Version 1.0 — Effective 1 August 2026

Privacy Policy

This Privacy Policy explains how DayByDay ("we", "us", or "our") collects, uses, stores, and protects your personal data when you use our household finance tracking service (the "Service"). By using the Service, you agree to the practices described in this policy.

1. Data We Collect

We collect the following categories of personal data:

  • Account information via Google OAuth: when you sign in with Google we receive your name and email address from Google. We store these to identify your account and to send you service-related notifications.
  • Financial data you upload: bank statements, transaction records, receipts, and any other files you choose to import into the Service.
  • Transactions and categories: financial transactions (amount, merchant, date, category) derived from the files you upload or entered manually.
  • Usage metadata: login timestamps, audit events, and feature usage signals that help us operate, secure, and improve the Service.

We do not collect payment card numbers, bank credentials, or any data not described above.

2. How We Use Your Data

We use your data solely to provide and improve the Service:

  • To authenticate you and maintain your account.
  • To store and display your financial transactions and reports.
  • To parse and categorise bank statements and receipts on your behalf.
  • To detect and investigate security incidents.
  • To respond to your support requests.

We do not sell, rent, or share your personal data with third parties for marketing or advertising purposes.

3. Third-Party Services

The Service relies on the following third-party services. Each has its own privacy policy and data handling practices:

  • Google OAuth — used for sign-in. When you choose "Sign in with Google", Google shares your name, email, and profile photo with us under Google's OAuth consent screen. We do not receive your Google password or access to your Google account beyond the fields you consent to share. Google Privacy Policy.
  • AI providers (statement and receipt parsing) — when you upload a bank statement or receipt for AI-assisted parsing, the document content is sent to an AI provider's API for extraction. We do not permit AI providers to use your data to train their models. Please refer to the AI provider's own privacy policy for their data retention practices.

4. Data Storage and Security

Your data is stored on servers located in Singapore. We implement reasonable technical and organisational measures — including encrypted connections (TLS), hashed passwords, and access controls — to protect your data against unauthorised access, loss, or disclosure.

No system is completely secure. You acknowledge that you use the Service at your own risk. If you suspect unauthorised access to your account, contact the administrator immediately.

5. Data Retention

We retain your data for as long as your account is active. If you request account deletion, your personal data and financial records will be removed from active systems within a reasonable time, subject to any legal retention obligations.

6. Your Rights

Subject to applicable law (including Singapore's Personal Data Protection Act 2012), you have the right to:

  • Access the personal data we hold about you.
  • Export your transaction data in machine-readable format via the in-app export feature.
  • Correct inaccurate personal data associated with your account.
  • Delete your account and associated data by contacting us.

To exercise any of these rights, please contact us using the details in Section 8 below.

7. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will increment the version number shown at the top of this document and, where practical, notify active users. Your continued use of the Service after changes become effective constitutes your acceptance of the updated policy.

8. Contact

If you have questions about this Privacy Policy or wish to exercise your data rights, please contact the administrator of your DayByDay instance via the Contact page.

Version 1.0 · Effective 1 August 2026