Me by Day

Privacy, in plain sight.

Analysis on your device. A clear explanation of how your data gets there.

What happens when you connect

Oura authenticates you on its own website. This installation’s server exchanges the authorization code for tokens, and relays your data requests to the Oura API. Tokens and health data pass through the server in transit; the application does not persist them in a server database or intentionally log their contents.

The hosting provider still processes network traffic and may keep infrastructure or request logs. A public installation’s operator must configure hosting and logging appropriately. Self-hosting lets you choose that operator.

What stays in this browser

The app stores access and refresh tokens, connection settings and preferences in browser local storage. Retrieved health data is cached in IndexedDB for quicker repeat visits. This storage is not encrypted by Me by Day. Other people with access to this browser profile, browser extensions or compromised scripts may be able to access it.

Cache freshness checks are not automatic deletion. Data may remain until you clear it, disconnect or your browser removes site storage. Different devices and browser profiles have separate copies.

How insights are calculated

Trends, comparisons and correlations are computed locally using inspectable statistics. The application includes no advertising pixels or AI processing of your health data. Fonts are served with the app. The demo uses fictional data and makes no requests to Oura.

Optional website and demo analytics

When enabled by the operator and allowed by you, selected interface actions on the public website and sample-data demo are sent to PostHog’s EU service. They include an action category, timestamp, and a random identifier held only in this page’s memory. This is pseudonymous telemetry, not a promise of anonymity.

We do not send health values, selected goals, account details, page URLs or referrers. Oura-connected sessions are excluded, including visits to the homepage while connected. There is no automatic click capture, session recording, advertising, or active onboarding experiment.

Consent is saved locally for up to 180 days. No analytics request is made before permission, after decline, or when analytics is not configured. Requests expose your network address to the receiving service. The operator must enable PostHog’s discard-IP setting and review its processing terms and retention before activation. Withdrawing stops future capture but cannot recall events already delivered.

Analytics is not enabled on this installation.

You can change your choice at any time. Withdrawal stops future capture and clears this tab’s analytics identifier. It cannot recall requests already delivered.

Delete or revoke access

Use “Disconnect & clear local data” in the footer of a connected session to remove Me by Day’s local cache, credentials and preferences. Close other tabs if the browser reports a storage error. You can also clear this site’s data in your browser settings.

Disconnecting locally does not delete your Oura records or revoke the grant at Oura. To revoke access, visit your Oura account. Files you exported stay wherever you saved them.

External links and technical cookies

Signing in uses short-lived cookies to validate the authorization flow. External sites linked from Me by Day, including Oura, GitHub, LinkedIn and Buy Me a Coffee, have their own privacy practices. They receive a request when you open their links.

Questions or security concerns

Review the source code and security documentation, or contact the operator of your installation. See the project story for the maintainer. Do not include health data, tokens or secrets in public issue reports.

Application notice updated 27 September 2026. Public operators must provide their own applicable identity, contact and hosting details before accepting users.