Privacy Policy
Our Commitment to Privacy
At Yanmoo we take your privacy seriously. To diagnose a product we read publicly available pages of the website you give us — the same pages any visitor or search engine can reach — and send their text to our AI provider to extract your positioning. We never need access to your systems to produce a diagnosis.
Data Collection and Usage
- Account details: your name, email address, and the sign-in method you chose. If you sign in with Google or GitHub we receive your basic profile from them; we never receive your password.
- Company and growth data: the products, channels, playbooks, goals and measurements you create, together with the work your agents produce.
- Agent activity: the runs your agents perform, the tools they call, and the transcripts of that work.
- Connected tools: when you connect a third-party tool, we store the connection and use it only to perform the work you asked your agents to do. Credentials are held encrypted and are never shared with other customers.
What a diagnosis stores
When you run a diagnosis without an account we store the URL you entered, its domain, the resulting profile, and coarse technical details for rate limiting and latency tracking. We keep it so you can sign up without re-running the analysis, and so any corrections you make are preserved. An unclaimed diagnosis expires 72 hours after it is created.
Product analytics and session recording
We use PostHog to understand how the product is used and to find faults. PostHog is a data processor acting on our instructions, and the data is held in their United States region.
- Usage events: pages viewed, and product milestones such as running a diagnosis, launching a growth team, or activating a channel. These carry your user identifier and your company identifier.
- Errors: when a request fails, we record the fault together with the account and company that encountered it, so we can fix it.
- Session recordings: we record how pages are used, so we can see where the product is confusing. Recordings are masked and limited — every input field is masked, the model connection panel is excluded entirely, playbook contents are masked, and pages that display raw agent run output are not recorded at all.
If you would prefer that we do not record your sessions, email privacy@yanmoo.ai and we will exclude your account.
AI providers and what we send them
Producing a diagnosis, a playbook or agent work requires sending text to an AI model provider. That text includes the public website content we read, the growth information you provide, and the instructions your agents follow.
The first diagnosis, which you get by entering a website address before you have an account, runs on a model we pay for. Once you connect your own model, your agents' work runs on that.
We keep a record of these requests and their responses so we can measure quality and cost, diagnose a poor result, and score how well the product performs. These records are held in PostHog, the same processor listed below, and they include the text sent and the text returned — for diagnoses, for playbook generation, and for the work your agents do.
If you bring your own model subscription or API key, your agent work runs against the provider you chose, under your agreement with them. We still keep the request and response record described above, because it is what lets us tell a good result from a bad one.
If you would prefer that we do not retain the content of your agents’ requests, email privacy@yanmoo.ai and we will exclude your company.
Google user data and Limited Use
When you connect a Google account, Yanmoo accesses only the Google services you authorise, and only to operate features you asked for.
- Ads, Analytics, Search Console, Business Profile, Tag Manager, YouTube, Merchant Center and BigQuery — to measure acquisition cost, attribution and channel performance, and to act on it: adjusting campaigns, configuring conversion tracking, submitting sitemaps, publishing posts and video, and updating product feeds.
- Docs, Sheets, Slides, Forms, Drive, Calendar, Contacts and Tasks — to produce and deliver the work into your own workspace, and to schedule and track it. On Drive we use the per-file scope, so we can only reach files Yanmoo created or that you explicitly select.
- Gmail — send-only, for outreach you have approved. Yanmoo cannot read your mailbox.
Limited Use. Yanmoo's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
We do not train AI models on your Google data. We do not use, transfer or retain data obtained through Google APIs to develop, improve or train generalised or non-personalised artificial intelligence or machine learning models. This applies to the raw data and to any aggregated, anonymised or derived form of it.
Google data may be processed by the AI model provider running your agents, under agreements that prohibit training on your data and require zero retention. No person at Yanmoo reads your Google data except where you have asked us to help with a specific problem, or where the law requires it.
You can revoke access at any time by disconnecting the integration inside Yanmoo, or from your Google account permissions page. Revoking deletes the stored token. Work already produced stays in your own Google workspace, and in Yanmoo until you delete it.
Service providers
We use the following processors to run the service. Each receives only what its function requires.
- Fly.io — application hosting and the managed database.
- Tigris — object storage for files and run logs.
- PostHog — product analytics, error tracking and session recording.
- Daytona — the isolated sandboxes your agents run inside.
- AI model providers — Anthropic, OpenAI, Google, xAI and Cursor, depending on the model you connect.
- OpenRouter — routes the AI model requests we make ourselves, to the inference providers it selects. We instruct it that these providers may not retain or train on what we send.
- Nango — the connection layer for third-party tools you connect.
- Resend — transactional email such as address confirmation and password reset.
- Jina — reading public web pages during a diagnosis.
How long we keep data
We keep personal data only for as long as it is needed for the purpose it was collected for. What that means in practice differs by the kind of data, because some of it is only useful while you are a customer and some of it is useful for a few days.
- Company and growth data — your products, channels, playbooks, goals and the work your agents produce: kept while your company account is active.
- Connected-tool data — including the customer identities, identity links and attribution records we derive from tools you connect: kept while your company account is active. Attribution and lifetime-value analysis need multi-year history to be meaningful, so a shorter window would remove the feature rather than protect anyone.
- Credentials for a connected tool — deleted immediately when you disconnect it. The records derived from that tool are deleted within 30 days.
- Agent run transcripts and the AI request records described above: kept for 24 months, then deleted.
- Product analytics and session recordings: kept for 12 months, then deleted.
- An unclaimed diagnosis — run without an account: expires 72 hours after it is created.
When you close your account we delete your company data within 30 days. You can ask us to delete it sooner by emailing privacy@yanmoo.ai. We keep only what we are required to keep by law — for example billing records — and for no longer than that law requires.
Data Security
- Data is encrypted in transit with TLS, and encrypted at rest by our hosting and storage providers.
- Credentials and API keys are held in an encrypted secret store rather than in application configuration.
- Each company gets its own isolated model credentials and its own sandbox environment, so one customer's agents cannot reach another customer's credentials or work.
- Access to production data is limited to the people who operate the service.
Your Rights and Controls
- Export your company and its work at any time.
- Disconnect a tool or a model credential at any time.
- Request deletion of your account and your company data by emailing privacy@yanmoo.ai.
- Ask us to exclude your account from session recording.
Contact Us
If you have any questions about your privacy or how we handle your data, please contact us at privacy@yanmoo.ai or through our support channels.
Updates to This Policy
We may update this privacy policy periodically to reflect changes in our services. Users will be notified of any significant changes through the platform and email.