Yvo
Features App Pricing Privacy Terms
Join waitlist
Features App Pricing Privacy Terms Join the waitlist

Yvo Privacy Policy

Effective date: July 5, 2026
Last updated: July 5, 2026


Beta Notice

Yvo is currently offered as Beta software (including TestFlight and pre-release builds). Features, data practices, and third-party integrations may change during Beta. We will update this Privacy Policy when our practices change materially. Continued use of Yvo after an update constitutes acceptance of the revised policy, to the extent permitted by applicable law.

This Privacy Policy applies to:

  • The Yvo iOS application (com.yvo.app)
  • The Yvo watchOS companion application (com.yvo.app.watch)
  • The Yvo Share Extension, which lets you send content into Yvo from other apps

Together, these are referred to as the Service.


Who We Are

Yvo ("we," "us," or "our") operates the Yvo personal knowledge application.

For privacy-related questions, requests, or complaints, contact us at:

Email: yvo.app@proton.me

We act as the data controller for personal data processed in connection with your Yvo account and subscription. For vault content stored primarily on your device, you remain in control of that data; we process it only as described below when you use specific features.


Summary

Yvo is designed as a local-first personal knowledge vault. In ordinary use:

  • Your notes, voice recordings, attachments, and most app data are stored on your device (or in a folder you choose, such as iCloud Drive).
  • We use Supabase only for account authentication and subscription status — not to store your vault.
  • Premium AI features may send content you actively use (voice, text, note excerpts) to third-party AI providers (such as OpenAI or a compatible API you configure) or to Apple speech and intelligence services.
  • We do not use advertising SDKs, analytics SDKs, or cross-app tracking.

This summary is not a substitute for the full policy below.


Information We Collect

We collect and process the categories of information described in this section. What applies to you depends on which features you use and whether you create an account or subscribe to Premium.

1. Account and Authentication Data

If you create a Yvo account, we collect:

Data Examples Purpose
Email address Address used for email sign-up or relay from Sign in with Apple Account creation, sign-in, password reset
Authentication credentials Password (stored hashed by our auth provider; we do not store plaintext passwords) Secure sign-in
User identifier Supabase user UUID Link your account and subscription
Sign-in provider Apple, email, or other supported provider Display how you signed in; account management
Session tokens Access and refresh tokens Keep you signed in; stored via the Supabase SDK (Keychain)
Name (optional) First and last name if provided on first Sign in with Apple Profile display (when supplied by Apple)

You may use many free features without creating an account. An account is required to purchase or restore Premium and to sync subscription status across devices tied to your login.

2. Subscription and Billing Metadata

When you purchase Yvo Premium through the App Store:

Data Examples Purpose
Subscription tier Free, monthly Premium, or lifetime Premium Unlock Premium features
Subscription expiration Renewal or expiry date for monthly plans Entitlement management
StoreKit transaction identifier Apple transaction ID Verify purchase; sync entitlement to your account

We do not receive or store your payment card number, Apple ID password, or full billing address. All payments are processed by Apple via StoreKit.

We store subscription metadata in Supabase (subscription_type, subscription_expires_at, storekit_transaction_id) and cache entitlement locally on your device for offline access.

3. Vault Content You Create (Stored Locally)

When you use Yvo, you create and store content on your device (or in a user-selected storage location). This includes:

  • Markdown notes, titles, tags, and folder structure
  • Todos, reminders, events, and due dates
  • Wiki pages and internal links
  • Checklists and structured note metadata
  • Voice recordings (for example, .m4a audio files)
  • Transcripts derived from voice input
  • Images, files, and other attachments
  • Saved web links and offline web clip archives (.webarchive, preview images, metadata)
  • Imported content from the Share Extension or file importers

This vault content is not uploaded to Yvo-operated cloud storage or Supabase. It remains under your control in local or user-chosen storage unless you invoke a feature that sends specific content to a third-party processor (see Sections on AI and Third-Party Processors).

4. Voice and Audio Data

When you use voice features (Quick Add, voice memo import, Watch recording, transcription):

Data Where stored / sent Purpose
Audio recordings Local vault (Audio/ folder) Playback; linked to notes
Transcripts Local note bodies Searchable text; editing
Transcription language preference Local app settings Improve transcription accuracy

Depending on settings and connectivity, audio and transcripts may be processed by:

  • OpenAI-compatible APIs (Whisper batch transcription, realtime transcription WebSocket) when cloud transcription is enabled and available
  • Apple Speech Recognition (SFSpeechRecognizer), which may use on-device models or, when unavailable, Apple's servers

See AI and Automated Processing and Third-Party Processors below.

5. Imports and Share Extension Data

The Yvo Share Extension accepts content shared from other apps, including:

  • Audio files (for example, from Voice Memos)
  • URLs and optional page titles
  • Images and generic files
  • Plain text

This content is staged locally in a shared App Group container (group.com.yvo.app) before you import it into your vault in the main app. The Share Extension does not make network requests.

6. Web Clips and Linked Content

When you save or capture web content, Yvo may:

  • Fetch the URL you provide (via WKWebView or similar)
  • Retrieve link metadata (title, icon) via Apple's LinkPresentation framework
  • Store an offline archive, preview image, and metadata locally in your vault

Third-party websites you request may log standard web server data (IP address, user agent) according to their policies, not ours.

7. Assistant Interactions

If you use the AI Assistant:

  • Chat messages (your prompts and assistant replies) are stored locally on your device (UserDefaults).
  • When using cloud AI, message content and vault context may be sent to third-party AI providers as described below.
  • When using Apple Intelligence on supported devices, processing occurs on-device.

8. Device Permissions and System Data

Yvo may request the following permissions:

Permission Why we request it
Microphone Record voice memos and Quick Add voice input
Speech Recognition Transcribe voice to text
Notifications Remind you of due items; notify you when shared imports are ready to review

We do not request access to your location, contacts, photo library (direct API), camera, Calendar app, or Reminders app. Calendar and task views in Yvo display your vault data only, not system calendar databases.

Yvo uses CoreMotion only for optional UI parallax effects on the home screen. Motion data is not transmitted off your device.

9. Technical and Support Data

We may process limited technical information necessary to operate the Service:

  • App version and build number (shown in Settings)
  • Network connectivity status (to show offline notices and choose cloud vs on-device processing)
  • Information you voluntarily include when contacting support

We do not operate third-party analytics, crash reporting, or advertising measurement SDKs in the Service.

10. Local Preferences

Stored locally via app settings (UserDefaults / @AppStorage), including:

  • Display name, vault name, and assistant name (optional)
  • Appearance, language, and transcription preferences
  • Reminder notification lead time
  • Cloud API configuration (when not locked in Beta builds)
  • Cached subscription entitlement

How We Collect Information

We collect information:

  1. Directly from you — when you create an account, write notes, record audio, import files, configure settings, or contact support
  2. Automatically when you use features — for example, when transcription or AI features process your input, or when web clips fetch URLs you provide
  3. Through Apple — Sign in with Apple, StoreKit purchases, Apple Speech, Apple Intelligence, LinkPresentation, and iCloud (if you store your vault in iCloud Drive)
  4. Through the Share Extension — when you share content from another app into Yvo

We do not collect information through hidden background tracking or advertising networks.


How We Use Information

We use personal data only for legitimate purposes related to the Service:

Purpose Data used
Provide core vault functionality Local vault content
Authenticate you and maintain sessions Account and session data
Manage Premium entitlements Subscription metadata, StoreKit data
Transcribe and enrich voice notes Audio, transcripts (local and/or third-party processing)
Operate AI Assistant, Smart Categorize, Quick Add AI Text, vault context, tool results (when cloud AI is used)
Capture and display web clips URLs and downloaded page content
Schedule local reminder notifications Note titles, due dates, preview text
Improve reliability and security Technical data; abuse prevention
Respond to support and legal requests Information you provide

We do not use your data for third-party advertising, sell your personal data, or build advertising profiles.


Local Storage and Your Choices

Default storage

By default, your vault is stored in the app's documents directory on your iPhone or iPad.

User-chosen storage

You may relocate your vault to a folder in the Files app, including iCloud Drive or external storage. If you choose iCloud, Apple handles sync and backup under Apple's terms and privacy policy.

App Group and Watch sync

The iOS app, Share Extension, and watchOS app share data through the App Group group.com.yvo.app, including a local SwiftData database and staged imports.

File Sharing

Yvo enables UIFileSharingEnabled, so your vault documents may be accessible through the Files app and traditional file sharing interfaces on your device.

What stays off our servers

Your markdown vault, audio files, attachments, web clip archives, and assistant chat history are not stored on Yvo-operated backend servers. Only account and subscription fields described above are stored in Supabase.


What We Do Not Do

To be explicit:

  • We do not sell your personal information
  • We do not use Firebase, Mixpanel, Amplitude, or similar analytics SDKs
  • We do not display third-party ads or use the Advertising Identifier (IDFA)
  • We do not require App Tracking Transparency (ATT) because we do not track you across other companies' apps and websites for advertising
  • We do not upload your vault contents to Supabase or other Yvo-operated cloud storage
  • We do not access your iOS Calendar or Reminders databases

Marketing phrases in the app such as "zero tracking" refer to no advertising or analytics tracking. They do not mean that no data is ever processed or transmitted — see this policy for accurate details.


Third-Party Processors

We use service providers that process data on our behalf. Each is used only for the purposes described. We require that processors handling personal data on our behalf protect it consistent with this policy and applicable law.

Supabase

  • Provider: Supabase, Inc.
  • Purpose: User authentication; profile and subscription metadata storage
  • Data processed: Email, user ID, sign-in provider, subscription tier, expiration, StoreKit transaction ID, optional name from Sign in with Apple
  • Data not processed: Vault notes, audio, attachments, assistant chat
  • Location: Cloud infrastructure as configured for our Supabase project
  • Privacy policy: https://supabase.com/privacy

Apple Inc.

Apple provides multiple services integrated into Yvo:

Apple service Purpose Data involved
Sign in with Apple Authentication Identity token; optional name/email
StoreKit In-app purchases and subscriptions Purchase and entitlement data
Apple Speech Speech-to-text Audio and transcripts
Apple Intelligence / Foundation Models On-device AI when available Vault content on device
LinkPresentation Link previews URLs
iCloud Drive (optional) User-chosen vault sync Vault files you store there
App Store / TestFlight Distribution As per Apple's policies

Apple's privacy policy: https://www.apple.com/legal/privacy/

OpenAI and Compatible AI APIs

When Premium or cloud AI features are active, content may be sent to OpenAI or another OpenAI-compatible API endpoint.

Beta note: In current Beta builds, cloud AI may use a developer-provided API key shared across Beta testers. Content you send through cloud AI features is processed by the configured provider on Yvo's behalf. Before general App Store release, this is expected to change so users supply their own key or use a production configuration with updated disclosures.

Features that may use cloud AI:

Feature Data that may be transmitted
Whisper transcription Audio (converted to WAV); optional language code
Realtime transcription (Quick Add) Streaming audio chunks
AI Assistant System prompt; vault context summary; chat messages; tool results including full note bodies when the assistant reads or edits notes
Note enrichment Full transcript; folder list
Smart Categorize Note title and body; folder list
Quick Add AI interpreter Spoken or typed capture text

Default API base URL: https://api.openai.com/v1 (configurable in developer settings). Processing is governed by the provider's terms and privacy policy:

  • OpenAI: https://openai.com/policies/privacy-policy

We do not control how third-party AI providers retain or use data sent to them. Review their policies before using cloud AI features.

Websites and content you link to

When you import URLs or capture web clips, those third-party sites may collect standard connection data. Their practices are governed by their own policies.


AI and Automated Processing

Yvo uses automated processing to transcribe speech, categorize notes, interpret Quick Add input, and power the Assistant.

When processing stays on your device

  • Vault storage and indexing (SwiftData, markdown files)
  • On-device Apple Intelligence Assistant (read-only tools on supported hardware)
  • On-device categorization fallback (OnDeviceCategorizer)
  • Local reminder scheduling

When processing uses third parties

Cloud processing occurs when you use Premium AI features and the app determines cloud services are available (network connectivity, API configuration, and feature gates). This includes:

  1. Transcription — OpenAI Whisper/realtime APIs when "enhanced cloud transcription" is enabled, otherwise Apple Speech (which may use Apple servers)
  2. Assistant — OpenAI-compatible chat completions with tool calling; vault metadata is sent by default, and full note content may be sent when tools fetch or edit notes
  3. Enrichment and categorization — Note/transcript text sent for structuring or folder suggestions

Your consent: By enabling cloud features, recording voice, sending messages to the Assistant, or using Premium AI tools, you direct us to transmit the relevant content to third-party processors for that purpose. You can limit cloud processing by:

  • Disabling enhanced cloud transcription in Settings
  • Using the app offline where on-device fallbacks apply
  • Not using Premium AI features
  • Revoking microphone or speech recognition permissions in iOS Settings

We do not use your vault content to train our own models. Third-party AI providers may have their own training and retention policies — consult their documentation.


Legal Bases for Processing (EEA, UK, and Switzerland)

If you are in the European Economic Area, the United Kingdom, or Switzerland, we process personal data under the following legal bases:

Processing Legal basis
Providing the Service and account Performance of a contract (Art. 6(1)(b) GDPR)
Subscription verification Performance of a contract; legitimate interests
Security, fraud prevention, Beta operation Legitimate interests (Art. 6(1)(f) GDPR)
Microphone, speech, notifications Your consent via iOS permission prompts (Art. 6(1)(a) GDPR)
Cloud AI processing you initiate Performance of a contract (Premium features); consent for optional processing
Compliance with legal obligations Legal obligation (Art. 6(1)(c) GDPR)

You may withdraw consent for permission-based processing in iOS Settings without affecting the lawfulness of processing before withdrawal.


Data Retention

Data category Retention period
Account data (Supabase) While your account is active; deleted or anonymized within a reasonable period after verified deletion request
Subscription metadata While account is active and as needed for billing disputes and legal compliance
Local vault content Until you delete it or uninstall the app (subject to your backups and iCloud settings)
Assistant chat history Until you clear it or uninstall the app
Share Extension staging files Until imported or cleared
Support correspondence As long as needed to resolve your request and comply with law

When you delete local content via in-app tools (including Danger Zone "Clear all notes"), it is removed from the active vault path subject to device backup behavior.


Your Rights and Controls

In-app and device controls

  • Sign out — ends your authenticated session (Account settings)
  • Clear vault — Settings → Danger Zone removes local notes; does not delete your cloud account
  • Vault location — choose on-device or Files/iCloud folder
  • Cloud transcription toggle — limit sending audio to cloud APIs
  • Permissions — iOS Settings → Yvo → Microphone, Speech Recognition, Notifications
  • Export — access vault files via Files app and UIFileSharingEnabled; ZIP export may be added in future versions

Account deletion

We do not yet offer in-app account deletion. To request deletion of your Yvo account and associated Supabase profile data, email yvo.app@proton.me with the subject "Account Deletion Request" from your account email.

Upon verified request, we will delete or anonymize account and subscription metadata within 30 days, except where retention is required by law (for example, tax or fraud records).

Local vault data on your devices is not deleted automatically when your account is deleted. Remove it manually before deletion if you no longer want it on your device.

Rights under GDPR (EEA/UK)

You may have the right to access, rectify, erase, restrict, object to processing, and data portability for personal data we control. Contact yvo.app@proton.me. You may lodge a complaint with your local supervisory authority.

Rights under CCPA/CPRA (California)

California residents may have the right to know, delete, correct, and opt out of certain sharing. We do not sell or share personal information for cross-context behavioral advertising as defined under California law.

To exercise rights, email yvo.app@proton.me. We will verify your request and respond within applicable timelines.

Revoking consent

You may revoke iOS permissions at any time. Revoking permissions may limit features (for example, voice recording without microphone access).


Children's Privacy

Yvo is not directed to children under 13 (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us account information, contact yvo.app@proton.me and we will take steps to delete it.


International Data Transfers

Our service providers may process data in the United States, the European Union, and other countries. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms offered by our processors.


Security

We implement measures designed to protect personal data, including:

  • Storing auth session tokens via platform secure storage (Keychain)
  • Storing optional user API keys in Keychain when not in Beta locked mode
  • Using HTTPS and secure WebSockets for network communication (default App Transport Security)
  • App Group isolation for shared extension data
  • Relying on iOS data protection for on-device files

No method of transmission or storage is completely secure. You are responsible for securing your device and Apple ID.

The app declares ITSAppUsesNonExemptEncryption: false (standard encryption only).


Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will post the updated version with a new "Last updated" date. For material changes during Beta or after release, we may also notify you in-app or by email where appropriate.


Contact Us

Yvo
Email: yvo.app@proton.me
Website: https://yvo.app


Appendix: App Store Privacy Nutrition Labels Reference

Use this table when completing App Store Connect → App Privacy. Adjust labels if practices change.

Data type Collected Linked to identity Used for tracking Purpose
Email address Yes Yes No App functionality; account management
User ID Yes Yes No App functionality; account management
Purchase history Yes Yes No App functionality (Premium entitlement)
Other user content (notes, audio, transcripts) Yes No* No App functionality (local storage; optional cloud AI when you use those features)
Audio data Yes No* No App functionality (voice features)
Customer support If you contact us Yes No Customer support

* Linked to identity only when tied to your account flow (e.g., subscription). Vault content is stored locally and is not linked to your account on Yvo servers because vault content is not uploaded to Supabase.

Tracking: None. We do not use data for tracking as defined by Apple.

Third-party data: Disclose Supabase, Apple, and OpenAI/compatible AI providers as third-party partners that receive data as described in this policy.


Hosted URL (for App Store Connect): https://yvo.app/privacy

© 2026 Yvo. All rights reserved.

Home Privacy Policy Terms of Service yvo.app@proton.me