Privacy

Last updated 3 September 2026

Day Director is a workspace app at daydirector.com. Account sign-in uses Firebase Authentication. Project, task, inbox, and file data live in Google Firebase (Firestore and Storage) under workspace security rules. Firebase is operated by Google; it is our application database, not a marketing or advertising destination.

Invites are copyable links. The app does not send invitation email. Members you add can see the workspace data their role allows.

Google OAuth reviewers: step-by-step Inbox and consent instructions are at daydirector.com/oauth.

How we access, use, and store Google user data

You can sign in with Google. That uses your Google account email and display name so we can create or match a Day Director user. We do not get your Google password.

Inbox can optionally connect Google Tasks with the read-only scope https://www.googleapis.com/auth/tasks.readonly (“See your tasks”). That is the narrowest Tasks scope Google offers. The Tasks API has no per-list, title-only, or incomplete-only scope. We use it only to list every task list and copy incomplete task titles, notes, and due dates into your Day Director Inbox so you can triage them into projects. We do not create, edit, complete, or delete Google Tasks. We do not request write or delete Tasks scopes.

The Google Tasks access token is stored only in your browser session storage. It is not written to our servers, Firestore, or logs. After you sync, copies of incomplete task titles, notes, due dates, and list names are stored as Inbox documents in your workspace so the feature still works when you return. You can disconnect by signing out of Day Director or by removing Day Director from Google Account permissions.

We follow the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to provide or improve user-facing Day Director features.

We do not use Google user data for advertising, credit decisions, lending, selling to data brokers, building unrelated databases, or unrelated product development.

With whom we share, transfer, or disclose Google user data

We do not sell Google user data. We do not rent Google user data. We do not share, transfer, or disclose Google Tasks contents or Google sign-in profile data to advertisers, data brokers, information resellers, or other unrelated third parties.

We share, transfer, or disclose Google user data only with the parties below, and only to operate the user-facing features described on this page:

  • Google Firebase (Auth, Firestore, Storage) — our hosting and database operator. Firebase stores your Day Director account and, after a sync you start, copies of incomplete Google Task titles, notes, due dates, and list names in your workspace Inbox. The OAuth access token is not stored there. Firebase is Google infrastructure used as our app backend, not a marketing recipient.
  • OpenAI (optional, inference only) — if a server API key is configured, Inbox title rewrite sends the imported task title and notes to OpenAI so the Inbox row can be shortened. This is a one-time inference request. It is not used to train Day Director models or generalized models. If rewrite is unavailable, the original Google Task text is stored unchanged. Do not sync tasks you do not want a model provider to process.
  • Workspace members you invite — people you add to the workspace can see Inbox items, including rows imported from Google Tasks, according to their role.
  • Agents you authorize with an MCP token — hosted MCP at /api/mcp uses a personal token you create in Settings. An agent you authorize with that token can read workspace data you already stored (including Inbox rows that originated as Google Tasks). Treat that token like a password. MCP cannot call Google Tasks on your behalf.
  • Legal process and safety — we may disclose data if required by law, to respond to valid legal process, or to prevent serious harm.

We do not transfer Google user data to other categories of recipients. If that list ever changes, we will update this page before the new sharing begins.

Data protection mechanisms for Google user data and other sensitive data

Sensitive data here means Google account identifiers, Google Tasks contents copied into Inbox, OAuth access tokens, and other workspace documents. Protection mechanisms:

  • Encryption in transit — all traffic to daydirector.com uses HTTPS/TLS.
  • Encryption at rest — workspace documents and files are stored in Google Firebase / Google Cloud, which encrypts data at rest.
  • Access control — Firestore and Storage security rules gate every document by workspace membership and role (owner / admin / member / viewer / guest). Unauthenticated callers cannot read Inbox or Google Task copies.
  • Least-privilege OAuth — Google Tasks access uses OAuth 2.0 with only https://www.googleapis.com/auth/tasks.readonly. We do not request write or delete Tasks permissions, so this app cannot change or purge tasks in your Google account.
  • Token isolation — the Google Tasks access token lives only in browser session storage and expires. It is never persisted on our servers, in Firestore, or in logs.
  • Least data to optional AI — optional title rewrite runs on our server after you are signed in. It receives only the task titles and notes you just synced, not your Google password or OAuth token.
  • Revocation and deletion — you can revoke Google access at any time in your Google Account. After revoke, Day Director cannot read further Tasks. Inbox copies already saved stay in your workspace until you delete them. You can delete those Inbox rows in the app, or email info@veliform.com to request account deletion.

AI and ML model training

Google Workspace APIs, including Google Tasks, are not used to develop, improve, or train generalized or non-personalized AI or ML models.

Optional Inbox title rewrite and the in-app Agent send only the text you submit (or just synced) to OpenAI for a one-time inference request when a server API key is configured. That processing is not training of a generalized or non-personalized model. We do not allow those requests to be used to train Day Director models. The Agent is instructed not to delete records. Do not paste secrets into Agent or Inbox if you do not want a model provider to process them.

Limited Use

We follow the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to provide or improve user-facing Day Director features.

Human access to Google user data is limited to cases you initiate (for example support you request), security investigations, or legal requirements. We do not use Google user data to serve ads.

Other product data

When Google Analytics is configured, the public site and the app send anonymous page views and product events (for example creating a task from a plan item) to Google Analytics. No Google Tasks titles or workspace document contents are sent as event payloads beyond short identifiers such as a project key or task id.

Support: info@veliform.com. This page describes the product as shipped; it is not legal advice.