1. Who this policy covers
This Privacy Policy applies to the Daymat mobile app and the services that support it. “Daymat,” “we,” and “us” refer to the Daymat app operator. Questions or privacy requests can be sent to support@daymat.app.
2. Information we handle
Account and profile information
We collect your email address, name, sign-in provider, and account identifiers. Your profile can include age or date of birth, sex, height, weight, yoga experience, goals, schedule, preferences, and timezone.
Health and fitness information
You may provide physical limitations, health conditions, practice history, duration, estimated calories, and related fitness information. Daymat uses this information to personalize general wellness content and avoid unsuitable suggestions. Daymat is not a medical service and does not diagnose or treat conditions.
Health Connect and Apple Health
Health sync is optional. If you enable it, Daymat requests write access to exercise or workout records and calories or active energy so it can export completed yoga sessions. Daymat does not read existing Health Connect records. Health platform data is not used for advertising, sold, or shared with data brokers. You can disable sync in Daymat and manage or revoke permissions in Health Connect or Apple Health.
Practice and coach activity
We store enrolled plans, completed and scheduled sessions, favorites, feedback, coach chats, safety consent records, usage limits, and information needed to generate or adapt a plan. Coach messages may include information you choose to type about how you feel.
Voice controls
With permission, Daymat uses the microphone for short practice commands such as pause, next, and coach. Speech recognition is provided by the device’s native recognition service and may use the platform provider’s network service, depending on device settings. Daymat does not store raw microphone audio. Recognized commands may be used in the app to perform the requested action.
Device, notification, analytics, and advertising information
We handle push notification tokens and preferences, app version, platform, session identifiers, approximate country derived from device locale, screens viewed, feature interactions, API timing, and diagnostic details. Google Mobile Ads may collect device or advertising identifiers, ad interactions, diagnostics, and approximate location according to your device and consent settings.
Connected services
If enabled by you, Google Sign-In or Strava may provide account identifiers and authorization tokens. Strava connection tokens are encrypted at rest and are used only for the connection and sharing actions you request. You can disconnect Strava in settings.
3. How we use information
- Provide sign-in, profiles, plans, practice tracking, and support.
- Personalize general wellness guidance and apply safety rules.
- Process coach requests and generate plan content.
- Send notifications you have enabled.
- Measure reliability, prevent abuse, and improve the app.
- Show and measure ads where advertising is enabled.
- Meet legal, security, and compliance obligations.
4. When information is shared
We share information only as needed with service providers that help operate Daymat, such as infrastructure and database providers, OpenAI for AI coach or plan requests, Google for sign-in, notifications, advertising, and Android services, Apple for iOS services, and Strava when you connect it. Providers process data under their own terms and our applicable arrangements.
We may also disclose information when required by law, to protect users and the service, or as part of a business reorganization with appropriate safeguards. We do not sell health information or use Health Connect or Apple Health data for advertising.
5. Retention
Account and practice data is retained while your account is active and deleted when you delete the account, subject to the limited exceptions below. Coach message content is normally retained for up to 90 days. Authentication and verification tokens expire or are revoked according to their security purpose.
De-identified analytics events and shared, non-identifying generated program content may remain for service measurement and to avoid disrupting content used by others. Records required for fraud prevention, legal compliance, or resolving disputes may be retained only as long as necessary. Deleted information may remain temporarily in protected backups until those backups are overwritten.
6. Your choices and rights
You can edit profile information, disable notifications, voice control, health sync, or Strava, and revoke system permissions in device settings. You can permanently delete your account in Daymat under Settings → Delete account. If you cannot sign in, use the public deletion request page.
Depending on where you live, you may also have rights to access, correct, delete, restrict, or receive a copy of personal information, or object to certain processing. Email support@daymat.app to make a request. We may need to verify that you control the account.
7. Security and international processing
We use access controls, encrypted network connections, password hashing, and encryption for sensitive connection secrets. No service can guarantee absolute security. Service providers may process data in countries other than yours, with safeguards required by applicable law.
8. Children and changes
Daymat is not directed to children under 13, and we do not knowingly collect personal information from them. If local law requires parental consent at a higher age, users must have that consent. Contact us if you believe a child provided personal information.
We may update this policy as the app changes. We will post the new date here and provide additional notice when a material change requires it.