The short version: Daily Captain stores what you write on your sheet, your email address, and what is needed to sign you in and keep your data in sync. We never read your goals, we never train anything on them, and we do not sell your information. There is no advertising and no tracking across other websites. Site analytics runs only if you accept it, and declining changes nothing about the app. Some things you write are meant to be seen: you get a profile page of your own, which is public and switched on by default, and a week you send to a buddy is read by that buddy. Everything else stays yours alone. You can join our newsletter from the app with one tick box, and it is Kit, not us, that then emails you to confirm it is really you. Deleting your account starts a 30-day grace period, after which everything is erased for good.
1. Who we are
Daily Captain is operated by Heegstra LLC, a Wyoming (USA) limited liability company at 30 N Gould St Ste N, Sheridan, WY 82801 ("we", "us"). We are the controller of the personal data described here.
Contact for anything in this notice, including privacy requests: hello@dailycaptain.app.
2. What we collect
You give us:
- Your email address, when you ask for a sign-in link. It is the only thing we need to make an account. We also record whether your account is on the invitation list, because access is invitation-only.
- Your sheet: the goals you write and which ones you tick, your midday check, and the three evening fields (one word, notes, tomorrow's first goal), each stored against a date.
- Your settings: your theme, and, if you turn reminders on, your reminder times and your time zone.
- Feedback, when you send it: the text you wrote, whether you ticked "allow reply", a short label for where in the app you sent it from, and your browser's user-agent string.
- A newsletter sign-up, if you tick the box when you set up your account. It is the Heegstra newsletter, the same one at heegstra.io, and ticking sends your account's email address to Kit, who hold the list. Kit then emails you one confirmation link, and you are only subscribed once you click it. On our side we record two things: that you asked, and when. We never claim you confirmed, because only Kit knows that. There is no toggle in the app to turn it off again: unsubscribing is the one-click link in every newsletter email, which is instant and final.
- Quotes you send to the community, if you use "submit a quote": the line you wrote, and the fact that it came from your account. A person reads every submission that reaches us before anything happens to it. Lines with swearing in them are refused as you send them and never stored. If it is approved it becomes the quote of one day, with your name on it and a link to your public profile page when you have one switched on. That day's quote is public: it appears on everybody's sheet, and anyone who asks the app for that day's quote can read it without having an account. We only approve a quote when there is a name on your profile to put on it, which is the stand-in "Captain" if you never typed one, and we then store a copy of that name alongside the quote, because it is the name the quote went out under. That copy is kept for as long as the approved quote is: changing the name on your profile afterwards does not rewrite a quote already published under the old one, and clearing your profile name does not take a published quote down. Ask us and we will change the name on it or remove the quote altogether; deleting your account deletes both. The link to your profile page is not a copy: it follows the setting, so switching your public page off removes it everywhere at once. If it is rejected it is seen by nobody but us. Either way we write you a notification in the app telling you what we decided, which repeats the line you sent. Either way, too, you can have it deleted by asking us, and deleting your account deletes your submissions and those notifications with it, approved ones included.
- Your profile: the name you choose, a line about what you do, where you are, a personal quote, the handle that forms your page's address, links to your own social profiles and a playlist, and the lines you write in your Cookie Jar. If you add a photo, we store the picture itself in our database. It must be a JPEG, at most 80 KB and 2048 pixels on a side.
- Your year and your week: your yearly goals and the names you give the four categories, your Dream Year lines, the tasks you line up for next week, the note you add to a goal in the Sunday review, and the day of the week you pick for that review. We also record when you closed a day, which is what your streak counts.
Your device or our systems generate:
- Sign-in material: a one-time link and a six-digit code, both valid for 15 minutes and usable once. We store only a hash of each, never the link or the code itself, plus a count of wrong code guesses.
- Session identifiers, stored hashed, so that you stay signed in for up to 90 days.
- Abuse-prevention records: a one-way hash (SHA-256) of the IP address a sign-in or code request came from, so we can rate-limit. We do not store or log raw IP addresses. Newsletter sign-ups are rate-limited differently, because they happen inside your account: we note the moment of each attempt against your account and delete those notes after a day.
- Push subscriptions, if you turn reminders on: the notification token your browser issues for that device, the browser's user-agent string, and the delivery status of the last push.
- Server logs, written by our host when the app answers a request. They record the event, not your content. Two of them record an email address: a sign-in request from an address that is not on the invitation list, so we can see who is asking to get in, and a sign-in link burned by five wrong code guesses. A third records only the part of an address after the @ sign, when a newsletter sign-up fails, so we can tell a provider-wide problem from a single bad address.
- Bot-check signals: when you request a sign-in link, Cloudflare Turnstile examines browser and device signals and your IP address to tell a person from an automated script. Cloudflare processes those signals; we receive only a pass or fail.
- Site analytics, only if you accept it: a pseudonymous browser identifier, the screens you view, approximate location derived from your IP address, and browser or device information. Never the contents of your sheet.
The invitation list. Separately from all of the above, we keep a list of invitations. An address gets on it in one of two ways: we invite someone, or somebody already using Daily Captain invites them as a buddy. We hold the address, the date, and, when the invitation is ours, a short note about where it came from. A buddy invitation is marked as one, and we keep the record of which invitation admitted which address so an admission can be taken back. An invitation is not an account: the person creates one themselves by signing in, so until they do, the invitation is all we hold about them. Unused buddy invitations are swept off the list automatically when they expire; the rest stays until we remove it by hand, and deleting your account removes your own entry and the admissions your invitations granted.
What you publish. Daily Captain gives you a page of your own at dailycaptain.app/your-handle. It is switched on by default, anyone who has the address can read it, and it asks search engines to index it, so it is meant to be found. It shows your name, your line about what you do, where you are, your personal quote, your photo, your social and playlist links, the first five lines of your Cookie Jar, and your yearly goals for the current year. The yearly goals are behind their own switch, also on by default; your Dream Year is behind a third switch, off by default. Your daily sheets, your weeks and your review notes are never on it. If you did not choose a handle we build one from your name, never from your email address, so your address cannot become a web address behind your back.
All of it is yours to switch off, on the Profile screen. Turning the page off takes the page and the photo down at once, and both then answer as though the handle never existed. Changing your handle frees the old address immediately, with no forwarding. What we cannot undo is what somebody else has already taken: a search engine's cache, the preview a chat app stored when the link was shared, a screenshot. And when a page's address is shared, the service it is shared in fetches the page and may keep its own copy of your name and your line or quote in that preview.
What you share with a buddy. You can invite someone to be your accountability buddy, and on a Sunday send them a copy of your week. When you do:
- The invitation is a one-time link that expires in 14 days. You share it however you like; we never send it for you and we never ask you for the other person's address. When somebody opens your link and asks for a sign-in link with their own address, we put that address on our invitation list so the link works, and we keep a record of which invitation admitted it. One link can admit up to three addresses that way, and they all come off the list when the link is used up or expires.
- Anyone holding that link, until it is used or expires, sees a page with your first name and your photo on it. That is what the link is for, but it means a link forwarded to somebody else shows them the same thing.
- A week you send is a frozen copy. It carries, for each day, the goals and whether you ticked them, the note you wrote on a goal in the review, and your one word for that day, plus next week's task list and your name as it was at that moment. Your buddy keeps that copy: unlinking later does not take it back. Your photo is not part of it. The page fetches your picture live, and only while you are still connected, so unlinking, deleting the photo or deleting your account takes your face off weeks they already hold. Deleting your account also removes the weeks themselves from the inboxes of everyone you sent them to.
- Their reply is stored with your week: what they wrote, the marks they put against individual goals of yours, and their name as it was when they wrote it. So are the notifications either of you get about any of this, and a notification can name the other person, so a line about you can sit in their app and a line about them in yours. When somebody sends a week to you, your name at that moment is frozen into their record of that send, and it stays there through a rename or an unlink.
- When you send a week, the person you sent it to gets an email saying so, with your first name in the subject line. Their mail provider sees that, and so does Resend, who deliver it for us. The email does not carry the week: it links to the app, and they sign in to read it.
- Your photo is shown to a live connection even when your public page is switched off. That switch governs the internet, not the people you chose to send your weeks to.
We do not collect your phone number, precise location, contacts, or anything else from your device. We do not ask for your name to create an account: that takes an email address and nothing else. A name is asked for when you set up your profile, and it is optional there: leave it blank on that screen and we store the word "Captain" instead, which is then what the app calls you, what your buddies see, and what a quote of yours would go out under. If you clear the name later on your profile, your page falls back to showing your handle. So the only names we hold are that stand-in, one you typed yourself, and frozen copies of whichever it was: kept with a community quote we approved, with a week you sent, with a week somebody sent you, and with a reply you wrote. We do not use cookies or similar technology for advertising. We do not buy personal data about you from anyone.
Payments. We take no payments. Daily Captain is an invitation-only preview, there is no charge for it, and no payment provider is connected to the app. If that ever changes, we will update this notice and tell you before anything is charged.
3. Why we use it, and our legal basis
Where the GDPR or UK GDPR applies, this is the basis for each purpose:
| What we do | Why | Legal basis |
|---|---|---|
| Show your sheet, save your goals, sync across your devices | To provide the service you asked for | Performance of a contract |
| Email you what your account needs: sign-in links and codes, security notices, and the notices our terms oblige us to send | You cannot use the account without them, and we promised you the rest | Performance of a contract |
| Email you what a feature produces: a buddy has sent you their week, or we have decided on a quote you submitted | It is how the feature reaches you when the app is closed | Performance of a contract for the buddy message, and the consent you gave when you submitted the quote for the other |
| Send the reminders you switched on | You asked for them, per device | Consent |
| Answer your feedback | To act on what you tell us, and to reply if you asked us to | Legitimate interests, and consent for the reply |
| Pass your address to Kit for the newsletter | You ticked the box, and Kit confirms it with you before adding you | Consent |
| Review a quote you submitted, and publish it if we approve it | You asked us to consider it; the review is what keeps the community page clean | Consent, and legitimate interests for the review itself |
| Show your profile page to anyone who has its address | You control it with a switch on the Profile screen | Consent |
| Deliver a week you chose to send to a buddy, and their reply back to you | It is the feature you asked for | Performance of a contract |
| Put an address you typed on our invitation list so your buddy can get in | Without it the invitation link does not work | Legitimate interests |
| Check what goes out: an automatic filter on profile text and quote submissions, and a person reading every quote submission | To keep what is published under our name lawful and decent | Legitimate interests |
| Rate limits, the bot check, and security logs | To keep the service up and to stop abuse of the sign-in form | Legitimate interests |
| Site analytics | To see which screens are used and where the app breaks | Consent |
| Keep records we are legally required to keep | Tax, accounting, responding to lawful requests | Legal obligation |
We do not profile you, we do not make automated decisions with legal or similarly significant effects about you, and we do not use your goals for advertising.
The emails we send you. Every account gets email from us, of two kinds. The things the account itself needs: your sign-in links and codes, security notices, and the notices our terms oblige us to send, such as a change to those terms or anything that would delete your sheets. And the things the features you use produce: a message when a buddy sends you their week, and a message telling you what we decided about a quote you submitted. Both kinds are the service itself, so they carry no unsubscribe link. The first stops when you delete your account. The second stops when you stop using the feature, by unlinking the buddy or submitting no more quotes. A feature email never carries your sheet or the week itself: it says something is waiting and links you to the app. We send you no marketing on the strength of having signed up. The only marketing we send is our newsletter, which you have to ask for and then confirm with Kit, and which you can leave with one click without touching your account. We will not put promotional content into any of the emails above to get around that.
We do not read your sheet, publish it, or use it to train any AI model. Nobody at Heegstra opens your goals to look at them. The exceptions are the ones you make yourself, and only those: what you put on your profile page, the yearly goals you leave switched on there, a week you send to a buddy, and a quote you submit to the community. Those are read by the people you sent them to, or by anyone, because that is what you asked for. Everything else, meaning your daily sheets, your evening notes and your Dream Year while its switch is off, is seen by nobody but you. The only thing a person at Heegstra reads is a quote you submit to the community, because you asked us to consider publishing it. Profile text and published lines pass an automatic filter and nothing more, and a photo is checked only for being a real image within the size we accept: nobody looks at what a picture shows before it goes up. If we ever build a feature that sends your content to an AI model, it will be off unless you turn it on, we will name the provider in this notice before it launches, and content sent that way will not be used to train that provider's models.
4. Cookies, local storage, and analytics
Strictly necessary. One first-party cookie, __Host-dgs_session, keeps you signed in. It lasts up to 90 days, is HttpOnly and Secure, and carries no information about you beyond a session reference. It is the only cookie Daily Captain sets by itself.
Your device also keeps things in the browser's own local storage so that the app works offline and remembers you between visits: your recent sheets and the quotes for those days, your theme, which account the cached sheet belongs to, any feedback waiting to be sent, and your cookie choices. That data never leaves your device except as described elsewhere in this notice, and signing out clears everything except your theme and your cookie choices. The installed app also keeps a copy of its own files in your browser's cache so it opens without a connection.
None of the above needs your consent, and none of it is used for advertising. There is a full list with names and lifetimes in our cookie table.
Bot check. Cloudflare Turnstile protects the sign-in form. We do not use its pre-clearance option, so it stores nothing on your device.
Optional: site analytics (Google). If, and only if, you accept site analytics, we load Google Tag Manager, which loads Google Analytics 4 for us. Tag Manager is how we manage that measurement; it is not a separate purpose and we use it for nothing else.
Analytics measures visits, screens viewed, approximate location and browser or device information, so that we can understand and improve the app. It uses first-party cookies (_ga and a _ga_<id> cookie) to tell browsers and sessions apart. We configure those to expire 390 days after they are first set, which is inside the 13-month maximum we work to, and we switch off the setting that would otherwise restart that clock on every visit. We keep event-level analytics data for 2 months and user-level data for 14 months, without resetting the user-level period when a browser comes back.
We keep Google Signals, Google advertising features, ads personalisation, user-provided data and Google Ads linking switched off. We never send your email address, your goals or any other direct identifier to Analytics. Google explains how it handles information from services that use its tools on its partner sites page.
Marketing: none, and nothing to accept. We do not run any advertising or retargeting technology today, and our cookie banner offers you no choice about it, because there is nothing to choose: accepting analytics accepts analytics and nothing else. We keep a reserved "Marketing" slot in the record of your choice, always off and impossible to switch on, so that the day we add something we have to ask you about it rather than treat today's choice as permission for it. If that day comes we will update this notice, add the choice to the banner, and ask you before anything runs.
Your choice. Nothing optional is pre-selected, declining keeps the entire app available, and you can change your mind at any time from the cookie settings link in Settings. If you decline analytics, nothing from Google loads at all. We remember your choice for 390 days, or until a material change means we should ask again. If your browser cannot store the record of your choice, nothing optional runs and we ask again next time.
Global Privacy Control. If your browser sends a GPC signal and you have not answered the banner yourself, we take it as a decline, record that it came from the signal rather than from you, and do not ask: your browser has answered. A choice you make yourself in Settings takes over from then on, which also means the signal does not undo an acceptance you gave before you switched it on. Change that in Settings and it changes. The full detail is in our cookie table.
If we ever add another technology that uses non-essential storage, we will update this notice and ask for consent before it goes live.
5. Who else sees your data
Other people, when you choose. Before the list of companies below, the more important answer: some of what you write is seen by other people, always because you switched something on or sent something.
- Anyone on the internet can read your profile page while it is switched on, and search engines are asked to index it. That is your name, your line, your place, your quote, your photo, your links, your Cookie Jar lines, and, each behind its own switch, your yearly goals and up to four lines of your Dream Year.
- A buddy you connect with sees your name and your photo, and reads any week you send them: the goals, ticks, review notes and one-word entries for that week, and next week's tasks. The photo reaches them whether or not your public page is on.
- Anyone holding an invitation link you sent sees your first name and your photo on the landing page, until that link is used or expires.
- Anyone at all sees a community quote of yours we approve, on its day. The quote of the day is public, so it takes no account to read it, and it carries your name and a link to your page when that page is on.
- The service you share a link in, a chat app or a social network, fetches the page to build a preview and may keep its own copy of what it found.
None of this happens to your daily sheet, which is not published or shared by any of these features.
Our service providers. We use a small number of them. Each of them acts on our instructions under a data processing agreement, and none of them may use your data for their own purposes.
| Provider | What it does | What it sees |
|---|---|---|
| Cloudflare, Inc. (USA) | Hosts the app and the database, and runs the Turnstile bot check | Everything stored in the app, and the technical data of every request |
| Resend, Inc. (USA) | Delivers every email we send you: sign-in links and codes, service notices, and the messages your features produce, such as a buddy having sent you their week | Your email address, the contents of those emails, and the first name of a buddy who sent you a week |
| Kit.com, Inc. (Kit, formerly ConvertKit; USA) | Holds the Heegstra newsletter list, and sends the confirmation email when you tick the newsletter box | Only your email address, and only if you tick that box |
| Google LLC (USA) | Google Analytics 4 and Tag Manager | Analytics data only, and only after you accept it |
| Your browser or phone's push service (Apple, Google, Mozilla and others) | Delivers reminder notifications | The notification text and a device token, never your sheet |
That is the whole list. We do not sell your personal information, we do not share it for cross-context behavioural advertising, and we have never done either. We disclose data to authorities only where the law requires it, and we will tell you when we are allowed to.
If Heegstra LLC is ever sold or merged, your data may transfer with the product. We would tell you first, and the buyer would be bound by this notice until it gave you a new one.
6. How long we keep it
- Your account and your sheets: for as long as your account exists.
- Sign-in links and codes: 15 minutes, then they stop working. The records are cleared once they are more than a day old by an automatic cleanup that runs every few minutes.
- Sessions: up to 90 days, and immediately when you sign out or delete your account. Signing in again replaces the session on the device you sign in on; a session on another device runs to its 90 days unless you sign out there.
- Hashed IP records for rate limiting: one hour, cleared by the same automatic cleanup.
- Your profile and your photo: for as long as your account exists. Clearing a field or deleting the photo removes it at once; deleting the account removes all of it, and takes your page down before the 30-day grace period even starts.
- Your year and your week: for as long as your account exists. A week becomes read-only once its Sunday has passed, on purpose, so a past week is a record rather than something you can tidy up afterwards. Deleting the account still erases it.
- Newsletter rate-limit records: one day, cleared by the same automatic cleanup, and deleted with your account before then if you delete it.
- Server logs: kept by our host, Cloudflare, for 3 days and then deleted automatically. We do not copy them anywhere.
- Feedback: for as long as your account exists, and deleted with it.
- The invitation list: an unused buddy invitation and the admissions it granted are swept off automatically when the invitation expires, 14 days after it was made. Entries we created ourselves stay until we remove them by hand, and you can ask us to remove yours. Deleting your account removes your own entry and the admissions your invitations granted.
- Connections, sent weeks, replies and notifications: for as long as either account exists. A week you sent stays in your buddy's inbox after you unlink, because it was delivered; it goes when either of you deletes an account. Notifications go the same way, including the copies that sit in somebody else's app because they are about you.
- Push subscriptions: until you turn reminders off, your browser drops the subscription, or your account is deleted. Turning reminders off deletes the subscription for every device on your account, not only the one you switched it off on, so turning them back on means allowing notifications again on each device.
- Newsletter: the list itself is held by Kit under the Heegstra privacy policy. What this app keeps is the fact that you asked and the date, for as long as your account exists. One click in any newsletter unsubscribes you, and your address then goes on a suppression list so it is not used for marketing again.
- Quotes you submitted: for as long as your account exists, whether they were approved, rejected or never reviewed, and deleted with your account. An approved one leaves everybody's rotation the moment your account is deleted.
- Analytics: as set out in section 4.
- Deleting your account: everything is scheduled for erasure and removed 30 days later, by the same cleanup. Signing in during those 30 days brings it all back.
7. Your rights
You can do the following yourself, from Settings: change or delete anything you wrote, turn reminders off, change your cookie choices, and delete your account. Every newsletter email has a one-click unsubscribe.
For everything else, email hello@dailycaptain.app. That includes:
- Access: a copy of the data we hold about you. We do not have a self-serve export button yet, so ask us and we will send you your sheets, settings, profile and feedback as a machine-readable file. If you have used the buddy loop, that includes the weeks you sent and the replies you received; a week somebody sent to you is part of your copy too.
- Correction of anything inaccurate.
- Erasure, beyond the self-serve deletion in Settings.
- Restriction of processing, and objection to processing based on our legitimate interests.
- Portability of the data you gave us.
- Withdrawing consent for the newsletter, for analytics or for reminders, at any time. Withdrawing does not affect the lawfulness of anything we did before you withdrew.
What erasure reaches, and what it cannot. Deleting your account takes down your profile page and photo at once, removes your submissions and any approved community quote from everybody's rotation, and removes the weeks you sent from your buddies' inboxes along with the notifications about you in their apps. It cannot reach what has already left us: a search engine's index or cache, a preview stored by a chat app, a screenshot, or anything a buddy chose to write down elsewhere. If a search engine still shows an old copy of your page, tell us and we will help you ask them to remove it, but the request is theirs to grant.
We answer within 30 days, usually much sooner, and we do not charge for it. We may ask you to confirm control of the email address on the account before we act, because that address is the only identifier we hold.
If you are in the EEA or the UK, the rights above are yours under the GDPR and UK GDPR, and you may also complain to your data protection authority. In the Netherlands that is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl); elsewhere, your national authority.
If you are in California, you have the right to know what we collect and why, to delete it, to correct it, and not to be treated differently for exercising those rights. We do not sell or share personal information, and we do not use sensitive personal information to infer characteristics about you. The categories we collect and our purposes are in sections 2 and 3, and we honour these requests whether or not the law formally applies to us.
8. Where your data is stored, and transfers
The app and the database run on Cloudflare's network, with the database in the United States. Our providers are US companies.
If you are in the EEA, the UK or Switzerland, that means your data is transferred to the United States. Kit and Google are certified under the EU-U.S. Data Privacy Framework and its UK and Swiss extensions. Our providers' data processing agreements also incorporate the European Commission's Standard Contractual Clauses, which is the mechanism we rely on for transfers generally.
9. How we protect it
Everything travels over HTTPS and nothing else is accepted. Sign-in links, codes and session identifiers are stored only as hashes, so a copy of our database would not let anyone sign in as you. Sign-in links expire in 15 minutes and work once, signing in replaces that device's session, and the sign-in form is rate-limited and protected by a bot check. We store no raw IP addresses. The app sends strict browser security headers on every response.
If a breach ever puts your rights at risk, we will tell you and the relevant authority, within 72 hours of becoming aware where the law requires it.
10. Children
Daily Captain is for people aged 16 and over. We do not knowingly collect data from anyone younger, and we ask people not to publish a page, a photo or an invitation for anybody under 16. If you believe a child has an account, tell us at hello@dailycaptain.app and we will delete it and take down anything published from it.
11. Changes to this notice
When this notice changes we update the version and the date at the top and note it in the changelog below. For anything material we tell you in the app or by email before it takes effect, and where the change relies on your consent we ask again rather than assume.
Changelog
- 2.3, 30 Aug 2026: section 3 says which emails an account brings with it now that features send them too, that both kinds are the service rather than a subscription, and how each kind stops. It also says what a feature email does not carry, which is your sheet. The legal-basis table gains a row for those emails. Section 2 says, in the paragraph about sending a week, that the person you send it to gets an email with your first name in it, and who sees that on the way. Resend's row in section 5 widens from sign-in and service notices to every email we send, and names the buddy's first name as something it sees.
- 2.2, 29 Aug 2026 (draft): the release of 29 August added a whole category of processing the notice did not mention: things other people see. Section 2 gains your profile (name, line, place, quote, handle, social and playlist links, Cookie Jar) and your photo, which is stored as an image in our database; your year and your week; a paragraph on what you publish, saying plainly that your page is on by default, readable by anyone with the address, and asks to be indexed; and a paragraph on what you share with a buddy, saying that a sent week is a frozen copy your buddy keeps after you unlink, that an invitation link shows your first name and photo to whoever holds it, and that your photo reaches a buddy even with your public page off. The invitation list now covers addresses another user adds by inviting a buddy, and the old line saying deletion does not remove it is corrected: it does. Section 3 gains four rows and an exception to the "we never publish your sheet" promise for the things you publish yourself. Section 5 answers "who else sees your data" with people before providers. Section 6 gains the profile, the photo, the year and week, connections, sent weeks, replies and notifications, and corrects the push-subscription and cleanup bullets to what the code now does. Section 7 says what erasure reaches in someone else's copy, and what it cannot reach at all.
- 2.2, second pass, 29 Aug 2026 (draft): a paragraph in section 3 saying which emails come with an account, that they have no unsubscribe because they are the service rather than a subscription, and that signing up is not consent to marketing: the newsletter stays the only marketing we send, opt-in and separately cancellable. The legal-basis row and Resend's row in section 5 widened from "sign-in emails" to the service emails they actually cover.
- 2.2 verification pass, 29 Aug 2026: nine corrections after checking every new sentence against the code. A buddy invitation never asks the inviter for an address: the invitee types their own while holding the link, and one link admits up to three. A sent week does not carry the photo: the picture is fetched live and stops being served the moment you unlink or delete it. A reply also stores per-goal marks and a frozen name, and a week sent *to* you freezes your name in the sender's record. Nobody at Heegstra reads a profile field or looks at a photo before it is published; only quote submissions get a human. The quote of the day is public, so an approved quote of yours is readable without an account. The Dream Year belongs in the list of what the internet can see. And clearing your name shows your handle on the page, not "Captain".
- 2.1, 28 Aug 2026 (draft): the newsletter is joinable from the app again, and two sections had to change to say so honestly. The anonymous sign-up endpoint was deleted; the one that replaced it only ever subscribes the address of the account calling it. Section 2 now says what a tick of that box stores here (that you asked, and when) and what it does not (any claim that you confirmed, which only Kit knows). Community quote submissions are described for the first time: what a submission is, that a person reads it, and what happens to it if we publish it under your name. Still draft, so this is the same 2.1 rather than a new number: the section also now says that approving a quote stores a copy of the name it goes out under, how long that copy is kept and how to have it changed or removed, that we write you a notification repeating the line you sent, and it qualifies the old flat claim that we collect no name, which stopped being true the moment a name could be stored with a quote. It also says, for the first time, that leaving the name field blank stores the stand-in "Captain" rather than nothing.
- 2.0, 28 Aug 2026 (draft): rewritten in Jan's Cowork legal review. Legal-basis table added; the collection list now matches the code exactly (one-time codes, hashed IPs, user-agent on feedback and push subscriptions, the gate log that records an email address); the self-serve export claim removed and replaced with export on request; retention now describes what actually happens; cookie and local-storage inventory made specific, with a separate cookie table; a reserved "Marketing" purpose declared but unused; Global Privacy Control honoured; forward-looking AI clause added; security, breach, business-transfer, California and supervisory-authority sections added.
- 2.0.3, 28 Aug 2026 (draft): section 4 now describes the banner that actually shipped. There is no marketing choice in it: accepting analytics accepts analytics only, and marketing is a reserved slot nothing can grant. Consent and analytics-cookie lifetimes are the real 390 days rather than a rounded 13 months, and the analytics cookies now genuinely expire 390 days after they are first set, because the setting that restarted that clock on every visit was switched off. Global Privacy Control has its own paragraph, saying what it does and, just as important, what it does not do: it decides for a visitor who has not answered, and it does not undo an acceptance given before the signal was switched on.
- 2.0.2, 28 Aug 2026 (draft): server-log retention in section 6 is now the real number. Cloudflare keeps Workers Logs for 3 days on the plan this app runs on, so "a few days" became "3 days".
- 2.0.1, 28 Aug 2026 (draft): payments removed. The notice described Stripe and card data for a payment flow that does not exist; Daily Captain is an invitation-only preview with no charge, and payments come back into the notice on the day they are wired.
- 1.1, 28 Aug 2026 (draft): beta newsletter via Kit, optional analytics via GTM and GA4, Turnstile, EEA/UK rights list, transfer mechanisms.
- 1.0, 27 Aug 2026 (draft): first version.