Privacy Policy
Last updated: 31 July 2026
This Privacy Policy explains how pass.day (“we”, “us”, or “our”) collects, uses, stores, shares, and deletes personal data when you use the pass.day website and related services (the “Service”).
pass.day is a quiet letter-passing experience: someone's yesterday can become someone else's morning. It is not a social network and does not publish a public timeline.
If you have questions about this policy or your personal data, contact us at info@passday.app.
Operator note: Before production launch, publish the operator’s name (and postal address if required) as the data controller. You currently operate as an individual in Tokyo.
1. Who is responsible for your data?
The data controller for pass.day is the operator of the Service.
Until a formal legal entity and postal address are published here, privacy requests should be sent to info@passday.app. We will respond without undue delay and, where GDPR applies, within one month (extendable where permitted by law).
2. Scope
This policy applies to:
- Visitors to pass.day
- Users who sign in and create a profile
- People who pass or receive letters through the Service
It does not cover third-party sites or services we link to (for example Google sign-in), which have their own privacy policies.
3. Personal data we collect
We collect only what we need to operate the Service.
3.1 Account and profile data
When you sign in with Google, we receive and store:
- Your account identifier
- Email address (from your Google account)
- Nickname, city, country, timezone, approximate coordinates, occupation, and preferred morning hours (you provide these during onboarding or in Settings)
- Optional profile avatar image
3.2 Letters and related content
When you use the Service, we process:
- Letter text you write
- Optional images you attach to letters
- Place and time snapshots associated with a letter (for example city, country, timezone, and approximate coordinates at the moment of writing)
- Delivery records (that a letter was received, when, and via which channel)
- Optional reactions to a received letter
- Lightweight product events used to operate matching, delivery, and reliability (for example that a letter was passed or claimed)
3.3 Technical and security data
We may process:
- Session and authentication cookies or tokens needed to keep you signed in
- Basic server and security logs (for example timestamps, error diagnostics, and abuse-prevention signals)
We do not sell personal data. We do not run advertising trackers as part of the core product experience.
4. Why we process your data (purposes and legal bases)
Where the EU/UK GDPR applies, we rely on the following legal bases:
| Purpose | Examples | Legal basis |
|---|---|---|
| Provide the Service | Create your account, store your profile, match and deliver letters, show your morning letter | Contract (Art. 6(1)(b)) — performing the service you request |
| Security and integrity | Prevent abuse, enforce content rules, protect accounts | Legitimate interests (Art. 6(1)(f)) and, where relevant, legal obligation |
| Optional email notices | Morning or delivery-related email if/when that feature is enabled | Contract and/or consent, depending on how the feature is offered |
| Legal compliance | Respond to lawful requests; keep limited records where required | Legal obligation (Art. 6(1)(c)) |
| Product reliability | Understand delivery failures and keep the letter exchange working | Legitimate interests (Art. 6(1)(f)) |
You may withdraw consent where processing is based on consent, without affecting prior lawful processing.
5. How letters work (important privacy context)
pass.day is designed around anonymous one-to-one delivery:
- A letter you pass may be delivered to one other person
- Recipients may see limited presence information you chose for the Service (for example nickname and place), together with the letter content
- Letters are temporary by design and are wiped or expire after a short period as part of normal product behaviour
- The Service is not intended for posting phone numbers, email addresses, or other direct contact details inside letters
Because a letter may already have been delivered to someone else, erasure of your account anonymises authored letters so they can no longer identify you, rather than silently rewriting another person's already-received morning experience in every case. See Section 9.
6. Sharing and processors
We share personal data only with service providers that help us run pass.day, under appropriate agreements, including:
- Supabase — authentication, database, and file storage
- Google — sign-in (OAuth); Google processes data under its own terms when you authenticate
- Hosting / infrastructure providers used to serve the website
- Email delivery providers (for example Resend) if morning or transactional email is enabled
We may also disclose information if required by law, or to protect the rights, safety, and integrity of users and the Service.
We do not sell your personal data.
7. International transfers
Our processors may store or process data in countries outside your own, including outside the EEA/UK. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses or the processor's equivalent transfer mechanism.
8. Retention
We keep personal data only as long as needed for the purposes above:
- Account and profile data — for as long as your account remains open
- Letter content and images — for a short operational window (typically around 72 hours), then wiped as part of normal expiry; related delivery metadata may be pruned later
- Security / operational logs — for a limited period needed for security and debugging
- After account deletion — we delete or anonymise personal data as described in Section 9, except where a limited record must be retained for legal, security, or dispute-resolution reasons
9. Your rights
Depending on where you live (especially in the EEA/UK), you may have the right to:
- Access your personal data
- Rectify inaccurate data
- Erase your data (“right to be forgotten”)
- Restrict or object to certain processing
- Data portability — receive a machine-readable copy of data you provided
- Withdraw consent where processing is based on consent
- Lodge a complaint with your local supervisory authority
How to exercise these rights in the product
In Settings → Danger zone you can:
- Download my data — export a JSON copy of your profile, letters, deliveries, reactions, and activity history
- Delete account — permanently delete your account and associated personal data
Account deletion generally includes:
- Deleting your profile and sign-in identity
- Deleting avatars and letter images you uploaded
- Deleting letters you received, reactions, and activity history tied to you
- Anonymising letters you wrote (clearing identifying content and location details) so they can no longer identify you
You can also email info@passday.app. We may need to verify your request.
10. Children
pass.day is not directed to children under 16 (or the higher age required in your country). We do not knowingly collect personal data from children. If you believe a child has provided data, contact us and we will take appropriate steps to delete it.
11. Cookies and similar technologies
We use essential cookies / local storage needed for authentication and session continuity. We do not use non-essential advertising cookies in the core Service. If we introduce optional analytics or non-essential cookies, we will update this policy and, where required, request consent.
12. Security
We use industry-standard measures appropriate to the nature of the Service, including encrypted transport (HTTPS), access controls, and restricted database / storage policies. No method of transmission or storage is perfectly secure.
13. Changes to this policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top will change when we do. Material changes will be highlighted in the Service or by other reasonable means where appropriate. Continued use after an update means you acknowledge the revised policy, except where consent is required by law.
14. Contact
Privacy questions and data-subject requests:
- Email: info@passday.app
- In-product: Settings → Danger zone (export and deletion)
If we appoint an EU/UK representative or Data Protection Officer, those details will be added here.