DayGraft is built by a solo indie developer trading as JS Digital, for UK subcontractors who need a straightforward way to log work, keep evidence, and get paid correctly. This policy explains what data the app collects, why, who it's shared with, and the choices you have. It's written in plain English on purpose — if anything's unclear, email privacy@daygraft.app and ask.
Contents
1. Who we are
DayGraft is developed and operated by JS Digital (Jevgenij Savel), an independent developer based in the UK. JS Digital is the "data controller" for the personal data described in this policy — the party responsible for deciding how and why your data is processed.
2. What data we collect
DayGraft is designed to work fully offline on your device. An account is optional and exists only to back up your data and let you use DayGraft on more than one device. Here's what we collect at each level:
Account data (only if you sign in)
- Your email address, via Sign in with Apple or Sign in with Google
- A unique account identifier generated by our authentication provider
- Sign-in timestamps, for security purposes
Apple and Google may offer you the option to hide your real email behind a relay address ("Hide My Email"). We store whatever address you choose to share.
Content you create in the app
- Profile details: name, trade, UTR (Unique Taxpayer Reference), phone number, CIS deduction rate — used only to populate your statements
- Work records: contractors, sites, days worked, rates, hours, overtime, materials, notes
- Home postcode and location: if you use automatic mileage, we store your home postcode and its approximate coordinates, plus site postcodes/coordinates, to calculate driving distance between them for HMRC mileage claims
- Mileage records: distances logged per day, used to estimate your tax-deductible travel allowance
- Evidence photos: images you attach as proof of work or receipts — including any signed daywork sheets or receipts you choose to photograph
- Payment records: amounts you log as received, and the dates
- Expense records: business expenses and receipt photos you log for your own tax purposes
We do not ask for or store your National Insurance number, bank details, or full date of birth. Your UTR and CIS rate are used only to calculate and display figures within your own statements — we never submit anything to HMRC on your behalf.
Technical & usage data
- Device type, operating system, and app version, for crash diagnostics and support
- General usage patterns (e.g. which features are used), to help us improve the app
- Approximate location (country/region) inferred from your network connection, if analytics is enabled — this is separate from, and never as precise as, the home/site postcodes you choose to enter for mileage, described above
We don't access your device's GPS location. Home and site locations used for mileage come only from postcodes you type in yourself.
3. How we use your data
| We use it to | Which data |
|---|---|
| Generate your weekly statements and reports | Profile, work records, materials |
| Back up your data and sync it across your devices | Account data, all content you create |
| Calculate driving distance for your mileage allowance | Home/site postcodes and coordinates |
| Let you download evidence and export CSV records | Evidence photos, work & expense records |
| Provide customer support when you contact us | Account data, and content you choose to share with us |
| Fix bugs and crashes | Technical/crash data |
| Understand which features are useful, so we build the right things | Usage data (aggregated/anonymised where possible) |
| Process subscription payments | Purchase/subscription status — not your card details, which Apple/Google handle directly |
We do not sell your data. We do not use your work records, photos, or financial details to serve you advertising, and DayGraft does not currently show ads.
4. Our legal basis for processing
Under UK GDPR, we rely on the following legal bases:
- Contract — processing needed to provide the app's core functionality you've asked for (e.g. generating a statement, syncing your data)
- Legitimate interests — improving the app, diagnosing crashes, and preventing fraud or abuse, balanced against your right to privacy
- Consent — for optional features such as analytics or marketing communications, which you can decline or withdraw at any time
5. Who we share data with
We use a small number of trusted service providers ("subprocessors") to run DayGraft. The table below lists everyone who may process your data on our behalf. If we add another, we'll list it here and update the date at the top of this page.
| Provider | Purpose | What they see |
|---|---|---|
| SupabaseActive | Database, authentication, and encrypted file storage for account backup/sync | Account data, all synced content, evidence photos |
| CloudflareActive | Website and app hosting, content delivery | Standard web request data (IP address, browser type) |
| Google / AppleActive | Sign-in authentication | Email address, sign-in identifier |
| postcodes.ioActive | Converts UK postcodes to coordinates, for mileage calculation | Postcodes you enter (home and site) — no account or identifying data |
| OSRM (Open Source Routing Machine)Active | Calculates driving distance between two points, for mileage | Coordinates derived from postcodes you enter — no account or identifying data |
| Apple App Store / Google PlayActive | App distribution and in-app purchase processing | Purchase/subscription status; payment details are handled entirely by Apple/Google, never by us |
| RevenueCatActive | Subscription management across platforms | Subscription status, purchase events — not full payment card details |
| PostHogActive | Product analytics, to understand feature usage | Usage events, device/app version — configured to avoid capturing your work content or photos |
| SentryActive | Crash and error reporting | Technical error data, device information — configured to exclude personal content where possible |
Each provider is contractually restricted to using your data only to provide their service to us, not for their own purposes. We do not share your data with data brokers, advertisers, or any party for marketing purposes.
We may also disclose data where required by law, to protect our legal rights, or in connection with a business transfer (e.g. if DayGraft is acquired) — in which case we'd notify you.
6. Where your data is stored
Our infrastructure providers (Supabase, Cloudflare) may process and store data in the UK, EU, or other regions with adequate data protection standards, including the United States under approved transfer mechanisms such as Standard Contractual Clauses. Evidence photos and work records are stored in access-controlled databases; only you can access your own data, enforced at the database level (Row Level Security), not just in the app's interface.
7. How long we keep it
- While your account is active: we keep your data for as long as you use DayGraft, so your records remain available to you
- Free tier evidence photos: retained for 90 days from upload, after which older photos may be automatically removed from cloud backup (your local device copy is unaffected unless you also delete it there)
- Pro tier evidence photos: retained for as long as your account is active, as part of your evidence archive
- After account deletion: we delete your account data within 30 days, except where we're legally required to retain limited records for longer (e.g. financial transaction logs for tax/audit purposes)
You can request deletion of your account and all associated data at any time — see your rights below.
8. Your rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data (most of this you can edit directly in the app)
- Delete your account and data ("right to be forgotten")
- Export your data in a portable format — DayGraft's built-in CSV export covers this for your work records
- Object to or restrict certain processing, such as analytics
- Withdraw consent at any time for anything based on consent
- Complain to the UK Information Commissioner's Office (ICO) at ico.org.uk if you believe we've mishandled your data
To exercise any of these rights, email privacy@daygraft.app. We'll respond within one month, as required by law.
9. Security
We take reasonable technical and organisational measures to protect your data, including encryption of data in transit (HTTPS/TLS), database-level access controls that restrict every user to their own data, and secure authentication via Apple/Google rather than passwords we'd have to store ourselves. No system is perfectly secure, and we can't guarantee absolute security — but we treat your financial and work records with the same care we'd want for our own.
10. Children's privacy
DayGraft is intended for self-employed construction subcontractors, who under UK law and CIS scheme rules must be old enough to work and hold a UTR. DayGraft is not directed at, and we do not knowingly collect data from, children under 18. If we become aware that we've inadvertently collected data from a child, we'll delete it promptly.
11. Cookies & local storage
The DayGraft app itself stores data locally on your device (using browser local storage and IndexedDB) so it works offline — this is core to how the app functions, not a tracking mechanism. Our marketing website (daygraft.app) may use minimal cookies for essential site functionality. We don't use third-party advertising cookies or cross-site tracking.
12. Changes to this policy
As DayGraft changes — if we add a feature that handles data differently, or start using a new service provider — we'll update this policy to reflect what's actually live, and update the "last updated" date at the top. For significant changes, we'll aim to notify you in-app or by email where we have one on file.
Contact us
Questions, requests, or concerns about your data:
JS Digital · United Kingdom