Privacy Policy
- Data Management: You can view and manage specific saved memories using the
/managedatacommand. For full account deletion, contact the developer via the Contact page from your original social handle. A centralised data console is on our roadmap. - No Tracking or Profiling: We do not track personal behavior or collect data without your explicit consent.
- Mental & Physical Health Tracking: For wellness support, Yuki may track health patterns if shared explicitly. You can delete it anytime.
- Encrypted Storage: Your profile and memory data is encrypted at rest using Fernet-based per-user encryption (PBKDF2-derived keys). We are building towards a client-side passphrase system. See our privacy roadmap.
- Moderation-Only Exceptions: Automated moderation ensures community safety. Logs are encrypted, and access requires user consent unless legally required.
- Services Used: Gemini (moderation/chat), NeonDB (encrypted storage), Vercel (frontend hosting), Oracle Cloud VMs (backend hosting), Cloudflare (security, DNS), platform APIs (Telegram, Discord, etc.).
- Legal Compliance: In case of legal disputes, we will advocate user interests and only access moderation logs after your consent (unless legally mandated).
- Contact: Contact page
Complete Edition
Effective Date: August 21, 2026
1. Introduction
Your privacy matters. This policy outlines how we handle data when you interact with Yuki across supported platforms. Yuki is a 15-year-old digital persona with limited memory and strict ethical safeguards.
Due to strict policies set by our cloud AI providers, you must be 18+ to interact with Yuki. Please do NOT share highly sensitive personal secrets (like passwords or financial details) during your chats, even during the 48-hour sunset window.
2. What We Collect
Data is collected only with your consent and limited to what you voluntarily share:
- Platform ID & Optional Name: Only if you provide it, for personalization and multi-platform continuity.
- Last 12 Chat Exchanges: Stored temporarily for conversation continuity.
- Key Discussion Events (up to 40): Yuki autonomously extracts and summarizes key themes from your conversations for long-term memory.
- User Mood: Used to adjust tone during chat.
- User-Shared Personal Info: Only if explicitly stated in chat.
- Health Information: If shared by the user, securely stored to enhance supportive responses. Deletable anytime via
/managedata. - Agentic Tool Usage: Yuki may check external sources (Web Search, Weather) to stay aware. These requests don't involve your personal data.
- Moderation Data: Gemini-powered safety filters store score changes. Immutable by design.
3. What You Control
You may instantly view or delete the following via /managedata:
- Event Memories
- Key Discussions
- Mood Tracking
- User-Shared Personal Data
- Health Data
Moderation data is handled solely by Gemini for ethical compliance and cannot be manually altered.
4. Use of Your Data
- Third-Party AI Processing: Conversations are processed by cloud AI providers (Google Gemini) to generate responses. Under their free-tier terms, providers may use interaction data to improve their services. Transitioning to private, non-training inference is a core priority of our roadmap.
- No Tracking: We do not follow user activity outside of the chat.
- No Analytics or Profiling: We do not profile you or track behavior.
5. Data Storage & Protection
- Location: All infrastructure (databases, virtual machines) is situated exclusively in the Singapore region. Despite the location, your data remains strictly encrypted at rest and in transit.
- Admin Access: User records (such as usernames and timestamps) are encrypted per-user. Admins will NEVER modify or view your data without your explicit permission.
- Backups: A rolling 6-hour encrypted database backup is maintained (via NeonDB) and is utilized solely as a last resort for disaster recovery.
- Data Retention: Inactive accounts may have memory stores purged after prolonged inactivity.
Your data is yours. All stored data on our infrastructure can be viewed and deleted by you via /managedata. However, data that has been processed by third-party AI providers is subject to their own retention policies and is outside our direct control. See our Research page for how we're addressing this.
6. Third-Party Services
- Gemini (Google Gen AI): Used for AI responses and automated moderation.
- NeonDB: Secure storage for encrypted user data.
- Hosting & Traffic Logs: Infrastructure providers (Vercel, Oracle Cloud VMs, Cloudflare) collect standard HTTP web traffic logs (such as IP addresses, visit timestamps, and browser user agents) under their respective privacy policies, even when we have tracking and analytics disabled.
- Platform Governance: Your user account identities, platform credentials, and chat transmission logs on third-party platforms (Telegram, Discord, and Hori-Z) are governed entirely by those platforms' own Terms of Service and Privacy Policies, which fall outside our direct control.
7. Legal & Government Requests
We always prioritize your rights. Access to encrypted user data will only occur with your informed consent unless legally mandated.
8. Updates to Policy
This policy will evolve. Changes will be transparently posted here with an updated effective date.
9. Contact Us
For any concerns, account deletion requests, or inquiries: please visit our Contact page.