← Back

Privacy Policy

Last updated: 2026-09-12

jeden.day is a personal habit tracker. This policy explains what personal data the service processes, why, and what rights you have under the EU General Data Protection Regulation (GDPR).

1. Controller

Michael von Bothmer, Süsterfeldstr. 83A, 52072 Aachen, Germany — email: mail@jeden.day.

2. What data is processed

Account data. Your email address (used to identify your account and to send sign-in and confirmation links), the date your account was created, the record of your consent (when you gave it and which version of these texts you agreed to), and — if you register passkeys — passkey metadata such as a label and usage timestamps. Passkeys never give the service access to your device or biometrics; only a public key is stored.

Provider sign-in. If you choose Google, GitHub, Apple, or Microsoft, the chosen provider learns that you are signing in to jeden.day and processes the sign-in under its own privacy policy. We receive an account identifier and, when available, an email address and its verification status. We store the provider, identifier, supplied email, connection date, and last sign-in date. We do not store provider access or refresh tokens, and sign-in gives the provider no access to your habits. A matching email never automatically connects an existing account: you must confirm that account with email or a passkey first.

Habit data. The habits you create (names, schedules, targets) and the daily entries you record. This content is yours: it is stored to show you your own tracker, is never analysed or profiled, and is passed to no one — with the single exception of an application you connect to your account yourself, described next.

Connected apps. You can connect an application — an AI assistant, for example — to your account. Approving a connection grants that application full read and write access to that account's habit data, and nothing else: it cannot see your email address, your passkeys, or any other account. Nothing is ever connected without your approval; the account menu's "Connections" entry lists every connection with when it was approved and last used and revokes one immediately, an unused connection lapses on its own within 30 days, and your data export lists them too. What a connected application does with the data it reads is governed by that provider's own terms and privacy policy, not by this one.

Feedback board. If you post on the feedback board, the title and text of your post, your comments, and which posts you have upvoted are stored on your account. A post is visible only to you and to the operator until the operator publishes it; once published, its text and the display name you chose are visible to every signed-in user of the service. Your email address is never shown there — only the operator can see which account wrote a post. The optional display name is yours to choose or leave empty, in which case posts are signed "Anonymous". This is the only content you can make visible to other users, and posting is entirely voluntary.

Daily reminders. If you turn reminders on, the service stores the time of day you chose and your time zone, and one record per device you enabled them on. That record contains the push endpoint your browser was issued — a web address at the push service your browser maker operates (Apple, Google or Mozilla) — together with the encryption keys your browser generated for it, which browser family it is (“Safari on a computer”, and nothing more specific — the browser’s own identification string is not stored), and the dates the device was added and last reminded. Turning reminders off on a device, or removing it from the list, deletes that record; removing the last one turns reminders off entirely. Your data export lists the devices and dates but never the endpoint or the keys, because anyone holding those could send that browser a notification.

Technical data. Server logs and short-lived, in-memory rate-limit counters contain IP addresses to keep the service running and to prevent abuse. Logs are kept for 14 days.

Usage statistics. The service keeps aggregate, cookie-free daily counters: how many pages were viewed, an approximate number of distinct visitors per day, coarse browser families, and which sites visitors arrived from. To count a visitor only once per day, a keyed hash of the network address is held in the server's memory for that day and never written to disk; only the daily totals are stored. No IP addresses, no browser fingerprints, and no per-visitor records are ever stored, and no third-party analytics service is involved.

Guest mode. Without an account, your data is stored only in your own browser and never reaches the server. It is transmitted once — and only — if you sign in and explicitly import it.

3. Purposes and legal bases

Account and habit data are processed to provide the service you signed up for (Art. 6(1)(b) GDPR). Technical logs, rate limiting, and the aggregate usage statistics described above rest on the legitimate interest of operating, securing, and improving the service (Art. 6(1)(f) GDPR). Where your habit content amounts to special-category data, processing rests on your explicit consent (Art. 9(2)(a) GDPR), given by ticking the box on the sign-in form. That consent is stored with a timestamp and the version of these texts it applied to, and it is part of your data export. You can withdraw it at any time by deleting the data or your account. The service is not directed at children: you must be at least 16 years old to use it, which is also the age from which a child's own consent is valid in Germany (Art. 8 GDPR).

4. Sensitive content

Habit names and entries are free text and may reveal sensitive information — for example about your health ("take medication") or beliefs. Whether to record such content is entirely your choice. It is processed exclusively to render your own tracker and is never evaluated for any other purpose.

Being the person who runs the server, the controller named above can technically reach the content of any account. That access is used to operate, support and moderate the service and for nothing else, and nobody else has it — but it is the limit of what any promise here can offer: if a particular record is one you would not want another person to be able to read, do not write it here.

5. Recipients

Sign-in and confirmation emails are delivered via Scaleway SAS, 8 rue de la Ville l'Évêque, 75008 Paris, France (Transactional Email, EU infrastructure). The service is hosted on a server rented from netcup GmbH, Daimlerstraße 25, 76185 Karlsruhe, Germany, and database backups are stored with Scaleway (Object Storage, Paris). Mail sent to the contact address is forwarded by INWX GmbH & Co. KG, Prinzessinnenstraße 30, 10969 Berlin, to the operator's mailbox. These providers act as processors under Art. 28 GDPR data processing agreements. An application you connect to your account is not a recipient the operator chose — see "Connected apps" above. If you turn on daily reminders, each notification is delivered through the push service operated by the maker of the browser you enabled them on — Apple (APNs), Google (FCM) or Mozilla — which may be outside the EU under its own privacy policy. The text of a notification is encrypted for your browser before it is sent, so the push service relays it without being able to read it; it does learn that a message was sent to your device and when. No notification is sent to any device until you enable it there. Beyond this, no data is sold or shared with anyone, apart from the provider sign-in you choose as described above; there are no third-party analytics and no advertising. The chosen sign-in provider may process information outside the EU under its own privacy policy: Google, GitHub, Apple, or Microsoft.

6. Cookies and browser storage

The service sets a strictly necessary session cookie (to keep you signed in), and short-lived browser-binding cookies when you start provider sign-in. Session storage remembers an unfinished sign-in in that tab so you can return from an email link. The service also uses the browser's own storage for equally necessary purposes: local storage for preferences such as the dark-mode setting, and IndexedDB for the guest tracker itself. Nothing is used for tracking, so no consent banner is required (§ 25(2) TDDDG).

7. Retention

Your data is kept until you delete it or your account; deleting the account removes everything it owns immediately — feedback posts, comments and votes included, which disappear from the board with it. You can also delete an individual post or comment at any time. Deleted data leaves server backups within 14 days. Sign-in links expire after 15 minutes; sessions expire after 90 days; server logs are deleted after 14 days. A reminder device record is kept until you remove it, and is deleted automatically once the push service reports that the browser no longer exists. The aggregate daily counters described above contain no personal data and are kept indefinitely.

Provider sign-in attempts expire after 15 minutes and are removed during subsequent authentication activity. Linked provider identifiers are included in your export and removed when you delete your account. Deleting your jeden.day account does not revoke the authorization recorded by the provider; you can remove it in that provider's account settings. Connecting and disconnecting providers from the account menu is not currently available.

8. Your rights

You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), and objection (Art. 21). The app itself covers the common cases: "Export data" in the account menu downloads everything in a machine-readable format, and "Delete account" erases it. For anything else, email mail@jeden.day. You also have the right to lodge a complaint with a data-protection supervisory authority, for example the one of North Rhine-Westphalia (LDI NRW).

9. Changes

If this policy changes materially, registered users will be notified by email before the change takes effect.