This is an archived version (v2.0) of the Daylight Privacy Policy, no longer in effect. View the current policy.
Privacy Policy
Version 2.0 (archived) — last updated 3 August 2026
Daylight is a product of Knowli. This page explains what information we collect, why we collect it, and who to contact with questions — covering both this site and the Daylight account and diary product itself.
Joining the waitlist
When you join the Daylight waitlist, we collect the email address you submit and, if you arrived via a shared link, a small set of campaign attribution data: the link's source, medium, and campaign tags, the referring page, the page you landed on, and the time of your first visit. That attribution data is set as a cookie for up to 90 days on your first visit and only stored against your waitlist entry when you submit the form.
Some waitlist entries aren't self-submitted. If you were personally invited to the private preview, we created your entry ourselves using an email address we already had for you, rather than one you typed into the waitlist form — it's used the same way as a self-submitted entry: to send you the invite and, if you register, to remember how you found us.
We use this to let you know when Daylight launches and to understand which channels are actually bringing people to the waitlist. We don't sell or share this data with third parties for advertising. If you'd like your waitlist entry removed, contact us using the email address below.
Some waitlisted people get early access to a private preview before public launch, via a personal invite link sent by email. Opening that link sets a short-lived, browser-scoped cookie that unlocks account creation early; registering through it is recorded on your account as having come from the private preview, the same way we record how anyone else found us (see "Creating an account" below).
Creating an account
When you register, we collect your email address and a password — passwords are hashed and never stored or logged in plain text. Each time you sign in, we also record your approximate device (parsed from your browser's user agent), an approximate location and IP address (used to recognize a new or unusual sign-in and shown on your account's Sessions page, where you can review and sign out individual devices), and the time of that sign-in.
We also record how you found Daylight — a link's source, medium, and campaign tags, the referring page, and the time of your first visit — the same attribution data described above for the waitlist, stored against your account instead once you register. If you registered through a private preview invite link, we record that specifically rather than whatever you may have clicked before receiving it.
If someone referred you using their referral link, we record that connection so we can credit their account — we don't use it for anything else.
Your diary entries
Your entry titles and bodies are encrypted at rest, each with a key unique to your account — a database leak alone can't expose what you've written. We also keep a timestamp-only edit history (when an entry was changed, not what changed) and a running view count on each entry. Exporting your entries decrypts them back to plain text in the downloaded file, since it's meant for you to actually read; importing re-encrypts them the same way new entries are.
While you're writing, an in-progress entry is also saved to your browser's local storage so nothing is lost if you lose your connection, alongside a short-lived cache of writing prompts so the app doesn't have to re-fetch them constantly. Signing out clears the prompt cache and any draft that's already been saved to your account, but never an unsynced draft — that's the only copy of that work until it reaches our servers, so we don't delete it on sign-out.
AI features
If you use the "Generate title" or "Refine" actions on an entry, the relevant text is sent to Google's Gemini API to produce a suggestion — that's the only time entry content leaves our systems to be processed by a third party. This happens only when you trigger it, is rate-limited per account, and is handled under Google's own privacy practices; see Google's Privacy Policy for how Google itself handles this data.
Sharing an entry
If you turn on password-protected sharing for an entry, we create a share link and store a hash of the password you set — never the password itself. We also log share activity (created, revoked, and viewed events) so you can see that history. Anyone who enters the correct password gets a short-lived, browser-scoped access cookie so they aren't re-prompted on every visit within that session.
Sessions & security
Each device or browser you sign in from gets its own session, so you can stay signed in without being interrupted. Your account's Sessions page lists every active session (device, approximate location, last active time) and lets you sign out an individual device or every device except the one you're currently using.
Notifications
We send in-app notifications for things like account updates, product announcements, and referral payouts. You can turn each category off independently from your notification settings — this only controls what appears in-app; we don't currently send notification email or push notifications.
Email delivery
When we need to email you — a private preview invite, or a password reset link — we use Resend to deliver it. Your email address and the message content are shared with Resend solely to send that email; we don't use email delivery for marketing.
Feedback & support
During the private preview, Daylight shows testers a short checklist of things to try, plus prompts to leave a note right after using certain features. If you submit feedback, we store the message, which feature or task it relates to (if any), your account (if you're logged in), and when you sent it. Feedback is reviewed manually and isn't shared outside our team.
If you contact support, we store your email address, the subject and message you send, your account (if you're logged in), and when you sent it. Support requests are handled manually — someone on our team replies by email — and are only used to help you and improve Daylight.
Site analytics
We use Google Analytics to understand how many people visit this site and which pages they view. It sets cookies and collects standard usage data — pages visited, approximate location, and device/browser information. This is used only to improve the site, never for advertising, and it never has access to anything you write in a diary entry.
You can opt out of Google Analytics using your browser's tracking protection or an ad blocker — most already block it by default. See Google's Privacy Policy for how Google itself handles this data.
Your choices
You can block cookies and analytics scripts entirely using your browser's privacy settings or an ad blocker — the site works fine without them. If you've joined the waitlist and want your entry removed, email us at knowlihq@gmail.com and we'll delete it.
If you have an account, you can delete it and its data yourself from Account settings — deletion is immediate, with a 21-day recovery window before it's permanently removed. To recover it during that window, reset your password for that email.
Changes to this policy
We'll bump the version number and "last updated" date at the top of this page whenever this policy changes, and keep the previous version readable at its own link rather than replacing it silently.
What changed in v2.0: accounts, diary entries, and every feature built since v1.0 now have their own section — encryption, sessions, AI title/refine (Gemini), entry sharing, notifications, referrals, and the private preview invite flow. v1.0 only covered this site's pre-launch waitlist page, before any of that existed. View the v1.0 archive.
Contact us
Questions about this policy or your data? Email us at knowlihq@gmail.com.