Last updated: 2026-05-12
This Privacy Policy explains what Daiyo collects, why, and what we do with it. We try to keep this plain English. Where a section is legally required to use specific phrasing, we use it.
By using Daiyo you agree to this Policy. If you don't, don't use Daiyo.
| You give us | We use it for | Who else sees it |
|---|---|---|
| Email, password | Logging you in | No one |
| Name, age, pronouns | Showing your profile to potential matches | Other users in your match flow |
| Photos | Profile + match-card display | Other users in your match flow |
| ID document + selfie | Verification only | Our moderation team and, if used, our verification vendor. Deleted after approval. |
| Approximate location | Showing nearby matches, deals, events | Not shared with other users — only used in our matching server |
| Messages with matches | Operating the chat product, moderation when reported or auto-flagged | The user you're chatting with. Moderators, in those review cases only. |
| Push tokens | Sending you push notifications | Apple / Google push services |
| Activity (slots, RSVPs, reviews) | Operating the product, ranking matches, safety analytics | Some derived data appears to other users (e.g., a verified badge, a trust score band) |
| Reports you file | Safety moderation | Daiyo moderators only |
We do not sell your personal information. We do not show third-party ads inside Daiyo.
You can withdraw consent at any time by toggling the relevant setting or deleting your account.
We do not sell, rent, or share your data with advertisers or data brokers.
Your ID and selfie are used only to verify your identity. We encrypt them at rest. We delete them after your account is approved, unless we are legally required to retain them or unless they are evidence in an open safety case.
If you are rejected, we retain the submission for up to 90 days so we have context if you re-submit.
If you delete your account before verification completes, we delete the pending submission.
You can revoke location permission anytime in your phone's settings. Features that need location stop working.
Messages inside a matched conversation are end-to-server encrypted in transit (HTTPS) and stored encrypted at rest. They are visible to:
We do not read message contents for marketing or analytics. We do not train ML models on the contents of private messages.
Conversations expire automatically an hour after the matched activity ends, unless both parties extend. After expiration, message contents are deleted on a rolling 30-day schedule.
Daiyo's mobile app uses minimal tracking:
We do not use third-party advertising SDKs.
Depending on where you live, you have the right to:
Email daiyosupport@gmail.com with the subject "Data Request" + your account email. We typically respond within 30 days.
California residents: you have the rights described in the CCPA / CPRA, including the rights to know, delete, correct, and opt out of "sale" (we do not sell). EU/UK residents: you have GDPR rights including data portability and the right to lodge complaints with your local DPA.
| Data | Retention |
|---|---|
| Account profile | Until you delete your account |
| Messages | Up to ~30 days after the conversation expires |
| Reports + moderation records | Up to 24 months after the related account is closed (longer if part of an open case or required by law) |
| Verification documents | Deleted after approval; up to 90 days if rejected |
| Crash logs | 30 days, anonymized |
| Backups | Up to 60 days |
If you delete your account, we initiate deletion within 30 days. Backups age out within 60 days.
We follow industry-standard practices: TLS in transit, encryption at rest, hashed passwords (bcrypt), restricted access to production data, audit logging on moderation actions. No system is perfectly secure. If we have a breach affecting your data, we notify you and any required regulators within the legally required window.
Daiyo is 18+ only. We don't knowingly collect data from anyone under 18. If we learn we have, we delete it.
Daiyo is operated from the United States. If you use the Service from outside the US, your data will be transferred to the US. Where required, we use appropriate transfer mechanisms (e.g., Standard Contractual Clauses).
We update this Policy as the product changes. The current version is always in the app under You → Legal. Material changes are announced via push or email at least 7 days before they take effect.