The fine print, in plain words
Privacy Policy
My Daily Tool: Effective September 16, 2026
What we collect
Your content stays on your device. Every meal, workout, task, journal entry, alarm, note, and setting you create lives only in your device's local storage. We do not run a database of your content, and there are no user accounts on our servers. So there is nothing of yours on our servers to browse, sell, or leak.
A few things leave your device for a moment to do what you asked, and only then: a support message you send (delivered by email, see "Contact & email delivery" below), an AI answer (your prompt goes to the AI provider through our server, see "Optional integrations"), or a forecast, headline list, or price ticker fetched for you and never logged. Nothing leaves your device automatically. Everything else leaves only when you ask. Nothing passing through our server is stored there, except the compact report snapshot we keep only while you have a scheduled report email active (see "Contact & email delivery" below).
What we do not collect
- No account creation required. The app works fully offline; there is no sign-in and no login path. It opens straight into your day.
- No advertising trackers. No third-party fingerprinting. No IDFA.
- No personal content (meals, journal, tasks, notes) transmitted to our database. We do not have a content database. Your entries live only on your device.
Zero telemetry
The app ships with zero telemetry: no product analytics, no crash reporting, no advertising trackers, no fingerprinting, no cross-site tracking. Nothing you do in the app is measured, counted, or sent anywhere automatically.
The only data that ever leaves your device is what you explicitly ask for: a support message you send, an AI answer you request, a report you email to yourself, or a forecast/headline/price you fetch. Your meals, journal entries, notes, tasks, alarms, photos, and other personal content are never transmitted automatically.
Verify it yourself
You don't have to take our word for "zero telemetry." Here's how to check.
What leaves automatically: nothing. The app makes zero automatic network requests. No analytics beacon on launch, no crash uploader, no session ping, no config fetch. The complete list of network egress the app can ever make is opt-in, and every item on it is something you explicitly asked for:
- Resend, only when you send a contact message or schedule a report email (
api.resend.com). - AI assistant, only when you ask the assistant something; your prompt travels through our
/api/chatroute to the built-in provider DeepSeek, with NVIDIA NIM and OpenRouter free models then Mistral as automatic failover (api.deepseek.com,integrate.api.nvidia.com,openrouter.ai,api.mistral.ai). There is no way to supply your own key; the built-in free models are the only option. - AI vision, only when you ask about an image; the image goes through our
/api/visionroute to the built-in free vision models (NVIDIA NIM, then OpenRouter free vision models). There is no way to supply your own key. - Web search, only when you ask the assistant for live web results; your typed query goes out through the assistant's server-side search chain (
html.duckduckgo.com,api.browserbase.com,api.firecrawl.dev). - Open-Meteo, only when a forecast is shown or a run records a route (
api.open-meteo.com,geocoding-api.open-meteo.com). - OpenWeather fallback, only as a richer-conditions fallback, and only when the optional server-side key is configured (
api.openweathermap.org). - Apple WeatherKit fallback, only when the optional server-side WeatherKit key is configured (
weatherkit.apple.com). - World News API, only when headlines are fetched, through our
/api/newsroute (api.worldnewsapi.com). - News RSS: BBC and NPR feeds, fetched through our
/api/newsroute (feeds.bbci.co.uk,feeds.npr.org). - CoinGecko, only when the Finance watchlist refreshes (
api.coingecko.com), via our server proxy. - Stock quotes, only when the Stocks tool refreshes (
finnhub.io,query1.finance.yahoo.com,www.alphavantage.co). - Sports scores & odds, only when the Sports tools refresh (
site.api.espn.com). - Prediction markets, only when the Polymarket tracker refreshes (
gamma-api.polymarket.com,clob.polymarket.com). - Movies & shows, when the Watch tools fetch live titles or artwork (
api.themoviedb.org,image.tmdb.org). - Fitness & cocktail data, only when those tools fetch reference data (
api.api-ninjas.com). - Public holidays, only when the Holidays tool refreshes (
date.nager.at). - Riddles, only when the Riddles game fetches new riddles (
riddles-api.vercel.app). - Word lookups, only when the Word tool looks up a definition (
en.wiktionary.org). - Route planning, only when you plan a route: directions come from Mapbox or OSRM (
api.mapbox.com,router.project-osrm.org). - Address & places search, only when you search addresses or nearby places (
nominatim.openstreetmap.org,overpass-api.de,overpass.kumi.systems). - Pavlok, only on the iOS app after you pair the device (
api.pavlok.com); there is no Pavlok connection in the web app. - Fitbit, only after you connect it: you log in at Fitbit (OAuth2 with PKCE; the app never sees your Fitbit password). Note: our shared Fitbit app is not registered yet, so one-tap Fitbit sign-in is off until it is. You can still connect with your own Fitbit app from dev.fitbit.com; the app's Integrations screen shows you where to paste the client ID. Your access and refresh tokens are stored on this device, sealed in the app's encrypted store, and the app calls the Fitbit API directly with them (
api.fitbit.com). Only the exchange secret stays on our server; it trades the authorization code once and never ships in the app. Disconnecting wipes the synced data. - Oura, only after you connect it: a direct connection to the Oura API (
api.ouraring.com). You paste a personal access token from cloud.ouraring.com and the app calls Oura's servers directly with it. The token is stored on this device, sealed in the app's encrypted store. The Oura app and Apple Health are not part of this path. Disconnecting stops the sync. - Strava, only after you connect it: OAuth2 login at Strava, tokens exchanged through our server proxy (
www.strava.com); disconnecting wipes the synced data. - Garmin, only after you connect it: you sign in at Garmin (
connect.garmin.com), and the token exchange runs through our server proxy (/api/wearables?svc=garmin). Sync runs only when you tap it; disconnecting wipes the synced data. - Spotify, only after you connect it: you sign in at Spotify (
accounts.spotify.com), tokens are exchanged through our server proxy (/api/wearables?svc=spotify) and stored sealed on your device; playlists and playback state are read fromapi.spotify.comonly while you use the focus or workout players. - FlightAware, only when you test your own API key: the key travels through our server proxy (
/api/wearables?svc=flightaware) to FlightAware (aeroapi.flightaware.com) for that one validation request. The key stays sealed on your device; our server never stores it. - RSS feeds you add, only for feed URLs you add yourself: the URL you paste is fetched once through our server proxy to check it is a real feed (
/api/wearables?svc=rss); your device never contacts the feed host directly. - Food nutrition data, only when the food tools look up a barcode or a food name: the request goes directly from your device to the USDA FoodData Central or Open Food Facts public APIs (
api.nal.usda.gov,world.openfoodfacts.org), with no server proxy and nothing logged. - ICS proxy, only for calendar feed URLs you add yourself.
Every one of these matches the connect-src list in our Content Security Policy and the rewrites in vercel.json, the set of hosts the site is even allowed to talk to.
iOS privacy manifest. The app's PrivacyInfo.xcprivacy declares NSPrivacyTracking = false with an empty tracking-domains list. It lists three data types (crash data, performance data, product interaction), all marked not linked to you, not used for tracking, app functionality only. There is no crash-reporting SDK in the app to send crash data anywhere; the declaration covers what iOS itself may hold when you share diagnostics with Apple at the system level, which never reaches us.
Watch the traffic yourself (5 steps). Install Proxyman or Charles on your Mac, install its root certificate on your iPhone, and route the phone through it. Then: (1) force-quit My Daily Tool; (2) start the capture; (3) launch the app and leave it on Home for two minutes without touching anything; (4) use the app normally: plan a task, play a game, log water; (5) stop the capture and filter by the app. At rest you will see zero requests. In use you will see only the hosts in the list above, and only at the moment you asked for them. If you ever see anything else, tell us. That's a bug, and we'll treat it like one.
Contact & email delivery
When you send a message from the contact form (or from the contact section of the website), what you typed (your name, your email address, and your message) travels through our server to Resend, the email service that delivers it to the maker, with your address set as the reply-to so a reply reaches you. Weekly report emails you choose to send go the same way through Resend. We do not keep copies of the message itself: once delivered, it lives only in the inbox it was sent to. A scheduled report keeps a compact snapshot on our server so it can send on time; the snapshot holds only that report and is purged after the schedule goes quiet.
Where the data lives
All your data is stored locally on the device you are using. If you uninstall the app or clear app data, the data is gone. We cannot recover it.
Optional cross-device sync is off by default. If you turn it on (Settings → Sync), your data is also stored in the private cloud project you connect: that project belongs to you, not us. We never operate it, receive it, or store your content. When enabled, sync includes your health-adjacent logs (weight, sleep, energy, and water) so they appear across your own devices. These go only to your project, never to the developer. Your 2FA secrets, game scores, and media files (meal photos, voice memos) are deliberately excluded from sync.
My Daily Tool offers an "Export all data (JSON)" button in Settings so you can back up your own data whenever you want. The export includes only the active profile's data.
Optional integrations
The features below are opt-in. Nothing is shared until you explicitly connect an account or enable a feature.
No Google integration. As of September 2026 the app offers no Google sign-in, no Gmail or Calendar sync, and no Gmail-delivered reports. It requests no Google OAuth scopes, stores no Google tokens, and sends nothing to Google APIs. Calendar widgets read events you enter yourself or import; weekly reports send only through Resend (above). If you granted Google access in an older version of the app, revoke it under Third-party access in your Google account at myaccount.google.com.
AI assistant: If you use the assistant, your typed prompt is sent to the AI provider that powers it: DeepSeek (deepseek-chat), served through our server proxy at /api/chat with NVIDIA and OpenRouter free models then Mistral as automatic failover. There is no way to supply your own API key; the built-in free AI is the only option. The proxy means the chosen provider sees a request from our IP, not your IP. Your typed prompt and the assistant's reply are treated as User Content and may be retained by the upstream AI provider per their own policy. We do not log or persist the prompts or replies on our server.
What context the assistant sends, and your control over it. To answer in context, the assistant can attach some of your on-device data to the request. This is off by default: the first time a send would include this data, the app shows a one-time prompt asking your permission, and you can decline (the assistant then sees only what you type). When you allow it, the context that is sent is exactly:
- your profile name and any email addresses you have entered (account, Outlook, work);
- your tasks and your daily calorie goal;
- today's meal log (names and calories);
- any facts you have saved in the assistant's "Memory" feature (Settings → Assistant), which are editable and clearable at any time.
You can change your choice at any time in Settings → Privacy. There is no "no PII attached" guarantee for assistant requests you have consented to. The items above are intentionally included so the assistant can be useful.
Health insights: Your health metrics stay on your device except when you explicitly ask the assistant for health insights (the "Ask AI about my health" action) and consent. In that one flow, your recent metrics (steps, sleep, resting heart rate, heart-rate variability, active energy) plus your derived age and BMI are sent to the AI provider so it can answer. A normal chat never sends health data, even after you have consented to the other context above.
Weather: The home dashboard shows current conditions. The app uses coordinates that default to a fixed location in coastal South Carolina, but that you can change at any time in Settings. Coordinates are sent to Open-Meteo (a free, attribution-only weather API) which does not require a key or account. With your permission, the app can read your device location when you tap "Use current location" in Settings (for local weather) or start a run in the Run tracker (to record real distance and route). Your coordinates are used only to fetch the forecast or record your run and are otherwise kept on your device; the app never accesses your location in the background. When the optional server-side keys are configured, the app can fall back to OpenWeather or Apple WeatherKit for richer conditions (api.openweathermap.org, weatherkit.apple.com).
Crypto prices: The optional Finance widget pulls public ticker prices from CoinGecko. No identifiers attached. Stock quotes in the Finance tools come from Finnhub, Yahoo Finance, and Alpha Vantage (finnhub.io, query1.finance.yahoo.com, www.alphavantage.co).
News headlines: The News tab and the Home news card show US headlines (or the results of a keyword search) from the World News API. Every request goes through our own /api/news route, so the API key stays on our server and is never shipped inside the app. A keyword search forwards only the term you typed, clamped to 80 characters; a headlines or category request forwards only the category id. No account, no device identifier and no personal data is attached, and we do not log the query. The News tab also fetches BBC and NPR RSS feeds through the same route (feeds.bbci.co.uk, feeds.npr.org).
Connected accounts (Fitbit, Oura, Strava): These are account-linked and entirely opt-in. Nothing connects until you choose it in Settings or Health Center.
- Fitbit: you log in at Fitbit (OAuth2 with PKCE; the app never sees your Fitbit password). Your access and refresh tokens are stored on this device, sealed in the app's encrypted store, and the app calls the Fitbit API directly with them. Only the exchange secret stays on our server; it trades the authorization code once and never ships in the app.
- Oura: a direct connection to the Oura API (
api.ouraring.com). You paste a personal access token from cloud.ouraring.com into the app, and the app calls Oura's servers directly with it. The token is stored on this device, sealed in the app's encrypted store. The Oura app and Apple Health are not part of this path. - Strava: OAuth2 login at
www.strava.com(the app never sees your Strava password); the authorization code is exchanged for access tokens through our server proxy, and your activities are read from Strava's API (www.strava.com/api/v3). You can disconnect at any time. The stored tokens are discarded and no new activities are fetched. - Pavlok (iOS only): you log in with your Pavlok account in the iOS app; the stimuli you trigger (zap, beep, vibe) are sent to Pavlok's API (
api.pavlok.com). There is no Pavlok connection in the web app.
Notifications
If you enable notifications, the app schedules them locally on your device for alarms, calendar reminders, and (optionally) ambient quotes. Notification content is generated on-device and never sent to a server. The app does not register for remote push notifications. There is no server that can push to your device.
Children
The app is rated 17+ in the App Store. It includes a cocktail recipe tool with alcohol references and a sports-betting / prediction-markets tracker with simulated gambling, so it is not intended for children. We do not collect any data, knowingly or otherwise, from children under 13.
Your rights (CCPA / GDPR)
My Daily Tool stores no personal data on any server except the scheduled-report snapshot described above. There is nothing else for us to delete, modify, or hand over under CCPA "right to know," CCPA "right to delete," or GDPR "right of access / erasure / portability." Your local data is yours: export, edit, or wipe it from Settings at any time.
There are no connected accounts to revoke: nothing leaves your device except through the opt-in integrations above, each removable in Settings.
Changes to this policy
If we materially change how the app handles data, we will update this page and bump the "Effective" date at the top. Because we don't have a user database, we can't email you about changes. Please re-read this page after major updates.
Contact
My Daily Tool is published by BFS Development LLC.
Questions or feedback: write to contact@mydailytool.com or use the contact form.
Built by BFS Development LLC.