Everyd.AIDE
EVERYDAY LIFE, TOGETHER / Privacy

Privacy notice

Website, contact and app: the data Everyd.AI processes and the optional functions still being prepared.

1. Controller and contact

The controller for the processing described here is:

Steffen Deißler
Fritz-Reuter-Str. 65, 16540 Hohen Neuendorf, Germany

Everyd.AI is operated by an individual. Privacy, support and direct contact: hallo.everydai@posteo.de

Version and effective date: 27 September 2026.

2. Scope and current operation

This notice describes the public information website, contact inquiries and the app in closed founder dogfood. Everyd.AI helps adults organize household events, tasks, lists and responsibilities together. Public registration and a generally accessible alpha are not yet available. Children do not receive accounts.

Native Everyd.AI events, tasks and lists do not require a Google connection. As of this version, the Google Calendar connection, AI processing and push delivery are not enabled for ongoing app operation. Limited development trials are distinct from that operation.

Planned scope of the first external alpha: core functions plus Google Calendar, AI and push. AI is intended to support text input and deliberately started short voice input (push-to-talk), and push is intended to work on Android and iPhone. This development scope has been decided but is not yet enabled. Connecting Google, using AI and granting push permission remain separate, voluntary choices; merely opening an account does not enable them together. Before external use, actual provider terms, data flows and operating procedures must match the approved version.

3. Data we process

Particularly sensitive content, such as health, financial or custody/contact information, is outside the current trial. Permitting brief everyday information does not authorize unrestricted information about others, their calendars or transfer of their data to AI services. Merely mentioning someone or granting technical access does not establish permission to process their data.

4. Purposes and legal bases

The following legal bases concern today’s limited founder dogfood. The planned alpha scope is a development decision; the relevant notices and legal bases will be provided before additional data flows actually begin.

You are not subject to solely automated decisions with legal or similarly significant effects.

5. Recipients and service providers

Active authorized adults in the same household can access shared content. In the intended Google flow, this also includes expressly selected calendar content. Household content is not displayed on this public website. Necessary administrative access serves operation, specific support cases, security or legal duties, rather than routine analysis of private content.

App backend and sign-in

Supabase Pte. Ltd., Singapore, provides the database, authentication and backend as a processor. The project currently used is located in Frankfurt (eu-central-1). Email codes currently use Supabase’s built-in test email service; this does not establish a general delivery service for external alpha accounts.

The Supabase Data Processing Addendum and subprocessor list describe responsibilities, additional recipients and transfer rules. The German database region does not exclude possible processing in third countries, for example for support or operational metadata. The agreement provides safeguards including standard contractual clauses for relevant transfers outside the EEA; information and a copy of applicable safeguards can be requested from the privacy contact.

Email contact

The contact mailbox is hosted by Posteo e.K., Germany. Posteo describes its mail service as an independently controlled telecommunications service and operates its own servers in Germany according to its privacy notice. The mailbox is monitored regularly. Please do not send passwords, access tokens or unnecessary sensitive household information.

Public website

This information website is hosted through OpenAI’s ChatGPT Sites. For providers in the European Economic Area, the Sites terms identify OpenAI Ireland Ltd as the contracting party. OpenAI processes hosting data on behalf of the website operator; the Sites Data Processing Addendum governs this processing and transfers outside the EEA based on standard contractual clauses or adequacy decisions. The subprocessor list describes additional recipients and processing locations.

The website is delivered through Cloudflare. Requests involve processing information including the IP address, time, requested URL and browser/connection details, for delivery and protection of the service. Exclusively German or European processing is not promised. These hosting details apply to the information website, not automatically to the Everyd.AI app or its calendar data.

Prepared services and operational monitoring

The OpenAI API has been used for limited AI trials; ongoing app access to it is currently disabled. Google Cloud services are used for technical health monitoring and prepared push components. Health checks and operator notifications do not analyze household content. Regional components must be distinguished from global administration/security metadata; exclusively EU-based processing across all services is not promised. Before optional functions are enabled, their specific recipients and conditions will be communicated in the relevant usage context.

6. Google Calendar in Everyd.AI

The connection is currently not activated and is not publicly available. This section describes the prepared limited founder-dogfood flow. It is voluntary, separate from Everyd.AI sign-in and unnecessary for native Everyd.AI content.

Only the following Google permissions are intended:

Google technically grants access to the calendar list and readable events of the connected account. No calendar is initially selected in Everyd.AI; events are read only from individually selected and confirmed calendars. Before each selection, users are informed that sharing with active adults in the household may extend beyond the original Google sharing.

Displayed data may include titles, optional locations, times, all-day date ranges, necessary recurrence/deletion information, calendar name and update status. Technical identifiers support matching and updates. Descriptions/notes, attendee lists, organizer or email identities, conference details, attachments, Google reminders, ACLs and arbitrary URLs are not imported.

Google events remain an external source and are edited in Google Calendar. Everyd.AI does not create, modify or delete Google events or automatically convert them into native events. The normal intended window covers 30 days in the past and 365 days in the future.

Google Calendar data is not sent to AI services or used for model training, advertising, advertising profiles, analytics or sale. Google processes the connected account as an external provider under the terms and privacy notice applicable to that account.

Tokens, disconnection and revocation

The prepared server flow stores OAuth tokens encrypted on the server. Tokens do not belong in browser storage, public files, exports or content logs. Before activation, the deployed flow must meet these requirements.

Deselecting or disconnecting blocks display first. The target for deleting imported details from the active system is 24 hours; disconnecting also removes or invalidates the stored access authorization. This is not a promise of immediate deletion of every backup copy. Google originals and independently created Everyd.AI content remain.

Authorization can also be revoked under Connections in your Google Account. This prevents further authorized access but does not immediately delete previously imported copies. Please also disconnect in Everyd.AI or request deletion from the privacy contact.

Limited Use

Everyd.AI’s use and transfer of information obtained from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements, and the Google Workspace User Data and Developer Policy. This commitment is not confirmation of Google verification or approval.

Selection and limits of the first Google dogfood

7. Prepared AI and push functions

AI processing and push delivery belong to the planned alpha scope but are currently switched off. The following flows describe the intended handling of data, not an already active alpha.

AI: deliberate input and reviewable suggestions

The intended flow is: an adult starts a text input or a visible short voice recording. The app sends the chosen input and its permitted minimized context to the Everyd.AI backend at Supabase. The server-side AI flow calls the OpenAI API; speech is transcribed first, after which the transcript may be processed like text input. Continuous or background microphone recording is not intended.

Results return as suggestions that can be reviewed and edited. Only deliberate confirmation may turn them into native household content; the model has no autonomous write authority. Raw text, audio, transcripts and model responses do not belong in general diagnostic logs. Google Calendar data is excluded from this AI flow. Each adult decides about their own AI use; microphone permission does not replace that decision.

The currently checked OpenAI configuration does not allow voluntary data sharing for model training. The prepared application flow disables Responses storage with store=false. This does not mean that no data is retained: depending on the endpoint and model, abuse-monitoring logs may generally persist for up to 30 days, longer in legally or security-required exceptions, and limited prompt caches may exist. Exclusively EU-based processing or Zero Data Retention is not currently promised. See OpenAI’s data controls documentation for details.

Push: a notification to the authorized device

For Android, the intended flow is: following separate authorization, a device/installation token is associated with the current adult and session. The backend and prepared Google Cloud delivery components process the identifiers, recipient and timing information needed for delivery. Google Firebase Cloud Messaging receives the delivery token and a reduced message with technical references, without titles, notes or other household prose. After opening, the app loads content only under still-valid household authorization.

A token is a personal technical delivery identifier even when the message contains no event text. Sign-out, loss of permission or a device change must end the associated delivery authorization; token retention and cleanup form part of the operational acceptance before alpha. Push on iPhone is also planned for the first external alpha. This requires delivery through Apple Push Notification service (APNs); a completed or active iPhone integration has not yet been established. The specific backend/APNs flow, including any further intermediaries, token processing and provider terms, must be implemented, documented and tested before activation.

8. Retention, deletion and backups

Account and household data is needed for the ongoing service relationship and the respective organizational purposes. A deletion request must distinguish account data, shared content and other household members’ rights. One person leaving does not automatically delete independently continuing shared content. Necessary legal records may be retained separately with restricted access for longer.

Support messages are retained to handle the request and necessary follow-up; subsequent retention depends on remaining evidentiary or legal obligations. Technical logs serve troubleshooting and security and must not be retained longer than needed for those purposes. No single fixed deletion period is promised for all provider logs.

The local app provides bounded storage: cache entries generally for up to seven days and editable drafts for up to 30 days. Sign-out or loss of authorization initiates cleanup. This cannot remotely erase screenshots or other copies independently made by household members.

The prepared Google flow has the 24-hour target for deletion of imported details, plus separately bounded repair metadata for up to 30 days and content-free replay-prevention markers for up to 90 days. The normal reading window of 30 days past and 365 days future is not a retention period for all technical data.

Backup and recovery

The current Supabase Pro project has daily database backups. According to Supabase’s documentation, Pro provides access to backups from the last seven days. This access window is not a confirmed promise that every physical copy is erased after exactly seven days. Continuous point-in-time recovery (PITR) is not enabled. Storage files are not automatically part of database backups.

Backups may temporarily contain data already deleted from the active system. They serve recovery rather than ordinary display. Before access is restored after recovery, deletions, revocations and household permissions must be reapplied. An isolated database restore has been tested; this does not establish full recovery of all app functions.

Posteo describes daily email backups retained for seven days. This concerns residual copies after deletion; messages still present in the contact mailbox are not automatically deleted by that backup cycle.

9. Your rights

Subject to the GDPR, you have rights of access and a copy, rectification, erasure, restriction and data portability. You may object to processing based on legitimate interests on grounds relating to your particular situation. You may withdraw consent at any time for the future; previous lawful processing remains unaffected.

In today’s closed founder dogfood, rights requests are handled personally by Steffen Deißler. No already-tested automated export or account-deletion service is promised. We establish which data is concerned, consider other household members’ rights and provide information through an agreed secure channel. You may also make a request without an account.

Requests for access, rectification, erasure, restriction, data portability or objection can be sent to hallo.everydai@posteo.de. Please state the email address of your Everyd.AI account, if you have one, and describe your request. Do not send passwords or access tokens. We review the request and ask for additional information only if there are reasonable doubts about your identity. We provide information and data copies through an appropriate secure channel. We aim to respond within one week. We generally inform you of the action taken no later than one month after receipt. If a legally permitted extension is needed, we inform you within that month and explain the reasons.

Requested rectification, restriction or erasure is handled specifically. We distinguish personal account data, personal information in shared content and other people’s continuing rights. We report completed actions and any justified limits or technical partial failures; deletion is described as complete only after checking it. Acknowledging a request is not confirmation of deletion.

You may complain to a data protection supervisory authority, particularly where you habitually reside, work or where an alleged infringement occurred. The authority for the controller’s location is the Brandenburg Commissioner for Data Protection and Access to Information.

10. Website and cookies

The authored pages use no tracking, marketing or analytics scripts, externally loaded fonts, embedded third-party content or forms. Switching languages does not store a language preference. External links are accessed only when opened.

The hosting platform sets Cloudflare’s __cf_bm security cookie to protect against automated abuse. It was observed on the publicly delivered website. According to Cloudflare’s documentation, it expires after 30 minutes of inactivity; associated processing may also take place in the United States. The website is therefore not cookie-free. Disabling it by Everyd.AI through the available Sites settings has not been confirmed.