Legal

Privacy Policy

Last updated: June 2026

This policy describes how Daybreak (“we”, “us”) handles your personal data. Contact: privacy@readdaybreak.com.

What we read in your Gmail

Only messages from the last 24 hours that carry a List-Unsubscribe header — newsletters. We never read personal mail, Drive files, attachments, contacts, or calendar entries. Access is read-only; we cannot send mail from your account.

What we store

  • Your email, name, timezone, and language preference.
  • OAuth tokens for Gmail, encrypted at rest (AES-256-GCM).
  • The daily digests we generate for you.
  • Subscription status (kept in sync with Polar).

We do not store raw newsletter contents. They are passed to the AI model in memory and discarded once the digest is written.

Google Limited Use

Our use of Google user data complies with the Google API Services User Data Policy, including the Limited Use requirements. We use Gmail data only to produce your daily digest. We do not transfer it except to our AI processor for that purpose, do not use it for advertising, do not let humans read it (except for security investigations or with your consent), and do not use it to train or improve general-purpose AI models.

Who processes your data

  • Clerk — authentication (USA).
  • Neon — Postgres database (EU, Frankfurt).
  • Vercel — hosting (USA / global edge).
  • Anthropic — AI summary. Inputs are not used to train models (contractually guaranteed).
  • Resend — email delivery (USA).
  • Polar — payments, merchant of record (USA).
  • Upstash — rate-limit counters (EU).

We don't sell your data

We do not sell or share personal information with advertisers or data brokers (including as those terms are defined under the California CCPA / CPRA).

Your rights

In Settings → Your data, you can download a full JSON export of everything we hold and you can delete your account entirely. If you prefer, email privacy@readdaybreak.com. If you are in the EU you have rights under the GDPR to access, rectify, restrict, or object to processing, and to lodge a complaint with your local data protection supervisory authority.

Security

Traffic is encrypted in transit (TLS). OAuth tokens are encrypted at rest. We follow the principle of least privilege for every integration and do not store payment card data on our systems.

Changes

We'll notify you by email of material changes at least 14 days before they take effect. The “Last updated” date above reflects the most recent revision.

Contact

privacy@readdaybreak.com

Daybreak — every newsletter you get, in one short summary