Privacy
Privacy Policy
Last updated: September 5, 2026
1. Who Operates Daydraft
Daydraft is developed and operated by Praashon from Kathmandu, Nepal. We are committed to safeguarding your privacy and ensuring transparency regarding how your data is collected, stored, and processed. Questions or privacy requests can be directed to praashon.dev@gmail.com.
2. Account Information & Authentication Data
When you register for a Daydraft account or update your profile, we collect and store:
- Profile Details: Your email address, unique chosen username, and optional display name.
- Credentials & Security: Cryptographically hashed passwords managed by Supabase Auth. Plaintext passwords are never stored or accessible by us.
- Multi-Factor Authentication (MFA): TOTP enrollment secrets and WebAuthn/Passkey public keys if you choose to activate two-step authentication in your profile settings.
- Profile Avatars: Profile photos you upload are stored in our secure Supabase Storage bucket (
avatars) with strict access controls.
3. Password Breach Verification (k-Anonymity)
During account registration and password changes, we verify that your password has not been exposed in previous public data breaches. To ensure absolute privacy, we use HaveIBeenPwned's k-anonymity model:
Your browser locally computes the SHA-1 hash of your password and transmits only the first 5 hexadecimal characters of that hash. Neither your actual password nor the full hash is ever transmitted across the network or disclosed to any third party.
4. Workspace Content & Supabase Storage Architecture
Daydraft persists your workspace content securely in Supabase cloud database infrastructure using PostgreSQL Row Level Security (RLS). When signed in:
- Tasks, Notes & Schedules: Your tasks, daily schedule plan items, focus goals, notes, and trash items are saved directly in our Supabase database tables (
tasks,daily_plan_items,notes,trash). - User Preferences & Themes: Theme choices (Light, Dark, Red, Catppuccin, One Dark), coaching insight history, and custom CSS reside in Supabase preference records linked to your user account.
- Row Level Security (RLS): Strict database RLS policies (
auth.uid() = user_id) enforce complete data isolation, guaranteeing that your workspace data can only be accessed or modified by your authenticated account. - Local Caching: For seamless performance and offline responsiveness, workspace data is cached locally in your browser's
localStorage.
5. Cookies & Session Management
Daydraft uses essential HTTP-only cookies generated by @supabase/ssr to maintain secure user login sessions across page navigations and verify access in Next.js middleware.
We do not use advertising cookies, third-party analytics trackers, or behavioral tracking pixels.
6. API Key Storage & Encryption Vault (BYOK)
If you choose to supply personal API keys for third-party AI features (Google Gemini or OpenRouter):
- Server-Side Vault Encryption: API keys saved to your account are encrypted server-side using AES-256-GCM authenticated envelope encryption with per-user derived cryptographic keys.
- Write-Once Architecture: Encrypted keys are stored as ciphertext in our database (
public.user_api_keys). They are decrypted in-memory strictly during active AI request execution and are never returned in plaintext to the browser client or logged anywhere. - Third-Party Processing: Prompts and context sent to Google Gemini or OpenRouter during AI interaction are handled in accordance with their privacy policies:
7. Your Choices & Data Rights
You have complete control over your information:
- Profile Management: You can edit your name, username, and profile avatar at any time via the Profile Settings page.
- MFA Management: You can enroll or remove TOTP factors and Passkeys directly from your security settings.
- API Key Vault Management: You can update or permanently delete your stored API keys at any time from Settings.
- Data Reset & Deletion: You can clear your workspace data using the in-app reset controls or delete individual items across tasks, notes, schedule, and trash.
- Account Deletion & Data Purging: If you request full account deletion, all associated database records (
profiles,tasks,daily_plan_items,notes,trash,user_preferences,user_api_keys) and uploaded storage avatars are permanently purged from Supabase. Contact us at praashon.dev@gmail.com.
8. Changes to this Policy
We may update this Privacy Policy as Daydraft evolves and introduces new features. The date at the top of this page indicates the most recent update. Continued use of Daydraft following any revisions signifies your acceptance of the updated policy.