Data ownership and privacy
Day Planner has no cloud service of its own. Accounts, spaces, projects, tasks, documents, labels, schedules and notifications all live in the PostgreSQL database your server connects to, and each record belongs to exactly one account. The only calls that ever leave the machine are the ones you configure: SMTP, an OIDC provider for external sign-in, or Google Calendar.
Everything belongs to one account
Section titled “Everything belongs to one account”Every space, project, task, label and document carries the id of the account that owns it. Each API request works out who is calling and then filters results by their id, so your sign-in lists and changes only your own things. There is no sharing model: spaces have no members.
The checks run in both directions. Requesting another account’s document returns the same “not found” as an id that doesn’t exist, and linking to records you don’t own fails: creating or updating something with someone else’s space, project, task, schedule or label id is rejected with 400 and the name of the field. Checklist items hang off a task and inherit its owner’s access.
API keys act as their owner
Section titled “API keys act as their owner”An API key resolves to the account that created it and gets exactly that account’s access, never anyone else’s. Day Planner refuses requests that carry neither a signed-in session nor a valid key, and keys belonging to a banned account stop working. See How sign-in and API keys work for what a key can and can’t do.
What admins can see
Section titled “What admins can see”The admin role manages accounts, not content. In Settings, an admin sees the account list — display name, email, role, banned status and join date — and can create accounts, change someone’s role, ban or unban them, and create and revoke invites. Banning signs the person out and stops their API keys. An admin can’t change their own role or ban themselves.
Admin status doesn’t widen data access. The spaces, projects, tasks, documents and labels endpoints always filter by the caller’s own account, so an admin gets the same view of your work as anyone else.
Self-hosting keeps the data with you
Section titled “Self-hosting keeps the data with you”Everything sits in the PostgreSQL database you configure, and Day Planner sends nothing to a service of its own. Optional features contact other systems only where you’ve set them up: SMTP for email, and an OIDC provider for external sign-in. Google Calendar is not wired up yet. Morning summaries and deadline warnings are generated from your own tasks and stored in the same database.
Day Planner doesn’t back up the database for you; that’s part of running the server. See Backups for how to protect it.
Who can sign up
Section titled “Who can sign up”An instance-wide sign-up policy decides who can join:
- closed (the default): only an admin creates accounts;
- invite: people join through an invite link an admin creates;
- open: anyone who can reach the site can sign up.
Invite links work for seven days and work whatever the policy is, as do accounts an admin creates directly. Signing in with an external provider creates a new account only while the policy is open; it can still link to an existing account at any policy. See Users and sign-up for the details.
See also
Section titled “See also”- How sign-in and API keys work: what a key can and can’t do
- Backups: protect the database yourself
- Users and sign-up: decide who can join
- API keys: create a key for an agent