Privacy Policy
Version 2.6 · Effective September 21, 2026
Our Commitments
This Privacy Policy describes how dechnologies, llc, a North Carolina limited liability company ("Daypiction," "we," "us"), collects, uses, and shares information when you use the Daypiction app and related services (the "Service"). It applies to everyone who uses the Service, including guest users who have not yet created an account.
Daypiction has no public feed. Your in-app canvases are visible to friends you mutually accept. Public share links and images you export can also show content to other people, as described below. We collect what we need to run the Service, and:
- We do not sell your personal information
- We do not share it for advertising, and there are no ads in the Service
- We do not use your content to train AI models
- Apple Health data is never used for advertising, marketing, or data mining
1. Information We Collect
We collect the following categories of information. Under U.S. state privacy laws these include identifiers, customer records, commercial information, network activity, geolocation (place search, places you tag, and imported workout routes), audio/visual information, health information, and limited usage inferences.
Information you provide:
- Account and profile information: account identifier, name, email, username, optional bio, and profile photo. Clerk provides account authentication
- Age and AI permission records: eligibility result, proof source, applicable policy versions, and confirmation, grant, withdrawal, or invalidation records. We use these records to enforce age and AI access requirements. The age check uses a declared age range where supported, or your confirmation. We do not retain the returned age-range bounds
- Your content: photos, notes, links, places you tag, movies/TV/books you log, workouts you import or enter manually, polls you create and the votes you cast (votes are associated with your profile and can be read by the poll owner and accepted friends who can see the poll), reactions and replies (including @mentions), and your friend connections, requests, and blocks
- Search text you type in the place/movie/TV/book pickers, sent to the relevant provider (Google Places, TMDB, OpenLibrary) to return results. Place search also sends device coordinates when location access is enabled. These requests do not add your profile name or account ID; providers receive the network information needed to answer them
- Communications you send us (support or privacy requests)
Information collected automatically:
- Usage information: screens viewed, features used, and app events through PostHog. We link signed-in activity to your account identifier and can send PostHog your available name and email. Events and diagnostics can also contain navigation paths, identifiers, and the link that opened the app
- Device and diagnostic information: device model, OS and app version, language, time zone, device identifiers, push tokens, and IP address. Sentry receives app and server errors, diagnostic context, and your account identifier when available. Expo EAS Observe receives app performance and interaction timing. Guest abuse controls use a random device-stored guest identifier, device-integrity checks where supported, and Apple's DeviceCheck flag. Apple App Attest serves iOS; Google Play Integrity requires a supported and configured Android release
- Purchase information: subscription status, purchase and refund events, and platform receipts via Apple/Google billing and RevenueCat, plus our own record of your credit balance and credit activity (credits granted, spent, refunded, and expired); we never receive your full payment card number
Our websites (daypiction.com and its share subdomains):
- Pages you view, the links and buttons you click, referring page, approximate region derived from IP address, browser and device type, via the same analytics provider (PostHog), so a visit and an install read as one funnel
- Our analytics configuration uses browser local storage for a visitor identifier. We set no advertising cookies and run no ad network. Share and install events help us understand how people reach the app
- When you view a share page or tap its install button, our website forwards your IP address and device details to our server to help connect a visit to an app install. The install-matching database stores a salted hash of the IP address. This does not describe the separate access logs or retention of our hosting and analytics providers
- Clear site data for daypiction.com and its share subdomains to reset locally stored visitor identifiers. A content blocker may block analytics requests. Do Not Track does not prevent our pages from loading the analytics script, and handling differs between the landing page and share pages
Health and fitness information (optional, iOS):
- From Apple Health, if you grant access: workouts (type, duration, date), related statistics (distance, energy, heart rate), and, where available, the workout's GPS route. You can also enter workout details manually without connecting Apple Health
- If you drop a workout onto your canvas, its details (including the route's GPS coordinates, which the app draws as a map) are stored with your other content so your canvas syncs and your accepted friends can see it
- Used only to provide this feature, never for advertising, marketing, data mining, or sale, and never shared except as necessary to provide the feature you asked for
Location:
- We do not track your device's location in the background
- With foreground location permission, the place picker reads a last-known and current position to request nearby places and bias searches through Google Places. This can happen before you choose a place. A tagged place and an imported workout can also store location with your content
2. How We Use Information
We use the information we collect to:
- Provide, maintain, and personalize the Service: your canvas, your friends' feeds, syncing, widgets, AI artwork generation, notifications you've enabled, and your preferences
- Process purchases and manage subscriptions through Apple/Google and RevenueCat, including entitlements, credit balances and allowances, and refund reversals
- Communicate with you: service messages, notifications you control, and support
- Understand and improve the Service: analytics, crash diagnostics, and research on aggregated or de-identified data
- Keep the Service safe: authentication, device integrity for guest mode, fraud and abuse prevention, enforcing limits, automated screening of uploaded photos, and moderating reported content
- Comply with law and enforce our Terms of Service
- For any other purpose disclosed at collection, or with your consent
3. AI Features
We send relevant canvas content to AI providers to make artwork. The supported providers include Google and OpenAI for images, and xAI for video where available. Related AI calls can interpret images and prepare descriptions, captions, and other text for the artwork. The selected feature and provider determine which calls occur. Google also provides automated photo safety screening.
You must meet the age requirement and grant the current AI permission before generation can run. Generation can start at your request, including during onboarding. For eligible signed-in accounts, servers can attempt overnight generation for days with at least three drops and no existing artwork card. We use your stored time zone. Availability, limits, safety checks, and processing failures can prevent completion. We do not guarantee morning delivery.
- Your words: notes, captions, reviews, poll questions, and poll option labels. We normalize whitespace and limit field lengths. Details you put in these fields can be sent to the AI provider
- Your photos: approved photo inputs and whether a photo is a panorama. Other context can include your rating as a sentiment word, the day of the week, and the season
- Workout facts: activity type, duration, distance, calories, and caption. The structured workout input excludes GPS routes, heart rate, and raw HealthKit metadata
- Catalog and link facts: movie/show titles, year, genres, keywords, synopsis, director or creator, cast, logged season/episode and season synopsis; book title, author and characters; place name and type; link title, description, author, source, kind, tags and brand color; and stored media titles, artists/shows and album details. Your associated reviews and notes can also be included
- Excluded fields: the structured input filter excludes provider artwork fields (posters, covers, album art, place photos, link thumbnails), street-address fields, separate photo-location metadata, contact names and headshots, your profile name, and the calendar date. It does not recognize and remove those details if you put them in a note, caption, or photo
- Your AI choice: Settings → AI Artwork → Make art with AI lets you withdraw permission for future processing. Work already started may finish. This permission is separate from Apple Health access and also covers automated photo safety screening. Without this permission, new photo drops cannot complete server synchronization. Turning it off does not remove photos that already reached the Service
- No training: we do not use your content or outputs to train AI models. We do not authorize our AI providers to use them for model training
- Google abuse monitoring: Google's published Cloud terms permit automated checks for suspected abuse. Google may retain a flagged prompt for up to 90 days. Authorized Google personnel may review that prompt solely to investigate suspected abuse. Google states that it does not use this data to train or fine-tune AI models
- Other provider retention: OpenAI describes default abuse-log retention of up to 30 days, with legal and safety exceptions. Its endpoint and account settings can affect other stored data. xAI describes default API request and response retention of 30 days for abuse auditing. Provider retention and safety review are separate from model training. Withdrawing AI permission does not automatically erase data from a provider's earlier processing
- We do not routinely review your content or artwork ourselves; our systems automatically screen uploaded photos for safety, and we may review specific content to investigate abuse, a report, or a legal obligation
4. How We Share Information
We do not sell personal information, and we do not share it for cross-context behavioral advertising (and have not in the preceding 12 months). We share personal information only:
- With other users: accepted friends can see your canvas content and non-anonymous poll votes. Profile fields, including your username, display name, and avatar, can also be visible to other signed-in users for discovery and on public share pages. There is no public feed
- Through sharing you initiate: anyone with a public share link can view its preview without signing in. Images you export can be saved or forwarded by recipients. Revoking a link does not erase copies or cached previews already received
- With service providers: Clerk provides authentication, Supabase provides database and storage, Vercel provides website hosting, and RevenueCat provides subscription services. PostHog provides analytics, Sentry provides error reporting, and Expo provides app infrastructure, performance diagnostics, and push delivery
- With AI providers: Google and OpenAI for artwork images and related processing, Google for photo safety screening, and xAI for available video generation. Section 3 describes inputs, choices, training restrictions, and provider retention
- With search and platform services you use: Google Places, TMDB, OpenLibrary, and Apple or Google platform services. Search requests include your query and network information; place search can also include permitted device coordinates. Our picker requests do not add your account identity. Platform services include maps, HealthKit, sign-in, distribution, billing, and push delivery where available. These services also operate under their applicable terms and privacy policies
- On your device: widgets can display stored canvas images and artwork. Notification previews can include names and reply text. People who can view your device or Lock Screen can see content shown there. Your device's widget and notification settings control those surfaces
- For legal reasons: to comply with law or legal process, enforce our Terms, prevent fraud or abuse, or protect the rights and safety of our users and the public (we report child sexual abuse material to NCMEC as required by law)
- In a business transfer (merger, acquisition, financing, or asset sale), subject to commitments materially consistent with this Policy
- As aggregated or de-identified data that no longer identifies you, which we commit to keep de-identified and never attempt to re-identify
5. Data Retention
We keep personal information as long as needed for the purposes above, based on: whether your account is active; whether the content remains on your canvas; what the feature needs; security and abuse-prevention records; how long purchase, credit, and refund records are needed for accounting and dispute purposes; and what the law requires or permits for legal claims. In general, your content persists until you delete it or your account; unclaimed guest cleanup depends on the operating schedule and can be paused, including to preserve beta accounts. Analytics, diagnostics, backups, moderation evidence, and billing records have separate retention from your active canvas content. When retention ends, we delete or de-identify the data.
For artwork generation, we keep private records of the text and reference information used in each model request. We use these records to verify generation, resolve failures, and handle support requests. The records identify selected photos and other reference images but do not contain image bytes.
Editing or deleting a drop does not erase the historical generation input record. Input content for delivered artwork remains until you delete the artwork or your account, subject to applicable preservation obligations.
Input content for failed requests or uncertain outcomes expires after thirty days. Input content for cancelled requests that never reached a provider expires after twenty-four hours. Scheduled cleanup removes expired content. Restricted evidence can remain under a separate, applicable preservation period.
Generation input records follow our backup policy. Deletion from the live service does not immediately erase every backup copy. Provider retention follows the separate terms described in Section 3.
6. Your Rights and Choices
In-app and device controls: edit your profile, delete drops, remove or block connections, control notification categories, and manage the app's photo, camera, and Health permissions in iOS/Android settings.
Account deletion: you can delete your account in the app's Settings, or by emailing contact@daypiction.com. The deletion workflow removes your account, profile, and associated canvas records and attempts to remove stored content files. File-cleanup failures can leave residual copies for follow-up. It does not automatically erase separate provider, diagnostic, billing, backup, or legal-hold records. Images others have saved can remain outside the Service.
Depending on applicable law, you may have rights to access, obtain a portable copy, correct, or delete your personal information. You may also have rights concerning sensitive-data use and freedom from discrimination for exercising your rights. We do not sell personal information or share it for cross-context behavioral advertising. The disclosures in Section 4 still occur to provide and protect the Service.
To exercise rights, email contact@daypiction.com. If you have an account, use its email address where possible. Guests, website visitors, and people without account access can also contact us. Describe your request and your connection to the information. We may request information needed to verify your identity or authority. You do not need to create an account to submit a request.
An authorized agent may act with your signed permission, subject to applicable verification requirements. We respond within the time the law requires, generally 45 days. If we deny a request, you may appeal by replying with 'Appeal' in the subject line. If we deny the appeal, you may contact your state Attorney General.
7. Children
The app is only for adults age 18 or older. We do not knowingly permit anyone under 18 to hold an account or use guest mode. If we identify an under-age user, we promptly terminate access and delete their personal information, except records we must retain by law.
An adult's content can contain information about other people, including children. Contact contact@daypiction.com about an under-age user or a child's information in content. We review the request under the applicable privacy and safety requirements.
8. Consumer Health Data
Health data can come from Apple Health, manual workout entries, or other content you provide. Apple Health permission controls future HealthKit reads. It does not control every use of health-related content that you add to the Service.
Our separate Consumer Health Data Privacy Policy describes the categories, sources, purposes, recipients, and rights for this information. Read it at https://dev.daypiction.com/consumer-health-data. It applies alongside this Privacy Policy.
9. Security
We use administrative and technical safeguards designed to protect personal information: encryption in transit, access controls and row-level authorization on our database, short-lived signed URLs for private images, and device-integrity attestation for unauthenticated flows. However, no method of transmission or storage is 100% secure, and we cannot and do not guarantee absolute security. Keep your device and sign-in credentials secure.
10. Where Processing Happens
We are based in the United States and the Service is currently offered to users in the United States. We use processors with global infrastructure, including a global Google AI endpoint. We do not guarantee that all processing or storage occurs within the United States. If we later offer the Service in other regions, we will update this Policy accordingly.
11. Changes to This Policy
We may update this Policy from time to time. If we make material changes, we will notify you in advance through the app and/or the email on your account and update the effective date. Material changes will not retroactively reduce your rights with respect to previously collected data without any consent the law requires. Prior versions are archived and available on request.
12. Contact Us
Privacy requests and questions: contact@daypiction.com
4030 Wake Forest Road STE 349, Raleigh, NC 27609 USA