Privacy Policy

Effective Date: August 5, 2026


Key points


1. Who We Are and What This Covers

Daytical (“we”, “us”, “our”) is a digital teacher planner and micro learning management system (LMS) for K-12 educators. It helps teachers prepare yearly, unit, and lesson plans; build worksheets and forms; maintain course rosters and gradebook-style checklists; run daily and weekly planning rituals; and, optionally, connect Google Drive. Daytical is operated from the Czech Republic, in the European Union; our full legal details appear in §16.

This policy applies to the Daytical web application and to daytical.com. It explains what we collect, why we collect it, who we share it with, how long we keep it, and the rights you have.

Our practices are designed to meet the requirements of the EU GDPR; the US federal and state privacy laws that apply to us (including CCPA/CPRA, COPPA and, where relevant, FERPA and state student-privacy laws); PIPEDA and Quebec’s Law 25 in Canada; and the Australian Privacy Act 1988 and its Australian Privacy Principles. Region-specific disclosures appear in §15.

Questions, requests or complaints: info@daytical.com.

2. Our Two Roles: Teacher Data and Student Data

Daytical processes two distinct categories of data, and our legal role differs for each.

For schools and districts that require one, we offer a Data Processing Agreement (DPA) covering the processor relationship, including standard contractual clauses for international transfers. Request one at info@daytical.com.

3. What We Collect from Teachers

3.1 Information you provide

Data Purpose Legal basis (GDPR)
Name, email address, profile picture Create and identify your account, address you in the product and in emails Contract
Locale, time zone, first day of week, ritual schedules and checklists Present the product in your language, time zone and working rhythm Contract
Access PIN and backup PIN (optional) Quick re-entry to the app on a shared or classroom device Contract
Your content — yearly/unit/lesson plans, homework, worksheets, forms, tasks, notes, checklists, school-year and timetable setup The core service we provide to you Contract
Files you upload as teaching assets (images, documents) Embed them in your plans, worksheets and materials — see §9 on how they are served Contract
Billing details Process payment and issue invoices Contract, Legal obligation
Support messages, bug reports and feature requests Respond to you and resolve what you report Legitimate interest

We authenticate you with a one-time code sent to your email address or with Google sign-in. We do not store a reusable account password.

3.2 Information collected automatically

Data Purpose Legal basis (GDPR)
IP address and user agent, recorded with each session Keep you signed in, detect suspicious sign-in activity Legitimate interest, Contract
Application and error logs Keep the service running, diagnose faults Legitimate interest
Feature usage (which parts of the product you use) Guide product improvement Legitimate interest
AI agent usage counters (tokens, requests) Meter your plan’s AI allowance and prevent abuse Contract

We do not operate advertising or cross-site tracking technology, and we do not build advertising profiles.

3.3 Information from third parties

4. Student Data: Scope and Strict Limits

Students cannot create accounts. There is no student sign-up, and a student never uses Daytical outside a lesson their teacher is running. Students appear in Daytical in two ways only:

A student’s roster record is limited to:

Beyond the roster record, we store the classwork a teacher collects through Daytical — a student’s responses to a worksheet or form run in a lesson session. You may also create custom student checklists to track additional data tight to a roster. For example attendance or grades.

What we never do with student data:

Authorisation. We collect student data only from, and at the direction of, teachers and schools — never from students themselves, beyond the name a student picks or types to join their teacher’s lesson.

Children under 13 (COPPA). Where a student is under 13, we rely on the school’s authorisation in place of individual parental consent, as the FTC’s COPPA guidance permits for educational technology used for a school-authorised educational purpose. We do not ask teachers to obtain parental consent on our behalf — the obligations COPPA places on us stay with us. We give the school notice of what we collect and how it is used (this policy, and our DPA on request), we use student data solely for the educational purpose the school authorised, and we never use it for advertising, profiling, or any commercial purpose of our own, as set out above. Daytical is not for collecting data about children under 13 outside a school context. If you are not acting under a school’s authorisation, do not enter data about a student under 13.

Everything else. The school — or, where you act on your own account, you — is the controller, and is responsible for having a lawful basis for entering a student’s data and for any school authorisation or parental consent required by the GDPR, FERPA, state student-privacy laws, PIPEDA, or the Australian Privacy Act. Where the law that applies to your school requires a written agreement with us before student data may be entered, request our DPA at info@daytical.com.

Parent and guardian rights. Parents and guardians can exercise their child’s rights — access, correction, deletion, and refusal of further collection — through the child’s teacher or school, who can review, edit, export, and delete student records directly in Daytical using self-service controls, at any time and without our involvement. If a school needs our assistance, we will provide it on request at info@daytical.com. Because we act as processor, we refer any request that reaches us directly to the responsible teacher or school and assist them in fulfilling it; where the law requires us to act on a request ourselves, we will.

5. How We Use Information

Student data is used solely as described in §4 and for none of the other purposes above.

Where we rely on legitimate interest, we have weighed that interest against your rights and privacy expectations, and you may object at any time (see §10).

6. Artificial Intelligence Features

Daytical includes an AI agent that helps teachers draft plans, worksheets, and other teaching material.

7. Cookies and Local Storage

We use only essential cookies. We do not use advertising or cross-site tracking cookies.

Cookie Purpose Set by
Session cookie Keeps you signed in Daytical
Locale preference Remembers your language before you sign in Daytical
Referral identifier When a colleague invites you with a referral link, stores the referral ID so that the credit can be attributed to both of you after sign-up Daytical
Support and feedback identity cookies Our support chat, feedback board and bug-report widgets set their own cookies to recognise you across sessions Intercom, Canny, Ybug

Because these cookies are strictly necessary for the service, or set to fulfil a preference you have expressed, they do not require consent under the ePrivacy rules in most jurisdictions. You may still block or clear them in your browser, although blocking the session cookie will prevent you from signing in.

8. Retention

Data Retention
Account and content data Kept while your account is active
Deleted accounts Deletion is scheduled with a 30-day grace period during which you can cancel it; at the end of that window the data is erased immediately from our live systems
Trial workspaces If you do not subscribe after your trial ends, your workspace and its data — student records included — are deleted
Database backups Rolling 30 days, then overwritten — data from a deleted account is therefore gone from backups no later than 60 days after you request deletion
Technical and application logs Up to 30 days
Billing and invoicing records Up to 10 years, as required by accounting and tax law
Support conversations, bug reports and feature requests While your account is active and for up to 2 years afterwards or 10 years in cases where required by law (e.g. refund requests support tickets), so that the history of a reported issue can be traced.
Student roster records Kept for as long as the teacher keeps them; deleted immediately when the teacher deletes the student, the course, or their account (subject to the same backup window)

If you need data erased sooner than the schedule above provides, write to info@daytical.com and we will process the request manually.

9. Security

No system connected to the internet is completely secure, and we cannot guarantee absolute security. You can help by keeping access to your email account and devices secure.

Breach notification. If a breach affects your personal data, we will notify the competent supervisory authority within 72 hours of becoming aware of it where the GDPR requires, notify affected users without undue delay where the risk to them is high, notify affected individuals and the Australian OAIC where a breach is likely to result in serious harm, as the Notifiable Data Breaches scheme requires, and meet US state and Canadian notification requirements. Where we act as processor for student data, we notify the school or teacher without undue delay so that they can meet their own obligations.

10. Your Rights

Wherever you live, you have the following rights:

To exercise anything not available as a self-service control, email info@daytical.com. We verify your identity before acting, and we respond within 30 days (extendable by a further 60 days for complex requests, in which case we will inform you). Exercising your rights is free of charge and will never result in a reduced level of service.

Appeals. If we refuse a request, our response will explain why and how to appeal. To appeal, reply to that response or write to info@daytical.com with the subject “Privacy appeal”; we will respond within 45 days. If we deny your appeal, you may contact your state attorney general or supervisory authority.

11. Sharing and Disclosure

We do not sell personal data, and we do not share personal data for cross-context behavioural advertising. We disclose personal data only:

12. International Transfers

We are established in the Czech Republic. Our application and database are hosted in the European Union. Our sub-processors process personal data in the European Union and the United States.

For personal data originating in the EEA, we rely on the European Commission’s Standard Contractual Clauses, supplemented by our own technical and organisational measures, wherever a provider is not covered by an adequacy decision (including the EU–US Data Privacy Framework, where a provider is certified). For Canadian and Australian users, we remain accountable for personal data we transfer to a service provider abroad and require comparable protection by contract, as PIPEDA and Australian Privacy Principle 8 require. Copies of the relevant transfer mechanisms are available on request.

13. Sub-Processors

We keep this list short and give each provider only the data it needs for the purpose listed. With a single exception, none of them receives student data: our infrastructure hosting provider stores our database — student records included — on our behalf, with no independent use of it. Every other provider processes teacher/account data only, for the purpose listed.

Sub-processor Purpose Data it receives
Railway Application and database hosting All account and content data stored in our database, student records included (as infrastructure host; no independent use)
Google Cloud Platform (Cloud Storage, Vertex AI / Agent Platform) Storage of uploaded and AI-generated files; AI model access; potentially further infrastructure hosting Files you upload or generate; agent prompts and planning content. See §6
Google (Google Workspace APIs) Google sign-in, Drive file access, contact suggestions for referrals Your Google profile and the data covered by the scopes you individually grant
OpenAI AI agent models Prompts and planning content you send to the agent. See §6
Anthropic AI agent models Prompts and planning content you send to the agent. See §6
Autumn Subscription, plan, credit and metering management Account identifiers, plan and usage counters
Stripe Payment processing Billing identifiers and payment details. Full card details are handled by Stripe and never stored on our servers
Resend Transactional email delivery (sign-in codes, email verification, account-deletion notices, referral invitations) Recipient name and email address, message content. Teachers and their invited colleagues only
Intercom Customer support messaging Your user ID, name, email and support conversations
Canny Feature request and feedback board Your user ID, name and email (you may also post anonymously; Canny still receives your identity to grant you access)
Ybug Bug reporting from inside the app Your user ID, name, email, and the screenshot/session details attached to a report you submit
Linear Tracking bug reports and feature requests through to a fix Your name and email, attached to the issue you reported
Better Stack Logging, telemetry and uptime monitoring Application logs, which may include IP address, user agent, user ID and request metadata
Plausible Website analytics Visits to daytical.com. Cookie-less, aggregate analytics; no cross-site tracking and no advertising profiles

We keep this list current. To be notified by email before we add a new sub-processor, write to info@daytical.com and ask to be added to the notification list.

14. Changes to This Policy

We may update this policy as the product, the law, or our providers change. If a change is material, we will notify you by email or by a prominent in-app notice before it takes effect. The current version is always available on our website, and previous versions are available on request.

One commitment sits outside this flexibility: we will not materially weaken the student-data commitments in §4 with respect to previously collected student data without the consent of the teacher or school that controls it.

15. Regional Disclosures

15.1 European Union

15.2 United States

California (CCPA/CPRA) and other state privacy laws. In the past 12 months we have collected the categories below. We have not sold personal information and have not shared it for cross-context behavioural advertising, and we do not do so today — including the personal information of anyone under 16.

Category of personal information Sources Business purpose Disclosed to Retention
Identifiers (name, email, user ID, IP address) You, automatic collection, Google sign-in Account creation, authentication, service delivery, security, support Hosting, email, support, feedback, logging and billing sub-processors Until account deletion (see §8)
Visual information (your profile picture) You, Google sign-in Identifying an account holder in the product; helping students and teachers recognise the right person on a roster Hosting sub-processor Until account deletion; student pictures until deleted by the teacher
Customer records (billing details) You, payment provider Subscriptions, invoicing, fraud prevention Autumn, Stripe 10 years (tax law)
Commercial information (plan, subscription and credit history) You, automatic collection Billing, entitlement, support Autumn, Stripe Until account deletion; billing records 10 years
Internet/network activity (feature usage, application logs, user agent) Automatic collection Security, diagnostics, product improvement Hosting, logging sub-processors Up to 30 days for logs
Geolocation (coarse, inferred from IP) Automatic collection Security and regional/tax settings Hosting, logging sub-processors Up to 30 days
Professional information (that you are an educator, your school-year and timetable setup) You Service delivery Hosting sub-processor Until account deletion
Your content (plans, lessons, worksheets, tasks) You Service delivery, AI assistance you request Hosting and AI sub-processors Until account deletion
Student data (roster: first name, last name, email address; classwork collected by the teacher) Teacher input, CSV import, classwork in teacher-run lessons Attributing classwork and checklist entries to the correct student Infrastructure hosting sub-processor only (storage on our behalf; no independent use) Until deleted by the teacher

Sensitive personal information. We do not use or disclose sensitive personal information for any purpose other than providing the service you requested, so the CPRA right to limit its use does not arise; you may nonetheless write to us with any concern. We do not use personal information for automated decision-making or profiling in furtherance of decisions producing legal or similarly significant effects.

Your US state rights — to know, access, correct, delete, port, opt out of sale/sharing and targeted advertising, appeal a refusal, and be free from discrimination for exercising them — are covered by §10. You may use an authorised agent; we will verify their authority.

Global Privacy Control. We honour the GPC browser signal. Because we do not sell or share personal information for targeted advertising, there is nothing for it to opt you out of — but we recognise and respect it.

Students (COPPA, FERPA, and state student-privacy laws). Students do not create accounts and receive no communications from us. The only information a student ever enters directly is the name they pick or type to join a lesson their teacher runs; everything else about a student comes from the teacher or school, and all of it is collected for the school’s educational purpose, at the teacher’s direction, and handled as described in §4 — never for any commercial purpose of our own. Where a school or district uses Daytical under an agreement with us, we act as a school official under FERPA (34 CFR § 99.31(a)(1)) under the school’s direct control, and as a school service provider under state student-privacy laws such as California’s SOPIPA: we do not use student data for targeted advertising, do not create a non-educational profile of a student, do not sell student data, and delete it on the school’s instruction.

15.3 Canada

We comply with PIPEDA and, for Quebec residents, Law 25. You may access and correct your personal information as described in §10, and complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca) or, in Quebec, the Commission d’accès à l’information du Québec. Personal information may be stored or processed outside Canada, including in the European Union and the United States, where it is subject to the laws of those jurisdictions; we remain accountable for it and protect it by contract. Our privacy contact for Canadian and Quebec purposes is info@daytical.com.

15.4 Australia

We comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. You may request access to and correction of your personal information (APP 12 and 13) as described in §10, and complain to us first at info@daytical.com; if you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (oaic.gov.au). Personal information is disclosed to overseas recipients — the sub-processors listed in §13, located in the European Union and the United States — and we take reasonable steps under APP 8 to ensure they handle it consistently with the APPs. We do not adopt or use government-related identifiers.

16. Contact Us

We aim to respond to privacy enquiries within 3–5 business days, and to formal rights requests within the statutory deadlines set out in §10.