Privacy Policy
Last updated: 8 September 2026
Last updated: 8 September 2026
The short version. We collect the least data our products can work with. We do not sell personal data and we never have. We do not use your content to train third-party AI models, and we do not track you across other companies' apps and sites. You can ask us at any time what we hold about you, and ask us to delete it, by writing to hello@dayantech.com.br.
This site and the products listed on it are operated by RAPHAEL BORGES DE ANDRADE DAYAN CONSULTORIA EM TECNOLOGIA DA INFORMACAO LTDA, trading as DayanTech, a limited company registered in Brazil with D-U-N-S Number 579119303, registered at Rua Pais Leme, 215, Conj. 1713 — São Paulo, SP, 05424-150, Brazil.
For the purposes of the Brazilian General Data Protection Law (LGPD, Law 13.709/2018) and the EU General Data Protection Regulation (GDPR), we are the controller of the personal data described below. Our contact point for all privacy matters is hello@dayantech.com.br.
This policy applies to this website and to the DayanTech mobile applications and web products listed on our products page. If you choose to use our software, you agree to the collection and use of information in accordance with this policy. The personal information we collect is used to provide and improve the software, and we will not use or share it with anyone except as described here.
Individual apps that collect more than what is described here ship their own, more specific privacy notice, linked from their App Store or Google Play listing and from inside the app. Where an app-specific notice exists, it governs that app; this policy covers everything else.
This policy does not cover third-party websites we link to. When you leave one of our products, the destination site's own policy applies.
You do not need an account to browse this website. The table below is the complete list of what we may process across our products, using the same categories Apple uses on App Store privacy labels so you can compare them directly.
| Category | What it is | Why we process it | Linked to you? |
|---|---|---|---|
| Contact info | The email address and any name you type when you write to us. | To answer your message and keep a record of the request. | Yes |
| Account info | In products that offer accounts: email address, sign-in provider and an authentication token; optionally a display name, profile picture, language and time zone. We never store passwords in readable form. | To create your account, sign you in, and restore your data on a new device. | Yes |
| User content | Notes, photos, files and entries you create inside an app. Several of our apps are local-first: your content stays on your device unless you turn on sync. | To provide the feature you are using and, with sync on, to make it available on your other devices. | Yes |
| Purchases | Subscription status and receipt validation. Payments run through Apple, Google or our payment provider — we never see or store your card details. | To unlock paid features and handle refunds and billing questions. | Yes |
| Usage data | Pages or screens opened, features used, which step of a flow happened, approximate country, referring site, session length. | To understand which parts of a product are useful and to plan what to fix next. | No |
| Diagnostics | Crash reports, error type, performance timings, device model and operating system version. | To find and fix bugs and crashes. | No |
| Identifiers | A random installation or session identifier, and your account identifier where you have an account. | To count sessions accurately and to attach a crash report or a funnel to a person rather than to a ghost. | No |
To know where people get stuck and whether an app is breaking, we use two tools across our products:
Both receive your account identifier where you have one, so that an error or a funnel can be tied to a person rather than to a ghost. We do not track you across other companies' apps or websites, we do not run advertising, and we do not sell data to anyone.
Where a product has an AI feature, the specific content you submit for that feature leaves your device so a model can produce your result. It travels through our own server, which holds the API keys and does not store the text, to a model provider under a contract that forbids the provider from using it to train models. Our server logs only numbers per call — tokens in and out, cost, latency, which model answered, and whether it failed — never the content. The app-specific notice for that product names the provider and asks for your explicit permission before the first use.
We share personal data only with service providers who process it on our instructions, under a data processing agreement, and only to the extent they need it to do their job:
| Provider | What it receives | Where |
|---|---|---|
| Hostinger | website hosting and email delivery | Brazil / European Union |
| Supabase | account and the synced copy of your content | United States |
| Vercel | API traffic in transit, not stored | United States |
| PostHog | usage events, no content | United States |
| Sentry | errors and crashes, no content | United States |
| Google Analytics | anonymised website usage, only after you accept analytics cookies | United States |
| RevenueCat · Apple · Google | subscription status | United States |
| AI model providers | only the content you submit to an AI feature, never for training | United States |
We may also disclose data where we are legally required to, or to establish, exercise or defend a legal claim. If DayanTech is ever involved in a merger or acquisition, we will tell users before their data is transferred and honour this policy until it is replaced by an equivalent one.
We are established in Brazil and several of the providers above operate in the United States and the European Union. This is an international transfer of data under articles 33 to 36 of the LGPD, and it happens under contractual data protection clauses. For transfers out of the European Economic Area we rely on the European Commission's Standard Contractual Clauses.
| Data | Retention |
|---|---|
| Support emails | 24 months from the last message in the thread. |
| Account and user content | For as long as the account exists. After you delete the account there is a 30-day grace period in which signing back in cancels the deletion; after that it is erased for good. |
| Diagnostics and crash reports (Sentry) | 90 days. |
| Usage events (PostHog) | Up to 12 months, without content. |
| Website analytics (Google Analytics) | Up to 14 months, in a form that does not identify you. |
| Billing and tax records | As long as Brazilian tax law requires, currently five years. |
Traffic to our sites and APIs is encrypted with TLS. Data at rest is encrypted by our infrastructure providers, and a row-level rule in the database prevents any account from reading another account's rows. Access to production systems is limited to the people who need it, protected by two-factor authentication, and reviewed periodically. Several of our apps are local-first by design: your content stays on your device unless you explicitly turn on sync.
If a breach ever puts your rights at risk, we will notify you and the Brazilian data protection authority (ANPD) — and, where the GDPR applies, the relevant supervisory authority — within the deadlines the law sets.
Wherever you live, you can ask us to:
Write to hello@dayantech.com.br. We answer within 15 days, the deadline set by the LGPD, and always within 30 days where the GDPR applies. We may ask you to confirm your identity before acting on a request, so that nobody else can use it against you.
If you are not satisfied with our answer, you may complain to the Brazilian data protection authority (ANPD) at gov.br/anpd, or to your local supervisory authority in the EU/UK.
Our products are not directed to children under 13, and we do not knowingly collect personal data from them. Where an app is designed for families, it is rated accordingly in the store and follows the applicable children's privacy rules, including the App Store Kids Category requirements and COPPA. If you believe a child has given us personal data, write to hello@dayantech.com.br and we will delete it.
This website sets two kinds of cookies and similar storage:
You can change your mind at any time by clearing this site's storage in your browser, which brings the notice back. We do not use advertising or cross-site tracking cookies on this website.
When we change this policy we update the date at the top of the page. If a change materially affects your rights we will announce it on this site and, where we can reach you, by email before it takes effect.
RAPHAEL BORGES DE ANDRADE DAYAN CONSULTORIA EM TECNOLOGIA DA INFORMACAO LTDA