Privacy Policy
⚠️ DRAFT — NOT YET IN EFFECT. This document is a working draft containing placeholder values (shown in
[BRACKETS]) and has not been reviewed by a lawyer. It is provided for preview only and is not legally binding until finalised and published with an effective date.
Effective date: 06-06-2026
In short: DailyRealm is an ADHD-focused productivity and health app. This policy explains what data we collect, how we use it, who we share it with, and the controls and rights you have. We treat your health data as sensitive, we never sell your personal data, and you can contact us any time at kush@dailyrealm.co.in.
This Privacy Policy applies to the DailyRealm mobile apps (Android and iOS), the web companion app at https://app.dailyrealm.co.in, and the marketing website at https://dailyrealm.co.in (together, the "Service").
1. Who this policy is for
In short: This applies to everyone who uses DailyRealm. We are based in India, and we also serve users outside India.
Our primary market is India, and our servers are located in Mumbai (AWS ap-south-1 region). The Service is also available to international users. Depending on where you live, you may have additional rights described in Section 13 (India), Section 14 (EU/UK), and Section 15 (United States).
2. The short version of what we collect
In short: Account info, your profile and onboarding answers, your tasks ("quests") and game progress, your health entries, basic usage and device data, and login tokens.
The detailed breakdown is in the next section. We only collect what we need to run the Service and the features you choose to use.
3. Data we collect
In short: Here is every category of data, grouped by type, with examples.
3.1 Account data
- Display name
- Email address
- Password — stored only as a bcrypt hash. We never store or see your plain-text password.
- Your chosen character class
3.2 Profile and onboarding data
- Wake-up time (used to send one daily reminder)
- Your first-quest goal
- Height
- Goal weight
- Activity level
- Timezone
- Onboarding status
- Pinned achievements
3.3 Productivity data
- Quest titles, descriptions, tags, difficulty, and timestamps
- XP, levels, streaks, and achievements
3.4 Health data (sensitive / special category)
We treat the following as sensitive personal data. See Section 4 for how we protect it.
- Weight, BMI, blood pressure, heart rate, blood sugar, HbA1c, cholesterol
- Sleep hours, water intake, steps, mood
- Workout logs
- Medical appointment entries (for example: GP, dental, eye, blood test, specialist)
3.5 Usage and analytics data
- Events about how you use the app (for example, which features you open)
- Basic device and log data (for example, device type, app version, crash logs, IP address)
3.6 Authentication tokens
- JWT access tokens and refresh tokens used to keep you signed in securely
4. How we handle your health data
In short: Your health values are encrypted and never written to our logs. One optional feature shares summarised health trends with OpenAI to create a supportive plain-language report.
We know health data is personal, so we give it extra protection:
- Encrypted at rest. Health values are encrypted when stored.
- Never logged. Health values are never written to our application logs.
- Consent first. We only process your health data after you give explicit consent, and you can withdraw that consent at any time (see Section 11).
Weekly AI Health Report (optional)
If you turn on the Weekly AI Health Report, we send summarised health trends (not your raw record history) to our third-party AI provider, OpenAI, so it can generate a supportive, plain-language summary for you.
- This is an optional feature you control.
- OpenAI processes this content to produce your summary. We instruct our AI providers not to use your content to train their models, to the extent their service terms allow.
- The AI summary is for general wellbeing support only. It is not medical advice or a diagnosis (see our Terms of Service medical disclaimer).
- You can turn this feature off at any time, which stops future sharing.
5. How we use your data and our legal bases
In short: We use your data to run the app, personalise the game, deliver AI features, generate health insights, handle subscriptions, show ads to free users, send limited notifications, and keep the Service secure. Each use has a legal basis.
| Purpose | What this means | Legal basis |
|---|---|---|
| Provide the Service | Create your account, store your quests, sync across devices | Performance of a contract |
| Personalise gamification | XP, levels, streaks, achievements, quests tailored to you | Performance of a contract; legitimate interests |
| Deliver AI features | Quest Decomposer task breakdowns | Performance of a contract |
| Generate health insights | Weekly AI Health Report and health trends | Explicit consent (sensitive data) |
| Process subscriptions | Manage Pro billing, renewals, receipts (once enabled) | Performance of a contract |
| Show ads to free-tier users | Ads displayed only to free accounts | Consent and/or legitimate interests, as required by law |
| Send limited notifications | Up to ~2 per day, paused during active tasks | Consent (push) and/or legitimate interests |
| Product analytics | Understand and improve features | Legitimate interests (or consent where required) |
| Security and fraud prevention | Protect accounts and the Service | Legitimate interests; legal obligation |
Where we rely on consent — including for all sensitive health data — you can withdraw it at any time without affecting processing that already took place.
6. Third-party services and sub-processors
In short: We use trusted providers to run DailyRealm. Some process data outside India. We list them all here.
Currently in use
| Provider | Purpose | Data location notes |
|---|---|---|
| Supabase | PostgreSQL database hosting | India (ap-south-1) |
| Upstash | Redis caching | May process data outside India |
| OpenAI (GPT-4o-mini) | AI task breakdown ("Quest Decomposer") and Weekly AI Health Report; relevant content is sent for processing | Processes data outside India (e.g. USA) |
| Railway | Backend / API hosting | May process data outside India |
| Vercel | Web app and marketing site hosting | May process data outside India |
| Expo | Mobile app build/delivery and push notifications | May process data outside India |
| Email delivery provider | Transactional email from noreply@dailyrealm.co.in | May process data outside India |
Planned / future (may apply once enabled)
These are not active yet. We will update this policy and, where required, ask for your consent before they go live.
- Razorpay — payments in India
- Stripe — international payments
- RevenueCat + Apple App Store / Google Play billing — in-app subscriptions
- Google AdMob — ads shown only to free-tier users
- Apple HealthKit & Google Fit — optional health import
- Google Calendar & Apple Calendar — optional calendar sync
We require our sub-processors to protect your data and to use it only to provide their service to us.
7. International data transfers
In short: Some providers process data outside India. When that happens, we put legal safeguards in place.
Although our primary database is in Mumbai (ap-south-1), some of the sub-processors listed in Section 6 may process your data in other countries (for example, the United States). When personal data leaves India or the EU/UK, we rely on appropriate safeguards such as Standard Contractual Clauses or equivalent contractual and technical protections, as permitted by applicable law.
8. Notifications
In short: We send a small number of helpful notifications, and you can control them.
We send up to about two notifications per day, and we pause notifications while you have an active task running so we don't interrupt your focus. You can turn push notifications off in your device settings, and you can opt out of marketing emails at any time (see Section 11).
9. Children and minimum age
In short: You must meet our minimum age to use DailyRealm. We require parental consent for eligible minors.
You must be at least 13+ to use the Service.
- If our minimum age is set so that minors may use the Service, we will obtain verifiable parental or guardian consent before processing a child's personal data, as required by the DPDP Act, 2023.
- We do not knowingly process the personal data of children below the permitted age without verifiable parental consent.
- We do not use children's data for tracking, behavioural monitoring, or targeted advertising.
- If you believe a child has provided us data without proper consent, contact us at kush@dailyrealm.co.in and we will delete it.
10. How long we keep your data
In short: We keep your data while your account is active, and delete it after you close your account, except where the law requires us to keep some records.
- We retain your personal data for as long as your account is active and as needed to provide the Service.
- When you delete your account, we delete or anonymise your personal data within 30 days, except where we must keep certain records to meet legal, tax, accounting, or security obligations.
- Backups are deleted on a rolling schedule and may persist for a short period after deletion before being overwritten.
11. Your rights and controls
In short: You can access, correct, export, and delete your data, withdraw consent, disconnect integrations, and opt out of marketing. Email us and we'll help.
Depending on where you live, you have some or all of these rights:
- Access — get a copy of the personal data we hold about you.
- Correction — fix data that is inaccurate or incomplete.
- Deletion — delete your account and associated data.
- Data export / portability — receive your data in a portable format. (CSV/PDF export is a planned Pro feature.)
- Withdraw consent — for example, turn off the Weekly AI Health Report or stop health-data processing.
- Disconnect optional integrations — for example, "Disconnect Health App" to stop HealthKit / Google Fit, or disconnect calendar sync (once enabled).
- Opt out of marketing — unsubscribe from marketing emails at any time.
How to exercise your rights
Email kush@dailyrealm.co.in with your request. We may need to verify your identity. We aim to respond within 30 days, or sooner where the law requires. We will not charge a fee for reasonable requests.
12. Security
In short: We use strong, standard security measures, but no system is ever 100% secure.
- Authentication: JWT-based, with short-lived access tokens (15 minutes) and refresh tokens (30 days).
- Passwords: hashed with bcrypt; we never store plain-text passwords.
- In transit: encrypted using TLS.
- At rest: health data is encrypted at rest, and health values are never written to our logs.
We work hard to protect your data, but no method of transmission or storage is completely secure. We cannot guarantee absolute security. If we become aware of a data breach affecting you, we will notify you and the relevant authorities as required by law.
13. India — your DPDP rights
In short: Under India's DPDP Act, 2023, you consent to our processing, you can withdraw consent, and you can raise a grievance with our Grievance Officer or complain to the Data Protection Board of India.
If you are in India, the Digital Personal Data Protection Act, 2023 ("DPDP Act") applies:
- We process your personal data based on your explicit consent (and, for some processing, other lawful grounds permitted by the Act).
- For sensitive health data, we obtain your explicit consent before processing.
- You can withdraw consent at any time by emailing kush@dailyrealm.co.in. Withdrawal is as easy as giving consent.
- You have the rights to access, correction, and erasure of your data, and the right to nominate another person to exercise your rights in case of death or incapacity.
14. EU / UK — your GDPR rights
In short: If you are in the EU or UK, you have full GDPR rights and we apply transfer safeguards.
You have the rights to: access, rectification, erasure ("right to be forgotten"), restriction of processing, data portability, objection to processing, and to not be subject to solely automated decisions with legal effects. You also have the right to withdraw consent and to complain to your local data protection authority.
Our legal bases are described in Section 5. Where we transfer your data outside the EU/UK, we use the safeguards described in Section 7. Retention is described in Section 10.
15. United States — CCPA / CPRA
In short: We do not sell or share your personal data. California residents have specific rights.
- We do not sell your personal data, and we do not "share" it for cross-context behavioural advertising as those terms are defined under the CCPA/CPRA.
- If you are a California resident, you have the right to know what we collect, to request deletion, to request correction, and to not be discriminated against for exercising your rights.
- To exercise these rights, email kush@dailyrealm.co.in.
16. Changes to this policy
In short: If we make important changes, we'll tell you.
We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the app, by email, or by posting a notice on our website before the changes take effect. The "Effective date" at the top shows when this version was last updated.
17. Contact us
For any privacy questions or requests, contact:
- Email: kush@dailyrealm.co.in
This document is a template and not legal advice; have it reviewed by a qualified lawyer before publishing.