Privacy Policy

Last updated: 24 August 2026

This policy explains what Daytify does with your personal data: what we collect, why, who else sees it, how long we keep it, and what you can tell us to do about it. It is written in plain English on purpose. If anything here is unclear, email support@daytify.com and we will explain it.

It should be read together with our Terms of Service, Cookies Policy, Content Moderation Policy and Refund Policy.

Quick answers

  • What happens to my photos, audio and video? They are published immediately with no moderation queue, and only logged-in members can see them. Full detail in Your photos, audio and video.
  • Who can see my profile? Only people who have registered and logged in. Daytify is not open to the public — a visitor who is not logged in sees “Members only” instead of profiles.
  • Is my sexual orientation involved? Yes. Your gender plus the gender you are seeking reveals it, which makes it special category data. See Your profile is special category data.
  • Do you track me with analytics? No. There is no analytics, measurement or advertising tracking on this site at all.
  • Do you sell my data? No. We do not sell, rent or trade personal data, and we do not use your profile data to target advertising.
  • How do I delete everything? Delete your account in your account settings, or email us. See Your rights.

1. Who we are

Daytify is operated by:

Daytify OÜ is the controller of the personal data described in this policy. That means we decide why and how it is processed, and we are the ones answerable for it. Saying that members are responsible for what they post does not transfer that responsibility away from us.

2. Your profile is special category data

This is the most important section in this policy, so it comes early.

A Daytify profile states your own gender and the gender you are seeking. Put those two facts side by side and they reveal your sexual orientation. Under Article 9(1) of the GDPR that is special category data — the most strongly protected class of personal data there is.

Two more of the profile questions fall into the same class: Religion (religious beliefs) and Ethnicity (racial or ethnic origin). And the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), when it monitored 21 Estonian dating portals between 2023 and 2024, treated profile photographs and information about sexual life and orientation on dating sites as special category data. We take the same view and handle your photos on that basis.

The legal basis is your explicit consent, and nothing else

We process this data on one basis only: your explicit consent under Article 9(2)(a) GDPR, together with Article 6(1)(a). There is no other realistic basis available to a commercial dating service.

To make that consent real rather than decorative:

  • It is asked for separately from your acceptance of the Terms of Service. Ticking one does not tick the other. They are distinct choices with distinct tick boxes.
  • It is separately withdrawable. You can withdraw the Article 9 consent without cancelling your account or accepting anything else, at any time, in your privacy settings or by emailing support@daytify.com.
  • Withdrawing is as easy as giving it, and takes effect from the moment you withdraw. It does not undo processing that already lawfully happened before then.

We do not rely on Article 9(2)(e) — the “manifestly made public by the data subject” exception. Daytify is behind a registration wall: nobody who is not logged in can see your profile. Publishing information to other members of a closed platform is not making it manifestly public, and we will not pretend otherwise.

What happens if you withdraw this consent

We will be straight with you about the consequence. A dating profile is made of exactly this data. If you withdraw your Article 9 consent, your profile can no longer be shown to other members — it is removed from search, matches, the member list and other members’ views. You can keep your account and log in, but it will not function as a dating profile until you give consent again.

Equally importantly:

  • Withdrawing consent is not a breach of contract. Estonian law says so directly — Law of Obligations Act (võlaõigusseadus) § 6218: exercising a GDPR right to withdraw consent cannot be treated as a breach of a digital content or digital service contract.
  • There is no penalty, fee or charge of any kind for withdrawing.
  • Your unused dayts are not forfeited. Dayts do not expire and are not lost if you withdraw consent or close your account.

3. What we collect

When you register

Registration is free and the form asks for: username, gender, first name, last name, password (with confirmation), email address (with confirmation) and your date of birth. Your password is stored only as a cryptographic hash — we never see or hold the password itself.

Your profile

Basic profile data: country, region, city, postcode, gender, who you are seeking, age, an “about me” description, interests, approximate coordinates (latitude and longitude), and your hidden-mode and profile-privacy settings.

Fourteen further profile questions, all of which are currently mandatory in the form: Seeking, Eye Colour, Religion, Ethnicity, Marital Status, Children, Income, Body Type, Smoker, Drink, Hair Colour, Employment, Education, and a free-text “My Match” field of up to 2,000 characters.

Anything you type into a free-text field is up to you. Please do not put health details, political opinions, identity document numbers or other people’s personal data in there.

Media you upload

Up to 10 photos, up to 8 audio files, up to 6 videos, photo albums and galleries, private photos and a profile cover image.

What you do on the site

Internal mail and one-to-one and group chat messages, flirts and winks, profile comments, virtual gifts, friend requests and friendships, favourites, “Meet Me” responses, profile ratings, saved searches, who viewed your profile and whose profiles you viewed, and your activity feed and notification settings.

Payments

If you buy dayts: your name, email, the amount in euro, which package, how many dayts, the transaction reference, the invoice we generate, and a record of the confirmations you gave before paying (the time in UTC, your IP address, your browser user agent and the version of the text you agreed to).

We never receive or store your payment card details. Card data is handled entirely by the third-party payment gateway you choose. At the time of writing, no payment gateway is enabled on the site, so purchases cannot currently be made at all.

Consent records

When you register we record proof of the consents you gave: which documents you accepted, the version of the text shown to you, the time in UTC, your IP address and your browser user agent. We are required to be able to demonstrate consent (GDPR Articles 5(2) and 7(1)), and for marketing consent Estonian law places the burden of proof on us, not on you (Electronic Communications Act § 1031(5)).

Technical data

Our web server records your IP address, the time, the page requested, the response and your browser user agent. Our Wordfence firewall and malware scanner processes the same kind of data to detect attacks.

4. What we do with it

Every purpose, its legal basis and its retention period, in one table.

Purpose Data used Legal basis How long we keep it
Creating and running your account Username, name, email, hashed password, gender, date of birth Art. 6(1)(b) — performance of our contract with you While the account exists. Deleted when you delete the account
Showing your dating profile to other members Gender and who you are seeking, Religion, Ethnicity, the other profile answers, free text, photos, audio and video Art. 9(2)(a) — your explicit consent, with Art. 6(1)(a) Until you withdraw consent or delete the account, whichever is first
Checking that you are 18 or over Date of birth Art. 6(1)(b), and Art. 6(1)(f) — our legitimate interest in keeping minors off an adult service While the account exists
Being able to prove you consented Documents accepted, text version, UTC timestamp, IP address, user agent Art. 6(1)(c) — legal obligation under Art. 5(2) and 7(1); ESS § 1031(5) for marketing consent 3 years after the account closes (the general limitation period for contractual claims in Estonia)
Messaging, chat, winks, gifts, comments, friends, favourites, Meet Me, profile views Message and comment content, sender and recipient, timestamps Art. 6(1)(b) — performance of our contract with you While the account exists. Copies already delivered to another member may remain in that member’s mailbox
Search, advanced search, saved searches, My Matches, Trending Users Your profile answers, including the special category ones, and your saved search criteria Art. 6(1)(b), and Art. 9(2)(a) for the special category fields Saved searches until you delete them or the account
Service emails and notifications (new message, wink, friend request, match digest, password reset, payment result, low balance) Email address, name, the event being notified Art. 6(1)(b) — these are part of the service, not marketing Not retained after sending, apart from mail server logs (10 days)
Marketing emails Email address, name, your consent record Art. 6(1)(a) — your prior consent, as required by ESS § 1031(1) Until you withdraw or object. The consent record is kept for 3 years afterwards
Selling dayts and issuing invoices Name, email, amount, package, transaction reference, invoice, pre-purchase confirmation record Art. 6(1)(b), and Art. 6(1)(c) for accounting records Invoices and accounting records: 7 years from the end of the financial year, as Estonian accounting law requires
Running your dayts balance and Profile Boost Balance, spending history, boost periods Art. 6(1)(b) While the account exists, except entries that form part of an accounting record
Safety and moderation: reports about members and comments, blocking, the member blacklist, the spam word filter, profile status decisions Reported content, who reported and who was reported, moderation decision and reason Art. 6(1)(f) — protecting members and the service; Art. 6(1)(c) for our obligations under the Digital Services Act Up to 3 years from the decision, so that repeat behaviour can be recognised and decisions defended
Security: firewall, malware scanning, abuse and intrusion detection IP address, user agent, requested page, time, blocked-request records Art. 6(1)(f) — keeping the site and your account secure Web server logs: 10 days. Firewall traffic records: 30 days
Answering complaints and dealing with legal claims Your correspondence and the account data it concerns Art. 6(1)(c) — Consumer Protection Act § 24 requires us to answer within 15 days; Art. 6(1)(f) for legal claims 3 years from the end of the matter
Cookies and similar technologies See the Cookies Policy Art. 6(1)(a) for everything except strictly necessary cookies; Art. 6(1)(f) for those Consent record cookie: 6 months. Login cookies: 2 days, or 14 with “remember me”

5. Your photos, audio and video

Because this is what most people actually want to know, here it is in one place.

  • Who sees them. Photos, audio and video on your public profile are visible to logged-in members only. Files you place in private photos are visible only to members you have allowed. Nobody who is not logged in can see any of it.
  • They go live immediately. There is no moderation queue and no automatic content scan before publication. Uploads appear on the site at once. Members can report content afterwards, and we review reports — see the Content Moderation Policy.
  • Metadata stays in the file. We do not re-compress or re-encode what you upload. That means any metadata your camera or phone embedded in the file stays there — which can include GPS coordinates of where the photo was taken. If that matters to you, strip the metadata before uploading.
  • We treat them as special category data, in line with the Estonian Data Protection Inspectorate’s approach to dating sites. They are covered by the same Article 9(2)(a) explicit consent as the rest of your profile.
  • Deleting. Removing a photo, audio file or video removes it from your profile and from other members’ view. Deleting your account removes your media with it.
  • What we cannot undo. If another member has already saved or screenshotted a file, we have no way to reach that copy. That is a limit of the technology, not a policy choice.

6. Who your data goes to

We do not sell, rent or trade personal data. It reaches only the following people:

  • Other members. Your profile, photos and messages are shown to other logged-in members, subject to your privacy settings, hidden mode and private photo settings.
  • Our hosting provider. The site runs on servers operated by Contabo GmbH, physically located in France, in the European Union. They act as our processor.
  • Nobody, for email. Our emails are sent from our own mail server, not through a third-party email marketing platform, so the contents of your notification and marketing emails are not passed to an outside provider. SPF, DKIM and DMARC are configured on our domain.
  • Payment gateways. If and when a payment method is enabled, the gateway you choose processes the payment as its own controller and receives what it needs to do so. Your card details go to it and never to us.
  • Wordfence, our firewall and malware scanner, which processes IP addresses and request data to block attacks.
  • Authorities, where the law actually obliges us to disclose — for example a lawful order from a court or a competent authority. We do not hand over member data on informal request.

Third-party content loaded by your browser

Some parts of the page are loaded from other companies’ servers. When that happens, your browser contacts them directly and they see your IP address, your browser details and which page you were on.

  • Google Fonts — typefaces. Loads on every page.
  • cdnjs (Cloudflare) — the Font Awesome icon set and the toastr notification library. Loads on every page.
  • Facebook SDK (Meta) and Google reCAPTCHA — these load only if you have consented to marketing cookies. Without that consent, your browser makes no requests to them at all.

To be explicit, because dating sites are often assumed to be worse than they are: no analytics package, no advertising pixel and no measurement or behavioural tracking tool of any kind is installed on this site. We do not measure your behaviour across pages and we do not build advertising profiles. The four services listed above are the complete list of outside companies your browser contacts.

7. Transfers outside the European Economic Area

Your account data itself stays in the EU — it lives on our servers in France and we do not export it.

Transfers happen only through the third-party content described above. Google LLC, Cloudflare, Inc. and Meta are established in the United States, so when your browser fetches a font, an icon, the Facebook SDK or reCAPTCHA, your IP address and browser information reach a US company.

Those transfers rely on the European Commission’s adequacy decision for the EU–U.S. Data Privacy Framework where the recipient is certified under it, and otherwise on the Commission’s standard contractual clauses under Article 46(2)(c) GDPR. You can ask us for the details at support@daytify.com. Declining marketing cookies removes the Meta and reCAPTCHA transfers entirely.

8. Cookies

In short: we set a small number of strictly necessary cookies that make login and sessions work (including PHPSESSID and the WordPress login cookies, which last 2 days, or 14 days if you choose “remember me”), plus a cookie that records your cookie choice for 6 months. Everything beyond that is set only if you consent, and you can accept all, refuse all non-essential cookies, or choose individually — and change your mind just as easily later.

The full list, with what each cookie does, who controls it and how long it lasts, is in the Cookies Policy.

9. Marketing emails, and how they differ from service emails

Service emails are not marketing. Notifications that someone messaged you, winked at you, sent a friend request, added you to favourites, or that a payment succeeded or your balance is low, are part of the service you signed up for. They rely on Article 6(1)(b). You can turn most of them off in your notification settings.

Marketing emails require your prior consent. Under Estonian Electronic Communications Act (elektroonilise side seadus) § 1031(1), direct marketing to a natural person by electronic mail requires consent given in advance, to the GDPR standard: a freely given, specific, informed and unambiguous opt-in. We do not send marketing to people who have not opted in.

Alongside that:

  • Every marketing message contains a free and simple way to object — an unsubscribe link that works without you logging in, paying anything, or explaining yourself, as § 1031(3) and (4) require.
  • We do not send marketing at all if the sender cannot be identified, if there is no working objection route, or if you have already objected — each of those is prohibited by § 1031(4).
  • The burden of proving your consent is on us, not on you (§ 1031(5)). That is why we keep the consent record described above.
  • Supervision of electronic direct marketing in Estonia is carried out by the Data Protection Inspectorate (Andmekaitse Inspektsioon), under § 133(4) of the same Act — not by the Consumer Protection and Technical Regulatory Authority. If you want to complain about marketing email from us, AKI is the right address.

10. Automated decision-making and profiling

We do not make decisions about you that are based solely on automated processing and that produce legal effects or similarly significantly affect you. Article 22 GDPR is not engaged.

For clarity about what the site does do:

  • Search, advanced search and My Matches filter profiles against criteria that you and other members typed in yourselves. There is no scoring model and no inferred ranking of people.
  • Profile Boost moves a profile to the front of the default member list for a period the member paid for. It never overrides a sort order you chose yourself, such as alphabetical or oldest first.
  • The spam word filter checks message text against a short fixed word list. It does not profile you.
  • We do not use special category data for advertising. Presenting advertising based on profiling that uses Article 9 data is prohibited by Article 26(3) of the Digital Services Act, and we do not do it.
  • Prices are not personalised. Dayt package prices are the same for everyone and are not adjusted by any automated assessment of you.

11. Do you have to give us this data?

None of it is required by statute. It is a contractual requirement, in this sense:

  • Registration fields — without a username, name, email, password and date of birth we cannot create an account for you. There is no way to use Daytify without one.
  • Being 18 or over is a condition of entering into the contract at all. It is not negotiable.
  • The profile questions, including the special category ones, are currently mandatory fields in the form. If you would rather not answer them, the honest answer is that this service will not be usable for you — and that you can withdraw your Article 9 consent at any point afterwards, with the effect described in section 2.
  • Payment and invoice data only becomes necessary if you decide to buy dayts, and then partly because accounting law requires the record.

12. How long we keep things

The table in section 4 gives the period for each purpose. Three things it does not cover:

  • Backups. Routine server backups may contain copies of data for a short period after you delete it. Those copies are not used for anything, and are overwritten as the backup cycle rotates. If we restore a backup, we re-apply deletions that were made after the restore point.
  • Server and security logs. Web server access and error logs rotate daily and are kept for 10 days. Firewall traffic records are kept for 30 days.
  • Inactive accounts. We do not currently delete accounts automatically for inactivity. If your account is dormant and you want it gone, you need to delete it or ask us to.

13. Your rights

You can exercise any of these by emailing support@daytify.com, or from your account settings where the site offers the option directly. We answer within one month, as Article 12(3) GDPR requires. Exercising a right is free.

  • Access (Art. 15) — a copy of the personal data we hold about you, and confirmation of how it is used.
  • Rectification (Art. 16) — correction of anything inaccurate. Most profile data you can edit yourself, immediately.
  • Erasure (Art. 17) — deletion of your data. You can delete your account yourself in your account settings. We keep only what we are legally required to keep, such as invoices and consent records.
  • Restriction (Art. 18) — you can require us to hold data without using it, for example while a dispute about its accuracy is resolved.
  • Portability (Art. 20) — your data in a structured, commonly used, machine-readable format. Separately, Estonian law (võlaõigusseadus § 6215(4)) gives you the right to retrieve non-personal content you created on the platform, free of charge and in machine-readable form.
  • Objection (Art. 21) — you can object to processing based on our legitimate interests. Where the processing is for direct marketing, your objection is absolute and we stop immediately, with no balancing test.
  • Withdrawal of consent (Art. 7(3)) — for anything based on consent, including the Article 9(2)(a) consent for your profile and the consent for marketing and non-essential cookies. Withdrawal is as easy as consenting was, takes effect from that moment, and — as section 2 sets out — is not a breach of contract and carries no penalty.
  • Complaint (Art. 77) — see the next section.

We may need to confirm who you are before acting, so that we do not hand your data to someone else pretending to be you.

14. Complaints and the supervisory authority

Please try us first at support@daytify.com — it is usually faster. We must acknowledge a written complaint and reply within 15 days under § 24 of the Estonian Consumer Protection Act, saying whether we accept your claim, and give written reasons if we refuse.

You do not have to come to us first, and you can complain to the supervisory authority at any time. In Estonia that is:

You may also lodge a complaint with the supervisory authority in the EU country where you live or work, or where you think the problem happened. Separately from all of this, you have the right to an effective judicial remedy against us or against a supervisory authority decision (Articles 78 and 79 GDPR).

15. Under 18s

Daytify is an adult service. You must be 18 or over. We do not knowingly collect data about anyone younger, and the service is not directed at children.

At registration you must confirm you are 18 or over, and the site independently checks the date of birth you give on the server. A date of birth showing an age under 18 is rejected, whatever the tick box says. We do not carry out automated identity-document age verification.

If we find out that an account belongs to someone under 18 — whether from a report, from moderation, or in any other way — we suspend the account immediately, stop it being shown to other members, and delete the account and its content, including all uploaded photos, audio and video. We keep only the minimum record needed to show we acted and to stop the account being recreated. Any money paid is refunded.

If you believe a member is under 18, tell us at safety@daytify.com and we will treat it as urgent.

16. How we protect your data

  • The whole site is served over HTTPS.
  • Passwords are stored only as cryptographic hashes.
  • Wordfence provides a web application firewall and malware scanning.
  • The administrative login is not at the standard address; it is moved to a non-obvious path to reduce automated attacks.
  • Servers are in the European Union, and access to them is limited to people who need it.
  • Email is authenticated with SPF, DKIM and DMARC so that messages claiming to be from Daytify can be verified.

No system is perfectly secure. If a personal data breach is likely to result in a high risk to your rights and freedoms, we will notify you as well as the Data Protection Inspectorate, as Articles 33 and 34 GDPR require.

17. Changes to this policy

If we change how we handle your data, we will update this page and change the “last updated” date. If a change is significant — a new purpose, a new category of recipient, or anything affecting your Article 9 consent — we will tell you by email or by a notice on the site before it takes effect, and where the change requires fresh consent we will ask for it rather than assume it.

We will never quietly widen what we do with data you gave us for something narrower.

18. Contact

Daytify OÜ, registry code 17541094 (Estonian Commercial Register — Äriregister), Tööstuse tn 48, Põhja-Tallinna linnaosa, Tallinn, Harju maakond, 10416, Estonia.