Privacy Policy
Last updated: 12 September 2026 · applies to the My Day iOS app and this website
In short: My Day keeps your tasks, events, habits and workouts on your device and — while you are signed in — in a database in the EU (Ireland). There is no advertising, no tracking and no analytics SDKs. AI features contact Google only at the moment you trigger an action. Purchases run through Apple; purchase and subscription events reach us via RevenueCat. Apple Health and your device calendar are only accessed after you grant permission; calendar events you edit or delete in My Day are written back to your device calendar. You can delete your account together with all of its data at any time, directly in the app.
1 · Controller
The controller for the processing described here, within the meaning of Art. 4(7) GDPR, is:
Tilmann Pheiler
Asbeckweg 43
48161 Münster, Germany
Email: tilmann.pheiler05@gmail.com
There is no statutory obligation to appoint a data protection officer. For any question about your data, write to the address above; the support page lists the same contact.
2 · Data in the app
2.1 Account
An account is required in order to use the app. For this we process your email address and your password, the latter stored only as a cryptographic hash — never in plain text. Sign-in data (session tokens) is kept on your device in the iOS Keychain.
If you request a password reset, a one-time link is sent to your email address so that you can set a new password. When you register and whenever you change your password, the password is additionally checked against a list of publicly known leaked passwords; how that check works is described in section 5 under Have I Been Pwned.
Purpose: creating and securing your account, signing in, synchronising your data across your devices. Legal basis: Art. 6(1)(b) GDPR (performance of a contract); for the password check Art. 6(1)(f) GDPR (our legitimate interest in account security).
2.2 Your content
Everything you create in the app: tasks, events, habits, workouts, recurring templates, saved routines and preferences, and your settings. This content is held locally on your device and — while you are signed in — stored on the server for synchronisation, technically as one JSON document per account.
Sync device list. After a successful sync, the app reports a random identifier for each account and app installation and the general device type (such as iPhone or iPad); the server adds the time. Personal device names and hardware identifiers are not read for this purpose. These records are accessible only to the associated account and let you review successful syncs. They are removed by “Delete my data” and by account deletion. The local time of the last successful sync belongs only to this account on this device and is not part of exported content.
Home screen widget. For signed-in Free and Pro accounts, the app keeps a second copy of a few of these entries on your device: the title and time of your next event and of your topmost tasks, in a storage area it shares with the widget. That is what allows iOS to draw the widget while the app is not running. The copy stays on the device, is never transmitted, is excluded from the device backup, and is overwritten on every change. Free shows the basic overview; Pro adds content options and direct check-off. Signing out replaces widget content with an empty sign-in prompt.
Storage location: Supabase (see section 5), region EU (Ireland, eu-west-1). Transfer is exclusively TLS-encrypted; on the server side, access is isolated per account (Row Level Security), so one account can never read another account’s document.
Legal basis: Art. 6(1)(b) GDPR.
2.3 Subscription, entitlements and voucher codes
My Day is free to use; the optional Pro subscription is bought as an in-app purchase through the App Store. So that the app knows which functions are unlocked for you, we store on the server:
- your current plan and the sources it derives from (for example an active App Store subscription or a redeemed voucher code), together with the date on which it expires;
- your voucher redemptions, if you have redeemed a code;
- failed redemption attempts, in order to limit brute-force guessing of codes. These are deleted automatically after 24 hours (section 6).
We never see your payment details. Payment, invoicing, renewal and refunds are handled by Apple alone; see sections 3 and 5.
Legal basis: Art. 6(1)(b) GDPR; for the limit on failed attempts Art. 6(1)(f) GDPR (protection against abuse).
2.4 The website and the waiting list
This website is static. It sets no cookies and uses no analytics tools. Fonts and icons are served from our own server; nothing is loaded from third-party servers such as Google Fonts or a CDN. When the site is accessed, technically necessary server log data (for example IP address, time of the request) is produced at our hosting provider Vercel Inc. (see section 5.6); legal basis Art. 6(1)(f) GDPR.
If you enter your email address in the waiting list, we store it in the same EU database solely in order to notify you about the app. Legal basis: Art. 6(1)(a) GDPR (consent). You can withdraw at any time by an informal email, after which the entry is deleted.
2.5 No tracking, no advertising
The app contains no advertising, no tracking and no analytics or advertising SDKs. We do not build usage profiles, we do not track you across apps or websites, and nothing is sold to anyone. Accordingly, the app declares NSPrivacyTracking = false in its privacy manifest.
3 · Distribution channels (App Store and TestFlight)
My Day is distributed through Apple’s App Store. Download, the purchase of a Pro subscription, billing, renewal, cancellation and refunds all take place in your relationship with Apple; for that part Apple is the controller in its own right and Apple’s own privacy policy applies. We receive neither your payment details nor your Apple ID.
Pre-release versions are distributed through TestFlight. If you take part, Apple — and, in aggregated form, we — receive technical data such as crash reports, plus any feedback you choose to send. The details are governed by Apple’s privacy policy and by the notice shown inside TestFlight itself. A TestFlight build is a time-limited test version, not a substitute for the App Store release.
4 · AI features
The AI features are optional and are part of the paid Pro subscription; without Pro no AI action is available and nothing is transmitted to an AI provider. They are only ever triggered by you: nothing is sent while the app merely sits open. Something leaves your device only for the AI actions you start yourself, and in the current app there are exactly two of them: writing a message to the assistant, and the “Generate with AI” button that writes the description of an event. In those two cases the request goes to Google Gemini through a server function of ours.
For the assistant, what leaves your device is:
- the text you entered and the most recent messages of the same conversation,
- a limited excerpt of the relevant day: your open tasks and the ones you have already completed today (title, due date, time window, duration, checklists, and whether you flagged it as important), events (titles, times, type), habits (name, current streak, whether it is done today, any weekly goal) and the routines you have saved,
- your recurring templates: the title, whether they produce a task or an event, how often and on which weekdays they repeat, the time of day and the duration — taken together they describe your usual week,
- your planning rules: working windows and blocked times with their hours and weekdays, globally and per category, and your preferred time of day — these show when you are regularly available and when you are not,
- the number of the workouts you recorded today, without any workout details (see section 8.1),
- if you have granted access to your device calendar: the titles and times of the events in it around today, so that the plan can take them into account (see section 8.2),
- the total number of your open tasks, events, habits, recurring templates and planning rules, so that it stays apparent when the excerpt above is only a part of them.
All of these entries travel with a technical identifier — a randomly generated string with no content of its own, by which an answer from the AI is matched to the right row. A category is likewise present only as such an identifier; its name stays on your device. Events from your device calendar deliberately carry no identifier at all, which is what makes it impossible for the AI to change them.
For the “Generate with AI” button, what leaves your device is only the title, start and end of that one event and the language set in the app; no excerpt of your day is sent.
Nothing is sent at all for the features your device works out on its own: “Plan my day”, “Book focus time”, the weekly review and tomorrow’s preview are computed entirely on your device and never ask an AI provider. App versions up to and including 1.1.0 also had a morning briefing that sent the same excerpt as the assistant; that action no longer exists as of version 1.1.1.
The API key for the AI provider is held exclusively on the server and is never present in the app. We do not store your conversations.
For quota and abuse control the server function keeps two things: a monthly usage counter per account, and short-lived technical request metadata without any content, which is deleted automatically after 48 hours (section 6). Which Gemini model answers is not decided by the server according to your plan: the app sends the model selected in its settings — gemini-2.5-flash unless you change it — and the server only checks that name against a fixed list of permitted models; gemini-2.5-pro is reserved for Pro. Without Pro no request reaches a model at all, because the monthly allowance of an account without Pro is zero.
Legal basis: Art. 6(1)(b) GDPR; as regards the transfer to a third country, additionally your consent through the deliberate use of an AI feature, Art. 49(1)(a) GDPR.
5 · Recipients and processors
We pass data on only where it is necessary to run the app, and only to the following recipients. There is no disclosure to anyone else, and no data is sold.
5.1 Supabase, Inc. — database, authentication, server functions
- Purpose: account and sign-in, storage and synchronisation of your content, entitlements, quota counting, waiting list.
- Data received: email address and password hash; your app state as one JSON document; the AI quota counter; short-lived AI request metadata; plan and its sources; voucher redemptions and failed redemption attempts; waiting-list entries.
- Legal basis: Art. 6(1)(b) GDPR; processing on our behalf under a data processing agreement pursuant to Art. 28 GDPR.
- Third country: the project runs in the EU region Ireland (eu-west-1), so the data is stored inside the EU. Supabase, Inc. is based in the USA; where access from the USA cannot be ruled out for support or operational purposes, it is covered by the EU standard contractual clauses agreed in that agreement.
5.2 Google LLC — Gemini (only on a triggered AI action)
- Purpose: generating the answer, plan, review or preview you asked for.
- Data received: only the request described in section 4 — your text plus the limited excerpt of the day. Nothing is transmitted unless you trigger an AI action.
- Legal basis: Art. 6(1)(b) GDPR; for the third-country transfer additionally Art. 49(1)(a) GDPR.
- Third country: USA. Google is certified under the EU-US Data Privacy Framework; Google’s privacy policy applies in addition.
5.3 Apple Inc. — App Store and TestFlight
- Purpose: distributing the app, selling and administering the subscription, and — only with your permission — access to Apple Health and to the calendar on your device. Notifications do not belong here; see section 8.3.
- Data received: whatever arises from your relationship with Apple when you download the app and buy a subscription (Apple ID, payment details, purchase history). We have no access to any of it. Health data and calendar entries stay on your device unless you import them into the app yourself.
- Legal basis: Art. 6(1)(b) GDPR for the contractual relationship; Apple acts as controller in its own right for the App Store.
- Third country: USA; see Apple’s privacy policy.
5.4 RevenueCat, Inc. — purchase and subscription events
- Purpose: establishing reliably whether an App Store subscription is active, so that Pro is unlocked on every one of your devices and expires when the subscription ends.
- Data received: the app passes your Supabase user ID as the „App User ID“. In return we receive the event type, that app user ID, the environment (production or sandbox), the expiry timestamp, the entitlement identifiers, an event ID and the time of the event. No payment details are involved on either side.
- Legal basis: Art. 6(1)(b) GDPR (performance of a contract), processing on our behalf under a data processing agreement.
- Third country: USA, on the basis of the EU standard contractual clauses agreed in that agreement.
5.5 Have I Been Pwned — api.pwnedpasswords.com
- Purpose: refusing passwords that are already known from public data breaches, when you register and when you change your password.
- Data received: only the first five characters of the SHA-1 hash of the password (k-anonymity). Neither the password nor its full hash ever leaves your device; the service returns a list of matching hash suffixes and the comparison happens locally on your device. From those five characters the service can identify neither you nor your password. If the request fails — for instance because you are offline — the check is simply skipped.
- Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the security of accounts and stored data).
- Third country: the service is operated outside the EU. Because no personal data and no usable password fragment is transmitted, the transfer is limited to the technical connection data of the request.
5.6 Vercel Inc. — hosting of this website
- What it receives: the server log data described in section 4 when this website is accessed — IP address, time of the request, the page requested. The app itself never contacts this service.
- Third country: Vercel Inc. is based in the USA. Where access from the USA cannot be ruled out for operational purposes, it is covered by the EU standard contractual clauses.
- Legal basis: Art. 6(1)(f) GDPR — secure and trouble-free operation of the website.
5.7 OpenStreetMap Foundation — Nominatim place search
- Purpose: turning a place name into real-world results when an AI action you triggered asks the assistant to look one up.
- Data received: only the search term the assistant derives from your message — what to look for and, if you named one, the area to look in (the query and near fields, for example „dentist in Münster“). Neither your account ID nor any other part of the excerpt described in section 4 is sent. The request is made by our server, never by the app, so your device’s IP address never reaches the service.
- Legal basis: Art. 6(1)(b) GDPR — carrying out the AI action you triggered.
- Third country: the service does not act on our behalf and is not a processor. Under the OpenStreetMap Foundation privacy policy, request data is stored in the United Kingdom and the Netherlands, with backups in the EU.
6 · Retention and deletion
Two categories are deleted automatically by a scheduled database job, whether or not you do anything:
- AI request metadata: 48 hours. The short-lived technical records described in section 4 are removed by a job that runs every hour, once they are older than 48 hours.
- Failed voucher redemption attempts: 24 hours. Likewise removed by an hourly job once they are older than 24 hours.
Everything else has no fixed retention period, because it exists for exactly as long as your account does. This applies to your email address and password hash, your app state document, the AI quota counter, your plan and the sources it derives from, and your voucher redemptions. We do not delete them on a timer — they live until the account is deleted, and they disappear with it. Waiting-list entries are deleted after launch or on request; data held only on your device disappears when you delete the app.
Signing out is not deletion. When you sign out, the content of that account stays on the device, so that signing in again does not have to load everything from the server a second time. It goes when you delete the app, and it goes when you delete the account, which clears the local copies of every account on the device along with the server side.
You can delete your account yourself at any time, in the app under Profile → Danger zone → Delete account. On the server this removes everything relating to you, permanently and in one step: the deletion cascades from the account through the app state, the quota counter, the entitlements and their sources, the redemptions and the remaining request metadata.
7 · Your rights
Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21), as well as the right to withdraw consent at any time (Art. 7(3)), without this affecting the lawfulness of the processing carried out until then. To exercise any of them, write to the email address in section 1 — no particular form is required.
Two of these you can exercise directly, without asking us: erasure through Profile → Danger zone → Delete account, and portability through the file export built into the app, which is available on every plan. That file is readable plain text (JSON) and is not encrypted, and it carries your imported workouts along with everything else. That is precisely what makes it portable, and it is why you should only pass it on to a destination you trust.
You may also lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), for example the authority responsible for the federal state in which you live, or the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia, which is the authority responsible for us.
8 · Permissions (Apple Health, calendar, notifications)
8.1 Apple Health (HealthKit)
Only if you actively enable the import and iOS grants permission does My Day read completed workouts from Apple Health: type of activity, duration, energy burned and date. My Day also reads your daily exercise minutes (the AppleExerciseTime HealthKit type) — one total per day, in minutes. From 30 exercise minutes onwards My Day records that day like a workout and ticks off the exercise habit; the number is counted and displayed, not evaluated. The first import covers the last 90 days; after that only new workouts and the exercise minutes of the last seven days are read. My Day has read access only and never writes anything into Apple Health.
- Health data is never used for advertising, never sold, and never passed to a third party.
- No workout details are sent to the AI provider under section 4. What does go along is the number of the workouts you recorded today, and nothing beyond it.
- You can stop the import at any time, in the app or under Settings → Privacy & Security → Health, and delete imported workouts in the app.
Legal basis: Art. 9(2)(a) GDPR (explicit consent, revocable at any time).
8.2 Device calendar
Only after you grant permission does the app access the calendar on your device, so that your appointments appear alongside your tasks. If you edit or delete one of those events in My Day, My Day writes that change back to your device calendar. This happens solely on your explicit input, never on its own and never through the AI features, and only for calendars that iOS allows to be modified — subscribed calendars such as public holidays stay unchangeable. If you create an event in My Day yourself, My Day writes it into the calendar you pick for it — only calendars that iOS allows to be modified are offered. Access happens on the device; iOS controls it and you can withdraw the permission at any time under Settings → Privacy & Security → Calendars. Legal basis: Art. 6(1)(a) GDPR.
“Tasks in Apple Calendar” is a separate, default-off opt-in. Enabling it creates a new “My Day” calendar in your default calendar account. My Day copies its task block titles and times there when you open or use the app. Other calendars are never selected as fallback write targets. The EventKit mapping and random technical marker stay on this device, outside My Day backups and cloud sync. Apple may sync calendar copies to your other devices through your calendar account. Turning this off or switching My Day accounts removes only marked copies, preserving the calendar and manually created events. If permission is unavailable, removal waits until access is restored. My Day overwrites edits to copies within its calendar; copies moved into another calendar remain untouched.
8.3 Notifications
Reminders, the daily agenda and streak notices are local notifications: they are scheduled entirely on your device and delivered there by iOS. They do not travel over the network, we operate no notification server, no push tokens are transmitted, and we do not build audiences from them. You can revoke the permission at any time under Settings → Notifications. Legal basis: Art. 6(1)(a) GDPR.
The title of the task or the event is part of the notification itself, and a streak notice can name a single habit. That text is therefore visible on the lock screen as well, for as long as you do not restrict the preview. Two switches govern this: Hide details in the app under Profile → Notifications puts a generic word in place of the title, and iOS decides separately, under Settings → Notifications → Show previews, whether a preview appears at all while the device is locked.
9 · Children
My Day is not directed at children and we do not knowingly process the data of children. Using the app requires an account, and creating one requires full legal capacity; if you are under 16, you may only create an account with the consent of a parent or guardian (Art. 8 GDPR). If you believe that a child has created an account without that consent, write to the address in section 1 and we will delete it.
10 · Changes
We adapt this policy when the app or the services behind it change — for example when a processor is added or replaced, or when a new feature processes new data. The version published here at the time is the one that applies; the date at the top of the page shows how current it is. Where a change requires your consent, we will ask for it before the processing begins.
11 · Legal notice (Impressum)
Information pursuant to § 5 DDG:
Tilmann Pheiler
Asbeckweg 43
48161 Münster, Germany
Email: tilmann.pheiler05@gmail.com
Responsible for the content: Tilmann Pheiler (address as above). The terms of use are set out separately in the Terms.
Last updated: 12 September 2026. This version replaces all earlier ones. The German version is the binding one; this English version is a translation for information.