Legal
Daybreak Labs Privacy Policy
Effective date: September 3, 2026 | Version: v1.3 | Last updated: September 3, 2026
IMPORTANT NOTICE. This Privacy Policy is one half of a pair. It is read together with the Daybreak Labs Master Terms of Use at
daybreaklabs.studio/termsand with the applicable Product Schedule for the specific Daybreak Labs Product you are using. The Master Terms incorporate this Privacy Policy by reference at Master §14. Capitalized terms used and not defined here have the meanings given in the Master Terms.
This Privacy Policy explains how Daybreak Labs LLC,
a New York limited liability company ("Daybreak Labs,"
"we," "us," or "our"), collects, uses, shares, and protects personal
information when you visit our websites, purchase or use any of our
Products, or communicate with us. It applies to every Daybreak Labs
Product (each defined in the Master Terms) and to the Daybreak Labs
storefront and marketing site at daybreaklabs.studio and
its subdomains. Product-specific privacy notes that differ from or
supplement this Privacy Policy appear in §S.13 of the applicable Product
Schedule; in the event of any direct conflict between this Privacy
Policy and a Schedule §S.13, the Schedule controls solely with respect
to that Product (consistent with Master §2).
What this means in practice: plain-English summary
- We collect only what we need to deliver the Product you bought, and very little else. For most Products, that is your email address, the payment metadata our payment processor shares with us, and any message you send to support. When you buy from us, we will also email you about our other Daybreak Labs Products and updates, you can unsubscribe from that with one click at any time. Some Products collect more, and the additional categories are listed in the applicable Schedule §S.13.
- Some Products operate locally on your own device. Where a Product is a downloadable file or otherwise runs on your computer without sending data back to us, the data you enter into the Product stays on your device. The applicable Schedule §S.13 describes the data flow for each Product, including any "no telemetry" representation.
- We do not sell your personal information. We do not share it with advertising platforms, data brokers, or trackers for advertising purposes. We do not allow our service providers to use your information for their own purposes.
- We use a short, named list of service providers.
The current authoritative list is published at
daybreaklabs.studio/subprocessors. Each provider is bound by a written agreement that limits it to providing its service to us. Which providers are used by which Product is described in the applicable Schedule §S.13. - You have rights over your information. You can ask
us what we have, ask us to correct it, ask us to delete it, ask us to
stop sending you marketing, and, if you live in the EU, the UK,
Switzerland, California, Virginia, Colorado, Connecticut, Utah, Texas,
Oregon, Tennessee, Florida, or any other US state that grants the right,
exercise the additional rights described in §11 below. Email
info@daybreaklabs.studioto exercise any of them.
If anything in this Privacy Policy is unclear, email us. We would rather answer the question than have you guess.
1. SCOPE AND WHAT THIS POLICY COVERS
This Privacy Policy covers Daybreak Labs's collection, use, sharing, retention, and protection of personal information, meaning information that identifies, relates to, or could reasonably be linked with you (or, where required by applicable law, your household or device).
This Privacy Policy applies to:
- (a) personal information you provide to us when you visit
daybreaklabs.studioand its subdomains, purchase a Daybreak Labs Product, create an account, sign up for a mailing list, use any Product that communicates with our servers, or contact us; and - (b) personal information we receive about you from our payment processor, our identity and fraud-prevention vendors (if any), and our service providers.
This Privacy Policy does not apply to:
- (c) information you provide to or process within a Daybreak Labs Product that operates locally on your own device. That information stays on your device. Daybreak Labs has no technical means of seeing, receiving, or storing it. The "no telemetry" representation for any such Product is set out in the applicable Schedule §S.13;
- (d) personal information processed by third-party websites or services you reach through links from a Daybreak Labs Product, which is governed by those third parties' own privacy policies (see also Master §12, Third-Party Links); or
- (e) personal information you choose to share with your own CPA, Enrolled Agent, tax attorney, doctor, or other licensed professional in connection with your use of a Daybreak Labs Product, those professionals are independent of Daybreak Labs and are bound by their own professional and legal duties.
For the avoidance of doubt, Daybreak Labs is not a tax return preparer within IRC §7216 with respect to any Daybreak Labs Product, we do not prepare federal, state, or local returns for any customer; do not assist any customer in preparing a return; do not transmit any return to any taxing authority; and are not an Authorized IRS e-File Provider.
2. INFORMATION WE COLLECT
We collect personal information in three buckets: what you provide directly, what we collect automatically when you use a Product, and what we receive from other sources we work with.
2.1 Information you provide directly
| What | When you give it to us |
|---|---|
| Name, email address, and (for paid Products) billing address | When you buy a Product, create an account, or sign up for a mailing list |
| Payment information collected by our payment processor (see §2.3 below, we do not see or store your full card number, CVV, or bank-routing information) | When you check out for a paid Product |
| Customer-support messages and attachments | When you email us or use any support form |
| Product-specific inputs, the categories of personal information collected by any particular Product (e.g., account profile fields, self-reported wellness inputs, voice or text inputs to an AI feature, in-app logs) | When you use the applicable Product; the categories are listed in the applicable Schedule §S.13 |
| Survey responses, feedback, and other voluntary submissions | When you choose to send them |
We try to limit each form to the minimum information we actually need. When a field is optional, we say so. When you purchase a Product, we also add your email address to the Daybreak Labs mailing list so we can send you product updates and marketing about our own Products, on an opt-out basis (you can leave at any time (see §3 and §10). We obtain your opt-in consent first, rather than relying on opt-out, where the law requires it) for example, before marketing to someone who joined our mailing list without purchasing, or to a non-customer located in the EU, the UK, or Switzerland.
2.2 Information we collect automatically
When you visit a Daybreak Labs website or use a Daybreak Labs web or mobile Product, we automatically collect a limited set of technical information:
| What | Why |
|---|---|
| Server logs. IP address, timestamp, requested URL, HTTP status, user agent | Operate the site, debug errors, detect abuse, comply with law |
| Device and browser data, browser type and version, operating system, screen size, language, time zone | Render the page correctly, choose appropriate units, debug rendering issues |
| Usage data, which pages you visit, which Products you load, error events | Improve the Product; not used for advertising |
| Strictly-necessary and preferences cookies | Keep you signed in, remember your preferences (see §6 below) |
| Limited first-party analytics cookies (where enabled) | Understand which pages and features are used; first-party only, never used for advertising, consent-gated for EU/UK/Swiss visitors and disabled on a Global Privacy Control signal (see §6) |
We do not run cross-site advertising trackers (no Meta Pixel, no Google Ads tags, no LinkedIn Insight Tag, etc.) on Daybreak Labs websites or in our Products. We have not done so and do not plan to.
2.3 Information from other sources
| Source | What we receive |
|---|---|
| Our payment processor | Payment status, masked last four digits of the payment card, billing name, billing address, country, and a payment-processor-issued customer or charge ID. We do not receive your full card number, CVV, or bank-routing information at any point. |
| Our transactional email provider | Delivery status, bounce status, and engagement metadata for emails we send you |
| Public sources (only if you reach out from a public channel) | Limited contact information you have made publicly available |
The current identities of our payment processor and transactional
email provider are published on the maintained subprocessor list at
daybreaklabs.studio/subprocessors.
We do not buy email lists, marketing data, or behavioral data from data brokers.
3. HOW WE USE YOUR INFORMATION
We use the information described in §2 for the following purposes, and only for these purposes:
- Deliver the Product you purchased. Send you the download link, deliver entitlement renewals, provision and maintain your account where the Product has one.
- Process payments. Charge you for a Product or renewal through our payment processor; issue refunds where applicable per the Refund Policy.
- Communicate with you about your purchase. Send order confirmations, receipts, license-renewal notices, security notices, material changes to the Master Terms or this Privacy Policy, and replies to support requests. These communications are transactional and you cannot opt out of them while you are using the Product (per Master §15).
- Provide customer support. Read, respond to, and act on the messages you send us.
- Operate, maintain, debug, and improve our Products and websites. Use server logs and usage data to fix bugs, measure performance, and inform product decisions.
- Detect, prevent, and respond to fraud, abuse, and security threats. Spot suspicious activity, block unauthorized access, defend against attacks, and comply with abuse-handling obligations.
- Comply with legal, tax, accounting, and regulatory obligations. Retain transaction records as required by federal and state tax law; respond to lawful requests from government authorities; defend or assert legal claims.
- Send you marketing and product-update emails about Daybreak Labs. Keeping you informed about new Daybreak Labs Products, updates, and offers is one of the purposes we collect your email address for, and we state it plainly. When you purchase a Product, we may add your email address to the Daybreak Labs mailing list on an opt-out basis. We market only our own Daybreak Labs Products (never third parties') and we never email purchased, rented, or harvested address lists. Every marketing email carries a one-click unsubscribe link and our postal address (see §15); you can also opt out by emailing us; and we honor every opt-out within ten business days. Where applicable law requires your opt-in before we may market to you, for example, if you join our mailing list without making a purchase, or you are in the EU, the UK, or Switzerland and are not an existing customer being told about our own similar Products, we obtain that consent first instead of relying on opt-out (see the legal-basis table in §4). The transactional messages described above (order confirmations, receipts, renewal and security notices, and material policy-change notices) are not marketing: they are not subject to the unsubscribe mechanism and continue regardless of your marketing preference, for as long as you use the Product.
We do not use your personal information for third-party advertising, cross-context behavioral advertising, or targeted advertising of any kind. We do not share, sell, rent, lease, or trade your personal information with advertising networks, social-media platforms, data brokers, or analytics trackers for advertising purposes. The relevant US state-law definition of "sale" includes sharing for cross-context behavioral advertising; we do not do that either (see §11.1).
4. LEGAL BASES FOR PROCESSING (EEA, UK, AND SWISS DATA SUBJECTS)
For users protected by the EU General Data Protection Regulation, the UK GDPR, or the Swiss Federal Act on Data Protection, our legal bases under Article 6 of the GDPR (or its UK and Swiss equivalents) for each processing purpose are as follows:
| Processing activity | Lawful basis |
|---|---|
| Deliver a Product you purchased; provide and maintain your account; deliver downloads and entitlement renewals | Art. 6(1)(b), performance of a contract with you |
| Process payments via our payment processor | Art. 6(1)(b), performance of a contract with you |
| Send order confirmations, receipts, renewal notices, security notices, and material policy-change notices | Art. 6(1)(b), performance of a contract with you |
| Provide customer support in response to your inquiry | Art. 6(1)(b) (performance of a contract; or Art. 6(1)(a)) consent, where you initiate the conversation |
| Retain transaction and accounting records for tax, accounting, and regulatory periods | Art. 6(1)(c), compliance with a legal obligation |
| Operate, maintain, debug, secure, and improve our Products and websites; prevent fraud and abuse | Art. 6(1)(f), our legitimate interests in running a viable business and a safe service, balanced against your rights |
| Send marketing communications to past customers about new Daybreak Labs Products | Art. 6(1)(f) (legitimate interests, with an opt-out in every message; or Art. 6(1)(a)) consent, where required by ePrivacy law |
| Send marketing communications to a non-customer who has signed up for a mailing list | Art. 6(1)(a), your unambiguous opt-in consent |
| Place non-essential cookies (analytics, preferences beyond strictly necessary) | Art. 6(1)(a), consent via the cookie banner |
Special-category data (Article 9). Where a Daybreak Labs Product processes inputs that include information relating to your health, sleep, fatigue, energy, mood, or other wellness topics, those inputs may include "data concerning health" under Article 9(1) GDPR. The lawful basis for processing such special-category data is Article 9(2)(a), your explicit consent, captured during the applicable Product's onboarding flow with a separate, granular checkbox that is not bundled with acceptance of the Master Terms. You can withdraw that consent at any time in the Product's settings or by emailing us; withdrawing it will cause us to delete the affected inputs and may limit your use of the affected feature. The full data flow for any such Product is described in the applicable Schedule §S.13.
5. HOW WE SHARE YOUR INFORMATION
We share your personal information only in the limited circumstances described below.
5.1 Service providers and subprocessors
We use a small number of service providers ("subprocessors") to run
our Products and websites. The current authoritative subprocessor list
is maintained at
daybreaklabs.studio/subprocessors and is
updated whenever the list changes. The maintained list identifies, for
each subprocessor, the service it provides to us, the country or region
in which it processes data, and a link to its own privacy policy.
Each subprocessor is bound by a written data-protection agreement that limits it to using your personal information only to provide its service to us and prohibits any independent use for the subprocessor's own purposes.
Which subprocessors process data for any particular Daybreak Labs Product (the Product-by-Product mapping) is set out in the applicable Schedule §S.13. We chose to maintain the subprocessor list at a single canonical URL rather than embed it in this Privacy Policy so that the list stays current without requiring a Privacy Policy version bump every time a vendor is added or replaced; material changes to the subprocessor footprint are nonetheless treated as a material change under §14.
Where a subprocessor on the maintained list offers an EU-US Data Privacy Framework self-certification or executes Standard Contractual Clauses, those mechanisms apply to transfers (see §12).
5.2 Aggregated or anonymized information
We may share aggregated or de-identified information that cannot reasonably be linked back to you (for example, total active accounts, total purchases in a quarter, or aggregate performance metrics) with the public, the press, partners, or our own service providers. We will not attempt to re-identify aggregated information, and we will require any recipient of de-identified data to commit to the same.
5.3 Legal disclosures
We may disclose personal information when we believe in good faith that disclosure is required by, or appropriate in response to:
- a subpoena, court order, search warrant, or other lawful request from a US, EU, UK, or other competent authority;
- a request from law enforcement to investigate suspected illegal activity;
- our need to defend our own legal rights, your rights, or the rights of any other user;
- an emergency that we reasonably believe involves a risk of death, serious physical injury, or material harm to a person; or
- our compliance with applicable law, including tax, accounting, regulatory, and anti-money-laundering law.
We will narrow any disclosure to what the request reasonably requires, will challenge requests we believe to be overbroad, and will, where permitted by law, give you notice of the request so you can respond.
5.4 Business transfers
If Daybreak Labs is involved in a merger, acquisition, financing, restructuring, sale of substantially all of its assets, bankruptcy, or similar transaction, personal information may be transferred as part of that transaction. We will give you advance notice of any such transfer where required by law, and the successor entity will be bound by privacy commitments at least as protective as those in this Privacy Policy in respect of personal information transferred.
5.5 With your direction or consent
We will share personal information with any other recipient if you direct us to or give us your consent, for example, if you ask us to forward a copy of your support thread to your CPA.
5.6 What we do NOT do
We do not:
- sell your personal information for monetary consideration;
- share your personal information with third parties for cross-context behavioral advertising or any other targeted-advertising purpose;
- allow any subprocessor to use your personal information for the subprocessor's own purposes;
- use your personal information, account history, conversation history, AI transcripts, order history, email address, or support correspondence to train any general-purpose AI model;
- buy email lists, marketing data, or behavioral data from data brokers;
- embed third-party advertising trackers (Meta Pixel, Google Ads tag,
LinkedIn Insight Tag, TikTok Pixel, etc.) on
daybreaklabs.studioor in any Daybreak Labs Product; or - send marketing email to anyone with whom we have no relationship and who has neither purchased a Daybreak Labs Product nor opted in to our mailing list, and we never send marketing email to purchased, rented, or harvested address lists.
6. COOKIES, ANALYTICS, AND TRACKING TECHNOLOGIES
We use cookies and similar technologies sparingly. We group what we set into four categories:
- Strictly necessary cookies, keep you signed in, remember the state of a form, route your request to the right region. Always set; you cannot turn these off and continue to use the Product.
- Preferences cookies, remember your timezone, dark/light mode, and other settings.
- Analytics cookies (limited), first-party only; aggregate, privacy-respecting product analytics that help us understand which pages and features are used. Optional and disabled by default for visitors who appear to be in the EU, the UK, or Switzerland until consent is given; disabled for any visitor whose browser sends a Global Privacy Control signal (see below).
- Advertising cookies, we do not set any.
Payment-processor checkout. When you reach the
payment processor's checkout step of a purchase, the payment processor
sets its own cookies for fraud prevention and session management. Those
cookies are governed by the payment processor's privacy and cookie
policies (linked from the maintained subprocessor list at
daybreaklabs.studio/subprocessors). We do not control
them.
Global Privacy Control (GPC). We honor GPC signals
(Sec-GPC: 1) for all US visitors regardless of state of
residence. When we detect GPC, we treat the request as an opt-out of any
sharing or sale of personal information, disable optional analytics
cookies for the session, and record the GPC signal as your standing
preference.
"Do Not Track." Most web browsers offer a "Do Not Track" setting. There is no industry consensus on how websites should respond to DNT signals. Daybreak Labs does not currently respond to DNT signals, we honor the Global Privacy Control signal described above instead, and we do not use cross-site advertising trackers, so the practical privacy outcome on our sites is the same whether or not your browser sends DNT.
Mobile-app SDKs. Where a Daybreak Labs Product is a mobile or desktop app, equivalent technologies (local storage, native identifiers) substitute for cookies; the same categories and consent rules apply.
7. ARTIFICIAL INTELLIGENCE AND AUTOMATED PROCESSING
This Section 7 applies only to Daybreak Labs Products for which the
applicable Schedule indicates that artificial intelligence or automated
outputs are used (i.e., where the Schedule's §S.9 sets
ai_applicable: true). For Products whose Schedule states
ai_applicable: false, this Section 7 does not apply and the
Product's "no AI" representation in §S.9 of the applicable Schedule
controls. This Section 7 supplements (and is read together with) Master
§16.
For Products that use artificial intelligence, the following Privacy Policy commitments apply:
- You are interacting with an AI system, not a licensed professional. When you use any AI-powered feature of a Daybreak Labs Product, the responses you receive are generated by automated systems. They may be inaccurate, incomplete, or contextually inappropriate. You should not enter into the AI any personal or sensitive information beyond what is necessary for the conversation, and you should not rely on AI Outputs as a substitute for the judgment of an appropriately licensed professional (see Master §16 and the applicable Schedule for the complete AI disclaimer).
- We do not use your personal information, conversation history, or AI transcripts to train any general-purpose AI model. This commitment binds us and binds each subprocessor that handles AI-related data on our behalf. Where a subprocessor's default offering would train on customer data, we elect the no-training option in our contract with that subprocessor. The identity of the AI subprocessors used by any particular Product appears in the applicable Schedule §S.13 (and on the maintained subprocessor list).
- No solely automated decisions with legal or significant effects. We do not use AI to make decisions about you that are based solely on automated processing and that produce legal or similarly significant effects (such as eligibility for the Product, account suspension, or pricing) without human review. This commitment is given for the benefit of all users and satisfies the substantive requirements of Article 22 GDPR and analogous emerging US-state profiling rights.
- Sensitive content. AI inputs and outputs that relate to your health, mental state, or other sensitive topics are treated as sensitive personal information for retention, sharing, and rights purposes (see §11.1 California sensitive-PI handling; the applicable Schedule §S.13 describes the Product's specific data flow and retention).
Where a Daybreak Labs Product gives you an option to opt out of AI features and continue to use the rest of the Product, that option is described in the Product's settings UI; opting out has no other consequence for your account.
8. DATA RETENTION
We keep personal information only as long as we need it for the purpose for which we collected it, and then we delete or de-identify it. The portfolio-level retention periods or criteria are as follows; per-Product retention that differs from these defaults is set out in the applicable Schedule §S.13, and the Schedule controls for that Product (consistent with Master §2).
| Category | Retention period |
|---|---|
| Order records (purchase confirmation, payment-processor metadata, license entitlement) | 7 years from the date of purchase, to satisfy federal and New York tax, accounting, and recordkeeping obligations |
| Account data for Products that have accounts | While your account is active; then 90 days after you delete the account, after which we delete or de-identify the account data, except where a longer period is required by law |
| Email address on a marketing list | Until you unsubscribe; we then remove your address from the active mailing list within 10 business days and from suppression-list backups within 90 days |
| Customer-support messages and attachments | 2 years from the close of the support thread |
| Product-specific data (e.g., AI transcripts, in-app inputs, wellness logs) | As stated in the applicable Schedule §S.13; default 30 days where the Schedule does not state otherwise. Where the Product surfaces a user-controlled retention setting, that setting overrides the default. |
| Server logs and usage events | 90 days, after which logs are deleted or de-identified |
| Operational backups | 35 days rolling window; backups are encrypted and access-controlled |
| De-identified or aggregated data | Indefinite; cannot reasonably be re-linked to you |
Where a legal hold, a regulator's request, a pending dispute, a fraud investigation, or a comparable legitimate purpose requires us to retain a specific record for longer than the period above, we will retain it only for as long as that purpose continues to apply, and then delete or de-identify it.
9. SECURITY, SAFEGUARDS, AND BREACH NOTIFICATION
We maintain reasonable administrative, technical, and physical safeguards designed to protect the personal information we receive, consistent with applicable state law (most notably the New York SHIELD Act, NY Gen. Bus. Law §899-bb, and analogous statutes in Massachusetts, Illinois, and Texas), appropriate to the size and complexity of our business, and proportionate to the sensitivity of the information we hold.
Those safeguards include:
- Encryption in transit for all traffic to and from our websites and Products (TLS 1.2 or higher).
- Encryption at rest for account data and Product-specific data where supported by the underlying platform.
- Access controls that limit access to personal information to the Daybreak Labs personnel and service providers who need it to perform their role.
- A designated individual responsible for our information-security practices. During the solo-founder phase, that individual is Daybreak Labs's founder; the designation passes to a named security lead as the team grows.
- A written incident-response procedure covering detection, containment, eradication, recovery, internal lessons-learned, and external notifications.
- Service-provider oversight, written agreements with every subprocessor identified on the maintained subprocessor list that require the subprocessor to maintain safeguards appropriate to the data we share with it.
- Periodic review and adjustment of the program in response to changes in our business, the threat landscape, or applicable law.
No security program is perfect, and we cannot guarantee that personal information will never be the subject of unauthorized access, use, disclosure, or loss. If a security incident affects your personal information and triggers a notification obligation under applicable law, we will notify you and the relevant supervisory authorities as required:
- Under GDPR Art. 33 to 34, notification of the competent supervisory authority (Art. 55) within 72 hours of becoming aware of a personal-data breach where it presents a risk to your rights and freedoms, and direct notification to you where the breach is likely to result in a high risk.
- Under NY SHIELD Act §899-aa, notification to affected New York residents, the New York Attorney General, the New York Department of State, the New York State Police, the New York Department of Financial Services, and (where more than 5,000 NY residents are affected) consumer reporting agencies, in the most expedient time possible and without unreasonable delay.
- Under other applicable state breach-notification statutes, comparable notifications on the timelines required by those statutes.
We do not gratuitously hold ourselves out as a "financial institution" under the Gramm-Leach-Bliley Act or as a tax-return preparer subject to IRC §7216, because we are neither (see §1 above and Master §4). The reasonable-safeguards standard described in this section is the standard that applies to us, and it is the standard we follow.
10. YOUR RIGHTS: UNIVERSAL BASELINE
We voluntarily extend the following rights to every user, regardless of where you live. Applicable law in your jurisdiction may give you additional or more specific rights, those are described in §11 (US state rights) and §12 (EU, UK, Switzerland).
You have the right to:
- Know what personal information we have about you, the categories we collect, the purposes we collect it for, and the categories of third parties we share it with;
- Receive a copy of the personal information you provided to us, in a portable, machine-readable format where technically practicable;
- Correct inaccurate or incomplete personal information we hold about you;
- Delete the personal information we hold about you, subject to legal, accounting, regulatory, fraud-prevention, or legitimate-business exceptions described in §8;
- Opt out of marketing at any time, with one-click unsubscribe in every marketing email and a process for opting out of any other marketing channel we adopt;
- Withdraw consent to any processing for which we relied on your consent, at any time, without affecting the lawfulness of processing before withdrawal;
- Not be discriminated against for exercising any of these rights, you will receive the same Products, Service, and pricing whether or not you exercise any right.
10.1 How to exercise a right
Email info@daybreaklabs.studio with the
words "Privacy rights request" in the subject line and a brief
description of which right you want to exercise. We do not require a
specific form, account, or login to submit a request. You can also send
a written request to the mailing address in §15.
10.2 Verification
To protect you against fraudulent requests submitted under your name, we will take reasonable steps to verify your identity before acting on a request. The verification we require is calibrated to the sensitivity of the request, for an access or deletion request from someone with an account, we will typically verify via the email on file; for a request from someone without an account, we may ask for additional information sufficient to match against records we hold. We will not ask for new information beyond what is reasonably necessary to verify your identity, and we will use the information you give us only for the verification.
10.3 Response time
We aim to acknowledge requests within 5 business days and to substantively respond within 30 calendar days (one calendar month), extendable as permitted by applicable law (e.g., a further two months under GDPR Art. 12(3) for complex or numerous requests, with notice to you of the extension). Where applicable law sets a shorter timeline, we will respond within the shorter timeline.
10.4 Authorized agents
You may use an authorized agent to submit a request on your behalf. The agent must provide a signed written authorization from you, and we may verify your identity directly with you in addition to verifying the authorization. We will not act on an unverified agent submission.
10.5 Appeals
If we decline a request in whole or in part, we will explain why. You may appeal the decision by replying to our response with the word "Appeal" in the subject line; we will review the appeal within 45 days and respond in writing. If we maintain our decision on appeal, our response will include contact information for your state's attorney general or, for GDPR users, your member-state supervisory authority, so you can lodge a complaint.
11. STATE-SPECIFIC PRIVACY RIGHTS (UNITED STATES)
Several US states have enacted general consumer-privacy laws that give residents specific rights. We voluntarily extend the rights in §10 to all US residents regardless of whether we meet the applicability thresholds of any specific state law. The list below names the state laws under which residents have additional or more-specific rights, and the table summarizes those rights so you can see what applies in your state.
States with general consumer-privacy laws that may apply (the specific rights are summarized in the table below; effective dates and applicability thresholds vary): California (CCPA / CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Tennessee (TIPA), Florida (FDBR), and the newer regimes in Delaware, Iowa, New Hampshire, New Jersey, Minnesota, Maryland, and Rhode Island as those come into force.
| State | Statute | Eff. | Know / Access | Delete | Correct | Portability | Opt-out Sale/Share | Opt-out Targeted Ads | Opt-out Profiling | SPI opt-in/limit | Appeal |
|---|---|---|---|---|---|---|---|---|---|---|---|
| CA | CCPA / CPRA | 2020/2023 | Yes | Yes | Yes | Yes | Yes (sale + share) | Yes | Yes | Limit use; opt-in for minors <16 | No statutory consumer appeal |
| VA | VCDPA | 2023 | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Opt-in | Yes |
| CO | CPA | 2023 | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Opt-in | Yes |
| CT | CTDPA | 2023 | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Opt-in | Yes |
| UT | UCPA | 2023 | Yes | Yes | No | Yes | Yes | Yes | No | Opt-out | No |
| TX | TDPSA | 2024 | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Opt-in | Yes |
| OR | OCPA | 2024 | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Opt-in | Yes |
| TN | TIPA | 2025 | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Opt-in | Yes |
| FL | FDBR | 2024 | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Opt-in | Yes |
To exercise any right under your state's law, email
info@daybreaklabs.studio as described in
§10.1. We will identify the rights available to you under your state's
law and respond accordingly.
11.1 California: additional disclosures
The following disclosures are made for California residents in compliance with the CCPA and CPRA:
Categories of personal information we have collected in the past 12 months (mapped to Cal. Civ. Code §1798.140(v) statutory categories):
- Identifiers, name, email address, billing address, IP address, payment-processor-issued customer ID
- Customer records (Cal. Civ. Code §1798.80(e)), billing name, billing address, last four digits of payment card
- Commercial information, products purchased, transaction history
- Internet and network activity, server logs, usage events, browser type, device type
- Geolocation data, coarse IP-derived location only (city/region); precise geolocation is not collected by default. Where a Product asks you to provide your city or location optionally for a functional purpose, the applicable Schedule §S.13 describes the use.
- Audio, electronic, visual, or similar information, where a Product collects voice recordings, text transcripts, or other audio/visual inputs, the categories are listed in the applicable Schedule §S.13
- Inferences, none drawn for advertising or profiling purposes
Categories of sensitive personal information we collect (CPRA-added §1798.140(ae)):
- Personal information collected and analyzed concerning health, where a Product processes inputs that include sleep, fasting, energy, mood, or other wellness content; the specific Product is identified in the applicable Schedule §S.13
- Contents of communications, where a Product captures voice or text inputs to an AI feature (we are the intended recipient of your spoken or typed input, which may exclude this limb; we treat such inputs as sensitive PI in any event for safety)
We use sensitive personal information only for the purposes permitted
by CCPA Reg. §7027(m) without triggering the right to limit (delivery of
the Product you purchased, security, and fraud prevention), and
otherwise only as required by law, and not for inferring characteristics
about you. You have the right to limit the use and disclosure of
your sensitive personal information under §1798.121, to
exercise it, email info@daybreaklabs.studio as described in
§10.1.
Sale and sharing of personal information. Daybreak Labs does not sell personal information for monetary consideration, and does not share personal information for cross-context behavioral advertising within the meaning of California Civil Code §1798.140(ah). We have not done so in the prior 12 months.
Notice at collection. When you visit a Daybreak Labs website that collects personal information, the notice at collection appears at or before the point of collection and links here.
California "Shine the Light" (Cal. Civ. Code §1798.83). California residents may request information about our disclosure of personal information to third parties for those third parties' direct-marketing purposes. We do not disclose personal information for third-party direct-marketing purposes.
Financial incentives. We do not offer any financial incentive program tied to the collection, retention, sale, or sharing of personal information.
11.2 Other US states: additional notes
- Texas (TDPSA). Texans have the rights in the table above. We honor Global Privacy Control as a Universal Opt-Out Mechanism.
- Colorado, Connecticut, Oregon. We honor Global Privacy Control as a Universal Opt-Out Mechanism in these states.
- Tennessee (TIPA). We design our information-security program around recognized cybersecurity frameworks so that it is consistent with the affirmative defense available under TIPA.
- Utah (UCPA). Utah residents do not have the right to opt out of profiling or an appeal mechanism under UCPA, and (through June 30, 2026) no statutory right to correct; effective July 1, 2026, UCPA as amended (Utah Laws 2025, Ch. 468) adds a right to correct. We already extend the universal correction right described in §10 to Utah residents on a voluntary basis, so this change does not affect how we treat your request.
- Florida (FDBR). FDBR's applicability thresholds (US$1B+ global revenue, plus a Big-Tech business model) do not currently bring Daybreak Labs into scope. We extend the universal rights in §10 to Florida residents on a voluntary basis.
12. INTERNATIONAL DATA TRANSFERS
Daybreak Labs is a New York limited liability company. We process personal information on servers operated by our service providers in the United States. If you are located in the European Economic Area, the United Kingdom, Switzerland, or another jurisdiction whose laws restrict cross-border transfers of personal data, your personal information will be transferred to, processed in, and stored in the United States.
We rely on the following transfer mechanisms, in this order of preference:
- EU-US Data Privacy Framework, UK Extension, and Swiss-US
Data Privacy Framework. Where a subprocessor on the maintained
list self-certifies under the DPF, we rely on that certification.
DPF-certified status for any given subprocessor is identified on the
maintained subprocessor page at
daybreaklabs.studio/subprocessors. - Standard Contractual Clauses (2021 EU SCCs, with the UK International Data Transfer Addendum where applicable). Where a subprocessor is not DPF-certified, or as a fallback layer behind a DPF certification, we execute the 2021 SCCs in the applicable module (controller-to-processor or processor-to-processor) and maintain a transfer impact assessment for each material transfer.
- Article 49 GDPR derogations in the narrow circumstances they permit (contract necessity, your explicit consent, legal claims, vital interests).
Lead supervisory authority and EU representative. Daybreak Labs does not currently have an establishment in the European Union. Under Article 27 GDPR, a controller without an EU establishment that offers goods or services to, or monitors the behaviour of, EU data subjects must designate a representative in the Union unless an exemption in Article 27(2) applies. The exemption in Article 27(2)(a) applies only to processing that meets all of the following: it is (i) occasional; (ii) does not include, on a large scale, processing of special categories of data (such as health data) under Article 9(1) or criminal-offence data under Article 10; and (iii) is unlikely to result in a risk to the rights and freedoms of natural persons. We are assessing, with counsel, whether that exemption is available for each Product.
Until that assessment is complete for a given Product, no
Daybreak Labs Product that processes special-category data (e.g., health
data) of EU users will be offered to EU users unless and until we have
either (a) appointed an Article 27 representative established in the
Union, or (b) restricted access for EU-located users. Where a
representative is appointed, we will identify it and its contact details
here. Pending that, EU and UK users may contact us directly at
info@daybreaklabs.studio.
You also have the right to lodge a complaint with the supervisory
authority in the EU member state of your habitual residence, place of
work, or place of the alleged infringement, or with the UK Information
Commissioner's Office (ICO) at ico.org.uk.
13. CHILDREN'S PRIVACY
Daybreak Labs Products are not directed to children under 16. We do not knowingly collect personal information from anyone under 16 without verifiable consent from a parent or legal guardian. This commitment satisfies both:
- the US Children's Online Privacy Protection Act (COPPA), which establishes a 13-year-old floor, and
- Article 8 GDPR, which establishes a 16-year-old floor for the use of consent as a lawful basis for "information society services" offered directly to a child, subject to member-state derogation down to 13.
If you are a parent or legal guardian and you believe that we have
collected personal information from your child under 16, please email
info@daybreaklabs.studio. We will delete the information
promptly upon verification.
14. CHANGES TO THIS PRIVACY POLICY
This Privacy Policy is a living document. The protocol for changes mirrors the modifications protocol in Master §22.
- Non-material changes (typographical corrections,
clarifications, updated references, formatting) take effect upon posting
at
daybreaklabs.studio/privacy, with the "Last updated" date refreshed accordingly. Your continued use of any Daybreak Labs Product after a non-material change constitutes your acceptance of the updated Privacy Policy. - Material changes, changes that materially expand the categories of personal information we collect, materially expand the purposes for which we use it, materially reduce your rights, or change the categories of subprocessors with whom we share it, take effect on the date stated in the change notice. Before a material change takes effect, we will: (a) post the updated Privacy Policy at the canonical URL; (b) email the address you have provided to us (if any); (c) display an in-product or in-website notice; and (d) where the change materially reduces your rights, give you at least 30 days advance notice before the change takes effect, during which you may stop using the affected Product.
The "Last updated" date at the top of this Privacy Policy identifies
the most recent version. Earlier versions are preserved in the public
CHANGELOG at daybreaklabs.studio/changelog so you can
compare. Product-specific privacy detail (categories of data, retention,
subprocessor mapping, AI training commitments) lives in the §S.13 of
each Product's Schedule and is versioned with that Schedule.
15. CONTACT
Questions about this Privacy Policy, requests to exercise your rights, complaints, or any other privacy-related communications should be sent to:
Daybreak Labs LLC Attn: Privacy 300 State Route 313,
Cambridge, NY 12816 Email:
info@daybreaklabs.studio
For everything else (Product support, billing, partnerships, press), see the Product-specific contact information in the applicable Schedule.
We aim to acknowledge privacy emails within five business days. If something here is unclear, email us, we would rather answer the question than have you guess.
Daybreak Labs LLC | Privacy Policy v1.3 | Effective: September 3, 2026 | Last updated September 3, 2026
This Privacy Policy is read together with the Daybreak Labs
Master Terms of Use v1.1 (daybreaklabs.studio/terms) and
the applicable Product Schedule (each Schedule's §S.13 contains the
Product-specific privacy notes). The maintained subprocessor list lives
at daybreaklabs.studio/subprocessors. See
daybreaklabs.studio/privacy for the canonical current
version of this Privacy Policy.