Digital Services Act Labels

Digital Services Act - Transparency Labels and Markings

Effective Date: September 28, 2026

Service Provider

YukiSoftware OÜ

Estonian Company Registration Number: 17417945

1. Service Classification

1.1 Primary Categories

  • Service Type: Personal data management and productivity application
  • Main Purpose: Automated extraction and organization of structured insights from user emails and calendar data (travel itineraries, financial transactions, delivery tracking, calendar events)
  • Actions on the User's Behalf (Yuki Agent, where available): Sending emails the user asked for, moving, cancelling or declining the user's Google Calendar events, and working through websites in a cloud browser — each carried out only after the user approves it
  • User Interface Type: Mobile application (iOS, Android) and web portal
  • User Base: Individual consumers in the EU and worldwide

1.2 Data Handling Categories

  • Primary: Email inbox data (read-only access via Gmail API)
  • Secondary: Calendar events, contacts, account authentication data
  • Processing Method: Rules on our servers decide which emails are relevant; the content of a relevant email is processed for natural language understanding only by Google Vertex AI in the EU — Gemini models, with Anthropic’s Claude models, served by Vertex AI in the EU (europe-west1), as the backup for some features. No AI service outside Google Vertex AI in the EU receives email content, and if Vertex AI is unavailable the email is retried later (for up to three days) rather than sent elsewhere. Some features the user chooses involve other providers, including some outside the EU (for example Google Maps Platform for "leave by" estimates, and Browserbase for the browser agent); each one, and what it receives, is listed in Section 6 of the Privacy Policy
  • Data Retention: Email bodies are never stored — they are held in memory only while processed. Derived insights, email IDs, some subject lines and attached travel and finance documents are kept while the account is active; service logs for a limited time

2. Risks and Risk Mitigation Measures

2.1 Systemic Risks Identified

Data Privacy & Security

Risk: Unauthorized access to sensitive user personal data (emails, financial info, travel plans)

Mitigation:

  • End-to-end encryption for data in transit (TLS 1.3+)
  • PostgreSQL with AES-256 encryption at rest via Supabase
  • Row-Level Security (RLS) policies enforcing user data isolation
  • Email bodies are never stored; they are held in memory only while processed. What is kept: the extracted insights, the email's ID, for some records its subject line, attached travel and finance documents (tickets, boarding passes, invoices) so users can open them in the app, and — only if the user asks Yuki to learn their writing style — a short description of that style
  • Annual security audits and penetration testing
  • GDPR compliance with user data deletion on account termination

Third-Party Data Sharing

Risk: Inadvertent sharing of personal data with unauthorized third parties

Mitigation:

  • Every processor and other third-party recipient, and exactly what each one receives, is listed in Section 6 of the Privacy Policy
  • No data sale or commercial sharing with third parties
  • Limited third-party integrations with explicit user consent
  • Regular audits of third-party data access

AI/ML Model Training Risks

Risk: User data being used to train or improve AI models without consent

Mitigation:

  • Contractual prohibition on model training with customer data from our AI providers (Google Vertex AI, which processes email content; OpenAI, which turns a Support-chat question into a help-article search and writes recipe suggestions for users outside the EU/EEA, the UK and Switzerland)
  • No model fine-tuning or custom training on user data
  • Clear privacy policy disclosing AI processing methods
  • User opt-out mechanisms for AI-powered features (email extraction)

Actions Taken on the User's Behalf (Yuki Agent)

Risk: An AI agent sending, booking, paying or submitting something the user did not intend — including because a web page, an email or a calendar invitation tries to steer it

Mitigation:

  • Every action that sends, submits, books, pays, cancels or declines something in the user's name is shown on an approval card first and runs only after the user approves it; sending email, anything submitted on a website, bookings, orders, payments and changes to existing calendar events can never be approved in advance
  • Web pages, emails and calendar invitations are treated as untrusted data: they reach the AI model only inside a marked envelope, and nothing in them can change what the user asked for
  • The browser agent never types card numbers, passwords or one-time codes and never creates accounts; payment and sign-in are handed back to the user (the one exception, Pay with Link, needs each payment approved in the Link app), and no screenshot is taken once a payment step is reached
  • A calendar change is checked against Google again immediately before it runs, and refused if the event changed after its card was shown
  • One browser session at a time, and limits on AI requests and browser sessions that stop runaway loops and abuse
  • Every action is recorded in the user's Activity log

Authentication & Authorization Vulnerabilities

Risk: Unauthorized account access or privilege escalation

Mitigation:

  • OAuth 2.0 with Google and Apple Sign-In (no password storage)
  • Secure token management with refresh token rotation
  • Session management with automatic expiration
  • Two-factor authentication ready (future enhancement)

Illegal Content or Activities

Risk: Platform used for facilitating illegal activities (fraud, phishing, etc.)

Mitigation:

  • Terms of Service prohibiting illegal use
  • Abuse reporting mechanism in app and web portal
  • Account suspension and law enforcement cooperation procedures
  • No user-generated content moderation required (personal data only)

2.2 Content Moderation Measures

As a personal data management tool, Yuki does not host user-generated content, forums, or social features. Therefore, traditional content moderation is not applicable.

  • Abuse Reporting: Users can report abuse via email ([email protected]) or in-app contact form
  • Takedown Requests: GDPR subject access requests and deletion requests are processed within 30 days
  • DMCA/Copyright: No user-uploaded media; copyright concerns handled on a case-by-case basis

3. Service Provider Information

Legal Entity

YukiSoftware OÜ

Registration Number

17417945 (Estonia)

Principal Place of Business

Tallinn, Estonia

Contact for DSA Inquiries

[email protected]

Terms of Service

Available at yukihq.com/terms

Privacy Policy

Available at yukihq.com/privacy

4. User Rights & Remedies

  • Data Access: Users can download their data via account settings or request a complete data export
  • Data Deletion: Users can delete their account and all associated data at any time
  • Correction: Users can update their profile information in account settings
  • Withdrawal of Consent: Users can disconnect Gmail, Calendar, and Contacts integrations at any time
  • Complaint Handling: Support requests are processed within 5 business days; formal complaints can be escalated to supervisory authorities

5. Additional Information

This document is provided in accordance with Article 24 of the Digital Services Act (2022/1957/EU) and is updated regularly as our service and risk profile evolves.

Last Updated: September 28, 2026