Legal

Privacy Policy

What we collect from your household, why, and the choices you have — written section by section to match what Lakeday actually does, not a generic template.

Effective: September 23, 2026Applies to: the Lakeday web dashboard, iOS app, and Android app

Lakeday is a product of The Hyytinen Group LLC, a Texas limited liability company (“Lakeday,” “we,” “us”), and provides a shared calendar, task, meal-planning, and household-organization service (the “Service”) to households in the United States. This policy explains what information we collect, how we use it, who we share it with, and the choices available to you.

1

Overview & scope

This policy covers the Lakeday web dashboard and the Lakeday iOS and Android apps, and is written for households located in the United States — see Section 11. It doesn't cover third-party sites you may reach by following a link from Lakeday — for example, a recipe's original source page, or a calendar provider's own consent screen — those are covered by that site's own policy.

Lakeday is a household product: one household subscription with an individual account for each adult member. Most of the information described below is entered directly by a household's primary member or another invited member, not collected passively.

2

Information we collect

2.1 Account & household information

When a household is created, we collect the primary member's name, email address, and a password (stored as a salted hash — we never store or can retrieve the plain password). If you sign in with Google, Apple, or Facebook instead, we receive the name and email address that provider shares, and a token that lets Lakeday keep working with that provider on your behalf — we never see or store your password with that provider. Additional household members are added by invitation and supply the same basic information when they accept. Every account holder confirms they're 18 or older when the account is created — see Section 8.

2.2 Calendar, task, meal & grocery content

Everything a household enters directly — calendar events, their titles, times, locations and notes, tasks and their due dates, weekly menus, and grocery list items — is stored so it can be shown back to every member of that household, with one exception: an event or task marked private is visible only to the household member who created it, not to the rest of the household.

2.3 Location information

A household's home address, entered during setup, is geocoded (converted to map coordinates) so weather and drive-time features work. If you turn on “Use my location” on a device, that device's precise, real-time location is used to personalize drive-time estimates and the weather shown to you, and is sent to the weather and routing providers listed in Section 5 to do so. Lakeday asks for your device's location permission when you first open the app, and “Use my location” is on by default once you grant it; if you decline, no location is collected and Lakeday uses your household's home address instead. You can turn it off at any time in Lakeday's Account & Location settings. See Section 10 for how we treat this as sensitive information.

2.4 Forwarded & imported content

If your household forwards an appointment email to its private Lakeday inbox address, or scans a flyer, schedule, or recipe photo, we process that email or image — see Section 4 — to suggest a calendar event or recipe for you to review. Nothing is added to your calendar automatically. Recipe imports from a pasted URL work the same way: the page is fetched directly by our servers and read to extract ingredients and steps.

2.5 Payment information

Your full card number and other complete payment credentials are collected and held directly by Stripe (web subscriptions) or Apple (iOS subscriptions) — Lakeday never sees or stores them. Lakeday's servers do receive limited billing metadata from Stripe in order to display your billing status and history to you: your card's brand, last four digits, and expiration date, and your invoice records (amounts, dates, currency, and payment status). For an iOS subscription, we receive a subscription identifier, product, status, and renewal date from Apple.

2.6 Cookies & local device storage

The web dashboard sets one essential session cookie (HTTP-only, Secure, SameSite=Strict) to keep you signed in — it's required for the Service to work and isn't used for tracking or advertising. The dashboard and apps also use your browser's or device's local storage to remember display preferences and cache data for faster loading, and use on-device storage (IndexedDB) to cache Google Photos images and device-selected wallpaper for the wall-display feature — those cached images stay on your device and are never uploaded to Lakeday's servers.

2.7 Server logs, diagnostics & audit records

These are three separate, differently-retained records — see Section 6 for how long each is kept:

  • Request/error logs: every API request our servers handle logs the timestamp, HTTP method and route, response status and duration, a request ID, your account and household ID, your role in the household, how you authenticated, and your browser/app's user-agent string — plus, for an error, a sanitized error name and message. These go to Google Cloud Logging.
  • Diagnostic events: a separate, smaller record of specific application events (for troubleshooting features like the wall display and native widgets), similarly scoped to an account/household and a short, sanitized summary.
  • Administrative audit records: actions taken through Lakeday's internal administration console are separately logged for security and accountability.
3

How we use this information

  • To operate the Service: show your household's calendar, tasks, meals, and grocery list to the right people, and only to them.
  • To provide features you turn on: weather, drive-time and “time to leave” estimates, flight-status tracking for a flight you've added, and reminders.
  • To process forwarded emails, scanned photos, and recipe imports into a suggestion you review before anything is added to your calendar — see Section 4.
  • To process payment and keep your subscription status accurate.
  • To secure the Service — detect abuse, enforce household-data isolation, and investigate reported problems.
  • To communicate with you about your account, such as an invitation, a billing receipt, a household-deletion notice, or a reply to a support request.

We do not use your household's content to train AI models. We do not sell your information, and we do not use it for targeted advertising or engage in profiling that produces legal or similarly significant effects on you.

4

How Lakeday uses AI

A handful of Lakeday's features rely on an AI model (Google's Vertex AI) to read content you submit and pull structured information out of it:

Forwarded appointment emails
The AI reads a forwarded email to suggest a calendar event — title, date, time, and location.
Scanned photos
A flyer, schedule, or recipe photo you scan or share is read the same way, to suggest an event or a recipe.
Recipe imports
A recipe page or video you import is read to pull out ingredients and steps.

In every case, the AI's output is a suggestion you review — nothing is added to your calendar, menu, or recipe collection without you looking at it and choosing to add it. Lakeday doesn't use AI to make decisions about you or your household (like billing, access, or account standing) without a person's involvement, and we don't use your household's content — including anything you submit for AI processing — to train AI models, ours or anyone else's. Content you submit for AI processing is sent to Google Vertex AI under Google's own data-handling terms for that service; see Section 5 for what Google receives, and Section 6 for how long the underlying content (the forwarded email, photo, or recipe import) is kept.

5

How information is shared

We do not sell your information, and we do not share it with data brokers or advertisers. Information is shared only where necessary to run the Service, with the service providers and other third parties below — we call them that rather than “processors” as a defined legal term, since that depends on the specific contract terms in place with each one.

ProviderPurposeWhat it receives
GoogleSign-in; Google Calendar sync; Google Photos import; address autocompleteAccount email/name; calendar data you connect; Google Photos you select (cached on-device after that — see 2.6)
Google Vertex AIReads forwarded emails, scanned photos, recipe pages, and recipe videos to extract event or recipe details (see Section 4)Forwarded email text, scanned images, recipe page/video content you submit for import
AppleSign in with Apple; in-app subscription purchase and verificationAccount email/name (or Apple's private relay); subscription identifier, status, and renewal date
Meta (Facebook)Optional sign-inAccount email/name, where used
StripeWeb subscription billingFull payment credentials (never touch our servers); customer, billing, and invoice records
MailgunDelivers forwarded appointment emails to your household's private inbox address, and may also deliver transactional account email (invitations, receipts, account-deletion notices)The forwarded email's content; recipient address and content of transactional emails sent to you
OpenWeatherMapWeather shown on your dashboardYour household's home location, or your device's location if you've turned that on — in both cases rounded to roughly a city-sized area (about 11 km) before it's sent
MapQuestDrive-time estimatesOrigin coordinates (home or your device's location) and a destination, as either an address you typed or coordinates
Photon (Komoot / OpenStreetMap) & ZippopotamAddress lookup, autocomplete, and reverse geocodingAddresses, place searches, or ZIP codes you enter, or your device's coordinates when a city name is needed to label your location
AeroDataBox (api.market)Flight status for a flight you've added to an eventThe flight number and date you entered
Recipe & content source sitesRecipe import from a URL you provideThe URL you submit — our servers request that page directly, so the site sees a request from Lakeday, not from your device
Google Cloud PlatformHosting — application servers, database, file storage, loggingAccount and household information stored or processed by Lakeday, recipe-import files, application records, and server logs — not payment credentials (held directly by Stripe/Apple) or photographs cached only on your device (Section 2.6)

Inbound SMS import isn't available yet; if we launch it, Twilio would be added here before that feature goes live, with its own update to this section.

We may also disclose information if required by law, or to protect the rights, property, or safety of Lakeday, our users, or others.

If Lakeday is ever involved in a merger, acquisition, or sale of assets, household information would be one of the assets transferred — we'd tell affected households before that happens and before information is used differently than described here.

6

Retention & deletion

Active household content
Calendar, task, meal, and grocery data is kept as long as your household is active.
Raw recipe-import uploads
A raw video you upload for a recipe import is deleted automatically within 24 hours of processing.
Extracted recipe drafts & preview images
The recipe text and preview image our AI extracts are generated before you decide whether to save the recipe. If you don't save it, the draft and its preview image are deleted automatically — within 7 days if the import never finished processing, or within 90 days if it did. Once you save a recipe, its preview image is kept as long as your household is active, including if you later remove that recipe from your menu; deleting your household deletes it immediately, along with every other draft and saved recipe image.
Forwarded/imported inbox items
An item you haven't reviewed yet is automatically deleted 90 days after we received it. Once you import or dismiss an item, it's deleted 30 days later. Either happens sooner if your household is deleted first.
Connected-calendar tokens
Kept, encrypted, while the connection is active; removed when you disconnect it or delete your household.
Subscription & billing records
Kept for the life of the subscription and afterward as needed for accounting, tax, and legal recordkeeping.
Address & location lookup caches
To avoid repeating identical lookups, our servers keep a shared cache of address-to-coordinate and coordinate-to-city results (up to 30 days) and of weather forecasts for approximate locations (about an hour). These entries are not tied to any account or household.
Request/error logs
Held in Google Cloud Logging under its default retention (currently 30 days).
Diagnostic events
Currently ~30 days (configurable 7–365), pruned automatically.
Administrative audit records
Retained for up to 2 years as a security and accountability record, then deleted.
Support correspondence
Kept for as long as needed to assist you and for quality and legal purposes, then deleted or anonymized.
Backups
Up to 30 daily database backups plus 7 days of point-in-time recovery are kept for disaster recovery. Deleted information may persist temporarily in a backup and is not selectively restored from one except to recover from an actual data-loss incident.
Deleting your household
The household's primary member can schedule deletion (Settings → “Permanently delete [household]”). Every household member is emailed when this happens. The household keeps full access for a 7-day grace period, during which the primary member can cancel the deletion; at the end of that period, the account, calendar, tasks, meals, grocery list, and connected-calendar tokens are permanently deleted.
Deleting only your own account
A household member who isn't the primary member can delete their own account at any time (Settings → “Delete Account”). It takes effect immediately: the member's account and their private events and tasks are deleted, while anything they added to the shared household calendar stays with the household.
Sign in with Apple and app-store subscriptions
When an account that signed in with Apple is deleted, we revoke its Sign in with Apple authorization with Apple. An iOS subscription is billed by Apple, so deleting your account does not cancel it — cancel it in your Apple ID subscription settings to stop future charges.
7

Security

Every household's data is isolated from every other household at the database level. Sensitive fields — connected-calendar tokens, the content of forwarded messages, and verified phone numbers — are encrypted at rest, in addition to the encryption already protecting all traffic to and from the Service (HTTPS/TLS). Passwords are never stored in plain text. We run regular dependency and code-security scanning, and we test that one household truly cannot reach another's data.

No method of transmission or storage is 100% secure, and we can't guarantee absolute security — but we design for household-level isolation as a first principle, not an afterthought.

8

Children's privacy

Lakeday is not directed at children, and no one under 18 may create a Lakeday account or accept a household invitation — every new account confirms this when it's created (see Section 2.1 and the Terms of Service). A household's calendar may naturally include a child's name, school events, or activities, but only as entered by the adult who manages that household's account; a child never holds their own Lakeday sign-in. If we learn that an account was created by someone under 18, we'll close it.

9

Your privacy rights

Depending on where you live, you may have the right to know what personal information we hold about you, correct it, delete it, receive a copy of it (portability), and not be discriminated against for exercising these rights. Here's how each works at Lakeday:

Access & correction
You enter and edit almost all of your content directly in the app. For anything you can't reach yourself, contact us at the address in Section 13.
Portability
A revocable, private iCalendar feed link lets you take your events to another calendar app at any time (Settings → Calendar feed).
Deletion — your own account
Any household member can email us at the address in Section 13 to request deletion of their own account or personal information.
Deletion — the whole household
Only the household's primary member can delete the entire household, from within the app — see Section 6.
Non-discrimination
We won't deny you the Service, charge a different price, or provide a different level of service for exercising these rights.
Making a request
Email us at the address in Section 13 from the email address on your account, so we can verify it's really you. We'll respond within 45 days (extendable once by another 45 days for a complex request), consistent with applicable law.
Appeals
If we decline your request, you can appeal by replying to our response. We'll respond to an appeal within 60 days. If we decline an appeal, we'll tell you how to file a complaint with your state's attorney general (for Texas residents, the Texas Attorney General).

To repeat what Section 3 already says: we do not sell personal information, and we do not process it for targeted advertising or for profiling that produces legal or similarly significant effects.

10

Sensitive information

Your device's precise, real-time location (Section 2.3) is sensitive personal information under laws like the Texas Data Privacy and Security Act. We only collect it after you grant your device's own location permission, which Lakeday asks for when you first open the app (“Use my location” is then on by default), and we keep a record of that setting. You can turn it off at any time in Account & Location settings, which stops new location data from being collected or sent to the weather and routing providers listed in Section 5.

Household content may also include other sensitive information that an adult member chooses to provide — for example, information about a child, a medical appointment, or a religious activity, whether typed directly into an event or note, contained in a forwarded email, or visible in a photo. Lakeday processes that information only at the household member's direction, to provide the Service, the same way it handles any other household content. The person submitting it represents that they're authorized to do so, including as a parent or legal guardian where the information concerns a child.

11

Where we operate

Lakeday is intended for use by households in the United States. Our primary application servers and database are located in the United States, on Google Cloud infrastructure. Our service providers (Section 5) may process information in other locations under their own respective agreements and privacy notices. We do not currently offer the Service outside the United States, and this policy doesn't address the additional legal requirements (such as the EU/UK GDPR) that would apply if we did.

12

Changes to this policy

If we make a material change to this policy, we'll notify the household's primary member by email and update the effective date above before the change takes effect.

13

Contact us

Questions about this policy, or a request regarding your information: help@lakedayboard.com, or by mail to:

The Hyytinen Group LLC
Attn: Lakeday Privacy
5900 Balcones Dr., Ste. 100
Austin, TX 78731