Privacy, in plain sight.
Analysis in your browser. A clear explanation of how your data gets there.
The short version
- Your Oura data passes through our server on its way to your browser. Your browser stores your history and runs the analysis.
- Daytlas has no server-side health database and no user accounts. We do not store or log your Oura data or tokens on our servers.
- Your Oura connection key is encrypted and kept in a secure cookie that no script can read.
- We do not sell your data, show ads, build marketing profiles or send your Oura data to any AI or large language model.
- You can disconnect and clear your data in this browser at any time, and revoke Daytlas’s access in your Oura account.
Who is responsible
The controller of your personal data is Jakub Had, an individual who builds and runs Daytlas. Contact: hadjkb@gmail.com. There is no data protection officer. Daytlas is independent and is not affiliated with or endorsed by Oura.
When you connect Oura
You sign in on Oura’s own website. Oura asks you to approve each data type, and you can share less than we ask for. We request these Oura scopes: daily, heartrate, tag, spo2 and heart_health. We do not ask for your email or personal information.
With your approval, Daytlas reads: daily sleep, readiness and activity summaries and scores; sleep periods (timing, stages, durations, and heart rate and HRV during sleep); heart rate samples; daily blood oxygen (SpO2); cardiovascular age; and tags you add in Oura, including any custom names or comments. Oura also gives us an access token and a refresh token for your connection.
Purpose: to show your own history in your dashboard and to let you export it. Nothing else.
Legal basis: these readings are health data. We process them only with your explicit consent (GDPR Article 9(2)(a) and Article 6(1)(a)), which you give when you select Connect with Oura and approve access at Oura. You can withdraw consent at any time, see “Disconnect, revoke and delete” below.
How it travels: Daytlas’s server is a small relay on Cloudflare Workers. It exchanges Oura’s authorization code for tokens, protected by PKCE, and encrypts them into a cookie for your browser. Your browser sends that cookie back with each request. The relay decrypts it, refreshes the tokens when needed, and forwards read-only requests to eight fixed Oura API endpoints. Tokens and readings exist on the server only in memory while a request is handled. They are not written to a database, cache or log. Responses are marked no-store.
What stays in your browser
Your browser keeps your copy. The readings it has loaded are cached in IndexedDB, so repeat visits are faster. Connection settings and preferences you set, such as goals, are in local storage. This copy stays until you disconnect, clear this site’s data, or your browser removes it. Another browser or device needs its own connection.
Your Oura access and refresh tokens are kept in a cookie, encrypted with AES-256-GCM. The cookie is HttpOnly: scripts on the page, including Daytlas’s own, cannot read it. The key to decrypt it stays on Daytlas’s server relay and never reaches your browser. Your browser sends the cookie only to Daytlas’s server.
The cached readings are not additionally encrypted by Daytlas. Anyone with access to this browser profile, a browser extension or malicious code running on the page could read them, or use your connection through Daytlas while this browser holds it. Use Daytlas on a device and browser profile you trust, and disconnect on shared computers.
When you import a file
A CSV or ZIP export from Oura is read in your browser. Supported sleep, readiness and activity values are shown in a preview and saved to IndexedDB only after you confirm. The file and its contents are not uploaded to our server. Unsupported columns are not kept. A new import replaces the previous imported snapshot. Keep your original export as a backup.
The demo
The demo uses fictional sample data generated in your browser. It makes no requests to Oura.
How insights are calculated
Trends, comparisons and correlations are calculated in your browser with ordinary statistics. There is no AI or large language model processing of your Oura data, no model training, no automated decision-making and no profiling. Exports to CSV or JSON are created in your browser.
Who else is involved
- Oura is the source of your data. Oura’s own privacy policy applies to your Oura account.
- Cloudflare, Inc. hosts Daytlas and runs the relay as our service provider. It processes network data such as your IP address to deliver and protect the site, and may keep infrastructure logs under its own policies. For the optional Premium interest list it also stores contacts in a database located in the EU and runs the Turnstile spam check.
- Google provides our email mailbox. If you email us, Google processes that message under its own terms.
- PostHog (EU) would receive optional analytics events, but only if analytics is switched on and you allow it. It is switched off today.
We do not sell, rent or share your data with anyone else, and we do not use it for advertising. Cloudflare is based in the United States and its network is global. Cloudflare states that it is certified under the EU–US Data Privacy Framework, and its data processing addendum includes the European Commission’s Standard Contractual Clauses for transfers outside the EEA. See the Cloudflare privacy policy.
Optional website and demo analytics
Analytics is switched off on Daytlas today. If we switch it on, nothing is measured until you allow it. With your permission, selected interface actions on the public website and in the sample-data demo would be sent to PostHog’s EU service: an action category, a timestamp and a random identifier held only in the page’s memory. This is pseudonymous, not anonymous.
We never send health values, goals, page URLs or referrers. Oura-connected and imported-data sessions are always excluded. There is no automatic click capture, session recording or advertising. The legal basis is your consent (GDPR Article 6(1)(a)). Your choice is saved in this browser for up to 180 days. Withdrawing stops future capture but cannot recall events already sent.
Analytics is not enabled on this site.
You can change your choice at any time. Withdrawal stops future capture and clears this tab’s analytics identifier. It cannot recall requests already delivered.
The Premium interest list
Joining the optional Premium interest list stores your email address, where you joined, the wording and time of your permission and your email preferences. It holds no Oura data. The legal basis is your consent (GDPR Article 6(1)(a)). We keep it for up to 12 months from your latest sign-up, unless you unsubscribe or ask us to delete it sooner. See the interest list privacy notice.
The form is protected by Cloudflare Turnstile. Only when you open the form, your browser loads Turnstile from challenges.cloudflare.com, and Cloudflare processes technical data such as your IP address and browser characteristics to check that the request is not automated. The legal basis for this check is our legitimate interest in keeping the list free of automated sign-ups (GDPR Article 6(1)(f)).
When you email us
“Send us feedback” opens a draft in your own email app. Nothing is sent automatically. If you send it, we receive your email address and message and use them only to reply and improve Daytlas, based on our legitimate interest in answering you (GDPR Article 6(1)(f)). We keep messages only as long as needed to handle your request. Please do not include health data, tokens or passwords.
Storage on your device
Daytlas uses only storage that is strictly necessary for the service you ask for, plus one optional item:
- Local storage entries starting with “daytlas.”: whether this browser is connected, the connection mode, preferences and app state. No tokens. Kept until you disconnect or clear site data.
- IndexedDB database “daytlas”: your cached Oura readings or imported history. Kept until you disconnect or clear site data.
- Cookie “daytlas_oura”: your Oura access and refresh tokens, encrypted with AES-256-GCM. HttpOnly, Secure and SameSite=Lax, sent only to Daytlas’s server. Deleted when you disconnect, and expires 90 days after your connection was last renewed.
- Cookie “daytlas_oauth_state”: a random value and a one-time PKCE code verifier that protect the connection flow. HttpOnly, expires after 10 minutes and is deleted when you return from Oura.
- Optional: your analytics choice, saved only when you make one, for up to 180 days.
No advertising or third-party tracking cookies are used.
Security
All connections use HTTPS. The dashboard loads no third-party scripts, except Cloudflare Turnstile when you open the optional Premium interest form, and uses a strict Content Security Policy. Our Oura client secret stays on the server. The relay only accepts same-site requests, forwards them only to Oura’s API and only to eight read-only endpoints, and does not log tokens or readings. The connection flow is protected with a one-time state value and PKCE. Your Oura tokens are encrypted with AES-256-GCM in an HttpOnly cookie readable only by the relay. As explained above, the readings cached in your browser are not additionally encrypted by Daytlas. If we learn of a security incident affecting your data, we will act promptly and inform you and the authorities where the law requires.
Disconnect, revoke and delete
- In Daytlas: use “Disconnect & clear local data” in the footer of any page while connected. It deletes the connection cookie with your tokens and removes cached readings, imported history and preferences from this browser. You can also clear this site’s data in your browser settings.
- At Oura: disconnecting in Daytlas also asks Oura to revoke this connection’s access token. To make sure Daytlas no longer has access, open the Oura app, go to Settings and then App integrations, and revoke Daytlas if it is listed there, or contact Oura Member Care. Revoking stops all further access immediately.
- Deletion request: email hadjkb@gmail.com. We hold no Oura data on our servers, and we delete anything else we hold about you within 72 hours of your request.
- Your copy: you can download your readings as CSV or JSON from your profile at any time.
Disconnecting never deletes your records at Oura. Files you exported stay wherever you saved them.
Your rights
You have the right to access, correct, delete, restrict and port your personal data, to object to processing based on legitimate interests, and to withdraw consent at any time without affecting earlier processing. To use these rights, email hadjkb@gmail.com. We answer within one month. You can also complain to the data protection authority in the EU or EEA country where you live or work, or where you think your rights were infringed.
Children
Daytlas is not intended for anyone under 16. Do not connect an Oura account if you are under 16.
Changes and questions
If this notice changes, we update it here with a new date and explain important changes on the site. Questions about privacy or security: hadjkb@gmail.com. See the project story and the terms.
Updated 5 October 2026.