Daily Drop

Terms & Data Use

Effective 01-07-2026

This page explains, in plain language, what data Daily Drop accesses, how we use it, and how it's stored and retained. For the full policy, including our Google API Limited Use commitment, see our Privacy Policy.

What Daily Drop does

Daily Drop generates a personalized morning-briefing podcast for you and publishes it each morning to your own private podcast feed, which you subscribe to once by URL in a podcast app. To make that briefing feel like it was made for you, it pulls together a few sources you connect.

Data we access

  • Google Calendar (read-only): today's events, to narrate your schedule. We never create, edit, or delete calendar entries.
  • Gmail (read-only, recent mail): only the last 24–48 hours, to surface high-priority messages and follow-ups. Categorization is rule-based. We never send, modify, or delete email.
  • Location: a city or coordinates you provide, used only for the weather segment.
  • News interests: the topics you choose, used to pick stories.
  • Account info: your email address and an optional name (used to greet you in the briefing).

How we use it

Your data is used solely to generate your daily briefing. We do not sell it, share it for advertising, or use it to contact you for marketing. Google Calendar and Gmail access is strictly read-only — Daily Drop never writes to or sends anything from your Google account.

Storage & retention

  • Google tokens are encrypted at rest and limited to the minimum read-only scopes needed.
  • Your briefing audio is stored privately and delivered through your personal feed URL, which contains a secret token. Treat that URL like a password; you can rotate it anytime to invalidate the old one.
  • Account data is kept while your account is active and removed when you delete your account.

Third-party services

To build and deliver your briefing, we rely on:

  • Google APIs — read-only Calendar and Gmail access you authorize.
  • OpenAI — generates the briefing script and the spoken audio. Only the minimal context needed is sent; OpenAI does not use data submitted through its API to train its models.
  • Supabase — authentication, database, and private audio storage.
  • Fly.io and Vercel — application and website hosting.

Your controls

  • Disconnect Google at any time — this revokes our access to your Calendar and Gmail.
  • Rotate your feed URL if it was lost or shared, which permanently disables the old one.
  • Delete your account — this removes your data, revokes Google access, and purges your stored audio.

Contact

Questions about your data or these terms? Reach us at ajay@zen-flow.in.