Privacy Policy
Effective Date: July 8, 2026
This Privacy Policy outlines how yarnnn ("we", "our", or "us") collects, uses, and protects your information when you use our services.
1. Information We Collect
We collect the following types of information:
- Account Information: Email address, name, and profile data from authentication providers (Google, etc.)
- Content: Documents you upload, notes and memories you save, workspace files you store, and tasks you manage — including anything you choose to save through a connected LLM assistant (see §5)
- Provenance & metadata: For each saved item, we record when it was written, which source contributed it (you, a connected assistant, or YARNNN itself), and its revision history. This attribution is core to the product
- Usage Data: How you interact with our services, features used, and work requests made
- Work Outputs: AI-generated content created through our agents and recurring tasks
2. How We Use Your Data
- Provide and improve our AI work platform services
- Generate context-aware outputs through autonomous agents and tasks
- Send service-related communications (e.g., daily updates or account notices)
- Maintain security and prevent abuse
We do not sell your personal data or share it with third parties for marketing purposes.
3. Data Storage & Security
Your data is stored using Supabase (PostgreSQL) with application and database access controls. All data transmission is encrypted via HTTPS. Connector credentials are encrypted where stored as credentials, and we continue to harden credential rotation, retention, and deletion coverage. For a plain-English overview of the architecture and its current limits, see our Privacy Architecture.
4. Third-Party Services
We use the following third-party services as data processors:
- Supabase: Authentication and database (PostgreSQL)
- Render: Application and connector hosting
- Vercel: Web hosting and analytics
- AI providers (Anthropic Claude, OpenAI): to generate work outputs and to power our judgment layer. Content sent to these providers is processed under their respective data-use terms and is not used to train their models where their API terms provide such assurance
5. Connected LLM Assistants (MCP Connector)
YARNNN can be connected to LLM assistants you already use — such as ChatGPT, Claude, and others — through the open Model Context Protocol (MCP). This connection is established by you, through your assistant, using OAuth; you authenticate as yourself and the connection is scoped to your own workspace.
When a connected assistant is authorized, it can, on your behalf:
- Save content you ask it to remember into your YARNNN memory (attributed to that assistant)
- Read your recorded material when you ask it to recall something, and view how a recorded item changed over time
What this means for your data: content you save through one assistant becomes part of your durable YARNNN memory and is therefore available to you through any other assistant you have connected, as well as in the YARNNN web app. The assistant's provider (e.g. OpenAI for ChatGPT) processes the request under its own privacy terms; YARNNN stores the resulting content and its attribution. We record which assistant contributed each item so this provenance is transparent to you. You can disconnect any assistant at any time from within that assistant's settings, which revokes its access to your workspace.
6. Your Rights
You have the right to:
- Access your personal data
- Request deletion of your account and data
- Export your content
- Opt out of non-essential communications
7. Data Retention
We retain your data for as long as your account is active. Upon account deletion, we will remove your personal data within 30 days, except where required by law.
8. Changes to This Policy
We may update this policy and will notify you of material changes. Continued use after changes constitutes acceptance.
9. Contact Us
Questions about privacy? Contact us at admin@yarnnn.com