DayMapr Privacy Policy
Effective: April 18, 2026
DayMapr ("we," "our," or "the app") is a personal task and habit management app built for people with ADHD. This policy explains what data we collect, how we use it, who we share it with, and the choices you have. We keep this short on purpose.
Who we are
DayMapr is operated by Michael Cerdeiros. You can reach us at hello@daymapr.com.
What we collect and why
- Account info. Your email address, display name, and authentication credentials. Used to sign you in, sync your data across devices, and send you transactional email (receipts, password resets, important account notices).
- Profile content you enter. Your wake/sleep times, biggest struggle, life stage, notification preferences, and any people, pets, medications, therapy appointments, doctors, vehicles, home details, subscriptions, routines, habits, chores, tasks, and brain-dump notes you choose to add. Used to power the app's features and personalize your dashboard.
- Usage and diagnostic data. Anonymous events describing how you use the app (screens visited, features tapped, session length), device type, OS version, and crash reports. Used to fix bugs, prioritize features, and improve performance. You can turn this off at any time in Settings → Analytics.
- Purchase data. If you subscribe, our payments provider records your subscription status, renewal date, and store receipt. We do not receive your credit card number.
- Calendar (optional). If you grant Calendar access, DayMapr reads your upcoming events on-device to show them on your timeline and detect routine patterns. Calendar event content is not uploaded to our servers.
- Notifications (optional). If you grant Notifications access, we deliver reminders for tasks, habits, and routines.
What we do not collect
- We do not collect your precise or coarse location.
- We do not access your Contacts, Photos, Microphone, or Camera.
- We do not collect browsing history or search history from outside the app.
- We do not sell your data to anyone, ever.
- We do not use your data for advertising and DayMapr does not display third-party ads.
Third parties that process data on our behalf
We use the following sub-processors strictly to operate the app. Each is bound by its own privacy and security terms.
- Supabase — hosting, database, and authentication. Stores your account and profile data.
- PostHog — anonymous product analytics and crash reporting. Data is pseudonymous and tied to a DayMapr-generated ID, not to third-party advertising networks. Opt out in Settings → Analytics.
- RevenueCat — subscription management. Receives your store receipt and subscription status.
- Resend — transactional email delivery. Receives your email address when we need to send you an account-related message.
- Apple — App Store payments, push notifications, and iOS system services.
Tracking
DayMapr does not track you across apps or websites owned by other companies for advertising purposes. We do not use the Identifier for Advertisers (IDFA). We do not share identifiers with data brokers.
Your rights and choices
- Access or export your data. Email hello@daymapr.com and we will send you a copy of your account data within 30 days.
- Delete your data. Tap Settings → My Profile → Delete Account inside the app, or email us. Deletion is permanent and takes effect within 30 days across all systems.
- Turn off analytics. Settings → Preferences → Analytics.
- Turn off manifestation content. Settings → Preferences → Manifestation.
- Revoke Calendar or Notification permissions. iOS Settings → DayMapr.
Data retention
We retain your account data for as long as your account is active. Anonymous usage and crash data is retained for up to 12 months. When you delete your account, we remove your personal data from production systems within 30 days; residual backups are purged on the normal backup rotation (up to 90 days).
Children
DayMapr is not directed at children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, contact us and we will delete it.
International users
DayMapr is operated from the United States. If you use the app from outside the U.S., you consent to the transfer and processing of your data in the U.S. We apply the same protections to all users regardless of location.
California residents (CCPA)
California residents have the right to know what personal information we collect, to request deletion, and to opt out of the sale of personal information. We do not sell personal information. To exercise these rights, email hello@daymapr.com.
EU/UK residents (GDPR)
If you are in the European Economic Area or the United Kingdom, you have the right to access, correct, delete, restrict processing of, or port your personal data, and to object to processing. Our legal basis for processing is (a) performance of our contract with you, (b) your consent for optional features like analytics and manifestation content, and (c) our legitimate interests in securing and improving the app. Contact hello@daymapr.com to exercise any of these rights. You may also lodge a complaint with your local supervisory authority.
Security
We use industry-standard encryption in transit (TLS) and at rest for data stored with our sub-processors. No system is perfectly secure; we will notify affected users and regulators of any confirmed breach within required timeframes.
Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify you in the app or by email. The "Effective" date at the top reflects the current version.
Contact
hello@daymapr.com
DayMapr is a product of Michael Cerdeiros. © 2026.