DayPilot
Privacy Policy
Last updated: October 3, 2026
DayPilot is a personal planning service that schedules your tasks around your calendar. This policy explains what information DayPilot stores, why, who else sees it, and how to remove it. It applies to the website at daypilot.app and the DayPilot apps.
Information DayPilot stores
- Account details. Your email address, display name, password hash (if you use a password), time zone, preferences, and an optional profile picture. If you sign in with Google or Apple, DayPilot stores the identifier those services use for your account so it can recognize you next time. Apple may provide a private relay email address instead of your real one; DayPilot treats it like any other address.
- Your planning data. Tasks, projects, schedules, templates, attachments you upload, and the plan DayPilot computes from them, including how often a planned block was missed.
- Calendar data. If you connect Google Calendar, DayPilot reads the events of the calendars you choose (titles, times, free/busy status, recurrence) and stores a copy of the events within the planning window so it can plan around them. It writes the task blocks it plans to the calendar you pick. DayPilot keeps the authorization tokens Google issues so it can keep syncing; it does not store your Google password.
- Emailed tasks. If you send email to your private DayPilot inbox address, DayPilot stores the message, turns it into a task, and keeps a record of the sender, subject and outcome.
- Devices. If you enable notifications in the app, DayPilot stores the push token for that device.
- Billing. If your workspace subscribes to a paid plan, DayPilot stores the plan, its status and renewal date, and the subscription and customer identifiers assigned by the payment processor (Stripe on the website, Apple in the app). DayPilot never sees or stores your card number.
- Workspace membership. Which workspace you belong to, your role in it, groups you are in, and invitations sent to you.
- Technical logs. The server keeps short-lived logs of requests and errors for troubleshooting. They are not used for advertising or profiling.
How DayPilot uses it
Only to provide the service: planning your time, syncing with your calendar, turning emails into tasks, sending the notifications you turn on, and letting people in your workspace share projects you choose to share. DayPilot does not sell your data, show advertising, or use your data to train models.
Services DayPilot relies on
- Google for Sign in with Google and Google Calendar. DayPilot's use of information received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements: calendar data is used only to plan your tasks and write your planned blocks back, is never transferred to others except as needed to provide the service, and is never used for advertising. You can revoke DayPilot's access at any time from your Google account's security settings or by disconnecting the calendar in DayPilot.
- Apple for Sign in with Apple, push notifications to Apple devices, and in-app purchases. Apple processes app subscriptions under its own privacy policy; DayPilot receives only the subscription status, not your payment details.
- Stripe to take payment for plans bought on the website. Your card details and billing address go directly to Stripe and are handled under Stripe's privacy policy; DayPilot receives a customer identifier, the plan and its status.
- OpenAI to draft a title, estimate and due date from an email you send to your inbox address. The content of that email is sent to OpenAI for that purpose only. Email is not sent to OpenAI unless you use the inbox feature.
- Resend to receive the emails you send to your DayPilot task address ([email protected]), and to deliver DayPilot's own emails: the link that confirms your address when you sign up with a password, password reset links and notices, and workspace invitations. Resend handles those messages and their sender and recipient addresses; it does not receive your tasks or calendar.
DayPilot is self-hosted; your data lives on the operator's own server rather than with a cloud provider, protected by encrypted connections.
Who can see your data
Your personal tasks and calendar are visible only to you. Work you place in a shared group is visible to that group's members, and workspace admins can see who is in the workspace. Nobody outside your workspace can see your data. The operator of the server can access the database for maintenance and support and does not look at your content otherwise.
Retention and deletion
Data is kept while your account exists. You can delete tasks, projects, attachments and calendar connections individually at any time. Deleting your account (Preferences → Account on the web, or Settings → Account in the app) removes your personal data, uploaded files, calendar copies and device tokens, revokes DayPilot's access at Apple and Google, and removes any DayPilot-created events from your Google Calendar. Shared group work stays with the workspace. Backups are kept for 14 days and then overwritten.
Children
DayPilot is not directed at children under 13 and does not knowingly collect information from them.
Changes
If this policy changes in a way that matters, the date above will change and the website will say so.
Contact
Questions about privacy, requests about your data, or anything else: [email protected].