Privacy Policy
DASH (the "App") is an iOS and Android application provided by an individual developer (GitHub: skier-song9, the "Developer"). This policy explains what information the App processes, for what purpose — and what it does not process. Both platforms offer the same features and process the same information for the same purposes; where they differ (the name of the encrypted store, for one) both are named below. This is a translation provided for convenience; if it conflicts with the Korean version, the Korean version prevails.
1. Information processed
| Item | Details | Stored in |
|---|---|---|
| OAuth tokens | Tokens linking your AI coding tool (Claude Code, Codex, Antigravity) accounts | iOS Keychain · Android EncryptedSharedPreferences (encrypted) |
| AI service usage | Usage limits and remaining quota for Claude Code · Codex · Antigravity | On device (including the App's own storage it shares with the home-screen widget) |
| Calendar events | Only if you allow calendar access — the title, date, time and calendar colour of upcoming events in the device's Calendar app, used solely to show "my calendar" in the D-Day sidebar | On device (read for display only) |
| D-Day settings | Region, chosen interests, category order, whether the sidebar is collapsed, and the IDs of events you already reacted to (to prevent duplicate reactions) | On device |
| Holiday and event list | A public list (dates of holidays, observances and events per country) downloaded from the Developer's site. Not personal data; the request carries no credentials or identifiers | On device (cache) |
| Anonymous event reactions | Only when you long-press an event and choose Useful · Not for me · turn off an interest — five fields: event ID, reaction type, country code, platform (ios/android), and app version; the server adds only the UTC day of receipt. Nothing that could identify you — no account, e-mail, device ID, advertising ID or install ID | The Developer's counting server (Cloudflare) |
2. Purposes of use
- Reading each service's usage API to display AI coding tool limits.
- Antigravity sign-in uses the same Google account used by the Antigravity app, through the system browser. DASH receives only an OAuth token scoped to reading quota; it does not read mail, Drive, Calendar or any other Google data through that token.
- Forecasting when quota runs out from how usage changes. This is computed on the device only.
- If you allow it, reading upcoming events from the device calendar to show them in the D-Day sidebar. What is read is never sent off the device. If a calendar you linked already carries a holiday the App knows (for example the device's built-in holiday calendar), it is shown once — of two items with the same title and overlapping days, the lower-priority one (holiday > my calendar > event) is left off the screen. The comparison runs on the device only, is sent nowhere, and never modifies the calendar itself.
- Only when you tap "Add to Calendar" on a detail card, opening the operating system's event editor to write an event to your calendar. Nothing is saved unless you tap Save there; the App never creates or changes events on its own.
- Checking the Developer's site once a day for an updated holiday and event list, and downloading it.
- Using anonymous event reactions only as aggregate input for deciding which kinds of events to show more or less. Reactions cannot be linked to an individual and are never used for profiling, advertising or any other purpose.
3. Storage and security
- Everything the App stores — OAuth tokens, usage readings, forecasts, card order, D-Day settings, cached holiday/event list, and records of events you already reacted to — stays in the App's own storage on the device. The home-screen widget only draws the last usage reading left in that storage; it does not talk to anything itself. The Developer operates no server that stores user data. The only outbound data is quota requests, the public feed download, and an anonymous reaction when you tap one.
- OAuth tokens are held in the encrypted store the operating system provides — the Keychain on iOS, and EncryptedSharedPreferences, keyed by hardware-backed keys, on Android.
- All network traffic is encrypted with TLS (HTTPS).
- The App contains no advertising, tracking, or analytics SDKs.
- Calendar events are read on the device only, through the operating system's calendar permission, and are never sent to the Developer's servers or to third parties. You can revoke the permission at any time in the system settings (iOS: Settings › Privacy & Security › Calendars · Android: Settings › Apps › DASH › Permissions); doing so only removes "my calendar" items — everything else keeps working.
- Anonymous event reactions contain no value that identifies you, your account or your device. To limit abusive repeat submissions, the counting server derives a hash from the sender's IP address mixed with the current UTC date and a server secret, and keeps it only for that day. A nightly job nulls it; the raw IP address is never stored, and request logs are never written.
- Reaction rows themselves (event ID, signal, country code, platform, app version, day) are kept for 12 months. A device sends each Useful/Not for me vote at most once per event; turning an interest off is not limited this way. Reactions are always anonymous: no account, e-mail, device ID, advertising ID or install ID is sent; the Developer cannot tell who sent one, and there is no switch because nothing identifying is ever sent. The IDs of events you already reacted to are recorded on the device only.
4. Third parties and processors
The Developer does not provide or sell user data to third parties. The App communicates with exactly three parties, and sends none of them anything that could identify you.
- Anthropic (Claude Code), OpenAI (Codex), and Google (Antigravity) usage APIs — each request carries only the token that service issued. The App never sends prompts, code, or conversation content and never calls a text-generation API; it only reads quota.
- The Developer's site dash-worklife.org (hosted on GitHub Pages) — the holiday and event list files are downloaded from here. As with any web request the connecting IP reaches the hosting provider (GitHub), but the App sends no credentials or identifiers.
- The Developer's counting server (running on Cloudflare Workers and D1) — receives anonymous event reactions. Cloudflare is the infrastructure that runs code the Developer deployed; the stored data contains no identifiers.
5. Retention and deletion
- On-device data is deleted when you delete the App.
- Disconnecting an account in the App's settings immediately deletes that account's token.
- D-Day settings (region, interests, category order, collapsed state), cached feed files, and the IDs of events you already reacted to are deleted together with the App.
- Calendar events are not stored by the App, so there is nothing to delete; calendar access can be revoked in the system settings.
- Anonymous reaction counts cannot be linked to you, so it is technically impossible to single out and delete one person's reactions. Reaction rows expire and are deleted after 12 months.
Step-by-step instructions are on the Delete your data page.
6. Children's privacy
The App is not directed at children under 14 and does not knowingly collect their personal information.
7. Changes to this policy
Changes will be posted on this page; material changes will be announced in the App.
8. Contact
Privacy inquiries: 0603paul@gmail.com