Privacy Policy
Last updated: June 2026
1. Introduction
Daymark ("Daymark", "we", "us", or "our") is a health and wellbeing tracking application designed to help people living with Multiple Sclerosis (MS) and other chronic conditions understand their energy patterns and manage daily wellbeing.
This Privacy Policy explains how we collect, use, store, share, and protect your personal information when you use:
The Daymark mobile app (iOS and Android)
The Daymark web app at daymark.base44.app
Related services such as email reminders, push notifications, and subscription billing
By creating an account or using Daymark, you acknowledge that you have read and understood this Privacy Policy.
If you have questions about this policy or your data, contact us at info@daymarkapp.com.
2. Who Is Responsible for Your Data
Daymark is the data controller for personal information processed through the Daymark apps and related services, except where third-party processors act on our behalf (see Section 8).
3. Information We Collect
We collect information you provide directly, information generated through your use of the app, and limited technical information needed to operate the service.
3.1 Account and identity information
Name and email address
Authentication credentials (managed securely by Firebase Authentication; we do not store plain-text passwords)
Sign-in method (email/password, Google Sign-In, or Apple Sign-In)
Optional phone number (collected during onboarding to help prevent duplicate trial accounts)
3.2 Health and wellbeing data
Daymark is designed to track health-related information. Depending on how you use the app, this may include:
Daily check-ins: sleep duration and quality, energy levels (morning/afternoon/evening), mood, fatigue, stress, physical and cognitive symptoms, activity levels, and environmental factors (e.g. heat exposure)
Energy risk assessments: computed green/amber/red risk levels and contributing factors
Medication information: medication names, doses, schedules, and adherence logs
Nutrition logs: meal descriptions, ingredients, nutritional attributes, barcode scan results, and meal photos
Journal entries: free-text content you write in the app
Relapse records: dates, symptoms, severity, and treatment notes
Profile and condition data: condition type (e.g. MS), diagnosis details, baseline fatigue, sleep goals, known triggers, food sensitivities, and treatment notes
This information may constitute special category data (health data) under UK GDPR and similar laws.
3.3 App preferences and settings
Reminder preferences (check-in, medication, meal times)
Timezone
Notification settings
Onboarding and profile configuration choices
3.4 Device and technical information
Push notification token (FCM token on mobile)
Device type and operating system (inferred from platform services)
App version and basic usage data needed for troubleshooting
Network connectivity status (to support offline-aware features)
3.5 Payment and subscription information
We do not store full payment card details. Subscription and billing are handled by:
Apple App Store and Google Play (mobile app subscriptions via RevenueCat)
Stripe (web app subscriptions)
We may receive subscription status, plan type, trial dates, and transaction identifiers from these providers.
3.6 Information from third-party lookups
When you scan a product barcode, we query the Open Food Facts public database to retrieve product name and ingredient information. Only the barcode and resulting product data are transmitted; no account identifiers are sent to Open Food Facts.
3.7 Communications
If you contact us, submit feedback, or request a clinical report, we process the content of those communications and associated account details.
4. How We Use Your Information
We use your information to:
Provide the service
Store and display your check-ins, medications, meals, journal, and profile
Generate insights
Compute energy risk scores, surface pattern correlations, and produce charts
AI-powered features
Analyse journal entries, generate meal suggestions, parse meal photos/text, and provide supportive reflections
Send reminders
Deliver push notifications, local reminders, and (where opted in) email reminders
Manage subscriptions
Process trials, verify Pro access, and handle billing through app stores or Stripe
Export your data
Generate CSV exports and clinician-ready PDF reports at your request
Secure the service
Authenticate users, enforce access controls, and prevent abuse
Improve Daymark
Diagnose errors, monitor performance, and develop new features
Communicate with you
Respond to support requests and notify you of important service changes
We do not use your health data for advertising, and we do not sell your personal information.
5. Legal Basis for Processing (UK & EEA Users)
Depending on the type of data and activity, we rely on one or more of the following legal bases under UK GDPR:
Health and wellbeing tracking
Explicit consent (provided when you create an account, complete onboarding, and enter health data)
Account management and authentication
Contract (necessary to provide the service you signed up for)
Subscription billing
Contract and legal obligation (tax/accounting where applicable)
Push notifications and email reminders
Consent (you can disable these in app settings)
Security and fraud prevention
Legitimate interests (protecting users and the service)
Service improvement and analytics
Legitimate interests (improving reliability and user experience, with data minimisation)
You may withdraw consent at any time where processing is consent-based. Withdrawal does not affect the lawfulness of processing before withdrawal.
6. AI Processing
Daymark uses artificial intelligence to provide supportive, non-medical features such as:
Journal sentiment analysis and reflective feedback
Post check-in insights and pacing recommendations
Meal text and photo analysis
Energy-matched meal suggestions
Pattern-based wellbeing insights
How AI processing works:
On mobile, your data is sent to Firebase Cloud Functions (our secure backend proxy). These functions call OpenAI models (e.g. gpt-4o-mini). API keys are never embedded in the app.
On web, similar AI features are processed through our backend infrastructure.
We apply data minimisation: only the data necessary for each feature is sent for processing. AI outputs are stored in your account to display insights to you. AI-generated content is supportive and educational only — it is not medical advice (see Section 14).
7. Device Permissions (Mobile App)
The Daymark mobile app may request the following permissions:
Camera
Scan meal barcodes and capture meal photos
Photo library
Select existing photos for meal logging
Notifications
Deliver check-in, medication, and meal reminders
Internet
Sync data, authenticate, and use AI features
You can revoke permissions at any time through your device settings. Some features may not work without the relevant permission.
8. Third-Party Service Providers
We use trusted third-party processors to operate Daymark. They process data only on our instructions and under appropriate agreements.
Google Firebase
Authentication, database (Firestore), file storage, cloud messaging, cloud functions
Account data, app content, FCM tokens
OpenAI
AI text and vision analysis (via our backend proxy)
Journal text, meal descriptions, meal photos, check-in context
RevenueCat
Mobile subscription management
User ID, subscription status, purchase receipts
Apple App Store / Google Play
In-app purchase processing
Payment and subscription data (handled by the store)
Stripe
Web subscription payments
Payment and billing data (web app only)
Open Food Facts
Public barcode product lookup
Barcode numbers only
Google / Apple
Social sign-in
Authentication tokens and basic profile info
CRM tools (e.g. HubSpot, Salesforce)
Account and communication management
Contact details and account status (web/backend workflows)
A current list of subprocessors is available on request at info@daymarkapp.com.
9. Data Sharing
We do not sell, rent, or trade your personal information.
We may share data:
With service providers listed in Section 8, solely to operate Daymark
With your direction, when you export or share a clinician report
For legal reasons, if required by law, court order, or to protect rights, safety, or security
In a business transfer, if Daymark is acquired or merged (you will be notified where required by law)
We do not share your health data with advertisers, data brokers, or unrelated third parties.
10. International Data Transfers
Daymark is operated from the United Kingdom. Some of our service providers (including Firebase, OpenAI, RevenueCat, and Stripe) may process data in the United States or other countries.
Where personal data is transferred outside the UK or EEA, we ensure appropriate safeguards are in place, such as:
Standard contractual clauses approved by the UK Information Commissioner's Office (ICO) or European Commission
Adequacy decisions where applicable
Processor agreements requiring equivalent protection
11. Data Retention
We retain your personal data for as long as your account is active and as needed to provide the service.
When you delete your account through Settings (mobile) or equivalent web settings:
Your Firebase Authentication account is removed
Your Firestore data (check-ins, meals, medications, journal, relapses, reminders, profile, and subscription records) is permanently deleted
Residual backups may persist for a limited period (typically up to 30 days) before being purged, except where we must retain data for legal, tax, or dispute-resolution purposes
If you cancel a subscription without deleting your account, your health data remains stored until you delete your account or request deletion.
Anonymised or aggregated data that cannot identify you may be retained for analytics and service improvement.
12. Your Rights
If you are in the UK, EEA, or another jurisdiction with similar privacy laws, you may have the following rights:
Access — request a copy of the personal data we hold about you
Rectification — correct inaccurate or incomplete data
Erasure — request deletion of your data ("right to be forgotten")
Restriction — ask us to limit how we use your data
Portability — receive your data in a structured, machine-readable format (CSV export is available in-app)
Objection — object to processing based on legitimate interests
Withdraw consent — where processing is consent-based
Complaint — lodge a complaint with the ICO (UK) or your local supervisory authority
To exercise these rights, email info@daymarkapp.com. We will respond within one month, or inform you if an extension is needed.
13. Security
We implement technical and organisational measures to protect your data, including:
Encryption in transit (HTTPS/TLS) for all network communication
Firebase Authentication for secure sign-in
Firestore security rules enforcing owner-only access to user data
Backend-only AI API keys (never exposed in client apps)
Access controls limiting employee and contractor access to production data
No method of transmission or storage is 100% secure. If you believe your account has been compromised, contact us immediately.
14. Not Medical Advice
Daymark provides personal tracking, pattern insights, and educational content only. It is not a medical device and does not provide medical advice, diagnosis, or treatment.
AI-generated insights and recommendations are supportive in nature. Always consult a qualified healthcare professional for medical decisions.
15. Children's Privacy
Daymark is not intended for users under 16 years of age. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, contact us and we will delete it promptly.
16. Cookies and Similar Technologies (Web App)
The Daymark web app may use cookies and local storage for:
Maintaining your login session
Storing app preferences
Analytics and performance monitoring
You can control cookies through your browser settings. Disabling cookies may affect web app functionality.
17. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or through an in-app notice. The "Last updated" date at the top reflects the most recent revision.
Continued use of Daymark after changes take effect constitutes acceptance of the updated policy, unless otherwise required by law.
18. Contact Us
For privacy questions, data subject requests, or concerns about this policy:
Email: info@daymarkapp.com
We aim to respond to all privacy enquiries within 30 days.