Privacy policy
Last updated: 13 September 2026 · Effective: 13 September 2026 · Applies to the dizay web app, the dizay Android and iOS apps, and this website (dizay.app).
dizay is built to be private by default. This policy explains what data we handle, why, where it is stored, who we share it with, and the choices and rights you have wherever you live. It is written in plain language on purpose. If anything is unclear, write to privacy@dizay.app.
1. Who we are
The data controller (the company responsible for your data) is Dizay LLC, a limited liability company organised in Wyoming, United States, with its principal office at 30 N Gould St Ste R, Sheridan, WY 82801, United States ("dizay", "we", "us"). Contact for privacy matters: privacy@dizay.app.
2. Data we collect and why
| Data | Why we need it | Where it lives |
|---|---|---|
| Account data: email address, username, password hash, interface language, time zone, optional two-factor settings, and, if you use social sign-in, the identifier and email the provider gives us | To create and secure your account, verify your email, help you recover access, and show the app in your language and local time | Our server and your device |
| Workspace content: tasks, notes, checklists, drawings, labels, reminders, chats, and the append-only activity history | This is the product. It is stored so you can use it across devices and keep a complete history | Your device first (browser storage on the web, an on-device database on Android and iOS), then synced to our server |
| Information about other people that you enter in optional tools: names, phone numbers, loans, shared expenses, and people you share items with | To run the optional tools you switch on (contacts and call handoff, loans and IOUs, shared expenses, selective sharing) | Your device and our server. You are responsible for having a legitimate reason to store other people's details |
| Vault and authenticator data (optional tools): passwords, secrets and one-time-code seeds you store | To provide the password vault and authenticator features | Encrypted on your device and on our server. When these tools launch, the in-app vault notice describes the encryption and the key you control |
| Voice recordings and transcripts (only when you use voice capture) | To transcribe what you said and turn it into tasks or notes | Your device and our file storage; the audio is sent to a speech provider for transcription. You can set an audio retention period in Settings |
| AI chat inputs and outputs (only when you use the assistant) | To generate the assistant's replies and task suggestions | Our server, relayed to the AI provider for that request |
| Your own AI provider connection (optional): the API key or connection you add | To let the assistant run on your own provider account on the Free plan | Encrypted on our server; used only for your requests |
| Push notification tokens (Android and iOS, if you allow notifications) | To deliver reminders as push notifications | Our server, Apple Push Notification service, Google Firebase Cloud Messaging (via Expo push) |
| Device and sync metadata: an identifier generated by the app, app version, platform, sync cursors and timestamps | To synchronise safely between your devices and resolve conflicts | Our server |
| Subscription data (Pro): plan, status, renewal date, country, and a customer reference from the payment provider | To manage your subscription, entitlements and invoices, and to meet tax rules. We never receive or store your full card number | Our server and the payment provider (Stripe or PayPal on the website; Apple or Google if you subscribed in the app) |
| Advertising data (Free plan only, see section 5): device advertising identifier, coarse location derived from IP, consent choices | To show contextual ads that fund the Free plan, and to respect your consent | Handled by Google's advertising services on your device; never joined to your dizay account in our database |
| Support messages: your name, email and what you wrote | To answer you | Our mailbox (Google Workspace) |
| Technical logs: IP address, request timestamps, user agent, error traces | Security, abuse prevention, rate limiting and fixing bugs | Our server and Cloudflare, kept for a limited time (see retention) |
3. What we do not do
- We do not sell your personal data, and we do not share it with third parties for their own marketing.
- We do not use your tasks, notes, recordings, chats or contacts to target ads, and we never pass your content, titles, contacts or precise location to advertising services.
- We do not use your content to train AI models, and our AI providers are used under terms that prohibit training on it.
- We do not read your tasks, notes or chats, except when you ask us to for support and give explicit permission.
- We do not access your contacts, calls, SMS or messaging apps unless you explicitly enable an optional tool that needs them, and any call or message leaving the app requires your confirmation each time.
- We do not use third-party analytics or tracking SDKs in the apps or on this website.
4. AI and speech providers
When you use the AI assistant or voice capture, the relevant text or audio is sent from our server to OpenAI (assistant and speech-to-text) or Anthropic (assistant) to produce a transcript or a reply. On the Free plan, the assistant runs on a provider connection you add yourself; on Pro, it runs on our provider accounts within your included allowance. We send only what is needed for the request, and nothing is sent to these providers when you are not using AI features. Requests made while offline are queued on your device and processed only after you reconnect. Assistant suggestions are applied to your workspace only when you confirm them, and every change is recorded in your history.
5. Advertising on the Free plan
The Free plan may show a small number of contextual ads (a banner on main screens) served by Google AdMob in the Android and iOS apps and Google Ad Manager in the web app. Paid plans never request ads. Where the law requires it, you are asked for consent before any personalised ad is shown (Google's consent framework in the EEA, UK and Switzerland; Apple's App Tracking Transparency prompt on iOS). If you refuse or the prompt is not shown, only non-personalised ads are served. Ads are never placed in the vault, authenticator, key-entry, account, sharing or recovery screens, in notifications or in exports. Google's use of data in advertising is described at policies.google.com/technologies/partner-sites. You can change your consent at any time in Settings → Privacy, and you can remove ads entirely with a Pro subscription.
6. Legal bases (EEA, UK and Switzerland)
- Contract (GDPR Art. 6(1)(b)): account, workspace content, sync, billing and support are needed to provide the service you asked for.
- Consent (Art. 6(1)(a)): push notifications, microphone access for voice capture, optional tools you switch on, personalised advertising, and your own AI provider connection. You can withdraw consent at any time in your device or app settings, without affecting earlier processing.
- Legitimate interests (Art. 6(1)(f)): security logs, abuse prevention, service improvement based on aggregate usage, and non-personalised ads on the Free plan. You may object (see your rights).
- Legal obligation (Art. 6(1)(c)): keeping billing and tax records, answering lawful requests.
7. Where data is stored and our service providers
Server data (database, file storage and backups) is hosted in the European Union, in Hetzner data centres in Germany, behind Cloudflare. Connections use TLS. Backups are encrypted and stored outside the main server so your data is recoverable. We use the following providers, each under a data-processing agreement and only for the purpose stated:
| Provider | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Servers, database, file storage, backups | Germany (EU) |
| Cloudflare, Inc. | DNS, CDN, DDoS protection, object storage replica | Global network; EU data localisation where available |
| Vercel, Inc. | Hosting of this website (dizay.app) | United States and global CDN |
| OpenAI, L.L.C. | AI assistant and speech-to-text, for requests you make | United States |
| Anthropic, PBC | AI assistant, for requests you make | United States |
| Apple Inc. / Google LLC (Firebase Cloud Messaging) / Expo | Push notification delivery | United States |
| Stripe, Inc. and PayPal, Inc. | Website payments, invoices, tax calculation | United States and EU entities |
| Apple Inc. / Google LLC | In-app purchases in the iOS and Android apps | United States and local entities |
| Google LLC (AdMob, Ad Manager) | Ads on the Free plan only | United States and global |
| Google LLC (Google Workspace) | Business email and support mailbox | United States and EU |
| Transactional email provider | Verification, recovery and billing emails from noreply@dizay.app | Named in the app's notices screen once selected |
Local data on your device is protected by your device's own security (screen lock, encryption). If you use a shared computer, sign out of the web app when you are done.
8. International transfers
Dizay LLC is a United States company and some providers above process data in the United States or other countries. Where we transfer personal data out of the EEA, the UK or Switzerland, we rely on the European Commission's standard contractual clauses (and the UK addendum) with our providers, or on the provider's certification under the EU-US Data Privacy Framework where applicable, plus the security measures in section 10. You can ask us for a copy of the safeguards.
9. Retention
- Workspace content and history: kept for as long as your account exists. History is append-only by design, so a moved or completed task keeps its trail until you delete the item's data or the account.
- Voice recordings: kept until the retention period you set in Settings expires, or until you delete the note, task or chat they belong to, or your account.
- AI chat inputs: kept as part of your chats until you delete them; our providers' retention of API data is governed by their terms (OpenAI and Anthropic API data are not used for training).
- Technical logs: up to 90 days.
- Support emails: up to 12 months.
- Billing records: as long as tax and accounting law requires, typically 7 years, then deleted.
- After account deletion: production data is removed within 30 days and encrypted backups expire within 90 days.
10. Security
Passwords are stored only as salted hashes. Your own AI keys and vault data are encrypted at rest. Access to production systems is limited to the people who operate the service, uses individual accounts with two-factor authentication, and is logged. We test backups and keep them outside the main server. If a breach affects your personal data, we notify you and the competent authority as the law requires. Security researchers can contact us through security.txt.
11. Your rights
Wherever you live, you can access, export, correct and delete your data. Depending on your country you may also have the right to restrict or object to processing, to data portability, to withdraw consent, not to be subject to solely automated decisions with legal effects (we make none), and to complain to a supervisory authority (in the EEA, your national data protection authority; in the UK, the ICO).
- Export: use the export features in the app, or ask us for a full copy of your data in a machine-readable format.
- Correct: edit your account and content in the app, or ask us.
- Delete: Settings → Account → Delete account in the app, or follow the account deletion page.
- Consent and objections: change notification, microphone, ads and optional-tool settings in the app or your device; email us to object to processing based on legitimate interests.
- Anything else: email privacy@dizay.app. We answer within 30 days (45 days for some US state requests) and may ask you to confirm the request from within the app to protect your account. Exercising your rights is free; we do not treat you differently for doing so.
12. California and other US states
If you live in California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon or another US state with a privacy law, you have the rights to know, access, correct, delete and port your personal information, and to opt out of "sale" or "sharing" for cross-context behavioural advertising and of profiling. We do not sell personal information. On the Free plan, personalised ads may be considered "sharing" under California law; you can opt out in Settings → Privacy → Ads (choose non-personalised ads) or by emailing privacy@dizay.app, and we honour Global Privacy Control signals in the web app. The categories of personal information we collect are listed in section 2; the sources are you, your devices and our providers; the purposes are those stated there. We do not knowingly sell or share the personal information of people under 16. You may authorise an agent to make a request for you. We will not discriminate against you for exercising your rights.
13. Children
dizay is not directed at children under 13 (or the age of digital consent in your country, if higher, such as 16 in some EU countries), and we do not knowingly collect data from them. If you believe a child has created an account, contact us and we will delete it.
14. App permissions
- Notifications: for reminders. Optional.
- Microphone: for voice capture. Optional, only while recording.
- Photos, camera and files: only when you choose to attach, import or export something.
- Contacts, phone, SMS: only if you enable the optional contacts tool, and only for the actions you trigger. Contacts are not uploaded in bulk.
- Location: only if you enable prayer times, to compute times for your city; you can enter a city by hand instead.
- Tracking (iOS): only asked on the Free plan for personalised ads; declining keeps everything else working.
15. This website
dizay.app has no analytics scripts, advertising trackers, cookies, account forms or payment forms. It uses no third-party fonts or embeds. Our hosting provider (Vercel) processes standard request data such as IP addresses to serve the pages and protect against abuse, and keeps its logs for a limited time. Email links open your own mail app.
16. Changes
If we change this policy in a meaningful way, we show a notice in the app, email account holders where appropriate, and update the dates at the top. Older versions are available on request.
17. Contact
Dizay LLC · 30 N Gould St Ste R, Sheridan, WY 82801, United States · privacy@dizay.app · +1 737-260-3933
This policy is available in French and Arabic. In case of a difference in meaning, the English version prevails.