This is the long version: every category of data YanMate holds, why we hold it, who else touches it, how long it stays, and what you can make us do about it.
Privacy is the short version, and it is the one to read first — it is the same facts in the space of a page. This document exists because "we don't do anything creepy" is not a lawful basis, a retention period, or a list of processors, and a regulator, a reviewer or a careful user is entitled to all three.
Status: structure, not counsel. Everything below describes what the service actually does, checked against the code rather than the intention. It has not been reviewed by a data protection lawyer, and the sections marked Incomplete — pending turn on decisions we have not made yet. Where this notice and the short one disagree, this one is wrong and should be corrected: the short page is checked by a test against the running system.
Who is responsible for your data
Incomplete — pending. The controller's legal name, registered address and company number go here, along with an EU/UK representative if one is required once launch markets are settled. Until then, reach us at support@yanmate.com.
What we collect
What you give us
| Data | When |
|---|---|
| Email address | Creating an account, and for sign-in, security notices and receipts |
| Display name | Creating an account; shown to you and on anything you publish |
| Password hash, or a Google account identifier | However you chose to sign in. We never see a Google password, and we never store yours in a readable form |
| Two-factor secret and recovery codes | Only if you turn 2FA on |
| Birth year | At sign-up. Never the full date |
| Characters, companions, greetings, scene notes | Whenever you write or import one |
| Conversations | Every message you send, and every reply |
| Voice notes and call audio | Only when you record or call |
| Uploaded and generated pictures | Avatars, backdrops, and pictures you generate |
| Appeal text | If you appeal a moderation decision |
| Payment details | Not to us. They go to Polar, our payment provider — see who else sees it |
What the product generates about you
| Data | What it is |
|---|---|
| Memory Ledger | Facts your companion has learned, visible and editable by you, with an audit trail of every change |
| Vector index of your memories | A per-account namespace so your companion can recall the right thing. Destroyed with the account |
| Credit and usage counters | What you have spent this month, and on what surface |
| Entitlements and plan state | Which plan you are on and when the period ends |
| Moderation and safety records | The rule that fired, the surface, and a hash of what was checked. Never the content |
| Enforcement history | The actions taken on your account and their appeals |
What we collect automatically
| Data | Why it exists |
|---|---|
| IP address | Delivered with every request. Used for rate limiting, abuse control, and to work out which country's minimum age applies |
| Approximate country | From the network request, not from a lookup on you |
| Session and device records | So you can see every signed-in session on your account page and end the ones you do not recognise |
| Request and error logs | Operating the service. Short-lived |
| Product and cost telemetry | Which features get used and what an interaction costs to serve — see processors, because this one leaves our systems |
What we never collect: identity documents, selfies, face scans, biometric templates, precise location, contacts, or anything from your device beyond the browser request itself.
Why we process it, and on what basis
| Purpose | Basis under UK/EU law |
|---|---|
| Running your account and the product you asked for — companions, conversations, memory, voice, pictures | Performance of a contract |
| Taking payment, issuing refunds, keeping billing records | Performance of a contract, and a legal obligation for the accounting records |
| Screening content for the content policy, and acting on what the screen finds | Legal obligation, and our legitimate interest in a service that is safe to be in |
| Applying the minimum age, and acting on an under-age signal | Legal obligation, and the legitimate interests of children |
| Security: rate limits, the bot check, session records, security emails | Legitimate interests in keeping accounts and the service intact |
| Product and cost telemetry | Legitimate interests in knowing what the product costs and which parts of it work. No consent is asked for this because nothing is stored on or read from your device — the measurement is server-side. You may object: see your rights |
| Advertising, if the free tier is ever ad-funded | Consent, asked for before any ad code loads. Not legitimate interests |
| Answering you when you get in touch, and deciding appeals | Performance of a contract, and legitimate interests |
Where we rely on legitimate interests, you can object — see your rights. Where we rely on consent, you can withdraw it, and withdrawing is as easy as giving it.
Who else sees it
Everyone we send data to, what they get, and what for. This list is exhaustive for personal data; if it changes, this notice changes with it.
| Who | What they receive | What for |
|---|---|---|
| Cloudflare | Effectively everything: the application runs on their network, and your account, characters, conversations, memory index, pictures and the models that answer you all sit inside it | Hosting, database, object storage, the vector index, all AI inference including your companion's replies, speech-to-text on voice notes and calls, the safety classifiers, the bot check, and transactional email |
| Fish Audio | The text your companion is about to speak | Turning a reply into audio, for spoken messages and live calls. It receives the words, not your account |
| Polar | Your email address, and the payment details you give them directly | Taking payment as merchant of record, subscriptions, invoices, refunds. Card numbers never reach us |
| PostHog | Product and cost events, keyed to an internal account number. No IP address, no device data, no content | Product and cost telemetry. Sent from our servers, never from your browser, and to their EU cloud — see where |
| An account identifier and email, only if you choose "Sign in with Google" | Signing you in | |
| Your browser's push service | An opaque push subscription, only if you turn on notifications | Delivering a notification. Which service depends on your browser — typically Google, Mozilla or Apple |
No model provider outside Cloudflare sees your conversations. Every model that reads or writes in this product — your companion, the safety classifiers, the transcription, the embeddings — runs on Cloudflare Workers AI. There is no call to OpenAI, Anthropic, Google or anyone else with your text in it.
We do not sell personal information, and we do not share it for cross-context behavioural advertising. There is no ad network in the list above because no advertising code is loaded on any page today.
We may also disclose data to professional advisers under confidentiality, to authorities where the law requires it, and to a buyer if the business is ever sold — in which case this notice travels with it and you are told before anything changes.
Where it is processed
The application runs on Cloudflare's network, which is global by design: a request is served near you, and stored data lives in the region Cloudflare places it in for the account.
Analytics is on PostHog's EU cloud, and so does not leave the EEA at all. It ran on their US cloud until 25 August 2026; that transfer is closed rather than papered over. What goes there is an internal account number and event metrics — not your IP, not your name, not anything you wrote.
The other processors are not all in Europe. Polar takes payment from the United States. Google sees an account identifier if you chose to sign in with them. Fish Audio receives the text of anything spoken aloud. Each is listed with what it receives in who else sees it, and each involves data leaving the UK and EEA.
Incomplete — pending. The transfer mechanism relied on for those processors — standard contractual clauses, the UK addendum, or an adequacy decision — is named here once the controller above exists and the data processing agreements are signed. It no longer applies to analytics, which is the one we could remove by moving rather than by paperwork.
How long we keep it
| What | How long |
|---|---|
| Your account, characters, conversations, memory, pictures | Until you delete them, or delete the account. Deletion is immediate and unrecoverable |
| An account you never signed up for — browsing anonymously | Hard-deleted automatically after 30 days with no activity, along with its companions and chats |
| Your birth year | For the life of the account |
| A birth year that was refused | Deleted at once. We keep only the fact that the account was turned away |
| Moderation and safety records | Kept after account deletion with your user id removed — a rule name, a timestamp and a hash, linked to nobody. We are required to keep the counts; we are not required to keep them attached to you |
| Billing records | For as long as tax and accounting law requires, which is measured in years. Polar holds their own copy as merchant of record |
| Operational job records | 90 days |
| Request and error logs | Short-lived, and not used to build anything about you |
Automated decisions, and your right to a person
Content on YanMate is screened by classifiers, automatically, before it is saved or shown. Those checks can block a message, refuse a character, or — for a behavioural under-age signal — put an account on hold. That is automated processing, and we would rather say so than describe it as "systems".
What you get in return is built into the product rather than promised here:
- Every action names the rule that fired, in plain language, at the moment it happens.
- A person reviews it on appeal, within 72 hours, and writes you a note in their own words. Not the classifier again.
- If we got it wrong, we reverse it — and refund the paid time you lost, pro rata, without you asking.
The one exception is the under-age hold, which is settled by a person you reach rather than through the appeal form. It is named in moderation and appeals for the same reason it is named here.
Your rights
Wherever you live, you can:
- See what we hold — export gives you one file with every character, transcript, Memory Ledger entry and billing record.
- Correct it — your account details and the Memory Ledger are editable by you, entry by entry.
- Delete it — self-serve, immediate, and permanent.
- Take it elsewhere — the export is machine-readable JSON.
- Object to processing we base on legitimate interests — product analytics included — and withdraw any consent you have given. Email support@yanmate.com and say so; it is not a setting we grant, it is a right you exercise.
- Complain — to us first, and to your data protection authority if we do not fix it.
Export and delete are both on your account page, neither is behind a plan, and both work on a lapsed account and on an account under moderation review. That is deliberate: a right you have to email someone for is a right with a queue in front of it.
Some jurisdictions add to this list. See the annexes below.
Children and young people
YanMate is open from 13, higher where local law says so, and relational or romantic companions are 18 and over. How a 13-to-17 account is treated differently — what it cannot reach, what is switched off, and what we do not collect — is set out in children and young people.
Cookies and similar technologies
What is set, by whom, for how long, and how to refuse it is in the cookie policy.
Worth stating here too, because it decides which rules apply: we set no analytics or advertising cookie and store no analytics identifier on your device. The rules that require a consent banner are triggered by storing or reading information on your equipment, and this product does neither for any purpose beyond keeping you signed in and remembering your interface preferences.
Changes to this notice
Every version of this notice is kept in version control, so what changed and when is a matter of record rather than of trust. For a change that materially affects you we give notice before it takes effect.
Contact
- Privacy questions, and rights requests we haven't built a button for: support@yanmate.com.
- Copyright and takedowns: the same address with "DMCA" in the subject line — full process in copyright and DMCA.
Annex: UK and EEA
If you are in the UK or the European Economic Area, the UK GDPR or the GDPR applies to you, and the legal bases in why are the ones we rely on.
In addition to your rights above, you have the right to restrict processing, and the right not to be subject to a decision based solely on automated processing that has legal or similarly significant effects — see automated decisions for how that is answered here.
You can complain to a supervisory authority. In the UK that is the Information Commissioner's Office (ico.org.uk). In the EEA it is the authority for the country you live in. You can do that without going through us first, though we would rather you told us.
Incomplete — pending. Whether a UK or EU representative under Article 27 is required, and who it is, is decided with the launch markets. So is the lead supervisory authority, if one applies.
Annex: California
If you are a California resident, the CCPA as amended by the CPRA gives you specific rights, and specific things we have to tell you.
Categories of personal information we have collected in the last 12 months: identifiers (email, account id, IP address); commercial information (plan, purchases, credits); internet activity (feature usage and cost telemetry); audio (voice notes and call audio you record); and user content (characters, conversations, the Memory Ledger). We collect them for the purposes in why, from you and from your device.
We have not sold personal information, and we have not shared it for cross-context behavioural advertising — in the last 12 months or ever. If the free tier becomes ad-funded, that changes only with your consent and this notice changes first, with a "Do Not Sell or Share" control on your privacy choices.
Sensitive personal information. We treat your birth year and your account credentials as sensitive, use them only to run the service and apply the age floor, and never to infer characteristics about you.
Your rights: to know, to delete, to correct, to opt out of sale or sharing, and to limit the use of sensitive personal information — all covered by the self-serve controls above. We will not discriminate against you for exercising them: the service, the price and the plan are identical either way. An authorised agent may act for you with proof that you asked them to.
Annex: Philippines
The Data Privacy Act of 2012 applies if you are in the Philippines. You have the right to be informed, to object, to access, to correct, to erasure or blocking, to damages, and to data portability — the controls in your rights cover all of them, and the export is portable by design.
You may withdraw consent where we rely on it, without affecting the service you get for anything we do not.
You can complain to the National Privacy Commission. You can also ask us to route a request through a person rather than the self-serve controls, and we will.
Incomplete — pending. Whether registration with the National Privacy Commission is required, and naming a Data Protection Officer, is decided with the launch markets. The DPA requires one of controllers processing personal data at scale.
Annex: Brazil
The LGPD applies if you are in Brazil. Its lawful bases map onto the ones in why: execution of a contract, legal obligation, legitimate interests, consent for advertising, and the protection of children, which the LGPD singles out and so do we.
You have the rights of confirmation, access, correction, anonymisation, portability, deletion, information about sharing, and the right to review decisions made by automated processing — the last of which is answered in automated decisions by a person who writes you a note.
You can complain to the ANPD.
Incomplete — pending. Naming an encarregado (data protection officer) is an LGPD requirement and is decided with the launch markets.
Annex: Indonesia
Law No. 27 of 2022 on Personal Data Protection applies if you are in Indonesia. You have the rights to information, access, correction, erasure, withdrawal of consent, objection to automated decision-making, and portability. The controls in your rights cover them, and the automated-decision answer is the same person who reads your appeal.
Incomplete — pending. The PDP Law's controller-registration and local-representative duties, and whether they attach at our scale, are part of the same launch-markets decision as the annexes above.