Back to StackDaily

Privacy Policy

Last updated: September 2, 2026

1. Introduction

StackDaily ("StackDaily," "we," "our," or "us") is a health and productivity app available on the web and on iOS through the Apple App Store. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices you have.

By creating an account or using StackDaily, you agree to the practices described in this policy. If you do not agree, please do not use the app.

2. Information We Collect

2.1 Information You Provide

  • Account information: email address, name, and authentication credentials. If you sign in with Google, we receive your basic Google profile (name, email, profile picture) via OAuth.
  • Profile information: age, height, weight, biological sex, activity level, and health goals you share during onboarding.
  • Health and fitness data: nutrition logs, calories, steps, workouts, weight entries, habits, sleep notes, and any related notes you enter manually or capture via photo.
  • Productivity data: tasks, notes, calendar events, meeting notes, and CRM contacts you create inside the app.
  • Support communications: messages, attachments, and metadata when you email us or report a problem from the app.

2.2 Information from Third-Party Services You Connect

When you choose to connect an integration, we receive data from that service:

  • Apple HealthKit (iOS): only the metrics you authorize. StackDaily reads steps, active energy, walking and running distance, resting heart rate, sleep, and workouts. With your permission it writes the workouts and the calories, protein, carbohydrates, and fat you log back to Health. It does not read body weight or body measurements from HealthKit. HealthKit data stays on your device unless you grant permission to read it. See Section 6.1 for how HealthKit data is handled once synced.
  • Fitbit: steps, calories burned, heart rate, sleep, weight, and activity metrics you authorize through Fitbit's OAuth flow.
  • Google: basic profile information for sign-in, plus calendar events if you connect Google Calendar.

You control which data is synced through Settings > Integrations, and you can disconnect any service at any time.

2.3 Information Collected Automatically

  • Device information (model, OS version, app version, language, time zone).
  • Device identifiers used by the iOS app, including the Apple Identifier for Vendors (IDFV) and the Apple Push Notification service (APNs) token used to deliver push notifications you opt in to.
  • Usage events and feature interactions used for product analytics and debugging.
  • Error logs and performance data (crash reports, latency, failed requests).
  • IP address and approximate location at the country / region level.

2.4 Payment Information

Subscription purchases on the web are processed by Stripe, and subscription purchases on iOS are processed by Apple and reconciled through RevenueCat. StackDaily does not receive or store your full payment card number, CVC, or bank account details. We retain only the information needed to manage your subscription (plan, status, renewal date, last four digits, country, and a processor identifier).

3. How We Use Your Information

We use your information to:

  • Provide, maintain, and improve the StackDaily app and related services.
  • Calculate health metrics such as BMR, TDEE, calorie targets, macro splits, and habit streaks.
  • Personalize dashboards, reminders, and insights for your goals.
  • Sync data between StackDaily and the third-party services you connect.
  • Power the AI features you choose to turn on, including meal photo analysis, food parsing, note summaries, task prioritization, workout coaching, and the StackDaily Assistant. The content these features work on is sent to OpenAI for processing. Section 5.1 lists exactly what is sent, and nothing is sent until you agree in the app.
  • Send you account, billing, security, and service notifications.
  • Send optional product communications (such as the weekly digest, daily brief, and trial-ending reminders) that you can disable in Settings.
  • Respond to support requests.
  • Detect and prevent fraud, abuse, and security incidents.
  • Comply with our legal obligations.

4. Data Sharing and Disclosure

We do not sell your personal information, and we do not share it with advertisers. We share information only in the following situations:

  • With service providers (subprocessors): the vendors listed in Section 5 who process data on our behalf under written contracts.
  • With your consent: when you explicitly authorize a connection or share.
  • For legal reasons: when required by law, subpoena, or other valid legal process, or to protect the rights, safety, or property of StackDaily, our users, or the public.
  • In a corporate transaction: in connection with a merger, acquisition, financing, or sale of assets, in which case we will notify you and continue to honor this policy.

5. Third-Party Processors

The following providers process StackDaily data on our behalf. Each is bound by a data processing agreement and only handles the data needed for its role.

  • Supabase: primary database, authentication, and file storage. All account, health, and productivity data is stored here under row-level security.
  • Cloudflare R2: storage of images you attach to notes. Meal and nutrition-label photos are stored in Supabase Storage. In both cases files are private and are retrieved only through signed links.
  • Google (OAuth): sign-in and, if you connect it, Google Calendar access.
  • Apple: App Store purchase processing, Sign in with Apple, and delivery of push notifications via APNs. If you choose Hide My Email when signing in with Apple, we store and use the private relay address Apple provides; we never ask you to replace it with another address.
  • RevenueCat: management and reconciliation of in-app subscription purchases.
  • Stripe: processing of web subscription payments.
  • Fitbit: retrieval of activity, sleep, and body metrics that you authorize.
  • Resend: delivery of transactional and product emails (account, billing, digests).
  • OpenAI: processing for AI features. Because this is the processor that receives the content you create in StackDaily, it is described in full in Section 5.1.

Each provider has its own privacy policy. We encourage you to review them if you would like more detail on how they handle data.

5.1 OpenAI and AI features

StackDaily's AI features are powered by OpenAI, a company in the United States. When you use an AI feature, StackDaily sends what you are working on to OpenAI and shows you what comes back. OpenAI acts as our processor for this purpose only.

Nothing is sent to OpenAI until you agree in the app. Before your first AI request, StackDaily shows you this same list and asks you to turn AI features on. You can turn them off at any time in Settings > Privacy; from that moment no further content is sent, AI features become unavailable, and everything you have already logged stays exactly as it is.

What StackDaily sends to OpenAI:

  • Your display name, time zone, and daily calorie target, which give the Assistant context on every request
  • Food descriptions, and meal or nutrition-label photos you ask StackDaily to analyze
  • Your weight history and calorie or macro targets, when you ask something that needs them
  • Your training profile — including any injuries or areas to avoid that you have entered
  • Note text you ask StackDaily to summarize, rewrite, or extract tasks from
  • Task titles, descriptions, due dates, and tags you ask StackDaily to organize or reprioritize
  • Habit names and goals you ask StackDaily to build a plan around
  • Details you have saved about other people — name, email, phone, job title, and your notes about them — when you ask StackDaily to summarize a contact
  • Titles and times of your upcoming calendar events, when a request needs your schedule
  • Messages and images you send to StackDaily Assistant

Information about other people. One of these categories is not about you. If you ask StackDaily to summarize or enrich a contact in Teams & People, the details you have saved about that person — their name, email address, phone number, job title, and the notes you have written about them — are sent to OpenAI to produce the summary. Those people have not agreed to this themselves. By turning on AI features you confirm you are comfortable sharing the contact details you have chosen to store in StackDaily for this purpose, and you can use the CRM without ever running an AI feature on it.

What StackDaily never sends to OpenAI:

  • Your email address, password, or payment information
  • Steps, workouts, heart rate, and sleep synced from Apple Health
  • Anything you have not run an AI feature on

How OpenAI handles it. StackDaily uses OpenAI's API under OpenAI's business terms. Under those terms, OpenAI does not use content sent through the API to train or improve its models, and retains API inputs and outputs for up to 30 days solely to detect abuse and misuse, after which they are deleted. OpenAI states these commitments in its API data usage and enterprise privacy terms. We consider these protections equivalent to our own for the content involved.

Meeting audio. StackDaily does not currently record or transcribe audio. If we add meeting transcription in the future, audio will be transcribed on your device and will not leave it; the resulting text transcript would be sent to OpenAI for summarization, and both this policy and the in-app disclosure will be updated before that feature is released.

6. Third-Party Integrations You Control

6.1 Apple HealthKit

Health data is treated as its own category. Data read from HealthKit with your permission — steps, active energy, distance, resting heart rate, sleep, and workouts — is stored in your StackDaily account under row-level security so that it can appear in your dashboards and be reconciled with the same metrics from Fitbit. It is used only to provide the features you see in the app. It is never used for advertising or marketing, never sold, never shared with data brokers, and never sent to OpenAI or any other AI provider. You can revoke StackDaily's HealthKit access at any time in the iOS Health app or Settings, and disconnecting stops all future syncing.

6.2 All integrations

When you connect Apple HealthKit, Fitbit, or Google Calendar:

  • We only access the data you authorize through the integration's permission screen.
  • Data is synced according to the preferences you set in Settings > Integrations.
  • You can change permissions or disconnect at any time.
  • Disconnecting stops future syncing. You may also delete data that was previously synced from your StackDaily history.

7. Data Security

We use industry-standard safeguards to protect your information, including:

  • Encryption in transit using HTTPS / TLS.
  • Encryption at rest for the database and file storage.
  • Row-level security so each account can only read and write its own data.
  • Scoped service credentials, audit logging, and least-privilege access for our team.
  • Support for OAuth and biometric unlock on supported devices.

No system is perfectly secure. If we ever become aware of a security incident affecting your information, we will notify you as required by applicable law.

8. Data Retention

We keep your information for as long as your account is active and as needed to provide the service.

  • Account and profile data: retained until you delete your account.
  • Health, habit, and productivity data: retained until you delete the individual entries or your account.
  • Audit and security logs: retained for up to 90 days for security and debugging.
  • Billing records: retained as required by tax and accounting laws (typically up to 7 years).

You can delete individual entries (logs, weight, notes, contacts) at any time. Deleting your account removes your account and associated app records from our active database. Images attached to notes are removed through a separate cleanup process, with retries when needed. We retain limited deletion and security records to verify cleanup and prevent deleted image references from being reused. Temporary image links can remain usable until they expire or the stored image is removed. Backup copies follow our storage providers’ configured retention periods.

9. Your Rights and Choices

You have the right to:

  • Access: view and export your data from Settings.
  • Correction: update inaccurate information in your profile and logs.
  • Deletion: delete specific entries or your entire account from Settings.
  • Portability: request a copy of your data in a machine-readable format.
  • Withdraw consent: turn AI features off in Settings > Privacy, disconnect integrations, or revoke push and HealthKit permissions at any time.
  • Opt out: turn off non-essential emails and push notifications in Settings.

Depending on where you live, you may also have additional rights under laws such as the GDPR (EEA / UK), CCPA / CPRA (California), or similar state laws. To exercise any right, use Settings or contact us at privacy@stackdaily.ai. We will respond within the timeframes required by applicable law.

10. Children's Privacy

StackDaily is not directed to children. You must be at least 13 years old to use StackDaily, or 16 if you are in the European Economic Area or the United Kingdom. We do not knowingly collect personal information from children below these ages. If we learn that we have, we will delete the data and the associated account.

11. International Data Transfers

StackDaily and its processors operate primarily in the United States. If you use the app from outside the U.S., your information will be transferred to and processed in the U.S. and other countries that may have different data protection laws than yours. We rely on appropriate safeguards (such as Standard Contractual Clauses, where applicable) to protect your information during these transfers.

12. Changes to This Policy

We may update this Privacy Policy as our app evolves. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify you in the app or by email. Your continued use of StackDaily after the changes take effect means you accept the updated policy.

13. Contact Us

If you have questions, concerns, or requests about this Privacy Policy or our data practices, contact us at: