Privacy Policy
Version 2.1 — last updated 21 August 2026
Previous versions: v2.0 (21 August 2026), v1.0 (16 July 2026)
Daylight is a product of Knowli. This page explains what information we collect, why we collect it, and who to contact with questions — covering both this site and the Daylight account and diary product itself.
Creating an account
When you register, we collect your email address and a password — passwords are hashed and never stored or logged in plain text. Each time you sign in, we also record your approximate device (parsed from your browser's user agent), an approximate location and IP address (used to recognize a new or unusual sign-in and shown on your account's Sessions page, where you can review and sign out individual devices), and the time of that sign-in.
We also record how you found Daylight when you register — a link's source, medium, and campaign tags, the referring page, and the time of your first visit. If you signed up before public launch through our waitlist or a private preview invite, that's recorded too, the same way.
If someone referred you using their referral link, we record that connection so we can credit their account — we don't use it for anything else.
If you install Daylight to your device's home screen, we detect that and record it against your account (which devices, not what you've written) so we can measure adoption. Members of our team can access account and usage metadata like this — never your diary entry content, which stays encrypted (see "Your diary entries" below).
Your diary entries
Your entry titles and bodies are encrypted at rest, each with a key unique to your account — a database leak alone can't expose what you've written. We also keep a timestamp-only edit history (when an entry was changed, not what changed) and a running view count on each entry. Exporting your entries decrypts them back to plain text in the downloaded file, since it's meant for you to actually read; importing re-encrypts them the same way new entries are.
While you're writing, an in-progress entry is also saved to your browser's local storage so nothing is lost if you lose your connection, alongside a short-lived cache of writing prompts so the app doesn't have to re-fetch them constantly. Signing out clears the prompt cache and any draft that's already been saved to your account, but never an unsynced draft — that's the only copy of that work until it reaches our servers, so we don't delete it on sign-out.
AI features
If you use the "Generate title" or "Refine" actions on an entry, the relevant text is sent to Google's Gemini API to produce a suggestion — that's the only time entry content leaves our systems to be processed by a third party. This happens only when you trigger it, is rate-limited per account, and is handled under Google's own privacy practices; see Google's Privacy Policy for how Google itself handles this data.
Sharing an entry
If you turn on password-protected sharing for an entry, we create a share link and store a hash of the password you set — never the password itself. We also log share activity (created, revoked, and viewed events) so you can see that history. Anyone who enters the correct password gets a short-lived, browser-scoped access cookie so they aren't re-prompted on every visit within that session.
Sharing to social media
Some accounts have access to a "Share to social" feature — currently being tested with a small group of users — that turns an entry into plain text or a downloadable branded image for posting outside the app. Both include a link back to Daylight. We log which action you took (copied text, shared text, downloaded image, or shared image) against your account, so we can tell whether this feature is actually being used — not the content itself. The image is generated on demand and isn't stored on our servers.
Sessions & security
Each device or browser you sign in from gets its own session, so you can stay signed in without being interrupted. Your account's Sessions page lists every active session (device, approximate location, last active time) and lets you sign out an individual device or every device except the one you're currently using.
Notifications
We send in-app notifications for things like account updates, product announcements, and referral payouts. You can turn each category off independently from your notification settings.
If you turn on push notifications, we store the subscription your browser gives us for that device (an endpoint URL and encryption keys, not readable by us as anything other than a delivery address) so we can deliver the same notifications to your device even when Daylight isn't open. Delivering a push notification means its (short, truncated) title and body pass through your browser or OS vendor's own push service (Google, Mozilla, Apple, or Microsoft, depending on your device) — that service only sees the notification text, not your account or diary data. You can turn push off per device at any time from notification settings.
Email delivery
When we need to email you — account verification, password resets, product announcements, support replies, or similar account-related messages — we use Resend to deliver it. Your email address and the message content are shared with Resend solely to send that email; we don't use email delivery for marketing.
Error monitoring
We use Sentry to catch and report unhandled errors in production, so we can find and fix problems quickly. Error reports can include technical details like the page you were on and request metadata, but not your diary entry content or password — those are deliberately kept out of what gets reported.
Feedback & support
During the private preview, Daylight shows testers a short checklist of things to try, plus prompts to leave a note right after using certain features. If you submit feedback, we store the message, which feature or task it relates to (if any), your account (if you're logged in), and when you sent it. Feedback is reviewed manually and isn't shared outside our team.
If you contact support, we store your email address, the subject and message you send, your account (if you're logged in), and when you sent it. Support requests are handled manually — someone on our team replies by email — and are only used to help you and improve Daylight.
Site analytics
We use Google Analytics to understand how many people visit this site and which pages they view. It sets cookies and collects standard usage data — pages visited, approximate location, and device/browser information. This is used only to improve the site, never for advertising, and it never has access to anything you write in a diary entry.
You can opt out of Google Analytics using your browser's tracking protection or an ad blocker — most already block it by default. See Google's Privacy Policy for how Google itself handles this data.
Your choices
You can block cookies and analytics scripts entirely using your browser's privacy settings or an ad blocker — the site works fine without them. If you contacted us before creating an account (for example, by joining our waitlist before launch) and want that record removed, email us at knowlihq@gmail.com and we'll delete it.
If you have an account, you can delete it and its data yourself from Account settings — deletion is immediate, with a 21-day recovery window before it's permanently removed. To recover it during that window, reset your password for that email.
Changes to this policy
We'll bump the version number and "last updated" date at the top of this page whenever this policy changes, and keep the previous version readable at its own link rather than replacing it silently.
What changed in v2.1: removed the waitlist section (joining ended at public launch); added sections for sharing to social media, push notifications, and error monitoring (Sentry); broadened the email-delivery and account sections to reflect what's actually collected today, including app-install detection and internal team access. View the v2.0 archive.
What changed in v2.0: accounts, diary entries, and every feature built since v1.0 now have their own section — encryption, sessions, AI title/refine (Gemini), entry sharing, notifications, referrals, and the private preview invite flow. v1.0 only covered this site's pre-launch waitlist page, before any of that existed. View the v1.0 archive.
Contact us
Questions about this policy or your data? Email us at knowlihq@gmail.com.