Privacy Policy
· Last updated September 13, 2026
DayMirror (“we”, “us”, or “our”) is a time-audit product operated by Irfan Saeed Khan. This Privacy Policy explains what personal data we collect, why we collect it, how we use and share it, and the choices you have. It applies to https://day-mirror-mocha.vercel.app and related app experiences (the “Service”). Effective September 13, 2026.
1. Who we are
The Service is provided by Irfan Saeed Khan, operating the product DayMirror. For privacy questions, account requests, or data protection inquiries, contact us at irfansaeed.kg@gmail.com or irfansaeedkhan@protonmail.com.
If you use Google sign-in or Google Calendar with DayMirror, Google also processes data under Google’s Privacy Policy. This Policy covers our processing only.
2. Scope
This Policy covers personal data processed when you:
- visit our marketing site or guides;
- create an account (email/password or Google);
- use Tracker, Planner, Todo, Notes, Analytics, Pomodoro, Jarvis, or related features;
- connect Google Calendar;
- use voice or text AI capture, summaries, or coaching features;
- contact us for support.
It does not cover third-party websites or apps that we do not control, even if linked from the Service.
3. Data we collect
Depending on how you use the Service, we may process:
- Account data: name, email address, password hash (if you use email signup), authentication identifiers, and session information.
- Profile and settings: timezone, day-window preferences, theme or palette choices, notification preferences, and plan-tier flags used for feature access.
- Time and planning content you create: hourly logs, moods, descriptions, tasks, todos, planner entries, notes and note structure, goals, timers, and related metadata (dates, hours, completion state, links between notes and tasks).
- Google account data (if you connect Google): basic profile identifiers needed for sign-in, and, if you enable Calendar, calendar event data we import as plan context (titles, times, calendar identifiers). We treat Google Calendar events as planned commitments, not as proof of what you actually did.
- AI and voice inputs: text prompts, short audio recordings you choose to submit for transcription, derived transcripts, model outputs, and limited usage metrics (for example capture counts).
- Device and technical data: IP address, browser type, device type, approximate location derived from IP, pages viewed, referrers, and diagnostic logs.
- Communications: messages you send to support, waitlist submissions, and feedback you choose to provide.
We do not require government ID. We do not knowingly sell personal data.
4. How we use data
We use personal data to:
- create and secure your account, and keep you signed in;
- provide core product features (hourly reflection, planning, notes, analytics, reminders);
- sync and display Google Calendar events you authorize;
- run optional AI features you invoke (transcription, capture into hours or tasks, summaries, coaching suggestions);
- send product emails or push notifications you enable;
- monitor reliability, debug errors, and prevent abuse;
- improve the Service with aggregated, de-identified product analytics;
- comply with law and enforce our Terms of Service.
5. Legal bases (EEA/UK users)
If you are in the European Economic Area or United Kingdom, we process personal data under one or more of these bases:
- Contract: to provide the Service you request (account, tracker, planner, notes).
- Consent: for optional Google Calendar access, microphone access in the browser, marketing emails where required, and certain cookies or similar technologies where consent is required.
- Legitimate interests: securing the Service, preventing fraud, understanding aggregate product usage, and improving reliability, balanced against your rights.
- Legal obligation: when we must retain or disclose information to comply with applicable law.
You may withdraw consent at any time (for example by disconnecting Google Calendar, denying microphone permission, or deleting your account). Withdrawal does not affect processing already performed.
6. Google sign-in and Google Calendar
If you choose “Sign in with Google” or connect Calendar, you authorize Google to share certain information with us under Google’s terms and your Google account settings.
- Sign-in: we receive identifiers needed to create or link your DayMirror account (typically email and basic profile fields).
- Calendar (optional): with your permission we request read-only calendar access so we can show upcoming or day events inside Planner. We store event metadata needed to render and refresh that view. We do not use Google Calendar contents to train foundation models, and we do not sell Calendar data.
- You can disconnect Calendar in Settings. You can also revoke access in your Google Account security settings. Revoking stops new access; we remove or stop refreshing stored calendar cache according to our retention practices.
DayMirror’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
7. AI features and voice
Some features send content you provide (text, and optionally short voice audio) to AI providers we configure so we can transcribe speech, interpret capture requests, draft summaries, or generate coaching suggestions.
- Voice is optional. You can use the Service fully by typing. Browsers without a microphone, or users who deny permission, are supported.
- Audio is processed to produce a transcript and fulfill your request. Do not submit sensitive data you are not comfortable processing through third-party AI providers.
- Model outputs can be wrong. Treat AI suggestions as assistance, not as legal, medical, or financial advice.
- Usage limits or plan gates may apply depending on how the Service is configured at the time.
9. Service providers and sharing
We share personal data with processors who help us run the Service, under contracts that require appropriate protection. Categories include:
- cloud hosting and database providers;
- authentication infrastructure;
- AI transcription and language-model providers you trigger by using AI features;
- email or notification delivery providers;
- error monitoring and product analytics providers;
- Google, when you use Google sign-in or Calendar.
We may also disclose data if required by law, or to protect rights, safety, and security.
We do not sell your personal information, and we do not share Google user data with third parties for advertising.
10. International transfers
We and our processors may process data in countries other than where you live, including the United States and other locations where cloud or AI providers operate. Where required, we rely on appropriate transfer mechanisms (such as standard contractual clauses) or provider certifications.
11. Retention
We retain account and content data for as long as your account remains active, and for a limited period afterward if needed for backups, dispute resolution, security, or legal compliance. You may export your data and delete your account from Settings. After deletion, we remove or anonymize personal data from active systems within a reasonable period, except where retention is required by law or needed for security logs.
12. Security
We use industry-standard measures appropriate to a web application, including encrypted transport (HTTPS), access controls, and hashed passwords for email accounts. No method of transmission or storage is perfectly secure. Please use a strong unique password and protect access to your devices and email.
13. Your rights and choices
Depending on your location, you may have rights to:
- access the personal data we hold about you;
- correct inaccurate data;
- export a copy of your data (available in Settings);
- delete your account and associated app data (available in Settings);
- object to or restrict certain processing;
- withdraw consent where processing is consent-based;
- lodge a complaint with a supervisory authority.
To exercise rights that are not available in-product, email irfansaeed.kg@gmail.com. We may need to verify your identity before fulfilling a request.
14. Children
The Service is not directed to children under 16 (or the minimum age required in your country). We do not knowingly collect personal data from children. If you believe a child has created an account, contact us and we will take appropriate steps to delete it.
15. Changes to this Policy
We may update this Privacy Policy from time to time. We will change the “Effective” date above and, when changes are material, provide additional notice in the product or by email when appropriate. Continued use of the Service after an update means you acknowledge the revised Policy.
16. Contact
Privacy and data requests: irfansaeed.kg@gmail.com
Alternate contact: irfansaeedkhan@protonmail.com
Related: Terms of Service