Privacy policy

This policy explains the information Dialog needs to plan your day, the services that process it, and the controls available to you.

Effective September 4, 2026

Dialog is developed and operated by Yugo Atobe in Japan. This policy applies to the Dialog iOS app, the website at dialog.day, and related support communications.

Dialog does not sell personal information or share it for cross-context behavioral advertising. The website does not use advertising cookies or client-side analytics.

Information Dialog processes

Account and profile information

Dialog processes the name, email address, authentication identifiers, sign-in provider, and profile information associated with the Apple or Google sign-in method you choose. Authentication is provided by Clerk. Dialog does not receive your Apple or Google password.

If you use Sign in with Apple and choose Hide My Email, Dialog receives the Apple relay address instead of your personal address.

Calendar information

With your permission, Dialog reads events from the calendars you leave enabled in Dialog for the day you ask it to plan. Planning context may include event titles, original dates and times, time zones, all-day status, exact availability or status, calendar names and provider-supplied original colors, location text, structured location title and precise latitude, longitude, and radius, notes, URLs, recurrence details, travel time, detached occurrence details, and organizer or attendee information supplied by the calendar provider.

You can show or hide available input calendars from the Calendars screen in Dialog. Hidden input calendars and the selected plan-calendar destination are excluded from planning reads. Dialog does not modify source calendar events. After Dialog generates, restores, keeps, or undoes a plan, it full-replaces only Dialog-created events in the plan calendar you selected or created with the current working plan. Keep confirms the proposed changes in Dialog; Undo restores the prior confirmed plan and reprojects it to that calendar.

Planning profile and preferences

Dialog processes the planning details you provide, such as waking and working hours, focus preferences, buffer time, commute or meal preferences, selected calendars, notification choices, time zone, and app settings.

Plans and conversations

Dialog stores the instructions and messages you submit, generated replies and plans, reviewable plan changes, keep or undo decisions, session history, and recovery checkpoints. This information lets the service continue a conversation, restore an earlier plan, and keep your work available across signed-in devices.

Subscription and access information

Apple processes payment. Dialog, RevenueCat, Superwall, and Convex process a stable billing identifier, product and entitlement status, purchase or renewal events, trial state when applicable, and related subscription metadata. Dialog does not receive your full payment card number or Apple Account password.

Technical and support information

The app and its infrastructure process operational information needed to deliver and protect the service, including request times, app and operating-system versions, model and token-usage metadata, error state, and security or abuse-prevention signals. If you contact support, Dialog processes your email address, message, and any attachments you choose to provide.

Optional referral codes

If you choose to submit a referral code, Dialog checks it against registered invitation sources and records an anonymous accepted-submission count in its own backend. This does not grant subscription access. Dialog does not attach your account, email, device, or advertising identifier to this count, and does not forward the referral code to third-party analytics or billing services. A random retry receipt is retained for seven days to avoid counting repeated submissions, then deleted. Invalid code input is not stored. You can skip the referral step without submitting anything.

Diagnostics and analytics

The Diagnostics & Analytics setting is on by default. You can turn it off in Settings at any time. The device applies an opt-out immediately, and Dialog stops sending new optional diagnostics and analytics events while it is off.

When enabled, Sentry receives crash and error events only. Dialog disables performance traces, session tracking, network capture, breadcrumbs, logs, screenshots, view hierarchy, and default personally identifiable information. Dialog does not send prompts, messages, plan or calendar content, email addresses, account identifiers, or billing identifiers to Sentry.

When enabled, Dialog’s backend may send PostHog US Cloud a small, server-side allowlist of non-content product and reliability events, such as whether a supported operation reached a coarse success or failure outcome. These events are personless and each event uses a new random event identifier. Dialog does not create PostHog user profiles or use a stable user or device identifier, client-side autocapture, session replay, or screen recording. Prompts, messages, plans, calendar content, email addresses, account identifiers, and billing identifiers are excluded.

Dialog uses this optional information to identify crashes, understand whether core release flows are operating, and prioritize reliability work. The account-scoped preference itself is stored so your choice can follow your signed-in account.

Cloudflare processes standard web request information, such as IP address, request headers, requested URL, and timestamp, to deliver and protect this website. Dialog does not currently run client-side analytics or advertising technology on the website.

Information kept on your device

Dialog stores local onboarding drafts, account-scoped restoration data, selected calendar settings, notification choices, and cached app state on your device. Calendar data also remains with the calendar accounts configured on your device. iOS controls access to that data.

How Dialog uses information

Dialog uses information to:

  • Authenticate you and keep your account secure
  • Read the selected day and generate a proposed schedule
  • Project the current working plan to the selected Daily plan calendar so you can review it, then keep or undo the proposed changes in Dialog
  • Preserve plans, conversations, settings, and recovery checkpoints
  • Confirm subscription access and present paywalls
  • Send local notifications you request
  • Respond to support and privacy requests
  • Detect abuse, troubleshoot failures, and maintain service reliability
  • Diagnose crashes and measure coarse, non-content reliability outcomes when Diagnostics & Analytics is enabled
  • Comply with law and enforce the Terms of use

Dialog does not use your content to train a model of its own.

AI processing

Calendar permission alone is not consent to cloud or AI processing. Before Dialog stores or sends rich calendar context for planning, you must explicitly grant the versioned AI Data Processing consent (ai-processing-v1) in onboarding or Settings. The consent covers sending the planning-relevant allowlist described above to Convex and an AI provider. Dialog schedules stored rich context for deletion after 90 days, and eligible records are normally removed by cleanup within 48 hours.

Dialog uses Vercel AI Gateway to route release AI requests to OpenAI’s API. OpenAI processes only the context needed for the selected task, which can include your instructions, relevant conversation history, planning preferences, and calendar context for the selected day.

Dialog sets Vercel AI Gateway’s zero-data-retention option for release AI requests. That setting restricts routing to a zero-data-retention-compatible OpenAI API path and includes provider training opt-out for the request. Vercel and OpenAI process the request long enough to route it and return the result but do not retain the request content under that request-level setting. If the required route is unavailable, Dialog fails the request instead of silently using a route with broader retention. This statement applies to Dialog’s configured API requests and does not describe every consumer product or API configuration offered by Vercel or OpenAI.

You can revoke or grant AI Data Processing again from Settings. After revocation, the app and backend fail closed before storing or sending new rich calendar context, so affected AI planning requests will not run until current consent is granted again. Revocation does not by itself delete context already stored by Dialog. Stored rich context is scheduled for deletion after 90 days and normally removed by cleanup within 48 hours after becoming eligible; it can be removed sooner with Delete app data or Delete account.

Zero-data-retention routing concerns the gateway and inference provider. It does not remove the plans, conversations, or account information that Dialog stores to provide the features you requested. Those records follow the retention and deletion rules below.

AI output can be inaccurate, incomplete, or unsuitable. Review every proposed change before relying on it. Dialog may already have projected the current working version to your selected Daily plan calendar; use Keep to confirm it or Undo to restore the prior confirmed plan.

Service providers and disclosures

Dialog discloses information only as needed to operate the service, follow your instructions, complete a transaction, or comply with law. Current provider categories include:

  • Apple, for app distribution, Sign in with Apple, TestFlight, App Store billing, and platform services
  • Google, when you choose Google sign-in
  • Clerk, for authentication and account sessions
  • Convex, for application hosting, database storage, realtime sync, conversations, and backend operations
  • Vercel AI Gateway and OpenAI, for zero-data-retention AI request routing and generation
  • RevenueCat, for subscription entitlement and purchase-state management
  • Superwall, for paywall presentation, placement, and related subscription experience measurement
  • Sentry, for crash and error reporting while Diagnostics & Analytics is enabled
  • PostHog US Cloud, for allowlisted, server-side, personless product and reliability events while Diagnostics & Analytics is enabled
  • Cloudflare, for domain, content delivery, security, and website hosting
  • Support and infrastructure providers, when needed to receive email, diagnose a problem, protect the service, or maintain availability

Dialog requires service providers that receive personal information from Dialog to protect it consistently with this policy and applicable privacy law, to process it only for the service they provide or as law requires, and to use appropriate security and confidentiality safeguards. Dialog reviews provider terms and data controls before enabling a provider for production use.

Information may also be disclosed to authorities when legally required, to protect users or the service, or as part of a merger, financing, acquisition, or transfer of Dialog, subject to appropriate notice and safeguards.

International transfers

Dialog is operated from Japan and uses providers that may process information in Japan, the United States, and other countries. Privacy laws in those countries may differ from those where you live. Where required, Dialog and its providers rely on appropriate contractual or legal transfer safeguards.

Retention

Dialog keeps account information, settings, plans, conversations, and recovery history while your account remains active and for as long as needed to provide the service or meet legal, security, and dispute-resolution obligations.

Some operational records have shorter default windows:

  • Temporary streamed plan preview data is scheduled for deletion after 30 days.
  • Rich plan-generation context derived from selected calendar events is scheduled for deletion after 90 days.
  • Raw subscription webhook audit data is generally retained for about 30 days by the billing integration.
  • Eligible short-lived records are normally removed by scheduled cleanup within 48 hours after their retention window ends.

Support communications are kept only as long as reasonably necessary to answer the request, maintain a support history, protect the service, or meet legal obligations.

Backups, security records, provider records, and information that must be kept by law may remain for a limited period after deletion. Dialog restricts retained information to the purpose that requires it.

Deletion and your controls

You can change calendar and notification permission in iOS Settings. Inside Dialog, you can show or hide input calendars, select the plan-calendar destination, change notification preferences, revoke or grant AI Data Processing, turn Diagnostics & Analytics off or on, and open subscription-management links.

Dialog provides two in-app deletion scopes under Settings, then Data & Privacy:

  • Delete app data removes Dialog-owned plans, conversations, planning settings, generated context, recovery history, and identifiable Dialog-created projection events. It keeps the account, a minimal identity and billing continuity link, the selected plan calendar itself, and subscription state.
  • Delete account removes Dialog-owned content and the account profile, requests deletion of the Clerk identity used to sign in, removes identifiable Dialog-created projection events from the selected plan calendar, clears account-scoped local data, and signs you out. It keeps the physical calendar and other events in it, and it does not cancel an App Store subscription.

For deletion safety, Dialog temporarily retains a minimal account tombstone while the Clerk deletion finishes and previously issued short-lived session tokens expire. After provider deletion is confirmed, Dialog removes the identity-bearing tombstone and keeps only an opaque, capability-protected completion receipt so an interrupted device can finish local cleanup without restoring the deleted account. These technical records are not shown in the app or used for advertising. RevenueCat customer and billing records are retained separately for entitlement continuity, purchase restoration, and support; deleting those records would not itself cancel an App Store subscription, which you manage through Apple. If you used Sign in with Apple, Apple may continue to list Dialog in your Apple Account until you remove that authorization in Apple settings; the app provides a link to those instructions after deletion. A later protected sign-in creates a fresh Dialog account shell without restoring deleted Dialog content.

To request access, correction, portability, objection, restriction, or external erasure that includes provider-held identity or billing records, contact support@dialog.day. Dialog may need to verify that the request belongs to you. Legal, security, fraud-prevention, or accounting requirements can limit a request.

Where a legal basis is required, Dialog relies on:

  • Contract, to provide the app, account, and subscription features you request
  • Consent, for calendar access, notifications, and other permission-controlled features
  • Legitimate interests, to secure, maintain, improve, and support the service
  • Legal obligation, when records or disclosures are required by law

Depending on where you live, you may have rights to know, access, correct, delete, restrict, port, or object to processing, withdraw consent, appeal a privacy decision, or complain to a privacy regulator. Exercising a right will not result in unlawful discrimination.

California residents may request the categories and specific pieces of personal information Dialog holds, correction, or deletion, subject to applicable exceptions. Dialog does not sell personal information or share it for cross-context behavioral advertising.

Residents of the European Economic Area, United Kingdom, or Switzerland may complain to their local data protection authority. Residents of Japan may exercise rights available under the Act on the Protection of Personal Information.

Security

Dialog uses measures intended to protect information, including encrypted network transport, provider-managed encryption at rest, access controls, secret management, and data-minimizing client and backend contracts. No service can guarantee perfect security. Please use a secure device and sign-in method, and contact support if you believe your account has been compromised.

Children

Dialog is not directed to children under 13, and Yugo Atobe does not knowingly collect personal information from a child under 13. A person who is not old enough to consent to data processing or form a contract where they live must use Dialog only with permission from a parent or legal guardian.

Changes

This policy may change as Dialog, its providers, or the law changes. A material change will be identified by a new effective date and, when appropriate, notice in the app or by email.

Contact

Yugo Atobe, Japan
support@dialog.day