YOUR DATA, YOUR CHOICE
Privacy
Updated September 29, 2026
Daylight processes camera video on your computer. Camera images are not sent to Daylight. Accounts, email updates, and anonymous usage sharing are separate optional choices; every current camera and background feature works without them.
Location, daylight and weather
Daylight requests your device location only after you choose Use my location and approve the system permission. When live weather is enabled, the app sends approximate latitude and longitude to Open-Meteo to retrieve current conditions. City and postal-code searches send the search text to Open-Meteo’s geocoding service. These requests also include ordinary network information such as your IP address.
Daylight does not send your location to Daylight’s servers. Your selected place and preferences are saved on your computer. Sun position, sunrise and sunset are calculated locally from the selected coordinates and time. You can avoid device-location access by choosing a city, or turn off local time and weather and set both manually. See Open-Meteo’s terms and privacy information.
Clicky website analytics
Clicky loads on every daylightcam.com page and is separate from the optional anonymous usage choice in the desktop app. It measures website visits and interactions and receives page addresses, referrers, browser information and connection information through Daylight’s server. Clicky may use its own cookies depending on its privacy settings.
The Daylight proxy forwards only Clicky-related cookies and does not expose application storage credentials. See Clicky’s privacy policy for details.
Download measurement
When you choose a Windows or Mac download, Daylight records a click counter and, when the download route issues a valid browser redirect, a separate request counter. These counters contain the operating-system platform, Daylight version, a fixed landing-page category and a broad source category such as direct, search, AI assistant, social or referral.
The counters are aggregated by hour in Daylight’s private Railway database. Daylight does not store an IP address, full referrer, query text or browser identifier with them. The server briefly uses an IP address only to limit repeated requests. Aggregate counters expire after approximately 13 months. A request counter means that the server issued a download redirect; it does not prove that the download finished or that Daylight was installed.
Anonymous usage sharing
Usage sharing starts only after you select Anonymous analytics and save the combined account and privacy step. The choice starts off and does not require an account or newsletter subscription. When enabled, Daylight records app starts, periodic active-session heartbeats, webcam starts and virtual-camera starts. Each record contains random installation, session and event identifiers, the Daylight version, operating system, processor architecture and a server timestamp.
Usage records do not contain camera images, microphone audio, location, weather, background or scene choices, email addresses, meeting names, meeting participants or meeting activity. The hosting service processes ordinary network metadata. The telemetry endpoint briefly uses an IP address to limit repeated requests and does not store that address in the telemetry database.
Open Account & privacy in Preferences and turn off Anonymous analytics to stop new records immediately. Existing anonymous records expire after approximately 13 months. A fresh app install uses a new random identity.
Optional Daylight accounts
You can use Daylight without an account. If you request a passwordless login code, Daylight stores your normalized email, the code’s creation and expiry times, delivery state, and a keyed digest of the code. Codes expire after about 10 minutes, can be used once, and are not stored in plaintext. Client addresses are represented only by keyed hashes in persistent abuse limits.
After successful verification, Daylight stores an opaque user ID and hashed, revocable session tokens. The desktop keeps the current token encrypted using Windows credential protection or macOS Keychain; page scripts and the Electron renderer do not receive it. Sessions rotate, have rolling and absolute expiries, and can be revoked by signing out. Account emails are not connected to camera frames, locations, scene choices, or anonymous usage records. Accounts are intended to synchronize generated background packs in a future release; this version does not upload or store those packs.
Optional email updates
We save an email subscription only when you enter an address, select Email updates, and save the combined account and privacy step. Newsletter consent starts off, is independent of account creation and anonymous analytics, and can be saved without creating an account. The private record contains your address, consent text and version, server timestamps, subscription status, app version, operating system and a random signup ID. The app keeps a secret management token; the server stores only its hash. Addresses are currently unverified.
Email records live in a private Railway PostgreSQL database. Older records created before the database migration may also remain in a private Railway storage bucket while we preserve consent and withdrawal history. Authorized operators can export active subscribers; there is no public list. In Preferences, open Account & privacy and turn off Email updates to unsubscribe. We retain consent and withdrawal history to honor that choice and prevent a delayed retry from subscribing you again. Email records currently have no automatic deletion schedule.
Where usage records live
Anonymous usage records are stored in a private PostgreSQL database on Railway, which also hosts the Daylight website. Database credentials remain on the server and are not included in the desktop app.