Skip to main content
Limited-Time Offer: Get 1 Year FREE with Code DAYSTAGE12

Privacy Policy

Last updated: August 2026

If you are reviewing Daystage for a school district, our security and privacy page covers the same ground in the format a vendor review usually asks for, including data residency, sub-processors, and FERPA.

What we collect

When you create an account, we collect your name and email address, and the school or district name and role you give us. When you send newsletters, we store the content you create and basic delivery data (recipient emails, open events, click events, bounces, and spam complaints). Daystage has no password field: you sign in either with a Google account or with a single-use link sent to your email, so we never set or store a password.

How we use it

We use your data to operate Daystage: delivering your newsletters, showing you analytics, and sending transactional email such as sign-in links and delivery receipts. We do not sell your data.

Your newsletter content and your subscriber lists are never used for advertising. If you accept marketing cookies, we do share conversion events from our own marketing pages with Google and Meta, for example that a signup or an upgrade happened, so we can tell which of our ads worked. That is limited to your own visit to daystage.com and never includes your subscribers. Decline marketing and we send nothing.

Subscriber data

Email addresses you upload for your subscriber lists are stored securely and used only to deliver newsletters you send. Recipients can unsubscribe at any time via the unsubscribe link in every email. A recipient who unsubscribes is kept in that state so that a later import cannot silently re-subscribe them.

We monitor delivery signals such as bounce rates and spam complaints across the platform to protect the deliverability of every sender and to detect misuse, including spam and phishing. If we determine an account is being used to send unsolicited or abusive content, we may retain the account's content and subscriber data beyond our normal retention period as needed to investigate, respond to the abuse, or comply with legal requirements, and we may delete or disable an abusive account's subscriber lists as part of that response.

Student data and FERPA

Daystage is a tool for emailing adults. The contact lists schools build in Daystage are email addresses for parents, guardians, and staff.

Daystage has no field for a student ID, grade, transcript, attendance record, IEP, or disciplinary record, and no integration with a student information system.

Any student information a school chooses to include in a newsletter is handled on that school's behalf and under its direction. We do not use it for any purpose other than providing the service to the school, and we never use it for advertising or sell it.

We recommend treating newsletter content the same way you treat any other outbound family communication, and applying the same review your district already applies to it.

Children's privacy

Daystage accounts are created by school staff, and there is no student-facing sign-up. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, email team@daystage.com and we will delete it.

Schools and districts

On school and district plans, the school or district is the owner of the data created under its account, and Daystage processes that data on its behalf. A district administrator can see the schools within that district and nothing outside it. Contact lists and newsletters are scoped to the account that created them and to the organization above it, so one school cannot read another school's contacts.

If your district requires a data privacy agreement, send it to team@daystage.com and we will review and return it.

Security

All traffic to Daystage runs over HTTPS, and our database and storage providers encrypt data at rest on their infrastructure. Because there is no password to steal or reuse, the most common route into an account does not exist here. Card numbers are collected by Stripe directly and never reach Daystage servers.

A small number of Daystage staff hold an administrative role used for support and billing. That access exists to resolve a specific issue, such as a delivery failure or a billing question, and is not used to read newsletter content otherwise.

Where your data is processed

Our application and database run in the United States (US East). Outbound email delivery currently runs through Amazon SES in the EU North region, which means recipient email addresses and newsletter content are processed there. Daystage has no student information system integration and no field for student records, so what crosses regions is adult email addresses and newsletter content. We are moving email delivery to the United States and will update this policy and our security page when that is complete.

Reporting a security concern

If you believe you have found a vulnerability, or you are seeing something that looks wrong, email team@daystage.com with “security report” in the subject line. Include what you saw and how to reproduce it, and we will come back to you.

Cookies

We ask before we set anything that is not essential. The first time you visit, a banner lets you accept or decline. You can change your mind at any point using the Cookie settings link at the bottom of every page.

There are three categories:

  • Strictly necessary. Always on. A session cookie keeps you signed in, and a small cookie named ds_consent remembers the choice you made here. These cannot be switched off, because the site does not work without them.
  • Analytics. Google Analytics and PostHog, so we can see which pages people use and where they get stuck. Nothing is set until you accept.
  • Marketing. Google Ads and Meta, used to measure whether an ad led to a signup. This covers measurement we send from our own servers as well as from your browser. Nothing is set until you accept.

If your browser sends a Global Privacy Control signal, we treat that as declining marketing, and the option stays off.

If you are in the EU, UK, Switzerland, Norway, Iceland, or Liechtenstein, nothing beyond strictly necessary loads until you opt in. Everywhere else, analytics and marketing start on and stop as soon as you decline.

Cookies are set on daystage.com only. They never touch your subscriber lists, and the newsletters you send to families carry no advertising or third-party tracking.

Data retention and deletion

Your account data is retained as long as your account is active. We do not expire contact lists, newsletters, or delivery history on our own, because schools reference past newsletters years later. Newsletters you move to trash are permanently removed 30 days later.

You can request full account deletion at any time by emailing team@daystage.com from an address on the account. Deleting an account removes its contact lists, newsletters, uploaded images, and delivery records.

Sub-processors

These are the services that can process data on our behalf, and what each one is for. Each has its own privacy policy.

  • Vercel. Application and website hosting
  • Neon. Managed PostgreSQL database
  • Amazon Web Services (SES). Outbound email delivery
  • Cloudflare (R2). Image and file storage
  • Stripe. Payments and subscription billing
  • Google. Optional sign-in with a Google account
  • Anthropic. Optional AI drafting assistance inside the editor
  • PostHog. Product analytics, only after you accept analytics cookies

Subject to your cookie choice, we also use Google (Analytics, Ads, and Tag Manager) and Meta for measurement on our own marketing pages. Those never receive subscriber data.

Changes to this policy

We may update this policy from time to time. When we do, we change the date at the top of this page. Continued use of Daystage after an update means you accept the current version.

Contact

Questions about privacy? Email us at team@daystage.com.