Privacy Policy

Effective September 1, 2026. Last updated September 1, 2026.

Daily Blocks is a personal routine app. It stores the routines you build and the days you run so they sync across your devices. It does not sell your data, does not show ads, and does not track you across other apps or websites.

The short version

Who we are

Daily Blocks is developed and operated by Jason Mancuso ("we", "us"), the data controller for the information described here. You can reach us any time at dailyblocksroutine@gmail.com.

What we collect and why

DataWhyWhere it lives
Email address
and display name, if you provide one
To create and secure your account, sign you in, and let you recover access. If you use Sign in with Apple and choose to hide your email, we only ever receive Apple's private relay address. Firebase Authentication
Content you create
tasks, blocks, routines, goals, categories, benefits, notes, tips, favorites, daily logs, streaks, sleep times
This is the app. It is stored so your routines sync across your devices and are not lost if you replace your phone. Cloud Firestore, plus an offline cache on your device
Health & fitness sessions
workout and mindfulness sessions: name, source app, start and end time, duration
Only if you explicitly grant Apple Health access and opt a task in. A matching session marks that task complete. We read only workouts and mindful minutes, and only for the current day. Read from Apple Health on your device; the matched session is saved to your day log in Cloud Firestore
Usage analytics
screen views, feature events, and your device's vendor identifier (IDFV)
To understand which parts of the app are used and where people get stuck, so we can improve them. Events record structure ("a routine was saved", "the Progress tab was opened"), never the names, notes, or text you type. Google Analytics for Firebase
Diagnostics
crash and error signals
To find and fix bugs. Firebase / Apple, as applicable

What we deliberately do not collect

Apple Health

The Health integration is off until you turn it on, and even then it applies only to tasks you individually opt in. Specifically:

Where your data is stored

Daily Blocks runs on Google Firebase (Firebase Authentication, Cloud Firestore, and Google Analytics for Firebase). Data is stored on Google Cloud infrastructure, primarily in the United States. Google acts as our processor and is bound by the Firebase Data Processing and Security Terms.

Your Firestore records are protected by security rules that allow only your own authenticated account to read or write them. As additional defense, the app uses Apple's App Attest via Firebase App Check, so the backend can reject requests that do not come from a genuine, unmodified copy of the app.

A copy of your data is also cached locally on your device so the app works offline and opens instantly. Deleting the app removes that local cache.

How long we keep it

We keep your account data for as long as your account exists. When you delete your account, your authentication record and your Firestore documents are deleted. Analytics events are retained by Google Analytics under its own retention window (currently 14 months) and are not tied to your account once it is deleted. Backups and logs may persist for a short period before they age out.

Your choices and rights

Depending on where you live, you may have additional rights, to access, correct, port, restrict, or object to processing of your personal data (GDPR/UK GDPR), or to know about and delete your personal information and to not be discriminated against for exercising those rights (CCPA/CPRA). We honour these for everyone, not just where required. We do not sell or share personal information as those terms are defined by the CCPA/CPRA. To make a request, email dailyblocksroutine@gmail.com; we respond within 30 days.

Our legal bases for processing under GDPR are performance of a contract (providing the account and sync you signed up for), consent (Apple Health, and notifications), and legitimate interests (keeping the service secure and understanding aggregate product usage).

Children

Daily Blocks is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has created an account, email us and we will delete it.

Security

Traffic is encrypted in transit (TLS) and data is encrypted at rest by Google Cloud. Access is restricted by per-user Firestore security rules and device attestation. No system is perfect; if we ever become aware of a breach affecting your data, we will notify you and any required regulator without undue delay.

Changes

If we change this policy, we will update the date at the top and, for material changes, notify you in the app before the change takes effect.

Contact

Questions, requests, or concerns: dailyblocksroutine@gmail.com.