Privacy Policy
Last updated: September 25, 2026
1. What Dategent is
2. Information we collect about you
- Account — your email address and a password (the password is hashed by our authentication provider, Supabase; we never see it in plaintext).
- Targeting preferences — your city, age range, target gender, and message tone.
- Instagram handle(s) — the handle you connect or ask us to audit, and the connected account's username.
- Profile audit results — scores, photo analysis, and rewrite suggestions we generate for your profile.
- Your photos and generated images — reference photos of yourself that you upload, and the profile images we generate from them for your review. They are kept in private storage that only our servers can read; you see them through short-lived links. We drop the location and device details from photos you upload. Nothing is posted to your Instagram unless you approve that specific image.
- Instagram posting connection — if you connect your Instagram for posting: the connected account's username, whether it is a Business or Creator account (learned from whether Instagram accepts a story), when you connected it, each post's planned time, and the link to each post once it is live. Your time zone, from your device, so posts go out at a reasonable local hour.
- Payment data — handled by Whop. We store only your Whop customer and subscription identifiers, your plan, and status. We never store your card number or CVV.
- Consent record — when you accept our Terms and safety acknowledgment, we record the timestamp, your IP address, and your browser user-agent as a consent audit trail.
- Usage metrics — counts such as follows, messages sent, and credits used, for product limits and your dashboard.
3. Your Instagram activity — what stays on your device
- Your Instagram login session / cookies (encrypted on-device using your operating system's secure storage). We never receive or store your Instagram password.
- Your local prospect pool, swipe decisions, and follow/message queue (kept in a local database on your machine).
4. Conversations and messages — what reaches our servers
5. Third-party Instagram users (the prospect pool)
- What we process — public profile information: Instagram handle, display name, profile-picture URL, bio, and follower/following/post counts; an AI-derived apparent age estimate, gender classification, and an internal desirability/attractiveness score; and content “vibe” tags.
- Where it is stored — when our server-side discovery feature is used, this data is stored in our database as a per-city pool, de-duplicated per user. The desktop app also keeps a copy of prospects you are reviewing in its local database. We store profile-picture URLs, not the image files themselves — images are fetched transiently for AI safety scoring and then discarded.
- Child safety — a profile is excluded fail-closed unless our checks affirmatively confirm the person is an adult; profiles that do not pass are deleted, not stored.
- How it is collected — server-side discovery is live. When you run discovery for your city, our servers search the web for public Instagram pages tied to that city (salons, studios, bars and similar local spots) and use Apify, a data-collection service, to read the public follower lists of those pages. Private accounts, and accounts that look like businesses, bots or minors, are dropped before any AI step. For the rest, the profile photo is sent to Anthropic to estimate age and gender and to score the profile, and the bio is checked on our servers for a stated age. We do this to show you people in your area you might want to meet.
6. AI processing and the providers we use
- Anthropic (Claude) — receives prospect profile photos to estimate apparent age and gender for safety filtering and to score the profile. When the desktop app runs its age check on a prospect (when adding them to your queue and again before messaging), Anthropic also receives up to three post thumbnails from the top of that person's public profile grid. It also receives your profile photos for your audit, and conversation text to draft replies and openers.
- Moonshot AI (Kimi) — receives conversation text and prospect context to draft message openers and replies.
- Kie — receives your own photos when you request AI photo enhancement or generated profile images, to make those images.
- Anthropic, for generated images — receives your reference photo and each generated image, to check that it still looks like you and passes our safety checks before you see it.
7. Service providers we share data with
- Whop — payment processing and payment receipts
- Supabase — database and authentication hosting
- Vercel — web hosting and edge network
- Resend — delivers our emails: password-reset links, and the desktop sign-in link only when you request it
- Anthropic, Moonshot AI, Kie — AI processing, as described in Section 6
- Apify and ScrapeCreators — Instagram public-data collection for the discovery feature
- Zernio (ZERNIO SOFTWARE SL, Spain) — posts the images you approve to your own Instagram, only if you connect Instagram for posting. It receives each approved image and its caption, and it holds the access token for the Instagram account you connect: Instagram issues that token to Zernio when you sign in on Instagram's own page, and we never see your Instagram password. Nothing is posted unless you approved that specific item. Disconnecting, or deleting your account, removes the connection.
8. Data retention
Generated profile images are deleted 30 days after you post or dismiss them (or reject them), together with their record. Images that fail our likeness or safety check are deleted right away. For an image we post for you, Zernio keeps its own copy as part of the post under its own retention, and the post stays on your Instagram until you delete it there. Reference photos you upload stay until you remove them or delete your account.
9. Your choices and how to delete your data
- Use the Delete account option in Settings, which removes your account and associated data and cancels any active subscription; or
- Email privacy@dategent.io from your account email address and we will fulfill the request within 30 days.
10. California privacy rights (CCPA / CPRA)
Categories we collect: identifiers (email, Instagram handle, IP address); commercial information (subscription and payment status); internet activity (in-app usage metrics); and inferences (AI-derived audit and prospect scores). Sources, purposes, and the providers we disclose to are described in Sections 2–7.
Your rights: to know and access the personal information we hold about you; to correct it; to delete it; and to opt out of sale or sharing.
Sale / sharing: we do not sell your personal information and do not share it for cross-context behavioral advertising. There is therefore nothing to opt out of, but you may still contact us to confirm.
Non-discrimination: we will not deny service, charge a different price, or provide a different quality of service because you exercised these rights.
To exercise any of these rights, email privacy@dategent.io. We will verify your request using your account email.