Privacy Policy
What we collect from your household, why, and the choices you have — written section by section to match what Lakeday actually does, not a generic template.
Lakeday is a product of The Hyytinen Group LLC, a Texas limited liability company (“Lakeday,” “we,” “us”), and provides a shared calendar, task, meal-planning, and household-organization service (the “Service”) to households in the United States. This policy explains what information we collect, how we use it, who we share it with, and the choices available to you.
Overview & scope
This policy covers the Lakeday web dashboard and the Lakeday iOS and Android apps, and is written for households located in the United States — see Section 11. It doesn't cover third-party sites you may reach by following a link from Lakeday — for example, a recipe's original source page, or a calendar provider's own consent screen — those are covered by that site's own policy.
Lakeday is a household product: one household subscription with an individual account for each adult member. Most of the information described below is entered directly by a household's primary member or another invited member, not collected passively.
Information we collect
2.1 Account & household information
When a household is created, we collect the primary member's name, email address, and a password (stored as a salted hash — we never store or can retrieve the plain password). If you sign in with Google, Apple, or Facebook instead, we receive the name and email address that provider shares, and a token that lets Lakeday keep working with that provider on your behalf — we never see or store your password with that provider. Additional household members are added by invitation and supply the same basic information when they accept. Every account holder confirms they're 18 or older when the account is created — see Section 8.
2.2 Calendar, task, meal & grocery content
Everything a household enters directly — calendar events, their titles, times, locations and notes, tasks and their due dates, weekly menus, and grocery list items — is stored so it can be shown back to every member of that household, with one exception: an event or task marked private is visible only to the household member who created it, not to the rest of the household.
2.3 Location information
A household's home address, entered during setup, is geocoded (converted to map coordinates) so weather and drive-time features work. If you turn on “Use my location” on a device, that device's precise, real-time location is used to personalize drive-time estimates and the weather shown to you, and is sent to the weather and routing providers listed in Section 5 to do so. Lakeday asks for your device's location permission when you first open the app, and “Use my location” is on by default once you grant it; if you decline, no location is collected and Lakeday uses your household's home address instead. You can turn it off at any time in Lakeday's Account & Location settings. See Section 10 for how we treat this as sensitive information.
2.4 Forwarded & imported content
If your household forwards an appointment email to its private Lakeday inbox address, or scans a flyer, schedule, or recipe photo, we process that email or image — see Section 4 — to suggest a calendar event or recipe for you to review. Nothing is added to your calendar automatically. Recipe imports from a pasted URL work the same way: the page is fetched directly by our servers and read to extract ingredients and steps.
2.5 Payment information
Your full card number and other complete payment credentials are collected and held directly by Stripe (web subscriptions) or Apple (iOS subscriptions) — Lakeday never sees or stores them. Lakeday's servers do receive limited billing metadata from Stripe in order to display your billing status and history to you: your card's brand, last four digits, and expiration date, and your invoice records (amounts, dates, currency, and payment status). For an iOS subscription, we receive a subscription identifier, product, status, and renewal date from Apple.
2.6 Cookies & local device storage
The web dashboard sets one essential session cookie (HTTP-only, Secure, SameSite=Strict) to keep you signed in — it's required for the Service to work and isn't used for tracking or advertising. The dashboard and apps also use your browser's or device's local storage to remember display preferences and cache data for faster loading, and use on-device storage (IndexedDB) to cache Google Photos images and device-selected wallpaper for the wall-display feature — those cached images stay on your device and are never uploaded to Lakeday's servers.
2.7 Server logs, diagnostics & audit records
These are three separate, differently-retained records — see Section 6 for how long each is kept:
- Request/error logs: every API request our servers handle logs the timestamp, HTTP method and route, response status and duration, a request ID, your account and household ID, your role in the household, how you authenticated, and your browser/app's user-agent string — plus, for an error, a sanitized error name and message. These go to Google Cloud Logging.
- Diagnostic events: a separate, smaller record of specific application events (for troubleshooting features like the wall display and native widgets), similarly scoped to an account/household and a short, sanitized summary.
- Administrative audit records: actions taken through Lakeday's internal administration console are separately logged for security and accountability.
How we use this information
- To operate the Service: show your household's calendar, tasks, meals, and grocery list to the right people, and only to them.
- To provide features you turn on: weather, drive-time and “time to leave” estimates, flight-status tracking for a flight you've added, and reminders.
- To process forwarded emails, scanned photos, and recipe imports into a suggestion you review before anything is added to your calendar — see Section 4.
- To process payment and keep your subscription status accurate.
- To secure the Service — detect abuse, enforce household-data isolation, and investigate reported problems.
- To communicate with you about your account, such as an invitation, a billing receipt, a household-deletion notice, or a reply to a support request.
We do not use your household's content to train AI models. We do not sell your information, and we do not use it for targeted advertising or engage in profiling that produces legal or similarly significant effects on you.
How Lakeday uses AI
A handful of Lakeday's features rely on an AI model (Google's Vertex AI) to read content you submit and pull structured information out of it:
- Forwarded appointment emails
- The AI reads a forwarded email to suggest a calendar event — title, date, time, and location.
- Scanned photos
- A flyer, schedule, or recipe photo you scan or share is read the same way, to suggest an event or a recipe.
- Recipe imports
- A recipe page or video you import is read to pull out ingredients and steps.
In every case, the AI's output is a suggestion you review — nothing is added to your calendar, menu, or recipe collection without you looking at it and choosing to add it. Lakeday doesn't use AI to make decisions about you or your household (like billing, access, or account standing) without a person's involvement, and we don't use your household's content — including anything you submit for AI processing — to train AI models, ours or anyone else's. Content you submit for AI processing is sent to Google Vertex AI under Google's own data-handling terms for that service; see Section 5 for what Google receives, and Section 6 for how long the underlying content (the forwarded email, photo, or recipe import) is kept.
Retention & deletion
- Active household content
- Calendar, task, meal, and grocery data is kept as long as your household is active.
- Raw recipe-import uploads
- A raw video you upload for a recipe import is deleted automatically within 24 hours of processing.
- Extracted recipe drafts & preview images
- The recipe text and preview image our AI extracts are generated before you decide whether to save the recipe. If you don't save it, the draft and its preview image are deleted automatically — within 7 days if the import never finished processing, or within 90 days if it did. Once you save a recipe, its preview image is kept as long as your household is active, including if you later remove that recipe from your menu; deleting your household deletes it immediately, along with every other draft and saved recipe image.
- Forwarded/imported inbox items
- An item you haven't reviewed yet is automatically deleted 90 days after we received it. Once you import or dismiss an item, it's deleted 30 days later. Either happens sooner if your household is deleted first.
- Connected-calendar tokens
- Kept, encrypted, while the connection is active; removed when you disconnect it or delete your household.
- Subscription & billing records
- Kept for the life of the subscription and afterward as needed for accounting, tax, and legal recordkeeping.
- Address & location lookup caches
- To avoid repeating identical lookups, our servers keep a shared cache of address-to-coordinate and coordinate-to-city results (up to 30 days) and of weather forecasts for approximate locations (about an hour). These entries are not tied to any account or household.
- Request/error logs
- Held in Google Cloud Logging under its default retention (currently 30 days).
- Diagnostic events
- Currently ~30 days (configurable 7–365), pruned automatically.
- Administrative audit records
- Retained for up to 2 years as a security and accountability record, then deleted.
- Support correspondence
- Kept for as long as needed to assist you and for quality and legal purposes, then deleted or anonymized.
- Backups
- Up to 30 daily database backups plus 7 days of point-in-time recovery are kept for disaster recovery. Deleted information may persist temporarily in a backup and is not selectively restored from one except to recover from an actual data-loss incident.
- Deleting your household
- The household's primary member can schedule deletion (Settings → “Permanently delete [household]”). Every household member is emailed when this happens. The household keeps full access for a 7-day grace period, during which the primary member can cancel the deletion; at the end of that period, the account, calendar, tasks, meals, grocery list, and connected-calendar tokens are permanently deleted.
- Deleting only your own account
- A household member who isn't the primary member can delete their own account at any time (Settings → “Delete Account”). It takes effect immediately: the member's account and their private events and tasks are deleted, while anything they added to the shared household calendar stays with the household.
- Sign in with Apple and app-store subscriptions
- When an account that signed in with Apple is deleted, we revoke its Sign in with Apple authorization with Apple. An iOS subscription is billed by Apple, so deleting your account does not cancel it — cancel it in your Apple ID subscription settings to stop future charges.
Security
Every household's data is isolated from every other household at the database level. Sensitive fields — connected-calendar tokens, the content of forwarded messages, and verified phone numbers — are encrypted at rest, in addition to the encryption already protecting all traffic to and from the Service (HTTPS/TLS). Passwords are never stored in plain text. We run regular dependency and code-security scanning, and we test that one household truly cannot reach another's data.
No method of transmission or storage is 100% secure, and we can't guarantee absolute security — but we design for household-level isolation as a first principle, not an afterthought.
Children's privacy
Lakeday is not directed at children, and no one under 18 may create a Lakeday account or accept a household invitation — every new account confirms this when it's created (see Section 2.1 and the Terms of Service). A household's calendar may naturally include a child's name, school events, or activities, but only as entered by the adult who manages that household's account; a child never holds their own Lakeday sign-in. If we learn that an account was created by someone under 18, we'll close it.
Your privacy rights
Depending on where you live, you may have the right to know what personal information we hold about you, correct it, delete it, receive a copy of it (portability), and not be discriminated against for exercising these rights. Here's how each works at Lakeday:
- Access & correction
- You enter and edit almost all of your content directly in the app. For anything you can't reach yourself, contact us at the address in Section 13.
- Portability
- A revocable, private iCalendar feed link lets you take your events to another calendar app at any time (Settings → Calendar feed).
- Deletion — your own account
- Any household member can email us at the address in Section 13 to request deletion of their own account or personal information.
- Deletion — the whole household
- Only the household's primary member can delete the entire household, from within the app — see Section 6.
- Non-discrimination
- We won't deny you the Service, charge a different price, or provide a different level of service for exercising these rights.
- Making a request
- Email us at the address in Section 13 from the email address on your account, so we can verify it's really you. We'll respond within 45 days (extendable once by another 45 days for a complex request), consistent with applicable law.
- Appeals
- If we decline your request, you can appeal by replying to our response. We'll respond to an appeal within 60 days. If we decline an appeal, we'll tell you how to file a complaint with your state's attorney general (for Texas residents, the Texas Attorney General).
To repeat what Section 3 already says: we do not sell personal information, and we do not process it for targeted advertising or for profiling that produces legal or similarly significant effects.
Sensitive information
Your device's precise, real-time location (Section 2.3) is sensitive personal information under laws like the Texas Data Privacy and Security Act. We only collect it after you grant your device's own location permission, which Lakeday asks for when you first open the app (“Use my location” is then on by default), and we keep a record of that setting. You can turn it off at any time in Account & Location settings, which stops new location data from being collected or sent to the weather and routing providers listed in Section 5.
Household content may also include other sensitive information that an adult member chooses to provide — for example, information about a child, a medical appointment, or a religious activity, whether typed directly into an event or note, contained in a forwarded email, or visible in a photo. Lakeday processes that information only at the household member's direction, to provide the Service, the same way it handles any other household content. The person submitting it represents that they're authorized to do so, including as a parent or legal guardian where the information concerns a child.
Where we operate
Lakeday is intended for use by households in the United States. Our primary application servers and database are located in the United States, on Google Cloud infrastructure. Our service providers (Section 5) may process information in other locations under their own respective agreements and privacy notices. We do not currently offer the Service outside the United States, and this policy doesn't address the additional legal requirements (such as the EU/UK GDPR) that would apply if we did.
Changes to this policy
If we make a material change to this policy, we'll notify the household's primary member by email and update the effective date above before the change takes effect.
Contact us
Questions about this policy, or a request regarding your information: help@lakedayboard.com, or by mail to:
The Hyytinen Group LLC
Attn: Lakeday Privacy
5900 Balcones Dr., Ste. 100
Austin, TX 78731
See also the Terms of Service.