dayrunner ↗Sign in

DAYRUNNER / POLICIES

Cookies and device storage

Policy version: 2026-09-08

Dayrunner uses an essential Flask session cookie for signed-in sessions, form security and temporary messages. It is configured as HttpOnly, SameSite=Lax and Secure on HTTPS deployments. It is normally a browser-session cookie; browser session restoration may preserve it.

Local storage remembers your chosen theme (dr-theme), home-screen prompt dismissal (ios-install-dismissed) and privacy choice (dr-privacy-v1). The privacy choice expires after 180 days or a policy-version change. Other preferences remain until you clear browser storage.

Optional analytics

When enabled and accepted, Dayrunner sends a count for a public page to its own server. It uses no analytics cookie or third-party analytics script. It sends no private page paths, account identifiers or advertising IDs. The server receives the normal network request, but the analytics table stores only the day, public page and count. Declining analytics does not affect your account or payments. A browser Global Privacy Control signal disables these counts.

External services

Fonts, icon styles and styling libraries load from external providers. These requests may disclose network information even if analytics is declined. Stripe Checkout and Stripe account pages are separate services with their own cookie notices. Dayrunner's preference controls do not change those providers' settings.

Business contact

Service operator: DayRunner.

For privacy requests, accessibility assistance and billing questions: support@dayrunner.co.