Privacy Policy
Effective Date: July 8, 2026
This Privacy Policy outlines how yarnnn ("we", "our", or "us") collects, uses, and protects your information when you use our services.
1. Information We Collect
We collect the following types of information:
- Account Information: Email address, name, and profile data from authentication providers (Google, etc.)
- Content: Documents you upload, notes and memories you save, workspace files you store, and tasks you manage — including anything you choose to save through a connected LLM assistant (see §5)
- Provenance & metadata: For each saved item, we record when it was written, which source contributed it (you, a connected assistant, or YARNNN itself), and its revision history. This attribution is core to the product
- Usage Data: How you interact with our services, features used, and work requests made
- Work Outputs: AI-generated content created through our agents and recurring tasks
2. How We Use Your Data
- Provide and improve our AI work platform services
- Generate context-aware outputs through autonomous agents and tasks
- Send service-related communications (e.g., daily updates or account notices)
- Maintain security and prevent abuse
We do not sell your personal data or share it with third parties for marketing purposes.
3. Data Storage & Security
Your data is stored using Supabase (PostgreSQL) with application and database access controls. All data transmission is encrypted via HTTPS. Connector credentials are encrypted where stored as credentials, and we continue to harden credential rotation, retention, and deletion coverage. For a plain-English overview of the architecture and its current limits, see our Privacy Architecture.
4. Third-Party Services
We use the following third-party services as data processors:
- Supabase: Authentication and database (PostgreSQL)
- Render: Application and connector hosting
- Vercel: Web hosting and analytics
- AI providers (Anthropic, OpenAI, Google, DeepSeek): when you ask an AI to work, the files needed for that task are sent to the provider running it. Which provider depends on the model chosen for the task. Content sent this way is processed under each provider's API terms, which do not use API content for training by default. We rely on those standard published terms — we do not hold a separately negotiated training prohibition with them
- OpenAI (search indexing): separately from the above, the text of your files is sent to OpenAI to build the embeddings that make your workspace searchable. This happens as files are written, not only when you ask an AI to do something
- Sentry: crash and error reporting, configured not to collect personal data
- Resend: transactional email delivery
- Lemon Squeezy: payments and billing
This list is the complete set of third parties that can receive your content or personal data. If we add one, we will update this page.
5. Connected LLM Assistants (MCP Connector)
YARNNN can be connected to LLM assistants you already use — such as ChatGPT, Claude, and others — through the open Model Context Protocol (MCP). This connection is established by you, through your assistant, using OAuth; you authenticate as yourself and the connection is scoped to your own workspace.
When a connected assistant is authorized, it acts on your behalf with the same reach over your workspace that you have. It can:
- Read your files, list and search your workspace, and view how any file changed over time
- Write new files and edit existing ones (attributed to that assistant)
- Move, rename, and delete files
- Share — mint a link to a file or the workspace, including links that grant full member access to whoever opens them
We state this plainly because it is a larger authority than "save and recall." Connect assistants you trust. Every action an assistant takes is signed with its name and kept in the file's revision history, so you can see what it did and walk it back.
What this means for your data: content you save through one assistant becomes part of your durable YARNNN memory and is therefore available to you through any other assistant you have connected, as well as in the YARNNN web app. The assistant's provider (e.g. OpenAI for ChatGPT) processes the request under its own privacy terms; YARNNN stores the resulting content and its attribution. We record which assistant contributed each item so this provenance is transparent to you. You can disconnect any assistant at any time from within that assistant's settings, which revokes its access to your workspace.
6. Your Rights
You have the right to:
- Access your personal data
- Request deletion of your account and data
- Export your content
- Opt out of non-essential communications
7. Data Retention
Nothing expires on a schedule. We do not run a retention timer: trash holds until you empty it, and no background process deletes your work after a fixed period. This is deliberate — a timer means the system destroying your work with nobody watching. If a timer is ever offered it will be a setting you turn on, not a default.
When you delete a file permanently, reset your workspace, or delete your account, removal is immediate rather than queued. Deleting your account removes your workspace files, their full revision history, and your account record. Some stored file contents may persist in backing storage after account deletion; completing that cleanup is named in our data page as current work. We retain what the law requires us to retain.
8. Changes to This Policy
We may update this policy and will notify you of material changes. Continued use after changes constitutes acceptance.
9. Contact Us
Questions about privacy? Contact us at admin@yarnnn.com