Privacy Policy
Effective Date: October 7, 2026
1. Introduction
YukiSoftware OÜ ("we") is committed to a privacy-first architecture. This policy describes how we handle your data when you use the Yuki App.
2. Data Minimization
- Only relevant emails reach an AI model: automatic rules on our servers decide which emails are relevant — a booking, bill, receipt, delivery, travel document or important notice — and skip the rest. For a relevant email we send its subject, sender and date, its text (with formatting, images, most links and boilerplate removed, and long messages shortened to a fixed length) and the text of attached PDFs where they matter, such as a ticket, an invoice or an official letter. We do not remove names or other details inside those emails, because they are often exactly what you need (the passenger on a ticket, the reference on a fine).
- What we keep: We do not store the body of your emails — it is held in memory only while it is processed. We store the Derived Insights extracted from it (e.g., "Flight to Paris on Jan 20" or "Spotify Subscription: $9.99"), the email's ID (to link a record to its email and not process it twice), for some records the email's subject line, and — for travel and finance emails — attached documents such as tickets, boarding passes and invoices, so you can open them in the app. For important notices (official letters, fines, school notices and appointments), the stored insight is limited to a short title, the issuer, what is required, the deadline (with any early-payment discount) or the appointment's time and place, any amount and currency, the reference number, a child's first name if the email gives it, and the IDs of the email and thread it came from — never the email body. Our service logs refer to a processed email by its ID, never by its subject line, sender or recipients; they may include some of the details extracted from it (such as a merchant or a booking reference), for troubleshooting, for a limited time.
3. Information We Collect
Agent availability notifications (Notify me): If you submit the public form, we store your email address, selected country or region, optional use-case text, the form source, consent version, request time and notification status. For a signed-in feature request, we use your verified account email and saved country (or ask you to choose one if missing), and store the requested feature with your account. We use these details to understand requested availability and contact you about that availability, not to grant Agent access, start a subscription, execute an action or add you to general marketing. Do not include passports, payment details or sensitive information in the optional text. Your submission is not shared with family/group members or supplied to Yuki's shared AI context.
The public form passes through Cloudflare (US/global infrastructure) before storage in our EU Supabase database. For abuse prevention, the form handler derives a keyed hash from the connecting IP address; the signup database stores that hash in short-lived request counters, not the raw address. Hourly address counters expire after two hours and global counters after two days; expired counters are removed on a later submission. Cloudflare also processes connection data to deliver and protect the website; see Sections 6 and 11.
Availability contact is handled by our team; submitting is not evidence that an email has been sent, and does not guarantee access or a launch date. Requests currently have no automatic deletion schedule. You can ask [email protected] to access, correct, withdraw or delete your submission, subject to appropriate identity verification. Withdrawal stops availability contact but retains the withdrawn record to avoid resubscribing you through an unauthenticated form; request deletion if you also want that record removed. Repeated public submissions do not overwrite saved details or reactivate withdrawn requests. Public submissions are not linked to an account, so deleting an account does not automatically remove a public-form submission; signed-in feature requests are removed with their account.
- Account Data (always collected): When you sign in with Google, we receive only your name, email address, and profile picture (the standard openid email profile scopes). When you sign in with Apple, we receive your full name and email (or a relay address if you choose to hide your real one).
- Google API Data (OPTIONAL — opt-in via "Connect Gmail & Calendar"): The scopes below are not requested at sign-in. You can use Yuki without granting any of them — calendar and email-derived features will simply show empty states. To enable them, tap "Connect Gmail & Calendar" on the post-signup screen, or any time later from Profile > Connect Gmail & Calendar. You can disconnect at any time from the same screen, which immediately revokes our access tokens.
- Gmail (Read — gmail.readonly): We access your Gmail inbox in read-only mode to automatically extract structured insights such as travel itineraries, financial transactions (receipts, invoices, subscriptions), delivery tracking updates, and important notices (official letters, fines, school notices and appointments). When you open an email in the web app, Yuki reads it from Gmail through its servers in the EU and shows it to you, without keeping a copy.
- Gmail (Send — gmail.send): The Day Organizer's "Focus Zone" feature displays priority emails that need your attention, along with AI-suggested quick replies. When you tap a quick reply, the app sends the reply on your behalf using the Gmail API. Where Yuki Agent is available to you, Yuki AI can also write an email or a reply you ask for, or ask a sender to unsubscribe you. It is sent from your Gmail only after you approve a card showing the recipients, the subject and the full text (which ends with a short "— sent via Yuki" line) — or, for an unsubscribe, the sender and how the request is made: through the sender's own one-click unsubscribe link, or by an email to the address the sender gives. You are asked every time; this approval can never be given in advance. Emails are only sent when you explicitly initiate or approve the action — the app never sends emails automatically or without your knowledge.
- Gmail (Modify — gmail.modify, optional): requested only if you tap "Allow tidying" under Profile → Connections. It lets Yuki archive an email (remove it from your inbox; it stays in All Mail) or add a Gmail label — and only for the specific emails you approve on an approval card, each time. Yuki never deletes mail and never changes your mailbox on its own. You can revoke this at any time in your Google account.
- Google Calendar (calendar): We read your calendar events to display them in the Day Organizer and write events to help you organize auto-detected commitments (e.g., flights, hotel check-ins) and appointments found in your emails. An appointment is only added when you approve it or have chosen to add appointments automatically, and never if it is already in your calendar (see Section 4A). Where Yuki Agent is available to you, Yuki AI also reads your calendar when you ask about your schedule or for a free time, and it can move, cancel or decline an event on your primary calendar — only after you approve a card showing the change and whom Google will notify (see Section 5, "Calendar agent").
- Google Contacts (contacts.readonly): We access your contacts in read-only mode to display upcoming birthday and anniversary reminders on the Home dashboard. You can import them from the mobile app or from the web app; either way, the same data is kept (contacts with a birthday or anniversary), in our database in the EU. Contact data is stored securely in our database and never shared with third parties.
- Location: During onboarding, we request your location to personalize your experience (e.g., setting your home city). Location data is stored in your profile and is never shared with third parties. You can update or remove it at any time in your profile settings.
- Usage Data: Crash logs and performance metrics via Sentry (mobile + web) and product analytics via PostHog (mobile app and web app), linked to an internal user ID rather than your name or email address; heatmaps and session recordings via Microsoft Clarity, on the website only, to improve the layout; and install and subscription events via AppsFlyer, to measure our ad campaigns (see Sections 6 and 7).
- Group Data: If you create or join a Group (see Section 4C), you voluntarily share certain data with other group members, including shared tasks, task assignments, expense details (amounts, categories, splits), poll responses, grocery lists, comments, and optionally your calendar events. Your email address is shared with group members via the invitation process.
- Device & Notification Data: We store your device push notification token (via Expo Push Notifications) to deliver real-time alerts for task reminders, group activity, and email-arrival notifications. We also collect a Firebase App Check attestation token to verify that requests originate from a genuine installation of the App. You can disable push notifications at any time through your device settings.
- Grocery & Shopping List Data: If you use the grocery list feature, we store your list items, categories, quantities, and check-off status. Grocery lists created within a Group are visible to all group members and may include item assignments to specific members.
- Support Chat Data: When you use the in-app support chat, we store your messages, AI responses, and any replies from human support agents. This data is linked to your account and stored in our database. If your conversation is escalated to a human agent, the chat history is shared with our support platform, HelpScout (see Section 6).
- Third-Party Data Enrichment:
- Weather: For trip and travel features, we fetch weather forecasts for your trip destinations from the Open-Meteo API. Weather data is cached temporarily on our servers and on your device. Only place names or geographic coordinates are transmitted; no personal data is sent.
- Flight Data: For detected flight bookings, we may query the AirLabs API to retrieve supplementary real-time flight information such as gate numbers, terminal assignments, and delay status. Only flight numbers or departure airport codes are transmitted.
- Imported Calendar Files: You may import events by sharing .ics (iCalendar) files with the App. The App reads the file contents to create calendar entries; the raw file is not permanently stored.
- Clipboard Access: The grocery list feature allows you to copy your shopping list to your device clipboard for sharing outside the App. Clipboard data is accessed only when you explicitly initiate the copy action and is not transmitted to our servers.
- AI Processing: Some features (e.g., email sync, AI Quick-Add, summaries, and parsing of text, receipts, and statements) send the relevant input to a third-party AI/cloud provider to generate results. We send only the data needed for the feature and do not sell your data; your inputs are not used to train third-party models. See Section 5 (AI/ML Processing Disclosure) and Section 6 (Third-Party Sub-Processors) for details.
- Camera / Receipt & Document Scanning (OCR): When you scan a receipt or document with your camera, the image is processed (on-device and/or via our processing pipeline / OCR provider) to extract structured details such as merchant, amount, and date. We store the extracted details; raw images are not retained beyond what is needed to process them.
- Statement Import: When you import a bank or card statement, the file is processed to extract transactions. We store the extracted transactions, not the original statement file beyond processing.
- Bank Connections (optional, EU/EEA): Where we offer it, you can connect a current, savings, card or loan account at a bank in the EU/EEA through Enable Banking (see Section 6). Access is read-only: Yuki reads the accounts you share at your bank (account name and type, currency and the last four digits of the account number), their balances, and their transactions (date, amount, currency, the other party's name, the payment description and whether it is still pending) — up to 180 days back when you connect, as far as your bank provides. Yuki cannot make payments, move money or change anything at your bank. See Section 9 for how long this is kept.
- Travel Documents: If you store travel documents (e.g., boarding passes, tickets, visas, hotel confirmations), or they arrive as attachments to booking emails Yuki processes, this information is personal data stored securely in your account, visible only to you (and group members if you share a trip), and is never sold or shared with third parties for their own use.
- Saved Personal Details (you and people you add): If you choose to save details such as a date of birth, the gender marker on a passport, a passport number, issuing country or expiry date, nationality, visas, a phone number, email or address — for yourself or for someone else — they are stored privately in your account and used only to fill in the forms and bookings you ask for and — for the address you save for yourself — as the starting point of "leave by" estimates when you haven't said where you are leaving from (see Section 5, "Calendar agent"). Yuki never saves them without your confirmation, does not send stored passport numbers to the AI model when it fills a form, and you can edit or delete them at any time in Profile → Saved details.
- Information You Provide About Other People: Save only information you have permission or other lawful authority to use for the requested purpose. You can manage your saved travel details in Profile → Saved details and your private contact notes in People. The distinct record sources and responsibilities are explained below.
Your records and other people's shared profiles: A private People/contact record you create, including travel details you save about that person, is your account's copy. It is not that person's Yuki account profile and editing it does not update their account. A connected user's own details are a separate source, usable only through the sharing permissions and purposes they authorise. A connection or family/group membership alone does not grant access to private identity or travel documents. Revocation stops future authorised use through that sharing permission; it cannot recall copies already lawfully supplied to an airline, hotel or other recipient or automatically erase independently entered records. Requests about independently held information can be made to its holder or to [email protected]; applicable access, correction and erasure rights still apply.
You are responsible for ensuring you have permission or another lawful basis to enter and use someone else's information, keeping it accurate, limiting it to the requested purpose, and respecting their privacy and choices. For children or dependants, you must have the necessary authority. Yuki's provision of these tools does not authorise impersonation, unauthorised disclosure or other misuse. Yuki remains responsible for its own processing, security and other duties under applicable law; nothing in this policy removes those duties or individuals' statutory rights.
- Booking links (people who book time with a Yuki user): A Yuki user can share a booking link (yukihq.com/book/…) that anyone can open without a Yuki account. If you book through one, we collect the email address you enter (required), your name and notes (optional), the time you picked and your time zone, and — only to prevent abuse — a keyed hash of your IP address, never the address itself. Cloudflare Turnstile checks your browser to keep bots out. We process this on behalf of the Yuki user you book with (they decide what happens to their meetings; Yuki acts as their processor), in the EU (Supabase in Frankfurt, our backend in europe-west1). The booking is added to that person's Yuki calendar and/or Google Calendar; when it goes to Google Calendar, Google sends you the invitation. Yuki does not create an account for you or send you marketing. The booking record is deleted 180 days after the meeting; the event in the host's own calendar is theirs and stays unless they delete it. To change or cancel, use the link on your confirmation page; for anything else, contact the person you booked with or [email protected].
- Public polls (people who vote in a Yuki user's poll): A Yuki user can share a poll (yukihq.com/poll/…) that anyone can open and vote on without a Yuki account. If you vote, we store your answers, any comment you write, the name you enter (only when the poll asks for names) and — only to allow one vote per person and to prevent abuse — a keyed hash of your IP address, never the address itself. Your browser keeps a private edit link so you can change your vote; we store only a hash of it. Cloudflare Turnstile checks your browser to keep bots out. We process this on behalf of the Yuki user who made the poll (they decide what it asks and who sees the results; Yuki acts as their processor), in the EU (Supabase in Frankfurt). The poll's creator sees every answer and, on a poll that asks for names, who gave it; other voters see only totals, and only when the creator allows it. If you vote from the Yuki app, your vote is linked to your account so that you have one vote per poll. Yuki does not create an account for you or send you marketing. The poll and every vote in it are deleted 30 days after voting closes. To change your vote, use your edit link; for anything else, contact the person who shared the poll or [email protected].
4. How We Use Your Data
We use Google API data exclusively to provide the app's core features:
- Extracting travel, finance, and delivery insights, and important notices (official letters, fines, school notices and appointments), from emails
- Sending quick replies from the Day Organizer (only when you explicitly initiate the action)
- Displaying calendar events and creating new events for detected trips, and for appointments found in your emails when you approve them or have chosen to add them automatically
- Showing birthday and anniversary reminders from contacts
- Reading an email when you ask Yuki AI about it, and learning your writing style if you ask Yuki to (see Section 5)
- Where Yuki Agent is available to you: answering your questions about your calendar and finding free time, and sending the emails and making the calendar changes you approve (see Section 5)
We do not use Google API data for advertising, market research, or any purpose unrelated to providing the app's functionality.
A. Automated Task Creation
The App may automatically create tasks based on actionable information extracted from your emails, such as payment due dates, flight check-in reminders, subscription renewals, trial expiration dates, and delivery pickup deadlines. It also recognizes important notices and turns them into tasks with an automatic reminder that joins your daily reminder digest: official and government letters (e.g., tax, residence permits, visas and immigration appointments, benefits, council matters, jury duty, elections, vehicle registration), fines and penalties (e.g., parking, traffic, speed camera, toll or library fines, with the pay-by date, amount, reference number and any discount deadline), school and childcare notices about your children (e.g., events, forms to return, closures, parent meetings, fees, trips), and appointments (e.g., doctor, dentist, vet, hospital, government office, school). Emails that look like phishing (such as fake "tax refund" offers) are ignored. Yuki only reminds you: it never pays a fine and never replies to a notice on its own. These tasks are created locally in your account and are not shared unless you are part of a Group. A child's first name is kept only if the email gives it, and information about your children is used only for your own reminders — it is never shared and never used for anything else. You can disable this feature at any time via Profile > Notifications > Auto-Create Tasks from Emails.
Appointments found in your emails are handled the way you choose in Profile > Notifications: with "Ask me first" (the default), Yuki offers each one to you as a one-tap question; you can instead have them added to your calendar automatically, or ignored. An added appointment goes to your Yuki calendar and — only if you have connected Google and allowed calendar writes — to your Google Calendar. Yuki never adds an appointment that is already in your calendar, including one that arrived as a calendar invite.
B. Record Enrichment
When follow-up emails arrive regarding an existing record (e.g., a flight cancellation after a booking confirmation, a refund after a purchase, or a delivery status update), the App automatically enriches the original record with the updated information. This ensures your data stays current. When the App is uncertain about the nature of an update, it uses hedging language (e.g., "Probably cancelled — best to confirm with airline directly"). Enrichment includes updating booking statuses (confirmed, cancelled, delayed, rescheduled), recording refund transactions with negative amounts, and adjusting or cancelling related auto-created tasks.
C. Groups
Groups allow you to collaborate with family, friends, roommates, or coparenting partners. When you create or join a Group:
- Shared Data: Tasks (including assignments to specific members), expenses (amounts, categories, payer, split details), settlements, poll questions and votes, grocery lists (items, categories, assignments, check-off status), comments, and activity history are visible to all active group members.
- Calendar Sharing (Opt-In): You may choose to share your calendar events with the group. This is disabled by default and requires explicit opt-in.
- Email Disclosure: When you invite someone to a group, their email address is stored in the invitation record. Group members can see the display names and avatars of other members.
- Activity Logging: Actions within a group (tasks created, expenses added, members joined) are logged in a shared activity feed visible to all members.
- Removal: When a member is removed from a group or leaves voluntarily, they immediately lose access to all group data. Historical activity records (e.g., "Alice added an expense") remain visible to other members.
- Data Isolation: Your personal data (emails, individual financial records, private tasks) is never shared with group members. Only data you explicitly create within the Group context is visible to other members.
- Delegated Tasks: Group members can delegate tasks to people outside the group via a secure, unique link. The delegated recipient can view and complete only the specific task shared with them — no account or login is required. No other group or personal data is accessible through these links.
- Birthday & Special Day Wishes: The App provides a feature to send birthday or anniversary wishes to your contacts. When you initiate a wish, the App deep-links to your preferred messaging app (WhatsApp, SMS, Telegram, or Email) with a pre-filled greeting message. The message is sent through the third-party messaging platform, not through Yuki servers. We do not store or transmit the content of these messages.
5. AI/ML Processing Disclosure
We use third-party language models for seven purposes: (a) parsing unstructured email text into structured data (flight numbers, amounts, tracking IDs, booking statuses, refund details, deadlines, fine and reference numbers, appointment times), (b) generating draft trip itineraries when you use the Plan-a-Trip feature, (c) creating individual records (tasks, reminders, occasions, transactions, subscriptions, grocery lists) when you use the AI Quick-Add feature, (d) powering the Yuki AI in-app conversational assistant that lets you ask questions about your records and perform actions (create/update/delete tasks, expenses, trips, etc.) via natural language, (e) generating responses in the in-app Support chat, (f) generating recipe suggestions when you ask for a recipe or for a change to one, and (g) driving the browser agent, which works through a website for you where Yuki Agent is available to you. To keep AI features available when one model is degraded, a request can fall back to another model; all of these models run on Google Vertex AI in the EU (see Section 6), with one exception: recipe suggestions for users outside the EU/EEA, the UK and Switzerland (see "Recipes" below). This processing:
- Is performed solely to provide the app's core features
- Does not involve training or improving AI/ML models with your data
- Uses provider APIs with data processing agreements that prohibit model training on customer data
- Email sync: if you connect Gmail with a plan that includes email sync, our servers read your recent emails when you first connect, and each new email as it arrives, to decide automatically whether it is relevant — a booking, bill, receipt, delivery, travel document, or an important notice such as an official letter, a fine, a school notice or an appointment. A relevant email's content (its subject, sender, date, cleaned-up text and the text of relevant PDF attachments — see Section 2) is sent only to Google Vertex AI in the EU (Gemini models) to extract the details, never to another AI provider; if Vertex AI is unavailable, Yuki keeps just the email's ID and tries again later, for up to three days. Yuki keeps the extracted details, not the email (see Section 2); the providers do not use it to train their models; and you can stop this at any time by disconnecting Gmail in Profile > Connect Gmail & Calendar
- Reading an email on request: when you ask Yuki AI about a specific email (for example "summarize this", or with Summarize on the email), Yuki reads that email in full: the text of its latest message or messages (shortened to a fixed length), with its subject, sender and date, is sent to the AI provider to answer you. When you ask Yuki AI to find an email, only the sender, subject, date and Gmail's short preview of up to 10 matching emails are sent. Yuki AI reads nothing in your mailbox without your asking (email sync, above, is a separate process), and the message text itself is not stored — only your question and the answer stay in your conversation
- Suggested replies: when you tap "Suggest reply" on an email in Focus, its sender, subject and Gmail's short preview are sent to the AI provider to write the suggestions. Nothing is sent until you tap, and the suggestions are not stored
- Writing style (optional): if you tap "Learn my writing style" under Profile → Connections, up to 12 emails you sent in the last year are read once and sent to the AI provider to produce a short description of how you write (greeting, sign-off, tone). Only that description is stored, it is shown to you in full, and you can clear it at any time. The emails themselves are never stored
- Trip planning only sends the prompt you type, the trip window you select, and a brief summary of your existing trips/items in that window. Your email contents are never shared with the trip-planning AI.
- Quick-Add sends the short prompt you type and the current date; it returns a structured payload that we then write to the relevant table on your behalf. Like Yuki AI, it may look up the records your request needs, and it reads your email only when you ask it to.
- Yuki AI Assistant: When you chat with Yuki AI, the model receives your message, recent conversation history, and your timezone. To answer questions or perform actions you request, the model may call internal "tools" that read or write specific records on your behalf — but only the records relevant to your current request, and only within your own account. When a request needs a lookup first (for example "what's on tomorrow, then add a task before it"), the result of that lookup — such as a summary of your agenda or trips — is passed back to the model within the same request so it can complete what you asked. The model sees the text of an email only when you ask about that specific email (see "Reading an email on request" above), never accesses other users' data, and only writes/updates records when your request makes the intent clear. Where Yuki Agent is enabled, actions that cannot be undone from the app (such as permanently deleting a trip leg, transaction or subscription) are not carried out by the model directly: Yuki shows you exactly what would change and does it only after you approve, keeps a record of every such action in Activity, and lets you undo it for 30 days. Where Yuki Agent is available to you, your conversations are stored in your account: messages are deleted automatically after 90 days, and you can delete a conversation at any time from your list of conversations. Otherwise, your conversation history is kept on your device.
- Calendar agent (where Yuki Agent is available to you): when you ask about your schedule, Yuki reads your Google Calendar through our servers — your primary calendar and the other calendars you have ticked in Google Calendar (never holiday, birthday or week-number calendars), for the days you ask about, at most two weeks at a time — together with the events you keep in Yuki. The AI model receives each event's title, time and place, the number of guests (not their addresses), the organiser's address when it isn't you, and whether it repeats; Yuki never requests an event's description from Google. To find free time, Yuki asks Google when you — and anyone you name, up to five people — are busy: Google shows another person's busy times only if their calendar is shared with you, and never the details of their events. When you ask what is waiting for you, the model receives the items Home shows you, including the sender, subject and date of up to eight emails from Focus — never their text. To move, cancel or decline an event, Yuki reads it again from Google and shows you a card; nothing changes until you approve it, and only events on your primary calendar are ever changed. Google then notifies the other guests (for a decline, the organiser) in your name. Yuki does not copy your Google Calendar into our database: what it reads is used to answer you and then discarded. What stays is Yuki's reply in your conversation (together with any free times it found and whose calendars it checked) and, for every change Yuki proposes, its card — the event's title, times and place and the guests' addresses — in your conversation and in Activity.
- "Leave by" estimates: when Yuki reads your calendar and knows where you will be leaving from — a place you mention in the chat, or otherwise the address you saved for yourself in Profile → Saved details — it estimates when to leave for up to three of your upcoming events in the next 36 hours that have a real address (not a video link or a room number). For each one, our servers send the starting point, the event's location, the travel mode and a departure or arrival time to the Google Maps Platform Routes API (see Section 6) — never your name, your account or the event's title. If Google gives no route and both places are known as coordinates, Yuki estimates from the straight-line distance instead, without sending anything. Route answers are kept only in our servers' memory, for reuse within 10 minutes, and are never written to our database; the estimate appears in Yuki's reply, without your address. If you haven't saved an address and don't say where you are leaving from, nothing is sent.
- Browser agent (where Yuki Agent is available to you): when you ask Yuki to do something on a website, the AI model that drives the browser receives your request and, at each step, the page's address and title, its visible text and the buttons and fields on it, and every few steps a screenshot. Page content is treated as untrusted: nothing a page says can change what you asked for. This model runs only on Google Vertex AI in the EU (Gemini models, with other Gemini models in the EU as the backup). Yuki types only what your request contains — never a card number, password or one-time code — and stops for your approval before anything that books, buys, confirms, submits or sends. No screenshot is taken once a payment step has been reached, or while you are using the browser yourself. See Section 6 ("Browserbase") for where the browser runs and Section 9 for what is kept.
- Recipes: when you ask for a recipe that Yuki's recipe book does not have yet, or ask to adapt a recipe (for example "Vegan" or "No oven"), the recipe suggestion is generated by an AI model. If you are in the EU/EEA, the UK or Switzerland, or have not set your country, it is generated by Google Vertex AI in the EU. If you are elsewhere, it is generated by OpenAI (US), with Google Vertex AI in the EU as the backup. What counts is the country set in your profile. In both cases, only the dish name (and the cuisine's country, if you picked one), the recipe's ingredients and steps, and the change you choose or type under "Make it…" are sent — nothing about you or your account. A change you type (up to 120 characters) is sent exactly as you wrote it, so please don't include personal details in it.
- Support Chat: When you use the in-app Support chat, your messages — together with the titles and dates of tasks and calendar events you added in the last 7 days, so the assistant can confirm what was saved — are sent to Google Vertex AI in the EU to write a reply. To find the help articles that answer your question, the text of your latest message, and nothing else, is also turned into a search query by OpenAI (see Section 6). If you escalate to a human agent, your conversation history is forwarded to HelpScout (see Section 6) for our team to respond.
6. Third-Party Sub-Processors
To provide the Service, we utilize specific third-party infrastructure:
- OpenAI (US): Two uses: turning the text of your latest Support-chat message into a search query to find relevant help articles, and generating recipe suggestions for users outside the EU/EEA, the UK and Switzerland (only the dish, the recipe and the change you choose or type; see Section 5, "Recipes"). Nothing else from your account is sent to OpenAI. Data is not used to train their models.
- Anthropic (US company; Claude models served by Google Vertex AI in the EU, europe-west1): Backup model for some of the AI features listed under Google Cloud Platform below (such as Yuki AI, AI Quick-Add and trip planning) when a Gemini model is unavailable. The request is processed by Google Vertex AI in the EU. Data is not used to train their models.
- Google Cloud Platform (EU): Backend API services hosted on Cloud Run in europe-west1, and Google Vertex AI — the AI provider for email parsing, Yuki AI, AI Quick-Add, trip planning, email summaries, suggested replies and your writing-style description, the morning note, the monthly finance summary, categorising transactions, Support-chat replies, recipe suggestions and the browser agent's steps on websites — using Google Gemini models, with Anthropic Claude models as a backup, served from Google's EU regions (data stored and processed within the European Union). Data is not used to train models.
- Supabase (AWS, Frankfurt, Germany — EU): Secure database and file storage for your account — your profile, Derived Insights and stored files such as travel documents and the browser agent's screenshots.
- RevenueCat (US): Subscription status and entitlement checks.
- Paddle.com (UK): Merchant of Record for web-only subscription purchases made at yukihq.com. Processes payment information (card details, billing address) and handles VAT/GST collection. Your payment credentials are stored by Paddle, not by us. Paddle's privacy policy applies to payment data they process. Paddle is not available inside the iOS or Android apps — in-app purchases on iOS go exclusively through Apple's In-App Purchase system, and on Android exclusively through Google Play Billing, in compliance with Apple App Store and Google Play policies.
- Sentry (US company; data stored in its EU region): Error tracking and crash reporting. A report is linked to an internal user ID, not to your name or email address.
- HelpScout (US): Human support agent platform. When your support conversation is escalated to a human agent, your conversation history (messages, issue type, your name and account email) is shared with HelpScout to enable our support team to respond. HelpScout's privacy policy applies to data processed on their platform.
- Resend (US company) — email delivery: Delivers two kinds of email. First, a daily email to Yuki's team for quality review, with short AI-written summaries of chats with Yuki AI that have been scrubbed of personal details; it carries no chat transcripts and no email content. Second, a trip invitation you choose to send by email where automatic flight check-in is available to you: Resend receives the address you type, your first name, the trip's name, the flight number if there is one and the link to join the trip — never a boarding pass, a booking reference or anyone's passport details.
- PostHog (EU): Product analytics — in the mobile app and in the web app (the signed-in app at yukihq.com/app, not the public website) — linked to an internal user ID, never your name or email address, plus a few subscription events sent by our servers and, if you came to Yuki from one of our ads, which campaign it was. In the web app, it starts only after you accept analytics cookies where consent is required. You can opt out of the app's analytics in Profile > Privacy & Data, and of the web app's in Settings > Account > Data & privacy > Analytics Tracking.
- Google Analytics 4 (US/EU): Anonymous click analytics for the marketing website only (yukihq.com) — counts Download-button clicks by store (App Store/Google Play) and by page, so we can see which pages drive installs. Runs in Consent Mode with advertising signals permanently denied: no Google Ads conversion tracking, no Google Signals, no ad personalization, and no advertising profile is built from this data.
- Cloudflare (US/EU): Hosts the public website (yukihq.com) and documentation site (docs.yukihq.com). Cloudflare Web Analytics provides anonymous, cookieless traffic measurement for marketing-site pages.
- Microsoft Clarity (US/EU): Heatmaps and session recordings that show how our screens are used, so we can improve the layout — on the public website and docs site only. On the website, Clarity runs in cookieless mode and masks sensitive form fields by default. The mobile app contains the Clarity SDK, but it is switched off: no Clarity data is collected from the app.
- AppsFlyer (US) — ad measurement: Tells us which of our ad campaigns bring people to Yuki. The app reports the install and three kinds of events to AppsFlyer — your first sign-in on the device (with the sign-in method), the start of a free trial or promotional access, and each subscription bought in the App Store or Google Play (with its price, currency and product) — together with identifiers for your device and this installation. On iPhone these include your advertising identifier (IDFA) only if you allow tracking; on Android they include the device's advertising ID unless you have deleted it in your device settings. AppsFlyer may pass these events on to the ad networks that ran our campaigns, such as Google Ads or Meta, so they can measure and improve them. No name, email address or Yuki account ID, and nothing from your emails, calendar or chats, is sent.
- Open-Meteo: Weather forecast data for trip destinations. No personal data is transmitted; only place names or geographic coordinates are sent.
- Photon by komoot (Germany), OpenStreetMap data: Place search when you choose where something should happen (for example, the area for a restaurant booking). Only what you type in the place field — or, if you tap "Use current location", your device's coordinates at that moment — is sent, directly from your device, and only when you do it. No account details are sent.
- Ticketmaster (US/EU): Event search when you ask Yuki about concerts, sport or shows. Our servers send only the search itself — an artist, team or venue, a city or area, and dates — never your name, email or account. Buying happens on Ticketmaster's own site or app under their terms; Yuki does not sell, hold or pay for tickets.
- Swiggy (India) — Dineout and Instamart: If you connect your Swiggy account, Yuki uses your Swiggy sign-in to search restaurants and groceries, and — only after you approve a card showing the details and total — books a table or places a grocery order in your own Swiggy account. Payment (UPI on Swiggy's page, or cash on delivery) is between you and Swiggy; Yuki never sees or stores payment details. Swiggy's terms and privacy policy apply to your orders and bookings.
- Instacart (US/Canada): When you ask Yuki to send a shopping list or recipe to Instacart, our servers send only the item names, amounts and title — never your name, email or account. You choose a store and check out on Instacart under their terms; Yuki does not place orders or handle payment there.
- Uber — ride hand-off: When you ask Yuki for a ride, Yuki opens Uber's app or website with the pickup and drop-off you chose already filled in. Our servers send nothing to Uber: you choose, confirm and pay for the ride in Uber, under Uber's terms and privacy policy.
- Nuitee (Nuitée Travel Limited, Ireland) — hotel bookings: When you ask Yuki to book a hotel, our servers send the search (place, dates, the number of guests and any children's ages, and — from the app — your phone's region setting as the guests' nationality, which hotels use for their prices) and, once you approve a booking, the guest name and email to Nuitee, which confirms the room with the hotel. You pay on Nuitee's secure payment form; Nuitee processes the payment as the seller of the booking and Yuki never sees or stores card details. Nuitee may store booking data in the United States. The hotel's and Nuitee's terms apply to your stay.
- Nuitee (Nuitée Travel Limited, Ireland) — flight bookings: When you ask Yuki to find or book a flight, our servers send Nuitee the search (origin, destination, dates, number of travellers and cabin class) and, once you approve a booking, each traveller's name, date of birth, gender, nationality, passport details, email and phone number, which Nuitee uses to issue the ticket with the airline. You pay on Nuitee's secure payment form; Nuitee processes the payment as the seller of the booking and Yuki never sees or stores card details. Nuitee may store booking data in the United States. The airline's and Nuitee's terms apply to your flight.
- eSIM supplier (Nuitee's eSIMply, or another eSIM provider named on the card) — travel eSIMs: When you ask Yuki to order an eSIM, our servers send the supplier the destination, dates and plan and, once you approve, your name, email and phone number, which the supplier needs to issue the eSIM. The eSIM's install codes are stored in your account and shown only to you.
- Duffel (UK) — flight bookings: When you ask Yuki to find or book a flight, our servers send Duffel the search (origin, destination, dates, number of travellers and cabin class) and, once you approve a booking, each traveller's name, title, date of birth, gender, email and phone number, which Duffel uses to reserve the seats with the airline. Flight booking is currently offered only as a test to selected users, in Duffel's test environment: no real ticket is issued, no payment is taken from you, and Yuki never sees or stores card details. Duffel's and the airline's terms apply to a booking. Duffel is based in the UK, which the EU recognises as protecting personal data adequately; some of the service providers Duffel uses are in the United States, under the European Commission's Standard Contractual Clauses.
- 1Checkin (1Checkin Solutions Ltd, Cyprus — EU) — automatic flight check-in: Our servers send the approved flight (airline, flight number, airports, departure time and booking reference) and, for each selected traveller, their name as on the passport and the fields the check-in requires: date of birth, supported passport gender marker, nationality, passport details, visa information and additional answers such as an e-ticket number. Saved fields can be reviewed and corrected before approval. Provider success and boarding-pass retrieval are separate outcomes; Yuki can save passes only when they are returned and successfully retrieved. See the disclosure below.
- Flyo — automatic flight check-in (selected accounts): For a limited set of accounts, an approved check-in is sent to Flyo instead of 1Checkin. The approval card names the provider before you approve. Flyo receives the same flight and traveller fields listed for 1Checkin and uses them with the airline to check you in. Once you approve, a check-in sent to Flyo can't be stopped from Yuki.
Automatic flight check-in (Agent; limited availability): This feature is available only to selected users and countries. After you review and approve a flight and its selected travellers, Yuki sends the required booking, identity and travel-document fields to 1Checkin, which uses them with the operating airline to attempt check-in. Requirements vary with your location, airline, route, nationality, age, passport, visa, residence permit and any further airline or border-document checks. Information you submit is used to perform that approved check-in, not to determine legal permission to travel or enter a country. Provide another traveller's details only when you are authorised; access to that person's saved details requires their sharing permission, and group membership alone does not grant it. For a child, the adult supplying the details must have the appropriate parental or guardian authority.
Boarding passes returned and saved in Yuki are trip documents, private by default and shared only when you explicitly choose to share them. Yuki retains saved trip documents until you delete them. Deleting Yuki's copy does not cancel airline check-in or by itself delete copies already received by 1Checkin or the airline. Their own processing, retention and rights procedures apply to those copies; see 1Checkin's privacy policy and the operating airline's policy. The airline and its service providers may process the required information outside the EU; Yuki's EU storage does not mean the airline's processing stays in the EU. See Section 11 for transfer safeguards and contact us about provider-side deletion requests. Do not enter passport or visa details in the Agent availability signup form.
- Enable Banking Oy (Finland) — bank connections (EU/EEA): A licensed account information service provider supervised by the Finnish Financial Supervisory Authority. You choose your bank in Yuki, then sign in and give your consent on your bank's own page — never in Yuki, and Yuki never sees your bank login. Your consent lets Yuki read your accounts, balances and transactions (read-only, no payments) for as long as your bank allows, at most 180 days; your bank then asks you to confirm again, and Yuki reminds you in the week before it ends. Yuki reads your bank when you connect or refresh and, while your consent lasts, automatically about once a day. Our servers send Enable Banking your chosen bank and country, the App's language and, when you are using Yuki at the time, your device's IP address and browser or app type, which banks require — never your name or email. Bank data is processed in the EU. You can end the consent at any time by disconnecting the bank in Profile → Connections (which also ends it at Enable Banking) or at your bank. Enable Banking's own terms and privacy notice apply to the consent you give it.
- Plaid (US) — bank connections: Connecting a bank through Plaid is not yet available to users: it is being tested with selected accounts. You sign in to your bank on Plaid's own page, never in Yuki. Our servers send Plaid an internal user number — never your name or email — and keep the accounts, balances and up to 180 days of transactions Plaid returns until you disconnect the bank or delete your account.
- Link by Stripe (US and Canada) — agent payments: Pay with Link is still being tested and is not offered to users yet. Once it is, if you connect your Link wallet, Yuki can ask Link for a one-time card for a purchase the browser agent is making for you. You approve every payment in the Link app, for the exact amount and site. The one-time card is typed into that site's checkout by Yuki's servers and is never shown to the AI, stored or logged; your real card never leaves Link. Stripe's Link terms and privacy policy apply. You can disconnect Link at any time in Connections.
- Browserbase (US company) — browser agent: When you ask Yuki to do something on a website, the pages open in a cloud browser that Browserbase runs for us in the region of that site — Virginia (US) for sites in the Americas, Singapore for sites in Asia and Oceania, and Frankfurt (EU) for all others, including whenever the site's country is unclear — because sites turn away browsers that seem to come from elsewhere. That browser sees the sites Yuki visits and everything typed or chosen on them — by Yuki, from your request, or by you in the live browser; our servers give Browserbase only an internal session number — never your name, email or account. Session recording and logging are turned off, and the browser is closed when the task ends, at the latest after an hour. Screenshots of Yuki's progress are kept in our own private storage in the EU until 7 days after the task ends, and are deleted with your account. Yuki never types card numbers or passwords and never creates accounts — when a site asks you to pay or sign in, you do that yourself in the live browser, and anything that books, sends or confirms waits for your approval. The one exception is Pay with Link (above): a one-time card from your Link wallet, for a payment you approve in the Link app, is typed into that checkout by Yuki's servers. The website's own terms and privacy policy apply to what is done there.
- Google Maps Platform (Google; a global service) — "leave by" estimates: When the calendar agent estimates when you should leave for an event, our servers send Google the starting point, the event's location, the travel mode and a departure or arrival time (see Section 5, "Leave by" estimates) — never your name, your account or the event's title. Google handles this data under the Google Maps Platform terms as an independent controller, not as our processor, and may process it outside the EU; Google's privacy policy applies.
- Google Search (Google; a global service) — Watches: Where Watches are available to you, a watch you set up is checked on the schedule you choose using Grounding with Google Search, through Google Vertex AI (see Google Cloud Platform above). Google receives only the watch's search — what you are looking for, the place and the requirements you set — never your name, email address or account. Google Search is a global service, so these searches may be processed outside the EU.
- AirLabs: Real-time flight status enrichment (gate, terminal, delay). Only flight numbers or departure airport codes are transmitted.
- Firebase / Google (US): App Check device attestation to prevent API abuse. No personal data is collected beyond the attestation token.
7. Cookies & Tracking Technologies
- Website (yukihq.com) & Docs (docs.yukihq.com): Three complementary tools, all privacy-friendly: Cloudflare Web Analytics for cookieless traffic measurement (pageviews, sources, top pages), Microsoft Clarity for heatmaps and session recordings to improve layout, and Google Analytics 4 for counting Download-button clicks by store and by page. Clarity is configured in cookieless mode and automatically masks form inputs. GA4 defaults to denied consent (no "_ga" cookie is set) and Google Ads/advertising features are permanently disabled — it is used strictly for anonymous, aggregate click counts, never for advertising or cross-site tracking. No advertising cookies or ad-retargeting trackers are used on either site.
- Mobile App: The Yuki mobile app does not use cookies. PostHog analytics data is stored locally on your device using file-based persistence. You can opt out of analytics tracking at any time via Profile > Privacy & Data > Analytics Tracking.
- Web App (yukihq.com/app): When you are signed in, PostHog analytics data is kept in your browser's local storage (no cookie). Where consent is required — for example in the EEA, the UK and Switzerland — it starts only after you accept analytics in the cookie banner; elsewhere you can decline there at any time. You can also opt out via Settings > Account > Data & privacy > Analytics Tracking, or change your choice under Cookie settings on the same screen.
- Sentry (Crash Reporting): Sentry is classified as an essential service for application stability. Crash reports are linked to an internal user ID, not to your name or email address. It operates regardless of analytics preferences.
- Install Attribution (AppsFlyer): On iOS, the App shows the system App Tracking Transparency (ATT) prompt before it starts AppsFlyer. If you allow tracking, AppsFlyer also receives your IDFA; if you don't, it doesn't — but it still receives the events and the other device and installation identifiers described in Section 6. We use AppsFlyer only to measure and improve our own ad campaigns and to open the right screen when you install the App from one of our links; the App shows no ads. The Analytics Tracking setting in Profile > Privacy & Data does not switch AppsFlyer off: on iPhone, you can turn tracking off at any time in Settings > Privacy & Security > Tracking, and on Android you can reset or delete your advertising ID in your device settings.
- No Advertising in the App: The App shows no ads, and neither the App nor our websites use advertising cookies or retargeting pixels. The only advertising-related tool is AppsFlyer, which measures our own ad campaigns as described above.
8. Google API Services User Data Policy
Yuki's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- No Sale of Data: We never sell, rent, or trade your personal data or Google API data.
- No Advertising: We never use your Google data — or anything else you keep in Yuki, such as your emails, calendar, contacts or chats — for advertising, retargeting, or interest-based profiling. (The install and subscription events we use to measure our own ad campaigns are described in Section 6, "AppsFlyer".)
- No Human Access: Humans do not read your emails. Automated systems process email text solely for feature delivery. When fixing a problem, our engineers may see limited details in service logs, such as an email's ID or a detail extracted from it — never its subject line, sender or text.
- No AI/ML Training: Your Google data is never used to develop, train, or improve AI/ML models, whether ours or third-party.
- Minimum Necessary Scopes: We request only the scopes required for the features you use (gmail.readonly, gmail.send, calendar, contacts.readonly).
9. Data Retention & Deletion
- Derived insights are retained as long as your account is active.
- The body of an email is never stored: it is held in memory only while it is processed. The extracted details, identifiers, subject lines and attached travel and finance documents described in Section 2 are kept while your account is active; service logs are kept for a limited time.
- Yuki Agent records: Activity keeps a record of every action Yuki proposes or takes for you — what its card showed, whether it was approved or declined, and the outcome — while your account is active. The record of each browser-agent task (your request, the website, the steps Yuki reported, the outcome and the browser's region) is also kept while your account is active; its screenshots are deleted 7 days after the task ends. Yuki does not copy your Google Calendar into our database, and route answers from Google Maps Platform are never written to it.
- Google API tokens are encrypted at rest using AES-256-GCM. On account deletion, we call Google's revocation endpoint with your refresh token, which terminates the entire OAuth grant — all access and refresh tokens, all scopes, all sessions — not just the short-lived access token. You can verify Yuki has been removed from the list of authorised apps at myaccount.google.com/permissions. You can also revoke at any time without deleting your account by tapping Disconnect in Profile > Connect Gmail & Calendar; we immediately call Google's token revocation endpoint and clear our stored copy.
- Bank connections: The accounts, balances and transactions read from a connected bank are kept while the bank is connected; the reference that lets Yuki read it is encrypted at rest (AES-256-GCM). They are used to show your spending, balances and debts in the App, to answer your questions about them in Yuki AI, and — for current and savings accounts, unless you switch an account to "Don't count in my total" — to add each day's balance to your net-worth check-ins; card and loan balances are shown as debts. To sort transactions into categories, merchant names Yuki has not seen before are sent to Google Vertex AI in the EU. When you disconnect a bank, the consent is ended at Enable Banking and the accounts, balances and transactions read from it are deleted; from that day the bank no longer counts in Your total, while balances already added to earlier net-worth check-ins stay there as history until you edit or delete them. Deleting your account ends every bank consent and deletes all of this.
- Group data lifecycle on account deletion: in groups with other members, your activity log entries are deleted (other members no longer see "Alice added a task" entries authored by you). Tasks and expenses you created or paid for remain for accounting continuity but are anonymized — your user ID is removed from expense splits, your name and avatar are scrubbed from activity metadata, and your reference is cleared from any task you owned or were assigned to. Groups where you were the sole member are hard-deleted along with all their content.
- Support chat retention: In-app Support chat threads (your messages + AI/agent responses) are anonymized but retained for up to 5 years after account deletion for fraud prevention and dispute defense, on the basis of our legitimate interest under GDPR Article 6(1)(f). The link to your identity (user_id) is removed; remaining content cannot be tied back to you. You can request earlier deletion by emailing [email protected].
- You may delete your account at any time via Profile > Privacy & Data > Delete Account. Deletion is immediate and permanent: confirming the action runs the full erasure described in this section in a single transaction (cascade across all data tables, drop of your auth row, anonymization of activity in shared groups).
- Subscription handling on deletion:
- Paddle (web-only) subscriptions: Paddle is the Merchant of Record for purchases made at yukihq.com only; it is not used inside the iOS or Android apps. For users who subscribed on the web, the Paddle subscription is automatically cancelled server-side before the data cascade runs, so you don't accrue further charges. If the cancellation call fails (rare — network or Paddle outage), the account deletion is aborted so you are never left in a "data deleted but still being billed" state.
- App Store and Google Play subscriptions: Apple and Google policy prohibits third-party apps from cancelling store subscriptions on your behalf. To prevent accidental data deletion while billing continues, the app performs a pre-flight check: if an active App Store or Play Store subscription is detected, deletion is blocked and you are directed to cancel the subscription first in Settings > [Your Name] > Subscriptions (iOS) or Play Store > Account > Payments & subscriptions > Subscriptions (Android). Only once the store subscription is cancelled does the in-app deletion proceed.
- Manual deletion requests can be sent to [email protected] and will be processed within 30 days.
10. Your Rights (GDPR & Global)
As an Estonian company, we uphold your rights under the General Data Protection Regulation (GDPR) regardless of your location:
- Right to Access: Request copies of the personal data we hold about you.
- Right to Erasure ("Right to be Forgotten"): Delete your account and all data via the app or by contacting us.
- Right to Data Portability: Request a copy of your structured data by contacting [email protected].
- Right to Rectification: Correct inaccurate personal data within the App or by contacting us.
- Right to Restriction: Request limitation of how we use your data.
11. Data Transfer & Location
Our database and file storage (Supabase, on AWS in Frankfurt, Germany) and our backend (Google Cloud, europe-west1, Belgium) are located in the European Union, and Yuki's AI features run on Google Vertex AI in the EU, except recipe suggestions for users outside the EU/EEA, the UK and Switzerland (see Section 5). Some providers listed in Section 6 are based outside the EU or run global services — for example OpenAI, RevenueCat, HelpScout, AppsFlyer and Resend, Nuitee for hotel bookings, Duffel for flight bookings, Google Maps Platform for "leave by" estimates, Google Search for Watches, and Browserbase when the browser agent opens a site outside Europe — so what they receive, as described there, may be processed outside the EU. When personal data goes to a provider outside the EU/EEA, the transfer relies on an adequacy decision of the European Commission (for example for the United Kingdom), on the provider's certification under the EU–U.S. Data Privacy Framework, or on the European Commission's Standard Contractual Clauses. Where a recipient acts as an independent controller — such as the hotel or airline you book, or Google Maps Platform — its own terms and privacy policy govern its use of the data. You can ask us for details of these safeguards using the contact details in Section 13.
12. Regional Compliance
- EU / UK (GDPR): We adhere to GDPR principles. Our lawful basis for processing is contract fulfillment and, where applicable, consent.
- India (DPDP Act): We comply with the DPDP Act, aligning with the duties of a Data Fiduciary.
- US (CCPA): California residents have the right to know, delete, and opt-out. We do not sell personal information.
- Brazil (LGPD): We comply with Brazil's General Data Protection Law regarding consent, data subject rights, and cross-border transfers.
- Rest of World: We apply the highest standard of protection defined in this policy globally.
13. Data Controller
YukiSoftware OÜ
Registry Code: 17417945
Harju maakond, Tallinn, Kesklinna linnaosa, Uus-Sadama tn 21-207, 10120
Estonia, European Union
Email: [email protected]
14. Governing Law
This Privacy Policy shall be governed by and construed in accordance with the laws of the Republic of Estonia and the applicable laws of the European Union, including the General Data Protection Regulation (GDPR). Any disputes arising from this policy shall be subject to the exclusive jurisdiction of the courts of Harju County, Tallinn, Estonia.
15. Changes
We may update this policy to reflect changes in our practices or features. Material changes will be communicated via in-app notification. Continued use after changes constitutes acceptance.