Your data, clearly explained
Privacy
Policy.
Information we access
Daylight may access the following information when you use the service:
- Google account information: your name, email address, and profile image, used to authenticate you and identify your Daylight session.
- Connected calendar event information: event identifiers, titles, dates and times, all-day status, locations, event links, and provider information from any Google Calendar or Microsoft Outlook Calendar you choose to connect.
- Connection information: Google or Microsoft OAuth access and refresh tokens, the connected account email, and technical metadata needed to maintain each calendar connection.
- Basic technical information: session cookies and ordinary request information needed to operate, secure, and troubleshoot the service.
Daylight requests the Google Calendar calendar.events.readonly scope and, when you connect Outlook, Microsoft Graph Calendars.Read and User.Read. It does not request permission to create, modify, or delete events.
How we use calendar data
Daylight uses connected account and calendar data only to provide the features you see in the product. Specifically, it is used to:
- sign you in and associate the calendar connection with your account;
- retrieve events from the Google and/or Outlook calendars you choose to connect;
- display your schedule, next event, event timing, and event location inside Daylight;
- refresh an authorized connection so your schedule stays current; and
- protect, maintain, and troubleshoot the service.
Daylight's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
How data is stored and protected
Google and Microsoft OAuth tokens and connection credentials saved by Daylight are encrypted with AES-256-GCM before they are written to the service database. Tokens and credentials are handled only on the server and are not returned to the browser.
Calendar event details are requested from the providers you connect when you use the dashboard and are sent to your browser to render your schedule. Daylight does not write those event details to its application database. Calendar responses are marked private and not cacheable.
Daylight uses reasonable technical safeguards, but no internet service can guarantee absolute security.
Your choices and control
You can disconnect Google Calendar or Outlook Calendar independently from within Daylight. When you disconnect a provider, Daylight clears the stored OAuth tokens for that connection. Daylight also attempts to revoke Google authorization when Google is disconnected. You can review or revoke access at any time from your Google or Microsoft account settings.
Some limited account and connection metadata may remain where necessary for security, service integrity, or legal obligations. Revoking access stops Daylight from retrieving new calendar data.
Changes to this policy
This policy may be updated as Daylight changes. Material changes to how connected calendar data is accessed, used, stored, or shared will be reflected here, with an updated date and any consent required by applicable policy or law.