Privacy Policy
Effective Date: August 5, 2026
Key points
- What Daytical is. A digital teacher planner and micro LMS for K-12 educators: yearly, unit, and lesson planning, worksheets and forms, course rosters and checklists, daily and weekly planning rituals, an AI agent, and an optional Google Drive integration.
- What we collect from teachers. Name, email address, profile preferences (locale, time zone, working rhythm), the content you create (plans, lessons, worksheets, tasks), technical logs, and billing records.
- What student data we collect and how. We collect student directory data: first and last name, and email address. Student data collection is fully under your control, either by you explicitly entering or importing it or by collecting the data as part of the lesson rooms you create and provide to students.
- What protection measures we implement to protect student data. Daytical is built so it requires no or as least amount of student data as possible. If you use Daytical only for planning and never use lesson rooms, we require no data at all. we provide you with all the controls to manage student data in our service. We don’t collect any data, you can’t control via our interface directly. You can enter, import, alter, review, delete, and export all the data, both individually and in bulk. We don’t disclose student data to any of our sub-processors listed below except Railway, which provides us infrastructure to host our database. We minimize collection of telemetry data from students’ sessions and they are used solely to detect failures, abuse or breach attempts.
- Sharing. We share data only with the sub-processors listed in §13, and only to the extent each of them needs to run the service. We do not sell personal data and do not share it for targeted advertising.
- Your rights. You can export everything in your account and request deletion at any time, directly from your settings. We claim no rights on any of the content you import or create in Daytical.
- Contact. info@daytical.com.
1. Who We Are and What This Covers
Daytical (“we”, “us”, “our”) is a digital teacher planner and micro learning management system (LMS) for K-12 educators. It helps teachers prepare yearly, unit, and lesson plans; build worksheets and forms; maintain course rosters and gradebook-style checklists; run daily and weekly planning rituals; and, optionally, connect Google Drive. Daytical is operated from the Czech Republic, in the European Union; our full legal details appear in §16.
This policy applies to the Daytical web application and to daytical.com. It explains what we collect, why we collect it, who we share it with, how long we keep it, and the rights you have.
Our practices are designed to meet the requirements of the EU GDPR; the US federal and state privacy laws that apply to us (including CCPA/CPRA, COPPA and, where relevant, FERPA and state student-privacy laws); PIPEDA and Quebec’s Law 25 in Canada; and the Australian Privacy Act 1988 and its Australian Privacy Principles. Region-specific disclosures appear in §15.
Questions, requests or complaints: info@daytical.com.
2. Our Two Roles: Teacher Data and Student Data
Daytical processes two distinct categories of data, and our legal role differs for each.
- Teacher and account data — we are the controller. Your account details, your planning content, your billing records, and your use of the platform. We determine why and how this data is processed, within the boundaries of this policy.
- Student data — we are the processor. The student records you (or your school) enter or import, and the classwork collected in lessons you run. Where you use Daytical in the course of your work for a school, the school is normally the controller and you act on its behalf; where you act on your own account, you are. In either case we process student data only on the controller’s instructions — expressed through the product’s controls — and only to provide the service. Where a school or district uses Daytical under an agreement with us, we act in US terms as a school official with a legitimate educational interest under FERPA and as a service provider under CCPA/CPRA.
For schools and districts that require one, we offer a Data Processing Agreement (DPA) covering the processor relationship, including standard contractual clauses for international transfers. Request one at info@daytical.com.
3. What We Collect from Teachers
3.1 Information you provide
| Data | Purpose | Legal basis (GDPR) |
|---|---|---|
| Name, email address, profile picture | Create and identify your account, address you in the product and in emails | Contract |
| Locale, time zone, first day of week, ritual schedules and checklists | Present the product in your language, time zone and working rhythm | Contract |
| Access PIN and backup PIN (optional) | Quick re-entry to the app on a shared or classroom device | Contract |
| Your content — yearly/unit/lesson plans, homework, worksheets, forms, tasks, notes, checklists, school-year and timetable setup | The core service we provide to you | Contract |
| Files you upload as teaching assets (images, documents) | Embed them in your plans, worksheets and materials — see §9 on how they are served | Contract |
| Billing details | Process payment and issue invoices | Contract, Legal obligation |
| Support messages, bug reports and feature requests | Respond to you and resolve what you report | Legitimate interest |
We authenticate you with a one-time code sent to your email address or with Google sign-in. We do not store a reusable account password.
3.2 Information collected automatically
| Data | Purpose | Legal basis (GDPR) |
|---|---|---|
| IP address and user agent, recorded with each session | Keep you signed in, detect suspicious sign-in activity | Legitimate interest, Contract |
| Application and error logs | Keep the service running, diagnose faults | Legitimate interest |
| Feature usage (which parts of the product you use) | Guide product improvement | Legitimate interest |
| AI agent usage counters (tokens, requests) | Meter your plan’s AI allowance and prevent abuse | Contract |
We do not operate advertising or cross-site tracking technology, and we do not build advertising profiles.
3.3 Information from third parties
- Google, if you connect your Google account: your
Google profile (name, email address, profile picture) on sign-in, and —
only for the scopes you individually grant — the Google Drive files
you explicitly select, and “other contacts” suggestions used to invite
colleagues.
Each scope is granted separately, is optional, and can be revoked at any
time in your Google Account settings or by disconnecting the integration
in Settings → Integrations. Daytical asks Google only for
the
drive.filepermission, which grants access to individual files at the moment you pick them in Google’s own file picker — it cannot list, browse or read anything else in your Drive. Data obtained from Google Workspace APIs is used only to provide the feature you enabled — never for advertising, and never sold. - Our billing provider, which confirms your subscription status and returns invoice records.
4. Student Data: Scope and Strict Limits
Students cannot create accounts. There is no student sign-up, and a student never uses Daytical outside a lesson their teacher is running. Students appear in Daytical in two ways only:
- as roster records created by their teacher — entered manually or imported from a CSV file; and
- as participants in lesson sessions their teacher opens, controls, and closes. To join, a student enters a short code the teacher shares in class and picks their name from the roster — or, where the teacher has enabled it, types their own name. When the teacher closes the session, the code stops working.
A student’s roster record is limited to:
- First name and last name — so that a teacher can attribute classwork and checklist entries to the correct student.
- Email address — used solely as a unique identifier to prevent the same student from being recorded twice on a roster. We recommend you to use school-provisioned emails instead of personal ones.
Beyond the roster record, we store the classwork a teacher collects through Daytical — a student’s responses to a worksheet or form run in a lesson session. You may also create custom student checklists to track additional data tight to a roster. For example attendance or grades.
What we never do with student data:
- We never sell it, rent it, or share it for targeted advertising or any commercial purpose of our own.
- We never give AI models access to it. Our agent is built so that student names and contact details are excluded from what the model can read; it may see that a course has, for example, 24 students, but never who they are. Text you yourself write into a prompt or your planning content is transmitted as written (see §6) — which is why we ask you not to put student personal data there.
- We never train models on it — ours or anyone else’s.
- We never email students — no marketing, no notifications, no transactional mail. Students receive no communications from us of any kind.
- We never disclose it to the sub-processors listed in §13, with a single, necessary exception: our infrastructure hosting provider stores it as part of our database, as the host of that database, and makes no independent use of it. No other sub-processor receives student data.
- We never use it to build profiles for any purpose other than delivering the service the teacher requested.
Authorisation. We collect student data only from, and at the direction of, teachers and schools — never from students themselves, beyond the name a student picks or types to join their teacher’s lesson.
Children under 13 (COPPA). Where a student is under 13, we rely on the school’s authorisation in place of individual parental consent, as the FTC’s COPPA guidance permits for educational technology used for a school-authorised educational purpose. We do not ask teachers to obtain parental consent on our behalf — the obligations COPPA places on us stay with us. We give the school notice of what we collect and how it is used (this policy, and our DPA on request), we use student data solely for the educational purpose the school authorised, and we never use it for advertising, profiling, or any commercial purpose of our own, as set out above. Daytical is not for collecting data about children under 13 outside a school context. If you are not acting under a school’s authorisation, do not enter data about a student under 13.
Everything else. The school — or, where you act on your own account, you — is the controller, and is responsible for having a lawful basis for entering a student’s data and for any school authorisation or parental consent required by the GDPR, FERPA, state student-privacy laws, PIPEDA, or the Australian Privacy Act. Where the law that applies to your school requires a written agreement with us before student data may be entered, request our DPA at info@daytical.com.
Parent and guardian rights. Parents and guardians can exercise their child’s rights — access, correction, deletion, and refusal of further collection — through the child’s teacher or school, who can review, edit, export, and delete student records directly in Daytical using self-service controls, at any time and without our involvement. If a school needs our assistance, we will provide it on request at info@daytical.com. Because we act as processor, we refer any request that reaches us directly to the responsible teacher or school and assist them in fulfilling it; where the law requires us to act on a request ourselves, we will.
5. How We Use Information
- Operate the service — run your planner, courses, plans, worksheets, and lesson sessions. (Contract)
- Authenticate you — one-time email codes, Google sign-in, session management. (Contract)
- Provide AI assistance — see §6. (Contract)
- Process billing — subscriptions, invoices, AI credit packs, trial handling, referral credits. (Contract, Legal obligation)
- Provide support — answer questions, triage bug reports and feature requests. (Legitimate interest)
- Keep the platform secure — detect unauthorised access, abuse, and fraud. (Legitimate interest)
- Improve the product — understand which features are used, resolve what breaks. (Legitimate interest)
- Comply with the law — tax and accounting records, responding to lawful requests. (Legal obligation)
- Send optional product news — only if you opt in; every such email includes an opt-out. (Consent)
Student data is used solely as described in §4 and for none of the other purposes above.
Where we rely on legitimate interest, we have weighed that interest against your rights and privacy expectations, and you may object at any time (see §10).
6. Artificial Intelligence Features
Daytical includes an AI agent that helps teachers draft plans, worksheets, and other teaching material.
- What is sent to the model. Your prompts, the conversation history, and the planning content the agent needs in order to respond — your plans, units, lessons, homework, worksheets, standards, and tasks. Where you enable it, the agent can also search the web, generate images, and read Google Drive files you explicitly select; images it generates are stored with your uploaded assets (see §9).
- What is not sent. Student roster records — names, email addresses, identifiers and profile pictures from your rosters — and student classwork. The agent can see aggregate figures such as a roster count, but not the students themselves.
- Content you enter is sent. If you type personal information into the agent yourself, that text is transmitted to the AI provider like any other prompt. Please do not paste student or third-party personal data into it.
- Providers. We access AI models only through commercial APIs — the OpenAI API, the Anthropic API, and Google Cloud’s Vertex AI / Agent Platform (see §13). Under all three providers’ business terms, your content is not used to train their models, and they retain it for up to 30 days for abuse monitoring and service operation — longer only where the law requires it, or where content is flagged as violating a provider’s usage policy.
- Human control. AI output is a draft and may be inaccurate. Nothing the agent produces is applied to grades, records, or decisions about a student without a teacher reviewing it and acting on it.
- No automated decision-making. Consistent with GDPR Article 22, Daytical makes no decision producing legal or similarly significant effects about you or a student by automated means alone, and does not carry out profiling for such purposes.
7. Cookies and Local Storage
We use only essential cookies. We do not use advertising or cross-site tracking cookies.
| Cookie | Purpose | Set by |
|---|---|---|
| Session cookie | Keeps you signed in | Daytical |
| Locale preference | Remembers your language before you sign in | Daytical |
| Referral identifier | When a colleague invites you with a referral link, stores the referral ID so that the credit can be attributed to both of you after sign-up | Daytical |
| Support and feedback identity cookies | Our support chat, feedback board and bug-report widgets set their own cookies to recognise you across sessions | Intercom, Canny, Ybug |
Because these cookies are strictly necessary for the service, or set to fulfil a preference you have expressed, they do not require consent under the ePrivacy rules in most jurisdictions. You may still block or clear them in your browser, although blocking the session cookie will prevent you from signing in.
8. Retention
| Data | Retention |
|---|---|
| Account and content data | Kept while your account is active |
| Deleted accounts | Deletion is scheduled with a 30-day grace period during which you can cancel it; at the end of that window the data is erased immediately from our live systems |
| Trial workspaces | If you do not subscribe after your trial ends, your workspace and its data — student records included — are deleted |
| Database backups | Rolling 30 days, then overwritten — data from a deleted account is therefore gone from backups no later than 60 days after you request deletion |
| Technical and application logs | Up to 30 days |
| Billing and invoicing records | Up to 10 years, as required by accounting and tax law |
| Support conversations, bug reports and feature requests | While your account is active and for up to 2 years afterwards or 10 years in cases where required by law (e.g. refund requests support tickets), so that the history of a reported issue can be traced. |
| Student roster records | Kept for as long as the teacher keeps them; deleted immediately when the teacher deletes the student, the course, or their account (subject to the same backup window) |
If you need data erased sooner than the schedule above provides, write to info@daytical.com and we will process the request manually.
9. Security
- Encryption — TLS for all data in transit; encryption at rest for our database and backups.
- Passwordless authentication — you sign in with a one-time email code or with Google, so there is no reusable account password that could be stolen from us.
- Access control — internal access to production data is limited to staff who need it for support or operations, and is logged. Support staff may, with authorisation, temporarily act on your behalf in the app to diagnose a problem; such sessions are recorded as impersonation sessions and are attributable to the individual staff member.
- Isolation — every request is scoped to your own organisation membership, so one teacher’s data is not reachable from another account. The deliberate exception is files you upload or generate as teaching assets (images, documents): so that they can be embedded in your materials, they are served from public, unguessable web addresses — do not upload anything you would not share with someone who has the address.
- Sub-processor diligence — we keep the list of providers in §13 short, we choose providers that publish GDPR-compliant data processing terms, and we give each of them only the data it needs for the purpose listed there.
No system connected to the internet is completely secure, and we cannot guarantee absolute security. You can help by keeping access to your email account and devices secure.
Breach notification. If a breach affects your personal data, we will notify the competent supervisory authority within 72 hours of becoming aware of it where the GDPR requires, notify affected users without undue delay where the risk to them is high, notify affected individuals and the Australian OAIC where a breach is likely to result in serious harm, as the Notifiable Data Breaches scheme requires, and meet US state and Canadian notification requirements. Where we act as processor for student data, we notify the school or teacher without undue delay so that they can meet their own obligations.
10. Your Rights
Wherever you live, you have the following rights:
- Access and portability. Export everything in your
account yourself, at any time, from Settings → Export
data. The export is a ZIP archive containing PDFs of your
plans, lessons, worksheets and forms, CSV files of your rosters and
checklists, and a
data.jsonwith the raw records in machine-readable form. - Correction. Edit your profile and your content directly in the app.
- Deletion. Request account deletion yourself from Settings. Deletion runs after the 30-day grace period described in §8; you can cancel it during that window.
- Objection and restriction. Object to processing based on legitimate interest, or ask us to restrict processing, by writing to us.
- Withdrawal of consent. Where processing rests on consent, withdraw it at any time; this does not affect processing that has already taken place.
- Marketing opt-out. Unsubscribe from any optional product email.
- Complaint. Lodge a complaint with your data protection authority — see §15.
To exercise anything not available as a self-service control, email info@daytical.com. We verify your identity before acting, and we respond within 30 days (extendable by a further 60 days for complex requests, in which case we will inform you). Exercising your rights is free of charge and will never result in a reduced level of service.
Appeals. If we refuse a request, our response will explain why and how to appeal. To appeal, reply to that response or write to info@daytical.com with the subject “Privacy appeal”; we will respond within 45 days. If we deny your appeal, you may contact your state attorney general or supervisory authority.
11. Sharing and Disclosure
We do not sell personal data, and we do not share personal data for cross-context behavioural advertising. We disclose personal data only:
- to the sub-processors listed in §13, each under contract, only to the extent needed to operate the service, and — with the single exception of the infrastructure host that stores our database — never including student data;
- when the law requires it, in response to a valid, legally binding request. We assess every request, refuse overbroad ones, and notify you unless legally prohibited from doing so;
- to protect rights and safety, where necessary to prevent fraud, abuse or imminent harm;
- in a business transfer — if we are involved in a merger, acquisition, or asset sale, data may transfer to the acquirer. We will notify you before your data becomes subject to a different privacy policy, and the acquirer remains bound by the commitments in §4 with respect to student data;
- on your explicit instruction, for anything else.
12. International Transfers
We are established in the Czech Republic. Our application and database are hosted in the European Union. Our sub-processors process personal data in the European Union and the United States.
For personal data originating in the EEA, we rely on the European Commission’s Standard Contractual Clauses, supplemented by our own technical and organisational measures, wherever a provider is not covered by an adequacy decision (including the EU–US Data Privacy Framework, where a provider is certified). For Canadian and Australian users, we remain accountable for personal data we transfer to a service provider abroad and require comparable protection by contract, as PIPEDA and Australian Privacy Principle 8 require. Copies of the relevant transfer mechanisms are available on request.
13. Sub-Processors
We keep this list short and give each provider only the data it needs for the purpose listed. With a single exception, none of them receives student data: our infrastructure hosting provider stores our database — student records included — on our behalf, with no independent use of it. Every other provider processes teacher/account data only, for the purpose listed.
| Sub-processor | Purpose | Data it receives |
|---|---|---|
| Railway | Application and database hosting | All account and content data stored in our database, student records included (as infrastructure host; no independent use) |
| Google Cloud Platform (Cloud Storage, Vertex AI / Agent Platform) | Storage of uploaded and AI-generated files; AI model access; potentially further infrastructure hosting | Files you upload or generate; agent prompts and planning content. See §6 |
| Google (Google Workspace APIs) | Google sign-in, Drive file access, contact suggestions for referrals | Your Google profile and the data covered by the scopes you individually grant |
| OpenAI | AI agent models | Prompts and planning content you send to the agent. See §6 |
| Anthropic | AI agent models | Prompts and planning content you send to the agent. See §6 |
| Autumn | Subscription, plan, credit and metering management | Account identifiers, plan and usage counters |
| Stripe | Payment processing | Billing identifiers and payment details. Full card details are handled by Stripe and never stored on our servers |
| Resend | Transactional email delivery (sign-in codes, email verification, account-deletion notices, referral invitations) | Recipient name and email address, message content. Teachers and their invited colleagues only |
| Intercom | Customer support messaging | Your user ID, name, email and support conversations |
| Canny | Feature request and feedback board | Your user ID, name and email (you may also post anonymously; Canny still receives your identity to grant you access) |
| Ybug | Bug reporting from inside the app | Your user ID, name, email, and the screenshot/session details attached to a report you submit |
| Linear | Tracking bug reports and feature requests through to a fix | Your name and email, attached to the issue you reported |
| Better Stack | Logging, telemetry and uptime monitoring | Application logs, which may include IP address, user agent, user ID and request metadata |
| Plausible | Website analytics | Visits to daytical.com. Cookie-less, aggregate analytics; no cross-site tracking and no advertising profiles |
We keep this list current. To be notified by email before we add a new sub-processor, write to info@daytical.com and ask to be added to the notification list.
14. Changes to This Policy
We may update this policy as the product, the law, or our providers change. If a change is material, we will notify you by email or by a prominent in-app notice before it takes effect. The current version is always available on our website, and previous versions are available on request.
One commitment sits outside this flexibility: we will not materially weaken the student-data commitments in §4 with respect to previously collected student data without the consent of the teacher or school that controls it.
15. Regional Disclosures
15.1 European Union
- Controller: Daytical — our full legal identification appears in §16. Contact: info@daytical.com.
- Lead supervisory authority: the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů, uoou.gov.cz). You may also complain to the authority where you live or work.
- We are established in the EU, so no Article 27 representative is required.
- We have not appointed a Data Protection Officer, as we do not meet the Article 37 criteria. Privacy matters are handled directly by senior management at info@daytical.com.
- We maintain a data protection impact assessment covering our student-data and AI-agent processing; supervisory authorities may request it, and schools may review its relevant conclusions on request.
- Your GDPR rights are those listed in §10, which we extend to all users.
15.2 United States
California (CCPA/CPRA) and other state privacy laws. In the past 12 months we have collected the categories below. We have not sold personal information and have not shared it for cross-context behavioural advertising, and we do not do so today — including the personal information of anyone under 16.
| Category of personal information | Sources | Business purpose | Disclosed to | Retention |
|---|---|---|---|---|
| Identifiers (name, email, user ID, IP address) | You, automatic collection, Google sign-in | Account creation, authentication, service delivery, security, support | Hosting, email, support, feedback, logging and billing sub-processors | Until account deletion (see §8) |
| Visual information (your profile picture) | You, Google sign-in | Identifying an account holder in the product; helping students and teachers recognise the right person on a roster | Hosting sub-processor | Until account deletion; student pictures until deleted by the teacher |
| Customer records (billing details) | You, payment provider | Subscriptions, invoicing, fraud prevention | Autumn, Stripe | 10 years (tax law) |
| Commercial information (plan, subscription and credit history) | You, automatic collection | Billing, entitlement, support | Autumn, Stripe | Until account deletion; billing records 10 years |
| Internet/network activity (feature usage, application logs, user agent) | Automatic collection | Security, diagnostics, product improvement | Hosting, logging sub-processors | Up to 30 days for logs |
| Geolocation (coarse, inferred from IP) | Automatic collection | Security and regional/tax settings | Hosting, logging sub-processors | Up to 30 days |
| Professional information (that you are an educator, your school-year and timetable setup) | You | Service delivery | Hosting sub-processor | Until account deletion |
| Your content (plans, lessons, worksheets, tasks) | You | Service delivery, AI assistance you request | Hosting and AI sub-processors | Until account deletion |
| Student data (roster: first name, last name, email address; classwork collected by the teacher) | Teacher input, CSV import, classwork in teacher-run lessons | Attributing classwork and checklist entries to the correct student | Infrastructure hosting sub-processor only (storage on our behalf; no independent use) | Until deleted by the teacher |
Sensitive personal information. We do not use or disclose sensitive personal information for any purpose other than providing the service you requested, so the CPRA right to limit its use does not arise; you may nonetheless write to us with any concern. We do not use personal information for automated decision-making or profiling in furtherance of decisions producing legal or similarly significant effects.
Your US state rights — to know, access, correct, delete, port, opt out of sale/sharing and targeted advertising, appeal a refusal, and be free from discrimination for exercising them — are covered by §10. You may use an authorised agent; we will verify their authority.
Global Privacy Control. We honour the GPC browser signal. Because we do not sell or share personal information for targeted advertising, there is nothing for it to opt you out of — but we recognise and respect it.
Students (COPPA, FERPA, and state student-privacy laws). Students do not create accounts and receive no communications from us. The only information a student ever enters directly is the name they pick or type to join a lesson their teacher runs; everything else about a student comes from the teacher or school, and all of it is collected for the school’s educational purpose, at the teacher’s direction, and handled as described in §4 — never for any commercial purpose of our own. Where a school or district uses Daytical under an agreement with us, we act as a school official under FERPA (34 CFR § 99.31(a)(1)) under the school’s direct control, and as a school service provider under state student-privacy laws such as California’s SOPIPA: we do not use student data for targeted advertising, do not create a non-educational profile of a student, do not sell student data, and delete it on the school’s instruction.
15.3 Canada
We comply with PIPEDA and, for Quebec residents, Law 25. You may access and correct your personal information as described in §10, and complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca) or, in Quebec, the Commission d’accès à l’information du Québec. Personal information may be stored or processed outside Canada, including in the European Union and the United States, where it is subject to the laws of those jurisdictions; we remain accountable for it and protect it by contract. Our privacy contact for Canadian and Quebec purposes is info@daytical.com.
15.4 Australia
We comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. You may request access to and correction of your personal information (APP 12 and 13) as described in §10, and complain to us first at info@daytical.com; if you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (oaic.gov.au). Personal information is disclosed to overseas recipients — the sub-processors listed in §13, located in the European Union and the United States — and we take reasonable steps under APP 8 to ensure they handle it consistently with the APPs. We do not adopt or use government-related identifiers.
16. Contact Us
- Email: info@daytical.com
- Website: https://daytical.com
- Operator: Doubek Industries s. r. o., Husitská 73, 417 41 Krupka, Czech Republic · Reg. No. 09188690
We aim to respond to privacy enquiries within 3–5 business days, and to formal rights requests within the statutory deadlines set out in §10.