DayMarshal
Privacy policy
Last updated: 21 July 2026
DayMarshal is a personal command center that helps you keep track of what matters across your email, meetings, and chats. This policy explains what data DayMarshal collects, why, who it is shared with, and the choices you have. It applies to the DayMarshal web application and website.
In this policy, “DayMarshal”, “we”, and “us” mean the DayMarshal service; “you” means a person who uses it.
What we collect
We collect only what the service needs to work.
- Account information. Your name, email address, and a securely hashed password, plus the organization (workspace) you belong to and your role in it.
- Connected Gmail account (optional). If you connect Gmail, we use the read-only
gmail.readonlypermission to receive message and thread identifiers, sender and recipient addresses, subjects, dates, labels, snippets, message bodies, and attachment metadata. Attachment content is fetched from Google only when you open or download it. We store synchronized messages so you can read them, search retained content, follow source references, and create tasks manually. We never send, delete, archive, label, mark, or otherwise modify email, and never request Google Drive access. - Connected Google Calendar account (optional). If you connect Calendar, we use
calendar.calendarlist.readonlyto list the calendars available to you andcalendar.events.readonlyto read events from calendars you select. Event data can include the title, start and end time, all-day status, location, description, organizer, and conferencing link. We use it to show a unified calendar and identify calls you may choose to send a notetaker to. We never create, edit, delete, accept, or decline Google events. - Connected Zoom account (optional). If you use the Zoom notetaker, Zoom asks you to authorize two minimum permissions: view your basic user identity and obtain a token that attributes the visible notetaker to you. DayMarshal does not list, create, edit, or delete your Zoom meetings and does not access Zoom cloud recordings. Our meeting-bot provider securely stores and refreshes the Zoom OAuth credentials; DayMarshal retains only opaque connection and Zoom user identifiers needed to launch your notetaker.
- Meetings and transcripts. When you choose to send a notetaker to a call, upload a recording, or record an in-person meeting through your microphone, we obtain a transcript and generate a summary from it. In-person audio is uploaded in private temporary segments while recording and may be translated when you select a target language. Those temporary segments are deleted after the durable transcript is assembled. For online notetaker calls, audio is captured by our meeting-bot provider and deleted once the transcript has been retrieved.
- Chat excerpts and linked channels. Text you paste for analysis, and messages from any chat channel you explicitly link.
- Technical and acquisition information. Standard server logs (such as IP address, browser type, and timestamps) and an essential session cookie that keeps you signed in. We retain the first public landing path, referring domain, and any campaign source, medium, and campaign labels so we can understand which pages lead to waitlist entries, registrations, and subscriptions. We never retain the complete referrer URL or sensitive query parameters for this purpose. On our public marketing pages only, we also use Google Analytics; analytics cookies are set only if you accept the consent banner, and declining changes nothing about how the site works. Analytics never runs inside the signed-in workspace, and we do not use advertising cookies anywhere.
How we use your data
- To provide the service: synchronizing and displaying connected Gmail and Calendar data; summarizing meetings, email, and chats when your plan includes intelligence; extracting tasks, decisions, and follow-ups; and preparing your daily brief and digests.
- To secure and operate the service, diagnose problems, and prevent abuse.
- To communicate with you about your account and service changes.
We do not sell your personal data; use Google user data for advertising, retargeting, data brokerage, lending, or creditworthiness; or allow humans to read it except when you ask for support, when access is necessary to investigate abuse or a security incident, or when required by law. Any permitted human access is limited to authorized personnel with a need to know.
Google API Services User Data Policy
DayMarshal’s use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
DayMarshal does not use Google user data to train DayMarshal models or any general-purpose artificial-intelligence or machine-learning model. Google user data is used only to provide or improve the user-facing features you request, and is not transferred for advertising or unrelated purposes.
Optional AI processing
Free Gmail synchronization does not send email to an AI provider. If you have Trial, Pro, Complimentary Pro, or Early Access and email intelligence is available, DayMarshal sends the message subject, sender, received date, and a bounded portion of the body to OpenAI to generate a summary, importance score, highlights, action flag, and grounded task suggestions. Other Pro features may send the source text you choose to process—such as meeting transcripts or linked chat excerpts—to OpenAI for the result you requested.
OpenAI states that data submitted through its API is not used to train its models by default. Under OpenAI’s default API data controls, abuse-monitoring logs may be retained for up to 30 days; a shorter or zero-retention arrangement applies only if OpenAI approves DayMarshal for that control. DayMarshal separates untrusted source content from its instructions, prohibits the model from following commands embedded in messages or transcripts, uses constrained output formats where available, and does not give email-analysis models tools that can follow links or take actions.
Meetings and the notetaker
When you send a notetaker to a Zoom, Google Meet, or Microsoft Teams call, it joins as a visible participant named “DayMarshal Notetaker”. Everyone in the meeting can see it and can remove it. Nothing joins a meeting unless you ask it to, on a specific call.
For Zoom specifically, you authorize DayMarshal before using the notetaker. The meeting-bot provider uses an on-behalf-of token so Zoom can attribute the visible notetaker to you; the notetaker can join only after you are present and must leave when you leave. You are responsible for making sure the people in a call are willing to be recorded, in line with the laws that apply to you.
Who we share data with
We share data only with the service providers (subprocessors) that make the product work, and only as needed to provide it:
- Attendee — hosts the meeting notetaker, produces meeting transcripts, and securely manages the Zoom OAuth credentials used for attributed notetaker joins.
- OpenAI — generates optional summaries and analysis from the bounded email content, transcripts, and chat text you have chosen or are entitled to process. API data is not used for model training by default; default abuse-monitoring retention may be up to 30 days.
- Google — the source of your calendar and mailbox data, only if you connect your Google account.
- Our hosting and infrastructure providers — run the servers and databases that store your data.
Some of these providers operate in the United States, so your data may be processed there. We may also disclose data if required by law, or to protect the rights and safety of our users and the service.
How long we keep it
In short: connected Gmail message bodies and metadata stay until you disconnect that mailbox, subject to a pooled limit for unanalyzed messages; analyzed and task-linked messages remain protected from that automatic pruning. Gmail attachment files are streamed on demand and not retained. Selected Calendar names and encrypted identifiers stay until you disconnect; Google event details are read on demand and are not retained as permanent calendar records. Online-notetaker recordings are deleted from our provider once the transcript is retrieved. Temporary in-person audio segments are deleted after the durable transcript is assembled; transcripts, translations, summaries, and outcomes remain until you delete the meeting or close your account. Full detail is in our data protection & retention policy.
How we protect it
- All traffic is encrypted in transit (HTTPS/TLS).
- Connected-account tokens are encrypted at rest.
- Production databases, private storage volumes, and backups containing Google user data must be encrypted at rest, with access limited to the application and authorized operators.
- Each organization’s data is isolated from every other organization’s.
- Access to your data is governed by role-based permissions, and meeting content is never written to our logs.
Your choices and rights
You may exercise the rights available under the data-protection law that applies to you. Depending on where you live, these can include the right to:
- Access the personal data we hold about you and receive a copy of it.
- Correct inaccurate or incomplete personal data. You can update basic account information from within the app.
- Delete your personal data. You can delete individual meetings in the app, disconnect a mailbox to remove its stored messages, or request deletion of your account and associated data.
- Export or receive your data in a portable form, where applicable.
- Restrict or object to certain processing, and withdraw consent where our processing relies on consent.
- Complain to your local data-protection authority. You may also appeal a decision we make about your request where local law provides that right.
How to exercise your rights
Email privacy@daymarshal.com with the subject “Data rights request” and describe what you would like us to do. We may ask for information reasonably necessary to verify that the request relates to you. You may use an authorized agent where applicable; we will ask for proof that the agent is permitted to act for you.
We will acknowledge and respond within the period required by applicable law. We do not discriminate against anyone for exercising a privacy right. If we cannot fulfill all or part of a request, we will explain why and describe any available appeal or complaint route.
Children
DayMarshal is a workplace tool and is not intended for children. We do not knowingly collect personal data from anyone under 16.
Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the “last updated” date above and, where appropriate, notify you in the app.
Contact
Questions about this policy or your data? Email us at privacy@daymarshal.com.