Privacy Policy
Privacy Policy
Effective September 3, 2026 · Applies to everyone, everywhere.This policy covers Dayposter: the website at dayposter.com, the service behind it, the emails it sends, and the Dayposter connection to Instagram. Dayposter is operated by Sleeping Bear Studio LLC, doing business as Dayposter ("we"). This policy covers only Dayposter; it is not shared with any other app or product.
The short version.
We collect the minimum needed to post your schedule story each night, we share it only with the companies that make the service run, we never sell it, and one email closes your account and deletes everything.
Everything we collect,
item by item.
When you use the free demo, with no account:
- The website or booking-page link you type, and the email address you enter to get your setup link
- The public schedule at that link: class names, start times, instructor names, substitutes, cancellations, and instructor photos where your booking profiles show them
- Colors read from your public website, used to propose the design
- Standard web logs: IP address, browser type, pages requested
When we set up your account:
- Your name and email address, and, if you add one, a second address that receives previews (the front desk)
- Studio name and time zone
- Booking platform and booking-page link, and the booking line shown on the story
- Brand: your accent color, logo file, typeface choice, design choice, and up to twenty brand photos if you send them
- Settings: short class names, how substitutes are shown, the "spots left" tag, what is not shown, post time, frames, days off, preview time, and your choice of Hold for me or Auto for overnight changes
When you connect Instagram:
- Your Instagram handle and the status of the connection
- The Instagram account id and the access token that authorize publishing to your account. Meta issues both when you approve the connection on Instagram's own screens. At launch they are held by our posting rail, upload-post, on our behalf; we hold the reference that ties your studio to its profile there.
- For each published frame, the rail's delivery reference
Every night:
- The schedule as it stood at preview time, and the two rendered story images (today, then tomorrow)
- What happened: previewed, approved, held, posted, skipped, or failed, and when
When you subscribe:
- Payment is handled by Stripe through a Stripe checkout page in the last step of setup. Your card number goes to Stripe and never touches our systems. We store your Stripe customer id, subscription id, plan, and billing status. Cards and cancellations are managed in Stripe's customer portal.
When you email us or we email you:
- The emails we send, including the preview images inside them
- Messages to stop@dayposter.com: our software reads the sender, subject, and body to find a STOP, START, or PAUSE, and records who sent it and when
- Everything else you write to us, in our support inbox
We do not collect your booking-platform login, your Instagram password, your clients' or members' personal data, or your clients' payment details.
How we use each item.
- Schedule data: to build your daily schedule story, and for nothing else.
- Brand and settings: to make the story look like your studio and post it the way you asked.
- Instagram handle and account id: to show you which account is connected and to make sure each story publishes to the right account. This is the only use of the basic-identity permission.
- Instagram access token: to publish your schedule story to your account. This is the only use of the content-publishing permission. We request no other Instagram permissions: no messages, no comments, no followers, no insights.
- Name, email, time zone: to run your account, send the evening preview and the confirmations, and answer you when you write. Every email we send carries a stop link.
- Each night's record: to send the preview, to run the second check before posting, to hold or post an overnight change the way you chose, and to tell you what happened.
- Billing data: to charge the subscription you chose, and nothing more.
- Web logs: to keep the service up and to investigate abuse.
We do not sell personal data. We do not use your data for advertising. We do not train anything on your data. Nothing in your story is generated: it is built from your schedule, checked again before it posts, and shown to you first.
Who we share it with.
Only the companies that make the service run, and only what each one needs:
- Cloudflare: runs the software (Workers), the database (D1), image storage (R2, a private bucket with no public address), rendering (Browser Rendering), and inbound email (Email Routing), and hosts dayposter.com. Holds everything listed above, plus request logs for a limited period.
- Resend: sends every email we send, previews inside. Holds your email address, each email, and delivery records.
- Stripe: billing. Holds your card, your invoices, and your Stripe customer record.
- upload-post (TONVI TECH SL, Spain): the posting rail that carries each story to Instagram through the official API at launch. Holds your Instagram account id and access token, each story image as it is published, and delivery records.
- Meta: Instagram itself. Holds your Instagram account and receives each published story.
We update this list before adding anyone to it. A person reads your replies; if we ever bring in a company to help answer them, it goes on this list first.
Beyond that, we disclose data only if the law requires it, or, with notice to you, as part of a sale of the business, in which case this policy's promises travel with the data.
How long we keep it.
- Demo form entries and demo renders: deleted within 30 days
- Rendered stories, previews, and the schedule as it stood each night: 30 days, then deleted
- Instructor photos fetched from your booking page: cached for 7 days, then fetched again
- Account, brand, settings, and each night's outcome (dates and what happened): while your account is open. After you cancel, we keep them for 90 days so a returning studio can pick up where it left off, then delete them. Ask sooner and they go within 7 days.
- Instagram connection: until you revoke it on Instagram, or until your account closes, when we delete the profile at the posting rail and the token with it, within 7 days
- Email in our support inbox: while your account is open, then deleted with it. Resend keeps its own delivery records under Resend's privacy policy.
- Invoices and tax records: 7 years, as tax law requires, held by Stripe
Deletion is unconditional,
for everyone.
Anyone can have their data deleted: subscribers, former subscribers, demo visitors, anyone whose data we hold. Wherever you live. No fee, no conditions, no questions, no account required.
One email closes your account and deletes everything. Email hello@dayposter.com with the subject "Delete my account" and we delete your data, including your Instagram connection and its access token at the posting rail, your account details, brand, settings, each night's record, and every rendered story, within 7 days, and send you a confirmation when it is done. The stop flag is set the moment we read your request, so nothing further posts while the deletion runs.
The only records that survive are invoices and tax records we are legally required to keep, held by Stripe and used for nothing else.
Step-by-step instructions are at dayposter.com/data-deletion.
Your choices.
- Revoke Instagram access any time on Instagram's own screens; the token dies immediately.
- Stop posting any time: the stop link in every email, a STOP reply, or stop@dayposter.com. Stopping posting and unsubscribing from marketing email are separate controls; using one never silently changes the other.
- Pause, skip a day, or change any setting by replying to any Dayposter email in plain English.
- Unsubscribe from marketing email with the link in any marketing message. Service emails (the evening preview, confirmations) stop when posting stops or your account closes.
- See or correct your data: email hello@dayposter.com and we send you what we hold or fix what is wrong.
Security and storage.
Data moves over HTTPS and is encrypted at rest by Cloudflare. There is no dashboard and no password: every link in our emails is signed and acts only for your account, only for the action it names, and only until it expires. The plain-language version of our security posture, what we touch, what we can never do, and who else touches your data, is at dayposter.com/security.
Not for children.
Dayposter is a business tool and is not directed at children under 16. We do not knowingly collect data from children.
Changes to this policy
If this policy changes in a way that matters, we email account holders before the change takes effect and update the date at the top. We will not weaken the deletion promise.