Dayworth AI · Last updated 27 August 2026
Dayworth AI is a field-sales planning app. It holds the list of businesses you visit, what you did on each visit, where you drove, and, if you use the assistant, the questions you ask it. That is commercially sensitive information, and this page explains plainly what happens to it.
This is deliberate. Dayworth AI's users are field-sales reps, and some of them compete with one another, including, potentially, with us. You should not have to trust that we won't look at your pipeline. We have built it so that we can't.
The trade-off is real: your password is the key, so a password reset restores access to your account, not to your data. If no device of yours still holds your territory, the backup cannot be recovered by anyone, including us.
Dayworth AI is operated by Dayworth LLC ("Dayworth AI", "we"), a Texas limited liability company. For privacy questions, contact privacy@dayworth.ai.
| What | Why |
|---|---|
| Email address and password | To create and secure your account. Passwords are hashed by Google Firebase Authentication; we never see the plaintext. |
| Google account name and email (if you sign in with Google) | To identify your account. We do not receive your Google password. |
| Your accounts and prospects: business names, addresses, phone numbers, websites, industry, tier, notes | This is the core of the product: the list of places you visit. |
| Contacts at those businesses: names, job roles, notes | So the app can tell you whether the right person is likely to be there. See §4 on other people's data. |
| Visit records: dates, what you logged, next steps, quotes, photos you attach | Visit history and reporting. |
| Setup answers: what you sell, what you're optimising for | To tune which accounts the app ranks highest. |
| What | Why |
|---|---|
| Location: your device's coordinates, only while the app is open on screen | To sort accounts by distance, plan routes from where you are, and record mileage. Only with your permission, which your phone asks for and you can revoke at any time. See §3a for exactly when this does and does not happen. |
| Trip and mileage records | Mileage logs and deduction reports. |
| Assistant usage: number of questions, tokens consumed, resulting cost | To enforce plan limits and bill correctly. We record the size of each request; the content is covered in §5. |
| Basic technical data: IP address, browser and device type, error logs | Security, abuse prevention, and fixing crashes. |
We do not use advertising trackers, third-party analytics, or cross-site cookies. We do not sell personal information, and we do not share it for cross-context behavioural advertising.
Location is the most sensitive thing Dayworth AI touches, so this section says exactly what happens rather than summarising it. What Dayworth AI can do depends on how you use it, so it is split by that.
Used from a browser, Dayworth AI reads your location only while the app is open and on screen. When you lock your phone or switch apps, the browser suspends the page and location reading stops. This is enforced by your phone's operating system, not by our good intentions. A web page is not permitted to track you in the background, and Dayworth AI cannot do so however it is configured.
The Dayworth AI app for iPhone and Android can log drives with the app closed and the screen off, so your mileage deduction records itself. This is the one capability a browser cannot provide, and it is handled as follows:
Status as of 9 August 2026: the installed app has not been released yet. Today Dayworth AI is browser-only, so the first section above is the one that applies to you. This section is published in advance so the behaviour is on the record before the feature exists, not after.
Your position and trip history are stored on your device — in the clear, so the passcode on your phone is what protects them — and, if you sync, uploaded as ciphertext we cannot read (§3). Coordinates of route stops, not names and not notes, are sent to our routing provider to calculate driving times. Your location trail is never sent to us in readable form, in either mode.
Switch off automatic drive detection in the app, or revoke the location permission in your phone's settings. Distance sorting and automatic mileage stop working; nothing else does, and you can still log trips by hand. Trips already recorded stay yours. Export or delete them at any time (§8).
Your data is encrypted on your device with AES-256-GCM before it is uploaded. The key is derived from your account password using PBKDF2 (310,000 iterations) over a per-account salt, and is never transmitted or stored — each of your devices derives the same key from the password you type when you sign in. What reaches our servers is ciphertext and a salt, which is not secret.
A consequence worth stating: resetting a forgotten password restores access to your account, not to the backup encrypted under the old password. A new password derives a new key, and the stored ciphertext will not open under it. If you still have a device with your territory on it, that device simply replaces the unreadable backup the next time it syncs; if you do not, the backup cannot be recovered, by you or by us.
The copy held on your own device is not encrypted unless you turn on the Face ID lock. The lock is off by default. With it off, anyone who can unlock your phone can read what is on it — keep a passcode on the device. Turning it on (Account › Security) encrypts the on-device copy with AES-256-GCM under a random key that your device's biometric check (Face ID, Touch ID or the platform equivalent) releases; your account password can release it too, so a failed biometric never locks you out. Earlier versions used a device PIN instead; that was removed in August 2026 because forgetting it locked reps out of their own territories with no way back — the Face ID lock has no PIN, and your password remains the way back in. What we hold is ciphertext either way, and that has not changed.
What this means in practice: nobody at Dayworth AI can read your account names, addresses, contacts, notes or visit history. Not to provide support, not under commercial pressure, and not if compelled. We cannot produce what we cannot decrypt. If our database were breached tomorrow, the attacker would get an opaque blob.
The ciphertext is held on Google Cloud infrastructure in the United States, additionally encrypted in transit (TLS) and at rest, and locked to your account by database security rules.
A copy also lives on your own device so the app works with no signal. Unless you have turned on the Face ID lock, that copy is not encrypted — see above — and a lost or stolen phone is protected by the phone's own passcode, not by us. With the lock on, that copy is encrypted and the phone asks for your biometric before opening it.
What we can see: your email address, when you signed in, how many assistant questions you asked and what they cost, and basic technical logs. We need these to run and bill the service. None of them reveal who your customers are.
Much of what you put into Dayworth AI is information about other people: the buyer at a distribution company, the maintenance manager at a plant. In data-protection terms, you decide what to collect about them and why; Dayworth AI processes it on your instructions.
Practically, that means you are responsible for having a legitimate business reason to hold those details, and for honouring requests from those individuals about their data. We will help you locate, export, correct, or delete anything in your account so you can meet those obligations. If you are subject to GDPR or similar law, ask us for a data processing agreement.
Please do not store special categories of data in Dayworth AI, such as health information, government identifiers, payment card numbers, or anything about a person's race, religion, politics, or sexuality. The app is not designed for it.
The assistant is the one place your data leaves your device in readable form, and only the part needed to answer the question you asked, only when you ask it, and only for as long as the answer takes.
When you use it, your question and the relevant slice of your accounts are decrypted on your device and sent to xAI, which operates the Grok model that answers it. We pass it through; we do not store it. If you never use the assistant, nothing readable ever leaves your phone.
You can dictate a visit note instead of typing it. This section says exactly where your voice goes, because the answer is not "nowhere".
Don't use the button. Type instead. Nothing else in the app changes. Your phone's microphone permission can also be revoked in its settings, which stops this working while leaving the rest of Dayworth AI untouched.
Speaking is quicker than typing, which makes it easy to record more than you would have written: a person's mood, health, or family circumstances. §4 still applies: hold only what you have a legitimate business reason to hold, and keep special categories of personal data out of Dayworth AI entirely.
We use a small number of sub-processors. Each one receives only what it needs.
| Company | What it does | What it receives |
|---|---|---|
| Google (Firebase, Cloud) | Hosting, sign-in, database | Account details and app data |
| xAI | The AI assistant | Your questions and relevant account data |
| Stripe | Subscription payments | Email and billing details. Card numbers go to Stripe directly and never reach our servers. |
| OSRM / Mapbox | Driving times and routes | Coordinates of your stops, not names or notes |
| OpenStreetMap, CARTO, Nominatim | Map tiles and address lookup | Addresses you geocode, map areas you view |
| Overpass | Finding nearby businesses | The area you're searching in |
| Salesforce | CRM sync, only if you connect it | Whatever you choose to sync |
Depending on where you live, you may have rights to access, correct, delete, or port your data, to object to processing, and not to be discriminated against for exercising them. Email privacy@dayworth.ai and we will respond within 30 days. We will not charge you or degrade your service for asking.
Encryption in transit and at rest; per-account isolation enforced in the database; secrets held in a dedicated key manager and never in our source code; a strict content security policy in the browser; and an optional Face ID lock that encrypts the copy on your own device (§3).
No system is perfectly secure. If personal data is breached, we will notify affected users without undue delay and within 72 hours where the law requires it, telling you what happened, what was affected, and what to do.
Dayworth AI is a business tool and is not directed at anyone under 18. We do not knowingly collect data from children.
Data is processed in the United States. If you use Dayworth AI from outside the US, you are sending your data to the US, where privacy law differs from your own. For transfers of personal data out of the EEA or UK, we rely on Standard Contractual Clauses with our sub-processors.
If we change this policy in a way that materially affects you, we will email you and show a notice in the app at least 14 days before it takes effect. The date at the top always reflects the current version.