Privacy Policy
Last updated: August 31, 2026
1. Information We Collect
When you create an account and use Yaasvi products, we collect:
- Account information: name, email address, and password (stored securely via Supabase Auth)
- Usage data: content you generate, tool inputs/outputs, star ratings and bookmarks, platform preferences, and generation history
- Brand and team data: if you set up a brand profile, we store details you provide such as industry, niche, target audience, and voice/tone preferences; if you create or join a team, we store member emails, roles, and any documents you upload to your brand knowledge base
- Payment information: processed and tokenized securely by Razorpay — we never store your card details, including for the optional Auto Top-up feature
- Social account data: if you connect a supported social account (Instagram, Facebook, Twitter/X, LinkedIn, YouTube, TikTok, Pinterest, Reddit, Bluesky, Threads, Google Business Profile, Telegram, Snapchat, WhatsApp, or Discord — connected and managed through our unified social-connection provider, Zernio), we store encrypted access tokens needed to publish content and, for the features below, read activity on your behalf
- Email addresses collected by documents you gate: if you turn on the email gate for a document you share, the address a reader enters to unlock it is stored as a subscriber of your brand, with the same consent record, export and deletion rights as any other subscriber. This is data from people who read your content, not your own activity — you are responsible for having a lawful basis to contact them, and we act only as your processor for it
- Comments and messages on your connected accounts: if you enable Auto DM, an opt-in automation that watches for comments or direct messages matching keywords you configure and replies automatically, we receive and store the text of the matching comment/message plus the sender's platform user ID and (for comments) username — this is data from people who interact with your account, not only your own activity. It is used solely to run the automation you configured and is kept for as long as that automation exists in your account; deleting the automation deletes this data with it
- Conversations in your unified Inbox: if you connect a social account, we read and store the direct messages and comments on that account — the message text, the sender's platform user ID and username, and timestamps — so they can be shown and replied to in one place. This is separate from and broader than Auto DM above: it applies whether or not you enable any automation, and it covers ordinary conversations, not only ones matching a keyword. Some of it arrives by webhook as it happens, and a scheduled hourly sweep also fetches recent threads directly, because several platforms send no message webhooks at all and one replays a large batch of existing conversations when an account is first connected. This is data from people who message your account, not only your own activity. It is retained for as long as the account stays connected; disconnecting the account deletes the stored conversations with it
- Performance data about your posts and accounts: for connected accounts we fetch, on a scheduled basis, the metrics each platform reports — impressions, reach, engagement counts, follower totals and the like — and store them so we can show analytics over time and suggest posting times. These are aggregate figures about your own content and audience as the platform reports them; we do not receive a list of the individual people who viewed or engaged with a post. Note this is different from the product-usage analytics described below, which is about your use of Yaasvi itself
- Files you convert: if you use a document or image conversion tool, the file you upload is processed by our conversion infrastructure to produce your output and is not retained by that infrastructure once the job completes
- Technical data: browser type, IP address, and device information, used for rate-limiting, abuse prevention, bot detection (via Cloudflare Turnstile on login/signup/password-reset), general security monitoring, and error diagnostics (via Sentry)
- Seller verification details, if you choose to sell for money on the Store: your legal name, postal address, tax identifier and payout-account details. Your tax identifier is encrypted at rest and we never store your full bank account number — our payment providers hold it and we keep only a reference and the last four digits for display. We collect this because we cannot lawfully pay you or account for tax without it, and we retain it for the period Indian tax and financial-record law requires, which is longer than the retention described below and survives account deletion for that purpose
- Analytics data: product usage events (e.g. which tools and features you use), collected via PostHog and tied to your account if you're logged in, or pseudonymously if you're not
2. How We Use Your Information
We use your information to:
- Provide, operate, and improve Yaasvi products and services
- Process payments, including recurring charges you authorize via Auto Top-up
- Track and pay out referral commissions if you participate in our referral program
- Send transactional emails (welcome, team invitations, monthly free-credit notices, low-balance alerts, password reset)
- Enforce our Terms of Service and prevent fraud or abuse
- Respond to your support requests and feedback
3. AI Content Generation
Content you generate through our AI tools is processed using third-party AI infrastructure. Generation requests are routed through OpenRouter, which may use models from providers including Anthropic, Google, Alibaba Cloud (Qwen), or Moonshot AI depending on the specific tool; select tools call Anthropic's API directly instead of routing through OpenRouter. For brand knowledge-base search, we use OpenAI to generate text embeddings from documents you upload. We do not use your content to train our own models; how each provider handles data in transit is governed by their own terms. Your prompts and generated content are stored in your account history and are only accessible by you.
On paid plans you may supply your own provider API keys (OpenRouter, Google Gemini, OpenAI, fal.ai or Replicate) so that generations run on your provider account instead of ours. Keys you save are encrypted at rest, are never shown back to you in full or exposed to any other user, and are used for one purpose only: authenticating the generation requests you initiate. Deleting a key removes it from our systems. If your subscription lapses, saved keys stop being used and generations fall back to platform credits — the keys themselves are left in place and untouched so that resuming a paid plan restores them, and you can delete them at any time regardless of your plan. Anything you generate through your own key is also subject to your agreement with that provider.
4. Data Sharing
We do not sell your personal data. We share data only with the service providers needed to run Yaasvi, and with law enforcement when required by law:
- Supabase — database and authentication infrastructure
- Netlify — application hosting
- Contabo — hosting for select self-managed infrastructure (e.g. document/image conversion, voice features)
- Cloudflare — DNS, storage of generated media (R2), and bot-protection signals (Turnstile) on our login, signup, and password-reset pages
- OpenRouter — routes AI text-generation requests to the underlying model provider for each tool
- Anthropic — AI text generation, either via OpenRouter or directly, depending on the tool
- OpenAI — image generation, embeddings for brand knowledge-base search, and automated content moderation of generation requests and outputs
- Google (Gemini) — image generation
- Apollo.io — only if you use the Lead Enrichment tool: we send the company domain (never a name, email, or other personal detail) from your uploaded list to look up public company information
- Upstash — job queue (QStash) and caching/rate limiting (Redis)
- Razorpay — payment processing, including tokenized Auto Top-up charges
- PostHog — product analytics (only after you accept analytics cookies)
- Sentry — error tracking and diagnostics, to help us find and fix bugs
- Resend — transactional and lifecycle email delivery
- Zernio — our unified social-connection provider: only if you connect a social account, to publish content on your behalf and, for Auto DM specifically, to read and reply to comments/messages on that account
- Telegram — only if you link your Telegram account, to deliver generated content and support bot commands
- Law enforcement when required by applicable law
5. Data Retention
We retain your account data for as long as your account remains active, with the following rolling windows applied automatically:
- Generation history and chat conversations — 12 months, then deleted
- Creations you manage (storybooks, images, heroes, eBooks and other saved projects) — kept until you delete them or close your account
- Automations, including Auto DM (workflows you build, and any comment/message data received for them) — kept for as long as the automation exists in your account; deleted immediately when you delete it
- Documents and library files — kept until you delete them; items in Trash are permanently removed 30 days after deletion
- Analytics for documents you share publicly (view counts, the visitor’s country and referring site) — 12 months. We never store a visitor’s IP address: uniqueness is measured with a one-way, daily-rotating fingerprint that cannot be traced back to a person or reused across days
- In-app notifications — 90 days
- Closed support tickets — 24 months
- Payment records — up to 8 years, as required by Indian tax and accounting law; these survive account deletion in pseudonymized form (not linked to your identity)
If you delete your account, your personal data is removed immediately and any remaining cleanup completes within 30 days, except the pseudonymized payment records above and anything we must retain for legal or fraud-prevention purposes.
6. Security
We implement industry-standard security measures including encrypted connections (HTTPS), hashed passwords, encrypted storage of connected social account tokens, and row-level security on all database tables. You can also enable optional two-factor authentication (TOTP) from Settings → Security; your authenticator secret is held by our authentication provider (Supabase) and never by Yaasvi directly. However, no method of transmission over the internet is 100% secure.
7. Your Rights
You have the right to access, correct, port, or delete your personal data, and to withdraw consent for analytics at any time. Most of these are self-serve:
- Export your data — request a machine-readable copy of everything we hold about you from Settings → Account
- Delete your account — permanently, from Settings → Security
- Analytics consent — change your cookie choice via "Cookie preferences" in the footer
- Disconnect social accounts — any time from your brand settings
For anything else, contact us at legal@yaasvi.com.
8. Changes to This Policy
We may update this policy from time to time. We will notify you of significant changes via email or an in-app notice. Continued use of our services after changes constitutes acceptance of the updated policy.
9. Contact & Grievances
If you have questions about this Privacy Policy, please contact us at legal@yaasvi.com.
Yaasvi is operated by Yaasvi Tech Private Limited, with its registered office at No.6, Veerasamy Street, Oldpet, Krishnagiri – 635001, Tamil Nadu, India. For grievances under India's Digital Personal Data Protection Act, 2023 (or any other applicable data-protection law), write to our Grievance Officer at legal@yaasvi.com with the subject line "Grievance". We acknowledge grievances within 72 hours and aim to resolve them within 30 days.