fxa.digital

── DAYCHIEF PRIVACY

Privacy Policy

LAST UPDATED · AUGUST 8, 2026

DayChief is an iPhone app from FXA Digital Solutions LLC for voice, text, planning, drafting, and user-approved connected actions. This policy explains what DayChief collects, how it is used, and how users control it.

Information DayChief Collects

How Information Is Used

DayChief uses information to authenticate users, provide voice and text assistant features, prepare drafts and plans, show approval queues, execute user-approved actions, enforce entitlement and usage limits, maintain security, and respond to support requests.

Optional Connectors

Google and Todoist connectors are optional. DayChief requests the scopes needed for the workflows a user chooses to enable. Connector data is used to answer user requests, prepare drafts, create approval records, and execute actions only after the required user confirmation.

Google Workspace Data

When a user connects Google, DayChief stores the connected account identifier and email address, the permissions granted, an encrypted OAuth refresh token, and selected connector settings. Depending on the permissions the user chooses, DayChief may also access:

Relevant Google content may be transmitted through FXA Digital's Google Cloud infrastructure and to OpenAI's API to interpret the request or produce the requested answer, summary, draft, or action preview. DayChief does not sell Google data, use it for advertising or credit decisions, or permit it to be used to train generalized AI or machine-learning models. DayChief does not create or use aggregated or anonymized datasets derived from Google Workspace content for advertising, analytics, product development, or model training. Non-content operational measurements, such as request counts, timing, and error rates, may be aggregated to operate and secure the service.

Voice, BYOA Voice, and Sidecar

Hosted DayChief voice and text features may process prompts, audio, transcripts, and assistant responses through FXA Digital infrastructure and third-party AI providers. BYOA Voice sends iOS audio through DayChief infrastructure and LiveKit while inference runs through the user's configured Sidecar. Sidecar is operated by the user; Sidecar data is controlled by that deployment unless the user shares it with FXA Digital for support.

External Processing

DayChief may use Firebase or Google Cloud infrastructure for authentication, hosting, databases, logging, speech processing, and backend operation. Hosted assistant features may use OpenAI services. BYOA Voice may use LiveKit and Google speech services for audio transport, speech-to-text, and text-to-speech. RevenueCat processes purchase and subscription-entitlement information; DayChief does not send Google Workspace content to RevenueCat. Connected-service requests are sent to the relevant provider, such as Google or Todoist, only when the user configures that connector and requests or approves the action.

Retention and Deletion

Pre-release status: DayChief is not yet generally available. The comprehensive account-deletion workflow described below is an approved production control that is still being implemented and verified. Current test builds should not be treated as proof that every related top-level application record or external processor record has been removed.

The approved production workflow will first record a durable deletion request, then promptly delete identifying account and connector data; stored OAuth credentials; conversations, prompts, transcripts, assistant responses, and tool results; Google Workspace content or derived excerpts; voice-session records; local tasks; and pending approvals. After local content and credentials are removed and minimum encrypted external-cleanup state is durable, it will delete the Firebase authentication user. Provider-side deletion or revocation may complete asynchronously without restoring ordinary account access.

DayChief may retain only minimum non-Workspace billing and service-usage information after it has been irreversibly de-identified and combined into broad monthly company-wide totals. Those totals may be retained for no longer than three years from the underlying transaction or usage period. They exclude Google Workspace content and derived data, prompts, transcripts, free text, user or provider identifiers, precise timestamps, and small or distinctive cohorts.

To prevent a delayed subscription event from recreating a deleted account, DayChief's approved workflow will retain a restricted, keyed cryptographic suppression marker. The marker is pseudonymous security data, not an analytics profile. It contains no raw user ID, email, receipt, product, transaction, prompt, or Google Workspace content. It expires three years after the most recent verified matching RevenueCat subscription lifecycle event; a later verified matching event restarts that period solely so it can continue to suppress account recreation.

Primary production records will be targeted for prompt deletion. Firestore point-in-time recovery and scheduled backups may retain protected copies for up to seven days before they age out. They are not available through the ordinary app, and any restore procedure must reapply deleted-account suppression before restored data is exposed. Deleting a DayChief account does not remove an email draft, sent message, calendar event, or other data already written to the user's Google account.

Deleting a DayChief account also does not cancel an Apple subscription. Users must cancel separately through Apple's subscription-management controls if they do not want billing to continue. See Data Management and Account Deletion for the current controls and release status.

Security and Human Access

DayChief encrypts data in transit using HTTPS/TLS and uses Google Cloud encryption at rest. In production, OAuth refresh tokens are additionally encrypted with Google Cloud KMS, and service access is restricted through authenticated user boundaries and least-privilege service identities. Access tokens are used only to call the APIs authorized by the user. Application logging is designed to redact credentials and connected-service content.

FXA Digital does not routinely inspect Google Workspace content. Access by authorized personnel is limited to what is necessary when a user explicitly requests support, to investigate security or abuse, to maintain service integrity, or to comply with law. DayChief does not allow service-provider personnel to use Google data for their own purposes.

Google API Limited Use

DayChief's use and transfer to any other app of information received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Additional details are available in the Google API Disclosure.

Tracking and Advertising

DayChief does not use advertising identifiers, data brokers, third-party advertising, or cross-app tracking. FXA Digital may collect basic website analytics on fxa.digital to understand public site usage; that website analytics is separate from DayChief app tracking.

User Choices

Contact

For privacy questions, access requests, or deletion help, contact FXA Digital Solutions LLC at [email protected]. Do not email passwords, OAuth tokens, message contents, file contents, or other sensitive account data.