← Back

Privacy Policy

Last updated: July 15, 2026 · Version 1.2

1. What Data We Collect

Account information: name, email address, and Google OAuth profile data (if using Google sign-in).

Payment information: processed entirely by Stripe. We do not store credit card numbers, bank account details, or other payment credentials.

Usage data: pages visited, features used, reports run, timestamps, and credit transactions.

Uploaded files: documents you upload for analysis, stored in your isolated tenant schema.

Device and browser information: IP address (hashed for anonymization), user agent, and browser type — collected for analytics, security, and abuse prevention.

2. How We Use Your Data

  • To provide the intelligence service (running reports, generating outputs)
  • To process payments via Stripe
  • To improve the platform (anonymized, aggregated analytics)
  • To communicate with you (account notifications, service updates)
  • To detect and prevent abuse or unauthorized access

3. How AI Processes Your Data

When you run an intelligence report, your query and any uploaded documents are sent to third-party AI model providers via their APIs for processing. Those providers process data under contractual terms that include zero-retention or limited-retention policies for API usage — they do not use API queries for model training. We do not use your data to train any AI models. Named providers are available to customers under agreement; see /subprocessors for processing categories.

4. Data Sharing

We do NOT sell your personal data.

We share data only with subprocessors in the categories below, solely to operate the platform. A named vendor schedule is not published on this page (competitive and security posture); customers under agreement may request it via privacy@ysaere.com. Categories:

  • Payment processing — checkout and subscriptions (card data handled by the processor)
  • Transactional email — verification and service notifications
  • DNS, edge security & bot protection — sign-up / sign-in abuse controls (no advertising cookies)
  • AI inference & embeddings — report generation under contractual retention limits
  • Cloud infrastructure & hosting — application, database, and storage hosting
  • Error & operational monitoring — when enabled for reliability

See also Subprocessors. We may disclose data if required by law, court order, or government regulation.

5. Data Retention

  • Account data: retained while your account is active
  • Uploaded files: retained until you delete them, then permanently removed within 30 days
  • Intelligence reports: retained until you delete them
  • Analytics data: retained in anonymized, aggregated form
  • On account deletion: all personal data is removed within 30 days

6. Your Rights

Regardless of where you are located, you have the right to:

  • Access your personal data
  • Delete your account and data
  • Export your data
  • Correct inaccurate data
  • Opt out of analytics tracking

California residents (CCPA/CPRA): You have the right to know what personal information we collect, the right to delete it, the right to opt out of sale (we do not sell data), and the right to non-discrimination for exercising your rights.

Florida residents (FDBR): Under the Florida Digital Bill of Rights, you have the right to access, correct, delete, and port your personal data. You may also opt out of the processing of your data for targeted advertising (we do not engage in targeted advertising).

7. Passkeys (WebAuthn)

If you register a passkey, your device stores a cryptographic credential locally (Face ID, Touch ID, Windows Hello, or a security key). We store only the public key and credential identifier required to verify future sign-ins. We never receive your biometric data.

8. Cookies

  • Session cookies: required for authentication
  • Theme preference: stored in localStorage to persist your Light/Dark/System choice
  • Analytics cookies: for platform improvement (anonymized usage tracking)
  • UTM tracking cookies: to understand how users find us (30-day expiry)

We do not use third-party advertising cookies.

9. Security

  • All data in transit is encrypted via TLS/HTTPS (managed by Caddy with auto-renewed Let's Encrypt certificates)
  • Database is not accessible from the public internet
  • Tenant isolation: your data is stored in a separate database schema and is never visible to other users
  • Non-root containers with minimal attack surface
  • Session-based authentication (no tokens stored in localStorage)

10. Children

This platform is not intended for use by anyone under 18 years of age. We do not knowingly collect personal data from minors. If we learn that we have collected data from a minor, we will delete it promptly.

11. Contact

For privacy questions, data access requests, or to exercise your rights:

Email: privacy@ysaere.com

Ysaere, Inc., USA

12. Changes to This Policy

We may update this Privacy Policy. Material changes will be communicated via email or in-app notification. Your continued use of the platform after changes constitutes acceptance of the updated policy.

Ysaere, Inc. · USA

Additional notices — United States

  • United States residents have a range of state-level privacy rights depending on residency. Ysaere applies a unified strict-default posture: 30-day response to access, correction, and deletion requests, and the ability to opt out of analytics from Account → Privacy.
  • Ysaere honors the Global Privacy Control (GPC) signal as a valid opt-out mechanism.
  • You may designate an authorized agent to submit a request on your behalf. See https://app.ysaere.com/dsar/agent for the intake form.
  • Ysaere does not perform solely automated decision-making with legal or similarly significant effects on you. You may still opt out from the Account → Privacy page; the preference applies prospectively if our practices change.
  • Ysaere does not currently sell personal information for monetary or other valuable consideration.
  • You can submit a Data Subject Access Request — including export, correction, and deletion — at any time from Account → Privacy & Data, or by email to privacy@ysaere.com (Ysaere, Inc., USA).
Privacy Policy | Ysaere