privacy policy

effective august 8, 2026

DayOne ("DayOne," "we," "us") operates the dayone.fans website and the DayOne / Day 1's mobile application (together, the "Service"), which connects fans with the creators, artists, and performers they show up for. This Privacy Policy explains what we collect, how we use and share it, and the choices you have. By using the Service, you agree to this Policy.

what we collect connected accounts how we use it platform data how we share your rights deletion contact

1. Information we collect

Information you provide

Connected social accounts (creators)

When a creator connects an Instagram account (via Instagram Business Login) or a TikTok account, we access, with your authorization: (a) basic profile information such as account ID and username, and (b) permission to publish or repost content to that account on your behalf. We store the associated access and refresh tokens encrypted and use them only to provide the features you enable — for example, posting or reposting fan‑submitted content that you or your settings approve. We do not use these permissions to like, follow, or comment on other people's posts on your behalf, and we do not post to your account except as you configure or approve. You can disconnect a connected account at any time (see Data Deletion).

Information collected automatically

Information from third parties

We may receive information from sign‑in providers (e.g., Apple, Neon Auth), payment providers, and the social platforms you connect.

2. How we use information

3. Platform data (Instagram/Meta & TikTok)

Our access to and use of information received from the Meta/Instagram APIs and the TikTok APIs adhere to the Meta Platform Terms and Developer Policies and the TikTok Developer Terms and Content Sharing Guidelines, respectively. We use connected‑platform data only to provide the features you enable, we do not sell it, and we do not use it for advertising profiling. If your connection is revoked or expires, we stop using it and delete the stored tokens.

4. How we share information

We do not sell your personal information. We share it:

5. Data retention

We keep information for as long as needed to provide the Service and for legitimate business or legal purposes. Encrypted social tokens are retained until you disconnect the account or they expire/are revoked. You can request deletion as described below.

6. Security

We use technical and organizational safeguards, including encryption of connected‑account tokens at rest and access controls that keep those tokens out of client applications. No system is perfectly secure, but we work to protect your information.

7. Your rights & choices

Depending on where you live (e.g., the EEA/UK or California), you may have additional rights such as access, portability, correction, deletion, and objection. Contact us to exercise them.

8. Deleting your data

You can delete your account and associated data at any time. See dayone.fans/data for step‑by‑step instructions (in‑app and by email), what we delete, and our timeline.

9. Children

The Service is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child provided us information, contact us and we will delete it.

10. International users

We operate the Service from the United States and may process data in the U.S. and other countries. Where required, we use appropriate safeguards for cross‑border transfers.

11. Changes

We may update this Policy. We will post the updated version here and revise the "effective" date; material changes may be notified in‑app or by email.

12. Contact

Questions or requests: [email protected].