Security

Know exactly what we touch,
and how to switch it off.

This page lists everything Dayposter reads, holds, and is able to do with your accounts, and every way you can shut it off without asking us. Nothing here is a badge. It is a list, and it is short.

Exactly what we read,
and nothing more.

1. Your public schedule. We read the public schedule page of your booking platform (Momence, Mindbody, or Mariana Tek): class names, start times, instructor names, substitutes, cancellations, spots left where the page shows them, and the instructor photos your booking profiles already display. It is the same information anyone sees when they open your booking page. We never log in to your booking platform, and we never ask for credentials to it.

2. Your brand. Your accent color (proposed from your website, confirmed by you), your logo, your typeface choice, the design you picked, up to twenty brand photos if you send them, the short class names you set, your booking line, and the other settings shown on the Home page.

3. Your Instagram connection. When you connect Instagram, you approve the connection on Instagram's own screens through the official API, and Meta issues an account id and an access token that authorize publishing stories to your account. At launch those two items are held by our posting rail, upload-post, on our behalf. We hold your Instagram handle, the connection status, and the reference that ties your studio to its profile at the rail. The token is never in our website code, never in your browser, and never in an email.

4. Your account, each night's story, and billing. Your studio name, your time zone, your contact email, and, if you add one, a second address that receives previews (the front desk). For each night: the schedule as it stood at preview time, the two rendered images (today, then tomorrow), what happened (previewed, approved, held, posted, skipped, or failed), and the rail's reference for each published frame. For billing: your Stripe customer id, subscription id, plan, and billing status. Card numbers go to Stripe and never touch our systems.

5. Email between us. The emails we send you, including the preview images inside them, and what you send us. Every email we send replies to stop@dayposter.com. Our software reads the sender, subject, and body of each message to that address to find a STOP, START, or PAUSE, and records who sent it and when. Everything else you write to us lands in our support inbox, where a person reads it.

That is the whole list. We hold no client lists, no member records, no bookings, and none of your clients' payment details.

What we can never do.

How every night runs,
step by step.

  1. 8:00 pm, your time. We read your public schedule page, build today's story with tomorrow's as a second frame, in your brand, and send the preview by email with four links: Looks good, Skip, Pause, Stop. Do nothing and it posts on time. Reply in plain English to change something.
  2. 12:00 am, your time, or the time you set. We read your schedule page again. If nothing changed, the story posts. If a class was cancelled, it is removed and the story posts. If anything else changed, your setting decides. Hold for me: we send the updated story and wait for your tap; no answer by the cut-off (six hours after your post time unless you set otherwise) and the day skips. Auto: the updated story posts on time. You choose between the two during setup; neither is chosen for you.
  3. Every night, without exception. The second read always runs; it is not a switch you can leave off. Days off never post. Empty days never post. A broken feed never posts.

Stop means stop. Instantly.

The stop link is in every email we send, and every email we send replies to stop@dayposter.com. Either one sets the stop flag on your account before anything else happens, and you get a confirmation email every time. Our software reads that flag again in the moment before each publish, and if it cannot read the flag, that counts as stopped. If a stop arrives from an address that looks like yours but is not the one on file, we stop first and check with you afterwards. Wrongly paused beats wrongly posted. Resume with the link in the confirmation email, or reply START from your account address.

Switch it off yourself,
without asking us.

Stop posting. Tap the stop link in any email, reply STOP to any email, or write to stop@dayposter.com. Posting halts at once. Your designs, settings, and history stay exactly where they are, and you can resume whenever you like.

Pause. Tap Pause in the preview. No previews and no posts until you resume. Everything stays where it is.

Revoke the Instagram connection. In the Instagram app, open Settings, then Website permissions, then Apps and websites, and remove the Dayposter connection. The access token dies immediately and we can no longer post.

Close the account. One email closes your account and deletes everything. The steps are on the data deletion page; it is done within 7 days, and we confirm by email when it is.

Where your data lives,
and who can reach it.

Who else touches
your data.

WhoWhat they do for youWhat they hold
CloudflareRuns the software (Workers), the database (D1), image storage (R2), rendering (Browser Rendering), and inbound email (Email Routing)Everything listed above, plus standard request logs (IP address, browser, pages requested) for a limited period
ResendSends every email we send, previews insideYour email address, each email we send, and delivery records
StripeBillingYour card, your invoices, your Stripe customer record
upload-post (TONVI TECH SL, Spain)The posting rail that carries each story to Instagram through the official API at launchYour Instagram account id and access token, each story image as it is published, delivery records
MetaInstagram itselfYour Instagram account; receives each published story

We update this table before adding anyone to it. No one on it may use your data for anything except the service named.

Found something?
Tell a person.

Write to hello@dayposter.com with the subject "Security". A person reads it and replies within two business days. If you report a real vulnerability, we will credit you here if you'd like.

See your story, free