Legal

Privacy Policy

Last updated: 18 August 2026 · Effective for daygraft.app and the DayGraft app

DayGraft is built by a solo indie developer trading as JS Digital, for UK subcontractors who need a straightforward way to log work, keep evidence, and get paid correctly. This policy explains what data the app collects, why, who it's shared with, and the choices you have. It's written in plain English on purpose — if anything's unclear, email privacy@daygraft.app and ask.

Contents

  1. Who we are
  2. What data we collect
  3. How we use your data
  4. Our legal basis for processing
  5. Who we share data with
  6. Where your data is stored
  7. How long we keep it
  8. Your rights
  9. Security
  10. Children's privacy
  11. Cookies & local storage
  12. Changes to this policy
  13. Contact us

1. Who we are

DayGraft is developed and operated by JS Digital (Jevgenij Savel), an independent developer based in the UK. JS Digital is the "data controller" for the personal data described in this policy — the party responsible for deciding how and why your data is processed.

2. What data we collect

DayGraft is designed to work fully offline on your device. An account is optional and exists only to back up your data and let you use DayGraft on more than one device. Here's what we collect at each level:

Account data (only if you sign in)

Apple and Google may offer you the option to hide your real email behind a relay address ("Hide My Email"). We store whatever address you choose to share.

Content you create in the app

We do not ask for or store your National Insurance number, bank details, or full date of birth. Your UTR and CIS rate are used only to calculate and display figures within your own statements — we never submit anything to HMRC on your behalf.

Technical & usage data

We don't access your device's GPS location. Home and site locations used for mileage come only from postcodes you type in yourself.

3. How we use your data

We use it toWhich data
Generate your weekly statements and reportsProfile, work records, materials
Back up your data and sync it across your devicesAccount data, all content you create
Calculate driving distance for your mileage allowanceHome/site postcodes and coordinates
Let you download evidence and export CSV recordsEvidence photos, work & expense records
Provide customer support when you contact usAccount data, and content you choose to share with us
Fix bugs and crashesTechnical/crash data
Understand which features are useful, so we build the right thingsUsage data (aggregated/anonymised where possible)
Process subscription paymentsPurchase/subscription status — not your card details, which Apple/Google handle directly

We do not sell your data. We do not use your work records, photos, or financial details to serve you advertising, and DayGraft does not currently show ads.

Under UK GDPR, we rely on the following legal bases:

5. Who we share data with

We use a small number of trusted service providers ("subprocessors") to run DayGraft. The table below lists everyone who may process your data on our behalf. If we add another, we'll list it here and update the date at the top of this page.

ProviderPurposeWhat they see
SupabaseActiveDatabase, authentication, and encrypted file storage for account backup/syncAccount data, all synced content, evidence photos
CloudflareActiveWebsite and app hosting, content deliveryStandard web request data (IP address, browser type)
Google / AppleActiveSign-in authenticationEmail address, sign-in identifier
postcodes.ioActiveConverts UK postcodes to coordinates, for mileage calculationPostcodes you enter (home and site) — no account or identifying data
OSRM (Open Source Routing Machine)ActiveCalculates driving distance between two points, for mileageCoordinates derived from postcodes you enter — no account or identifying data
Apple App Store / Google PlayActiveApp distribution and in-app purchase processingPurchase/subscription status; payment details are handled entirely by Apple/Google, never by us
RevenueCatActiveSubscription management across platformsSubscription status, purchase events — not full payment card details
PostHogActiveProduct analytics, to understand feature usageUsage events, device/app version — configured to avoid capturing your work content or photos
SentryActiveCrash and error reportingTechnical error data, device information — configured to exclude personal content where possible

Each provider is contractually restricted to using your data only to provide their service to us, not for their own purposes. We do not share your data with data brokers, advertisers, or any party for marketing purposes.

We may also disclose data where required by law, to protect our legal rights, or in connection with a business transfer (e.g. if DayGraft is acquired) — in which case we'd notify you.

6. Where your data is stored

Our infrastructure providers (Supabase, Cloudflare) may process and store data in the UK, EU, or other regions with adequate data protection standards, including the United States under approved transfer mechanisms such as Standard Contractual Clauses. Evidence photos and work records are stored in access-controlled databases; only you can access your own data, enforced at the database level (Row Level Security), not just in the app's interface.

7. How long we keep it

You can request deletion of your account and all associated data at any time — see your rights below.

8. Your rights

Under UK GDPR, you have the right to:

To exercise any of these rights, email privacy@daygraft.app. We'll respond within one month, as required by law.

9. Security

We take reasonable technical and organisational measures to protect your data, including encryption of data in transit (HTTPS/TLS), database-level access controls that restrict every user to their own data, and secure authentication via Apple/Google rather than passwords we'd have to store ourselves. No system is perfectly secure, and we can't guarantee absolute security — but we treat your financial and work records with the same care we'd want for our own.

10. Children's privacy

DayGraft is intended for self-employed construction subcontractors, who under UK law and CIS scheme rules must be old enough to work and hold a UTR. DayGraft is not directed at, and we do not knowingly collect data from, children under 18. If we become aware that we've inadvertently collected data from a child, we'll delete it promptly.

11. Cookies & local storage

The DayGraft app itself stores data locally on your device (using browser local storage and IndexedDB) so it works offline — this is core to how the app functions, not a tracking mechanism. Our marketing website (daygraft.app) may use minimal cookies for essential site functionality. We don't use third-party advertising cookies or cross-site tracking.

This policy is written to be accurate and genuinely useful, but it isn't a substitute for legal advice. If you have specific legal concerns, please consult a solicitor.

12. Changes to this policy

As DayGraft changes — if we add a feature that handles data differently, or start using a new service provider — we'll update this policy to reflect what's actually live, and update the "last updated" date at the top. For significant changes, we'll aim to notify you in-app or by email where we have one on file.

Contact us

Questions, requests, or concerns about your data:

privacy@daygraft.app

JS Digital · United Kingdom