Skip to content
DashyV2

Privacy & data

Dashy Privacy Policy

Dashy is a browser extension that replaces your new tab with a customizable dashboard. You can use the core dashboard without an account. Account, sync, AI, integration, sharing, and billing features are optional and may use cloud services only when needed.

Last updated
Applies to
Dashy browser extension and website

Short Version

  • Dashy is local-first. Most settings, layouts, widget data, cached content, customizations, and browser-derived data live in browser storage on your device.
  • You do not need an account to use the core dashboard.
  • Dashy asks before collecting extension product analytics. Website analytics follows the regional settings explained below and can be turned off at any time. Product analytics uses pseudonymous identifiers and a closed event/property list; it does not include your dashboard content, searches, URLs, prompts, browser history, or integration data.
  • If you sign in, Dashy uses Supabase for authentication, account profile, cloud sync, shared dashboards, feature usage limits, and private file storage.
  • If you use AI features, prompts, relevant conversation context, selected page context, or voice session data may be processed by OpenAI through Dashy's Supabase Edge Functions.
  • If you connect an integration, Dashy uses that provider's OAuth flow and APIs only for the features you connect.
  • Dashy does not sell user data, does not use user data for personalized ads, and does not transfer browser, Google, or integration data to data brokers.
  • Dashy's use and transfer of user data received from Chrome extension APIs and Google APIs complies with the Chrome Web Store Limited Use requirements and the Google API Services User Data Policy, including their Limited Use requirements.

Data We Process

Account and authentication

If you create or sign in to a Dashy account, we process account identifiers needed to authenticate you and keep your data associated with your account:

  • Supabase user ID, session state, account tier, and auth provider metadata.
  • Email address if you use email, magic link, Google sign-in, or passkeys.
  • Google profile fields provided during sign-in, such as name, email, and avatar, when you choose Google sign-in.
  • Display name and avatar URL if you add or update them.
  • Passkey public credential metadata, friendly name, counters, transports, registration/login challenges, and last-used time. Dashy does not receive your private passkey.
  • MFA/TOTP factor metadata when you enable multi-factor authentication.

Passwords and authentication secrets are handled by Supabase Auth. Dashy does not store your password in application tables.

Access and product-update requests

If you join a Dashy access or product-update waitlist, Dashy stores the normalized email address you submit in Supabase so we can deduplicate requests, manage access, and send the updates you requested. Joining a waitlist does not create a Dashy account and is not consent to unrelated marketing.

If you have allowed website measurement, Dashy may link an accepted waitlist request to an opaque first-party acquisition session for aggregate campaign measurement. Your email address is not included in analytics or advertising-conversion payloads and is not sent to an advertising platform.

The signup endpoint applies short-lived abuse limits using a salted one-way hash of the requesting IP address. The waitlist does not store the raw IP address, and email addresses are not written to application logs. You can ask us to remove a request by emailing support@dashyapp.com from the address you submitted.

Feedback and support

If you submit the website feedback form, Dashy stores the feedback category, message, optional browser/operating-system description, optional follow-up email, and whether the form was opened from the extension's uninstall flow. An opaque uninstall association token may be included so Dashy can understand aggregate uninstall feedback without putting that token in a server-visible URL. The token is removed from the page address immediately and is sent only when you choose to submit the form. You can use the direct email fallback instead.

Dashboard, settings, and widget data

Dashy stores dashboard configuration and content so the product can render your new tab:

  • Theme, appearance, search preference, layout, dashboard list, widget positions, widget settings, and side panel preferences.
  • Non-private widget data such as todos, notes, habits, goals, bookmarks-style dashboard content, reading lists, calendar display preferences, and generated AI widget definitions.
  • Dashy Agent conversations when conversation sync is enabled.
  • Local AI widget storage scoped to each AI widget instance.
  • Wallpaper references, uploaded wallpapers, AI-generated wallpapers, and profile avatars when you choose those features.

For signed-in users, sync is controlled by Settings -> Account -> Sync & Privacy. The current categories are settings and appearance, widget layouts, widget data, and agent conversations.

Connected AI apps and Visual Brain

If you explicitly connect an AI app through Dashy’s Model Context Protocol (MCP) authorization screen, Dashy maintains a separate revisioned Visual Brain cloud copy. Depending on the permissions you approve, that app can read or change dashboard structure, supported appearance preferences, and the global Notes and To Do stores across Dashy. Fixed public wallpaper links and their attribution can be read or changed through that permission. A direct wallpaper URL is stored as a synced setting and is contacted by your browser when Dashy displays it. This path is separate from the ordinary Account sync categories above.

Dashy does not select or send your data to an AI provider on its own. The connected app accesses Dashy using your authorization. Restricting a connection to selected dashboards, or excluding any dashboard from MCP, withholds the global Notes and To Do stores from that connection. You can inspect and disconnect connections in Settings -> AI connections. Private local-only widget data is never included.

Local-only private widget data

Dashy treats some widget data as private to the local device by default. The current local-only blocklist prevents these widget types from being automatically synced to Supabase or copied into shared dashboards:

  • Medication reminder
  • Period tracker
  • Photo wall and photo-wall metadata
  • Screen recorder and screen-recorder metadata
  • Voice memos
  • Expense log
  • Subscription tracker
  • Net worth entries and net worth history
  • Sleep log
  • Journal
  • History search
  • Site time tracker

These data types stay local unless Dashy later builds a separate explicit opt-in flow, such as encrypted sync or a user-confirmed export.

Browser data and permissions

Dashy uses browser extension APIs to power dashboard widgets and agent tools. Depending on the feature, Dashy may read or act on:

  • Open tabs, tab groups, recently closed sessions, and active tab context.
  • Bookmarks and bookmark search.
  • Browser history and top sites for history, top-site, and time-spent widgets.
  • Downloads metadata for download-focused widgets.
  • Browser notifications for reminders and timer-style workflows.
  • The active page only when you ask a widget or Dashy Agent to inspect, summarize, or act on that page.

Browser-derived data is used to provide the specific dashboard, widget, side-panel, or agent feature you request. Dashy does not use this data for advertising, resale, credit decisions, or unrelated profiling.

Location

Weather and location-aware widgets may use browser geolocation if you allow it. If browser geolocation is unavailable or denied, Dashy may use IP-based lookup services to estimate city-level location. Location results are cached locally for performance.

AI And Integrations

AI features

Dashy AI features use server-side relays so provider API keys are never included in the extension:

  • Text agent requests send conversation input, tool schemas, and relevant context to Dashy's Supabase relay, which forwards the request to OpenAI.
  • AI widget generation sends your prompt and recent widget-generation conversation context to Dashy's OpenAI relay. Generated widget HTML is sanitized before it can be saved or rendered.
  • AI wallpaper generation sends your wallpaper prompt to Dashy's image relay and receives a generated image.
  • Voice mode mints a short-lived OpenAI Realtime session token. During a voice session, audio and transcribed text may be processed by OpenAI to provide the live response.

AI features are optional and subject to feature limits. Do not submit sensitive information to AI features unless you are comfortable with that information being processed by Dashy and OpenAI for the requested feature.

Connected integrations

If you connect an integration, Dashy uses OAuth and the provider's API only for the feature you connect. OAuth integrations offered in current distributable builds are Google Calendar, Google Tasks, Todoist, GitHub, Notion, and Linear. Raindrop.io and Asana integrations are implemented but are not offered in distributable builds until their production credentials and configuration are complete and the unchanged packaged extension passes real-provider OAuth testing.

During an active browser session, the extension keeps provider access tokens only in browser session storage. Long-lived provider credentials needed for exchange, refresh, and revocation are stored in a user-scoped Supabase OAuth vault and encrypted at rest with AES-256-GCM. Persistent browser storage contains connection metadata, not raw OAuth credentials. Dashy's Supabase Edge Functions perform provider exchanges, refreshes, and revocations without exposing provider client secrets to the extension.

Connected provider data may include task titles, calendar events, page titles, repository and issue metadata, bookmark metadata, project and assignment metadata, or other content returned by the scopes you grant. Safe display data is cached locally for the feature and expires no later than 30 days after it is cached. A successful disconnect asks the provider to revoke the server-held credential when supported, then purges that provider's Dashy-held credential, metadata, and cached data.

GitHub's classic OAuth repo scope technically grants broad read and write access to public and private repositories because GitHub does not offer a read-only private-repository scope for classic OAuth Apps. Dashy uses that grant only to read repository, issue, pull-request, and review metadata. Dashy's only GitHub mutation is marking a notification read after you use that control.

Private calendar feeds

You can add a private, read-only ICS calendar feed. The feed URL and parsed event cache stay in local extension storage and are not synced to Supabase or shared with other Dashy users. Dashy requests browser access only to the feed URL's exact HTTPS origin and fetches the calendar directly from that origin. Removing the feed purges its URL, cached events, and exact-origin permission.

Treat a private calendar feed URL like a password: anyone who obtains the URL may be able to read the calendar exposed by it. Use a read-only feed, do not paste a URL you do not trust, and revoke or regenerate the URL with your calendar provider if it is exposed.

Dashy is not created by, affiliated with, or supported by Doist.

Billing and feature usage

If you upgrade or manage a subscription, Dashy processes:

  • Current plan, subscription provider, subscription status, renewal/cancellation dates, and provider customer/subscription IDs.
  • Feature usage counters for metered features such as AI agent messages, voice minutes, AI widget generations, and AI wallpaper generations.
  • Checkout metadata sent to Lemon Squeezy, including your Dashy user ID and email address, so the subscription can be associated with your account.
  • Billing portal information returned by Lemon Squeezy, such as card brand and last four digits, when shown in the app. Full payment details are handled by Lemon Squeezy or PayPal, not by Dashy.

Sharing and invites

If you share a dashboard, Dashy stores the shared dashboard payload, collaborator permissions, invitee email addresses, invite status, and related metadata in Supabase. If email invites are enabled, Dashy uses Resend to send transactional invite emails.

Analytics and diagnostics

Dashy does not collect extension product analytics until you explicitly allow it in Settings -> Privacy. If allowed, Dashy records a small closed set of events needed to understand activation, retention, feature adoption, and reliability, such as first dashboard render, a daily-active summary, dashboard mode, registered widget type added or removed, and whether a crash fallback appeared. Events contain a pseudonymous installation ID, a rotatable actor ID, event UUID, timestamp, app/browser version, and strictly allowlisted low-cardinality properties.

Dashy never includes note or task text, widget content, URLs, page titles, hostnames, search queries, prompts, conversations, email address, name, OAuth data, browser history, or precise location in product analytics. High-frequency activity is reduced to daily milestones or summaries. Events wait in a bounded local queue and are sent to Dashy's Supabase validation gateway, which may forward accepted events to PostHog Cloud EU. PostHog autocapture, session recording, surveys, advertising profiles, and client-side extension SDKs are not used.

You can decline or later withdraw product analytics in Settings -> Privacy. Declining prevents capture; withdrawal clears queued events and rotates or removes the relevant processor association. A server-side kill switch can disable ingestion independently of the extension release.

This marketing website uses Google Analytics and PostHog Cloud US to understand visits, selected interactions, signup outcomes, and error categories. It records pseudonymous browser identifiers, browser/device information, public page groups, and referral/campaign labels. Session replay and PostHog autocapture are disabled. We do not send entered text, signup email addresses, prompts, or original error messages and stacks to either provider.

Website analytics is on by default for visitors whose country is identified as the United States, Australia, or New Zealand, unless they have turned it off or their browser sends Global Privacy Control. In other countries, or when the country cannot be determined, analytics waits for an explicit Allow choice. Your previous refusal is respected in every region. Use Analytics settings in the footer to turn analytics on or off. These website settings do not enable extension product analytics or the separate installation and advertising-conversion measurement.

To choose the appropriate website setting, we make a first-party request to Dashy’s website. Our hosting provider estimates the country from the connection’s IP address. The response contains only the applicable setting and whether a Global Privacy Control signal is present; it does not contain your IP address or country. This lookup does not request access to your device’s precise location. We store an explicit analytics choice in your browser’s local storage. When website analytics is enabled, the providers may use cookies or browser storage for pseudonymous measurement identifiers.

The website also uses Vercel Analytics and Speed Insights for cookieless aggregate visitor and performance measurements. These start after the regional setting is resolved, do not require an explicit analytics grant, and stop if you refuse analytics or send Global Privacy Control. Private admin pages are excluded from all website analytics.

The Dashy website separately asks before storing a first-party acquisition session or permitted campaign parameters. With website consent, Dashy may process UTM values, landing path, referring host, and advertising click IDs supplied in the landing-page link. A short-lived, one-time secret in the installed-page URL fragment can connect that website session to an installation without browser fingerprinting. The fragment is removed immediately and the raw secret is not used as an analytics property. If you withdraw website measurement, capture stops immediately. Until Dashy's gateway acknowledges the withdrawal, the browser retains and retries a minimal pending-withdrawal marker containing only the opaque acquisition-session ID; it does not retain campaign values, advertising click IDs, page data, or submitted content in that marker. A changed consent notice also disables measurement and uses the same withdrawal process before the old session capability is cleared.

Advertising platforms may receive only consented website or billing conversion facts, their own click identifier, a transaction/event ID, event time, value and currency, and consent status. Dashy does not send extension behavior, browser API data, Google API data, connected-integration data, or PostHog identifiers to advertising platforms, and does not use this data for personalized advertising or retargeting.

Why We Process Data

Dashy processes data for these purposes:

  • Provide the new tab dashboard, widgets, side panel, command palette, browser workflows, and Dashy Agent.
  • Save your settings, layouts, widgets, wallpapers, and preferences.
  • Sync your data across devices and browsers when you sign in and keep sync enabled.
  • Connect optional integrations that you authorize.
  • Generate AI widgets, AI wallpapers, text-agent responses, and voice-agent responses when you request them.
  • Enforce feature limits, subscriptions, abuse controls, and billing status.
  • Send transactional messages such as dashboard invites.
  • Improve reliability, debug crashes, and support users.
  • With consent, measure acquisition, activation, retention, feature adoption, subscription conversion, refunds, and aggregate campaign profitability.
  • Comply with law, store policies, security obligations, and fraud prevention needs.

Third-Party Processors And Services

Dashy may use these services depending on which features you use:

Dashy does not sell user data. Dashy does not transfer user data for personalized advertising, data brokerage, credit eligibility, lending, or unrelated profiling.

Limited Use Statement

Storage, Security, And Retention

  • Data in transit is sent over HTTPS.
  • Supabase protects cloud data with database access controls and row-level security policies. Most user-owned tables are scoped to the authenticated user.
  • Local extension data is stored using browser-managed storage. Browser storage is protected by the browser and operating system profile, but Dashy does not separately encrypt all local values.
  • Safe display data cached from a connected provider expires no later than 30 days after it is cached. Disconnecting an integration purges that provider's local cache, connection metadata, and session credentials.
  • A private ICS feed URL and its parsed event cache remain local until you remove the feed, clear local data, or uninstall Dashy. Removing the feed also removes Dashy's exact-origin browser permission for its host.
  • Signed-in cloud data remains while your account is active or as long as needed for the feature, legal, billing, security, and support purposes.
  • Anonymous Supabase accounts may be cleaned up after 30 days of inactivity when the cleanup job is enabled.
  • Billing, support, and security records may be retained longer when needed for legal, tax, fraud prevention, chargeback, or audit reasons.
  • Acquisition sessions, attribution claims, analytics receipts, and delivery-outbox records are retained only for their documented operational and deduplication windows and then deleted or aggregated. One-time claims expire and cannot be reused.

Your Controls

You can:

  • Use Dashy without signing in.
  • Turn website analytics on or off at any time using Analytics settings in the footer. We respect Global Privacy Control as a request to keep website analytics off.
  • Turn cloud sync categories on or off in Settings -> Account -> Sync & Privacy.
  • Use Settings -> Privacy to review browser permissions and agent capabilities.
  • Add protected sites that Dashy Agent may not read, summarize, click, or type on.
  • Disconnect integrations from the Integrations settings area.
  • Revoke optional browser permissions such as notifications and top sites when supported by the browser.
  • Clear recent local agent activity.
  • Export a dashboard as a local JSON file.
  • Sign out, which clears most local user data from the browser profile and resets local settings.

Account Deletion And Data Requests

Settings -> Account -> Data & Account can export your Dashy cloud account data as JSON and delete your Dashy cloud account. The deletion flow removes owned Supabase Storage objects, invite rows tied to your account or email, Supabase Auth, encrypted integration credentials, Supabase application rows that cascade from your Auth user, passkey metadata, shared dashboards, public share links, and feature usage records. Before erasing the account, Dashy makes a best-effort request to revoke each connected provider grant. A provider rejection, outage, or unsupported revoke endpoint does not block account deletion: Dashy's encrypted vault credentials are erased even when provider revocation fails, so Dashy can no longer use them. A residual authorization may remain at the provider; you can remove it from that provider's connected-app or account settings.

If the in-product flow fails, request account deletion, cloud data deletion, or a full cloud data export by contacting support@dashyapp.com from the email address associated with your Dashy account. Billing-provider records, payment-provider records, support records, and security/audit records may be retained where needed for tax, fraud prevention, chargeback, audit, legal, or security obligations.

Children

Dashy is not intended for children under 13. Do not use Dashy if you are not old enough to consent to the processing described in this policy.

Changes

Dashy may update this policy as the product changes. Material changes to data collection, use, sharing, AI processing, analytics, or permissions should be disclosed in the product and reflected here before or when the change ships.

Policy Sources