Privacy Policy
You tell this app what you ate. That is health information, and it is treated as such: it is not sold, not used for advertising, not analysed for anyone but you, and it leaves the server only where the feature you asked for cannot work otherwise.
Last updated 14 September 2026
1. Who is responsible
Day So Far is built and run by Nikolay Lyutov, an individual established in the European Union. For the purposes of the GDPR that makes me the data controller for everything described here.
Write to support@daysofar.com about anything on this page. It is a real inbox, read by one person.
This policy covers the hosted service at daysofar.com and the Day So Far apps for iOS and Android. Day So Far is also open source and can be run on your own server; if you are using somebody else’s installation, this policy does not describe it and whoever runs that server is responsible for it.
2. What is recorded
Because you have an account
- Your email address, and a hash of your password — never the password itself.
- If you sign in with Google: Google’s permanent id for your account, and the address it reports. Nothing else from your Google account is requested or received.
- Sign-in sessions, which expire 60 days after they are created.
Because you asked for a calorie target
- Sex, date of birth, height, activity level, goal, target weight.
- Your timezone and the hour your day starts, which is how a 1am snack lands on the right day.
- Any dietary rules you set, and your unit preference.
- If you turn notifications on, a push token for that phone — the address a reminder is delivered to, and nothing that describes you. It is deleted when you turn them off, sign out, or delete the account.
If you let the app count your steps
- A daily step count, and nothing else. No location, no route, no map, and no continuous tracking — the app asks for one number per day, when you open it, and asks for nothing while it is closed. On an iPhone it comes from the phone’s own motion sensor; on Android it is read from Health Connect, which holds what other apps — Samsung Health, Fitbit — have already recorded. Only the step count is read, and nothing is ever written back.
- It is off until you turn it on, from the Steps card on Today, and your phone asks you before the first reading. Withdrawing it — in iOS Settings, or in Health Connect on Android — stops new days arriving; the days already recorded are deleted with your account like everything else, or on request.
- What it is used for: setting your calorie target from what you actually do rather than from the activity level you picked when you signed up, and giving the assistant something better to say about a plateau than “eat less”. Steps are never converted into calories and never added to what you may eat.
- Steps travel to Anthropic with the rest of today’s totals, as a count and a date, whenever you send a message. See section 4.
Because logging is the product
- Every meal, with its items, quantities and nutrition estimates.
- Photos of food you upload, and any barcode you scan.
- Exercise, workouts and weight entries.
- The conversation itself — what you typed, or dictated, and what the assistant answered — kept as a record separate from the meals it produced. A dictated meal is stored as the words it became; the recording is never sent here and never kept.
- Recipes, meal plans, shopping lists and pantry items you create.
Because a server has to defend itself
- For each device that signs in: a fingerprint of it, its browser or app user agent, and the IP address it was last seen at. This is what makes the “new sign-in” email able to say where from. It is deleted with your account.
- IP addresses in the web server’s logs and in the rate limiter’s counters, held briefly and used for nothing but throttling and abuse.
- The token and time cost of each AI turn. What the app costs to run is the question that decides whether it keeps existing.
Before there is an account
- Which screens of the first-run questions a new install reaches — the welcome screen, each question, the plan, the sign-up form — as a count per day, per platform and app version. Nothing identifies the phone or the person: no device or install id, no account, no address is stored with it, and each screen is sent at most once. It tells us where people give up, and it cannot tell us who.
There is no analytics package, no advertising network, no third-party tracking script and no fingerprinting SDK anywhere in this product. Nobody is paid for a view of your data, and it is not sold, rented, or shared for anyone else’s marketing.
3. Why, and on what legal basis
4. Who else sees it
Six outside services, each doing one job. The first four handle personal data and do so as processors — under contract, on instruction, not on their own account. The last two never receive anything about you at all.
Beyond those: the server itself is rented, so the hosting provider has physical custody of the disk the database sits on, as every host does.
Data is also disclosed where the law actually requires it — a court order, a valid request from a competent authority. There has never been one.
5. Where it is, and where it goes
The server, the database and the photo bucket are in the European Union.
Anthropic is in the United States, so the contents of a chat turn cross the Atlantic to be answered. That transfer runs on the European Commission’s Standard Contractual Clauses in Anthropic’s data processing addendum. Resend and Cloudflare are US companies operating on the same footing.
The service is available worldwide, including to people in the United States. Wherever you are, your data is stored in the EU and this policy is what applies to it.
6. Cookies and what is on your device
There is no cookie banner because there is nothing to consent to. The web app sets exactly one cookie:
ct_session— your sign-in, valid 60 days, HttpOnly, SameSite=Lax. Strictly necessary; without it you are signed out.ct_oauth— a few minutes long, and only during a Google sign-in, to tie the round trip back to the browser that started it.
Your light-or-dark preference is kept in your browser’s local storage and never sent anywhere. In the mobile apps the sign-in token lives in the iOS keychain or the Android keystore rather than in a cookie.
No advertising cookies, no analytics cookies, no third-party cookies of any kind.
7. How long it is kept
Everything you log is kept until you delete it or delete your account. There is no automatic expiry, because a food journal whose history evaporates is not a food journal.
Deleting your account, from Settings, erases the account and everything attached to it immediately — meals, photos, weights, workouts, conversations, recipes and plans, devices, sessions, the log of every email ever sent to you, and any message you wrote to support from that address. Photo files are removed from storage in the same operation, not merely dereferenced.
One message goes out afterwards: a receipt saying what was deleted, and the last thing that address ever hears from here. The line recording that it was sent does not record who it was sent to.
Exactly one thing survives, and it is worth being precise about it. The record of what each AI turn cost stays, with the link to you cut: token counts and a price, owned by nobody, which is no longer personal data and cannot be turned back into it. Deleting an account must not retroactively change what the service costs to run. Nothing else is kept, archived, held in a “deleted” state, or recoverable — including by me.
8. Your rights
Under the GDPR you can ask for any of the following, and it costs nothing:
- A copy of everything held about you, in a portable form.
- Correction of anything wrong.
- Erasure — which is the Delete account button, or an email if you prefer.
- Restriction of processing, or objection to it where it rests on legitimate interests.
- Withdrawal of your consent to health data being processed, at any time. It does not undo what was already done, but it stops it.
Email support@daysofar.com. The law allows a month to answer; in practice it is one person and a small database, so it will be days.
If the answer is unsatisfactory you can complain to the data protection authority in the EU country where you live, work, or where you think something went wrong. The list is at edpb.europa.eu.
9. Children
Day So Far is not for anyone under 16, and accounts are not knowingly created for them. A calorie tracker is a poor thing to hand a child. If you believe a child has an account here, write and it will be removed.
10. Security
Passwords are hashed, never stored. Sessions are stored as hashes too, so the token in your cookie exists nowhere on the server. Everything travels over HTTPS. The database and the API are not reachable from the internet — only the web front end is, and it proxies inward over a private network.
No system is beyond reach. If something is ever exposed that puts you at risk, you will be told, and so will the supervisory authority, within the 72 hours the law allows.
11. Changes
When this policy changes the date at the top changes with it. Anything that materially alters what happens to data already collected — a new recipient, a new purpose — will be emailed to account holders before it takes effect, not slipped in.
See also the Terms of Service.