Privacy
Version 2026-08-29. This is the version recorded against your account when you signed up.
Daybook holds a team's internal planning: what they are building, what is broken, what they have decided and why. That is more sensitive than most project tools admit, so this page says plainly what happens to it rather than describing a category of processing in the abstract.
Who is responsible
Daybook is operated by the individual behind https://pm.hreben.us, reachable at[email protected]. For your workspace's contents you are the controller and Daybook is the processor: you decide what goes in, and it is not looked at, mined, or used to train anything.
What is stored
- Account details — email address, display name, a hashed password, and if you sign in with Google, the identifier Google returns. Passwords are hashed and never recoverable.
- Workspace content — projects, objectives, epics, work items, comments, documents, releases, labels and any files attached to them.
- Feedback you collect — including anything the person submitting it typed, and the page context your widget captured.
- Activity — who changed what and when, including which assistant made a change through the connector.
- Operational logs — requests, errors and email delivery records.
- Billing — a Stripe customer and subscription reference. Card numbers never reach Daybook; Stripe holds them.
Where it lives
Everything is in Helsinki, Finland, on infrastructure operated by Hetzner Online GmbH — the application, the PostgreSQL database, the uploaded files and the backups. Nothing is stored outside the EU.
Traffic reaches the servers through Cloudflare, which terminates TLS and may route through points of presence outside the EU in transit. Cloudflare does not store your workspace content.
Who else is involved
These are the only third parties that receive any data, and what each one gets:
| Subprocessor | Purpose | What it receives | Where |
|---|---|---|---|
| Hetzner Online GmbH | Hosting, database, file storage, backups | Everything | Finland |
| Cloudflare | DNS, TLS, proxy | Traffic in transit | Global |
| Postmark | Transactional email | Recipient address and message content | United States |
| Stripe | Payments | Billing contact and payment details | United States / EU |
| Sign-in, only if you use it | The fact that you signed in | Global |
Assistants connected over MCP are not subprocessors of Daybook. When you connect one, you are sending your own data to a provider you chose, under your agreement with them.
How long it is kept
- Workspace content — until you delete it. Deleting is reversible for a period, because an accidental deletion is more common than a malicious one.
- Backups — 14 days, then permanently removed. Content you delete can persist in a backup until it ages out.
- Operational logs — 3 days for diagnostic detail, 14 days for ordinary requests, 45 days for warnings, 180 days for errors.
- Billing records — as long as tax law requires, which is longer than the rest.
Getting your data out, or deleted
Every workspace can be read in full through the API and the MCP connector using a key you create yourself, so an export needs nobody's permission.
There is not yet a one-click export or a self-serve account deletion. Email[email protected] from your account address and both are done by hand within 30 days, usually the same week. Deletion removes the workspace and its contents; backups containing it age out within 14 days after that.
Your rights
Under the GDPR you may ask for a copy of your data, correction of anything wrong, deletion, restriction of processing, or portability, and you may object to processing. Write to[email protected]. If the answer does not satisfy you, you can complain to your national data protection authority.
Security
Traffic is encrypted in transit. Passwords are hashed. Uploaded files sit in a private bucket and are served only through short-lived signed links. Credentials such as connected GitLab tokens are encrypted before they are stored. Backups are taken daily and a restore has been performed and verified rather than assumed.
Perfect security is not claimed by anyone honest. If something happens that affects your data, you will be told what happened and what it means, without waiting to have a tidy story.
Changes
This page carries a version. When it changes materially you will be told before the new version applies, not after.