← deylo

Privacy

Last updated 10 September 2026

This policy describes the product as currently implemented: invite-gated community membership, one-recipient drops, location-based unlocks, replies, notifications, reports, blocks, and lightweight analytics.

What Deylo Collects

Deylo collects account data such as email address, username, display name if provided, account id, active community membership, and timestamps for account creation and updates.

Deylo stores invite and referral records so Deylo can run an invite-only community. This includes invite codes, invite status, max uses, uses count, the person or admin who generated the invite, the community it belongs to, expiration, and invite redemption records.

Deylo stores drop data needed to run the core loop: sender id, recipient id, community id, message text, optional image URL, latitude, longitude, radius, lock or unlock status, creation time, unlock time, and unlock source. Drop coordinates are used to decide whether a recipient is standing inside the drop zone.

Deylo stores replies after a recipient unlocks a drop. Replies are private between the sender and the recipient; nothing about them is public.

Deylo stores push notification tokens for signed-in devices so the app can notify users about drops sent to them, drops they unlock, and replies to drops they sent.

Deylo stores reports and blocks for safety. Reports may include the reporter id, target type, target id, reason, optional details added during moderation, status, community id, and timestamps. Blocks store the blocker id, blocked user id, optional community id, and creation time.

Deylo stores lightweight analytics events to understand whether drops are being sent, opened, and answered. Events can include event type, actor id, community id, invite id, drop id, small metadata, and timestamps. Analytics do not include message content, precise coordinates, or sensitive location payloads.

Location

Deylo uses your location for one thing: to open a drop when you are standing inside its drop zone.

When you open Deylo with a drop waiting, or use the manual check, the app reads your current location and unlocks any drop you are inside. That reading is not stored, is never shown to other people, and is never attached to a drop you send.

You can optionally allow location access "Always". If you do, your phone watches the area around your locked drops and nudges Deylo when you walk into one, even when the app is closed. Deylo does not run continuous location tracking, does not keep a history of where you have been, and never unlocks a drop from that nudge alone; you still open the app to unlock. If you decline, nothing breaks. Walk to the drop, open Deylo, and it unlocks.

Notifications

Deylo uses Expo push notifications to tell users about their own drop loop: a drop is waiting, a drop was unlocked, or someone replied to a drop they sent. Users can continue using the Received and Sent tabs even if notifications are disabled.

Service Providers

Deylo uses Firebase Authentication, Firestore, Firebase Storage, and Cloud Functions for account, database, media, and server workflows. Deylo uses Expo push services for push notification delivery. Deylo uses Sentry for crash reporting when configured.

These providers process data only as needed to operate, secure, observe, and improve Deylo.

Retention And Deletion

You can delete your account from Settings in the app, or ask us to do it by writing from the address on your account. Deleting an account removes the user's account document, push tokens, memberships, community profiles, and blocks created by that user.

Drops, replies, invite redemptions, reports, and blocks held against a deleted user may be retained because they belong to another participant's experience, referral history, or moderation record. Deleted users are anonymized in the app where their community profile is removed.

Manual deletion or privacy requests can be sent to help@deyloapp.com.

The Website

If you add your community on deyloapp.com, Deylo stores the community you chose, the email address you enter, the time you signed up, which link brought you to the page, and a hashed form of your connection's address that is used only to limit repeat submissions. The email address is used to count interest by community and, once email confirmation is in place, to send you one message confirming it is you and one the day Deylo opens in your community. Counts are shown publicly only once a community passes 25 confirmed signups, and no email address is ever shown. Write to help@deyloapp.com to be removed.

Safety

Users can report drops or users and can block other users. Deylo's team reviews reports and may disable memberships, remove content, or terminate accounts to protect community trust.

Age

Deylo is for people who are old enough to use the service under applicable law. Users under 13 may not use Deylo.

Changes

Deylo may update this policy as the product changes. If it changes in a way that matters, the date on this page changes.

Contact

Privacy contact: help@deyloapp.com.