Daybreak Labs ← Back to Daybreak Labs

Legal

Daybreak Labs Privacy Policy

Effective date: September 3, 2026 | Version: v1.3 | Last updated: September 3, 2026

IMPORTANT NOTICE. This Privacy Policy is one half of a pair. It is read together with the Daybreak Labs Master Terms of Use at daybreaklabs.studio/terms and with the applicable Product Schedule for the specific Daybreak Labs Product you are using. The Master Terms incorporate this Privacy Policy by reference at Master §14. Capitalized terms used and not defined here have the meanings given in the Master Terms.

This Privacy Policy explains how Daybreak Labs LLC, a New York limited liability company ("Daybreak Labs," "we," "us," or "our"), collects, uses, shares, and protects personal information when you visit our websites, purchase or use any of our Products, or communicate with us. It applies to every Daybreak Labs Product (each defined in the Master Terms) and to the Daybreak Labs storefront and marketing site at daybreaklabs.studio and its subdomains. Product-specific privacy notes that differ from or supplement this Privacy Policy appear in §S.13 of the applicable Product Schedule; in the event of any direct conflict between this Privacy Policy and a Schedule §S.13, the Schedule controls solely with respect to that Product (consistent with Master §2).


What this means in practice: plain-English summary

  1. We collect only what we need to deliver the Product you bought, and very little else. For most Products, that is your email address, the payment metadata our payment processor shares with us, and any message you send to support. When you buy from us, we will also email you about our other Daybreak Labs Products and updates, you can unsubscribe from that with one click at any time. Some Products collect more, and the additional categories are listed in the applicable Schedule §S.13.
  2. Some Products operate locally on your own device. Where a Product is a downloadable file or otherwise runs on your computer without sending data back to us, the data you enter into the Product stays on your device. The applicable Schedule §S.13 describes the data flow for each Product, including any "no telemetry" representation.
  3. We do not sell your personal information. We do not share it with advertising platforms, data brokers, or trackers for advertising purposes. We do not allow our service providers to use your information for their own purposes.
  4. We use a short, named list of service providers. The current authoritative list is published at daybreaklabs.studio/subprocessors. Each provider is bound by a written agreement that limits it to providing its service to us. Which providers are used by which Product is described in the applicable Schedule §S.13.
  5. You have rights over your information. You can ask us what we have, ask us to correct it, ask us to delete it, ask us to stop sending you marketing, and, if you live in the EU, the UK, Switzerland, California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Tennessee, Florida, or any other US state that grants the right, exercise the additional rights described in §11 below. Email info@daybreaklabs.studio to exercise any of them.

If anything in this Privacy Policy is unclear, email us. We would rather answer the question than have you guess.


1. SCOPE AND WHAT THIS POLICY COVERS

This Privacy Policy covers Daybreak Labs's collection, use, sharing, retention, and protection of personal information, meaning information that identifies, relates to, or could reasonably be linked with you (or, where required by applicable law, your household or device).

This Privacy Policy applies to:

This Privacy Policy does not apply to:

For the avoidance of doubt, Daybreak Labs is not a tax return preparer within IRC §7216 with respect to any Daybreak Labs Product, we do not prepare federal, state, or local returns for any customer; do not assist any customer in preparing a return; do not transmit any return to any taxing authority; and are not an Authorized IRS e-File Provider.


2. INFORMATION WE COLLECT

We collect personal information in three buckets: what you provide directly, what we collect automatically when you use a Product, and what we receive from other sources we work with.

2.1 Information you provide directly

What When you give it to us
Name, email address, and (for paid Products) billing address When you buy a Product, create an account, or sign up for a mailing list
Payment information collected by our payment processor (see §2.3 below, we do not see or store your full card number, CVV, or bank-routing information) When you check out for a paid Product
Customer-support messages and attachments When you email us or use any support form
Product-specific inputs, the categories of personal information collected by any particular Product (e.g., account profile fields, self-reported wellness inputs, voice or text inputs to an AI feature, in-app logs) When you use the applicable Product; the categories are listed in the applicable Schedule §S.13
Survey responses, feedback, and other voluntary submissions When you choose to send them

We try to limit each form to the minimum information we actually need. When a field is optional, we say so. When you purchase a Product, we also add your email address to the Daybreak Labs mailing list so we can send you product updates and marketing about our own Products, on an opt-out basis (you can leave at any time (see §3 and §10). We obtain your opt-in consent first, rather than relying on opt-out, where the law requires it) for example, before marketing to someone who joined our mailing list without purchasing, or to a non-customer located in the EU, the UK, or Switzerland.

2.2 Information we collect automatically

When you visit a Daybreak Labs website or use a Daybreak Labs web or mobile Product, we automatically collect a limited set of technical information:

What Why
Server logs. IP address, timestamp, requested URL, HTTP status, user agent Operate the site, debug errors, detect abuse, comply with law
Device and browser data, browser type and version, operating system, screen size, language, time zone Render the page correctly, choose appropriate units, debug rendering issues
Usage data, which pages you visit, which Products you load, error events Improve the Product; not used for advertising
Strictly-necessary and preferences cookies Keep you signed in, remember your preferences (see §6 below)
Limited first-party analytics cookies (where enabled) Understand which pages and features are used; first-party only, never used for advertising, consent-gated for EU/UK/Swiss visitors and disabled on a Global Privacy Control signal (see §6)

We do not run cross-site advertising trackers (no Meta Pixel, no Google Ads tags, no LinkedIn Insight Tag, etc.) on Daybreak Labs websites or in our Products. We have not done so and do not plan to.

2.3 Information from other sources

Source What we receive
Our payment processor Payment status, masked last four digits of the payment card, billing name, billing address, country, and a payment-processor-issued customer or charge ID. We do not receive your full card number, CVV, or bank-routing information at any point.
Our transactional email provider Delivery status, bounce status, and engagement metadata for emails we send you
Public sources (only if you reach out from a public channel) Limited contact information you have made publicly available

The current identities of our payment processor and transactional email provider are published on the maintained subprocessor list at daybreaklabs.studio/subprocessors.

We do not buy email lists, marketing data, or behavioral data from data brokers.


3. HOW WE USE YOUR INFORMATION

We use the information described in §2 for the following purposes, and only for these purposes:

We do not use your personal information for third-party advertising, cross-context behavioral advertising, or targeted advertising of any kind. We do not share, sell, rent, lease, or trade your personal information with advertising networks, social-media platforms, data brokers, or analytics trackers for advertising purposes. The relevant US state-law definition of "sale" includes sharing for cross-context behavioral advertising; we do not do that either (see §11.1).


For users protected by the EU General Data Protection Regulation, the UK GDPR, or the Swiss Federal Act on Data Protection, our legal bases under Article 6 of the GDPR (or its UK and Swiss equivalents) for each processing purpose are as follows:

Processing activity Lawful basis
Deliver a Product you purchased; provide and maintain your account; deliver downloads and entitlement renewals Art. 6(1)(b), performance of a contract with you
Process payments via our payment processor Art. 6(1)(b), performance of a contract with you
Send order confirmations, receipts, renewal notices, security notices, and material policy-change notices Art. 6(1)(b), performance of a contract with you
Provide customer support in response to your inquiry Art. 6(1)(b) (performance of a contract; or Art. 6(1)(a)) consent, where you initiate the conversation
Retain transaction and accounting records for tax, accounting, and regulatory periods Art. 6(1)(c), compliance with a legal obligation
Operate, maintain, debug, secure, and improve our Products and websites; prevent fraud and abuse Art. 6(1)(f), our legitimate interests in running a viable business and a safe service, balanced against your rights
Send marketing communications to past customers about new Daybreak Labs Products Art. 6(1)(f) (legitimate interests, with an opt-out in every message; or Art. 6(1)(a)) consent, where required by ePrivacy law
Send marketing communications to a non-customer who has signed up for a mailing list Art. 6(1)(a), your unambiguous opt-in consent
Place non-essential cookies (analytics, preferences beyond strictly necessary) Art. 6(1)(a), consent via the cookie banner

Special-category data (Article 9). Where a Daybreak Labs Product processes inputs that include information relating to your health, sleep, fatigue, energy, mood, or other wellness topics, those inputs may include "data concerning health" under Article 9(1) GDPR. The lawful basis for processing such special-category data is Article 9(2)(a), your explicit consent, captured during the applicable Product's onboarding flow with a separate, granular checkbox that is not bundled with acceptance of the Master Terms. You can withdraw that consent at any time in the Product's settings or by emailing us; withdrawing it will cause us to delete the affected inputs and may limit your use of the affected feature. The full data flow for any such Product is described in the applicable Schedule §S.13.


5. HOW WE SHARE YOUR INFORMATION

We share your personal information only in the limited circumstances described below.

5.1 Service providers and subprocessors

We use a small number of service providers ("subprocessors") to run our Products and websites. The current authoritative subprocessor list is maintained at daybreaklabs.studio/subprocessors and is updated whenever the list changes. The maintained list identifies, for each subprocessor, the service it provides to us, the country or region in which it processes data, and a link to its own privacy policy.

Each subprocessor is bound by a written data-protection agreement that limits it to using your personal information only to provide its service to us and prohibits any independent use for the subprocessor's own purposes.

Which subprocessors process data for any particular Daybreak Labs Product (the Product-by-Product mapping) is set out in the applicable Schedule §S.13. We chose to maintain the subprocessor list at a single canonical URL rather than embed it in this Privacy Policy so that the list stays current without requiring a Privacy Policy version bump every time a vendor is added or replaced; material changes to the subprocessor footprint are nonetheless treated as a material change under §14.

Where a subprocessor on the maintained list offers an EU-US Data Privacy Framework self-certification or executes Standard Contractual Clauses, those mechanisms apply to transfers (see §12).

5.2 Aggregated or anonymized information

We may share aggregated or de-identified information that cannot reasonably be linked back to you (for example, total active accounts, total purchases in a quarter, or aggregate performance metrics) with the public, the press, partners, or our own service providers. We will not attempt to re-identify aggregated information, and we will require any recipient of de-identified data to commit to the same.

We may disclose personal information when we believe in good faith that disclosure is required by, or appropriate in response to:

We will narrow any disclosure to what the request reasonably requires, will challenge requests we believe to be overbroad, and will, where permitted by law, give you notice of the request so you can respond.

5.4 Business transfers

If Daybreak Labs is involved in a merger, acquisition, financing, restructuring, sale of substantially all of its assets, bankruptcy, or similar transaction, personal information may be transferred as part of that transaction. We will give you advance notice of any such transfer where required by law, and the successor entity will be bound by privacy commitments at least as protective as those in this Privacy Policy in respect of personal information transferred.

We will share personal information with any other recipient if you direct us to or give us your consent, for example, if you ask us to forward a copy of your support thread to your CPA.

5.6 What we do NOT do

We do not:


6. COOKIES, ANALYTICS, AND TRACKING TECHNOLOGIES

We use cookies and similar technologies sparingly. We group what we set into four categories:

Payment-processor checkout. When you reach the payment processor's checkout step of a purchase, the payment processor sets its own cookies for fraud prevention and session management. Those cookies are governed by the payment processor's privacy and cookie policies (linked from the maintained subprocessor list at daybreaklabs.studio/subprocessors). We do not control them.

Global Privacy Control (GPC). We honor GPC signals (Sec-GPC: 1) for all US visitors regardless of state of residence. When we detect GPC, we treat the request as an opt-out of any sharing or sale of personal information, disable optional analytics cookies for the session, and record the GPC signal as your standing preference.

"Do Not Track." Most web browsers offer a "Do Not Track" setting. There is no industry consensus on how websites should respond to DNT signals. Daybreak Labs does not currently respond to DNT signals, we honor the Global Privacy Control signal described above instead, and we do not use cross-site advertising trackers, so the practical privacy outcome on our sites is the same whether or not your browser sends DNT.

Mobile-app SDKs. Where a Daybreak Labs Product is a mobile or desktop app, equivalent technologies (local storage, native identifiers) substitute for cookies; the same categories and consent rules apply.


7. ARTIFICIAL INTELLIGENCE AND AUTOMATED PROCESSING

This Section 7 applies only to Daybreak Labs Products for which the applicable Schedule indicates that artificial intelligence or automated outputs are used (i.e., where the Schedule's §S.9 sets ai_applicable: true). For Products whose Schedule states ai_applicable: false, this Section 7 does not apply and the Product's "no AI" representation in §S.9 of the applicable Schedule controls. This Section 7 supplements (and is read together with) Master §16.

For Products that use artificial intelligence, the following Privacy Policy commitments apply:

Where a Daybreak Labs Product gives you an option to opt out of AI features and continue to use the rest of the Product, that option is described in the Product's settings UI; opting out has no other consequence for your account.


8. DATA RETENTION

We keep personal information only as long as we need it for the purpose for which we collected it, and then we delete or de-identify it. The portfolio-level retention periods or criteria are as follows; per-Product retention that differs from these defaults is set out in the applicable Schedule §S.13, and the Schedule controls for that Product (consistent with Master §2).

Category Retention period
Order records (purchase confirmation, payment-processor metadata, license entitlement) 7 years from the date of purchase, to satisfy federal and New York tax, accounting, and recordkeeping obligations
Account data for Products that have accounts While your account is active; then 90 days after you delete the account, after which we delete or de-identify the account data, except where a longer period is required by law
Email address on a marketing list Until you unsubscribe; we then remove your address from the active mailing list within 10 business days and from suppression-list backups within 90 days
Customer-support messages and attachments 2 years from the close of the support thread
Product-specific data (e.g., AI transcripts, in-app inputs, wellness logs) As stated in the applicable Schedule §S.13; default 30 days where the Schedule does not state otherwise. Where the Product surfaces a user-controlled retention setting, that setting overrides the default.
Server logs and usage events 90 days, after which logs are deleted or de-identified
Operational backups 35 days rolling window; backups are encrypted and access-controlled
De-identified or aggregated data Indefinite; cannot reasonably be re-linked to you

Where a legal hold, a regulator's request, a pending dispute, a fraud investigation, or a comparable legitimate purpose requires us to retain a specific record for longer than the period above, we will retain it only for as long as that purpose continues to apply, and then delete or de-identify it.


9. SECURITY, SAFEGUARDS, AND BREACH NOTIFICATION

We maintain reasonable administrative, technical, and physical safeguards designed to protect the personal information we receive, consistent with applicable state law (most notably the New York SHIELD Act, NY Gen. Bus. Law §899-bb, and analogous statutes in Massachusetts, Illinois, and Texas), appropriate to the size and complexity of our business, and proportionate to the sensitivity of the information we hold.

Those safeguards include:

No security program is perfect, and we cannot guarantee that personal information will never be the subject of unauthorized access, use, disclosure, or loss. If a security incident affects your personal information and triggers a notification obligation under applicable law, we will notify you and the relevant supervisory authorities as required:

We do not gratuitously hold ourselves out as a "financial institution" under the Gramm-Leach-Bliley Act or as a tax-return preparer subject to IRC §7216, because we are neither (see §1 above and Master §4). The reasonable-safeguards standard described in this section is the standard that applies to us, and it is the standard we follow.


10. YOUR RIGHTS: UNIVERSAL BASELINE

We voluntarily extend the following rights to every user, regardless of where you live. Applicable law in your jurisdiction may give you additional or more specific rights, those are described in §11 (US state rights) and §12 (EU, UK, Switzerland).

You have the right to:

10.1 How to exercise a right

Email info@daybreaklabs.studio with the words "Privacy rights request" in the subject line and a brief description of which right you want to exercise. We do not require a specific form, account, or login to submit a request. You can also send a written request to the mailing address in §15.

10.2 Verification

To protect you against fraudulent requests submitted under your name, we will take reasonable steps to verify your identity before acting on a request. The verification we require is calibrated to the sensitivity of the request, for an access or deletion request from someone with an account, we will typically verify via the email on file; for a request from someone without an account, we may ask for additional information sufficient to match against records we hold. We will not ask for new information beyond what is reasonably necessary to verify your identity, and we will use the information you give us only for the verification.

10.3 Response time

We aim to acknowledge requests within 5 business days and to substantively respond within 30 calendar days (one calendar month), extendable as permitted by applicable law (e.g., a further two months under GDPR Art. 12(3) for complex or numerous requests, with notice to you of the extension). Where applicable law sets a shorter timeline, we will respond within the shorter timeline.

10.4 Authorized agents

You may use an authorized agent to submit a request on your behalf. The agent must provide a signed written authorization from you, and we may verify your identity directly with you in addition to verifying the authorization. We will not act on an unverified agent submission.

10.5 Appeals

If we decline a request in whole or in part, we will explain why. You may appeal the decision by replying to our response with the word "Appeal" in the subject line; we will review the appeal within 45 days and respond in writing. If we maintain our decision on appeal, our response will include contact information for your state's attorney general or, for GDPR users, your member-state supervisory authority, so you can lodge a complaint.


11. STATE-SPECIFIC PRIVACY RIGHTS (UNITED STATES)

Several US states have enacted general consumer-privacy laws that give residents specific rights. We voluntarily extend the rights in §10 to all US residents regardless of whether we meet the applicability thresholds of any specific state law. The list below names the state laws under which residents have additional or more-specific rights, and the table summarizes those rights so you can see what applies in your state.

States with general consumer-privacy laws that may apply (the specific rights are summarized in the table below; effective dates and applicability thresholds vary): California (CCPA / CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Tennessee (TIPA), Florida (FDBR), and the newer regimes in Delaware, Iowa, New Hampshire, New Jersey, Minnesota, Maryland, and Rhode Island as those come into force.

State Statute Eff. Know / Access Delete Correct Portability Opt-out Sale/Share Opt-out Targeted Ads Opt-out Profiling SPI opt-in/limit Appeal
CA CCPA / CPRA 2020/2023 Yes Yes Yes Yes Yes (sale + share) Yes Yes Limit use; opt-in for minors <16 No statutory consumer appeal
VA VCDPA 2023 Yes Yes Yes Yes Yes Yes Yes Opt-in Yes
CO CPA 2023 Yes Yes Yes Yes Yes Yes Yes Opt-in Yes
CT CTDPA 2023 Yes Yes Yes Yes Yes Yes Yes Opt-in Yes
UT UCPA 2023 Yes Yes No Yes Yes Yes No Opt-out No
TX TDPSA 2024 Yes Yes Yes Yes Yes Yes Yes Opt-in Yes
OR OCPA 2024 Yes Yes Yes Yes Yes Yes Yes Opt-in Yes
TN TIPA 2025 Yes Yes Yes Yes Yes Yes Yes Opt-in Yes
FL FDBR 2024 Yes Yes Yes Yes Yes Yes Yes Opt-in Yes

To exercise any right under your state's law, email info@daybreaklabs.studio as described in §10.1. We will identify the rights available to you under your state's law and respond accordingly.

11.1 California: additional disclosures

The following disclosures are made for California residents in compliance with the CCPA and CPRA:

Categories of personal information we have collected in the past 12 months (mapped to Cal. Civ. Code §1798.140(v) statutory categories):

Categories of sensitive personal information we collect (CPRA-added §1798.140(ae)):

We use sensitive personal information only for the purposes permitted by CCPA Reg. §7027(m) without triggering the right to limit (delivery of the Product you purchased, security, and fraud prevention), and otherwise only as required by law, and not for inferring characteristics about you. You have the right to limit the use and disclosure of your sensitive personal information under §1798.121, to exercise it, email info@daybreaklabs.studio as described in §10.1.

Sale and sharing of personal information. Daybreak Labs does not sell personal information for monetary consideration, and does not share personal information for cross-context behavioral advertising within the meaning of California Civil Code §1798.140(ah). We have not done so in the prior 12 months.

Notice at collection. When you visit a Daybreak Labs website that collects personal information, the notice at collection appears at or before the point of collection and links here.

California "Shine the Light" (Cal. Civ. Code §1798.83). California residents may request information about our disclosure of personal information to third parties for those third parties' direct-marketing purposes. We do not disclose personal information for third-party direct-marketing purposes.

Financial incentives. We do not offer any financial incentive program tied to the collection, retention, sale, or sharing of personal information.

11.2 Other US states: additional notes


12. INTERNATIONAL DATA TRANSFERS

Daybreak Labs is a New York limited liability company. We process personal information on servers operated by our service providers in the United States. If you are located in the European Economic Area, the United Kingdom, Switzerland, or another jurisdiction whose laws restrict cross-border transfers of personal data, your personal information will be transferred to, processed in, and stored in the United States.

We rely on the following transfer mechanisms, in this order of preference:

  1. EU-US Data Privacy Framework, UK Extension, and Swiss-US Data Privacy Framework. Where a subprocessor on the maintained list self-certifies under the DPF, we rely on that certification. DPF-certified status for any given subprocessor is identified on the maintained subprocessor page at daybreaklabs.studio/subprocessors.
  2. Standard Contractual Clauses (2021 EU SCCs, with the UK International Data Transfer Addendum where applicable). Where a subprocessor is not DPF-certified, or as a fallback layer behind a DPF certification, we execute the 2021 SCCs in the applicable module (controller-to-processor or processor-to-processor) and maintain a transfer impact assessment for each material transfer.
  3. Article 49 GDPR derogations in the narrow circumstances they permit (contract necessity, your explicit consent, legal claims, vital interests).

Lead supervisory authority and EU representative. Daybreak Labs does not currently have an establishment in the European Union. Under Article 27 GDPR, a controller without an EU establishment that offers goods or services to, or monitors the behaviour of, EU data subjects must designate a representative in the Union unless an exemption in Article 27(2) applies. The exemption in Article 27(2)(a) applies only to processing that meets all of the following: it is (i) occasional; (ii) does not include, on a large scale, processing of special categories of data (such as health data) under Article 9(1) or criminal-offence data under Article 10; and (iii) is unlikely to result in a risk to the rights and freedoms of natural persons. We are assessing, with counsel, whether that exemption is available for each Product.

Until that assessment is complete for a given Product, no Daybreak Labs Product that processes special-category data (e.g., health data) of EU users will be offered to EU users unless and until we have either (a) appointed an Article 27 representative established in the Union, or (b) restricted access for EU-located users. Where a representative is appointed, we will identify it and its contact details here. Pending that, EU and UK users may contact us directly at info@daybreaklabs.studio.

You also have the right to lodge a complaint with the supervisory authority in the EU member state of your habitual residence, place of work, or place of the alleged infringement, or with the UK Information Commissioner's Office (ICO) at ico.org.uk.


13. CHILDREN'S PRIVACY

Daybreak Labs Products are not directed to children under 16. We do not knowingly collect personal information from anyone under 16 without verifiable consent from a parent or legal guardian. This commitment satisfies both:

If you are a parent or legal guardian and you believe that we have collected personal information from your child under 16, please email info@daybreaklabs.studio. We will delete the information promptly upon verification.


14. CHANGES TO THIS PRIVACY POLICY

This Privacy Policy is a living document. The protocol for changes mirrors the modifications protocol in Master §22.

The "Last updated" date at the top of this Privacy Policy identifies the most recent version. Earlier versions are preserved in the public CHANGELOG at daybreaklabs.studio/changelog so you can compare. Product-specific privacy detail (categories of data, retention, subprocessor mapping, AI training commitments) lives in the §S.13 of each Product's Schedule and is versioned with that Schedule.


15. CONTACT

Questions about this Privacy Policy, requests to exercise your rights, complaints, or any other privacy-related communications should be sent to:

Daybreak Labs LLC Attn: Privacy 300 State Route 313, Cambridge, NY 12816 Email: info@daybreaklabs.studio

For everything else (Product support, billing, partnerships, press), see the Product-specific contact information in the applicable Schedule.

We aim to acknowledge privacy emails within five business days. If something here is unclear, email us, we would rather answer the question than have you guess.


Daybreak Labs LLC | Privacy Policy v1.3 | Effective: September 3, 2026 | Last updated September 3, 2026

This Privacy Policy is read together with the Daybreak Labs Master Terms of Use v1.1 (daybreaklabs.studio/terms) and the applicable Product Schedule (each Schedule's §S.13 contains the Product-specific privacy notes). The maintained subprocessor list lives at daybreaklabs.studio/subprocessors. See daybreaklabs.studio/privacy for the canonical current version of this Privacy Policy.