The quick read
A Dearly greeting is a public web page.
Anyone with its link can view and reshare it. Dearly asks search engines not to index personal greeting pages, but cannot control third-party copies or guarantee their removal from search results. Names, messages, relationship details, and uploaded photos used in a greeting should therefore be treated as public. Your signed-in archive is private, but the greeting pages inside it are not.
Celebration Cakes use separate, hard-to-guess contributor and recipient links and are marked not to be indexed. They are shared-by-link, not confidential: anyone who receives a valid link can use the access that link grants until it expires or the creator replaces it.
Memory Spaces are different: they require a signed-in account and an active owner, manager, contributor, or viewer membership. They are private by default, excluded from public discovery, and use short-lived signed links for photographs.
- Do not submit secrets, financial information, addresses, or sensitive personal details.
- Only share another person's name, story, or photo when you have permission or another lawful right.
- Dearly sends writing inputs—not uploaded photos—to Google's Gemini service to draft a message.
- We do not sell personal information or use it for targeted advertising.
- You can ask us to access, correct, export, or delete information by emailing us.
Who is responsible for your information
Dearly is a product published by BlindspotLab and operated by Mojeeb Titilayo from Ogun State, Nigeria. For applicable data-protection law, the Dearly operator is the controller of personal information handled through the service.
Privacy questions, complaints, and rights requests can be sent to hello@blindspotlab.xyz. Please use the subject “Dearly privacy request” and identify the relevant greeting URL or account email where possible. Do not send passwords, authentication links, or identity documents unless we ask for a specific verification method.
Information Dearly collects
| Category | Examples in the current service | Source |
|---|---|---|
| Greeting details | Recipient and sender names, relationship, occasion, traits, hobbies, tone, generated message, and creation date. | The greeting creator; some details concern the recipient. |
| Celebration Cake details | Recipient name, birthday celebration date, optional age, creator message, Cake configuration, contributor names and wishes, moderation state, reveal timing, and simple recipient reactions. | The signed-in creator, invited contributors, and the recipient. |
| Private Memory Space information | Subject name and date of birth, the owner's relationship, timeline destination age, dated stories, titles, milestone categories, private photographs, alternative text, contributor identifiers, roles, invitation status, and export or deletion activity. | The adult owner and signed-in people the owner or manager invites. Some information may concern a child or another family member. |
| Photos and public contributions | Optional greeting photos; names, countries, relationships, condolence notes, wishes, and heart placement on public tribute pages. | Creators and contributors. |
| Account and identity | Email address, Supabase user identifier, authentication events, and—if Google sign-in is chosen—Google name, email address, profile image, and Google account identifier. | You, Supabase Auth, or Google. |
| Payment and purchase records | Dearly Moment purchase reference, Flutterwave transaction identifier, amount, currency, payment status, selected Cake, and resulting entitlement status. Dearly does not receive or store your payment-card number. | You, Dearly, and Flutterwave. |
| Security and claim data | Short-lived greeting claim secrets, hashed claim records, hashed and expiring Cake access secrets, session information, and salted or transient hashes derived from request addresses for rate limits. | Your browser, device request, and Dearly. |
| Usage and device data | Page path, time, referrer, coarse location, browser, operating system, device type, aggregated interaction or performance data, and IP address processed transiently by network providers. | Your browser and privacy-preserving analytics providers. |
| Communications | Emails and details you send when requesting support, removal, or privacy assistance. | You. |
Dearly does not intentionally request government identifiers, precise location, payment-card details, health information, or other highly sensitive data. Free-text fields can still contain such information; please do not put it there. Dearly offers an optional one-time Flutterwave checkout for Dearly Moment, but does not operate a merchant marketplace.
How and why Dearly uses information
| Purpose | Typical legal basis |
|---|---|
| Create, host, display, moderate, and share the greeting, Celebration Cake, wish, or reaction you request. | Performance of our agreement with you; legitimate interests in providing the requested service; consent where the law requires it. |
| Generate a draft message and improve reliability of that request. | Performance of our agreement and your requested pre-contract steps. |
| Authenticate you, maintain your private creator desks, and connect greetings and Celebrations you own. | Performance of our agreement and legitimate interests in account security. |
| Create and protect a private Memory Space; calculate age at each memory; manage scoped contributors; store private photographs; provide export; and complete owner-requested deletion. | Performance of our agreement with the signed-in adult owner and invited members; legitimate interests in secure, private service delivery; consent or another lawful basis where applicable to information about another person. |
| Start an optional Dearly Moment checkout, verify payment, activate the purchased feature, prevent payment fraud, and resolve payment support requests. | Performance of our agreement with the purchaser; legitimate interests in fraud prevention, accurate reconciliation, and support; legal obligations where applicable. |
| Prevent spam, fraud, abuse, and unauthorized access; diagnose faults. | Legitimate interests in protecting people and the service; legal obligations where applicable. |
| Understand aggregated usage and performance. | Legitimate interests in maintaining and improving Dearly, using cookieless analytics designed not to identify visitors. |
| Respond to requests, enforce our terms, and comply with law. | Performance of our agreement, legitimate interests, and legal obligations. |
Legal labels differ by country. Where consent is the appropriate basis, you can withdraw it for future processing. Withdrawal does not undo processing that was lawful before withdrawal and may require us to remove content or close an account if the service can no longer operate for you.
Public pages and shared-by-link Celebrations
Greeting pages and tribute contributions are intentionally public. A link is not a privacy control: a viewer can copy it, capture the page, or reshare it. Dearly asks search engines not to index personal greeting pages, but cannot control third-party copies or guarantee removal from search results. Public pages may expose content to recipients, contributors, social networks selected by a user, and anyone else who receives the URL.
A creator must have authority to provide information about another person and must respect that person's privacy, confidentiality, publicity, and intellectual-property rights. This is especially important for photographs, information about children, bereavement messages, and details that reveal health, religion, sexuality, or other sensitive matters.
Optional photos upload to public storage as soon as the upload finishes, even if the greeting is not later submitted. Removing the browser preview does not currently delete the stored file. Ask us to remove an unused or published photo by sending its URL to hello@blindspotlab.xyz.
Celebration Cakes are not listed publicly and use different contributor and recipient links. The raw secret is carried in the link fragment, removed from the address bar after opening, and checked against a stored hash. Contributor links permit names and wishes; recipient links permit the revealed message, approved wishes, and a simple reaction. Do not forward either link beyond the people who should have that access. Dearly cannot prevent a recipient from copying or capturing content they can view.
Private Memory Spaces
A Memory Space is private from creation. It has no public profile, public listing, or public media URL. Access requires a Dearly account and a current role in that specific Space. Owners can manage membership, export the archive, and permanently delete it. Managers can edit and invite within their scope; contributors can add memories; viewers can read. Removing a member ends their future access immediately, although Dearly cannot erase copies they previously downloaded or captured.
Invitation links contain a one-use random secret in the URL fragment. Dearly stores only its hash, removes the fragment from the address bar when opened, and expires unused invitations after 30 days. Private photo downloads use signed URLs that normally expire after five minutes. Do not forward invitation or signed download links beyond the intended person.
The owner must be an adult authorised to preserve the subject's information. A child does not receive a Dearly login through this feature. Dearly does not use Memory titles, stories, names, birth dates, or photos for targeted advertising, public recommendations, or product analytics, and does not send selected Memory content to an AI provider unless a later, clearly disclosed feature asks the owner to review and confirm the exact selected content first.
Memory photographs are stored in a private Supabase bucket. JPG/JPEG, PNG, WebP, HEIC, and HEIF originals are accepted up to 10 MiB. HEIC or HEIF browser preview may be unavailable; the private original remains downloadable while the requester retains access. Dearly does not currently promise permanent archival preservation, so owners should keep independent copies and use the provided JSON export.
Google account data
If you choose “Continue with Google,” Dearly requests only the basic OpenID Connect identity scopes needed to sign you in: openid, email, and profile. This can provide your Google account identifier, name, email address, and profile image. Dearly uses this information to authenticate you, establish basic account identity, create or update your Dearly profile, and connect your saved greetings to your account.
Dearly does not request Google Drive, Gmail, Calendar, contacts, or advertising data; does not act on your behalf in those services; and does not sell Google user data or use it for advertising, credit, or surveillance. Supabase provides the authentication infrastructure. Google data is shared only as described in this policy, for security or legal compliance, or with your direction.
You can disconnect Dearly in your Google Account's third-party connection settings. To delete the copy held in your Dearly account, also email hello@blindspotlab.xyz; disconnecting Google alone does not automatically delete content already stored by Dearly. Dearly's use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements where applicable.
AI-assisted writing
Dearly sends the recipient name, sender name, relationship, occasion, traits, hobbies, and selected tone to Google's Gemini API to generate a draft message. The optional uploaded photo is not included in that AI prompt. Google receives and processes the request under the applicable Google service terms and settings.
Generated text can be inaccurate, repetitive, unsuitable, or unexpectedly sensitive. Review it before sharing. Dearly does not use the generation to make decisions that produce legal or similarly significant effects about a person. Do not enter confidential, regulated, or highly sensitive information into the writing fields.
Payments and Dearly Moment
Dearly Moment is an optional, one-time paid upgrade for a Celebration Cake. Dearly uses Flutterwave to host checkout and verify payment. Dearly sends Flutterwave the information needed to process the transaction, including the purchaser's email address, any available account name, payment reference, amount, currency, and limited product information. Flutterwave processes payment-card and other payment-method information under its own privacy notice; Dearly does not receive or store payment-card numbers.
Dearly stores the payment and entitlement records needed to prevent fraud, reconcile a transaction, unlock the selected Cake only after verification, respond to support requests, and meet applicable legal or accounting obligations. We do not use payment records for targeted advertising or sell them.
Analytics, cookies, and browser storage
Dearly currently uses Vercel Web Analytics and Umami Cloud. They report information such as page views, referrers, coarse country or region, browser, operating system, and device type. Both services describe their standard web analytics as cookie-free and designed to avoid identifying visitors. Dearly does not configure advertising trackers or cross-site behavioral profiles. Certain special tribute pages also request font files from Fontshare, which receives the standard technical data needed to answer that request.
Supabase stores the authenticated session in browser storage so you remain signed in. For a greeting made while signed out, Dearly temporarily stores a random claim secret in session storage so you can attach that greeting to an account. The secret expires server-side after 24 hours and is removed from the browser after a successful claim. Cake contributor and reveal secrets, and newly generated creator sharing links, may also remain in session storage for the current browser tab. A Memory invitation secret and an unsaved Memory text draft may also remain in session storage for the current tab until acceptance, successful saving, or the tab's storage is cleared. Google and other sites you choose to visit through links may use their own cookies under their policies.
How long information is kept
Dearly uses these criteria because not every record has the same purpose:
- Public greetings, uploaded photos, wishes, and tribute messages remain available until removed by Dearly, deleted at a valid request, or no longer needed to provide the service. There is currently no automatic expiry for published content.
- Account and profile information remains while the account is active and for a reasonable period needed for security, dispute handling, backups, and legal obligations after closure.
- Anonymous greeting claim secrets expire after 24 hours. Hashed claim status may remain as a security and ownership record.
- Celebration contributor and reveal secrets expire after one year unless the creator replaces them sooner. Cake configurations, approved and moderated wishes, and reactions remain until removed at a valid request or no longer needed to provide the service.
- Payment and Dearly Moment entitlement records remain for as long as reasonably needed for transaction reconciliation, fraud prevention, support, applicable legal or accounting obligations, and provider or backup cycles.
- Unused Memory invitation secrets expire after 30 days; only their one-way hashes are stored. Accepted, expired, or revoked invitation records may remain as narrowly scoped access and security records.
- Memory Space subject details, stories, membership records, and private photos remain until the owner permanently deletes the Space, a valid rights request requires earlier action, or Dearly can no longer provide the service. Signed photo URLs normally expire after five minutes.
- Salted IP hashes and operational logs remain only as long as reasonably needed for rate limiting, security, debugging, and legal obligations, subject to provider and backup cycles.
- Aggregated analytics remains according to Dearly's provider configuration. Vercel's visitor-identification hash resets daily; this does not mean every aggregate analytics record is deleted daily.
- Support and rights-request records remain as needed to resolve the request and demonstrate compliance.
A deletion request may not remove copies already saved or reposted by other people or indexed in a third party's cache. We may retain narrowly limited information where law requires it or where necessary to establish, exercise, or defend legal claims.
Your privacy rights and complaints
Depending on where you live and which law applies—including Nigeria's Data Protection Act 2023, the EU GDPR, the UK GDPR as amended by the Data (Use and Access) Act 2025, and applicable United States state laws—you may have rights to:
- be informed and access your data
- correct inaccurate data
- request deletion
- restrict or object to processing
- receive portable data
- withdraw consent for future use
- avoid certain solely automated decisions
- complain without discrimination or retaliation
Email hello@blindspotlab.xyz to exercise a right or make a complaint. We may need proportionate information to verify your identity, authority, and connection to the content. We will respond within the period required by applicable law. An authorized agent may submit a request where local law permits; we may verify the authorization directly with you.
If we cannot resolve a complaint, you may contact the Nigeria Data Protection Commission, the data-protection authority where you live in the EEA, the UK Information Commissioner's Office, or the relevant US state regulator. California residents can also review the California Attorney General's CCPA information. Dearly does not sell personal information, share it for cross-context behavioral advertising, or use sensitive personal information to infer characteristics, so there is currently no sale/sharing opt-out to process.
International data transfers
Dearly is operated from Nigeria and uses global cloud providers. Information may therefore be processed in Nigeria, the United States, the European Economic Area, or other countries where a provider operates. Those countries may have different privacy laws. Where applicable, Dearly relies on provider contractual terms, data-processing agreements, approved transfer mechanisms, and other safeguards required by law. Contact us if you need information about a transfer relevant to your request.
Children and family information
Dearly is a general-audience service and is not directed to children under 13. A person under 13 must not create an account or submit personal information. If local law sets a higher age for independent consent, a parent or legal guardian must authorize the use. We do not knowingly collect personal information directly from a child without required parental permission.
A Memory Space may let an adult parent or guardian preserve information about a child without creating an account for the child. The adult must affirm that they are authorised to provide the information. Memory Spaces use high-privacy defaults: there is no public discovery, no child-facing profile, no precise-location field, no targeted advertising, and no automatic sharing outside explicitly invited adult accounts.
Adults should not publish a child's name, image, school, location, health information, or other identifying detail on a public greeting unless they have parental authority and have considered the lasting risks of a public page. If you believe a child's information was submitted improperly, email us for priority review, access restriction, or removal. An attestation is not a substitute for any stronger consent or verification that applicable law may require.
How Dearly protects information
Dearly uses HTTPS, managed authentication, database Row Level Security, server-side role verification, private storage, short-lived signed media URLs, server-only administrative credentials, hashed invitation, claim, and Cake access secrets, salted or transient IP hashes for rate limiting, and separation between public content and family-sensitive records. Access is limited according to operational need.
No online service can promise absolute security. Keep sign-in links private, sign out on shared devices, avoid placing sensitive information in public greetings, and report a suspected incident promptly to hello@blindspotlab.xyz.
Changes and contact
We may update this policy when Dearly's product, providers, or legal obligations change. The date at the top will change, and we will provide additional notice when a change materially affects how existing personal information is used. Any future paid, merchant, or materially different family feature will receive updated, feature-specific disclosures before it launches.
Questions belong at hello@blindspotlab.xyz. For the rules governing use of Dearly, read our Terms of Use.