Privacy Policy
Last updated: 23 September 2026
Daytoon is a diary app. The text our users trust us with is more private than what most apps ever see. This document exists to say, as plainly as we can, where that text goes and where it does not.
What we collect
- Account details: your email address and an irreversible hash of your password. If you signed in with Google or Apple, your email address and the account id that provider gives us. If you started without signing up, only an anonymous account id.
- What you write: your diary entries, story titles, panel text, and any names and descriptions you give your characters.
- Photos you upload: only the reference photos you upload to create a character.
- Generated content: the drawn pages, PDFs and other outputs.
- Technical data: app version, device type, error reports and, if you allowed notifications, your device's push token.
Why we process it
Your diary text is processed for one job: turning it into a comic. The text is split into scenes, and those scenes are turned into images. There is no other use: we do not profile you for advertising, we do not sell data, and we do not train AI models on your diary.
Who receives it
Running the app takes a handful of service providers. We list what each one sees separately, because they do not all see the same thing:
- OpenRouter: your diary text goes here; the language model that breaks the story into scenes runs there.
- fal.ai: the drawing happens here. Scene descriptions and, if you use your own character, your reference photos are sent there.
- Cloudflare R2: generated images and uploaded photos are stored here.
- Railway: the server and database are hosted here.
- Resend: password reset email only; it sees nothing but your email address.
- RevenueCat, the App Store and Google Play: subscription purchases. We never see your payment details.
- PostHog: usage statistics. See below: your diary content is never sent there.
- Sentry: crash and error reports.
- Expo: delivers the "your comic is ready" notification to your device.
- Google and Apple: only if you use "Sign in with Google" or "Sign in with Apple". They verify the sign-in; what comes back to us is your email address and that account's id. If you sign in with a password, nothing reaches either of them.
What analytics never receives
This was the most concrete decision we made while building the app, and it is how the code works:
- Your diary text, story titles, panel text, character names and photos are sent to no analytics provider. What is sent are numbers of this kind: the style you chose, a rough length band for the text (for example "100–500 characters"), the page count, how long it took, and the type of error if one occurred.
- When a story fails, even the raw error message from the provider stays out of analytics. Only a classified error type is sent.
- The session replay package is not installed in the app. It is not switched off in a setting; it is not in the app at all.
- In error reports, screenshots, view hierarchies and personal data are all disabled.
Because this data is not shared with ad networks and is not used to track you across apps, it is analytics, not tracking.
Share links
When you share a story, an unguessable link is created. It is listed in no directory, closed to search engines, and only the person holding it can open it. You can turn it off at any time; when you do, both the page and the artwork become unreachable. We count how many people opened a link, not who.
How long we keep it
- While your account is open, what you wrote and what was drawn stays. that is what a diary is for.
- Anonymous accounts started without signing up are deleted automatically, with all their content, after a period without use.
- When you delete your account, your database record and every file in storage are permanently deleted. That cannot be undone.
Your rights
- Download your data: from inside the app, you can export every diary entry, title, panel text, page address and character as a single file.
- Delete your account: from inside the app, without going through us.
- For access, rectification, erasure and objection rights under the GDPR and Turkey's KVKK, write to hello@daytoon.co.
What stays on your device
The app lock, your daily reminder time and the draft saved while you write are kept on your device only; they are never sent to the server. The app lock belongs to that phone, not to your account.
This site
daytoon.co is a static page. It uses no cookies, runs no visitor analytics, and makes no request to any third-party server. Every file, typefaces included, comes from this domain. So nobody but you knows you opened this page, and we do not know who you are.
Children
Daytoon is not designed for users under 13, and we do not knowingly collect data from them.
Changes
If we update this policy we will change the date above, and tell you in the app when the change is significant.