Privacy Policy

Daylane · Last updated September 15, 2026

Daylane shows a household's shared week on a screen in their home. To do that, it reads calendars that the people in that household connect themselves. This page explains exactly what it reads, what it keeps, how long it keeps it, and who else is involved.

Who is responsible

Daylane is operated by Tomare LLC.

Questions about anything on this page: privacy@lane.systems.

What Daylane holds about you

Your account
Your email address, which is also how you sign in. Optionally a first name, if you gave one or accepted a suggested one. If you signed in with Google or Apple, the identifier that provider uses for you. If you use a password, only a salted hash of it — never the password itself.
Your calendar connections
For each calendar account you connect: which provider it is, the email address of that account, the access and refresh tokens the provider issued, the scopes granted, when it was last synchronized, and — for Google — the given name on the account. Tokens are encrypted before they reach the database (see How it is protected).
Your events
Only the fields a screen draws, listed in full below.
Your household
Its name, who owns it, who its members are, and any invitations that are still pending.
Your display
The name you gave the screen, an identifier the screen reports about itself, when it was paired, and when it last checked in. The token that authenticates the screen is stored only as a SHA-256 hash; the token itself is shown once, at pairing, and cannot be recovered afterwards.

The event fields Daylane keeps

Title, start time, end time, whether it is an all-day event, location, description, whether the time is marked busy, free, tentative, or out-of-office, what kind of entry it is, its recurrence rule, a label and reference for any conference attached to it, the display names of attendees, how many attendees there are, and the reminder time.

That is the complete list. Everything else the provider sends is discarded — see Other people's information.

Google data, and why each permission is asked for

Signing in with Google and connecting a Google Calendar are two separate things in Daylane, with two separate consent screens. Signing in with Google grants no access to your calendar at all, and the tokens from sign-in are not stored. Only the calendar connection produces stored tokens.

When you connect a Google Calendar, Daylane asks for exactly four scopes:

https://www.googleapis.com/auth/calendar.readonly
To read the events Daylane draws on the household's display. It is the read-only scope: it does not permit Daylane to create, modify, or delete anything in your calendar, and Daylane never attempts to. Daylane reads only the primary calendar of the connected account.
openid and email
To learn which Google account you just connected. Daylane identifies a connection by that address, so that connecting a personal and a work account gives you two distinct connections rather than one overwriting the other, and so the app and the display can show you which account a set of events comes from. It is not used to contact you.
profile
For one thing only: the given name on the Google account, offered as a suggestion for what the app should call you if you have never said. You can accept it, edit it, or decline it, and you are only ever asked once. The suggestion is stored on the connection; it is not copied onto your account unless you accept it. Nothing else from the profile is requested, read, or kept.

Limited Use

Daylane's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Concretely, and in the terms that policy uses:

Microsoft data

Connecting a Microsoft account asks for https://graph.microsoft.com/Calendars.Read — read-only calendar access — together with openid and email to learn which account was connected, and offline_access, which is what allows Daylane to keep the display up to date without asking you to sign in again every hour. As with Google, Daylane reads the account's default calendar and writes nothing.

Other people's information

An ordinary calendar is full of information about people who have never heard of Daylane: the email addresses of everyone invited to a meeting, who organized it, meeting join links, free-text descriptions, attachments. In one ordinary calendar measured while building this, twenty-three events carried thirty-one distinct email addresses.

Daylane discards all of it. The provider's response is used to fill in the event fields listed above and is then thrown away, not stored. No attendee email address and no meeting join link is written to the database at all — that is asserted by an automated test, not merely intended. Attendees appear on a display as names, never as addresses.

This is deliberate and load-bearing: those people are not Daylane users and have consented to nothing, so the safest thing to do with their data is not to keep it.

How it is protected

Who else is involved

Google and Microsoft
The calendar providers themselves. Daylane reads from them under the permission you granted, which you can withdraw at any time from your Google account or Microsoft account.
DigitalOcean
Hosts the server and the database, in DigitalOcean's New York region, in the United States.
Resend, which delivers through Amazon SES
Sends the only email Daylane sends: email-verification codes, password resets, and household invitations. These carry your email address, and an invitation carries the household's name and the first name of the person inviting you — deliberately no link and no email address of the inviter, because an invitation mistyped by one character reaches a stranger.
GitHub
Serves this website. Like any web host, GitHub receives the IP address of anyone who visits this page. Daylane adds no cookies, analytics, or third-party scripts of its own to it.

Daylane does not sell your data, and does not share it with anyone else. There is no advertising in Daylane and no third-party tracking in it.

How long it is kept

Removing your data

Disconnect a calendar
Daylane first tells the provider to stop sending change notifications, then deletes the connection along with the stored tokens and every event that connection contributed, in every household. You can also revoke Daylane's access directly in your Google or Microsoft account settings, which stops it reading anything further.
Leave a household, or be removed from one
Your events stop being shown on that household's display, and the copies held for that household are deleted on the next synchronization — within about fifteen minutes.
Delete your account
Deleting your account removes your account record, your calendar connections and the tokens stored with them, every event those connections contributed, the household you own together with its displays and its pending invitations, and your membership of any other household. Before anything is deleted, Daylane shows you what will go — including how many people lose access to a household you own, and how many displays go dark — because deleting an owner's account deletes the household with it.
The grants behind a deleted account
Deleting your account also hands your calendar grants back. A Google grant is revoked with Google, so Daylane stops appearing in your Google third-party access list. Microsoft publishes no way for an application to hand a delegated personal grant back, so Daylane tells you to remove it yourself in your Microsoft account rather than claiming it did. Apple sign-in stores no token here that could be revoked, so you remove Daylane under Settings → Apple Account → Sign in with Apple. You are told which of these actually happened.

The display in your home

A paired screen shows the household's week to whoever is in the room. That is the purpose of the product, and it is worth being explicit about: anything on a connected calendar may be visible to anyone who can see that screen, including guests in the home. Only the household owner can pair a display or unpair one, and unpairing takes effect within about twenty milliseconds on a screen that is online.

Changes to this policy

If what Daylane does with your data changes, this page changes with it, and the date at the top is updated.