Daystead privacy
Last updated 6 October 2026
Short version: your board's data lives in your own Supabase project, which you create and control. This website serves the app's pages and runs the setup helper. It doesn't keep your calendar, email, tasks or health data.
What this website handles
- The app's pages. They run in your browser and talk directly to your own Supabase project and to Google.
- The setup helper. During setup or an update, your licence key, your Supabase access token, your Google sign-in client details and your Google address pass through this site's setup service once, to install the board into your project. The access token and client secret are not stored or logged. Your licence key is checked with the store you bought from (Gumroad or Lemon Squeezy).
- Your licence's board. Because each key sets up one board, we keep a one-way fingerprint of your licence key (not the key itself) together with your Supabase project's ID. That's all: it can't be used to read your board.
- Ordinary hosting logs kept by our host, Netlify (for example IP addresses and pages requested), for security and reliability.
What your board reads
- Google Calendar (read-only): upcoming events.
- Gmail (read-only, only if you turn on Orders or University): subject lines and short previews of recent order, delivery and uni emails. Email bodies aren't stored.
- Google Tasks (only if you turn it on): to keep your next actions in step.
- Strava, WHOOP, Oura, Withings and Polar (only the ones you connect in Settings): daily sleep, recovery, heart rate, weight and step summaries, and workouts. They're fetched by your own Supabase project using a developer app you create on each service; this website never sees that data or the sign-in tokens.
- Garmin Connect (only if you install the optional sync on your Mac): daily health and workout summaries.
- Weather: your chosen location (rounded to about 1 km) is sent to Open-Meteo for the forecast.
All of this is stored in your Supabase project, where only your Google account can read it. Google's sign-in token is kept server-side in your project and is never readable by the browser.
Sharing
We don't sell or share your data, and we can't see your board's data. Your purchase is handled by Gumroad or Lemon Squeezy under their own privacy policies.
Removing access and deleting data
Revoke Google access at any time at myaccount.google.com/permissions. Delete your data by deleting your Supabase project. On a device, Settings → Unlink this device removes the board from that browser.
Contact
Questions: [email protected]