Privacy
Privacy Policy
This policy explains what yaya collects, why it is collected, who receives it, and how you can ask us to delete it.
Effective July 28, 2026. Last updated July 28, 2026.
Who we are
yaya is a macOS app and related website operated at useyaya.app. If you have privacy questions, contact support@useyaya.app.
What we collect
- Account data: your email address, password hash, session records, and account creation date.
- Text you submit: text you ask yaya to translate, rewrite, audit, or read aloud so the request can be processed.
- Usage and operational data: request counts, selected action type, input length, language pair, request source, rate-limit state, and app-open events.
- Purchase and entitlement data: Stripe customer and subscription identifiers, selected plan, payment status, access expiration, and billing events.
- Support communications: any information you send when you email us for help.
- Local app settings: preferences such as selected languages, backend URL, sign-in state, and any optional Bring Your Own Key configuration stored on your device.
How we use your data
- To create and secure your account.
- To provide translations, writing review, and speech generation.
- To enforce trial limits, subscriptions, and restore purchases.
- To prevent abuse, apply rate limits, and investigate failures.
- To understand app usage at an operational level, such as app opens and plan activity.
- To answer support requests and process deletion requests.
What yaya stores and what it does not
- For hosted requests, submitted text is processed transiently to produce the response.
- yaya's server-side database stores usage metadata such as action type, character count, language pair, source, entitlement state, and app-open events. It does not store the full text of each translation or review request as part of those usage logs.
- If you email support, the content of that email is retained as part of your support history.
When your data is shared
We do not sell your personal information and we do not use third-party advertising or cross-app tracking.
- Hosted yaya requests:when you use Pro or the hosted trial, the text you submit is sent through yaya's backend to OpenAI to generate the response.
- Bring Your Own Key mode:if you add your own OpenAI API key, the app can send your text directly to OpenAI using your key instead of routing the request through yaya's hosted model path.
- Stripe billing: Stripe processes checkout, payment methods, subscriptions, invoices, and the customer billing portal. yaya does not receive or store your full card number.
- Infrastructure providers: yaya uses hosted infrastructure to store account, session, entitlement, and operational records needed to run the service.
Retention
- Account, entitlement, and session records are kept while your account is active.
- Operational usage records and app-open events are retained as needed to run the service, monitor limits, understand product activity, and handle support issues.
- Support emails are retained as needed to resolve the issue and maintain a support history.
- If you request account deletion, we delete or de-identify account-linked records unless we need to retain some information for legal, security, accounting, or fraud-prevention reasons.
Your choices
- You can choose not to create an account, but hosted app features will not work.
- Basic app-open analytics are off by default. You can opt in or turn them off at any time in the app's Settings.
- You can use Bring Your Own Key mode instead of the hosted model path, subject to OpenAI's terms and your own API billing.
- You can ask us to delete your account from the app or through the instructions on the Delete account page.
- You can manage or cancel a subscription through the Stripe billing portal opened from yaya Settings.
Security
We use reasonable administrative and technical safeguards for the service, but no method of storage or transmission is guaranteed to be perfectly secure. Keep your device and account credentials secure.
On macOS, optional local secrets such as your Bring Your Own Key API key and active session token are stored on-device using macOS secure storage when available.
Changes
We may update this policy as the product changes. When we do, we will update the date at the top of this page.