Privacy policy
Day Orbit (called Omni Log until October 2026) is an app for food, training, recovery, school and money, made and run by one person as a private project. This page says what it stores, where it goes and how you get rid of it.
Who is responsible
Abdullah Cheema, South Tyrol, Italy.
Email: 08abdullahcheema@gmail.com
Write to this address for any question or request about your data. You get an answer within 30 days.
Without an account
Everything you type stays on your device, in the browser's storage. Nothing is sent to Day Orbit. Only the features listed under "Other services" below talk to the internet, and only when you use them.
With an account
- Account: your name, your email, your password only as a salted hash (PBKDF2), and one key per device you sign in on, also only as a hash. Nobody can read your password, not even the operator. Your recovery code is also only stored as a hash. A device that is not used for 90 days is signed out.
- Your entries: food, weight, workouts, recovery values, calendar entries, school tasks and grades, money entries, notes and scanned pages. They are stored so that every device you sign in on shows the same data.
- Health data: weight, food, sleep, heart rate and similar values are health data under the GDPR. They are only stored because you agree to it when you create the account (Art. 9(2)(a) GDPR). You can take that back at any time by deleting the account.
- Device name: a short label like "iPhone" so you can see and sign out your devices.
- Error reports: when the app crashes, it sends the error message, the app version and your browser type, so the bug can be fixed. No entries, no location.
Legal basis: providing the app you asked for (Art. 6(1)(b) GDPR) and, for health data, your consent. Your data is never sold, never used for ads and never shared with anyone, except the services below.
Where it is stored
On Cloudflare (Cloudflare, Inc.), which hosts the app and its database. Cloudflare processes the data only on the operator's behalf and briefly logs technical data such as your IP address to keep the service running and safe. Cloudflare may process data outside the EU under the EU standard contractual clauses and the EU-US Data Privacy Framework.
Other services, only when you use them
- Barcode scanner: the barcode number is sent from your device to Open Food Facts (privacy) to look up the product.
- Food photo and "read the text with the AI": the photo is sent through Day Orbit to an AI service (Cloudflare Workers AI, Google Gemini or Anthropic Claude, depending on the setup) to estimate the meal or read the page. The photo is not stored by Day Orbit. Both features are off unless you use them.
- Coach chat: when you ask the coach a question, the question, the last messages of the chat and a short summary of your data (workouts, the weights the app suggests, weekly body weight averages, calories and protein of the last two weeks, sleep and recovery, goal, age, height and sex from your profile) are sent through Day Orbit to an AI service (Anthropic Claude, Google Gemini or Cloudflare Workers AI) to write the answer. Day Orbit does not store the question on the server; the chat itself stays on your device. The other coach features (suggested weights, feedback, weekly check-in) run only on your device.
- Leaked password check: when you choose a password, the server checks it against the list of passwords from known data leaks at Have I Been Pwned (privacy). Only the first 5 characters of a scrambled (SHA-1) form of the password are sent, never the password itself and nothing about you, so the service cannot know your password or who you are.
- Watch data (Apple Watch, Samsung Galaxy Watch and others): only if you set it up. You make a private import link in Settings, Watch, and your own phone sends steps, sleep, heart rate variability, resting heart rate, active energy, exercise time and weight to it: on an iPhone through a Shortcut you build yourself in Apple's Shortcuts app, on Android through the free app Health Connect Webhook, which reads Android's Health Connect. That app is made by someone else and sends the data straight from your phone to Day Orbit. Day Orbit keeps the daily totals in your account and, for Health Connect, the single readings for up to 120 days so nothing is counted twice. A Samsung Health data download you pick in the app is read on your device only. Disconnect or make a new link any time; deleting your account removes the link and the readings.
- Google Calendar: only for the operator's own account. Other accounts cannot connect it. If connected, Day Orbit asks only for access to the one calendar it creates itself ("omnilog").
The app itself loads no ads, no trackers, no analytics and no fonts or scripts from other sites, except Paddle's payment page when you choose to start or manage a subscription (see below).
Payments (Paddle)
The subscription is sold by Paddle.com Market Limited, United Kingdom, our reseller and merchant of record. When you start the free week or pay, you enter your details on Paddle's payment page, which opens inside the app. Paddle then processes your name, email, payment details, country and postcode (for VAT), IP address and your purchase, as its own controller under the Paddle privacy notice. Day Orbit never sees or stores your card or bank details.
Day Orbit receives from Paddle and stores only: your Paddle customer and subscription IDs, the status (free week, active, cancelled, payment problem) and its dates, linked to your account, so the app knows whether it may be used. Legal basis: the contract (Art. 6(1)(b) GDPR) and keeping tax records (Art. 6(1)(c)). The UK has an EU adequacy decision. When you delete your account the subscription is cancelled and these records are deleted from Day Orbit; Paddle keeps its own records as tax law requires.
Visitor statistics on the public pages (Google Analytics)
Only on the public pages (the home page, the questions page and the "page not found" page), and only if you
click OK when asked, Day Orbit uses Google Analytics 4 from Google Ireland Limited, Gordon House, Barrow Street,
Dublin 4, Ireland, to count visits and see which pages are read and whether the "Get started" and "Log in" buttons
are used. Google then sets cookies (names starting with _ga, kept up to 2 years) and receives your
browser type, screen size, the pages you open, where you came from and a shortened IP address. Google signals and
ad personalisation are turned off. Google may process the data in the USA under the EU-US Data Privacy Framework.
See Google's privacy policy.
Nothing inside the app is sent to Google Analytics: not your food, training, recovery, school or money data,
and not your account. Legal basis: your consent (Art. 6(1)(a) GDPR, Art. 122 of the Italian privacy code). If you
click No thanks, nothing is loaded. You can change your mind any time with Cookie settings at the bottom
of the public pages; saying no later deletes the _ga cookies.
Cookies and storage on your device
The app uses no cookies. Only the public pages set Google Analytics cookies, and only after you say OK (see above). The app keeps your data, your sign-in key and your settings in your browser's local storage and IndexedDB, and the app itself in the service worker cache, so it opens without a connection. This storage is needed for the app to work, so no consent banner is shown. Clearing the site data in your browser removes all of it.
How long it is kept
Until you delete it or your account. Scanned pages and entries you delete are removed from the server on the next sync.
Your rights
- See and take your data: Settings, Backup and data, Export. You get everything as a JSON file.
- Correct it: edit any entry in the app.
- Delete it: Settings, account, Delete account. Your account, every device key and all your data on the server are removed right away. Without an account: Settings, Backup and data, Erase everything.
- You can also ask by email for access, correction, deletion, restriction or a copy of your data, and object to processing. You can complain to the Italian data protection authority, Garante per la protezione dei dati personali.
Children
You need to be 14 or older to create an account, or have a parent or guardian agree to it (Art. 8 GDPR and Art. 2-quinquies of the Italian privacy code). If you think a child under 14 signed up without that, write to the email above and the account is deleted.
Security
All traffic is encrypted (HTTPS). Passwords, device keys and recovery codes are only stored as hashes, every account's data is kept apart, sign-in attempts are limited, and passwords known from data leaks are refused. No system is perfectly safe: if a breach ever puts your data at risk, you are told by email.
Changes
When this page changes, the date at the top changes too. Big changes are also announced in the app.