The quick read
A Dearly greeting is a public web page.
Anyone with its link can view and reshare it, and search engines may index it. Names, messages, relationship details, and uploaded photos used in a greeting should therefore be treated as public. Your signed-in archive is private, but the greeting pages inside it are not.
- Do not submit secrets, financial information, addresses, or sensitive personal details.
- Only share another person's name, story, or photo when you have permission or another lawful right.
- Dearly sends writing inputs—not uploaded photos—to Google's Gemini service to draft a message.
- We do not sell personal information or use it for targeted advertising.
- You can ask us to access, correct, export, or delete information by emailing us.
Who is responsible for your information
Dearly is operated by Mojeeb Titilayo from Ogun State, Nigeria. For applicable data-protection law, the Dearly operator is the controller of personal information handled through the service.
Privacy questions, complaints, and rights requests can be sent to hello@mojeeb.xyz. Please use the subject “Dearly privacy request” and identify the relevant greeting URL or account email where possible. Do not send passwords, authentication links, or identity documents unless we ask for a specific verification method.
Information Dearly collects
| Category | Examples in the current service | Source |
|---|---|---|
| Greeting details | Recipient and sender names, relationship, occasion, traits, hobbies, tone, generated message, and creation date. | The greeting creator; some details concern the recipient. |
| Photos and public contributions | Optional greeting photos; names, countries, relationships, condolence notes, wishes, and heart placement on public tribute pages. | Creators and contributors. |
| Account and identity | Email address, Supabase user identifier, authentication events, and—if Google sign-in is chosen—Google name, email address, profile image, and Google account identifier. | You, Supabase Auth, or Google. |
| Security and claim data | Short-lived greeting claim secrets, hashed claim records, session information, and salted hashes derived from IP addresses for contribution rate limits. | Your browser, device request, and Dearly. |
| Usage and device data | Page path, time, referrer, coarse location, browser, operating system, device type, aggregated interaction or performance data, and IP address processed transiently by network providers. | Your browser and privacy-preserving analytics providers. |
| Communications | Emails and details you send when requesting support, removal, or privacy assistance. | You. |
Dearly does not intentionally request government identifiers, precise location, payment-card details, health information, or other highly sensitive data. Free-text fields can still contain such information; please do not put it there. Current Dearly does not process payments, operate a merchant marketplace, or provide private Memory Spaces. We will update this notice before those features collect information.
How and why Dearly uses information
| Purpose | Typical legal basis |
|---|---|
| Create, host, display, and share the greeting or contribution you request. | Performance of our agreement with you; legitimate interests in providing the requested service; consent where the law requires it. |
| Generate a draft message and improve reliability of that request. | Performance of our agreement and your requested pre-contract steps. |
| Authenticate you, maintain your private archive, and connect greetings you own. | Performance of our agreement and legitimate interests in account security. |
| Prevent spam, fraud, abuse, and unauthorized access; diagnose faults. | Legitimate interests in protecting people and the service; legal obligations where applicable. |
| Understand aggregated usage and performance. | Legitimate interests in maintaining and improving Dearly, using cookieless analytics designed not to identify visitors. |
| Respond to requests, enforce our terms, and comply with law. | Performance of our agreement, legitimate interests, and legal obligations. |
Legal labels differ by country. Where consent is the appropriate basis, you can withdraw it for future processing. Withdrawal does not undo processing that was lawful before withdrawal and may require us to remove content or close an account if the service can no longer operate for you.
Public greetings, photos, and tribute messages
Greeting pages and tribute contributions are intentionally public. A link is not a privacy control: a viewer can copy it, capture the page, reshare it, or submit it to a search engine. Public pages may expose the content to recipients, contributors, social networks selected by a user, search engines, and anyone else who receives the URL.
A creator must have authority to provide information about another person and must respect that person's privacy, confidentiality, publicity, and intellectual-property rights. This is especially important for photographs, information about children, bereavement messages, and details that reveal health, religion, sexuality, or other sensitive matters.
Optional photos upload to public storage as soon as the upload finishes, even if the greeting is not later submitted. Removing the browser preview does not currently delete the stored file. Ask us to remove an unused or published photo by sending its URL to hello@mojeeb.xyz.
Google account data
If you choose “Continue with Google,” Dearly requests only the basic OpenID Connect identity scopes needed to sign you in: openid, email, and profile. This can provide your Google account identifier, name, email address, and profile image. Dearly uses this information to authenticate you, establish basic account identity, create or update your Dearly profile, and connect your saved greetings to your account.
Dearly does not request Google Drive, Gmail, Calendar, contacts, or advertising data; does not act on your behalf in those services; and does not sell Google user data or use it for advertising, credit, or surveillance. Supabase provides the authentication infrastructure. Google data is shared only as described in this policy, for security or legal compliance, or with your direction.
You can disconnect Dearly in your Google Account's third-party connection settings. To delete the copy held in your Dearly account, also email hello@mojeeb.xyz; disconnecting Google alone does not automatically delete content already stored by Dearly. Dearly's use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements where applicable.
AI-assisted writing
Dearly sends the recipient name, sender name, relationship, occasion, traits, hobbies, and selected tone to Google's Gemini API to generate a draft message. The optional uploaded photo is not included in that AI prompt. Google receives and processes the request under the applicable Google service terms and settings.
Generated text can be inaccurate, repetitive, unsuitable, or unexpectedly sensitive. Review it before sharing. Dearly does not use the generation to make decisions that produce legal or similarly significant effects about a person. Do not enter confidential, regulated, or highly sensitive information into the writing fields.
Analytics, cookies, and browser storage
Dearly currently uses Vercel Web Analytics and Umami Cloud. They report information such as page views, referrers, coarse country or region, browser, operating system, and device type. Both services describe their standard web analytics as cookie-free and designed to avoid identifying visitors. Dearly does not configure advertising trackers or cross-site behavioral profiles. Certain special tribute pages also request font files from Fontshare, which receives the standard technical data needed to answer that request.
Supabase stores the authenticated session in browser storage so you remain signed in. For a greeting made while signed out, Dearly temporarily stores a random claim secret in session storage so you can attach that greeting to an account. The secret expires server-side after 24 hours and is removed from the browser after a successful claim. Google and other sites you choose to visit through links may use their own cookies under their policies.
How long information is kept
Dearly uses these criteria because not every record has the same purpose:
- Public greetings, uploaded photos, wishes, and tribute messages remain available until removed by Dearly, deleted at a valid request, or no longer needed to provide the service. There is currently no automatic expiry for published content.
- Account and profile information remains while the account is active and for a reasonable period needed for security, dispute handling, backups, and legal obligations after closure.
- Anonymous greeting claim secrets expire after 24 hours. Hashed claim status may remain as a security and ownership record.
- Salted IP hashes and operational logs remain only as long as reasonably needed for rate limiting, security, debugging, and legal obligations, subject to provider and backup cycles.
- Aggregated analytics remains according to Dearly's provider configuration. Vercel's visitor-identification hash resets daily; this does not mean every aggregate analytics record is deleted daily.
- Support and rights-request records remain as needed to resolve the request and demonstrate compliance.
A deletion request may not remove copies already saved or reposted by other people or indexed in a third party's cache. We may retain narrowly limited information where law requires it or where necessary to establish, exercise, or defend legal claims.
Your privacy rights and complaints
Depending on where you live and which law applies—including Nigeria's Data Protection Act 2023, the EU GDPR, the UK GDPR as amended by the Data (Use and Access) Act 2025, and applicable United States state laws—you may have rights to:
- be informed and access your data
- correct inaccurate data
- request deletion
- restrict or object to processing
- receive portable data
- withdraw consent for future use
- avoid certain solely automated decisions
- complain without discrimination or retaliation
Email hello@mojeeb.xyz to exercise a right or make a complaint. We may need proportionate information to verify your identity, authority, and connection to the content. We will respond within the period required by applicable law. An authorized agent may submit a request where local law permits; we may verify the authorization directly with you.
If we cannot resolve a complaint, you may contact the Nigeria Data Protection Commission, the data-protection authority where you live in the EEA, the UK Information Commissioner's Office, or the relevant US state regulator. California residents can also review the California Attorney General's CCPA information. Dearly does not sell personal information, share it for cross-context behavioral advertising, or use sensitive personal information to infer characteristics, so there is currently no sale/sharing opt-out to process.
International data transfers
Dearly is operated from Nigeria and uses global cloud providers. Information may therefore be processed in Nigeria, the United States, the European Economic Area, or other countries where a provider operates. Those countries may have different privacy laws. Where applicable, Dearly relies on provider contractual terms, data-processing agreements, approved transfer mechanisms, and other safeguards required by law. Contact us if you need information about a transfer relevant to your request.
Children and family information
Dearly is a general-audience service and is not directed to children under 13. A person under 13 must not create an account or submit personal information. If local law sets a higher age for independent consent, a parent or legal guardian must authorize the use. We do not knowingly collect personal information directly from a child without required parental permission.
Adults should not publish a child's name, image, school, location, health information, or other identifying detail unless they have parental authority and have considered the lasting risks of a public page. If you believe a child's information was submitted improperly, email us for priority review and removal.
How Dearly protects information
Dearly uses HTTPS, managed authentication, database and storage access controls, server-only administrative credentials, hashed claim secrets, salted IP hashes for rate limiting, and separation between public content and private account ownership records. Access is limited according to operational need.
No online service can promise absolute security. Keep sign-in links private, sign out on shared devices, avoid placing sensitive information in public greetings, and report a suspected incident promptly to hello@mojeeb.xyz.
Changes and contact
We may update this policy when Dearly's product, providers, or legal obligations change. The date at the top will change, and we will provide additional notice when a change materially affects how existing personal information is used. Future commerce, Memory Space, or private family features will receive updated, feature-specific disclosures before launch.
Questions belong at hello@mojeeb.xyz. For the rules governing use of Dearly, read our Terms of Use.