YAKKL Privacy Policy
How YAKKL collects, uses, discloses, retains, and protects personal data.
This Privacy Policy explains how YAKKL, Inc. ("YAKKL," "we," "us," or "our") collects, uses, discloses, and protects personal data when we act as a controller or business for YAKKL websites, individual accounts, self-service Services, sales, marketing, support, billing, security, and our own business operations.
This Policy does not govern personal data in Customer Data that YAKKL processes solely on behalf of a business customer as its processor or service provider. That processing is governed by the customer's agreement and YAKKL Data Processing Addendum ("DPA"). If your employer or another organization provides your YAKKL workspace, consult that organization; its administrators may control your account, settings, Content, and activity records.
"Services" means YAKKL software, applications, websites, AI development and orchestration features, Ari features, APIs, cloud storage, model routing, managed execution, BYOK/custom-endpoint capabilities, deployment, hosting, support, and related services.
1. Data paths matter
YAKKL is designed to support multiple data paths:
- Local use. Content stored and processed only on your device or environment is not collected by YAKKL. The application may separately send operational telemetry, diagnostics, and usage data described in Section 2.B; that data is designed to exclude Content.
- Direct BYOK. BYOK defaults to direct routing unless you select another supported route. When a customer-controlled client sends a request directly to a customer-selected provider using customer credentials, the request and response payloads — prompts, Content, and completions — travel from the client to that provider, and YAKKL does not receive those payloads merely because the YAKKL client initiated the connection. Operational telemetry, diagnostics, and usage data described in Section 2.B may still be sent to YAKKL and are designed to exclude Content.
- Custom endpoint. If you choose your own endpoint, its operator controls the data it receives under its terms.
- YAKKL cloud or managed routing. When you enable YAKKL cloud storage, logs, retrieval, managed execution, or hosting, YAKKL and applicable service providers process the data required for those features.
- Hybrid use. A workflow may combine these paths. Settings, product notices, usage records, or documentation identify the applicable path at a level reasonably sufficient for your choices.
2. Personal data we collect
The data collected depends on the Services and settings you use.
A. Data you provide
- Account and profile data: name, username, email address, authentication method, organization, role, preferences, and account identifiers.
- Billing data: billing contact, plan, purchases, invoices, payment status, tax information, and transaction identifiers. Payment processors receive payment-card or bank details; YAKKL generally receives limited payment confirmation and identifiers.
- Customer Content: prompts, responses, messages, source code, repository content, files, plans, artifacts, uploads, feedback, hosted content, and other material you choose to send to YAKKL-controlled cloud or managed Services. Customer Content may contain personal data.
- Support and communications: messages, attachments, call or meeting records where disclosed, survey responses, security reports, and other communications.
- Sales and business contacts: employer, title, business contact details, purchasing interests, and relationship records.
- Marketing choices: subscriptions, consent records, event registrations, and communication preferences.
B. Data generated through the Services
- Actions and tool records: tool calls, commands, file or repository operations, approvals, deployments, integrations, third-party service interactions, results, timestamps, and audit records for cloud or managed features.
- Usage and metering data: features used, model/provider selected, execution mode, request timing, approximate input/output or work measurements, CU consumption, retries, cache behavior, latency, errors, and reconciliation records.
- Logs and diagnostics: IP address, device and application information, operating system, browser, version, crash data, performance, security events, and error logs.
- Security and fraud-prevention signals: device and connection characteristics and interaction signals collected during sign-up, sign-in, and checkout — such as challenge responses and input timing and movement patterns — used solely to detect automated activity, fraud, and unauthorized purchases, and retained only as long as needed for those purposes.
- Cloud workspace data: conversation history, plans, indexes, embeddings, caches, artifacts, workspace membership, permissions, and retention settings when enabled.
- Hosted-service data: domains, deployment configuration, content, traffic records, and security logs when you use hosting.
C. Data from others
We may receive data from identity providers, model or infrastructure providers, integrations you connect, business-account administrators, payment processors, analytics and communications providers, security vendors, public sources, and business partners. The data depends on the connection and your settings.
3. How we use personal data
We use personal data to:
- provide, personalize, maintain, route, secure, and support the Services;
- authenticate users; administer accounts, workspaces, subscriptions, seats, and permissions;
- process payments, CU usage, reconciliation, taxes, and invoices;
- execute instructions, tool calls, deployments, storage, retrieval, and hosting selected by users;
- detect, investigate, and prevent fraud, abuse, security incidents, and policy violations;
- diagnose failures, improve reliability, allocate capacity, and understand feature and model usage;
- communicate about transactions, security, legal changes, support, and Service updates;
- send marketing where permitted and honor preferences;
- comply with law, enforce agreements, establish or defend legal claims, and respond to lawful process;
- protect people, YAKKL, customers, and third parties; and
- conduct corporate transactions, diligence, accounting, audit, and business administration.
No AI training. YAKKL does not use Customer Content or Output to train AI models and does not authorize third parties to do so on YAKKL's behalf. Product analytics and de-identified Usage Data do not include Customer Content.
Limited personnel access. YAKKL personnel do not inspect Customer Content as part of ordinary product analytics. Personnel access is limited to support you request, security or abuse investigation, legal compliance, or operation of a managed feature that cannot be provided through automated processing alone. Access must be authorized and appropriately logged or recorded.
4. De-identified Usage Data
YAKKL may aggregate or de-identify Usage Data so it cannot reasonably identify you, a user, or an organization. YAKKL may own, retain, and use that data for feature analytics, model-selection statistics, traffic, capacity, reliability, security, routing, product planning, and billing operations. YAKKL will not attempt to re-identify it except to test and improve de-identification safeguards or as required by law.
De-identification is not achieved merely by removing a name. YAKKL must apply reasonable technical and organizational measures appropriate to the data and re-identification risk.
5. Legal bases for processing
Where a legal basis is required, we process personal data as follows:
- Contract: to provide requested Services, administer accounts, process purchases, and perform our agreements.
- Legitimate interests: to secure and improve the Services, prevent abuse, support customers, manage the business, communicate about related Services, and establish or defend claims, balanced against individual rights.
- Consent: for optional cookies, certain marketing, and other processing where consent is requested. Consent may be withdrawn prospectively.
- Legal obligation: to comply with tax, accounting, sanctions, regulatory, law-enforcement, and other legal duties.
- Vital interests or public interest: when necessary to address an emergency or another legally recognized public-interest basis.
6. How we disclose personal data
We may disclose personal data to:
- Service providers and subprocessors supporting AI model execution, cloud infrastructure, hosting, storage, security, identity, analytics, support, communications, payment processing, tax, compliance, and IT. Current providers and purposes are maintained in the subprocessor/service-provider register rather than hard-coded in this Policy.
- Customer-selected third parties when you direct a BYOK request, custom endpoint, integration, deployment, repository operation, communication, or other Action.
- Business-account administrators who can manage the workspace and may access Content, activity, settings, billing, and account information according to their permissions.
- Other users and the public when you share, collaborate, publish, deploy, host, or make Content public.
- Professional advisers and transaction parties for legal, accounting, audit, insurance, financing, merger, acquisition, reorganization, bankruptcy, or asset-sale purposes under appropriate duties.
- Authorities and other parties when reasonably necessary to comply with law or lawful process; protect rights, safety, and security; investigate fraud or abuse; or enforce agreements.
YAKKL does not sell personal data and does not share personal data for cross-context behavioral advertising. YAKKL does not use personal data for targeted advertising or place third-party advertisements in the Services. If these practices change, YAKKL must update this Policy and provide legally required choices before the change.
7. AI providers and changing vendors
AI and infrastructure providers change frequently. Listing every vendor in the body of a privacy policy would become inaccurate and is not the correct control. YAKKL maintains a separate register identifying current YAKKL-controlled service providers/subprocessors, their purpose, processing location where relevant, and update date.
For direct BYOK and custom endpoints, you select the recipient. Its own terms, retention, safety review, and privacy practices apply. YAKKL cannot control or guarantee those practices.
For YAKKL-managed routing, applicable providers act under YAKKL's commercial and data-processing arrangements where required. Providers may use automated safety classifiers. Content flagged for suspected abuse may be retained and reviewed by authorized personnel for the limited time reasonably necessary to investigate, secure the Services, enforce policy, or comply with law. Abuse review does not permit model training.
8. Retention and deletion
YAKKL retains personal data only as long as reasonably necessary for the purposes described, considering the Service and plan selected; customer settings and deletion requests; sensitivity and risk; security, fraud, and abuse needs; legal, accounting, tax, and contractual requirements; backups; disputes; and limitation periods.
- Customer Content stored only on your device remains until you delete it.
- Customer Content stored in YAKKL cloud follows the retention period shown for the plan, workspace, or feature. You may delete eligible Content through available controls at any time.
- A plan downgrade may shorten future retention. YAKKL will provide reasonable notice or export opportunity where practicable.
- Deleted data may remain for a limited time in encrypted backups, security records, legal holds, billing records, or incident evidence before deletion or de-identification.
- De-identified Usage Data that is no longer personal data may be retained indefinitely.
Exact tier-specific cloud retention periods should be displayed in the Service and incorporated into the applicable order. They may change prospectively with plan changes but must not contradict this Policy.
10. Security
YAKKL uses reasonable administrative, technical, and organizational safeguards appropriate to the nature and risk of personal data. No system is completely secure. You are responsible for protecting devices, accounts, credentials, BYOK keys, custom endpoints, repositories, permissions, and backups under your control.
Report suspected vulnerabilities to security@yakkl.com. Do not send credentials or unnecessary personal data in a report.
11. International data transfers
YAKKL is based in the United States and may process data in the United States and other countries where YAKKL or its service providers operate. Laws in those countries may differ from your location.
Where required, YAKKL uses recognized transfer mechanisms such as adequacy decisions, the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum or other lawful UK mechanism, and supplementary safeguards. Business-customer transfers are addressed in the DPA.
12. Your rights and choices
Depending on where you live and applicable law, you may have rights to:
- know or access personal data and processing information;
- receive a portable copy;
- correct inaccurate personal data;
- delete personal data;
- object to or restrict processing;
- withdraw consent;
- opt out of sale, sharing, or targeted advertising;
- limit certain uses of sensitive personal data;
- not be subject to solely automated decisions with legal or similarly significant effects;
- appeal a denied privacy request; and
- lodge a complaint with a data-protection authority.
YAKKL will not discriminate against you for exercising applicable rights. Submit a request to privacy@yakkl.com or through available account controls. We may confirm identity and authority. An authorized agent may submit a request where law permits. If we deny a request, you may appeal by replying with "Privacy Appeal."
Some data may be exempt, and certain data must be retained for security, billing, legal, or other lawful reasons. If YAKKL processes data only for a business customer, direct your request to that customer; YAKKL will assist as required by the DPA.
You may unsubscribe from marketing emails using the link in the message. Account, security, billing, and legal communications may continue. Cookie choices may be changed through the consent center.
13. Children
The Services are not directed to people under 18, and YAKKL does not knowingly collect personal data from children through the Services. Contact privacy@yakkl.com if you believe a child provided personal data. Any future education or minor-facing service requires separate review, notices, age assurance, and consent controls before launch.
14. Third-party services and public content
This Policy does not govern independent third-party services, customer-selected providers, custom endpoints, integrations, websites, or public repositories. Review their policies before sending data. Information you publish or share publicly may be copied and retained by others beyond YAKKL's control.
15. Changes
YAKKL may update this Policy as Services, data practices, vendors, or law change. We will update the effective date and provide additional notice for material changes where required. We will request consent before materially different processing when law requires it.
16. Contact
- Privacy questions and rights: privacy@yakkl.com
- Support: support@yakkl.com
- Legal notices: legal@yakkl.com
- Security reports: security@yakkl.com
YAKKL, Inc.