Last updated: July 13, 2026
With your permission, Daybard may read or write local data through Apple APIs:
This local data stays on your device unless you explicitly enable a cloud integration or server-backed feature.
For certain optional features, Daybard creates a technical identifier and API key stored in the device keychain. This lets the app call our backend without a user password. This identifier is used for integrations, Openings booking links, and shared features such as guilds.
If you connect a third-party service, Daybard processes only the data needed for that integration:
OAuth tokens are encrypted before storage. For Google Calendar, the server-side event cache is also encrypted before storage. Integration data is used to display, sync, and automate your Daybard experience; it is not sold, used for advertising, or shared with data brokers.
Daybard requests only the Google Calendar permissions needed for enabled features: view the calendar list, read events, and act on events from calendars you own when you request an action from Daybard.
Google Calendar data processed by Daybard may include calendar names, calendar identifiers, event titles, dates, times, time zones, locations, descriptions, Google Meet links, event links, organizers, attendees, invitation status, response status, event identifiers, and recurrence information. Daybard uses this information to display your schedule in calendar and RPG views, detect meeting links, sync changes, create a Google Meet event when you ask, delete an event you created through Daybard, or respond to an invitation from the app.
Daybard does not use Google user data for advertising, targeting, resale, data brokerage, credit-worthiness, or training general AI models. Google user data is transferred to third parties only when strictly necessary to provide the service, such as to our hosting, key-value database, and backend infrastructure providers.
Daybard's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Daybard protects sensitive data, including Google Calendar data, through appropriate technical and organizational safeguards. Communications with our backend and Google APIs use HTTPS. Google OAuth tokens are encrypted at rest before storage using authenticated encryption. Server-side Google Calendar caches are also encrypted at rest. Encryption keys and OAuth secrets are kept in the server environment, not in public code or in the mobile app.
Access to Google user data is limited to the backend components required for the Google Calendar integration. We follow the principle of least privilege, request only the scopes required by available features, and revoke or delete associated tokens and caches when you disconnect Google Calendar. Data is not kept longer than necessary to operate the integration and can be deleted upon request.
You can disconnect an integration from Daybard settings. Disconnecting removes associated tokens and caches; for Google Calendar, Daybard also asks Google to revoke the token. You can also remove access from your Google, Todoist, Notion, or Linear account.
Uninstalling the app deletes local data. iCloud data is managed from your Apple account's iCloud settings.
Your game progress may be saved in your private iCloud space through your Apple account, so you can recover it after a reinstall or on another device.
Daybard uses Vercel and Upstash/Vercel KV to host its optional backend and store data strictly required for integrations. To display weather, the app may send approximate coordinates to Open-Meteo.
You may request access, deletion, or correction of data associated with Daybard services by contacting us.