobody, including us, can read them.
  • Access keys for connected calendar accounts are encrypted in the database (AES-256) and never leave our server.
  • Access control: every request must be signed in, and the server only returns data of your own family. Private items stay visible only to you.
  • Hosting in the EU: our server and database are hosted by Host Europe GmbH in a professional data centre in the EU.
  • Few people, little data: only the developer of Daili has administrative access, and we collect only what a feature needs — no location, no advertising ID, no tracking.
  • If something goes wrong: if a data breach ever happens, we inform the data protection authority and the people affected, as the GDPR requires (Art. 33 and 34 GDPR).

7. Where your data lives

The Daili server is hosted by Host Europe GmbH in the European Union (Germany). Firebase Authentication and Firebase Cloud Messaging are services of Google; Google may process limited technical data (such as device tokens) on servers outside the EU under the EU standard contractual clauses. Gemini requests may be processed by Google on servers outside the EU under the EU standard contractual clauses.

8. How long we keep data

Your data stays as long as your account exists. If you delete your account, it is deactivated immediately, kept for a 30-day grace period (in case you change your mind — you can restore it by e-mail link), and then permanently deleted. You can export your data as a file at any time (Settings → Profile → Download my data).

9. Children

Daili is made for families. Accounts for children are created and managed by a parent or guardian: either as a managed profile without a login, or via a personal invitation from a family admin. Parents can remove a child's profile and its data at any time.

10. Your rights

  • Access to the data we hold about you (the in-app export covers this)
  • Correction of wrong data, deletion, and restriction of processing
  • Data portability (the export file)
  • Objection to processing based on legitimate interest

Just write to support@daili.app. You also have the right to complain to the Austrian Data Protection Authority (Datenschutzbehörde, dsb.gv.at).

11. Changes

If Daili gains new features that change how data is handled, we will update this page and note the date at the top.

12. Language

This policy is written in English and German. Translations into other languages are provided for convenience; if they differ, the English version applies.

© 2026 Daili · support@daili.app
Web app Support Blog Help What's new Privacy Policy Terms Impressum