Privacy Policy

Last updated: July 27, 2026

This Privacy Policy explains what information Daylark collects, why, and what rights you have over it. It has been drafted against Daylark's internal product specification but has not yet been reviewed by a qualified attorney. It will be reviewed before Daylark's public launch, and updated if that review changes any of the terms below.

1. Identity of controller and contact

Daylark is a service operated by Aliaksei Smaliuk, a sole trader (jednoosobowa działalność gospodarcza) registered in the Polish CEIDG register. "Daylark" is a trading name; the data controller for the personal information described in this Privacy Policy is that natural person.

The controller is established in the European Union, so no representative under Article 27 of the EU GDPR is appointed. Our lead supervisory authority is the Polish Data Protection Authority (Prezes Urzędu Ochrony Danych Osobowych, UODO), ul. Stanisława Moniuszki 1A, 00-014 Warszawa, Poland.

2. What data we collect

We collect the following categories of information:

3. Lawful basis for processing

Where GDPR or UK GDPR applies, we process your account, billing, device, and usage data under Article 6(1)(b) (processing necessary to perform our contract with you — providing the Daylark service). We process child activity content — feeding, sleep, and diaper log entries, which can reveal information about a child's routine and wellbeing — under Article 9(2)(a) (your explicit consent), which we obtain through a dedicated consent screen shown the first time you create a child profile.

4. This app is for adults — children are data subjects, not users

Daylark accounts are created and operated by adult parents and caregivers. A child whose activities are logged in Daylark is a data subject, not an app user or account holder — they do not interact with Daylark directly. The parent or caregiver who creates a child's profile is responsible for having the authority to log that child's information and for managing consent on the child's behalf.

5. Who we share data with (processors)

We share personal information with the following processors, solely to operate the Daylark service on our behalf. All of the processors below are based in the United States; where required, transfers are covered by Standard Contractual Clauses (SCCs) and, for UK data, the UK International Data Transfer Addendum.

We do not sell your personal information, and we do not share it with third parties for their own marketing purposes.

6. How long we keep your data

We retain your account and child activity data for as long as your account is active. If you delete your account, we retain it for a 14-day grace period (so you can cancel the deletion by mistake) and then permanently delete it. Backups are purged on a rolling 30-day cycle, so residual copies in backups are fully cleared within 30 days of deletion.

7. Your rights

Subject to applicable law, you have the right to:

8. How to exercise your rights

You can export your data or delete your account at any time in-app, under Settings. For any other request, or if you'd rather email us, contact privacy@daylark.net. We respond to privacy requests within 30 days.

9. Cookies and tracking

The Daylark mobile app does not use cookies and does not collect an advertising identifier (IDFA). We do not invoke Apple's App Tracking Transparency prompt because we do not track you across other companies' apps or websites. This website (daylark.net) does not set tracking cookies.

10. Children's data

Daylark is not directed at children, and we do not knowingly collect personal information directly from a child under 13. Child profile data (a child's name, date of birth, and activity log entries) is entered exclusively by the adult parent or caregiver using the app, acting as the child's representative — not by the child.

11. International data transfers

Daylark's processors (Section 5) are based in the United States. Where we transfer personal information originating in the EU/EEA or UK to the United States, we rely on Standard Contractual Clauses and, for UK transfers, the UK International Data Transfer Addendum, to provide an adequate level of protection for that data.

12. Changes to this policy

We may update this Privacy Policy from time to time. If we make a material change, we will notify you in-app or by email before the change takes effect. The "Last updated" date at the top of this page always reflects the most recent version.

13. Effective date

This Privacy Policy is effective as of July 27, 2026.