Privacy Policy

Effective Date: October 8, 2026

Last Updated: October 8, 2026

Legal Entity: YAP Technologies Holding Company, Inc., a Delaware corporation

Business Address: 6231 Residencia, Newport Beach, CA 92660, United States

This Privacy Policy explains how the legal entity identified above ("YAP," "we," "us," or "our") collects, uses, shares, retains, and protects information in connection with the YAP mobile application, the theyapapp.co website, and related services (the "Service"). It also describes privacy choices and rights. This Policy is incorporated into our Terms of Use.

The short version

1. Scope and Who This Applies To

This Policy applies to information we handle when you use the Service. It does not apply to information handled by third parties whose services you access independently, including Apple, your mobile carrier, or an app or platform to which you choose to share YAP output.

The Service is intended for users who are at least 13 years old. If you are under 18, you may use YAP only with the knowledge and consent of a parent or legal guardian, and you represent that you have obtained that consent before using the Service. YAP does not separately collect or verify a parent email or other parental-consent credential as part of the current account flow. A higher minimum age or additional parental-authorization requirement may apply in some jurisdictions; where it does, that requirement controls. See Section 14.

2. Other People in the Conversation

When you use YAP, the microphone may capture the voices of people who are not YAP users. Their audio may be transmitted off your device to YAP's infrastructure and to service providers that process audio or transcript data on YAP's behalf.

Before each recording begins, YAP requires the user to affirm in the app that everyone participating has been told about the recording/analysis and has agreed. The recording control is not enabled until that confirmation is made. You remain responsible for obtaining any consent required by applicable law. Laws concerning recording, interception, and analysis of conversations vary by jurisdiction. This Policy describes YAP's data practices; the in-app confirmation does not itself obtain consent from other participants on your behalf.

If you participated in a conversation analyzed using YAP and wish to make a privacy request, contact privacy@theyapapp.co. Our ability to identify data relating to a non-user may be limited.

3. Information We Collect

3.1 Conversational audio, transcripts, and derived analytics

When you enable a YAP session, the Service accesses your device microphone and captures conversational audio. Audio is transmitted off your device over encrypted connections for processing.

AssemblyAI. YAP uses AssemblyAI for pre-recorded/asynchronous speech-to-text processing. YAP's production account is opted out of the Model Improvement Program; under this setting, AssemblyAI states that Customer Data is not used for model training or benchmarking. After successful durable ingestion into YAP, YAP requests deletion of the AssemblyAI transcript artifact and retries failed cleanup safely. The production account also has a one-day asynchronous audio/transcript time-to-live (TTL) as a fallback. These controls do not delete the transcript saved in your YAP History or override the provider's applicable security or legal-retention obligations.

pyannoteAI. YAP's legacy pyannoteAI speaker-diarization integration is disabled in the current production configuration. YAP does not currently send conversations to pyannoteAI or use its Voiceprint or speaker-identification services.

OpenAI. YAP uses the OpenAI API to analyze transcripts and structured conversational information and generate certain results. OpenAI states that API data is not used to train or improve its models unless the customer explicitly opts in. YAP does not opt in. Applicable YAP requests are configured with storage disabled (for example, store: false where supported). Under OpenAI's standard API controls, abuse-monitoring logs may nevertheless contain customer content and may be retained for up to 30 days, unless longer retention is required by law or reasonably necessary to protect OpenAI's services or third parties. YAP has disabled OpenAI model-feedback, evaluation/fine-tuning and input/output sharing. YAP sends transcripts and structured conversational information, not raw audio, to OpenAI. Storage-disabled requests do not establish Zero Data Retention or remove OpenAI's standard abuse-monitoring retention described above.

YAP also stores the audio recording of each session privately in its own systems to provide History and recovery, until you delete your account (see Section 7). Users can view the full transcript of their own sessions in the app. YAP may retain transcripts, structured results, and derived analytics in its own systems as necessary to provide History and other user-facing features. YAP does not use conversational audio, transcripts, or derived analytics for advertising or to train YAP machine-learning models.

3.2 Speaker diarization and biometric identifiers

YAP uses speaker diarization to distinguish speakers within a conversation. Diarization determines which portions of a session were spoken by different participants; it is not intended to determine a person's real-world identity.

YAP does not identify who a speaker is. Within a session, speakers are distinguished automatically, and the user assigns names to those speakers manually. YAP does not recognize a person's voice across different sessions.

YAP does not use pyannoteAI's optional Voiceprint or cross-session speaker-identification functionality in the current product. YAP does not intentionally create or retain a persistent voiceprint, voice template, or voice embedding for recognizing a person across unrelated YAP sessions, and does not use voice data to authenticate a person or compare a participant against a biometric database.

YAP may use temporary, within-conversation acoustic comparisons on Google Cloud infrastructure to support speaker verification. Voice embeddings used for these comparisons are transient and are not stored or reused as persistent voice templates across sessions; user-confirmed speaker names remain authoritative.

We do not sell, lease, trade, or otherwise profit from voice data. If YAP later introduces persistent speaker recognition or another feature that creates or uses biometric identifiers, we will update this Policy and obtain any consent required by applicable law before enabling that feature.

3.3 Account, device, purchase, and support information

YAP creates an anonymous Supabase identity without requiring an email address, password or account registration. YAP uses an authentication identifier and the display or participant names, preferences and consent/session information you provide or select. If you contact support or make a privacy request, we also receive the contact information you choose to provide.

We may receive limited device and operational information necessary to operate and secure the Service, such as app version, operating-system version, device or installation identifiers, IP address, request timestamps, server logs, and error information. Apple may also provide diagnostics where a user has chosen to share them with developers.

YAP does not use conversation content for advertising or cross-app tracking. The app and its infrastructure may generate operational logs, error information, and diagnostics needed to run, secure, troubleshoot, and improve the Service. If YAP later adds a third-party analytics, attribution, advertising, or crash-reporting service that materially changes these practices, this Policy and applicable App Store disclosures will be updated.

If you purchase YAP+, Apple processes the payment. RevenueCat receives customer identifiers, subscription and entitlement state, transaction/product information, and device/app metadata needed to operate subscription services. YAP does not send conversation audio, transcripts or conversation results to RevenueCat, and does not receive your full payment-card number or financial-account credentials. Deleting YAP data does not cancel an Apple subscription; cancellation and restoration remain governed by Apple and the subscription service.

If you contact us, we collect the information you choose to provide, such as your email address, message content, attachments, screenshots, and related metadata.

4. How We Use Information

We use information to provide transcription, diarization, analytics, summaries and shareable results; create and secure accounts and History; manage YAP+ subscriptions; detect fraud and abuse; diagnose errors and maintain reliability; respond to support and privacy requests; send service-related communications; and comply with law and protect our rights, users, and Service.

We may create aggregated or de-identified statistics that cannot reasonably be linked to a particular person. We maintain such information in de-identified form and do not attempt to re-identify it.

5. Legal Bases for Processing

Where applicable, YAP processes personal data to perform its contract with you, based on consent where consent is required, to pursue legitimate interests such as security and service reliability, and to comply with legal obligations. Where processing could reveal special-category data, YAP relies on an applicable legal basis and, where required, explicit consent.

Where we rely on consent, you may withdraw it at any time without affecting processing already carried out. For minors in the EEA or UK, the age at which a child may independently consent to an online service varies by jurisdiction; where parental authorization is legally required, it must be obtained before use.

6. How We Share Information

We do not sell personal information and do not share personal information for cross-context behavioral advertising.

We disclose information to service providers and processors used to operate the Service, including Supabase for anonymous authentication, private storage and saved YAP data; AssemblyAI for pre-recorded transcription; OpenAI for transcript and structured-data analysis; Google Cloud for processing infrastructure, including within-conversation speaker verification; RevenueCat for subscription management; and support or operational providers. YAP's production Supabase project is hosted in the United States, in region us-west-1. The legacy pyannoteAI integration is currently disabled.

We may also disclose information at your direction; when reasonably necessary to comply with law or valid legal process, enforce our Terms, protect rights or safety, or prevent fraud or illegal activity; in connection with a merger, financing, acquisition, reorganization, or sale of assets; or for another purpose that we explain and you authorize.

Shareable results. YAP generates Story/Square award cards and recaps on your device and shares them through the native iOS share sheet when you choose; YAP does not create a public hosted share URL. Shared results can include the names you assigned to conversation participants, statistics about their participation, and short excerpts or summaries of the conversation. Once you share a copy to another person, app, or platform, that copy is controlled by the recipient or destination platform and YAP cannot delete it.

7. Retention

AssemblyAI audio/transcript artifacts: YAP requests transcript-artifact deletion after successful durable ingestion and retries failed cleanup. The production account has a one-day asynchronous audio/transcript TTL as a fallback, subject to applicable provider security and legal-retention obligations.

OpenAI API content: not used for model training by default. Under standard API controls, abuse-monitoring logs may retain customer content for up to 30 days, subject to OpenAI's stated exceptions.

YAP private audio, transcripts, results and History: retained to provide saved History and recovery until account deletion, subject to applicable operational backup and legal-retention requirements. Account deletion is the supported in-app user-data deletion mechanism at launch; there is no separate in-app deletion control for an individual completed YAP.

Account, purchase, and support records: retained as reasonably necessary to provide the Service, manage subscriptions, comply with law and accounting obligations, resolve disputes, and enforce agreements.

You may request deletion of your anonymous YAP account and its owned conversation data through the in-app Delete Account flow or by contacting privacy@theyapapp.co. Accepted requests restrict access while queued cleanup removes private audio, owned conversations, transcripts, results and associated History/account records. Cleanup includes an approximately one-hour safety window for work already in progress and may take longer if retries are needed. A minimal deletion-status receipt containing a random identifier, status and timestamps, with the account identifier removed, is retained without automatic expiry so devices can confirm completion. Certain operational or legally required records may also remain. Supabase scheduled database backups are daily and currently provide approximately seven days of restore points; Point-in-Time Recovery is disabled. Deleted database data may remain in those restore points until they expire. Storage objects are not included in database backups; private audio is cleaned up separately through Storage.

8. Security

We use administrative, technical, and organizational safeguards designed to protect information, including encryption in transit, access controls, and security measures appropriate to the nature of the data. No system is perfectly secure, and we cannot guarantee absolute security. If a security breach triggers a legal notification obligation, we will provide the required notices.

9. Your Choices

You may revoke microphone access in iOS Settings; decide when to start and stop a YAP session; choose whether to share YAP results and what they reveal about other participants; manage notifications in iOS Settings; unsubscribe from marketing email where applicable; and use the in-app Delete Account flow or contact privacy@theyapapp.co to request deletion of your anonymous YAP account and its owned data. There is no separate in-app deletion control for an individual completed YAP at launch.

10. California Privacy Rights

If you are a California resident, applicable law may give you rights to know or access, correct, delete, and obtain a portable copy of personal information, and to receive information about categories of information collected, purposes of use, and categories of recipients. You also have the right not to be discriminated against for exercising applicable privacy rights.

YAP does not sell personal information or share it for cross-context behavioral advertising. Conversation audio may constitute sensitive personal information because it can contain the contents of communications. YAP uses such information to provide the requested Service, maintain security, and maintain the quality and safety of the Service, rather than to infer characteristics for advertising.

To exercise an applicable California privacy right, email privacy@theyapapp.co with the subject "Privacy Request" or use the in-app privacy/deletion controls. We may verify your identity before completing a request.

11. Privacy Rights in Other U.S. States

Residents of other U.S. states with comprehensive privacy laws may have rights to access, correct, delete, or obtain a copy of personal data, and in some states to appeal a denied request or obtain information about recipients. YAP does not engage in targeted advertising, sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects. Use the process in Section 10 to submit a request.

12. EEA, UK, and Switzerland Privacy Rights

Where applicable, you may have rights to access, correct, delete, restrict or object to processing, receive portable data, withdraw consent, and lodge a complaint with a supervisory authority. YAP does not use conversation analytics to make solely automated decisions that produce legal or similarly significant effects.

Submit requests to privacy@theyapapp.co.

13. International Data Transfers

YAP is based in the United States and uses Supabase and the other service providers identified in this Policy. Those providers may process information in the United States and other jurisdictions according to their infrastructure and YAP's service configuration. If you access the Service from outside the United States, your information may be transferred to countries with different data-protection laws. Where required, YAP will use legally recognized transfer mechanisms and contractual safeguards.

14. Children and Teens

The Service is intended for users aged 13 and over and is not directed to children under 13. We do not knowingly collect personal information from a child under 13. If we learn that we have done so, we will take appropriate steps to delete it and terminate the associated account.

Users aged 13 to 17 may use the Service only with the knowledge and consent of a parent or legal guardian, and the user represents that this consent has been obtained. The current guest account flow does not separately collect or verify a parent email or other parental-consent credential. Where applicable law requires a different or verifiable parental-authorization process, that requirement applies and the Service should not be used unless it has been satisfied.

Because YAP captures the voices of everyone present, users must also comply with applicable consent requirements for other participants, including minors.

15. Do Not Track and Global Privacy Control

The Service does not use conversation data for cross-context tracking or behavioral advertising. Our website may recognize legally required browser-based privacy signals, such as Global Privacy Control, where applicable.

16. Advertising and Future Changes

The Service does not currently use conversational audio, transcripts, or derived conversation analytics for advertising, ad targeting, or audience building. The YAP iOS app does not include third-party analytics, crash-reporting, attribution, advertising or behavioral-tracking SDKs; RevenueCat is used for subscription management and the related operational information described in Section 3.3. If we materially change our data practices, we will update this Policy before the change takes effect and obtain consent where required.

17. Changes to This Policy

We may update this Policy from time to time. If a change is material, we will provide notice as required by applicable law and update the "Last Updated" date. Where consent is legally required for a new use, we will obtain it before that use begins.

18. Contact Us

YAP Technologies Holding Company

6231 Residencia, Newport Beach, CA 92660, United States

Privacy requests and questions: privacy@theyapapp.co

General and support: info@theyapapp.co

Security reports: privacy@theyapapp.co (subject line "Security")