Dategent Legal

Privacy Policy

Last updated: September 25, 2026

1. What Dategent is

Dategent is a desktop application you install on your own computer (Mac today; a Windows version is coming) plus a companion website. The desktop app signs in to your own Instagram account and, on your behalf, follows accounts, sends and replies to direct messages, and helps you discover and evaluate other Instagram users as potential dating prospects. Some of this work runs on your device; some runs on our servers. This policy explains, honestly, which is which.

2. Information we collect about you

  • Account — your email address and a password (the password is hashed by our authentication provider, Supabase; we never see it in plaintext).
  • Targeting preferences — your city, age range, target gender, and message tone.
  • Instagram handle(s) — the handle you connect or ask us to audit, and the connected account's username.
  • Profile audit results — scores, photo analysis, and rewrite suggestions we generate for your profile.
  • Your photos and generated images — reference photos of yourself that you upload, and the profile images we generate from them for your review. They are kept in private storage that only our servers can read; you see them through short-lived links. We drop the location and device details from photos you upload. Nothing is posted to your Instagram unless you approve that specific image.
  • Instagram posting connection — if you connect your Instagram for posting: the connected account's username, whether it is a Business or Creator account (learned from whether Instagram accepts a story), when you connected it, each post's planned time, and the link to each post once it is live. Your time zone, from your device, so posts go out at a reasonable local hour.
  • Payment data — handled by Whop. We store only your Whop customer and subscription identifiers, your plan, and status. We never store your card number or CVV.
  • Consent record — when you accept our Terms and safety acknowledgment, we record the timestamp, your IP address, and your browser user-agent as a consent audit trail.
  • Usage metrics — counts such as follows, messages sent, and credits used, for product limits and your dashboard.
You sign in with your email address and password. If you ask us to email you the desktop link from your phone, that email contains a one-time sign-in link so you can open Dategent on your computer.

3. Your Instagram activity — what stays on your device

The desktop app stores the following locally on your computer only and does not transmit it to us:
  • Your Instagram login session / cookies (encrypted on-device using your operating system's secure storage). We never receive or store your Instagram password.
  • Your local prospect pool, swipe decisions, and follow/message queue (kept in a local database on your machine).

4. Conversations and messages — what reaches our servers

We do store the content of the direct messages your Dategent agent sends and receives. To draft in-context replies and let you review conversations, the text of incoming and outgoing DMs in agent-managed conversations, along with the other participant's Instagram handle and display name, is stored in our database (Supabase). To generate replies and openers, the relevant conversation text is also sent to our AI providers (see Section 6). We do not ingest your entire Instagram inbox — only the conversations your agent is actively managing.

5. Third-party Instagram users (the prospect pool)

To help you find prospects, Dategent processes data about other Instagram users — people you have not necessarily interacted with yet. This is a real processing activity worth disclosing plainly:
  • What we process — public profile information: Instagram handle, display name, profile-picture URL, bio, and follower/following/post counts; an AI-derived apparent age estimate, gender classification, and an internal desirability/attractiveness score; and content “vibe” tags.
  • Where it is stored — when our server-side discovery feature is used, this data is stored in our database as a per-city pool, de-duplicated per user. The desktop app also keeps a copy of prospects you are reviewing in its local database. We store profile-picture URLs, not the image files themselves — images are fetched transiently for AI safety scoring and then discarded.
  • Child safety — a profile is excluded fail-closed unless our checks affirmatively confirm the person is an adult; profiles that do not pass are deleted, not stored.
  • How it is collected — server-side discovery is live. When you run discovery for your city, our servers search the web for public Instagram pages tied to that city (salons, studios, bars and similar local spots) and use Apify, a data-collection service, to read the public follower lists of those pages. Private accounts, and accounts that look like businesses, bots or minors, are dropped before any AI step. For the rest, the profile photo is sent to Anthropic to estimate age and gender and to score the profile, and the bio is checked on our servers for a stated age. We do this to show you people in your area you might want to meet.
If you are an Instagram user who believes your information is in our prospect pool and you want it removed, email privacy@dategent.io.

6. AI processing and the providers we use

We use third-party AI providers to operate the Service. What each receives:
  • Anthropic (Claude) — receives prospect profile photos to estimate apparent age and gender for safety filtering and to score the profile. When the desktop app runs its age check on a prospect (when adding them to your queue and again before messaging), Anthropic also receives up to three post thumbnails from the top of that person's public profile grid. It also receives your profile photos for your audit, and conversation text to draft replies and openers.
  • Moonshot AI (Kimi) — receives conversation text and prospect context to draft message openers and replies.
  • Kie — receives your own photos when you request AI photo enhancement or generated profile images, to make those images.
  • Anthropic, for generated images — receives your reference photo and each generated image, to check that it still looks like you and passes our safety checks before you see it.
We do not sell your data to these providers; they process it to return a result to us. We do not use your data to train their public models.

7. Service providers we share data with

  • Whop — payment processing and payment receipts
  • Supabase — database and authentication hosting
  • Vercel — web hosting and edge network
  • Resend — delivers our emails: password-reset links, and the desktop sign-in link only when you request it
  • Anthropic, Moonshot AI, Kie — AI processing, as described in Section 6
  • Apify and ScrapeCreators — Instagram public-data collection for the discovery feature
  • Zernio (ZERNIO SOFTWARE SL, Spain) — posts the images you approve to your own Instagram, only if you connect Instagram for posting. It receives each approved image and its caption, and it holds the access token for the Instagram account you connect: Instagram issues that token to Zernio when you sign in on Instagram's own page, and we never see your Instagram password. Nothing is posted unless you approved that specific item. Disconnecting, or deleting your account, removes the connection.
We do not sell your personal information, and we do not share it with advertisers.

8. Data retention

We retain your account data, targeting preferences, audit results, conversation/message content, usage metrics, and prospect-pool data for as long as your account is active. Your consent record (Section 2) is retained as a legal compliance record. When you delete your account (Section 9), we delete the categories described there. We do not currently run a fixed-period auto-purge of conversation logs; if that changes we will update this policy.

Generated profile images are deleted 30 days after you post or dismiss them (or reject them), together with their record. Images that fail our likeness or safety check are deleted right away. For an image we post for you, Zernio keeps its own copy as part of the post under its own retention, and the post stays on your Instagram until you delete it there. Reference photos you upload stay until you remove them or delete your account.

9. Your choices and how to delete your data

You can access or correct most of your data from your in-app Settings. You can request a copy or a full deletion at any time:
  • Use the Delete account option in Settings, which removes your account and associated data and cancels any active subscription; or
  • Email privacy@dategent.io from your account email address and we will fulfill the request within 30 days.
Deleting your account removes your server-side data as described above, but it does not delete data Whop independently retains for tax and anti-fraud purposes, or the minimal consent record we keep for legal compliance. Separately, the desktop app stores some data on your own computer — its local database and your encrypted Instagram session — which is removed when you uninstall the app, not by the server-side deletion.

10. California privacy rights (CCPA / CPRA)

If you are a California resident, you have specific rights regarding your personal information.

Categories we collect: identifiers (email, Instagram handle, IP address); commercial information (subscription and payment status); internet activity (in-app usage metrics); and inferences (AI-derived audit and prospect scores). Sources, purposes, and the providers we disclose to are described in Sections 2–7.

Your rights: to know and access the personal information we hold about you; to correct it; to delete it; and to opt out of sale or sharing.

Sale / sharing: we do not sell your personal information and do not share it for cross-context behavioral advertising. There is therefore nothing to opt out of, but you may still contact us to confirm.

Non-discrimination: we will not deny service, charge a different price, or provide a different quality of service because you exercised these rights.

To exercise any of these rights, email privacy@dategent.io. We will verify your request using your account email.

11. Security

Traffic between your browser or desktop app and our servers is encrypted with HTTPS, and data at rest is encrypted by our managed database provider. Your Instagram session is encrypted on your own device and never sent to us. No method of storage or transmission is perfectly secure, and we cannot guarantee absolute security.

12. Cookies

We use only essential cookies required for authentication and core functionality. We do not use advertising or cross-site tracking cookies.

13. Children

Dategent is strictly for adults 18 and older, both as users and as prospects. We do not knowingly collect personal information from anyone under 18. Our safety systems are designed to exclude minors from the prospect pool and from messaging; if we learn we have information about a minor, we delete it.

14. Changes to this policy

We may update this policy from time to time. Material changes will be announced by email or in-app, and the “Last updated” date above will change.

15. Contact

Privacy questions or data requests? Email privacy@dategent.io.