Legal

Privacy
Policy.

Your privacy matters to us. This policy explains what data we collect, how we use it, and the choices you have over your personal information within Daily Standard.

Last updated: 4 August 2026

1. Who we are

Daily Standard is operated by:

TA Solutions AB
Organisation number: 559542-3517
Formgatan 29, 216 45 Malmö, Sweden
Email: founder@dailystandard.io

TA Solutions AB is the data controller for the personal data described in this policy. This means we decide why and how your data is processed, and we are responsible for it under the EU General Data Protection Regulation (GDPR).

2. What data we collect

Information you give us

  • Your name and email address when you create an account
  • Any profile information you choose to add
  • The authentication method you use (email and password, Google, or Sign in with Apple). If you use Sign in with Apple and choose to hide your email, we receive only Apple's private relay address and never see your real one
  • Messages you send us for support

Information created as you use the app

  • Your reading and listening activity, saved favourites, and content preferences
  • Your daily streak, mission completions, and mission statistics
  • Custom missions you create
  • Reminder times you set

Information collected automatically

  • Device type, operating system version, app version, and language settings
  • A push notification token, if you enable reminders
  • Crash reports, including technical details about the state of the app when a crash occurred
  • Usage analytics such as which screens you open and how long sessions last
  • Your subscription status and purchase history, received from Apple or Google

We do not collect your precise location, we do not access your contacts, and we do not read your photo library. The app asks for photo permissions only if you choose to upload or save an image, and only for that purpose.

We never receive your payment card details. All purchases are handled by Apple or Google. We are told only whether a subscription is active.

3. Why we process your data, and on what legal basis

Under GDPR we must have a lawful basis for each purpose. Ours are:

What we doWhyLegal basis
Create and maintain your accountTo give you access to the appPerformance of a contract (Art. 6(1)(b))
Save your streaks, favourites and mission progressThese are core features of the servicePerformance of a contract
Deliver personalised content based on your chosen topicsYou asked for a personalised feedPerformance of a contract
Verify and manage your subscriptionTo provide the paid features you boughtPerformance of a contract
Send reminder notifications you have set upYou configured themPerformance of a contract
Respond to support requestsTo help youPerformance of a contract, and our legitimate interest in supporting users
Collect crash reportsTo find and fix faultsLegitimate interest in a working, reliable app (Art. 6(1)(f))
Protect against fraud, abuse and unauthorised accessTo keep the service and other users safeLegitimate interest in security
Analytics on how the app is usedTo understand what works and improve the appYour consent (Art. 6(1)(a))
Keep accounting records of purchasesRequired by Swedish lawLegal obligation (Art. 6(1)(c))

Where we rely on consent, you can withdraw it at any time in the app's settings, and doing so is as easy as giving it. Withdrawing consent does not affect processing that already took place.

Where we rely on legitimate interest, we have weighed our interest against your rights, and you have the right to object — see section 8.

4. Who we share data with

We do not sell your personal data. We do not rent or trade it, and we do not share it with advertisers.

We use a small number of service providers who process data on our behalf, under contracts that require them to protect it and use it only for the purposes we specify:

  • Google Ireland Limited / Google LLC — Firebase provides our database, user authentication, file storage, push notifications, crash reporting and analytics
  • RevenueCat, Inc. — manages subscription status across platforms
  • Apple Inc. and Google LLC — process purchases through the App Store and Google Play, and tell us whether a subscription is active

We may also disclose personal data where we are legally required to do so, for example in response to a valid order from a public authority, or where necessary to establish, exercise or defend legal claims.

If our business is ever sold or transferred, personal data may be transferred as part of that transaction. We would tell you before it happened and you would keep all the rights described here.

5. How long we keep data

  • Account data: for as long as your account exists
  • After you delete your account: removed within 30 days
  • Crash reports and analytics: up to 14 months
  • Accounting records relating to purchases: seven years, as required by the Swedish Accounting Act (bokföringslagen). This applies even if you delete your account, but is limited to transaction records
  • Support correspondence: up to two years after the matter is closed

6. Transfers outside the EU/EEA

Our database and other Firebase services are currently hosted in the United States, which is outside the EU/EEA.

The United States does not have an EU adequacy decision that applies automatically to all transfers. We rely on the following safeguards:

  • Standard Contractual Clauses approved by the European Commission, included in our data processing agreement with Google
  • Google LLC's self-certification under the EU-US Data Privacy Framework
  • Technical measures including encryption of data in transit and at rest

We recognise that the legal framework governing EU–US data transfers is subject to ongoing litigation and may change. You may request a copy of the relevant safeguards by emailing us at founder@dailystandard.io.

RevenueCat, Inc. is also based in the United States, and the same safeguards apply.

7. Security

We use technical and organisational measures to protect your data, including encryption in transit (TLS), encryption at rest, access controls limiting who can reach production data, and authentication managed by Google Firebase rather than by us directly. We do not store passwords ourselves.

No system is completely secure, and we cannot guarantee absolute security. If a personal data breach occurs that is likely to result in a high risk to your rights, we will notify you and the Swedish Authority for Privacy Protection (IMY) as required by law.

8. Your rights

Under GDPR you have the right to:

  • Access the personal data we hold about you, and receive a copy
  • Rectification of data that is inaccurate or incomplete
  • Erasure of your data ("the right to be forgotten"). You can delete your account and its data directly in the app's settings
  • Restriction of processing in certain circumstances
  • Data portability — receive your data in a structured, machine-readable format, or have it sent to another provider
  • Object to processing based on legitimate interest, including profiling
  • Withdraw consent at any time, where processing is based on consent

To exercise any of these rights, email founder@dailystandard.io. We will respond within one month. There is no charge unless a request is manifestly unfounded or excessive.

We do not carry out automated decision-making that produces legal effects concerning you.

If you are unhappy with how we handle your data, you have the right to lodge a complaint with a supervisory authority. In Sweden this is:

Integritetsskyddsmyndigheten (IMY)
Box 8114, 104 20 Stockholm
imy@imy.se — www.imy.se

If you live elsewhere in the EU/EEA you may complain to your local supervisory authority instead.

9. Children

Daily Standard is not intended for anyone under 16, and we do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, contact us at founder@dailystandard.io and we will delete it promptly.

10. Cookies and similar technologies

Daily Standard is a mobile application and does not use browser cookies. We do use device identifiers and similar technologies through Firebase for analytics and crash reporting, as described above. Analytics identifiers are pseudonymous rather than anonymous — they do not contain your name, but they can be linked to your device and are therefore treated as personal data under GDPR. You can turn analytics off in the app's settings.

11. Changes to this policy

We may update this policy. If we make material changes we will notify you in the app before they take effect, and where the law requires it we will ask for your consent. The date at the top shows when this version was published.

12. Contact

Questions, requests, or concerns about this policy:

TA Solutions AB
Formgatan 29, 216 45 Malmö, Sweden
founder@dailystandard.io

Privacy Queries

Contact Us.