daybreakfiveBack to Daybreak →

PRIVACY & GDPR · LAST UPDATED 31 AUGUST 2026

Small data footprint.
No ad-tech.

Daybreak Five is built around GDPR principles: clear consent, collecting only what the service needs, letting you correct or remove it, and never selling it. “GDPR-aligned” describes our approach; it is not a certification from a regulator.

No advertising cookiesNo analytics cookiesNo sale of personal dataOne-click email unsubscribe

01

Who is responsible

Daybreak Five is operated by Akansh Miglani, who is the data controller for the personal data described here.

For access, correction, deletion, portability, objection or any privacy question, email miglaniakansh15@gmail.com. Please use the email attached to your Daybreak account so we can verify the request without collecting extra identification.

02

What we process—and why

Newsletter profile

Your name, email, five topics, delivery time, time zone and streak goal. We use these to confirm the subscription, personalise three news picks and deliver them at the time requested.

Project progress

Completed dates, live-streak information and preference changes. We use these for your dashboard, Project 100 progress and relevant reminder language.

Security identifiers

A random browser ID, signed email-link tokens and a signed reader session. These connect a confirmed profile across email links and help prevent someone else from changing it.

Messages you send

If you reply or write to Daybreak Five, Resend receives the message and forwards it to the founder’s inbox so a human can answer. Attachments may be included in that forwarding.

Ordinary technical data

Hosting and email infrastructure may process IP address, browser information, timestamps and delivery/security logs needed to serve the site, prevent abuse and diagnose failures.

What we do not do

We do not sell personal data, run behavioural advertising, use third-party ad trackers or make decisions that have legal or similarly significant effects on you.

03

Cookies and browser storage

There is no advertising or analytics cookie banner because Daybreak Five does not currently place those cookies. It does use the following service storage:

Reader-session cookieAfter you confirm a subscription or open a secure newsletter link, we set daybreak_reader_session. It is secure in production, unavailable to page scripts, used only to restore your confirmed profile, and expires after 120 days. It is not used for advertising.
Local browser storageThe browser remembers your anonymous ID, a local copy of profile settings, reading position, saved editions, private notes/reactions and sound choice. Most private reading notes stay on that browser. It remains until you clear site data in your browser.
Founder-only securityThe private publishing area uses a separate authentication cookie. It protects the CMS and does not track public readers.

Links to LinkedIn, Google Calendar or original news sources take you to another service; that service’s own privacy and cookie rules then apply.

04

Legal bases and personalisation

Consent: we send newsletter and routine emails only after you tick the permission box and confirm the address. You may withdraw consent at any time through the unsubscribe link.

Providing the service you requested: we process profile, progress and authentication data to supply the dashboard, restore your profile and record completed Project Days.

Legitimate interests: limited technical processing helps secure the service, rate-limit abuse, deliver messages and fix failures. We do not use this basis to add advertising.

The personalisation engine compares your five saved topics with the day’s eligible stories, selects up to three unique matches, and fills any gap with General editor picks. Streak and completion data also changes the greeting and encouragement. This has no legal or similarly significant consequence.

05

Where the data goes

We use service providers only to operate Daybreak Five:

  • Google Firebase / Firestore for subscriber profiles, progress and published editions.
  • Resend for confirmation, newsletter delivery, unsubscribe links and inbound email forwarding.
  • Vercel for website hosting, server functions and operational logs.
  • Cloudinary for editorial images and videos; it is not used to build reader advertising profiles.

These providers may process data outside your country. Their contractual data-processing and international-transfer safeguards apply. We do not give subscriber lists to news publishers, advertisers or data brokers.

06

Retention and your choices

An active subscriber profile is kept while you use the service. Unsubscribing immediately stops newsletter delivery and marks the record as unsubscribed so the opt-out is honoured; it does not automatically erase the existing profile. Email us if you want the profile deleted completely.

Local browser information remains until you clear Daybreak Five’s site data. Confirmation links expire after 24 hours, reader email links after 3 days, and the reader-session cookie after 120 days. Provider security and delivery logs follow the relevant provider’s operational retention settings.

Depending on applicable law, you may request access, correction, deletion, restriction or portability; object to certain processing; withdraw consent; and complain to your local data-protection authority. Withdrawing newsletter consent is as simple as clicking Unsubscribe in any Daybreak email.

For an independent explanation of these rights, see the European Commission’s GDPR guide ↗.

Privacy & GDPR