Dear Tomorrow
    How it worksPricingFor organisationsContactLog in
    Start free
    How it worksPricingFor organisationsContactLog in
    Start free

    Privacy Policy

    Published: 30 July 2026 · Version 1.0

    Dear Tomorrow is a platform that lets you record voice, video, and written messages for delivery to people you love — at a future date you choose. The messages you create may include some of the most personal moments of your life. We take that responsibility seriously.

    This Privacy Policy explains what personal data we collect, why we collect it, how we protect it, how long we keep it, and the rights you have over it. It applies to everyone who uses Dear Tomorrow — whether you are a sender, a recipient, or a person nominated to receive a message after the sender's passing. Because Dear Tomorrow may involve future delivery, nominated recipients, account verification, and highly personal message content, this policy also explains how we handle sensitive or private content, delivery instructions, account controls, and posthumous message-delivery processes.

    Dear Tomorrow is operated by Dear Tomorrow FZE LLC, With License #4430608.01, with its registered address at Business Center, Sharjah Publishing City Free Zone, Sharjah, United Arab Emirates. For the purposes of UAE data protection law, Dear Tomorrow acts as a “Controller” where it decides how and why your personal data is processed. For users in India, Dear Tomorrow acts as a “Data Fiduciary” where it determines the purpose and means of processing digital personal data.

    We have written this policy in plain language. Where legal terms are necessary, we explain what they mean. If anything is unclear, please contact us at the address in Section 14 or by email at [email protected]

    This Privacy Policy is intended to reflect the requirements of UAE Federal Decree-Law No. 45 of 2021 Concerning the Protection of Personal Data (the “UAE PDPL”), together with any applicable implementing regulations, Cabinet decisions and regulatory guidance issued under it and in force from time to time.

    This Privacy Policy should be read together with our Terms of Service, any consent forms or delivery instructions you provide, and any additional privacy notices shown to you when you use specific features of Dear Tomorrow.

    1. Introduction

    Dear Tomorrow is a platform that lets you record voice, video, and written messages for delivery to people you love — at a future date you choose. The messages you create may include some of the most personal moments of your life. We take that responsibility seriously.

    This Privacy Policy explains what personal data we collect, why we collect it, how we protect it, how long we keep it, and the rights you have over it. It applies to everyone who uses Dear Tomorrow — whether you are a sender, a recipient, or a person nominated to receive a message after the sender's passing. Because Dear Tomorrow may involve future delivery, nominated recipients, account verification, and highly personal message content, this policy also explains how we handle sensitive or private content, delivery instructions, account controls, and posthumous message-delivery processes.

    Dear Tomorrow is operated by Dear Tomorrow FZE LLC, With License #4430608.01, with its registered address at Business Center, Sharjah Publishing City Free Zone, Sharjah, United Arab Emirates. For the purposes of UAE data protection law, Dear Tomorrow acts as a “Controller” where it decides how and why your personal data is processed. For users in India, Dear Tomorrow acts as a “Data Fiduciary” where it determines the purpose and means of processing digital personal data.

    We have written this policy in plain language. Where legal terms are necessary, we explain what they mean. If anything is unclear, please contact us at the address in Section 14 or by email at [email protected]

    This Privacy Policy is intended to reflect the requirements of UAE Federal Decree-Law No. 45 of 2021 Concerning the Protection of Personal Data (the “UAE PDPL”), together with any applicable implementing regulations, Cabinet decisions and regulatory guidance issued under it and in force from time to time.

    This Privacy Policy should be read together with our Terms of Service, any consent forms or delivery instructions you provide, and any additional privacy notices shown to you when you use specific features of Dear Tomorrow.

    2. Who We Are — Data Controller

    For UAE PDPL and the India DPDP Act, the data controller (the entity responsible for your personal data) is:

    • Company name: Dear Tomorrow FZE LLC
    • Registered address: Business Centre, Sharjah Publishing City Free Zone, Sharjah, United Arab Emirates
    • Trade license: 4430608.01
    • Website: https://deartomorrow.ai
    • Privacy contact (PDPL contact person): [email protected]
    • General support: [email protected]
    • Data breach reports: [email protected]

    Privacy Contact

    For privacy questions, requests or complaints, please contact us at — [email protected]

    Dear Tomorrow determines the purposes and means of collecting, using, storing, securing, disclosing, retaining, and deleting personal data processed through the platform. Where Dear Tomorrow engages third-party service providers to host data, deliver messages, process payments, provide authentication, analytics, communications, support, or security services, such third parties act as processors or service providers on Dear Tomorrow's behalf, unless otherwise stated.

    3. Who This Policy Applies To

    This policy applies to the following categories of users:

    User typeDescription
    SendersPeople who create a Dear Tomorrow account and record messages for future delivery. Senders are responsible for ensuring that they have the lawful right, consent, authority, or other valid basis to provide any personal data, contact details, images, voice recordings, video recordings, written content, or information relating to other individuals through the platform.
    RecipientsPeople who receive a message that has been delivered to them through Dear Tomorrow. Recipients do not need a Dear Tomorrow account — they receive messages via a secure, OTP-protected link. Recipients' personal data may be processed for identity verification, secure delivery, access control, audit logging, fraud prevention, support, and compliance purposes.
    ConfirmersPeople nominated by a sender (on eligible plan) to confirm receipt of a critical event before message delivery is triggered. Confirmers' personal data may be processed for nomination, authentication, communication, event-confirmation, fraud-prevention, and record-keeping purposes. Confirmers must not provide false, misleading, or unauthorized confirmations.
    NomineesOn eligible plans only, a person designated by a sender to access the message vault after the sender's death, subject to verification of a death certificate. Nominees may be required to verify their identity, authority, relationship to the sender, and supporting documentation before access is granted. Access by a nominee remains subject to the sender's instructions, Dear Tomorrow's verification procedures, applicable law, and the rights of any living individuals whose personal data appears in the message vault.
    Emergency contactsPeople nominated by a sender to be notified if the sender's account becomes inactive, so they can prompt the sender to renew or recover access. Emergency contacts' personal data may be processed only for account-inactivity, renewal, recovery, safety, verification, and related communication purposes, unless otherwise notified.
    Institutional partnersHospitals, palliative clinics, IVF centers, and other institutions that refer patients to Dear Tomorrow under a partnership agreement. Institutional partners may act as independent controllers/data fiduciaries in respect of personal data they collect for their own purposes. Where they provide personal data to Dear Tomorrow or refer individuals to the platform, they are responsible for ensuring that they have obtained all required notices, consents, permissions, and lawful authority to do so. Dear Tomorrow's processing of such data will be governed by this Privacy Policy and the relevant partnership agreement.
    VisitorsPeople who visit our website without creating an account. Visitors' personal data may be processed through cookies, analytics tools, security logs, device identifiers, enquiry forms, or similar technologies, as further described in this Privacy Policy and any applicable cookie notice.

    This policy may also apply to family members, beneficiaries, guardians, legal representatives, estate representatives, next of kin, or other individuals whose personal data is included in messages, contact details, verification documents, delivery instructions, support communications, or account records.

    Where the platform is used in connection with minors or legally incapacitated persons, Dear Tomorrow may require consent or authorization from a parent, legal guardian, or other authorized representative, where required by applicable law.

    This policy does not apply to third-party websites, applications, institutions, payment providers, healthcare providers, or external services that are not owned or controlled by Dear Tomorrow, except where they process personal data on Dear Tomorrow's behalf as processors or service providers.

    4. What Personal Data We Collect

    We only collect data that is necessary for the service to function, for legal compliance, or for the security of your account. We process personal data in accordance with the principles of lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, confidentiality, integrity, and accountability, to the extent required under applicable law. We do not sell your data, and we do not use your messages or recordings for any purpose other than delivering them as you instructed. This does not prevent Dear Tomorrow from processing such data where necessary to host, store, secure, back up, transmit, verify access to, recover, delete, or comply with lawful requests relating to your messages or account. We do not sell your data, and we do not use your messages or recordings for any purpose other than delivering them as you instructed.

    4.1 Account information

    We collect account and profile information, such as your name, display name, email address, phone number, login credentials, country or region, account identifiers, subscription and account status, privacy and communication preferences, records of your acceptance of our legal terms, account activity, and billing or transaction references.

    We use this information to create and administer your Account, authenticate and secure access, manage subscriptions and payments, communicate with you about the Services, provide support, prevent fraud and misuse, maintain compliance records, and fulfil applicable legal and regulatory requirements.

    Where you use features, we may also collect information reasonably necessary to verify Nominees, Confirmers, Emergency Contacts, Recipients, identity, death, authority or eligibility.

    4.2 Message, Recipient and Appointed-Contact Information

    When you create, store, schedule or deliver a Message, we may collect and process:

    • the Message content, including written, audio and video content;
    • Message titles, tags and other metadata, such as Message type, format, file size, recording duration, creation date and time, scheduled delivery date and time, delivery status, access status and any optional notes or instructions;
    • Recipient details, such as name, email address, phone number, relationship to you, delivery information and verification status;
    • details relating to Confirmers, Nominees and Emergency Contacts, such as their name, email address, phone number, relationship to you, appointed role, relevant event or access conditions, confirmation status and verification information; and
    • technical and activity records relating to the creation, storage, access, confirmation, scheduling and delivery of Messages.

    We use this information to create, organize, display, store and deliver Messages; provide the features you select; verify Recipients and appointed persons; confirm relevant events; personalize and improve the Services; prevent fraud, misuse and misdelivery; maintain security and service records; provide support; and comply with applicable law.

    Message titles or recipients' details are processed by Dear Tomorrow's systems and are visible to the intended confirmers or recipients when the relevant Message is delivered or accessed. We may use Message titles, tags and other metadata to organize, personalize and improve the Services and may use aggregated or anonymized information for service analytics.

    Dear Tomorrow does not use the underlying Message content for advertising, marketing profiling, resale, unrelated analytics or training unrelated AI models. Staff do not routinely access Message content, although limited access may occur in the exceptional circumstances described in this Privacy Policy and our Acceptable Use Policy.

    Your message content is encrypted at rest using AES-256 and in transit using TLS 1.2 or higher (TLS 1.3 supported). Encryption keys are managed by AWS. Passwords are stored as a salted hash and never in readable form. Access to message content, encryption keys, and related systems is restricted on a least-privilege basis and subject to appropriate access controls, confidentiality obligations, audit logs, and security procedures. Message content is not accessible to staff for routine operations. Dear Tomorrow does not use message content for advertising, profiling, resale, training unrelated AI models, or any purpose unrelated to providing, securing, maintaining, or enforcing the service. Automated systems may scan content for the limited purpose of detecting prohibited material as described in our Acceptable Use Policy. Such scanning is limited to platform safety, abuse prevention, legal compliance, fraud prevention, security monitoring, and enforcement of the Terms of Service and Acceptable Use Policy. Where scanning flags content for review, access is limited to authorized personnel under audited and logged conditions. Any human review will be limited to what is reasonably necessary to assess the flagged issue, protect users or third parties, comply with applicable law, respond to lawful requests, or enforce Dear Tomorrow's legal rights and platform rules. Personnel with access to flagged content are bound by confidentiality and access-control obligations.

    4.3 Recipient and contact information

    • Recipient names and email addresses or phone numbers (only the contact details necessary to deliver the message) and to verify access, send secure delivery links or OTPs, maintain delivery logs, prevent misuse, and provide support in relation to the relevant message.
    • Confirmer details — name, email, phone, and relationship to you for appointment, communication, authentication, event confirmation, fraud prevention, audit logging, and delivery-trigger verification.
    • Nominee details — name, email, phone, government ID reference for verification (eligible plans only) and any supporting verification information strictly necessary to confirm identity, authority, death-certificate validity, and access entitlement. Dear Tomorrow will not collect or retain copies of government IDs or death certificates unless required for verification, legal compliance, dispute handling, fraud prevention, or audit purposes.
    • Emergency contact details — name and email (optional, all plans) for account-inactivity notices, renewal prompts, account-recovery assistance, and related service communications only.

    When you provide a third party's contact details (recipient, confirmer, nominee, emergency contact), you confirm that you have a reasonable basis to do so — for example, an existing personal relationship. You also confirm that, where required by applicable law, you have obtained any necessary consent, authority, or permission to provide their personal data to Dear Tomorrow and to nominate them for the relevant role. We will only contact those individuals as needed to perform the service you have requested. We will not use their contact details for unrelated marketing, profiling, sale, or disclosure, and they may contact us to exercise any rights available to them under applicable data protection laws.

    You are responsible for keeping recipient, confirmer, nominee, and emergency-contact details accurate and up to date. Dear Tomorrow is not responsible for failed, delayed, or misdirected delivery where incorrect, outdated, unauthorized, or incomplete contact information is provided.

    4.4 Payment information

    • Card details are processed directly by our third-party payment service providers

    We do not store full card numbers on our servers. Payment information is processed for the purposes of payment authorization, subscription activation, renewal, refunds, failed-payment handling, fraud prevention, chargeback management, accounting, reconciliation, and legal/tax compliance. Dear Tomorrow may receive limited payment tokens, payment status, and transaction confirmation information from its payment partners, but does not store CVV/CVC codes or full card numbers.

    • We retain transaction IDs, the last 4 digits of your card, card brand, expiry month/year, and billing country for your subscription records and tax compliance. We may also retain invoice records, payment status, refund records, chargeback records, payment method reference IDs, subscription history, renewal history, billing email, billing address where provided, tax identifiers where legally required, and payment-related support communications.
    • For users billed in AED, we retain your VAT applicability status as required by UAE tax law. For users billed in India or other jurisdictions, we may retain tax, invoicing, and billing information to the extent required under applicable law.
    • Payment partners may process your payment information in accordance with their own terms, privacy notices, security standards, and regulatory obligations. Dear Tomorrow uses such payment partners to process payments securely and does not sell payment information or use it for unrelated marketing, profiling, or resale.

    Payment and billing records may be retained for as long as reasonably necessary to provide the service, manage subscriptions, comply with accounting, tax, audit, anti-fraud, and legal obligations, resolve disputes, and enforce our Terms of Service.

    4.5 Technical and usage data

    When you access or use Dear Tomorrow, we may automatically collect limited technical, device, log, and usage information necessary to operate, secure, maintain, troubleshoot, analyze, and improve the platform.

    • IP address (for security monitoring, fraud prevention, and to determine your country) including approximate location derived from your IP address, but not precise GPS location unless separately requested and permitted by applicable law.
    • Device type, browser type, operating system device identifiers, session identifiers, language settings, time zone, referring URLs, network information, crash logs, error logs, authentication logs, and security-event logs.
    • Pages visited, features used, and time spent on the platform (to improve the service) including usage patterns, performance data, access times, feature interactions, delivery-status activity, support interactions, and diagnostic information, where necessary for service functionality, analytics, troubleshooting, security, fraud prevention, and product improvement.
    • Cookies and similar tracking technologies (see our separate Cookie Policy) which may include strictly necessary cookies, security cookies, preference cookies, analytics cookies, and other similar technologies. Where required by applicable law, non-essential cookies will be used only with appropriate notice and consent, and users may manage their cookie preferences through the available cookie controls.
    • We do not use technical and usage data to read or infer the substance of your private message content, and we do not sell such data or use it for unrelated advertising, profiling, or resale.
    • Technical and usage data may be processed by Dear Tomorrow and its authorized service providers, including hosting, analytics, security, monitoring, authentication, and infrastructure providers, only for the purposes described in this Privacy Policy and subject to appropriate confidentiality, security, and data-processing obligations.

    4.6 Partner referral data

    • If you sign up through a Dear Tomorrow partner using a referral code or QR code, we may record the associated partner code to identify the source of your registration, administer our partnership arrangements, maintain related records, and prevent misuse.
    • We never share your identity with the partner unless you have expressly authorized us to do so, or unless disclosure is required by applicable law, regulation, court order, or competent authority request. Partners receive only aggregate, non-identifying information about referrals such as total referral numbers, general usage trends, or non-identifiable conversion data, and such information will not include your name, contact details, account details, message content, health information, recipient details, nominee details, or any information that could reasonably identify you.

    Partners are not permitted to use aggregate referral information to identify, contact, profile, target, or make decisions about any individual user, recipient, nominee, confirmer, or emergency contact. Where referral information is shared with a partner, Dear Tomorrow will take reasonable steps to ensure that the information is aggregated, anonymized, or de-identified and subject to appropriate contractual confidentiality and data-use restrictions.

    4.7 Sensitive personal data — health context

    Dear Tomorrow is often used by people facing serious illness, palliative care, or end-of-life moments. We do not ask you to disclose health information, and we do not collect health records. However, the context in which you use Dear Tomorrow may itself be sensitive — for example, signing up via a palliative care clinic. Under the UAE PDPL definition of sensitive personal data, and subject to the processing controls under PDPL Article 5, sensitive personal data includes health-related information. We treat the fact of partner referral and any voluntarily disclosed health context with the same encryption and access controls as message content. We do not share or sell this information. Access to such information is restricted on a need-to-know basis and used only for service delivery, account administration, security, support, legal compliance, and partnership attribution in non-identifying form. We do not share or sell this information except where you have expressly authorized us to do so, or where disclosure is required by applicable law, regulation, court order, competent authority request, or necessary to protect the rights, safety, or security of users, recipients, Dear Tomorrow, or others.

    5. Why We Collect Your Data — Lawful Basis

    Under UAE PDPL Article 4, we may only process your personal data if we have a lawful basis to do so. We rely on the following:

    Lawful basisWhen we use it
    Performance of a contractTo provide the Dear Tomorrow service you signed up for — creating your account, storing your messages, scheduling delivery, processing payments.
    Your explicit consentFor optional features such as marketing communications, sharing your story for case studies, and any processing of sensitive personal data.
    Legitimate interestFor security monitoring, fraud prevention, service improvements, and aggregated analytics — provided your rights and freedoms are not overridden.
    Legal obligationTo comply with UAE tax law, anti-money laundering rules, court orders, and lawful requests from authorities.
    Vital interestsIn rare cases, where Dear Tomorrow becomes aware through a Recipient report, a report submitted through our support or abuse channels, or a lawful request from a competent authority of a credible threat to a person's life or serious physical safety, we may process or disclose the limited information reasonably necessary to assess or respond to that risk. Dear Tomorrow does not proactively monitor Message content for this purpose.

    You can withdraw consent at any time for any processing that relies on consent — see Section 9 (Your Rights). Withdrawing consent does not affect processing carried out before withdrawal.

    5.6 Marketing and product improvement

    We may use anonymized and aggregated usage data to improve our service. Such data will be processed in a manner that does not directly identify you and will not be used by Dear Tomorrow to re-identify any individual user, recipient, nominee, confirmer, emergency contact, or visitor. We may also send marketing communications (such as product updates, renewal reminders, and feature announcements) only to subscribers who have explicitly opted in at signup or via account settings. Where required by applicable law, we will keep records of marketing consent and will not send direct marketing without a valid consent or other lawful basis. For clarity, account-related, security, billing, payment, subscription-renewal, service, legal, and transactional notices are not treated as marketing communications and may still be sent where necessary to provide or administer the service. You can unsubscribe from marketing communications at any time without affecting your account or your access to the service. Withdrawal of marketing consent will not affect the lawfulness of any processing carried out before withdrawal. We never use the content of your messages for marketing, product analysis, model training, or any purpose other than delivering them as you instructed.

    6. How Long We Keep Your Data

    Under PDPL Article 4(6), we cannot keep your data longer than necessary. Our retention practices are tied to your subscription plan and the data category.

    6.1 Active subscriptions

    While your Subscription is active, we retain your Account information, Messages and Recipient details as necessary to provide the Services. You may delete any individual Message, Recipient details or your entire Account at any time, regardless of your Subscription status. Deleting your entire Account will end your access to the Services and cancel future renewals but will not automatically entitle you to a refund. We may retain limited records, such as transaction, tax, security and legal-compliance records, after deletion where required or permitted by applicable law.

    6.2 Cold storage and lapsed subscriptions

    When your subscription lapses (you do not renew before the renewal date), your messages move into encrypted cold storage on the same day. Cold storage protects your data while preventing further charges. You can renew at any time during the cold storage period, and your messages will be restored within a few hours. During cold storage you can download your messages from within the product basis your plan limits, and you retain your right under UAE PDPL to request a copy of your personal data at any time by emailing us at least 30 days before expiring of the cold storage period at [email protected], during the cold storage period. We will respond within 30 days.

    After the cold storage period ends, your messages are permanently deleted. You will receive renewal reminders before your subscription expires, and additional reminders before any data is permanently deleted.

    PlanCold storage entryPermanent deletion
    First Words (free)Day 0 (expiry)Day 30 after lapse
    CompanionDay 0 (expiry)Day 90 after lapse
    LegacyDay 0 (expiry)Day 180 after lapse
    EvergreenDay 0 (expiry)Day 365 after lapse

    Once data is permanently deleted, it cannot be recovered. We will send you reminders before this point. After deletion, only minimal records (such as transaction history for tax compliance and your email address for our suppression list) are retained — never your message content, recipient details, or the messages themselves.

    6.3 Data we are required to retain after deletion

    • Transaction and invoice records — retained for 5 years to comply with UAE Federal Tax Authority requirements.
    • Audit logs of admin actions — retained for 2 years for security and dispute resolution purposes.
    • Email suppression list (your email if you have unsubscribed) — retained indefinitely so we can honor your unsubscribe choice. Other account-level information you provided at signup (such as name and country) may be retained where you have consented to receive marketing communications or where retention is necessary for our legitimate business records, customer support, or fraud prevention purposes.
    • Limited account closure records — retained for 1 year to prevent abuse (e.g. a closed account being recreated to evade enforcement).

    6.4 Special case — messages stored for delivery after the sender's death

    On the eligible plan, you may nominate a person to access your message vault after your passing. If your subscription lapses, your data is held in cold storage as per your plan limit. During the applicable cold-storage period, your Nominee can request access through the verification process in Section 11. After the applicable cold-storage period from lapse, all data is permanently deleted regardless of any pending nominee request.

    7. How We Protect Your Data

    We implement appropriate technical and organizational measures to protect Personal Data, taking account of the nature, sensitivity, volume and risks of the processing. These measures may include encryption, pseudonymization, masking or tokenization, access controls, authentication, monitoring, logging, backups, recovery procedures and regular security reviews.

    7.1 Encryption and Security Control

    We use appropriate industry-standard encryption and security measures to protect Message content and Personal Data while stored and transmitted.

    Sensitive information may be protected through additional application-level or field-level encryption.

    Encryption keys and administrative access are protected through restricted access, authentication, monitoring and audit controls.

    We review and update our security measures from time to time, taking account of changes in technology, identified risks and applicable legal requirements.

    7.2 Access controls

    • Dear Tomorrow employees cannot access message content for routine operations. Message content may be processed by automated systems for the limited purpose of detecting prohibited material (as described in our Acceptable Use Policy), and may be accessed by a limited number of authorized personnel only where automated scanning has flagged content for review, where required by law, or in the case of a critical security incident or data recovery operation. All such access is logged in an audit trail.

    Administrative access to Personal Data is limited to authorized personnel and protected through appropriate authentication, access controls, confidentiality obligations, monitoring and audit measures.

    Security and access records are retained for as long as reasonably necessary for security, investigation, legal and compliance purposes, in accordance with our internal retention procedures.

    7.3 Secure delivery to recipients

    • When a message is delivered to a recipient, they receive a unique, time-limited link.
    • To open the message, the recipient must enter a one-time password (OTP) sent to the email or phone number you provided.
    • OTPs are 6-digit, single-use, and expire after 5 minutes. After 3 incorrect attempts, the OTP is invalidated. After 5 total failed attempts, the link is locked for 24 hours, and you (the sender) are notified.
    • The recipient session ends after 15 minutes of inactivity or 60 minutes total, whichever comes first.

    8. Who We Share Your Data With

    We never sell your personal data. We share it only with the parties listed below, only for the purposes described, and only under contractual arrangements that protect your data.

    Recipient categoryPurposeLocation
    Cloud-hosting, database, storage and key-management providersHosting, storage, backup, database and encryption servicesUAE and other countries worldwide
    Payment service providersPayment processing, billing, refunds, fraud prevention and chargeback managementUAE and other countries worldwide
    Email, message and communication providersTransactional communications, OTPs and service notificationsUAE and other countries worldwide
    Security, monitoring and analytics providersSecurity monitoring, error detection, service performance and analyticsUAE and other countries worldwide
    Courts, regulators and competent authoritiesCompliance with applicable law, legal process or binding requestsRelevant jurisdiction

    Our providers, sub-processors and processing locations may change from time to time. Where Personal Data is processed outside your country, we will use a transfer mechanism permitted by applicable law and apply appropriate data-protection and security safeguards.

    Product Improvement and Marketing

    We may use Account information, Subscription information, service-usage data and Message metadata — such as titles, tags, Message type, dates, delivery status and feature interactions — to operate, personalize, analyze and improve the Services, test new features, prevent misuse and understand Service performance. Where reasonably practicable, we use aggregated or anonymized information for these purposes.

    We do not use the underlying written, audio or video content of your Messages for marketing, advertising, profiling or unrelated product analytics. Message titles, tags, Recipient details, Nominee details and Confirmer details are not used for direct marketing or advertising.

    Where you have opted in, we may use your contact information, marketing preferences, Subscription information and interactions with our communications to send and measure promotional emails, messages or other marketing communications. You may withdraw your consent or unsubscribe at any time without affecting your use of the core Services.

    Where a service provider processes Personal Data on our behalf, we require it to be subject to appropriate written contractual, confidentiality, security and data-protection obligations, whether under a separate data-processing agreement or terms incorporated into the provider's service agreement. We take proportionate steps to assess material service providers and, where relevant, review their security, breach-notification, sub processor, retention, deletion and international-transfer arrangements. Some service providers, including payment providers, may process certain Personal Data for their own legal, regulatory, fraud-prevention or operational purposes and may act as independent controllers in respect of that processing. We do not authorize service providers to use Personal Data for unrelated marketing, profiling or commercial purposes.

    9. Your Rights Under UAE PDPL

    Under UAE PDPL Articles 13–18, you have the following rights over your personal data. These rights are exercisable by emailing [email protected]. We will respond within 30 days.

    RightWhat it meansHow to exercise
    Right of accessReceive a copy of the personal data we hold about you.Export or Email request
    Right of correctionCorrect any data we hold that is inaccurate or incomplete.Update from your account settings or email us.
    Right of deletionRequest deletion of your data (subject to legal retention requirements in Section 6.3).Account settings → Delete account or email us.
    Right of portabilityReceive your data in a structured, machine-readable format (JSON or ZIP).Account settings → Export, or email request.
    Right to restrict processingAsk us to pause processing your data while a dispute is resolved.Email request — processing pauses immediately.
    Right to objectObject to specific processing where we rely on legitimate interest.Email request — we will assess and respond.
    Right to withdraw consentWithdraw consent for any processing based on consent.Browser settings, unsubscribe links, or email.
    Right to lodge a complaintComplain to the UAE Data Office if you believe we have violated PDPL.UAE Data Office — see Section 14.

    For individuals in India, and where the Digital Personal Data Protection Act, 2023 applies and the relevant provisions are in force, you may have rights to access information about your Personal Data, request its correction, completion, updating or erasure, seek grievance redressal, and nominate another person to exercise your rights in the event of your death or incapacity.

    You may exercise these rights through the same request process described above, subject to applicable legal requirements and exceptions.

    9.1 Automated decision-making and human review

    We use limited automated processing to keep the service secure and to enforce our Acceptable Use Policy — for example, fraud- and abuse-detection signals and automated scanning that flags potentially prohibited content. We do not make decisions that produce legal effects concerning you, or similarly significant effects, based solely on automated processing without human involvement. Where automated scanning flags content, the material is reviewed by authorized personnel before any enforcement decision is taken, and material actions on your account (such as suspension or termination) involve human review.

    Where a decision about you is supported by automated processing, you have the right to obtain human review of it, to express your point of view, and to contest the decision, by emailing [email protected]. We will investigate your request and respond within 30 days.

    9.2 Exercising your rights and making a complaint

    You can exercise any of the rights described in this Section by contacting us at [email protected]. To protect your data, we may need to verify your identity before we act on a request, and we may ask for enough information to locate the data and confirm who you are. We will respond to requests within the period required by applicable law (and, in any event, aim to respond within 30 days), and we will let you know if we need more time because a request is complex. We do not charge a fee to handle a request unless the law permits it — for example, where a request is manifestly unfounded or excessive — in which case we will tell you before proceeding.

    10. Cross-Border Data Transfers

    Your data is hosted with reputable cloud infrastructure providers. Where data is processed outside your country, we apply the safeguards required by applicable data-protection law. Certain operations may involve data transfers — for example, payment processing through our payment gateway, email delivery through our email provider, or service operations involving our India team.

    Under PDPL Article 22, cross-border transfers are permitted only where the destination country provides adequate protection or where appropriate safeguards are in place. We rely on the following:

    • Standard Contractual Clauses (SCCs) or PDPL-equivalent contractual safeguards with all overseas processors.
    • Transfers to India are governed by both PDPL and DPDP Act 2023 — both regimes are functionally aligned on core data protection principles.
    • No transfers to jurisdictions without adequate protection or safeguards.

    11. Post-Death Access (Eligible Plans Only)

    If you have an eligible subscription and you have nominated a person to access your message vault after your death, the following process applies. This is critical to understand and is unique to Dear Tomorrow.

    11.1 How nominee access works

    • You nominate one person (the “Nominee”) at any time during an active eligible subscription, providing their name, email, and a government ID reference for verification.
    • After your death, the Nominee must contact Dear Tomorrow at [email protected] with a certified copy of the death certificate.
    • We verify the death certificate against publicly available records where possible and the ID information you provided. This process takes 3 to 5 business days.
    • The Nominee may request access at any time during the applicable cold-storage period. Once the Nominee has been successfully verified, Dear Tomorrow will issue a secure download link that remains valid for seven (7) days.
    • If the link expires before the Nominee completes the download, the Nominee may request a replacement link, provided the request is made and verification can be completed before the applicable cold-storage period expires.
    • A request for access or a replacement link does not pause or extend the retention period. At the end of the applicable cold-storage period, the data will be permanently deleted, unless applicable law requires otherwise.
    • The Nominee cannot create new messages, modify existing messages, or extend the access window in the service.

    11.2 What we do if the death certificate cannot be verified

    • We will request additional documentation — for example, a notarized statement from a family member or legal representative.
    • If verification fails, the Nominee's access request is denied, and your data remains in cold storage until permanent deletion under Section 6.
    • False or fraudulent death certificate submissions are reported to the authorities.

    11.3 Right to override

    You may change or remove your Nominee, or disable post-death access, at any time during your active Subscription through your Account settings or by submitting a verified request to Dear Tomorrow through the contact details stated in this Policy.

    Dear Tomorrow will honor the most recent valid instruction recorded in your Account or confirmed by us in writing.

    12. Data Breach Notification

    In the event of a personal data breach affecting your data, we will notify the UAE Data Office within 72 hours of becoming aware of it, as required by PDPL Article 9.

    Where the breach is likely to result in a high risk to you personally, we will also notify you directly without undue delay.

    • A description of the nature of the breach.
    • The categories and approximate number of users affected.
    • The likely consequences of the breach.
    • The measures we have taken or propose to take to address it and limit harm.
    • Contact information for follow-up questions.

    13. Children and Minors

    Dear Tomorrow is not intended for use by anyone under the age of 18. We do not knowingly collect personal data from children. If you become aware that a child has created an account or provided us with personal data, please contact us immediately at [email protected]. We will delete the account and all associated data.

    Recipients of messages may be of any age. When you provide a recipient's contact details, you confirm that the contact information is accurate and that you have a reasonable basis to send them the message. The sender bears responsibility for the appropriateness of providing those contact details.

    14. Contact and Complaints

    If you have any questions, requests, or concerns about this policy or your personal data, please contact us:

    • Privacy contact: [email protected]
    • Postal address: Business Center, Sharjah Publishing City Free Zone, Sharjah, United Arab Emirates
    • Response time: We will respond to your request without undue delay and ordinarily within 30 days. Where a request is complex, involves a large volume of information, or multiple requests are submitted, we may extend the response period by up to a further 30 days. We will inform you of the extension and the reason for it before the initial period expires. Any shorter period required by applicable law will apply.
    • Phone: +971 52 516 5235

    If you believe we have not handled your data in accordance with UAE PDPL, you have the right to lodge a complaint with the UAE Data Office:

    • Regulator: UAE Data Office
    • Website: https://u.ae/en/about-the-uae/digital-uae/data/data-protection-laws

    For users in India, complaints may be lodged with the Data Protection Board of India established under the DPDP Act 2023.

    15. Changes to This Policy

    We may update this Privacy Policy from time to time. If we make material changes — for example, to how we share data, to retention periods, or to user rights — we will notify you by email at least 30 days before the changes take effect, and we will publish the previous version of the policy on our website for reference.

    Minor changes — such as clarifications, corrections of typographical errors, or updates to contact details — may be made without advance notification but will always be reflected in the “Last updated” date at the top of this policy.

    16. Governing Law and Jurisdiction

    This Privacy Policy is governed by the laws of the United Arab Emirates as applied by the DIFC Courts, including the UAE PDPL and its Executive Regulations. Nothing in this Privacy Policy limits any mandatory rights, remedies, complaints, appeals, or protections available to you under applicable data protection laws, including the UAE PDPL, its Executive Regulations, the India DPDP Act 2023, and the Digital Personal Data Protection Rules, 2025, where applicable. Any dispute arising in connection with this policy will be subject to the exclusive jurisdiction of the DIFC Courts in Dubai, applying common law principles in the English language. Where the dispute also falls within the scope of our Terms of Service, the dispute resolution and arbitration process set out there shall apply.

    For individuals in India, and where Dear Tomorrow's processing falls within the scope of applicable Indian data-protection law, we will process Personal Data in accordance with the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025, in each case as applicable and in force from time to time.

    Nothing in this Policy limits any mandatory rights or protections available under applicable law. Where more than one data-protection law applies, Dear Tomorrow will seek to comply with each applicable requirement and any binding direction of a competent authority.

    Dear Tomorrow · Privacy Policy · Version 1.0

    Dear Tomorrow
    © 2026 Dear Tomorrow. Built with care.
    PrivacyTermsCookiesRefund PolicyAcceptable UseData RetentionNominee PolicySecurityNominee AccessContact