Last updated: 22 September 2026
Daitoo has no accounts and no sign-up. There is no advertising, no advertising identifier, no analytics SDK in the app and no tracking.
Your lists stay on your device. Four things talk to our server: choosing an emoji, sorting a list, reading a list off a photo, and sharing a list. The app also says hello once when it starts, so we know which versions are in use. Only sharing a list puts anything you have written onto a server permanently.
We do not use anything you write to train machine-learning models. We do not sell your data. We never have.
If you put other people's information on a shared list or in a photo you scan, please read section 4.6 — that part is on you, and we explain why.
Übelacker Solutions GmbH
Bläsiring 28
4057 Basel
Switzerland
support@daitoo.app
We are the controller for the processing described here, under the Swiss Federal Act on Data Protection (FADP) and, where it applies, the EU General Data Protection Regulation (GDPR).
Data protection officer. We have not appointed one. Daitoo's processing does not meet the conditions in Art. 37 GDPR — it is not a public authority, not large-scale regular monitoring, and not large-scale processing of special categories of data. If that changes, we will appoint one and say so here.
Representative in the EU. We have not appointed a representative under Art. 27 GDPR. We consider the exemption in Art. 27(2)(a) to apply: the processing described here is occasional, does not involve special categories of data or data relating to criminal convictions on any scale, and is unlikely to result in a risk to the rights and freedoms of individuals. You can reach us directly at the address and email above, in German, English, French or Spanish.
Daitoo is for people aged 16 and over. We do not knowingly process data from anyone younger. If you believe a child under 16 has been using Daitoo, write to support@daitoo.app and we will delete whatever we hold.
Do you have to give us anything? No. Daitoo works without an account, and you are never required to provide personal data. Each feature needs the data described below to function — if you would rather not send it, switch that feature off, and the rest of the app keeps working.
Your lists, items, notes, their order and the phrasings Daitoo has learned stay on your device.
On iPhone, they sync through your own private iCloud. That is Apple's service to you, under your iCloud settings and Apple's privacy policy — the data does not pass through our servers and we cannot see it. On Android, they stay on the device.
The phrase memory never leaves your device. It stores a cryptographic fingerprint of each phrase together with the emoji, not the phrase itself.
This data stays until you delete the list, the item or the app.
This runs only for a new phrase Daitoo has not seen before.
Sent to our server: the item's title line (never the note), your device language and region, and the list name.
What happens: our server passes it to OpenAI's language model, which returns an emoji.
What we keep: a cryptographic fingerprint (hash) of the request together with the emoji. We do not keep the wording, the list name, or any link to you or your device.
Purpose: providing the feature.
Legal basis: performance of the contract, Art. 6(1)(b) GDPR.
How long we keep the hash. Indefinitely, as a lookup cache. A hash is a one-way fingerprint: it contains no wording, no list name and no link to you or your device, so it cannot be traced back to a person. Keeping it is what lets the same phrase return the same emoji later without a second request to OpenAI — it means less data sent, not more.
Sent to our server: the items on the list — their titles and their notes — together with the list's name and your device language, when you have switched automatic sorting on.
What happens: our server passes them to Jev, a model made by TypeSafe AI and reached through the Vercel AI Gateway. Jev is not a language model and writes no text: it scores where each item belongs, and our server turns those scores into an order. For a kind of list it has no ordering scheme for, our server asks OpenAI's language model instead.
What we keep: nothing. The items are used for that one request and are not written to storage.
Purpose: providing the feature.
Legal basis: performance of the contract, Art. 6(1)(b) GDPR.
Both routes run under zero data retention: neither the gateway nor the model provider keeps the request after answering it, and neither uses it to train anything.
Sent to our server: the photograph you choose.
What happens: a language model reads it and returns the items it found.
What we keep: nothing. The image stays in the server's memory for that one request and then it is gone. It is not written to storage at either end, and there is no background retry.
Purpose: providing the feature.
Legal basis: performance of the contract, Art. 6(1)(b) GDPR.
Before Daitoo opens the camera or your photo library, it reminds you that a photograph carries more than the text on it — a till receipt shows the shop, the date and the last digits of a payment card, and the image may carry location and time information.
Stored on our server: the list and its items — titles, notes, emoji, order and completion times — so that everyone you invited can see them.
Also stored: a randomly generated user identifier and device identifier, not linked to any name, email address or account; invitation tokens, valid once and expiring after 24 hours; and tombstones for deleted items, which carry no wording and expire after 30 days.
Purpose: providing the sharing feature.
Legal basis: performance of the contract, Art. 6(1)(b) GDPR.
Leaving a shared list removes you from it. When the last member leaves, the list and its items are deleted from our server.
Two parts of Daitoo can carry information about people who are not you.
Shared lists. When you invite someone, their randomly generated identifier and whatever you write about them on that list sit on our server. We have no name, email address or account for them, and no way to contact them — so we cannot give them a privacy notice directly. This is the situation Art. 14(5)(b) GDPR describes: providing the information would require disproportionate effort, because we would have to identify people we have deliberately built the system not to identify. This policy, published openly, is how we make that information available instead.
Photographs. A photo you scan may contain another person's information — a name on a receipt, a handwritten note, someone else's shopping list. It goes to OpenAI along with the rest of the image and comes back as text. We do not store it, but we cannot filter it out either.
What this means for you. When you put someone else's personal data into a shared list or a scanned photo, you decide to do that, and you need a legal basis for it — usually because they know and agree, or because it is your own household activity. Please do not put other people's sensitive information, identity documents or payment details into Daitoo. This is also set out in our Terms of Use, §6.3 and §6.4.
Once when the app starts, it says hello to our server.
Recorded, against random identifiers only: the Daitoo version and build, the device type and operating system version (for example iPhone16,1 on 26.0), and your device language setting.
Not involved: any list, item or anything you have written.
Purpose: knowing which versions and devices are actually in use, so we can operate and maintain the service and decide what to keep supporting.
Legal basis: our legitimate interest in operating and maintaining the service, Art. 6(1)(f) GDPR. We keep no content and no identifying data, so the effect on you is minimal, and there is no practical way to maintain an app without knowing what it runs on.
The entry is overwritten each time and deleted one year after the last check-in.
Your device proves that it is running a real copy of Daitoo, without any account. On iOS this uses Apple's App Attest; on Android, Google's Play Integrity API. Apple and Google are involved in that check, under their own privacy policies.
What we keep: on iOS, the device's public key and a counter; on Android, a short-lived session token valid for one hour.
Purpose: protecting the service from abuse and keeping costs from being run up by automated requests.
Legal basis: our legitimate interest in operating the service securely, Art. 6(1)(f) GDPR.
The public key and counter are deleted one year after the last check-in, together with the rest of that install's record.
Daitoo Pro is sold by the App Store or Google Play. Neither store tells us your name, your email address or your payment details.
RevenueCat checks entitlements for us, as our processor. It receives a random identifier from the app and the store receipt. Our backend asks it one question — does this identifier have a subscription? — and caches the yes/no answer for 15 minutes.
Purpose: giving you the features you have paid for.
Legal basis: performance of the contract, Art. 6(1)(b) GDPR.
No advertising. No advertising identifier. No analytics SDK. No tracking. No profiling. No location tracking. No access to your contacts. No sale of data to anyone, ever.
The app asks for camera access only when you use the photo scan, and asks for no other permission.
| What we do | Legal basis |
|---|---|
| Choosing an emoji | Contract — Art. 6(1)(b) GDPR |
| Sorting a list | Contract — Art. 6(1)(b) GDPR |
| Reading a list off a photo | Contract — Art. 6(1)(b) GDPR |
| Sharing a list | Contract — Art. 6(1)(b) GDPR |
| Checking entitlement for Daitoo Pro | Contract — Art. 6(1)(b) GDPR |
| Checking in when the app starts | Legitimate interest — Art. 6(1)(f) GDPR |
| Proving the app is genuine | Legitimate interest — Art. 6(1)(f) GDPR |
| Website server logs | Legitimate interest — Art. 6(1)(f) GDPR |
| Analytics on this website | Consent — Art. 6(1)(a) GDPR |
| The contact form | Consent and our legitimate interest in replying — Art. 6(1)(a) and (f) GDPR |
Where we rely on a legitimate interest, you can object at any time — see section 13.
| What | How long |
|---|---|
| Lists, items and notes on your device | Until you delete them or the app |
| Emoji hash and its emoji | Indefinitely, as a lookup cache — see §4.2 |
| A sorting request | Not stored |
| A scanned photograph | Not stored — in memory for one request |
| A shared list and its items | Until the last member leaves, then deleted |
| Invitation tokens | 24 hours |
| Tombstones for deleted items | 30 days |
| Start-up check-in record | Overwritten each time, deleted 1 year after the last check-in |
| App Attest public key and counter | Deleted 1 year after the last check-in |
| Play Integrity session token | 1 hour |
| Subscription entitlement cache | 15 minutes |
| Website server logs | 24 hours |
| Website analytics data | 14 months |
| Contact-form emails | 12 months after the conversation ends |
| Who | What for | Where |
|---|---|---|
| Amazon Web Services | Hosting the backend and its database | Frankfurt, Germany (eu-central-1) |
| Vercel | Hosting this website | USA / Frankfurt, Germany |
| Vercel AI Gateway | Routing a sorting request to the model that answers it | USA |
| TypeSafe AI | Sorting a list, with its Jev model — reached through the Vercel AI Gateway | USA |
| OpenAI | Choosing an emoji, reading a photo, and sorting a list when Jev has no scheme for it | USA |
| Apple | App Attest, App Store | USA / EU |
| Play Integrity, Google Play, Analytics, reCAPTCHA | USA / EU | |
| RevenueCat | Whether an install has a subscription | USA / EU |
| Mailgun | Delivering contact-form emails | USA / EU |
Each of these processes data only on our instructions, under a data processing agreement.
iCloud is not on this list, on purpose. When your lists sync through iCloud, that is Apple's service to you under your own Apple account and Apple's privacy policy. The data does not reach us, and Apple is not acting on our behalf. The same goes for the App Store and Google Play as sellers of Daitoo Pro.
Our backend and database run in Frankfurt. Some of the providers above process data in the United States, or may do so.
For every transfer outside Switzerland and the EEA we rely on:
We also apply the additional measures these require: transport encryption throughout, no content stored at the AI providers, and pseudonymous identifiers rather than names or email addresses wherever the feature allows.
If you would like a copy of the safeguards for a particular provider, write to support@daitoo.app and we will send you what we have.
This site is hosted by Vercel and served from its Frankfurt region. Visiting it creates the usual web server log entries: IP address, time, page requested and browser identification.
Purpose: operating the site and keeping it secure.
Legal basis: our legitimate interest in a working, secure website, Art. 6(1)(f) GDPR.
Retention: 24 hours — that is how long our host keeps its runtime logs, and we copy them nowhere else.
We do not use these logs to identify you.
Until you accept the notice, this site sets no cookies other than strictly necessary ones.
If you accept, we use Google Analytics with IP anonymisation switched on, to see roughly how many people find the site and which pages they read.
Legal basis: your consent, Art. 6(1)(a) GDPR.
Retention: analytics data is deleted after 14 months.
Changing your mind. You can withdraw or change your consent at any time through the Cookie settings link in the footer of every page — it is exactly as easy as giving it was. Withdrawing does not affect processing that already happened.
| Cookie | Purpose | Duration |
|---|---|---|
| Consent preference | Remembers what you chose in the notice | 12 months |
_ga, _ga_* | Google Analytics — distinguishes visitors | 24 months |
| reCAPTCHA cookies | Google reCAPTCHA — spam protection on the contact form | Session to 6 months |
The form is protected by Google reCAPTCHA v3, which is why it is available only once you have accepted cookies. Google's terms and privacy policy apply to that check.
Your message reaches us by email through Mailgun.
Purpose: answering you.
Legal basis: your consent in sending the message, and our legitimate interest in replying, Art. 6(1)(a) and (f) GDPR.
Retention: 12 months after the conversation ends, so we can follow up sensibly. Then deleted.
We never use your address or message for advertising. You can always email support@daitoo.app directly instead, with no reCAPTCHA and no cookies.
Everything travels over encrypted connections. Our backend and database run in Frankfurt with access restricted to what is needed to operate the service. We store cryptographic fingerprints instead of wording wherever a feature allows it, random identifiers instead of names or email addresses, and nothing at all for the sorting and photo features. Device attestation keeps unauthorised clients off the backend.
We designed Daitoo so that the safest data is the data we never hold. Most of it never leaves your device.
If personal data we hold is breached and the breach is likely to result in a risk to your rights and freedoms, we will report it to the competent supervisory authority within 72 hours of becoming aware of it, as Art. 33 GDPR and Art. 24 FADP require. If the risk to you is high, we will tell you as well — in the app and on this site, since for most of Daitoo we have no way to email you.
Daitoo uses AI models to pick emoji, sort lists and read photographs. Those are suggestions about your list, not decisions about you.
We make no automated decisions producing legal effects concerning you or similarly significantly affecting you within the meaning of Art. 22 GDPR or Art. 21 FADP. We do no profiling. Nothing the model produces changes your rights, your pricing or your access to anything.
The model's output can be wrong — that is covered in §7 of our Terms of Use.
You have the right to:
Most of what Daitoo holds is in your hands: delete the list, leave the shared list, or delete the app, and it is gone.
How to exercise them. Write to support@daitoo.app. We reply within one month and it costs you nothing. Because Daitoo has no accounts, we may need you to tell us enough to identify the data you mean — the invitation link to a shared list, for example. We will not ask you for more identifying information than the request needs.
Complaints. You can complain to a supervisory authority: in Switzerland the Federal Data Protection and Information Commissioner (FDPIC), and in the EU the authority in your country.
There is no account to close, because there is no account.
We update this policy when the way Daitoo handles data changes. The date at the top always tells you when it last changed.
For material changes — a new sub-processor, a new legal basis, a new kind of data — we will also point them out in the app or on this site before they take effect, and we keep the previous versions so you can see what changed.
Übelacker Solutions GmbH
Bläsiring 28
4057 Basel
Switzerland