── DAYCHIEF PRIVACY
Privacy Policy
DayChief is an iPhone app from FXA Digital Solutions LLC for voice, text, planning, drafting, and user-approved connected actions. This policy explains what DayChief collects, how it is used, and how users control it.
Information DayChief Collects
- Account information used to sign in, manage entitlement state, and operate the app.
- Voice audio, transcripts, text prompts, assistant responses, and conversation metadata needed to provide voice and text assistant features.
- Approval records and action context for connected-service writes that require user confirmation.
- Optional connector account metadata and authorization tokens when a user links services such as Google or Todoist.
- Usage, cost, diagnostic, and security logs used to operate the service, enforce limits, and troubleshoot issues.
- Optional Sidecar connection details, such as a Sidecar URL, pairing token, device token, and conversation identifiers when the user connects DayChief to a self-hosted Sidecar.
How Information Is Used
DayChief uses information to authenticate users, provide voice and text assistant features, prepare drafts and plans, show approval queues, execute user-approved actions, enforce entitlement and usage limits, maintain security, and respond to support requests.
Optional Connectors
Google and Todoist connectors are optional. DayChief requests the scopes needed for the workflows a user chooses to enable. Connector data is used to answer user requests, prepare drafts, create approval records, and execute actions only after the required user confirmation.
Google Workspace Data
When a user connects Google, DayChief stores the connected account identifier and email address, the permissions granted, an encrypted OAuth refresh token, and selected connector settings. Depending on the permissions the user chooses, DayChief may also access:
- Gmail: message and draft identifiers, labels, sender and recipient fields, dates, subjects, snippets, message bodies, and draft contents. DayChief uses this data for user-requested inbox views, searches, reading, summaries, and draft workflows. It creates, updates, or sends a draft only after the user approves the action.
- Google Calendar: calendar-list metadata and event details such as titles, descriptions, dates and times, recurrence, locations, attendees, and meeting links. Read-only workflows use
calendar.events.readonly; approved event changes usecalendar.events; both usecalendar.calendarlist.readonlyonly to list and select calendars. DayChief uses this data for user-requested schedule lookups and, when write access is enabled, user-approved event creation, updates, and deletion. - Google Drive: file and shared-drive identifiers, names, types, modification dates, sizes, links, and the content of supported files. DayChief uses this data only for user-requested Drive search, retrieval, and research.
Relevant Google content may be transmitted through FXA Digital's Google Cloud infrastructure and to OpenAI's API to interpret the request or produce the requested answer, summary, draft, or action preview. DayChief does not sell Google data, use it for advertising or credit decisions, or permit it to be used to train generalized AI or machine-learning models. DayChief does not create or use aggregated or anonymized datasets derived from Google Workspace content for advertising, analytics, product development, or model training. Non-content operational measurements, such as request counts, timing, and error rates, may be aggregated to operate and secure the service.
Voice, BYOA Voice, and Sidecar
Hosted DayChief voice and text features may process prompts, audio, transcripts, and assistant responses through FXA Digital infrastructure and third-party AI providers. BYOA Voice sends iOS audio through DayChief infrastructure and LiveKit while inference runs through the user's configured Sidecar. Sidecar is operated by the user; Sidecar data is controlled by that deployment unless the user shares it with FXA Digital for support.
External Processing
DayChief may use Firebase or Google Cloud infrastructure for authentication, hosting, databases, logging, speech processing, and backend operation. Hosted assistant features may use OpenAI services. BYOA Voice may use LiveKit and Google speech services for audio transport, speech-to-text, and text-to-speech. Connected-service requests are sent to the relevant provider, such as Google or Todoist, only when the user configures that connector and requests or approves the action.
Retention and Deletion
- Account, conversation, transcript, approval, usage, and connector records are retained with the user's DayChief account until the user deletes the account. There is no separate fixed deletion date before account deletion.
- Google message, event, and file content is retrieved as needed and is not maintained as a separate permanent copy. Content, excerpts, summaries, or action details that become part of a DayChief conversation or approval record remain with the account until account deletion.
- While Google remains connected, DayChief retains the encrypted refresh token, granted-scope record, selected calendar settings, and cached connector metadata needed to operate the connection.
- Disconnecting a Google account in DayChief deletes its stored OAuth token and cached connector metadata and attempts to revoke the token with Google. Disconnecting does not delete content already included in conversation or approval history; users can remove that data by deleting their DayChief account.
- Production application logs are retained for 30 days. They are designed to contain operational identifiers, status, timing, and redacted errors rather than Google message bodies, file contents, or credentials.
Users can delete their DayChief account directly in the app under Settings. Account deletion removes the Firebase authentication user and the active user-scoped backend data tree, including stored connector tokens and metadata, conversations, transcripts, voice-session records, local tasks, and pending approvals. Deleting a DayChief account does not delete data in the user's Google account, such as an email draft or calendar event that the user previously approved.
Security and Human Access
DayChief encrypts data in transit using HTTPS/TLS and uses Google Cloud encryption at rest. In production, OAuth refresh tokens are additionally encrypted with Google Cloud KMS, and service access is restricted through authenticated user boundaries and least-privilege service identities. Access tokens are used only to call the APIs authorized by the user. Application logging is designed to redact credentials and connected-service content.
FXA Digital does not routinely inspect Google Workspace content. Access by authorized personnel is limited to what is necessary when a user explicitly requests support, to investigate security or abuse, to maintain service integrity, or to comply with law. DayChief does not allow service-provider personnel to use Google data for their own purposes.
Google API Limited Use
DayChief's use and transfer to any other app of information received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Additional details are available in the Google API Disclosure.
Tracking and Advertising
DayChief does not use advertising identifiers, data brokers, third-party advertising, or cross-app tracking. FXA Digital may collect basic website analytics on fxa.digital to understand public site usage; that website analytics is separate from DayChief app tracking.
User Choices
- Users choose whether to sign in, link optional connectors, configure Sidecar, or use hosted DayChief features.
- Before connecting Google, users choose Gmail reading, Gmail draft, Calendar, and Drive access separately. A service set to No Access does not receive that Workspace permission.
- Users can approve or reject queued actions before supported connected-service writes execute.
- Users can disconnect optional services and revoke provider access from the provider account settings.
- Users can delete their DayChief account and associated app data from Settings in the app.
Contact
For privacy questions or data requests, contact FXA Digital Solutions LLC at [email protected].