Donate to the Government of Nepal Prime Minister's Disaster Relief Fund

Legal

Legal Information & Notices

Last updated: September 5, 2026

1. Operator and Contact

Daydraft is an independent software application created and operated by Praashon in Kathmandu, Nepal. Official inquiries, legal questions, or security disclosures can be directed to praashon.dev@gmail.com.

2. Service Description & Scope

Daydraft is a distraction-free daily planning and cognitive organization web application designed to decompose unstructured mental thoughts ("brain dumps") into structured tasks, priority rankings, chronological timelines, notes, and focused work sessions.

Daydraft is strictly a self-management and personal productivity aid. It does not provide medical, psychiatric, legal, tax, financial, or any other certified professional advice.

3. Authentication & Cloud Infrastructure Architecture

Daydraft integrates modern cloud storage, encryption, and authentication services to protect user accounts and data:

  • Supabase Database & Authentication: User identity, verified email addresses, unique usernames, cryptographic password hashes, and user profile records (profiles) are managed via Supabase Auth and PostgreSQL database.
  • Row Level Security (RLS) Isolation: All workspace tables - including tasks (tasks), daily schedule plan items (daily_plan_items), notes (notes), trash history (trash), user preferences (user_preferences), and API key vaults (user_api_keys) - enforce strict PostgreSQL Row Level Security policies (auth.uid() = user_id). This guarantees tenant data isolation at the database layer.
  • API Key Vault Envelope Encryption: User-supplied API keys for Google Gemini or OpenRouter are encrypted server-side using AES-256-GCM authenticated envelope encryption with HKDF/HMAC key derivation before being stored in public.user_api_keys. Keys are decrypted strictly in-memory during active AI interaction and never returned in plaintext to clients.
  • Multi-Factor Authentication (MFA): Users can enroll additional security verification layers, including TOTP (Time-based One-Time Password apps) and FIDO2 WebAuthn / Passkeys.
  • Password Breach Verification: Passwords selected during registration or profile updates are checked against known compromised data breaches using HaveIBeenPwned's Pwned Passwords API. Verification relies on mathematical k-anonymity (transmitting only the first 5 hex characters of a SHA-1 hash), preventing disclosure of plain passwords or full hashes to third parties.
  • Profile Avatar Storage: User avatars are stored in a dedicated Supabase Storage bucket (avatars) with RLS write policies restricting file changes to the account owner.
  • Session Security & Middleware: Authenticated sessions utilize secure, HTTP-only cookies managed via @supabase/ssr and validated by server-side Next.js middleware.

4. Hybrid Storage & Offline Resilience

Daydraft employs a hybrid cloud-and-local persistence model. Workspace records stored in Supabase are synchronized with your browser's localStorage for offline availability and fast local rendering. In-app data reset tools allow users to clear local cache or purge items from cloud database storage.

5. AI Providers & Third-Party Services

Daydraft offers cognitive organization and coaching insights using artificial intelligence. AI requests are processed through Google Gemini (@google/genai) or OpenRouter, depending on your configuration, along with a deterministic local NLP heuristic parser:

  • When an AI feature is invoked, only the submitted brain dump or coaching query is sent to the selected provider.
  • Third-party AI processing is subject to the respective service terms and privacy policies of Google and OpenRouter.
  • Daydraft does not guarantee continuous availability, latency guarantees, or specific responses from third-party AI APIs.

6. AI Output & Accuracy Disclaimer

AI-generated suggestions, task breakdowns, deadlines, and coaching perspectives are produced probabilistically. They may occasionally be erroneous, incomplete, or inappropriate for your specific situation. You retain ultimate responsibility for reviewing and validating all generated tasks and schedules before relying upon them.

7. Intellectual Property

The Daydraft name, visual identity, logo, graphics, design system, source code, and interactive animations are the proprietary intellectual property of Praashon. You may not reproduce, duplicate, copy, sell, or exploit any portion of the Service interface or code without express written permission.

Users retain full intellectual property rights and title to all personal notes, tasks, and content created within their Daydraft workspace.

8. Contact Form Notice

The contact form on the marketing showcase currently provides a client-side confirmation only. It does not transmit messages to an email inbox or server database. For official, confidential, or urgent inquiries, please write directly to praashon.dev@gmail.com.

9. Disclaimers & Limitation of Liability

Daydraft is delivered without warranties of any kind. Praashon disclaims any liability for direct, indirect, consequential, or incidental losses resulting from data loss, third-party API outages, account compromise due to weak or unmanaged credentials, or decisions made on the basis of AI-generated content.

10. Governing Jurisdiction

All legal relationships, notices, and disputes connected with Daydraft are subject to the laws of Nepal. Venue and jurisdiction for any disputes shall lie exclusively in Kathmandu, Nepal.

Related Documents:Terms of Service•Privacy Policy