Privacy
P
Define the boundary before collecting data.
Effective: 2026-06-11. Deletion, correction, and review: support@yonerai.com
PolicyAccount data
When supplied by OAuth, YonerAI may receive minimal identifiers such as provider, provider user ID, display name, and email. Intended Google OAuth scopes are openid, email, and profile. Drive, Gmail, and Calendar access are not claimed here. Tokens, authorization codes, and provider keys are not public-page data.
PolicyAudit and message bodies
Audit and status surfaces follow a metadata-only posture. Cloud audit rows should not store raw prompts, raw completions, raw local/private content, authorization codes, access tokens, refresh tokens, or provider keys.
PolicyRetention constants
Local content is not uploaded by default. Web session maximum age is thirty days. OAuth state TTL is ten minutes. Link and run state TTL is fifteen minutes. Audit pruning is fourteen days.
PolicyLocal boundary
Local-origin content is not silently uploaded to cloud systems. A Web deletion request does not automatically delete device-local history.
PolicyRetention and deletion
Self-service deletion is not yet claimed. After identity verification, valid requests may revoke, delete, or expire active serving data under current policy. Immediate complete deletion from backups, PITR copies, or immutable logs is not promised.
PolicySharing
YonerAI does not sell personal data. Features that send content to a provider must separate sync consent from provider-sharing consent and disclose the transfer before use.
PolicyStaging and production
Owner-controlled staging and general availability are distinct. Production cloud is not complete. General production sync, production Google login, a completed production API, production database behavior, and complete persistent memory are not claimed.