Daitoo
FeaturesScreenshotsContactFAQHelpDownload
FeaturesScreenshotsContactFAQHelpDownload

Privacy Policy

Last updated: 22 September 2026

1. The short version

Daitoo has no accounts and no sign-up. There is no advertising, no advertising identifier, no analytics SDK in the app and no tracking.

Your lists stay on your device. Four things talk to our server: choosing an emoji, sorting a list, reading a list off a photo, and sharing a list. The app also says hello once when it starts, so we know which versions are in use. Only sharing a list puts anything you have written onto a server permanently.

We do not use anything you write to train machine-learning models. We do not sell your data. We never have.

If you put other people's information on a shared list or in a photo you scan, please read section 4.6 — that part is on you, and we explain why.

2. Who is responsible

Übelacker Solutions GmbH
Bläsiring 28
4057 Basel
Switzerland
support@daitoo.app

We are the controller for the processing described here, under the Swiss Federal Act on Data Protection (FADP) and, where it applies, the EU General Data Protection Regulation (GDPR).

Data protection officer. We have not appointed one. Daitoo's processing does not meet the conditions in Art. 37 GDPR — it is not a public authority, not large-scale regular monitoring, and not large-scale processing of special categories of data. If that changes, we will appoint one and say so here.

Representative in the EU. We have not appointed a representative under Art. 27 GDPR. We consider the exemption in Art. 27(2)(a) to apply: the processing described here is occasional, does not involve special categories of data or data relating to criminal convictions on any scale, and is unlikely to result in a risk to the rights and freedoms of individuals. You can reach us directly at the address and email above, in German, English, French or Spanish.

3. Who can use Daitoo

Daitoo is for people aged 16 and over. We do not knowingly process data from anyone younger. If you believe a child under 16 has been using Daitoo, write to support@daitoo.app and we will delete whatever we hold.

Do you have to give us anything? No. Daitoo works without an account, and you are never required to provide personal data. Each feature needs the data described below to function — if you would rather not send it, switch that feature off, and the rest of the app keeps working.

4. The app

4.1 What stays on your device

Your lists, items, notes, their order and the phrasings Daitoo has learned stay on your device.

On iPhone, they sync through your own private iCloud. That is Apple's service to you, under your iCloud settings and Apple's privacy policy — the data does not pass through our servers and we cannot see it. On Android, they stay on the device.

The phrase memory never leaves your device. It stores a cryptographic fingerprint of each phrase together with the emoji, not the phrase itself.

This data stays until you delete the list, the item or the app.

4.2 Choosing an emoji

This runs only for a new phrase Daitoo has not seen before.

Sent to our server: the item's title line (never the note), your device language and region, and the list name.
What happens: our server passes it to OpenAI's language model, which returns an emoji.
What we keep: a cryptographic fingerprint (hash) of the request together with the emoji. We do not keep the wording, the list name, or any link to you or your device.
Purpose: providing the feature.
Legal basis: performance of the contract, Art. 6(1)(b) GDPR.

How long we keep the hash. Indefinitely, as a lookup cache. A hash is a one-way fingerprint: it contains no wording, no list name and no link to you or your device, so it cannot be traced back to a person. Keeping it is what lets the same phrase return the same emoji later without a second request to OpenAI — it means less data sent, not more.

4.3 Sorting a list

Sent to our server: the items on the list — their titles and their notes — together with the list's name and your device language, when you have switched automatic sorting on.
What happens: our server passes them to Jev, a model made by TypeSafe AI and reached through the Vercel AI Gateway. Jev is not a language model and writes no text: it scores where each item belongs, and our server turns those scores into an order. For a kind of list it has no ordering scheme for, our server asks OpenAI's language model instead.
What we keep: nothing. The items are used for that one request and are not written to storage.
Purpose: providing the feature.
Legal basis: performance of the contract, Art. 6(1)(b) GDPR.

Both routes run under zero data retention: neither the gateway nor the model provider keeps the request after answering it, and neither uses it to train anything.

4.4 Reading a list off a photo

Sent to our server: the photograph you choose.
What happens: a language model reads it and returns the items it found.
What we keep: nothing. The image stays in the server's memory for that one request and then it is gone. It is not written to storage at either end, and there is no background retry.
Purpose: providing the feature.
Legal basis: performance of the contract, Art. 6(1)(b) GDPR.

Before Daitoo opens the camera or your photo library, it reminds you that a photograph carries more than the text on it — a till receipt shows the shop, the date and the last digits of a payment card, and the image may carry location and time information.

4.5 Sharing a list

Stored on our server: the list and its items — titles, notes, emoji, order and completion times — so that everyone you invited can see them.
Also stored: a randomly generated user identifier and device identifier, not linked to any name, email address or account; invitation tokens, valid once and expiring after 24 hours; and tombstones for deleted items, which carry no wording and expire after 30 days.
Purpose: providing the sharing feature.
Legal basis: performance of the contract, Art. 6(1)(b) GDPR.

Leaving a shared list removes you from it. When the last member leaves, the list and its items are deleted from our server.

4.6 Other people's data — on shared lists and in photos

Two parts of Daitoo can carry information about people who are not you.

Shared lists. When you invite someone, their randomly generated identifier and whatever you write about them on that list sit on our server. We have no name, email address or account for them, and no way to contact them — so we cannot give them a privacy notice directly. This is the situation Art. 14(5)(b) GDPR describes: providing the information would require disproportionate effort, because we would have to identify people we have deliberately built the system not to identify. This policy, published openly, is how we make that information available instead.

Photographs. A photo you scan may contain another person's information — a name on a receipt, a handwritten note, someone else's shopping list. It goes to OpenAI along with the rest of the image and comes back as text. We do not store it, but we cannot filter it out either.

What this means for you. When you put someone else's personal data into a shared list or a scanned photo, you decide to do that, and you need a legal basis for it — usually because they know and agree, or because it is your own household activity. Please do not put other people's sensitive information, identity documents or payment details into Daitoo. This is also set out in our Terms of Use, §6.3 and §6.4.

4.7 Checking in when the app starts

Once when the app starts, it says hello to our server.

Recorded, against random identifiers only: the Daitoo version and build, the device type and operating system version (for example iPhone16,1 on 26.0), and your device language setting.
Not involved: any list, item or anything you have written.
Purpose: knowing which versions and devices are actually in use, so we can operate and maintain the service and decide what to keep supporting.
Legal basis: our legitimate interest in operating and maintaining the service, Art. 6(1)(f) GDPR. We keep no content and no identifying data, so the effect on you is minimal, and there is no practical way to maintain an app without knowing what it runs on.

The entry is overwritten each time and deleted one year after the last check-in.

4.8 Proving that the app is genuine

Your device proves that it is running a real copy of Daitoo, without any account. On iOS this uses Apple's App Attest; on Android, Google's Play Integrity API. Apple and Google are involved in that check, under their own privacy policies.

What we keep: on iOS, the device's public key and a counter; on Android, a short-lived session token valid for one hour.
Purpose: protecting the service from abuse and keeping costs from being run up by automated requests.
Legal basis: our legitimate interest in operating the service securely, Art. 6(1)(f) GDPR.

The public key and counter are deleted one year after the last check-in, together with the rest of that install's record.

4.9 Your subscription

Daitoo Pro is sold by the App Store or Google Play. Neither store tells us your name, your email address or your payment details.

RevenueCat checks entitlements for us, as our processor. It receives a random identifier from the app and the store receipt. Our backend asks it one question — does this identifier have a subscription? — and caches the yes/no answer for 15 minutes.
Purpose: giving you the features you have paid for.
Legal basis: performance of the contract, Art. 6(1)(b) GDPR.

4.10 What the app never does

No advertising. No advertising identifier. No analytics SDK. No tracking. No profiling. No location tracking. No access to your contacts. No sale of data to anyone, ever.

The app asks for camera access only when you use the photo scan, and asks for no other permission.

5. Legal bases at a glance

What we doLegal basis
Choosing an emojiContract — Art. 6(1)(b) GDPR
Sorting a listContract — Art. 6(1)(b) GDPR
Reading a list off a photoContract — Art. 6(1)(b) GDPR
Sharing a listContract — Art. 6(1)(b) GDPR
Checking entitlement for Daitoo ProContract — Art. 6(1)(b) GDPR
Checking in when the app startsLegitimate interest — Art. 6(1)(f) GDPR
Proving the app is genuineLegitimate interest — Art. 6(1)(f) GDPR
Website server logsLegitimate interest — Art. 6(1)(f) GDPR
Analytics on this websiteConsent — Art. 6(1)(a) GDPR
The contact formConsent and our legitimate interest in replying — Art. 6(1)(a) and (f) GDPR

Where we rely on a legitimate interest, you can object at any time — see section 13.

6. How long we keep things

WhatHow long
Lists, items and notes on your deviceUntil you delete them or the app
Emoji hash and its emojiIndefinitely, as a lookup cache — see §4.2
A sorting requestNot stored
A scanned photographNot stored — in memory for one request
A shared list and its itemsUntil the last member leaves, then deleted
Invitation tokens24 hours
Tombstones for deleted items30 days
Start-up check-in recordOverwritten each time, deleted 1 year after the last check-in
App Attest public key and counterDeleted 1 year after the last check-in
Play Integrity session token1 hour
Subscription entitlement cache15 minutes
Website server logs24 hours
Website analytics data14 months
Contact-form emails12 months after the conversation ends

7. Sub-processors

WhoWhat forWhere
Amazon Web ServicesHosting the backend and its databaseFrankfurt, Germany (eu-central-1)
VercelHosting this websiteUSA / Frankfurt, Germany
Vercel AI GatewayRouting a sorting request to the model that answers itUSA
TypeSafe AISorting a list, with its Jev model — reached through the Vercel AI GatewayUSA
OpenAIChoosing an emoji, reading a photo, and sorting a list when Jev has no scheme for itUSA
AppleApp Attest, App StoreUSA / EU
GooglePlay Integrity, Google Play, Analytics, reCAPTCHAUSA / EU
RevenueCatWhether an install has a subscriptionUSA / EU
MailgunDelivering contact-form emailsUSA / EU

Each of these processes data only on our instructions, under a data processing agreement.

iCloud is not on this list, on purpose. When your lists sync through iCloud, that is Apple's service to you under your own Apple account and Apple's privacy policy. The data does not reach us, and Apple is not acting on our behalf. The same goes for the App Store and Google Play as sellers of Daitoo Pro.

8. Where data goes, and how it is protected

Our backend and database run in Frankfurt. Some of the providers above process data in the United States, or may do so.

For every transfer outside Switzerland and the EEA we rely on:

  • the European Commission's Standard Contractual Clauses, together with the Swiss addendum recognised by the Federal Data Protection and Information Commissioner, and
  • where the provider is certified under it, the EU–US Data Privacy Framework and its Swiss–US extension, and
  • an adequacy decision where one covers the country concerned.

We also apply the additional measures these require: transport encryption throughout, no content stored at the AI providers, and pseudonymous identifiers rather than names or email addresses wherever the feature allows.

If you would like a copy of the safeguards for a particular provider, write to support@daitoo.app and we will send you what we have.

9. This website

9.1 Hosting and server logs

This site is hosted by Vercel and served from its Frankfurt region. Visiting it creates the usual web server log entries: IP address, time, page requested and browser identification.

Purpose: operating the site and keeping it secure.
Legal basis: our legitimate interest in a working, secure website, Art. 6(1)(f) GDPR.
Retention: 24 hours — that is how long our host keeps its runtime logs, and we copy them nowhere else.

We do not use these logs to identify you.

9.2 Cookies and analytics

Until you accept the notice, this site sets no cookies other than strictly necessary ones.

If you accept, we use Google Analytics with IP anonymisation switched on, to see roughly how many people find the site and which pages they read.

Legal basis: your consent, Art. 6(1)(a) GDPR.
Retention: analytics data is deleted after 14 months.

Changing your mind. You can withdraw or change your consent at any time through the Cookie settings link in the footer of every page — it is exactly as easy as giving it was. Withdrawing does not affect processing that already happened.

CookiePurposeDuration
Consent preferenceRemembers what you chose in the notice12 months
_ga, _ga_*Google Analytics — distinguishes visitors24 months
reCAPTCHA cookiesGoogle reCAPTCHA — spam protection on the contact formSession to 6 months

9.3 The contact form

The form is protected by Google reCAPTCHA v3, which is why it is available only once you have accepted cookies. Google's terms and privacy policy apply to that check.

Your message reaches us by email through Mailgun.

Purpose: answering you.
Legal basis: your consent in sending the message, and our legitimate interest in replying, Art. 6(1)(a) and (f) GDPR.
Retention: 12 months after the conversation ends, so we can follow up sensibly. Then deleted.

We never use your address or message for advertising. You can always email support@daitoo.app directly instead, with no reCAPTCHA and no cookies.

10. How we keep things safe

Everything travels over encrypted connections. Our backend and database run in Frankfurt with access restricted to what is needed to operate the service. We store cryptographic fingerprints instead of wording wherever a feature allows it, random identifiers instead of names or email addresses, and nothing at all for the sorting and photo features. Device attestation keeps unauthorised clients off the backend.

We designed Daitoo so that the safest data is the data we never hold. Most of it never leaves your device.

11. If something goes wrong

If personal data we hold is breached and the breach is likely to result in a risk to your rights and freedoms, we will report it to the competent supervisory authority within 72 hours of becoming aware of it, as Art. 33 GDPR and Art. 24 FADP require. If the risk to you is high, we will tell you as well — in the app and on this site, since for most of Daitoo we have no way to email you.

12. No automated decisions about you

Daitoo uses AI models to pick emoji, sort lists and read photographs. Those are suggestions about your list, not decisions about you.

We make no automated decisions producing legal effects concerning you or similarly significantly affecting you within the meaning of Art. 22 GDPR or Art. 21 FADP. We do no profiling. Nothing the model produces changes your rights, your pricing or your access to anything.

The model's output can be wrong — that is covered in §7 of our Terms of Use.

13. Your rights

You have the right to:

  • know what personal data we process about you, and get a copy;
  • have it corrected if it is wrong;
  • have it deleted;
  • restrict how we process it;
  • object to processing based on our legitimate interest — including the start-up check-in and app attestation;
  • receive it in a portable format, and have it sent to someone else where that is technically possible;
  • withdraw your consent at any time, where we rely on it, without affecting what happened before.

Most of what Daitoo holds is in your hands: delete the list, leave the shared list, or delete the app, and it is gone.

How to exercise them. Write to support@daitoo.app. We reply within one month and it costs you nothing. Because Daitoo has no accounts, we may need you to tell us enough to identify the data you mean — the invitation link to a shared list, for example. We will not ask you for more identifying information than the request needs.

Complaints. You can complain to a supervisory authority: in Switzerland the Federal Data Protection and Information Commissioner (FDPIC), and in the EU the authority in your country.

14. Deleting your data

  • On your device: delete the list or the item, or delete the app.
  • On a shared list: leave it. You are removed. When the last member leaves, the list and everything on it are deleted from our server.
  • Everything else: write to support@daitoo.app. Tell us what you would like deleted and we will do it within 30 days, unless the law requires us to keep something — and if it does, we will tell you what and why.

There is no account to close, because there is no account.

15. Changes to this policy

We update this policy when the way Daitoo handles data changes. The date at the top always tells you when it last changed.

For material changes — a new sub-processor, a new legal basis, a new kind of data — we will also point them out in the app or on this site before they take effect, and we keep the previous versions so you can see what changed.

16. Contact

support@daitoo.app

Übelacker Solutions GmbH
Bläsiring 28
4057 Basel
Switzerland

Who is Mochi? | Animal welfare
© 2026 Übelacker Solutions GmbH
Imprint | Privacy Policy | Terms of Use |
Deutsch | Español | Français