What we collect
Account information. Your email address, for signing in and account recovery. Your name, your handle if you pick one, and a profile photo if you add one. Derby signs you in with a code sent to your email, so there is no password to store.
Photos you post. We store them so your friends can see them. Before a photo leaves your phone, Derby removes its metadata, including any GPS location your camera recorded. We don’t analyze your photos for advertising, don’t use facial recognition, and don’t scan them to build a profile of you.
Clips you post. Short videos, up to a minute each, stored so your friends can watch them. The same people who can see your photos can see your clips. Your phone re-encodes each clip at the size Derby plays it before it is sent, and the filter you chose travels with it so your friends’ phones can apply it. We don’t analyze clips for advertising or run facial recognition on them.
Plans. What you put in a plan (title, artwork, time, place, details), who it’s shared with, and your answers to other people’s plans.
Plan chat. Messages and photos you put in a plan’s chat, questions you ask its organizer, and the organizer’s answers. A photo loses its metadata before it leaves your phone, as a posted photo does.
Your friends. Your friendships, friend requests and any note sent with one, your private groups, and the people you’ve muted or blocked.
Hearts. Which photos you’ve hearted. Only the photo’s owner can see that you did.
Reports. When you report a person, a photo, or a message, we receive the reason, anything you write, and who sent it, so a person can act on it. A reported message is copied into the report.
Device tokens. If you allow notifications, a push token for your device, so Firebase Cloud Messaging can deliver them. It is removed when you sign out.
Security logs. Our servers keep a log of sensitive account actions. The account and IP address in each entry are stored as one-way hashes, and entries are deleted after 90 days.
Error reports. When our servers hit an error, they report it to Sentry with your account ID attached, but not your email address or IP address. The app itself contains no analytics or crash-reporting software.
What we don’t collect
- Your location. Derby has no location permission.
- Your contacts or address book. Derby never reads them.
- Data from other apps on your phone
- Your browsing history
- Advertising identifiers. Derby doesn’t track you across apps.
- Biometric data or facial recognition
Who can see what
- Your friends see all the photos you post, including ones from before you became friends. A friendship is mutual.
- You can make a photo or album public. Then anyone signed in to Derby can see it on your profile. It isn’t shown in anyone’s feed or on the web, and only your friends can talk on it. Photos start with friends; you make each one public yourself, and can put it back.
- A photo someone is tagged in can’t be made public, and nobody can be tagged in a public photo except by tagging themselves.
- A friend can ask to share one of your photos with their own friends, or you can offer it to them. It reaches their friends only if you both agree, and either of you can end it later.
- Photos from Fiber that were shared with close friends only stay that way until you open them to all your friends yourself.
- A plan is visible to the people its organizer shared it with. If the organizer allows it, it can also reach friends of people who say they’re Going. Someone who can see a plan keeps it unless the organizer changes who it’s for. Search only finds plans you can already see. Holding a plan’s link grants no access.
- A plan’s chat, photos included, is visible to everyone who can see the plan, for as long as they can see it. A photo you put in a plan’s chat is a copy. Everyone who can see the plan sees it, even if they couldn’t see the photo you posted.
- A question you ask an organizer is visible only to you and the organizer until they answer it. Then everyone who can see the plan sees the question, the answer, and your name.
- Anyone signed in to Derby can find you by name or handle. Someone who isn’t your friend sees your name, handle, profile photo, and the friends you have in common, and any photos you’ve made public. Your other photos and your plans are not part of that.
- Your list of friends is visible only to your friends, and only if you allow it.
- Your private groups, and their names, are visible only to you.
- Blocking someone overrides every rule above.
Derby does not notify anyone when you take a screenshot. A photo you save to your phone, or share out of Derby, is a copy that leaves Derby.
How we use your information
- Run Derby: show your photos and plans to the right people, deliver notifications, and sign you in.
- Communicate with you: send sign-in codes and important messages about your account. No marketing email.
- Prevent abuse: act on reports and enforce our Terms.
- Fix problems: find and fix errors in the service.
We don’t sell your personal information, and we don’t share it for advertising.
Service providers
These companies process information only to operate Derby, on our instructions:
- Supabase: accounts, sign-in, and the database
- Cloudflare: photo storage and delivery, security, and bot protection on sign-in
- Railway: the servers Derby runs on
- Firebase Cloud Messaging (Google): delivering notifications
- Mailgun: account email, such as deletion and export messages
- Sentry: server error reports
We may disclose information when the law requires it. Reports of child sexual abuse material are reported to NCMEC as U.S. law requires; see Child safety.
How we protect your information
Connections to Derby are encrypted. Photos are stored with encryption at rest, and each photo is served only to accounts allowed to see it. Access to our systems is limited to the people who run them.
Data retention
- Account data: kept while your account is active, deleted when you delete your account.
- Photos: kept until you delete them or your account.
- Clips: kept until you delete them or your account, with the still frame that stands in for each one.
- Plan chat and questions: a message and its photo are kept until you delete the message or your account, or the plan’s organizer deletes theirs. Questions are kept until you or the organizer delete your account.
- Security logs: deleted after 90 days.
- Push tokens: removed at sign-out, and after 60 days unused.
- Photo exports: deleted 24 hours after they’re ready.
- Backups: encrypted, kept on a rolling cycle for disaster recovery. Nothing is restored from them to bring back a deleted account.
Deleting your account takes two steps and a 24-hour wait, and then runs on its own. See Delete my account.
Your rights
- Access: ask us for a copy of your data at any time.
- Correction: change your name, handle, and photo in the app.
- Deletion: delete individual photos, or your whole account.
- Portability: export your photos from Settings.
- Clips in your export: each clip is in the same download, as a video file.
- Object: turn off notifications, and mute or block anyone.
Use the controls in the app, or write to privacy@derbysocial.app. We may ask you to confirm you control the account’s email address before we act on a request.
Age requirement
Derby is for adults 18 and older. We don’t knowingly collect information from anyone under 18. If you believe someone under 18 has an account, write to safety@derbysocial.app and we’ll remove it promptly.
International users
Derby is operated from the United States. If you use Derby from outside the U.S., your information is transferred to, stored, and processed in the U.S., where data protection laws may differ from those in your country.
For users in the European Economic Area and UK
We process your data on these legal grounds:
- Contract: processing needed to provide the Derby service you asked for
- Legitimate interests: security, fraud prevention, and fixing the service
- Consent: where you’ve given it, such as for notifications
You have the right to access, rectify, erase, restrict processing of, and port your data, and to object to processing. Write to privacy@derbysocial.app.
For California residents
Under the California Consumer Privacy Act, you have the right to:
- Know what personal information we collect and how it’s used
- Request deletion of your personal information
- Opt out of the sale of personal information. We don’t sell personal information.
- Non-discrimination for exercising your rights
Write to privacy@derbysocial.app or use account deletion in the app.
Coming from Fiber
Derby is the app that was called Fiber, redesigned and renamed, on the same account. This policy replaces Fiber’s. Derby collects less than Fiber did: no location, no direct messages, and no analytics in the app.
Business transfers
If Fiber, Inc. is acquired, merges with another company, or sells substantially all its assets, your information may be transferred. We will notify you before your information becomes subject to a different privacy policy and give you the opportunity to delete your account.
Changes to this policy
If we make material changes to how we handle your data, we’ll tell you in the app and by email before they take effect, and update the date at the top of this page. We’ll never retroactively change our commitments in ways that reduce your privacy.
Contact us
Privacy requests: privacy@derbysocial.app
General questions: support@derbysocial.app
Safety concerns: safety@derbysocial.app
Mailing address: Fiber, Inc., Philadelphia, PA 19125, United States