This privacy policy explains how the Dayivo mobile application and the dayivo.com / api.dayivo.com services collect, use, store and protect personal data. It is compliant with the Turkish Personal Data Protection Law (KVKK), Google Play Store policies and the European General Data Protection Regulation (GDPR).
1. Data Controller
- Application name: Dayivo (package:
com.vante.dayivo) - Email: privacy@dayivo.com
- Web: https://dayivo.com
2. Data We Collect
2.1 Account Data
- Email address (required for sign-in)
- Name or nickname (user input, required)
- Your password — it is never stored as plain text; it is transformed using a secure one-way method
- Device information (model, operating system — for secure session management)
2.2 In-App Data (Stays on Your Device)
- Your expense records, categories and budgets
- Your habit definitions and daily check-ins
- Your water tracking records
- Your notes / journal entries
- Your income records
This data is kept only on your device. Unless you enable the cloud backup feature, it is NOT SENT to our server.
2.3 Cloud Backup (Optional, Premium)
When cloud backup is enabled, your in-app data is stored on our server in a secure and unreadable form. You can disable or delete the cloud backup at any time.
2.4 Automatically Collected Data
- IP address (security and abuse protection)
- Device information (for secure sessions)
- Session information (to maintain your sign-in state)
- Subscription status (if Premium)
3. How We Use the Data
- Providing the service: Account management, synchronization, your subscription
- Security: Detecting unauthorized access, account recovery
- Communication: Email verification, password reset, security alerts
- Legal obligation: Court order, tax audit
We never:
- Share your data with third parties for marketing purposes
- Offer your data for sale
- Use your data for advertising profiles
4. Data Retention Periods
- Active account: As long as the account is open
- After account deletion: Permanently deleted within 30 days (including backups)
- Audit logs: 12 months (legal obligation)
- Billing records: 10 years (Turkish tax legislation)
5. Your Rights (KVKK Article 11 & GDPR)
You can request the following:
- To learn whether your personal data is being processed
- To request a copy of your data (data portability)
- To request correction of inaccurate data
- To request deletion of your data (the "right to be forgotten")
- To object to processing
You can send your requests to privacy@dayivo.com. We respond free of charge within 30 days.
6. Security Measures
- The connection between you and our server is always protected
- Your password is never stored in a readable form
- Your sensitive information is kept in a locked vault — it cannot be opened without the correct key
- Your sessions are renewed at regular intervals (for account security)
- We have protection against automated attack attempts
- Unusual sign-in attempts are detected and reported to you
- Backups are also stored in a protected form
Note: We deliberately do not share the technical details of our security — such information could guide malicious actors. Details for security researchers can be shared via security@dayivo.com.
7. Children
Dayivo is not intended for children aged 13 and under. We do not knowingly collect personal data from children under the age of 13. If you believe your child has provided us with data, please contact us.
8. Policy Changes
We may update this policy from time to time. For significant changes, we will notify you by email. The date of the last update is indicated above.
9. Contact
You can send your privacy-related questions or concerns to privacy@dayivo.com.