Privacy Policy

You tell this app what you ate. That is health information, and it is treated as such: it is not sold, not used for advertising, not analysed for anyone but you, and it leaves the server only where the feature you asked for cannot work otherwise.

Last updated 14 September 2026

1. Who is responsible

Day So Far is built and run by Nikolay Lyutov, an individual established in the European Union. For the purposes of the GDPR that makes me the data controller for everything described here.

Write to support@daysofar.com about anything on this page. It is a real inbox, read by one person.

This policy covers the hosted service at daysofar.com and the Day So Far apps for iOS and Android. Day So Far is also open source and can be run on your own server; if you are using somebody else’s installation, this policy does not describe it and whoever runs that server is responsible for it.

2. What is recorded

Because you have an account

  • Your email address, and a hash of your password — never the password itself.
  • If you sign in with Google: Google’s permanent id for your account, and the address it reports. Nothing else from your Google account is requested or received.
  • Sign-in sessions, which expire 60 days after they are created.

Because you asked for a calorie target

  • Sex, date of birth, height, activity level, goal, target weight.
  • Your timezone and the hour your day starts, which is how a 1am snack lands on the right day.
  • Any dietary rules you set, and your unit preference.
  • If you turn notifications on, a push token for that phone — the address a reminder is delivered to, and nothing that describes you. It is deleted when you turn them off, sign out, or delete the account.

If you let the app count your steps

  • A daily step count, and nothing else. No location, no route, no map, and no continuous tracking — the app asks for one number per day, when you open it, and asks for nothing while it is closed. On an iPhone it comes from the phone’s own motion sensor; on Android it is read from Health Connect, which holds what other apps — Samsung Health, Fitbit — have already recorded. Only the step count is read, and nothing is ever written back.
  • It is off until you turn it on, from the Steps card on Today, and your phone asks you before the first reading. Withdrawing it — in iOS Settings, or in Health Connect on Android — stops new days arriving; the days already recorded are deleted with your account like everything else, or on request.
  • What it is used for: setting your calorie target from what you actually do rather than from the activity level you picked when you signed up, and giving the assistant something better to say about a plateau than “eat less”. Steps are never converted into calories and never added to what you may eat.
  • Steps travel to Anthropic with the rest of today’s totals, as a count and a date, whenever you send a message. See section 4.

Because logging is the product

  • Every meal, with its items, quantities and nutrition estimates.
  • Photos of food you upload, and any barcode you scan.
  • Exercise, workouts and weight entries.
  • The conversation itself — what you typed, or dictated, and what the assistant answered — kept as a record separate from the meals it produced. A dictated meal is stored as the words it became; the recording is never sent here and never kept.
  • Recipes, meal plans, shopping lists and pantry items you create.

Because a server has to defend itself

  • For each device that signs in: a fingerprint of it, its browser or app user agent, and the IP address it was last seen at. This is what makes the “new sign-in” email able to say where from. It is deleted with your account.
  • IP addresses in the web server’s logs and in the rate limiter’s counters, held briefly and used for nothing but throttling and abuse.
  • The token and time cost of each AI turn. What the app costs to run is the question that decides whether it keeps existing.

Before there is an account

  • Which screens of the first-run questions a new install reaches — the welcome screen, each question, the plan, the sign-up form — as a count per day, per platform and app version. Nothing identifies the phone or the person: no device or install id, no account, no address is stored with it, and each screen is sent at most once. It tells us where people give up, and it cannot tell us who.

There is no analytics package, no advertising network, no third-party tracking script and no fingerprinting SDK anywhere in this product. Nobody is paid for a view of your data, and it is not sold, rented, or shared for anyone else’s marketing.

3. Why, and on what legal basis

To run the appLogging meals, working out a target, showing your history, sending the emails the service is made of. Necessary to perform the contract you entered into when you made an account — GDPR Article 6(1)(b).
Health dataWhat you eat, what you weigh and how you exercise is special-category data under Article 9. It is processed because you have explicitly asked for it to be, by typing it in — Article 9(2)(a). Withdraw that at any time by deleting your account, which erases it.
SecuritySign-in alerts, rate limits, keeping the service standing up. Legitimate interests — Article 6(1)(f).
First-run countsSeeing which question new installs stop at, so the questions can be made shorter or clearer. Anonymous counts that identify nobody — legitimate interests, where they count as personal data at all.
Cost accountingKnowing what a turn costs, so the service can be priced or stopped honestly. Legitimate interests. Detached from your account when you delete it.
Weekly reviews and nudgesPart of the service, and switchable off in Settings or from the link at the foot of every message. No marketing email is sent, because none exists.

4. Who else sees it

Six outside services, each doing one job. The first four handle personal data and do so as processors — under contract, on instruction, not on their own account. The last two never receive anything about you at all.

AnthropicThe model that reads “two eggs and toast” and turns it into numbers. It receives the message you sent, the photo if you sent one, your profile and today’s totals — including your step count for the day, if you have turned that on — and, when you ask about your history, the entries it looks up. It is used through Anthropic’s commercial API, under terms where inputs and outputs are not used to train their models. Their privacy policy.
ResendSends the confirmation codes, password resets, sign-in alerts and weekly reviews, and receives replies to support@daysofar.com. Sees your address and the contents of those messages. Privacy policy.
CloudflareR2 object storage holds meal photos. Cloudflare stores the bytes and does not look at them. Privacy policy.
GoogleTwo things, each only if you choose it. Signing in with Google: Google learns that you signed in to this app, and this app learns your Google id and address — sign in with a password instead and that half never happens. Dictating a meal on Android: the phone’s own speech recognition turns what you say into text. Where the phone has an offline language pack, that happens on the device and no audio leaves it; where it does not, Android hands the recording to Google to transcribe. Either way the recording is between your phone and Google — it is never sent to this app, which receives only the finished sentence, in the box, for you to send or delete. Notifications on Android: Firebase Cloud Messaging carries them, so Google is handed the push token and the text of the notification, and learns that a delivery happened. It is not given your meals; a reminder says only what you would read on the lock screen.
AppleNotifications on iPhone go the same way through the Apple Push Notification service: Apple is handed the token and the text, and learns a delivery happened. Turn notifications off and no token is ever registered with either company.
Open Food FactsConsulted when you scan a barcode. It receives the number on the packet and nothing else — no account id, no user agent identifying you, nothing that ties the scan to a person.
USDA FoodData CentralThe same, for American branded products Open Food Facts does not have. The barcode, and nothing else.

Beyond those: the server itself is rented, so the hosting provider has physical custody of the disk the database sits on, as every host does.

Data is also disclosed where the law actually requires it — a court order, a valid request from a competent authority. There has never been one.

5. Where it is, and where it goes

The server, the database and the photo bucket are in the European Union.

Anthropic is in the United States, so the contents of a chat turn cross the Atlantic to be answered. That transfer runs on the European Commission’s Standard Contractual Clauses in Anthropic’s data processing addendum. Resend and Cloudflare are US companies operating on the same footing.

The service is available worldwide, including to people in the United States. Wherever you are, your data is stored in the EU and this policy is what applies to it.

6. Cookies and what is on your device

There is no cookie banner because there is nothing to consent to. The web app sets exactly one cookie:

  • ct_session — your sign-in, valid 60 days, HttpOnly, SameSite=Lax. Strictly necessary; without it you are signed out.
  • ct_oauth — a few minutes long, and only during a Google sign-in, to tie the round trip back to the browser that started it.

Your light-or-dark preference is kept in your browser’s local storage and never sent anywhere. In the mobile apps the sign-in token lives in the iOS keychain or the Android keystore rather than in a cookie.

No advertising cookies, no analytics cookies, no third-party cookies of any kind.

7. How long it is kept

Everything you log is kept until you delete it or delete your account. There is no automatic expiry, because a food journal whose history evaporates is not a food journal.

Deleting your account, from Settings, erases the account and everything attached to it immediately — meals, photos, weights, workouts, conversations, recipes and plans, devices, sessions, the log of every email ever sent to you, and any message you wrote to support from that address. Photo files are removed from storage in the same operation, not merely dereferenced.

One message goes out afterwards: a receipt saying what was deleted, and the last thing that address ever hears from here. The line recording that it was sent does not record who it was sent to.

Exactly one thing survives, and it is worth being precise about it. The record of what each AI turn cost stays, with the link to you cut: token counts and a price, owned by nobody, which is no longer personal data and cannot be turned back into it. Deleting an account must not retroactively change what the service costs to run. Nothing else is kept, archived, held in a “deleted” state, or recoverable — including by me.

8. Your rights

Under the GDPR you can ask for any of the following, and it costs nothing:

  • A copy of everything held about you, in a portable form.
  • Correction of anything wrong.
  • Erasure — which is the Delete account button, or an email if you prefer.
  • Restriction of processing, or objection to it where it rests on legitimate interests.
  • Withdrawal of your consent to health data being processed, at any time. It does not undo what was already done, but it stops it.

Email support@daysofar.com. The law allows a month to answer; in practice it is one person and a small database, so it will be days.

If the answer is unsatisfactory you can complain to the data protection authority in the EU country where you live, work, or where you think something went wrong. The list is at edpb.europa.eu.

9. Children

Day So Far is not for anyone under 16, and accounts are not knowingly created for them. A calorie tracker is a poor thing to hand a child. If you believe a child has an account here, write and it will be removed.

10. Security

Passwords are hashed, never stored. Sessions are stored as hashes too, so the token in your cookie exists nowhere on the server. Everything travels over HTTPS. The database and the API are not reachable from the internet — only the web front end is, and it proxies inward over a private network.

No system is beyond reach. If something is ever exposed that puts you at risk, you will be told, and so will the supervisory authority, within the 72 hours the law allows.

11. Changes

When this policy changes the date at the top changes with it. Anything that materially alters what happens to data already collected — a new recipient, a new purpose — will be emailed to account holders before it takes effect, not slipped in.

See also the Terms of Service.