Last updated: August 27, 2026
This Privacy Policy explains how On That Day ("On That Day", "we", "us"), provided by Mehmet Ali Çopurlar, handles information when you use the On That Day mobile app (the "App"). If you have questions, contact us at support@onthatday.co.
On That Day is a private time-capsule app. Your capsule content — photos, videos, voice notes, and text — is end-to-end encrypted on your device before it ever leaves it. We cannot read it, and neither can anyone except the people you share a capsule with. We keep the minimum account and technical information needed to run the service, and you can delete your account from inside the App at any time — choosing what happens to the memories you've shared with others.
Account information - Email address — required to create an account and to send sign-in codes. - Display name — optional, shown to other members of your capsules. - Sign-in identifiers — depending on how you sign in: an Apple or Google account identifier (we receive a stable ID and, if you allow it, your email), or a passkey/public key. We store a cryptographic public key that represents your identity. - Optional profile details you choose to add (e.g. a profile photo, a date).
Your content (end-to-end encrypted) - Photos, videos, voice notes, text, captions, and any location you attach to a memory are encrypted on your device and uploaded only as ciphertext. We store and transmit this content in encrypted form and cannot decrypt or view it. The encryption keys are derived on your device and are protected by your recovery passphrase and/or device keychain. - When you choose a photo or video from your library, the App reads the date and location recorded inside that file (its EXIF or container metadata) on your device, to suggest the memory's date and place. You can change or remove both before posting. Whatever you keep is encrypted with the memory like any other content; we never see it.
Photos and videos on Android - The first time you upload from your library, the Android App asks for permission to access your photos and videos. It uses that access for one thing: reading the items you chose — including the date and location stored inside them — because the Android photo picker hands the App a copy with the location removed. The App does not scan, index, or upload your library, and it does not read anything you did not pick. - You can decline. You can still pick photos and videos through the system picker; the only difference is that the memory's location is not filled in for you.
Technical & usage information - Device push-notification tokens (if you enable notifications) — issued by Apple on iPhone and iPad, by Google on Android — IP address, and standard server logs (timestamps, request metadata, error diagnostics), used to operate and secure the service. - Limited capsule metadata that is necessarily visible to run the service: who is a member of a capsule, a memory's media type and timestamps, storage sizes, and reveal dates. This metadata does not include the content itself.
Diagnostics (error reports)
- When something goes wrong in the App — a request fails, a response can't be
read — we record a small error report: which API route failed, the HTTP
status code, the kind of error, your app version, your operating system
and its version (iOS or Android), device model (e.g. iPhone14,3,
Pixel 8), and language.
- These reports are not linked to your account. They carry a random
identifier generated on your device, which is not your user ID and cannot be
used to look you up.
- They never include your capsules, memories, photos, videos, voice notes,
text, or any account details.
- Error reports go to our own servers. We do not use a third-party
analytics or crash-reporting service, so no outside company receives them.
- They are deleted after 90 days.
Abuse reports - If you report a memory, we store report metadata — who reported it, which memory, the reason, and any note you add. Consistent with our encryption model, a report does not include the content.
We do not collect data for advertising, and we do not sell your personal information.
On That Day shares your encrypted content only with the people you invite to a capsule (co-owners, contributors, recipients) and only according to the capsule's rules (for example, a capsule opens to its recipients when it is revealed). We do not otherwise share content with anyone.
We use a small number of processors to run the App. They process data on our behalf under their own terms:
Content sent to storage is end-to-end encrypted; providers receive ciphertext.
We deliberately use no third-party analytics, advertising, or crash-reporting SDKs. Diagnostics described above are processed only by us, on the infrastructure listed here.
Content is protected with end-to-end encryption. Account recovery relies on a passphrase you control; if you lose it and your device access, encrypted content may be permanently unrecoverable — by design, we cannot recover it for you.
Android has no equivalent of iCloud Keychain, so a user who loses their phone without their recovery passphrase has lost every capsule permanently. To avoid that, the Android App includes one file in Android Backup: your six-word recovery passphrase. If you have Android Backup switched on, that file is copied to your Google Drive, encrypted, under your own Google account. It lets a new phone pre-fill the passphrase instead of asking you to type it.
Nothing else is included. Your encryption private key, your sign-in tokens and your cached content are written to storage that Android Backup cannot reach, and the App declines to back up at all on Android versions older than 9.0, which have no client-side backup encryption.
The passphrase on its own opens nothing: it is useless without also signing in to your account. So what may reach Google Drive is strictly less than what iCloud Keychain already syncs for iPhone users, which is the key itself.
Depending on where you live, you may have rights to access, correct, or delete your personal information, or to object to or restrict certain processing. You can delete your account and content in-app at any time; for other requests, contact us at support@onthatday.co and we will respond as required by applicable law (including the GDPR and CCPA/CPRA where they apply).
On That Day is not directed to children under 13 (or the minimum age required in your country), and we do not knowingly collect personal information from them. A capsule may be about a child, but the account holders and contributors are adults or teens who meet our minimum age. If you believe a child has provided us information, contact support@onthatday.co and we will delete it.
We act on abuse reports (which we assess from metadata and signals, not by viewing content) and may remove reported items and suspend accounts. Where a report indicates illegal content such as child sexual abuse material, we will report it to the relevant authorities (e.g., NCMEC) as required by law, independent of our encryption model. We may disclose information when required by valid legal process.
We may process and store information in countries other than yours, including the United States. Where required, we rely on appropriate safeguards for such transfers.
We may update this Policy from time to time. We will post the updated version with a new "Last updated" date and, for material changes, provide additional notice where appropriate.
Mehmet Ali Çopurlar support@onthatday.co