Privacy Policy
Last updated: June 4, 2026
Introduction
Welcome to When Did They Join Bluesky? ("we," "our," or "us"). We respect your privacy and are committed to protecting your personal data. This privacy policy explains how we collect, use, and safeguard your information when you use our service.
Information We Collect
We collect minimal information necessary to provide our service:
- Bluesky Handles: The usernames you search for to look up join dates.
- Usage Data: Anonymous analytics about how our service is used (page views, features accessed).
- Technical Data: Standard server logs including IP addresses, browser type, and access times.
We do not collect passwords, private messages, or any sensitive personal information.
How We Use Your Information
We use the collected information to:
- Provide and maintain our service
- Look up publicly available Bluesky profile information
- Improve and optimize our service
- Monitor for technical issues and abuse
Third-Party Services
Our service interacts with the Bluesky API to retrieve publicly available profile information. We do not share your data with any other third parties for marketing or advertising purposes.
We use Google Fonts to display the typography on this site. When a page loads, your browser may request font files directly from Google's servers, which can result in Google receiving your IP address. This use is governed by Google's own Privacy Policy.
We may use analytics services to understand usage patterns. These services collect anonymized data and have their own privacy policies.
Our Public API
We offer a free, public API that returns how many days ago a given Bluesky account joined the network. It requires no account, no API key, and no registration, and it is available to any developer who wants to use it.
What it returns. The API only exposes information that is already public on the AT Protocol: the handle, the account's decentralized identifier (DID), and its creation date, expressed as a date and as a number of days. It returns no posts, followers, email addresses, or any non-public profile data.
What we log. API requests appear in our standard server logs alongside ordinary page requests. We additionally hold a per-IP request counter in temporary memory for rate limiting; that counter expires within a minute and is never written to our database.
What we don't record. Lookups made through the API are deliberately excluded from the “Recent Lookups” list and the public lookup counter shown on our site. Querying a handle through the API does not cause that handle to be displayed anywhere on this site.
Cross-origin access. API responses are served with a permissive CORS header so they can be requested directly from a browser. The API is stateless: it sets no cookies and creates no session for you.
If you build on the API. You are responsible for how you use the data you retrieve, and for complying with the Bluesky Terms of Service and any applicable privacy and anti-spam laws in your jurisdiction. Account age is intended to help you welcome and support newcomers; it must not be used to send unsolicited bulk messages, to harass anyone, or to build profiles of individuals beyond what the AT Protocol already makes public. We may block IP addresses that abuse the endpoint or ignore its rate limits.
If your account is looked up. Your Bluesky join date is part of the public record published by the AT Protocol and the PLC directory, and it can be read by anyone with or without our service. We do not create, alter, or enrich that record; we only read and reformat it.
Cookies and Session Storage
We use cookies and server-side session storage to enhance your experience:
- Session Cookie: A cookie is set to identify your browser session. This cookie contains only a session identifier and no personal data.
- Session Data: We store the following information in your server-side session:
- Your most recently searched Bluesky handle
- The join date information retrieved for that handle
This session data is stored on our servers, not in your browser. While you can delete cookies through your browser settings, this will only remove the session identifier cookie. The associated session data on our servers will expire automatically based on our session timeout settings.
Session data is used solely to improve your experience (e.g., displaying your last search) and is not shared with third parties.
Data Security
We implement appropriate security measures to protect your information. However, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security but strive to use commercially acceptable means to protect your data.
Data Retention
We retain search queries and usage data only as long as necessary to provide our service and comply with legal obligations. Technical logs are typically retained for a limited period for security and debugging purposes.
Changes to This Policy
We may update this privacy policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last updated" date.
Contact Us
If you have any questions about this privacy policy or our practices, please contact us at: