privacy policy
effective august 8, 2026DayOne ("DayOne," "we," "us") operates the dayone.fans website and the DayOne / Day 1's mobile application (together, the "Service"), which connects fans with the creators, artists, and performers they show up for. This Privacy Policy explains what we collect, how we use and share it, and the choices you have. By using the Service, you agree to this Policy.
1. Information we collect
Information you provide
- Account & contact: name, email, username/handle, password or third‑party sign‑in (e.g., Apple), and, for creators, business/profile details.
- Waitlist: the email (and optional social handle and role) you submit on dayone.fans.
- Content: photos, videos, clips, captions, comments, and other content you submit or post.
- Messages: communications you send to creators, other users, or our support.
- Payments: purchases are processed by Apple, Google, and/or Stripe. We receive confirmation and limited transaction details but do not collect or store full payment‑card numbers.
Connected social accounts (creators)
When a creator connects an Instagram account (via Instagram Business Login) or a TikTok account, we access, with your authorization: (a) basic profile information such as account ID and username, and (b) permission to publish or repost content to that account on your behalf. We store the associated access and refresh tokens encrypted and use them only to provide the features you enable — for example, posting or reposting fan‑submitted content that you or your settings approve. We do not use these permissions to like, follow, or comment on other people's posts on your behalf, and we do not post to your account except as you configure or approve. You can disconnect a connected account at any time (see Data Deletion).
Information collected automatically
- Device & usage: device type, OS, app version, identifiers, and how you interact with the Service.
- Approximate location: with your permission, we use approximate location to power event/venue features such as proximity in "The Line." You can turn this off in your device settings.
- Log data: IP address, timestamps, and diagnostic data.
Information from third parties
We may receive information from sign‑in providers (e.g., Apple, Neon Auth), payment providers, and the social platforms you connect.
2. How we use information
- Provide, operate, and secure the Service, including the queue / "Day 1" features and creator communities.
- Publish or repost content to a creator's connected account as authorized by that creator.
- Process purchases and deliver what you buy (e.g., cosigns/shoutouts, line cuts).
- Communicate with you (service messages, and marketing where permitted — you can opt out).
- Personalize, analyze, and improve the Service.
- Detect, prevent, and address fraud, abuse, and safety issues, and comply with law.
3. Platform data (Instagram/Meta & TikTok)
Our access to and use of information received from the Meta/Instagram APIs and the TikTok APIs adhere to the Meta Platform Terms and Developer Policies and the TikTok Developer Terms and Content Sharing Guidelines, respectively. We use connected‑platform data only to provide the features you enable, we do not sell it, and we do not use it for advertising profiling. If your connection is revoked or expires, we stop using it and delete the stored tokens.
4. How we share information
We do not sell your personal information. We share it:
- With other users, as intended: content you post and profile details you choose to make visible are shown to creators and/or fans; content a creator's agent reposts appears publicly on that creator's connected account.
- With service providers who process data on our behalf, including Cloudflare (hosting/storage), Neon (database), Stripe and the app stores (payments), and Mapbox (maps).
- With the social platforms you connect, to publish content you authorize.
- For legal reasons — to comply with law, respond to lawful requests, or protect rights, safety, and property.
- In a business transfer (merger, acquisition, financing, or sale of assets).
5. Data retention
We keep information for as long as needed to provide the Service and for legitimate business or legal purposes. Encrypted social tokens are retained until you disconnect the account or they expire/are revoked. You can request deletion as described below.
6. Security
We use technical and organizational safeguards, including encryption of connected‑account tokens at rest and access controls that keep those tokens out of client applications. No system is perfectly secure, but we work to protect your information.
7. Your rights & choices
- Access, correct, or delete your data — see our Data Deletion page.
- Disconnect social accounts in the app; you can also revoke access in the platform's own settings.
- Marketing: opt out via the unsubscribe link or by contacting us.
- Location: control location permission in your device settings.
Depending on where you live (e.g., the EEA/UK or California), you may have additional rights such as access, portability, correction, deletion, and objection. Contact us to exercise them.
8. Deleting your data
You can delete your account and associated data at any time. See dayone.fans/data for step‑by‑step instructions (in‑app and by email), what we delete, and our timeline.
9. Children
The Service is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child provided us information, contact us and we will delete it.
10. International users
We operate the Service from the United States and may process data in the U.S. and other countries. Where required, we use appropriate safeguards for cross‑border transfers.
11. Changes
We may update this Policy. We will post the updated version here and revise the "effective" date; material changes may be notified in‑app or by email.
12. Contact
Questions or requests: [email protected].