Privacy Policy

Dayworth AI · Last updated 24 September 2026

Dayworth AI is a field-sales planning app. It holds the list of businesses you visit, what you did on each visit, where you drove, and, if you use the assistant, the questions you ask it. That is commercially sensitive information, and this page explains plainly what happens to it.

The one thing worth knowing up front. Your accounts, contacts, notes and visit history are encrypted in transit and at rest, and access within Dayworth AI is restricted to the small number of personnel who operate the service. We do not access your book, and we do not sell, license or train on it. Those are commitments we make and enforce through access controls and contract. They are not a mathematical guarantee, and this policy does not represent otherwise.

A correction to an earlier version. Before 24 September 2026, this page stated that your data was encrypted under a key we never received and that we were unable to read it. That described an earlier architecture. It is not how the service works today, and we have corrected the wording rather than leave a representation we do not meet. Two changes account for it: your data key is now held by your account, so that signing in on a new device restores your territory; and the team dashboard, CRM synchronisation and the assistant read account records on our servers in order to function. Section 3 sets out precisely what is stored, in what form, and who can reach it.

What you receive in exchange. A forgotten or reset password no longer costs you your territory. Signing in is sufficient to restore it.

If you compete with us, read this part. Dayworth AI's users are field-sales representatives, some of whom compete with one another and, potentially, with the people who operate this service. Your protection is our access controls and our contractual commitments, not cryptographic impossibility. You should evaluate whether that is sufficient for your circumstances before placing your pipeline in this product.

1. Who we are

Dayworth AI is operated by Dayworth LLC ("Dayworth AI", "we"), a Texas limited liability company. For privacy questions, contact privacy@dayworth.ai.

2. What we collect

Information you give us

WhatWhy
Email address and passwordTo create and secure your account. Passwords are hashed by Google Firebase Authentication; we never see the plaintext.
Google account name and email (if you sign in with Google)To identify your account. We do not receive your Google password.
Your accounts and prospects: business names, addresses, phone numbers, websites, industry, tier, notesThis is the core of the product: the list of places you visit.
Contacts at those businesses: names, job roles, notesSo the app can tell you whether the right person is likely to be there. See §4 on other people's data.
Visit records: dates, what you logged, next steps, quotes, photos you attachVisit history and reporting.
Setup answers: what you sell, what you're optimising forTo tune which accounts the app ranks highest.

Information collected automatically

WhatWhy
Location: your device's coordinates, only while the app is open on screenTo sort accounts by distance, plan routes from where you are, and record mileage. Only with your permission, which your phone asks for and you can revoke at any time. See §3a for exactly when this does and does not happen.
Trip and mileage recordsMileage logs and deduction reports.
Assistant usage: number of questions, tokens consumed, resulting costTo enforce plan limits and bill correctly. We record the size of each request; the content is covered in §5.
Basic technical data: IP address, browser and device type, error logsSecurity, abuse prevention, and fixing crashes.

We do not use advertising trackers, third-party analytics, or cross-site cookies. We do not sell personal information, and we do not share it for cross-context behavioural advertising.

3a. Location, in detail

Location is the most sensitive thing Dayworth AI touches, so this section says exactly what happens rather than summarising it. What Dayworth AI can do depends on how you use it, so it is split by that.

In a web browser: no background tracking, ever

Used from a browser, Dayworth AI reads your location only while the app is open and on screen. When you lock your phone or switch apps, the browser suspends the page and location reading stops. This is enforced by your phone's operating system, not by our good intentions. A web page is not permitted to track you in the background, and Dayworth AI cannot do so however it is configured.

In the installed app: also no background tracking

The installed Dayworth AI app reads your location on exactly the same terms as the browser: only while the app is open and on screen. Outside of active turn-by-turn navigation it does not track you in the background, and it asks for "Always" location only for that one feature, described immediately below. Automatic drive logging was removed in September 2026, so nothing else needs the app to watch you while it is closed.

Turn-by-turn navigation

The installed app can drive your route itself, with spoken directions, rather than handing you to a separate maps app. This is the one feature that uses background location, and only while a route is actually running:

Where location data goes

Your position and trip history are stored on your device in the clear, so the passcode on your phone is what protects them. If you sync, they are also uploaded inside the encrypted backup described in §3, which we are able to decrypt. Coordinates of route stops, not names and not notes, are sent to our routing provider to calculate driving times. What goes up is only the trips you record (date, distance, duration), inside that backup.

Turning it off

Revoke the location permission in your phone's settings and distance sorting, arrival detection and drive recording stop; nothing else does, and you can still log trips by hand. Trips already recorded stay yours. Export or delete them at any time (§8).

3. Where your data is stored, and who can reach it

Your data is held in two forms, and the distinction matters, so we set out both.

The synced backup. Your device encrypts this copy with AES-256-GCM under a per-account data key before uploading it. What reaches our servers is ciphertext. The data key is also held by your account, so that signing in on a new device restores your territory without any further step. A necessary consequence, stated plainly: a person with administrative access to our database could retrieve that key and decrypt that backup. We restrict such access to the personnel who operate the service and we do not use it to read customer data, but we are able to, and we will not claim otherwise.

Account and visit records created through the app's API. These (business names, addresses, contacts, notes and visit outcomes) are stored in readable form on our servers. They must be, because the team dashboard, manager visibility, CRM synchronisation and the assistant all operate on them server-side. They are protected by transport encryption, encryption at rest, and per-account database rules that prevent any other customer from reading them; they are not protected from us.

Because the data key is held by your account, resetting a forgotten password no longer costs you your data: signing in restores both your account and your territory. This is a deliberate change from an earlier design in which a password reset left the backup permanently unreadable.

The copy held on your own device is not encrypted unless you turn on the Face ID lock. The lock is off by default. With it off, anyone who can unlock your phone can read what is on it, so keep a passcode on the device. Turning it on (Account › Security) encrypts the on-device copy with AES-256-GCM under a random key that your device's biometric check (Face ID, Touch ID or the platform equivalent) releases; your account password can release it too, so a failed biometric never locks you out. Earlier versions used a device PIN instead; that was removed in August 2026 because forgetting it locked reps out of their own territories with no way back. The Face ID lock has no PIN, and your password remains the way back in. The Face ID lock governs the copy on your own device only; it does not affect what we are able to read on our servers, which is described above.

What this means in practice. Personnel with administrative access to our production systems are technically capable of reading your account names, addresses, contacts, notes and visit history. We commit that we do not do so, except where you ask us to in order to provide support, or where we are compelled by valid legal process. Where we are compelled, we will give you notice unless the law prohibits it. If our systems were breached, an attacker with sufficient access could obtain readable customer data; access control, least-privilege administration and the breach-notification commitment in §9 are therefore the operative protections.

Notifications you turn on

If you turn on notifications, we store, readable on our servers, the things needed to send them and nothing more: your device's push subscription (an opaque delivery address the browser issues, not your identity), your timezone (described under "What we can see" above), and which reminders you have switched on.

Two of the reminders depend on what is in your book, which we cannot read, so your device tells us only yes or no. "An account has gone cold" and "you have mileage that isn't logged" are worked out on your device, from the encrypted copy only it can open, and sent to us as a single on/off flag each. The flag carries no account name, no note, and no count, just that there is something of that kind waiting. When the reminder goes out it says only which kind it is; the app shows you which accounts after you open it. Nothing about your book crosses our servers in readable form through this feature.

Feedback you send us

If you use the in-app feedback form, we receive what you type, your email address, and technical context about the moment you sent it: the app build, which screen you were on, how many stops were in your route (the count, not which ones), your browser and screen size, whether you were online, and the last few error messages the app recorded. We read these. That is their whole purpose, and they are the only way a problem you hit reaches us.

Treat that box like an email to us. Whatever you type is readable by us and is not covered by anything else on this page: describe the problem rather than pasting a customer's name, address or notes into it. If you have already sent one you would rather we did not keep, email privacy@dayworth.ai and we will delete it.

§5 of the Terms of Service also covers feedback, but it answers a different question: who owns an idea you send us, not who can read it. This paragraph is the privacy answer.

What we use it for, and what we will never use it for

Access is one question; use is another, and this is the one that decides whether Dayworth AI is safe to put a live pipeline into. We access and process your data for three purposes, and we have tried to make the list exhaustive rather than flattering:

Nothing else. We will not, and will not permit anyone else to: sell, rent, license, trade or transfer your data; include it in any dataset, index, benchmark or aggregate product, whether identified or anonymised; use it to train, fine-tune, evaluate or ground any AI model; mine it for market intelligence or lead lists; use it to build or improve a product that competes with you; or use it for advertising, profiling or scoring.

That list is contractual rather than a statement of intent: it is §4 of the Terms of Service, it does not depend on which plan you are on, and it survives a change of ownership. An acquirer takes your data subject to the same restrictions or does not take it at all. The only exception is the valid legal process described above.

We say all of this specifically because we hold the key to your data and could read it. A commitment is what you are relying on, so it should be written down, enumerated, and binding, rather than left as a tone of voice.

The ciphertext is held on Google Cloud infrastructure in the United States, additionally encrypted in transit (TLS) and at rest, and locked to your account by database security rules.

A copy also lives on your own device so the app works with no signal. Unless you have turned on the Face ID lock, that copy is not encrypted, as described above, and a lost or stolen phone is protected by the phone's own passcode, not by us. With the lock on, that copy is encrypted and the phone asks for your biometric before opening it.

What we can see: your email address, the name you choose to set, when you created your account and when you last signed in, how many accounts and visits you hold (the counts, not what is in them) and when you last logged one, when you last synced and from which device, how many assistant questions you asked, which features they came from and what they cost, which optional features you use (CRM sync, push notifications, route planning), the timezone your device reports if you turn on notifications (so a morning reminder arrives in your morning and not ours), and errors the app recorded, including which account they came from, plus basic technical logs. We need these to run and bill the service. None of them reveal who your customers are.

4. Other people's data, and why this section matters to you

Much of what you put into Dayworth AI is information about other people: the buyer at a distribution company, the maintenance manager at a plant. In data-protection terms, you decide what to collect about them and why; Dayworth AI processes it on your instructions.

Practically, that means you are responsible for having a legitimate business reason to hold those details, and for honouring requests from those individuals about their data. We will help you locate, export, correct, or delete anything in your account so you can meet those obligations. If you are subject to GDPR or similar law, ask us for a data processing agreement.

Please do not store special categories of data in Dayworth AI, such as health information, government identifiers, payment card numbers, or anything about a person's race, religion, politics, or sexuality. The app is not designed for it.

5. The AI assistant

The assistant is the one place your data leaves your device in readable form, and only the part needed to answer the question you asked, only when you ask it, and only for as long as the answer takes.

When you use it, your question and the relevant slice of your accounts are decrypted on your device and sent to xAI, which operates the Grok model that answers it. We pass it through; we do not store it. If you never use the assistant, nothing readable ever leaves your phone.

The assistant can be wrong. It researches the open web, and the web is often out of date or mistaken. Verify an address, phone number, or business detail before acting on it. Do not put anything into the assistant that you would not be comfortable sending to a third-party service.

5a. Voice input

You can dictate instead of typing, in two places: a visit note, and the question you put to the AI assistant. This section says exactly where your voice goes, because the answer is not "nowhere".

Your phone's speech recognition is not on your phone. When you dictate, your browser sends the audio to Apple (on iPhone and Safari) or Google (on Chrome and Android) to be turned into text. That is how speech recognition works in every browser, and we cannot switch it off while offering the feature. Their handling of that audio is governed by their privacy policies, not ours.

If you would rather not

Don't use the button. Type instead. Nothing else in the app changes. Your phone's microphone permission can also be revoked in its settings, which stops this working while leaving the rest of Dayworth AI untouched.

Be careful what you dictate about other people

Speaking is quicker than typing, which makes it easy to record more than you would have written: a person's mood, health, or family circumstances. §4 still applies: hold only what you have a legitimate business reason to hold, and keep special categories of personal data out of Dayworth AI entirely.

6. Companies we rely on

We use a small number of sub-processors. Each one receives only what it needs.

CompanyWhat it doesWhat it receives
Google (Firebase, Cloud)Hosting, sign-in, databaseAccount details and app data
xAIThe AI assistantYour questions and relevant account data. Neither trains on it. Each keeps a copy for up to 30 days for abuse monitoring, then deletes it. See below.
OpenAIThe AI assistant, for some featuresYour questions and relevant account data, on the same terms as xAI.
StripeSubscription paymentsEmail and billing details. Card numbers go to Stripe directly and never reach our servers.
OSRM / MapboxDriving times and routes, and address lookupCoordinates of your stops for routing. For address lookup, the address text itself, a business name and street address, never your notes, contacts or visit history.
OpenStreetMap, CARTO, NominatimMap tiles and address lookupAddresses you geocode, map areas you view
OverpassFinding nearby businessesThe area you're searching in
SalesforceCRM sync, only if you connect itWhatever you choose to sync

About the two AI providers, in more detail than a table row allows. Neither xAI nor OpenAI trains on what we send them, and neither may use it for their own purposes. They act on our instructions as our sub-processors. Both keep a copy for up to 30 days for abuse monitoring, encrypted, after which it is deleted. During that window a reviewer at that company could in principle see it if something were flagged as misuse.

We pin a setting on every request (store: false) that stops the provider retaining the conversation for its own features. It does not switch off that 30-day abuse-monitoring copy, and we would rather say so than let “storage disabled” be read as “nothing is kept”. Both providers offer a zero-retention arrangement that removes it; we have asked about eligibility and will update this page if we obtain one.

7. How long we keep it

8. Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, or port your data, to object to processing, and not to be discriminated against for exercising them. Email privacy@dayworth.ai and we will respond within 30 days. We will not charge you or degrade your service for asking.

9. Security

Encryption in transit and at rest; per-account isolation enforced in the database; secrets held in a dedicated key manager and never in our source code; a strict content security policy in the browser; and an optional Face ID lock that encrypts the copy on your own device (§3).

No system is perfectly secure. If personal data is breached, we will notify affected users without undue delay and within 72 hours where the law requires it, telling you what happened, what was affected, and what to do.

10. Children

Dayworth AI is a business tool and is not directed at anyone under 18. We do not knowingly collect data from children.

11. International users

Data is processed in the United States. If you use Dayworth AI from outside the US, you are sending your data to the US, where privacy law differs from your own. For transfers of personal data out of the EEA or UK, we rely on Standard Contractual Clauses with our sub-processors.

12. Changes

We may update this policy. The date at the top always reflects the current version, and the previous version is available on request.

Where a change materially affects how we handle your data, we will show a notice in the app. We do not undertake to email you, and we do not commit to any period of notice before a change applies. Earlier versions of this section promised fourteen days' notice, and then an email. Both commitments have been removed deliberately, rather than kept as promises we would not always be able to meet: a correction to an inaccurate statement should reach you as quickly as possible, not sit behind a waiting period while the inaccurate version stays published. That is not hypothetical. It is why the note at the top of this page exists.

If a change is not acceptable to you, you can export everything and close your account at any time (§8).

13. Contact

privacy@dayworth.ai