How DeepDay handles your data
Last updated 21 September 2026 (version 2026-09-21).
Who we are
DeepDay is run by NexFood Sweden AB (organisationsnummer 559341-0490), Högerudsgatan 18 D, 216 13 Limhamn, Sweden. We decide how your data is used, which makes us the controller under the GDPR.
Questions, requests and complaints go to hello@deepday.app. We answer within one month.
What you give us
- Your account: your name, email address and a handle others can mention you by.
- Your work: the workspaces, projects, tasks, notes, comments and daily picks you and your team write. Your teammates see what is shared in your workspace, private projects stay yours, and your workspace's admins can export the workspace, members' names and emails included. DeepDay staff can open an account read-only to solve a problem you raised; each view lasts at most an hour and is recorded.
- Your settings: timezone, working hours, reminders, theme, and where you are if you tell us (see Prayer times and location below).
- Only if you use them: calendar links you add (stored encrypted, and read on your behalf from the calendar you chose), the Telegram bot (your chat id, Telegram username and the messages you send it), and phone notifications (your device's push address and browser name).
- The waitlist: if you asked for a seat, your name, email and, for a company, its name and the number of seats.
What we record ourselves
- One sign-in cookie, which keeps you signed in for up to 45 days. It cannot be read by scripts on the page. Staff who use the admin console get a few more, short-lived ones.
- A few preferences kept in your own browser, such as light or dark mode, sounds, and which tips you have dismissed.
- When you were last active, updated at most every 15 minutes, and which days your workspace closed its day, which is how the free year is earned.
- A record of what happened in your workspace (a task added, a project moved) that you and your team see in your history.
- Counts of requests per page per hour, with no person in them, and errors the app hits, with the page and a technical trace.
- Rate-limit records that stop sign-in abuse. They are stored scrambled, so they hold no readable email or IP address, and are deleted after about a day.
What we do not do
No advertising, no selling or sharing your data for marketing, no profiling, no third-party analytics and no tracking cookies. That is why there is no cookie banner: there is nothing to consent to.
Prayer times and location
Your location is optional. You can pick a city, use your device's location (rounded to about 11 metres), or type coordinates. Until you choose, DeepDay guesses a nearby city from your timezone. We use it to work out your prayer times, which set the shape of your day.
Prayer settings, such as prayer names on your day, Ramadan mode, the Asr school, the Hijri date, prayer-time adjustments and the calculation method, can show your faith. We keep them only after you agree, and only to time your day. Teammates who can see your day see it in the same words. You can withdraw in Settings at any time, which switches your day to sun words and puts the prayer settings back to their defaults.
Who else handles your data
These services process data for us, under our instructions, and only for the purpose named.
- Supabase: our database and sign-in. Your data is stored in Stockholm, Sweden.
- Vercel: runs the DeepDay website and app, in Stockholm, Sweden, and keeps short-lived technical request logs.
- Resend: sends our emails, such as sign-in codes, invitations and reminders you asked for.
- Hostinger: hosts the hello@deepday.app mailbox.
- AlAdhan (api.aladhan.com): calculates prayer times. It receives your location rounded to about 1 kilometre, the date and your calculation settings. Never your name or email.
- Your browser's notification service (from Apple, Google or Mozilla): delivers notifications you turned on.
- Telegram: only if you link the bot. It carries your messages to the bot and its replies.
Supabase, Vercel and Resend are companies based in the United States. Where a provider handles data outside the EU, the transfer relies on the EU standard contractual clauses or the EU-US Data Privacy Framework, as set out in that provider's data processing terms.
Why we may use it
- To provide the service you signed up for: your account, your work and your settings.
- Our legitimate interest in keeping DeepDay safe and working: the sign-in cookie, rate limits, error records and the admin audit log.
- Your consent: prayer settings, which you can withdraw.
How long we keep it
- Your account and your work: until you ask us to delete your account. Deletion removes your personal details, settings and devices, and replaces your name and email wherever they appear; work you wrote in a shared workspace stays with the team, no longer linked to you.
- Workspace history and the admin audit log: 2 years.
- Error records and request counts: 90 days.
- Rate-limit records: about a day.
- A data export we prepared for you: 30 days.
- Waitlist entries: 12 months.
- Database backups: kept by Supabase for a short period, then overwritten.
Your rights
You can ask to see your data, receive a copy of it (we send a complete export in a machine-readable file), correct it, delete it, restrict or object to how we use it, and withdraw a consent. Most settings you can change yourself in Settings; for the rest, write to hello@deepday.app. If you are not happy with our answer, you can complain to the Swedish Authority for Privacy Protection (IMY), imy.se.
Changes
When this policy changes in meaning, we update the date and version above and email account holders before the change takes effect. Each account records which version it agreed to.