Your data, plainly.
We don't train on your work, we don't delete it on a timer, and you can take all of it with you. Here are the details — including the parts still being tightened.
Never trained on
Not by us, and not by default by the models we call
Signed at the write path
Every change carries its author — enforced, not conventional
No retention timer
Nothing expires on a schedule; trash holds until you empty it
Exports as plain git
Full revision history as real commits, walkable offline
Training
We never use your workspace content to train any model of ours. We don't operate models at all — we call other companies' APIs, and under each one's published API terms, content sent that way isn't used for training by default. To be precise about the mechanism: we rely on those standard terms, not on a separately negotiated contract of our own. If that distinction matters to you, read their terms directly — we'd rather point you there than paraphrase them.
Who can receive your content
When you ask an AI to work, the files it needs go to the provider running that task. This is the complete list of third parties that can receive your content or personal data. If we add one, we'll update this page.
| Who | Why | What |
|---|---|---|
| Anthropic · OpenAI · Google · DeepSeek · xAI | Run the AI task you asked for | The files needed for that task, depending on the model chosen |
| OpenAI (search indexing) | Builds the index that makes your workspace searchable | File text, as files are written |
| Supabase | Database and authentication | Your workspace contents and account |
| Render · Vercel | Application hosting | Traffic in transit |
| Sentry | Crash and error reporting | Configured to collect no personal data |
| Resend | Transactional email | Recipients and message contents |
| Lemon Squeezy | Payments | Billing details |
Deletion
Nothing expires on a schedule. Trash holds until you empty it — deliberately, because a timer means the system destroying your work with nobody watching. When you delete something permanently, or delete your account, removal is immediate rather than queued.
Access
Who can read a file is a grant you make and can revoke — not a property of what kind of principal is asking. Connected assistants reach your workspace through OAuth you approve, and every write they make is signed with their name. A connected assistant can read, write, move, delete, and share files on your behalf — the same reach you have — so connect ones you trust.
What you can take
The whole workspace exports as a standard git repository, with the full revision history as real commits — readable with tools you already have, on a machine we have nothing to do with. Conversations aren't included yet.
It's in Workspace Settings, under Danger Zone — available any day, not just on the way out. The download names anything it couldn't include, so you always know what you have.
What's not done yet
On the roadmap. Two things we're tightening, both scheduled work rather than someday-maybe: some stored file contents can persist in backing storage after deletion, and reads of private file bodies still lean on application-layer checks rather than database-level rules. We name them here because you'd have no way to find them otherwise.
Not yet started. We hold no SOC 2 or ISO 27001 certification. Those are third-party audits, and we'd rather tell you we haven't done one than let a badge imply we have — we'll pursue them when our customers need them, and we'll say so here when that work begins. A DPA or BAA isn't an audit but a signed agreement: we don't offer one off the shelf today, so if you need either, talk to us and we'll tell you honestly where we stand.
The formal version is our privacy policy. Questions: admin@yarnnn.com.