Our reader

Dayposter: what it is,
and how to keep it out.

Dayposter draws a studio's daily Instagram story from its real class schedule. To do that it reads the studio's public website and public booking page once, when the studio owner asks. This page describes that reader for site owners, hosting providers, and anyone who sees it in a log.

When it visits,
and what it reads.

Only when asked. The reader visits a website when someone pastes that website into the form at dayposter.com, and again when that studio's schedule is drawn for the studio's own story. It never crawls the web on its own, follows no links off the site it was given, and keeps no index.

A few pages, once. On a visit it opens the homepage and at most three pages that look like a schedule or booking page, the site's robots.txt, and, if the site publishes one, its logo. It reads the public booking page that the site points to (Momence, Mindbody, Mariana Tek, or a public calendar feed). It reads nothing behind a login and submits no forms.

A light touch. A handful of requests, seconds apart, with a one-megabyte cap per page and a time limit of a few seconds. A busy site never sees more than that from us in a visit.

How it identifies itself.

By name. Every request carries the user-agent Mozilla/5.0 (compatible; Dayposter/1.0; +https://dayposter.com/reader).

By signature. Every request is signed with Web Bot Auth (an HTTP message signature, RFC 9421, Ed25519). The public key is published, signed, at https://dayposter.com/.well-known/http-message-signatures-directory. A request that carries our name without our signature is not from us. Dayposter's registration as a Cloudflare verified bot is filed on that basis.

By address. The reader runs on Cloudflare Workers, so its addresses are Cloudflare's. Verify a visit by its signature, not its address.

How to block it.

Add this to your robots.txt and the reader opens nothing beyond your homepage:

User-agent: Dayposter
Disallow: /

The reader honors robots.txt, including Crawl-delay, and a block takes effect on the next visit. If you would rather we never open the site at all, write to hello@dayposter.com with the domain and we add it to the reader's own block list.

What it keeps.

From a website: the studio's name, colors, typeface and logo as read from the public pages, kept with the preview for seven days and then deleted, or kept with the studio's account when the studio signs up. No copy of any page is stored. From a booking page: the day's class names, times, and instructors, drawn into a story image and kept as described on the Security and Privacy pages.

Questions.

Write to hello@dayposter.com. A person reads it.

Preview my schedule