Transparency
Privacy Policy
Daybreak is built for calm, private reading — without tracking cookies, ad tech, or behavioral profiling.
Effective date: September 14, 2026
1. No Tracking Cookies, No Banners
We do not use tracking cookies, advertising pixels, or cross-site identifiers. Because we set zero tracking or non-essential cookies, you will never see an intrusive cookie consent banner on Daybreak.
Routing relies on explicit URL paths and the standard Accept-Language header your browser already sends. Any address carrying an edition — /en-gb, say — is self-sufficient and needs no cookie at all.
One exception: if you explicitly choose a language yourself — during setup, in Settings, or with “Switch language” — Daybreak remembers that single decision in a cookie called “daybreak-locale”. It holds nothing but the edition you chose (a language and a region, such as “de-at”) and expires after one year. Its only job is to open the front page in your language next time.
It carries no identifier, no timestamp, and nothing that could tell two readers who picked the same edition apart. Our server never sets it on its own — it exists only because you clicked; skipping setup or following someone else's link leaves you without one. Delete it and automatic detection simply resumes. Because it records nothing but a choice you made yourself, it is strictly necessary to deliver the functionality you asked for (§ 25(2) TDDDG / ePrivacy Directive) and needs no consent: you will still never see a cookie banner.
2. Local Device Storage (localStorage & sessionStorage)
To provide core reader features like saved articles and display modes, Daybreak uses your browser's local storage (strictly necessary to deliver requested functionality under § 25(2) TDDDG / ePrivacy Directive). This data resides on your device:
daybreak-reader: Stores your saved-for-later articles (/saved), read article IDs (for unread indicators), custom RSS feed URLs, preferred regional editions, and your last visit timestamp to calculate unread stories.daybreak-theme: Remembers your light or dark display theme preference.daybreak-reading-mode: Remembers your Standard vs. Newspaper layout preference.daybreak-visit-baseline(sessionStorage): Temporarily tracks your visit baseline in the active browser tab to calculate unread stories.
You can delete all locally stored data at any time by clearing website data in your browser settings.
3. Custom RSS Feeds & Server-Side Processing
When you add or preview a custom RSS feed, your browser transmits the entered feed URL to our /api/feed endpoint. Our edge server fetches, sanitizes, and parses the public RSS XML, returning article summaries. The same applies when an article image is too low-resolution: your browser sends the public article URL to our /api/og-image endpoint, which retrieves the article's full-resolution preview image. Both feed previews and these resolved images are cached ephemerally.
To prevent overload and abuse, requests to our endpoints — the two above, and the reader described in section 4 — have their client IP address processed ephemerally for rate limiting (legal basis: Art. 6(1)(f) GDPR, legitimate interest in service reliability); for the image lookup and the reader, a request answered from cache skips even that — not for the feed preview, where the rate limiter runs before the cache. The rate limiter itself builds no usage profile and keeps nothing beyond the current window. For the operational logs in which request data is retained briefly beyond this, see section 5.
4. The In-App Reader
By default, selecting a story opens it in Daybreak's built-in reader. To do that, your browser sends the public address of that one article to our /api/article endpoint; our server fetches the publisher's page and extracts its body text (legal basis: Art. 6(1)(b) GDPR — providing the functionality you asked for). Together with the image request described in section 3, this is what tells our server which individual article you opened; opening a story can itself trigger that image request for the same article, because the reader's large illustration needs a higher resolution than a card does.
Successfully extracted text is cached for about ten minutes. It is addressed by the article's own URL, with no reference to you, and shared by every reader: the cache records that an article was fetched, never by whom. Failed requests are not cached at all.
We do not bypass paywalls. Where only a teaser survives extraction, or a publisher blocks automated requests, the reader shows the feed's own summary and links out to the original instead. How Daybreak identifies itself to publishers, and how often it fetches, is set out on the page for publishers.
You can turn the reader off: under Settings → General → “Open articles in”, choose “New tab”. Stories then open directly at the publisher again, and no /api/article request is made at all.
5. Infrastructure & Edge Delivery
Where Daybreak is delivered through Cloudflare Workers and Cloudflare's global edge network (Cloudflare Inc., 101 Townsend St, San Francisco, CA 94107, USA), Cloudflare processes technical request data (IP address, user agent, timestamps) to deliver cached content securely and mitigate attacks.
Where Daybreak is delivered through Cloudflare, any associated data transfers to the US are protected by Cloudflare's certification under the EU-U.S. Data Privacy Framework (DPF) and Standard Contractual Clauses (SCCs) pursuant to Art. 46 GDPR.
For operation and troubleshooting, Daybreak produces short-lived logs of requests to its own server (Cloudflare Workers Logs). Alongside technical request data these can include the address requested — for the endpoints in sections 3 and 4, that is the article's own address — and the request's IP address. On the plan in use, Cloudflare retains these logs for seven days and then deletes them automatically; we consult them solely to keep the service running (legal basis: Art. 6(1)(f) GDPR).
Where Daybreak is delivered through Cloudflare, automated threat mitigation may issue strictly necessary security tokens (e.g. __cf_bm). Aggregate analytics are provided through Cloudflare Web Analytics, which is enabled for this site: it records page views and performance data without cookies, without cross-site tracking, and without building a profile of you.
6. External Article Images & Publisher Links
Every story names its source and leads to the publisher's original article — directly, if you have turned the reader off, and otherwise through the source link the reader carries (section 4). Thumbnail images are requested from publisher hosts with referrerPolicy="no-referrer", preventing external servers from learning which Daybreak page or desk you are viewing.
7. Your Privacy Rights (GDPR)
Under the General Data Protection Regulation (GDPR), you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection (Art. 21). You also have the right to lodge a complaint with a supervisory authority.
8. Data Controller & Contact
The data controller for this website is the operator of Daybreak. For privacy inquiries, please reach out via the contact information provided in our Legal Notice.