DawnLegal

Privacy Policy

Last updated

This Privacy Policy explains how Magma Company GmbH, Salvemattweg 11, 6340 Baar (ZG), Switzerland ("Dawn", "we", "us", "our") collects, uses and protects personal data in connection with the Dawn application, its iOS app, its connector interfaces and the websites at dawn.am, app.dawn.am, help.dawn.am and legal.dawn.am (together, the "Service").

The short version

Dawn holds your calendar, your todos, your notes and the reasoning behind your decisions. That is about as personal as software gets, so:

  • We do not sell your data, rent it, trade it or advertise against it.
  • We do not train models on your content. Not ours, not anyone's, not in aggregate.
  • We measure how the Service is used — counts, timings, which screens are reached — and only with your consent, and never the substance of what is in your account. See section 3.7 and the Cookie Policy.
  • You can delete everything yourself, immediately, from Settings, without asking us.

The rest of this document is the same thing said precisely, because the short version is not what a supervisory authority reads.


1. Controller

Magma Company GmbH is the controller of the personal data described here, within the meaning of Article 4(7) GDPR and the Swiss Federal Act on Data Protection ("FADP").

Registered office and company details are on the Impressum.

Data protection contact: privacy@dawn.am

We have not appointed a Data Protection Officer, as we are not required to under Article 37 GDPR. Write to the address above and it reaches a person.


2. Our role, and yours

Dawn is a personal tool. You put things into your own account for your own purposes, and we operate the account.

2.1. We are the controller of your account data, of the content you store, and of the usage measurements described in section 3.7 — because we decide the purposes and means of holding and processing them in order to run the Service.

2.2. What you put in about other people is your decision. An event attendee, a friend you shared a list with, a name in a note, the sender of an email you forwarded: we did not choose to hold that information, you did. We process it only to run the features you used it for. If you are using Dawn purely for your own personal or household purposes, the GDPR does not apply to you as a data subject's controller (Article 2(2)(c)); if you are using it otherwise, you are responsible for having a lawful basis for what you enter.

2.3. A shared record has two sides. Where somebody has shared a calendar, list, board, sheet, note or validation run with you, we hold their content in order to show it to you, and their account remains the place it belongs to.


3. What we collect

3.1. Account

Your email address, and a display name and profile picture where your sign-in provided them. Authentication itself is handled by Clerk; we never receive or store your password.

3.2. Your content

Everything you put into Dawn: calendars and events, todo lists and todos, notes, folders and tags, boards, columns and cards, sheets, goals, rules, learnings, theses, decisions, flight bookings and their passengers, comments, and the people you record against any of these.

3.3. Sharing and friends

Who you shared a calendar, todo list, board, sheet, note or validation run with, who shared one with you, the state of the invitation, your friend code, your friendships and the requests either way.

3.4. Email you forward

If you use your private inbound address, we record the message: its subject, its sender, the prose we read out of it, and its attachments — whether or not we manage to make sense of it. We record before we understand, deliberately, so that "I forwarded that and nothing happened" is a question with an answer. We keep the prose and the attachments rather than the raw MIME.

3.5. Assistant activity

Each run of the built-in assistant, whether it succeeded or failed, and which tools it called in order. An assistant that can write to your account has to leave a trail; a row appearing with nobody able to say which instruction produced it is what this record prevents.

3.6. Connections and settings

The connectors and app sign-ins you have authorised and their tokens; your API key for the assistant, encrypted at rest rather than hashed, because it has to be handed back to Anthropic on every call; your timezone, feature switches and interface preferences.

3.7. Usage measurement

We use PostHog to understand how the Service is used. With your consent, it records events — a page viewed, a feature reached, a flow abandoned, an error raised — together with the technical context they happened in: browser and operating system, device type, screen size, referring page, and an approximate location derived from your IP address.

What it does not record is the substance of your account. No note body, no event title, no todo, no message you forwarded, no assistant instruction, no name of a person you recorded. Where a measurement would need your content to mean anything, we do not take it.

Analytics runs only where you have consented, is not set until you do, and consent can be withdrawn at any time. See the Cookie Policy.

3.8. Technical logs

Our servers record the ordinary facts of a request — IP address, timestamp, path, response status, user agent — for security, abuse prevention and diagnosis. These are not tied to analytics and are kept under section 7.

3.9. What we never collect

No advertising identifier. No device fingerprint. No precise location. No access to your phone's contacts, photos or calendar — the iOS app requests no permissions at all. No tracking of you across other websites, by us or by anyone on our behalf.


4. Why we process it, and on what basis

WhatWhyLegal basis
Account, content, sharing, settingsTo operate the Service you asked forPerformance of a contract — Art. 6(1)(b) GDPR
Forwarded email, assistant runsTo provide the features you chose to usePerformance of a contract — Art. 6(1)(b)
Sending invitations, share notices, RSVPsTo deliver a message you asked us to sendPerformance of a contract — Art. 6(1)(b)
Technical logs, rate limiting, abuse preventionTo keep the Service secure and availableLegitimate interests — Art. 6(1)(f)
Service emails about your accountTo tell you about changes that affect youPerformance of a contract — Art. 6(1)(b); legitimate interests — Art. 6(1)(f)
Usage measurement (section 3.7)To see what is used and what is brokenConsent — Art. 6(1)(a), and Art. 5(3) ePrivacy Directive
Responding to a legal obligationBecause we mustLegal obligation — Art. 6(1)(c)

Where we rely on legitimate interests, we have weighed them against your rights and concluded they are not overridden; you can ask us for that assessment, and you can object under section 8.

We do not carry out automated decision-making producing legal or similarly significant effects, and we do not profile you.


5. Who else sees it

Only the services it takes to run the thing, each doing one job, each under a data processing agreement, and each limited to what it needs. The current list, with locations and transfer mechanisms, is the Sub-processors page — it is maintained as a page of its own so that it can change without this document changing.

In summary: Clerk signs you in, DigitalOcean runs the app and its database, Resend sends the mail Dawn sends, Anthropic answers the assistant and reads forwarded email against your own API key, PostHog counts what is used, and Vercel serves the page you are reading.

Beyond those, we disclose personal data only:

  • When the law requires it — a binding order from a court or authority with jurisdiction. We will tell you unless we are forbidden to.
  • To protect rights — where disclosure is genuinely necessary to protect the safety or rights of a person, or the integrity of the Service.
  • On a business transfer — in a merger, acquisition or sale of substantially all our assets, where the acquirer is bound by protections no weaker than these. You will be told before your data moves, and can close your account first.

No data broker. No advertising network. No sale of any kind.


6. International transfers

The application and its database are hosted in the European Union (DigitalOcean, Frankfurt), and that is where everything in your account lives. Some sub-processors are in the United States, and these legal notices are served from a global content network.

Where personal data goes to a country without an adequacy decision from the European Commission or the Swiss Federal Council, we rely on:

  • EU Standard Contractual Clauses adopted under Article 46(2)(c) GDPR, with the Swiss addendum where the FADP applies, and a transfer impact assessment where one is needed; or
  • the EU–U.S. Data Privacy Framework and its Swiss–U.S. extension, where the recipient is certified under it.

Which applies to which recipient is on the Sub-processors page.


7. How long we keep it

  • Your account and its content — for as long as your account is open. When you close it, immediately (section 9).
  • Forwarded email and its attachments — for as long as your account is open, unless you delete the booking or message it relates to.
  • Assistant run records — for as long as your account is open.
  • Technical logs — up to 90 days, then discarded.
  • Usage measurement — up to 12 months from collection.
  • Records we must keep by law — for the period the law requires, and no longer.
  • Backups — our hosting provider holds database backups on a short rolling window; they age out on their own and are not restored to bring back a deleted account.

8. Your rights

Under the GDPR and the FADP you have the right to:

  • Access — confirmation of whether we process your data, and a copy of it.
  • Rectification — correction of anything inaccurate or incomplete.
  • Erasure — deletion, where the grounds in Article 17 apply.
  • Restriction — to have processing paused in the circumstances of Article 18.
  • Portability — a copy in a structured, commonly used, machine-readable format.
  • Object — to processing we base on legitimate interests, on grounds relating to your situation.
  • Withdraw consent — at any time, for anything we do on consent, without affecting what was lawful before you withdrew it.
  • Complain — to a supervisory authority (section 12).

Most of these you can exercise yourself, immediately, without asking us: Dawn is a window onto everything it holds about you. You read it by opening it, correct it by editing it, take a copy of it through the app's own interfaces and its iCal feeds, and erase it by closing your account.

For anything you cannot do yourself, write to privacy@dawn.am. We answer within one month, extendable by two further months for a complex request, in which case we will tell you within the first month and say why. We may ask you to confirm your identity where we genuinely cannot tell it is you.


9. Deleting your account

Settings → Close your account, on the web or in the iOS app.

It deletes your account and everything in it immediately: calendars and events, todos, notes, boards, sheets, goals, rules, learnings and theses, every share you gave or were given, your friends, your connections, your assistant history and the mail you forwarded. There is no soft delete, no grace period and no copy kept aside for us. It is gone, and we cannot get it back for you either.

Two things deliberately survive, because they are not yours to remove:

  • a comment somebody else left on something you shared with them is theirs, and stays in their thread, no longer attributed to you;
  • if somebody invited you to their event, their record of having invited you is theirs.

Backups held by our hosting provider age out on their own rolling schedule.


10. Security

  • Everything travels over HTTPS.
  • Your Anthropic API key is encrypted at rest rather than stored in the clear.
  • On iOS, your session token is held in the Keychain, marked so that a backup restored onto a different device cannot carry it.
  • Every read and write is scoped to your account by the same code, whether it came from the web, the app or a Claude connector — there is one implementation, so two surfaces cannot come to disagree about what you may touch.
  • A URL you ask us to fetch — a subscribed calendar feed — is checked on every redirect hop, so a public address that redirects to an internal one is refused.
  • Access to production systems is limited to those who need it, and authenticated with multi-factor authentication.

No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify the competent supervisory authority within 72 hours where Article 33 requires it, and notify you without undue delay where Article 34 requires it.

If you have found a vulnerability, please tell us at privacy@dawn.am. A good-faith report is welcome and is not a breach of the Terms.


11. Cookies and similar technologies

What is set, by whom, and how to change it is in the Cookie Policy.


12. Complaints

You can complain to a supervisory authority.

  • In the EU/EEA: the authority of the member state where you live, work, or where the issue occurred. The list is at edpb.europa.eu.
  • In Switzerland: the Federal Data Protection and Information Commissioner (FDPIC), edoeb.admin.ch.
  • In the UK: the Information Commissioner's Office, ico.org.uk.

We would rather you told us first — privacy@dawn.am — but you do not have to.


13. Children

Dawn is not directed at children and is not for anyone under 16. We do not knowingly collect personal data from a child. If you believe a child has given us data, write to privacy@dawn.am and we will delete it.


14. Changes

If this policy changes in a way that matters, the date at the top changes and anyone with an account is emailed at least 30 days before it takes effect. Small corrections just get a new date.

Where a change requires your consent, we will ask for it rather than assume it.


Contact

Magma Company GmbH
Salvemattweg 11
6340 Baar (ZG)
Switzerland

Privacy and data protection: privacy@dawn.am
Everything else: legal@dawn.am

Company details are on the Impressum.