Effective date: September 3, 2026
Last updated: September 2026
This Privacy Policy explains how Masilela Creative Studio (Pty) Ltd, trading as Dailies ("Dailies", "we", "us", "our"), collects, uses, discloses, and protects information in connection with the Dailies platform.
Masilela Creative Studio (Pty) Ltd is a private company registered in South Africa under registration number 2021/536143/07, with its registered office at Glen Austin Unit 58, 69 Glen Austin Road, Glen Austin AH, Gauteng, 1685.
This policy is written to comply with the Protection of Personal Information Act 4 of 2013 ("POPIA"). It applies to our website, our application, and the services we provide. It should be read together with our Terms of Service, which govern your use of Dailies more broadly.
This Privacy Policy does not constitute legal advice, either to you or about your own obligations under POPIA or any other law. If you require legal advice, you should consult a qualified attorney.
POPIA distinguishes between a "responsible party" (the party who decides why and how personal information is processed, and who bears legal accountability for that processing) and an "operator" (a party who processes personal information on behalf of, and under the instruction of, a responsible party).
This distinction matters for how Dailies works, because Dailies plays both roles depending on whose information is involved:
Masilela Creative Studio is the responsible party for personal information relating to your own Dailies user account, billing and subscription information, support requests and communications you send us directly, and visitors to our website.
You (the business using Dailies) are the responsible party for personal information you enter into Dailies about your own customers, suppliers and vendors, employees or contractors, and any other individual whose information you record in the platform.
Dailies acts as an operator when we process that customer-entered information on your behalf, strictly to provide the platform's functionality. We process this information only as necessary to operate Dailies, and do not use it for our own independent purposes.
This means that if one of your customers, suppliers, or employees wishes to exercise a right under POPIA regarding information you have entered about them into Dailies, that request should ordinarily be directed to you, not to Dailies directly. We will, however, reasonably assist you where necessary.
POPIA protects personal information relating to both natural persons and, in most respects, juristic persons (companies). Since much of the customer and supplier information recorded in Dailies relates to businesses rather than individuals, this broader protection is relevant.
Your account: name, email, phone number, login information, organisation membership and role.
Your business: business name, registration number, industry, address, contact details, banking details for invoices, logo and branding.
Financial records you create: customer and supplier records, invoices, estimates, bills, receipts, journal entries, Chart of Accounts, projects, recurring invoice templates.
Banking and transactions: bank account information, imported bank statements, transaction categorisation and reconciliation data.
Documents: files you upload directly, and references to files you link from Google Drive where connected.
Communications: support correspondence, and system-generated emails sent through the platform on your instruction.
Technical information: IP address, browser and device information collected as a normal part of web hosting. We do not use analytics, advertising trackers, or session-recording tools.
We only collect what is described above — not information merely because other software products commonly collect it.
To provide the core Dailies platform, send communications you request, provide optional AI-assisted features you choose to use, maintain your account and permissions, respond to support requests, and maintain platform security.
We do not sell your information, or information you enter about your customers or suppliers, to any third party. We do not use financial data for advertising.
Dailies offers, or plans to offer: AI Categorisation, AI Receipt Capture, Ask Dailies, and (planned) AI Payment Follow-ups — all provided using Anthropic's Claude API. When you use one of these features, relevant information is sent to Anthropic to generate a response.
Under Anthropic's Commercial Terms of Service, customer content is not used to train Anthropic's models by default, and conversation content submitted through the API is not retained by default. Anthropic may retain flagged content longer under its own safety systems. Refer to Anthropic's own documentation for current details.
Every AI feature requires you to take an action to use it — none run automatically on your data. AI-generated suggestions are recommendations only; you review, edit, or reject them before they affect your records.
We do not use your financial information to serve advertising, to you or anyone else.
Dailies processes bank account details, imported bank statement transactions (dates, amounts, descriptions, payee information), categorisation against your Chart of Accounts, and invoice/bill payment matching — solely to provide the accounting functionality you've requested.
If you connect Google Drive: Dailies requests Google's "drive.file" scope — the narrowest access Google offers. This does not grant access to your wider Drive.
Dailies can only access files you specifically select via Google's file picker, or files Dailies itself creates. We cannot browse, list, or search the rest of your Drive.
When you link a file, we store a reference (the file's identifier, name, and type) rather than copying the document into our own storage — the physical file stays in your Google Drive.
You can disconnect at any time from Settings. Disconnecting stops future access; existing references remain as a historical record but no longer provide working access unless you reconnect.
Deleting a Dailies reference does not delete the Google Drive file. Deleting the Drive file does not delete the Dailies record — it simply becomes inaccessible via that reference.
A connected accountant does not receive your Google credentials or independent Drive access — only access through the same Dailies permissions that already govern their access to your business.
Dailies cannot bypass Google's own sharing and permission system.
We use a limited number of providers, each only for its specific function:
| Provider | Purpose | Data location |
|---|---|---|
| Supabase | Database, authentication, file storage | Ireland (AWS eu-west-1) |
| Vercel | Application hosting | Primarily United States, global CDN |
| Anthropic | AI-assisted features | United States |
| Resend | Sending emails on your instruction | United States |
| Optional Drive document linking | Global (your Google account) | |
| PayFast | Subscription payment processing | South Africa (not yet in use) |
Some information is transferred across South African borders, regulated under section 72 of POPIA. The database, authentication, and storage holding the core of your Dailies data is located in Ireland, within the European Union.
Some processing involves transfers to the United States: Anthropic (AI features, under its Commercial Terms), Resend (email content and logs, under Standard Contractual Clauses and the EU-U.S. Data Privacy Framework), and Vercel (hosting).
Where we transfer information outside South Africa, we rely on the recipient being bound by terms providing protection substantially similar to POPIA, or on the transfer being necessary to provide the service you've requested. We continue to review these arrangements as Dailies grows.
Encryption in transit (HTTPS throughout); encrypted storage of particularly sensitive credentials such as Google Drive tokens (AES-256-GCM, decrypted only in memory, server-side); organisation-level access controls on every request; role-based permissions across four tiers (staff, accountant, admin, owner); server-side authorisation that cannot be bypassed from the browser; and database-level access restrictions alongside application checks.
We rely on Supabase and Vercel for underlying protections such as encryption at rest and infrastructure backups — refer to their own published documentation for specifics.
We do not currently hold SOC 2, ISO 27001, or any other formal security certification. No internet-connected system can guarantee absolute security, but we take ongoing, reasonable steps to reduce risk.
If we have reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person, we will notify the Information Regulator and affected individuals (unless their identity cannot reasonably be established) as soon as reasonably possible, per section 22 of POPIA. POPIA sets no fixed deadline and does not require a completed investigation before notifying.
Account information is retained while your account is active and briefly after. Financial and accounting records are retained for as long as your account is active — because these are often subject to statutory retention requirements, we do not automatically delete them immediately on request where such an obligation may apply. We have not yet designed or validated a feature guaranteeing compliance with every applicable statutory retention obligation. Documents and Drive references are retained alongside the records they relate to. Communications, security logs, and backups are each retained for a period appropriate to their purpose.
Deleting a record removes it from the live application, subject to retention considerations above. Disconnecting Google Drive stops future access without deleting your Drive files or existing references. Closing your account or deleting an organisation initiates deletion of that data, subject to the same retention considerations. Deleting a file directly in Google Drive makes the Dailies reference show as unavailable without deleting the Dailies record.
Subject to the exceptions above, you have the right to access, correct, or request deletion of personal information we hold about you; to object to processing on reasonable grounds; to withdraw consent where consent was the basis for processing; and to lodge a complaint with the Information Regulator.
To exercise these rights, contact us at privacy@mcstudio.co.za. If your request relates to information a business entered about you into Dailies, that business is ordinarily the responsible party and may be better placed to assist directly.
The Information Regulator of South Africa: inforegulator.org.za
Dailies uses only strictly necessary cookies: authentication cookies that keep you logged in, and a short-lived (~10 minute) cookie used only while connecting Google Drive. We do not use analytics, advertising, or tracking cookies. Vercel logs basic request information as normal hosting infrastructure — this is not used to build a profile of your activity. Because we use no non-essential cookies, we do not display a cookie banner or maintain a separate Cookie Policy.
Masilela Creative Studio's Information Officer can be contacted at privacy@mcstudio.co.za.
We may update this policy as Dailies evolves or our legal obligations change. The "last updated" date above reflects the most recent revision. Material changes will be communicated by email or an in-app notice where reasonably practicable.
privacy@mcstudio.co.za
Masilela Creative Studio (Pty) Ltd — Registration number: 2021/536143/07
Glen Austin Unit 58, 69 Glen Austin Road, Glen Austin AH, Gauteng, 1685
This Privacy Policy is provided for general information purposes and does not constitute legal advice.