Daytrove privacy policy
Version 2, effective 20 September 2026.
The Daytrove app shows this same policy, word for word.
On this page
The short version
#- Daytrove keeps the health data you choose to share on your device and in your Daytrove account, so your devices stay in sync.
- We do not show ads and we do not sell your data. We do not share your health data with other companies, except the providers that store and process it for us, as described below. The app carries no advertising tools, and no analytics beyond the crash and barcode-scanner diagnostics described below.
- We read only the health data types you approve, and we write only the weigh-ins you choose to save.
- You can export or delete your data from Settings.
- Daytrove is not a medical device.
Who we are
#Daytrove is provided by Pankaj Singh, a sole proprietor trading as Doon Digital (Doon Apps in the app stores), Lane No. 5G, Shimla Bypass Rd, Shivraj Nagar, Mehuwala, Badowala, Dehradun, Uttarakhand 248007, India ("we", "us"). Daytrove is offered in the App Store and Google Play in every country where they operate, except mainland China, the European Union, Iceland, Liechtenstein, Norway, the United Kingdom, Switzerland, South Korea and Brazil.
- Privacy questions and requests: hello@daytrove.app
- Grievance officer: Pankaj Singh (hello@daytrove.app)
What Daytrove is
#Daytrove is a health and fitness tracker for phones, watches and the web. It reads the data you choose to share from Apple Health or Health Connect, including data that other apps, such as Samsung Health, save there. It also lets you log water, food, habits and weight.
Data we collect
#- Account: your email address, which we use to send sign-in codes. Daytrove does not use passwords. If you sign in with Google or Apple, where the app offers it, we also receive the name, email address and account identifier they share with us.
- Profile: your display name if you set one, your units, your daily step and water goals, and a daily active energy goal if you set one.
- Health data you allow us to read: steps, distance, active energy, heart rate, resting heart rate, heart rate variability, weight, sleep sessions and stages, and workouts with the distance, energy and steps recorded during each one. For each reading we also keep which app or device recorded it.
- Data you enter: water, food and its nutrition values, habits and check-ins, reminders, weigh-ins, and any notes you add.
- Watch app: water you log and workouts you record on the Daytrove watch app, which it sends to the app on your phone. Live heart rate from the watch is shown on your phone but not saved.
- History you import: readings from an Apple Health, Google Fit (Google Takeout) or Samsung Health export that you choose. The file is read on your device, and only the readings are synced to your account. We keep only the kinds of readings we would read from Apple Health or Health Connect: steps, distance, active energy, heart rate, resting heart rate, heart rate variability and weight, plus workouts and sleep sessions with their stages. Anything else in the file, such as floors climbed, blood oxygen, body fat, resting (basal) energy or location, is left out on your device and never sent to us.
- Devices: for each phone or browser you sign in from, a random device id, the platform, the device model, the app version and when it was last seen.
- Consent record: which versions of the terms, this policy and the consent screen you accepted, that you confirmed you are 18 or older, whether you agreed to the processing of your health data, the app version and platform you used, and when. Withdrawals are recorded too, as a history.
- Sign-in sessions: when each session started and when it expires, and the app or browser name your device sends (its user agent).
- Security log: a record of sign-ins, "sign out everywhere", devices added or removed, profile changes, consent withdrawals and the erasure that follows, and export and deletion requests (including ones you make by email), with the time, and the device where we know it.
- Network (IP) address: we use it to limit repeated sign-in attempts and, in the web app, for the bot check at sign-in. We do not save it in your account, your sessions or the security log.
- Crash reports, only in builds where crash reporting is on: when the app hits an error, the error details, device model, operating system, app version, and the kinds of screens you opened just before it (for example a metric's detail screen, not which metric). Before sending, the app removes email addresses, sign-in tokens and codes, and masks numbers, quoted text and metric names in the error messages from its own code. Errors inside the phone's operating system or other native code are reported as the system describes them. Crash reports never include screenshots or recordings of the screen. When our server hits an error, the error details and which part of the service was called, without the request's body, query, cookies, authorization header or your network address, and with numbers and quoted text in error messages masked. Timing data from a small share of app sessions and server requests may also be sent.
- Service logs: our servers log each request: which part of the service was called, the result, how long it took, and sometimes your account id. Cloudflare's request logs can also include your network address and the approximate location it points to.
How we use your data
#We use your data only to run Daytrove for you:
- show your dashboard, charts, totals and scores
- keep your data in sync across your devices
- send sign-in codes
- keep your account secure, with sign-in limits, the security log and the bot check at web sign-in
- find and fix errors
Reminders are scheduled on your device.
We do not use your data for advertising or marketing, to decide on credit or lending, or to build profiles for anyone else. We do not use AI to process your health data, and we do not use any of your data to train AI models, including large language models.
Daytrove does not track you across other companies' apps or websites, and it does not let advertising or analytics companies do so, so a browser's Do Not Track signal changes nothing in Daytrove.
Apple Health and Health Connect
#Daytrove can ask to read the health data types listed above, and reads only the types you approve. On Android it can also check for new data in the background if you allow it.
Daytrove asks to write one type, weight. It writes a weigh-in only when you log one and choose to save it to Apple Health or Health Connect. The phone app writes nothing else. The Daytrove Apple Watch app, when it is released, saves the workouts you record to Apple Health, with the heart rate, energy, distance and steps it measures during them.
For data from Apple Health and Health Connect:
- We use it only to provide Daytrove's features to you.
- We never use it for advertising or marketing, and we never sell it.
- We do not share it with anyone unless you ask us to or the law requires it. Cloudflare stores it on our behalf as our hosting provider.
- We never use it to decide creditworthiness or lending.
- People at Daytrove do not look at it unless you ask us to, for example in a support request, or we need to for security or legal reasons.
- Daytrove never uploads it to iCloud. Your phone's own backup can still include the app's copy, as the next section explains.
You can remove access at any time in the Health app on iPhone or in Health Connect on Android. Daytrove then stops reading new data. Data already synced stays in your account until you delete it, withdraw your health-data consent, or delete your account.
Where your data is stored
#- On your device: in the app's private storage, or in your browser's storage if you use the web app. Daytrove does not add its own encryption to this copy. It relies on your device's protection, such as your screen lock.
- Device backups: if you turn on your phone's own backup, such as iCloud Backup or Google backup, it can include the app's copy on your phone.
- After you sign out: signing out or deleting your account does not remove the copy on your device. Withdrawing your health-data consent does, and you stay signed in. So does signing in to a different account on the same device: Daytrove first removes the previous account's copy, its unsynced changes and its reminders. Signing in again to the same account keeps it. To remove it otherwise, uninstall the app, or clear this site's data in your browser.
- In your account: on Cloudflare's servers. Cloudflare encrypts the data it stores, and data moving between your device and our servers is encrypted (HTTPS).
- Location: Cloudflare runs data centers in many countries, so your data may be stored and processed outside the country you live in. Some of your data, such as detailed readings, is stored in a Cloudflare data center near where you first synced. We do not yet use Cloudflare's options to keep data inside one country or region.
Service providers
#These companies process data for us:
- Cloudflare (Cloudflare, Inc., United States): hosting, databases, file storage for exports and backups, service logs, the bot check at web sign-in, and sending your sign-in codes by email, for which it receives your email address and the code.
- Sentry (Functional Software, Inc., United States): crash reports, only in builds where crash reporting is on, as described above.
- Open Food Facts: when you scan a barcode or search for a food, the app asks Open Food Facts directly and loads product images from it. Open Food Facts receives the barcode or your search words and your network address. It does not receive your account or health data.
- Google: on Android, the barcode scanner uses Google's ML Kit. The camera image is processed on your phone, but ML Kit sends Google diagnostic data, including device and app information, performance data, and identifiers for your device or this installation of the app. If you sign in with Google, Google confirms who you are. The web app loads its engine and fonts from Google's servers, which see your network address.
- Apple: if you sign in with Apple, Apple confirms who you are.
We do not sell your data, and we do not give it to advertisers or data brokers.
How long we keep data
#- Account, profile, synced readings and entries: until you delete them or delete your account. Your daily and weekly totals are worked out from this data and are updated when it changes.
- Entries you remove one at a time: they disappear from your devices, and our servers clear their values as soon as the deletion reaches them. Until you delete your account we keep only a deletion marker: the entry's id, which app or device it came from (and its id there), and when it was created, changed and deleted, so that your other devices remove it too. Copies made before the deletion stay in our backups until those are deleted, within 30 days (see Backups).
- Recent changes used to update your other devices: 90 days.
- Sign-in codes: expire after 10 minutes.
- Sign-in sessions: stop working 60 days after you last use them, or when you sign out.
- Export files: each download link works once and expires after 15 minutes. We delete the file within 8 days.
- Service logs: up to 7 days.
- Crash reports: up to 90 days.
- Backups: Cloudflare keeps restore points of our databases, and we keep a copy of the databases made before each server update. Both are deleted within 30 days.
- Consent history: as long as your account exists. It is deleted with your account.
- Security log: 12 months. When you delete your account, we remove your account id, device id and other details from its entries straight away, so they show only what happened and when.
Your controls
#- Export your data: Settings > Data > Export my data. You get a zip file with your data as JSON and CSV files. We may first email you a code to confirm it is you. The zip includes your consent history. Withdrawing your health-data consent erases export files too, so download yours first.
- Delete your account: Settings > Data > Delete account. We may first email you a code to confirm it is you. From the moment you ask, nothing new is uploaded or synced from any of your devices, but you can still see and export your data. Your account is deleted at our first nightly clean-up after 7 days, and you can cancel from Home or Settings until that clean-up starts.
- What deletion removes: your account, profile and sign-in methods, every health reading and entry synced to Daytrove, your devices, sessions, pending sign-in codes, export files and consent history. Data in Apple Health or Health Connect is not touched.
- Delete without the app: email hello@daytrove.app from the address on your account. We schedule the same deletion, which you can still cancel in the app within 7 days.
- Remove entries: swipe to remove water entries and weigh-ins, and archive habits you no longer track.
- Withdraw your health-data consent: Settings > Data > Health data consent, with one confirmation and no emailed code. What happens then is explained under Your rights.
- Stop health data access: in the Health app on iPhone or in Health Connect on Android. On Android, withdrawing your consent also gives back Daytrove's Health Connect access.
- Sign out everywhere: Settings > Account > Sign out everywhere ends your sessions on every device.
- Edit your profile: Settings > Profile.
Your rights
#You can ask to see, correct or erase your data, and you can withdraw your consent. You can do most of this yourself with the controls above. You can withdraw your consent to the processing of your health data at any time in Settings > Data > Health data consent, with one confirmation. Syncing stops at once, and within minutes we erase the health data you synced to Daytrove: readings, entries, daily and weekly summaries, and export files. The copy on the device you use is removed straight away, and your other devices remove theirs the next time they connect. Backups are deleted within 30 days. Your account, email address, devices and consent history stay, and you can consent again later and start from an empty account. Withdrawing does not affect processing before you withdrew.
You can also email hello@daytrove.app from the address on your account. That is how we confirm the request is yours. We reply to every request within 30 days.
If you are in India, the Information Technology Act, 2000 and its rules on sensitive personal data let you review and correct the information you gave us and withdraw your consent. If you are not satisfied with our reply, write to our grievance officer, Pankaj Singh, at hello@daytrove.app; grievances are resolved within one month. When the main parts of the Digital Personal Data Protection Act, 2023 come into force, expected in May 2027, you will also be able to ask for a summary of your data and of who processed it, nominate someone to use your rights if you die or cannot use them yourself, and complain to the Data Protection Board of India.
Depending on where you live, local law may give you other rights. Write to us to use them.
Children
#You must be at least 18 to use Daytrove. It is not meant for children, and we do not knowingly create accounts for them. If you think a child has an account, write to hello@daytrove.app and we will delete it, without the usual 7 days to cancel.
Security
#- Data is encrypted in transit, and Cloudflare encrypts the data it stores.
- You sign in with a one-time code sent to your email, or with Google or Apple where the app offers it. Daytrove has no passwords.
- Exporting your data or deleting your account needs a recent sign-in, confirmed with a code sent to your email address.
- Sign-in attempts and sync requests from each account are rate limited.
- If a breach affects your data, we will tell you and the authorities as the law requires.
Health disclaimer
#Daytrove is not a medical device and does not diagnose, treat, cure, or prevent any medical condition. Scores and trends are estimates. Talk to a doctor or another healthcare professional about anything that worries you.
Changes to this policy
#When we change this policy, we update the version and date at the top. When the version changes, the app asks you to accept the new version before you continue. The app also asks for your consent again when the wording of the consent screen changes. We keep every version.