‹ Back to Doneday

Privacy Policy

Last updated: August 25, 2026

Doneday has no server, no database and no user accounts. Your calendar data is never sent to us, because there is nowhere for it to be sent. This page explains that in detail.

Who runs Doneday

MATEDRA, obrt za poslovno savjetovanje, edukacije i digitalne usluge
Owner: Dražen Eldić
Ljudevita Rossia 33A, 47000 Karlovac, Croatia
OIB (tax number): 25386701111
Contact: info@matedra.com

What Doneday reads

When you sign in with Google, Doneday asks for a single permission: see events on all your calendars (calendar.readonly). That is a read-only scope. Doneday is technically unable to create, edit, move or delete anything in your calendar, even if it wanted to.

With that permission, your browser requests the list of your calendars and the events for the day you are looking at. For each event it uses the title, start and end time, location and the name of the calendar it came from.

Where that data goes

Nowhere. Your browser talks directly to Google's API. The events are held in the memory of the browser tab and are drawn on screen. Our web server only delivers the HTML, CSS and JavaScript files that make up the page — it never receives your calendar data and could not store it if it did.

What is stored on your device

Doneday keeps three things in this browser's local storage:

All three live only in the browser you used. They are not synchronized anywhere, and nobody else can read them. Clearing your browser data deletes them permanently — there is no backup, ours or anyone else's.

Your Google access token

Signing in produces a short-lived access token, valid for roughly one hour. It is kept in the memory of the page only, never written to storage, and it disappears when you close the tab. Doneday does not use a refresh token and cannot access your calendar while you are not using the app.

Google API Services User Data Policy

Doneday's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: calendar data is used only to display your day to you, it is never transferred to anyone, it is never used for advertising, and no human ever reads it.

Visitor counting

We count page visits with GoatCounter, an analytics service that sets no cookies and collects no personal data. It records that a page was opened, roughly from where and with what kind of browser, and nothing that identifies you. We deliberately do not use Google Analytics.

This tells us how many people visit — not what is in your calendar, which we could not see in any case.

Hosting

The files are served by Hostinger. Like any web server, it writes standard access logs that can include IP addresses. We do not analyze those logs and they contain no calendar data.

What we never do

Removing your data

There is nothing on our side to delete, so a request to us would achieve nothing. To remove everything yourself:

Under the GDPR you have the right to access, correct, delete and port your personal data, and to complain to a supervisory authority — in Croatia, AZOP. Those rights apply to personal data a company holds about you. In our case the honest answer is that we hold none.

Children

Doneday is not directed at children under 16. It requires a Google account and shows only that account's own calendar.

Changes

If this policy changes, the date at the top changes with it. Doneday is not verified by Google yet; if that changes, this page will say so.

Questions

Write to info@matedra.com. A real person reads it.

Doneday · Terms of Use · info@matedra.com