Privacy policy
Effective 30 August 2026
The short version
- Diurnal requires an account: Google, or email and password.
- Your tasks, tags and settings sync between your Macs.
- Your day is kept on your Mac, so it works offline.
- Google Calendar is optional and separate from signing in.
- Nothing is sold or used for advertising.
- Signing out empties that Mac.
Exact scopes and hosts: Data & permissions.
What is collected
- Account identity. The Google identifier or email address you signed in with.
- Your content. The tasks, tags and settings you create.
- Server logs. Request timing and errors, the ordinary records of running a service.
- If you connect a calendar: authorisation tokens, and the events for the days on screen.
Each exists to deliver a feature you asked for. None of it builds a profile or serves advertising.
Calendar data
Used for one thing: showing your events beside your tasks, and creating one when you ask. It is not analysed, mined, used to train anything, or shared.
Diurnal requests the narrowest Google scopes that do that; the list and the reasoning are on Data & permissions.
Diurnal’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
How long it is kept
- Local data: until you sign out.
- Synced content: while your account exists.
- Calendar tokens: until you disconnect the account or revoke access at Google.
- Server logs: a limited period, then discarded.
Product analytics
Diurnal records which features are used, so that the parts people rely on get better and the parts nobody opens can be removed. It is handled by Mixpanel, acting on instructions.
What that means precisely:
- Events name a feature, never its contents. A record says that a task was captured, a reminder fired, or the week board was opened. The words you type, your notes, your tags and your event titles are never part of it.
- It is tied to an account id, which is a random identifier, and no longer to your name or your email address. Both were sent until 22 September 2026 and both were removed on that date.
- This website counts page views and which buttons are pressed. A reader who has not signed in is not identified at all, and nothing here asks for a cookie.
- It can be switched off remotely without shipping a new version, which is how a problem gets stopped quickly rather than at the next release.
There is no in-app setting to turn this off yet. That is a gap rather than a position, and it is being worked on.
How it is protected
Encrypted in transit. Calendar tokens encrypted at rest. Every request is scoped to its own account.
Your choices
- Skip the calendar. It is a separate step, and declining it costs nothing.
- Disconnect it in Calendars settings, or revoke it at Google.
- Sign out to empty that Mac.
- Ask to see or delete the data held for your account.
Contact
Questions or requests: email yesitsanshul@gmail.com, naming the account. Diurnal is not directed at children. When this policy changes, the effective date above changes with it.