Privacy Policy
Last updated: 2026-09-08 · version 1.4
This Policy explains how Asc Systems Tecnologia Ltda handles your personal data when you use DayAlly, in accordance with Brazil's General Data Protection Law (Law No. 13.709/2018 — LGPD). This is a convenience translation; the Portuguese (Brazil) version prevails.
1. Who controls your data
The controller of the personal data processed in DayAlly is Asc Systems Tecnologia Ltda, registered under CNPJ No. 65.129.095/0001-93.
For any matter regarding this Policy or the exercise of your rights, contact us at: [email protected].
2. What data we collect
Account and identification data: name, email and profile picture provided by your login provider (Google or Microsoft), plus time zone and language.
Content you create: tasks, events, projects, categories, habits and notes, including titles, descriptions, dates and locations.
Conversations with the AI assistant: the messages you exchange with the chat and the text produced from voice commands.
Calendar integration data: when you connect Google Calendar or Microsoft Outlook, we access your events and store, in encrypted form, the access tokens required for syncing.
Payment data: when you subscribe to a paid plan, processing is handled by Stripe. We do not store your card details — only subscription identifiers.
Technical data: information required for operation and security, such as access logs and push notification identifiers.
3. Sensitive data (health data)
The habits module and the AI assistant may, depending on what you record, contain data related to your health (for example, sleep, exercise, medication or well-being). Under the LGPD, these are sensitive personal data (art. 5, II).
We process such data solely on the basis of your specific, highlighted consent, requested on first use, and only for the purposes described in this Policy.
You may withdraw this consent at any time by ceasing to use these features and requesting deletion of the related data.
4. Why we use your data and on what legal basis
To perform the contract and provide the service (art. 7, V): to create and maintain your account, organize your tasks, events and habits, and sync calendars.
Consent (art. 7, I and art. 11, I): to process health data and send content to the AI to generate responses, summaries and suggestions.
Compliance with legal obligations (art. 7, II): retention of records required by law.
Legitimate interest (art. 7, IX): security and fraud prevention, always respecting your rights. Data obtained from connected calendars is not used for this purpose beyond what is necessary to provide and protect the application's own features.
5. Sharing with third parties and international transfer
To operate DayAlly, we share data with processors that handle it on our behalf, as needed:
- OpenAI (USA): receives the content you send to the AI assistant (chat messages, voice audio and a summary of your tasks and events) to generate responses and summaries. OpenAI does not use this data to train its models by default via the API.
- Stripe (USA): processes payments and subscriptions.
- Google and Microsoft: when you connect your calendars.
- Push notification providers of your browser or device.
- Sentry (USA): receives automatic application error reports containing the technical error message, the address of the screen where it occurred, browser information and an internal identifier of your account. We do not send your name, email or the content of your tasks, events or conversations.
- Meta (USA): receives measurement of the site's PUBLIC PAGES and notice that an account was created, so that we can measure the results of our ads. It receives the ad click identifier, IP address, browser, and a scrambled code that represents your account only within our systems. We do NOT send your name, email, phone number or any application content.
- Google Analytics (USA): measures usage of the site's PUBLIC PAGES (the home page, the Help Center, the Terms and this Policy). It receives approximate location, browser type and the pages visited by people browsing those pages. It is not used on the application screens after you sign in: nothing you do inside DayAlly is sent to it.
- Resend (USA): sends the service emails (welcome, notices about your trial period, subscription and account deletion confirmations). It receives your email address and the content of those messages. Delivery runs on servers located in Brazil (São Paulo region).
Some of these processors are located outside Brazil. In such cases, the international transfer takes place with the safeguards required by the LGPD (art. 33), including data protection contractual clauses.
We do not sell your personal data.
6. Data from connected calendars
When you connect an external calendar (Google Calendar or Microsoft Outlook), DayAlly accesses that data exclusively to provide and improve the user-facing features within the application.
- This data is not used for advertising, marketing, profiling or any purpose unrelated to the application's features.
- It is not sold or transferred to third parties, except to the processors strictly necessary to provide the functionality you requested.
- It is not used to create, train or improve foundational or generalized artificial intelligence models. When you use the AI assistant, event titles and times may be sent to OpenAI solely to generate the response you requested at that moment.
- It is not read by humans, except with your explicit consent, for security purposes, or when required by law.
Specifically regarding Google APIs: the use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
7. Cookies
Inside the application, after you sign in, we use only strictly necessary cookies: the session cookie (to keep you signed in) and the language preference cookie. No third-party measurement runs there.
On the site's public pages — the home page, the Help Center, the Terms and this Policy — we use Google Analytics and Meta to understand how they are used and to measure the results of our ads. That is why we show a notice there asking whether you accept. Until you accept, no measurement cookie is stored in your browser, and a refusal is remembered on your next visits.
Being transparent about the limits of that: even without your acceptance, loading the page sends Google a cookieless record, which cannot recognise you across visits or across pages. What your acceptance controls is the cookie — and, with it, the ability to link one visit to the next.
Some of these cookies are advertising cookies. They serve two purposes: measuring the results of the ads we buy on Google and Meta — knowing whether someone who clicked one of our ads reached us — and allowing those ads to be shown to you again on other sites and applications if you have visited this page. This is commonly called remarketing.
Two limits that always apply: we do not display anyone's ads inside DayAlly, and nothing you do AFTER signing in — your tasks, your calendar, your habits, your conversations with the assistant — feeds any advertising. Advertising only reaches people browsing the public pages of the site.
8. How long we keep your data
We keep your data for as long as your account exists. When you delete your account, the associated data is permanently erased, except for records the law requires us to keep for a set period.
You may clear specific data (such as chat history or habits) at any time in the settings.
9. Security
We adopt technical and organizational measures to protect your data (art. 46 of the LGPD), including encryption of integration tokens, access control, data isolation between users and secure channels (HTTPS).
10. Your rights as a data subject
Under art. 18 of the LGPD, you may at any time: confirm the existence of processing; access your data; correct incomplete or outdated data; request deletion of your account and data; request data portability; and withdraw consent.
Many of these rights can be exercised directly in the app (profile and content editing, account deletion and data export). For the others, use the contact channel below.
11. How to exercise your rights and reach the data protection officer
To exercise your rights or ask privacy questions, contact us at: [email protected]. We will respond within the period set by law.
12. Changes to this Policy
We may update this Policy from time to time. When there are material changes, we will notify you and, where applicable, request renewed consent. The date of the last update is shown at the top of this document.