Dayleeds

Security

Last updated: August 22, 2026

Overview

Dayleeds reads, organizes, and clarifies your synced HubSpot sales activity. It does not change your CRM. This page describes the controls that are in place today. It does not claim any certification or audit, and it separates current controls from planned work.

Customer-authorized access

  • You authorize the HubSpot connection through OAuth, and access is read-only.
  • Dayleeds requests least-privilege read scopes where HubSpot supports them, and has no permission to send, edit, or delete anything in HubSpot.
  • You can revoke access at any time in HubSpot under Settings, Connected Apps, which stops future syncing. In Dayleeds, Disconnect and delete HubSpot data revokes access and also deletes the data already synced.

Data minimization

The narrowest control is the one that matters most: data that is never collected cannot be exposed.

  • Dayleeds does not intentionally ingest or store email bodies. It processes sender and recipient identifiers, subject lines, timestamps, direction, send status, and engagement metadata.
  • Dayleeds does not intentionally ingest or store call audio, recordings, or transcripts. The call integration requests an allowlist of analytics fields, and call titles, notes, and participant phone numbers are not among them. There is no database column for any of them.
  • Reply threads and internal teammate email can be excluded from reporting.

Separation between workspaces

  • Every synced record is stored against a workspace identifier, and the backend derives that identifier from the verified authenticated session rather than from anything the browser supplies.
  • Logical access controls are designed to prevent one workspace from reading or deleting another workspace's data, and automated tests exercise that boundary, including rejecting forged workspace claims.
  • CSV exports are scoped to the requesting workspace.

Authentication and access

  • Sign-in, sessions, and account identity are handled by our managed authentication provider, listed on the Subprocessors page.
  • Administrative access to production is restricted to the small number of people who need it to operate the service.
  • Credentials and provider secrets are held in backend environment configuration, never in frontend code, and an automated secret scan runs as part of validation.

Encryption

  • Web and API traffic is served over HTTPS/TLS, and the database connection uses the transport encryption the provider supports.
  • HubSpot authorization tokens are stored as ciphertext rather than plain text, and are not shown in the product interface or returned by the API.
  • Storage-level encryption for the database and its backups is provided by our managed database platform under its own configuration. Dayleeds does not encrypt each analytics field separately at the application layer, and does not claim to.

Operations

  • The database is operated by a managed provider that performs automated backups. Restores rely on that provider's tooling.
  • Application and error logging is used to operate and troubleshoot the service.
  • Development-only tools and demo data are gated so they do not run in production. Demo data is fabricated sample data, never real customer data.
  • Subprocessors are reviewed before use and listed publicly on the Subprocessors page.

Your controls

A workspace admin or owner can disconnect HubSpot and permanently delete the workspace's synced data from Settings, under Data and privacy. Deleting removes the synced activity, contacts, companies, and owners and the analytics derived from them, deletes stored HubSpot tokens, and revokes the app with HubSpot. A workspace owner can instead delete the whole Dayleeds workspace, which also cancels billing. Every analytics view offers a CSV export of the data behind it. Retention after deletion or termination, including the 30-day post-termination window and the 90-day backup window, is described in the Privacy Policy and the Data Processing summary.

Incidents

If we confirm a security incident affecting customer data, we will notify affected customers without undue delay and share the information reasonably available to us.

What we do not claim

Dayleeds does not hold SOC 2, ISO, PCI, HIPAA, or FERPA certification or attestation, and does not claim compliance with any of them. We have not commissioned an external security assessment. No service can be completely secure, and nothing on this page should be read as a guarantee.

Planned work

The following are planned and not yet in place. They are listed so the boundary between current and future is explicit:

  • audit logs for account, connection, and deletion activity;
  • rate limiting on sensitive endpoints;
  • expanded production monitoring and alerting;
  • a formal written incident-response runbook;
  • an independent security assessment.

Reporting a vulnerability

Please report suspected vulnerabilities to support@dayleeds.com. We aim to acknowledge reports promptly and investigate them. Please give us a reasonable opportunity to respond before public disclosure.

Dayleeds is an independent product and is not affiliated with, endorsed by, or sponsored by HubSpot, Inc.

Privacy · Terms · Security · Data processing · Subprocessors · Pricing

Back to Dayleeds · Contact support

PrivacyTermsSecuritySupportContact
Dayleeds is an independent product and is not affiliated with, endorsed by, or sponsored by HubSpot.