Privacy Policy
Last updated: June 3, 2026
This Privacy Policy explains how The Daily OKR (“we”, “us”) collects, uses, and protects information when you use the service. The Daily OKR is open-source software; if you access a self-hosted instance operated by your own organisation, that organisation is the controller of your data and its own policy governs — this policy covers the instance we operate at thedailyokr.com.
Information we collect
- Account & directory data — your name, work email, job title, department, manager relationship, and preferred language. These are provisioned by your organisation’s administrator (e.g. via a directory import), not by self-signup.
- Authentication data — if you sign in with a magic link we process your email to deliver it; if you sign in with Google we receive your Google account’s email and basic profile to verify your identity. We do not receive your Google password.
- OKR content — the objectives, key results, weekly check-ins, and related notes you create in the service.
- Messaging identifiers — where you enable a channel, the identifiers needed to reach you (e.g. Slack, Telegram, or WhatsApp IDs).
- Operational logs — audit and diagnostic records (such as sign-ins and administrative actions) used to operate and secure the service.
How we use information
- To provide the service: run check-ins, display OKRs, and route notifications.
- To generate AI feedback on your check-ins and OKRs (see “AI processing” below).
- To secure, maintain, and improve the service, and to comply with legal obligations.
We do not sell your personal information, and we do not use your OKR content to advertise to you.
AI processing
To produce coaching feedback, the text of your check-ins and the relevant OKR context is sent to the large-language-model provider configured for the instance (for example Anthropic, OpenAI, or a self-hosted model). That provider processes the content to return feedback and, per their terms, does not use it to train their models in the configurations we use. AI feedback is assistive and may be inaccurate; it is not a substitute for human judgement.
Service providers
We share data with vendors only as needed to run the service — for example hosting, database, transactional email, the configured LLM provider, and any messaging channels you enable. These providers process data on our instructions.
Google user data
When you choose “Continue with Google”, we use the email and basic profile Google returns solely to authenticate you and match you to your existing account. We do not use Google data for advertising, and our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Data retention
We retain your information for as long as your account is active or as needed to provide the service. When your organisation removes your account, associated personal data is deleted or anonymised within a reasonable period, except where retention is required for legal, security, or audit purposes.
Your choices
- You can opt out of non-essential email (e.g. reply STOP to a notification email).
- You may request access to, correction of, or deletion of your personal data by contacting us or your organisation’s administrator.
Security
We use reasonable technical and organisational measures to protect your data, including access controls and encryption in transit. No method of transmission or storage is perfectly secure.
Changes
We may update this policy from time to time. Material changes will be reflected by the “last updated” date above.
Contact
Questions about this policy? Email contact@thedailyokr.com.
