── DAYCHIEF PRIVACY
Privacy Policy
DayChief is an iPhone app from FXA Digital Solutions LLC for voice, text, planning, drafting, and user-approved connected actions. This policy explains what DayChief collects, how it is used, and how users control it.
Information DayChief Collects
- Account information used to sign in and operate the app, plus purchase and subscription-entitlement information used to grant or restore paid access.
- Voice audio, transcripts, text prompts, assistant responses, and conversation metadata needed to provide voice and text assistant features.
- Approval records and action context for connected-service writes that require user confirmation.
- Optional connector account metadata and authorization tokens when a user links services such as Google or Todoist.
- Usage, cost, diagnostic, and security logs used to operate the service, enforce limits, and troubleshoot issues.
- Optional Sidecar connection details, such as a Sidecar URL, pairing token, device token, and conversation identifiers when the user connects DayChief to a self-hosted Sidecar.
How Information Is Used
DayChief uses information to authenticate users, provide voice and text assistant features, prepare drafts and plans, show approval queues, execute user-approved actions, enforce entitlement and usage limits, maintain security, and respond to support requests.
Optional Connectors
Google and Todoist connectors are optional. DayChief requests the scopes needed for the workflows a user chooses to enable. Connector data is used to answer user requests, prepare drafts, create approval records, and execute actions only after the required user confirmation.
Google Workspace Data
When a user connects Google, DayChief stores the connected account identifier and email address, the permissions granted, an encrypted OAuth refresh token, and selected connector settings. Depending on the permissions the user chooses, DayChief may also access:
- Gmail: message and draft identifiers, labels, sender and recipient fields, dates, subjects, snippets, message bodies, and draft contents. DayChief uses this data for user-requested inbox views, searches, reading, summaries, and draft workflows. It creates, updates, or sends a draft only after the user approves the action.
- Google Calendar: calendar-list metadata and event details such as titles, descriptions, dates and times, recurrence, locations, attendees, and meeting links. Read-only workflows use
calendar.events.readonly; approved event changes usecalendar.events; both usecalendar.calendarlist.readonlyonly to list and select calendars. DayChief uses this data for user-requested schedule lookups and, when write access is enabled, user-approved event creation, updates, and deletion. - Google Drive: file and shared-drive identifiers, names, types, modification dates, sizes, links, and the content of supported files. DayChief uses this data only for user-requested Drive search, retrieval, and research.
Relevant Google content may be transmitted through FXA Digital's Google Cloud infrastructure and to OpenAI's API to interpret the request or produce the requested answer, summary, draft, or action preview. DayChief does not sell Google data, use it for advertising or credit decisions, or permit it to be used to train generalized AI or machine-learning models. DayChief does not create or use aggregated or anonymized datasets derived from Google Workspace content for advertising, analytics, product development, or model training. Non-content operational measurements, such as request counts, timing, and error rates, may be aggregated to operate and secure the service.
Voice, BYOA Voice, and Sidecar
Hosted DayChief voice and text features may process prompts, audio, transcripts, and assistant responses through FXA Digital infrastructure and third-party AI providers. BYOA Voice sends iOS audio through DayChief infrastructure and LiveKit while inference runs through the user's configured Sidecar. Sidecar is operated by the user; Sidecar data is controlled by that deployment unless the user shares it with FXA Digital for support.
External Processing
DayChief may use Firebase or Google Cloud infrastructure for authentication, hosting, databases, logging, speech processing, and backend operation. Hosted assistant features may use OpenAI services. BYOA Voice may use LiveKit and Google speech services for audio transport, speech-to-text, and text-to-speech. RevenueCat processes purchase and subscription-entitlement information; DayChief does not send Google Workspace content to RevenueCat. Connected-service requests are sent to the relevant provider, such as Google or Todoist, only when the user configures that connector and requests or approves the action.
Retention and Deletion
Pre-release status: DayChief is not yet generally available. The comprehensive account-deletion workflow described below is an approved production control that is still being implemented and verified. Current test builds should not be treated as proof that every related top-level application record or external processor record has been removed.
- Account, conversation, transcript, approval, usage, and connector records are retained with the user's DayChief account until the user deletes the account. There is no separate fixed deletion date before account deletion.
- Google message, event, and file content is retrieved as needed and is not maintained as a separate permanent copy. Content, excerpts, summaries, or action details that become part of a DayChief conversation or approval record remain with the account until account deletion.
- While Google remains connected, DayChief retains the encrypted refresh token, granted-scope record, selected calendar settings, and cached connector metadata needed to operate the connection.
- Disconnecting a Google account in DayChief deletes its stored OAuth token and cached connector metadata and attempts to revoke the token with Google. Disconnecting does not delete content already included in conversation or approval history; users can remove that data by deleting their DayChief account.
- Production application logs are retained for 30 days. They are designed to contain operational identifiers, status, timing, and redacted errors rather than Google message bodies, file contents, or credentials.
The approved production workflow will first record a durable deletion request, then promptly delete identifying account and connector data; stored OAuth credentials; conversations, prompts, transcripts, assistant responses, and tool results; Google Workspace content or derived excerpts; voice-session records; local tasks; and pending approvals. After local content and credentials are removed and minimum encrypted external-cleanup state is durable, it will delete the Firebase authentication user. Provider-side deletion or revocation may complete asynchronously without restoring ordinary account access.
DayChief may retain only minimum non-Workspace billing and service-usage information after it has been irreversibly de-identified and combined into broad monthly company-wide totals. Those totals may be retained for no longer than three years from the underlying transaction or usage period. They exclude Google Workspace content and derived data, prompts, transcripts, free text, user or provider identifiers, precise timestamps, and small or distinctive cohorts.
To prevent a delayed subscription event from recreating a deleted account, DayChief's approved workflow will retain a restricted, keyed cryptographic suppression marker. The marker is pseudonymous security data, not an analytics profile. It contains no raw user ID, email, receipt, product, transaction, prompt, or Google Workspace content. It expires three years after the most recent verified matching RevenueCat subscription lifecycle event; a later verified matching event restarts that period solely so it can continue to suppress account recreation.
Primary production records will be targeted for prompt deletion. Firestore point-in-time recovery and scheduled backups may retain protected copies for up to seven days before they age out. They are not available through the ordinary app, and any restore procedure must reapply deleted-account suppression before restored data is exposed. Deleting a DayChief account does not remove an email draft, sent message, calendar event, or other data already written to the user's Google account.
Deleting a DayChief account also does not cancel an Apple subscription. Users must cancel separately through Apple's subscription-management controls if they do not want billing to continue. See Data Management and Account Deletion for the current controls and release status.
Security and Human Access
DayChief encrypts data in transit using HTTPS/TLS and uses Google Cloud encryption at rest. In production, OAuth refresh tokens are additionally encrypted with Google Cloud KMS, and service access is restricted through authenticated user boundaries and least-privilege service identities. Access tokens are used only to call the APIs authorized by the user. Application logging is designed to redact credentials and connected-service content.
FXA Digital does not routinely inspect Google Workspace content. Access by authorized personnel is limited to what is necessary when a user explicitly requests support, to investigate security or abuse, to maintain service integrity, or to comply with law. DayChief does not allow service-provider personnel to use Google data for their own purposes.
Google API Limited Use
DayChief's use and transfer to any other app of information received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Additional details are available in the Google API Disclosure.
Tracking and Advertising
DayChief does not use advertising identifiers, data brokers, third-party advertising, or cross-app tracking. FXA Digital may collect basic website analytics on fxa.digital to understand public site usage; that website analytics is separate from DayChief app tracking.
User Choices
- Users choose whether to sign in, link optional connectors, configure Sidecar, or use hosted DayChief features.
- Before connecting Google, users choose Gmail reading, Gmail draft, Calendar, and Drive access separately. A service set to No Access does not receive that Workspace permission.
- Users can approve or reject queued actions before supported connected-service writes execute.
- Users can disconnect optional services and revoke provider access from the provider account settings.
- Users can delete their DayChief account and associated app data from Settings in the app.
- Users can review the deletion steps, retained-data exceptions, backup timing, and Apple subscription controls on the Data Management and Account Deletion page.
Contact
For privacy questions, access requests, or deletion help, contact FXA Digital Solutions LLC at info@fxa.digital. Do not email passwords, OAuth tokens, message contents, file contents, or other sensitive account data.