Privacy

Version 2026-08-29. This is the version recorded against your account when you signed up.

Daybook holds a team's internal planning: what they are building, what is broken, what they have decided and why. That is more sensitive than most project tools admit, so this page says plainly what happens to it rather than describing a category of processing in the abstract.

Who is responsible

Daybook is operated by the individual behind https://pm.hreben.us, reachable at[email protected]. For your workspace's contents you are the controller and Daybook is the processor: you decide what goes in, and it is not looked at, mined, or used to train anything.

What is stored

Where it lives

Everything is in Helsinki, Finland, on infrastructure operated by Hetzner Online GmbH — the application, the PostgreSQL database, the uploaded files and the backups. Nothing is stored outside the EU.

Traffic reaches the servers through Cloudflare, which terminates TLS and may route through points of presence outside the EU in transit. Cloudflare does not store your workspace content.

Who else is involved

These are the only third parties that receive any data, and what each one gets:

SubprocessorPurposeWhat it receivesWhere
Hetzner Online GmbHHosting, database, file storage, backupsEverythingFinland
CloudflareDNS, TLS, proxyTraffic in transitGlobal
PostmarkTransactional emailRecipient address and message contentUnited States
StripePaymentsBilling contact and payment detailsUnited States / EU
GoogleSign-in, only if you use itThe fact that you signed inGlobal

Assistants connected over MCP are not subprocessors of Daybook. When you connect one, you are sending your own data to a provider you chose, under your agreement with them.

How long it is kept

Getting your data out, or deleted

Every workspace can be read in full through the API and the MCP connector using a key you create yourself, so an export needs nobody's permission.

There is not yet a one-click export or a self-serve account deletion. Email[email protected] from your account address and both are done by hand within 30 days, usually the same week. Deletion removes the workspace and its contents; backups containing it age out within 14 days after that.

Your rights

Under the GDPR you may ask for a copy of your data, correction of anything wrong, deletion, restriction of processing, or portability, and you may object to processing. Write to[email protected]. If the answer does not satisfy you, you can complain to your national data protection authority.

Security

Traffic is encrypted in transit. Passwords are hashed. Uploaded files sit in a private bucket and are served only through short-lived signed links. Credentials such as connected GitLab tokens are encrypted before they are stored. Backups are taken daily and a restore has been performed and verified rather than assumed.

Perfect security is not claimed by anyone honest. If something happens that affects your data, you will be told what happened and what it means, without waiting to have a tidy story.

Changes

This page carries a version. When it changes materially you will be told before the new version applies, not after.