Privacy Policy
Last updated: 2026-07-20 · Version 1.33
Tap a section to read more. One opens, the others close automatically.
Who we are
Yovel is operated by Mohamed Dakkak, a sole proprietor based in the State of Maine, United States. You can reach us at [email protected].
What data we collect
We collect only the data needed to make Yovel work for you. Every piece is listed below.
- Email address and display name — from Firebase Authentication when you sign up. Used to identify your account. If you separately opt in to product-update emails, your email address can also be used to send those messages. Display names are moderated before they are saved.
- Routine generations — the AI-generated daily routines we create for you, plus the bounded inputs that produced them, such as current period, weather override if set, place context, mood snapshot, personalization profile, and Apple Health context only when Apple Health is connected.
- Mood entries — what you tell us about how you feel, including optional mood-note text and optional bounded factor chips such as sleep, work, body, people, weather, movement, food, or stress.
- Completion records — which routine activities you marked done or skipped, and when.
- Habits — habit definitions you create and daily habit check-off logs. These are account-scoped and deleted when you delete your account.
- AI-generated reflections — Yovel stores your AI Coach recaps and mood-pattern reflections in your account so you can revisit them after reinstalling or signing back in. AI Coach recaps summarize your own activity completion history and mood logs; mood-pattern reflections summarize recent mood patterns. Both are deleted when you delete your account. We do not share these reflections with other users.
- Personalized Memory and adaptive learning — when Personalized Memory is on, Yovel can maintain server-derived learned-memory records such as
adaptiveLearning/aggregate, weekly digests, monthly themes, yearly arcs, dynamic notes, and Memory Center correction/hide records. These are derived from your own account activity, completions, habits, reflections, and coarse Health context when Health is connected. They do not store raw Apple Health samples, exact HRV, exact sleep samples, or raw device identifiers. In Settings → Memory & AI, you can turn Personalized Memory off, which stops learned-memory use and new learned-memory writes. You can also reset Personalized Memory, which deletes the derived learned-memory layer, including corrections and hidden-memory records, without deleting your raw routines, moods, completions, habits, reflections, profile, billing, auth, or account data. - Location — when you grant location access, your device's coordinates are sent to Yovel's backend when you use location-aware features. For place classification, the backend uses Google Places and keeps one current per-user rounded-coordinate lookup result that may be reused for about 5 minutes; a newer lookup replaces it, and the account-linked place cache is deleted when you delete your account. For current weather, the backend uses Apple WeatherKit and stores weather results in a rounded-location cache that may be reused for about 15 minutes without your account ID. Home/Work pins and manual check-ins can store precise coordinates in your account until replaced or deleted with your account. We do not maintain a long-term location history, and exact coordinates are not sent to the AI that writes your routine.
- Health data — Apple Health is a Pro-only, opt-in feature that requires two separate consents: the iOS HealthKit permission prompt and a default-off toggle in Settings → Connections → Apple Health. When both are on, we can read recent sleep, steps/activity, and recovery-status signals to inform routines, generated stories, voice, and coarse adaptive-learning buckets. Sleep wind-down sessions can also write Mindful Minutes back to Apple Health when connected and permitted. We do not store raw HealthKit samples, exact HRV, exact sleep samples, or exact step-count history in the learned-memory aggregate. Turning the in-app toggle off is immediate: the next generation skips HealthKit entirely and sends nothing health-related to our servers.
- Subscription state — whether you have an active Pro subscription, the product, and renewal status. Source: Apple/RevenueCat.
- Preferences — your settings choices: theme, marketing-email opt-in, “help improve” opt-in, Personalized Memory setting, voice persona preferences, image-description preferences, accessibility toggles, optional personalization answers such as age band, identity/gender, goals, tone, daily rhythm, indoor/outdoor fit, weather comfort, movement intensity, social energy, preferred routine windows, and themes to use less often, plus your sleep-quiz answers when you take the sleep quiz.
- Public profile photo / avatar — optional user-uploaded image shown as your profile/social identity if you choose to add one. Pending uploads live in a private path while they are moderated; the published avatar is public to signed-in users and stored at
avatars/{uid}/avatar.jpg. Avatar image bytes are checked server-side by Google Cloud Vision SafeSearch and Google's Gemini vision classifier before publication. Both pending and published avatar files are deleted when you delete your account. - Daily usage counters — how many routines or paid AI features you used, to enforce free-tier and Pro fair-use limits.
- Device push notification tokens — when you grant notification permission, your device's Firebase Cloud Messaging token is stored at
users/{uid}/tokens/{tokenId}so we can send streak reminders and daily moment notifications. One entry per device. Tokens are deleted automatically when invalid and when you delete your account. - Website star ratings — if you rate the website with the star widget, we store your rating, optional comment, page, and a server timestamp. The stored rating contains no account ID, name, email, IP address, or IP hash. A short-lived rate-limit counter keyed on a one-way IP hash is scheduled to expire after 48 hours; Firestore processes the deletion asynchronously.
- Website contact messages — if you use the public contact form, we process the first and last name, email address, contact area, message type, and message text you submit. We also process the Cloudflare Turnstile response token and network IP address needed to verify the challenge. The raw form fields, token, and IP address are not stored in Firestore. For abuse prevention, Firestore stores deterministic SHA-256 hashes of the normalized email address and IP address as short-lived document keys, plus bounded counters, dates, submission times, and expiry times.
- In-app feedback you submit — when you tap Settings → Send feedback, we store the category, message body, and your account ID at
feedback/{id}. We do not auto-attach app version, OS, device model, route history, or other diagnostics. Deleted on account deletion. - Public posts you share — when you create a post in the social feed, we store the message body, your account ID, your display name, optional profile photo URL, time posted, and server-side moderation fields. Posts are visible to all signed-in Yovel users after your account creation date. Posts are checked by a local crisis classifier and by Google's Gemini API for sexual, violent, hateful, harassing, spam, and unsafe medical-advice content before publication; refused posts are never stored as public posts. When you delete a post, it is hidden/removed from the app, its body is cleared, and reactions are removed. Every post you authored is removed when you delete your account.
- Reports you file — when you report a post, we store the post id, reason, reporter account id, and status. We also maintain a server-only moderation queue aggregate for each reported post, including report counts and reason counts. Used to keep the feed safe; reports are reviewed within 24 hours. Reports you filed are deleted with your account, and your reporter-contributed queue counts are removed or decremented during account deletion.
- Block list — users you block are stored in your account, with a server-only reciprocal index so blocked accounts do not see each other's posts. Both lists tied to your account are deleted with your account.
- Device identifier hash — a one-way SHA-256 hash of your device vendor identifier (iOS) or Android ID, salted with a server-side secret pepper. We never store the raw device ID. The user-linked hash on your account is deleted when you delete your account. A minimal server-only fraud-prevention ledger keyed by the same hash may remain after deletion to enforce the lifetime two-account creation limit; it stores no raw device ID, email, name, wellness content, payment data, routines, mood entries, notes, or generated content.
- Email address hash for security logs — a one-way SHA-256 hash of your email address can be stored with security event records to detect abuse patterns. Records linked to your account are deleted when you delete your account and also expire by TTL.
- Security event records — server-only logs of signup attempts, rate-limit refusals, and App Check verification failures. Used solely for abuse prevention. Records auto-expire after 30 days via Firestore TTL and account-linked records are deleted immediately when you delete your account.
- Social abuse counters — server-only counters for social safety events such as post moderation refusals, report attempts, block actions, and reaction rate limits. They store small metadata such as event type, post id, category, reason, and timestamps; they do not store raw post text. Deleted when you delete your account.
- Email verification codes — for email sign-up, only a SHA-256 hash of the 6-digit code is stored. The record auto-expires after 10 minutes and is deleted after successful signup.
- Crash and error logs — crash and performance reports via Sentry and Apple's built-in reporting, used to fix bugs. They can include device model, OS version, stack traces, and operational app state. Yovel configures Sentry without default PII, console or network breadcrumbs, or intentional attachments of notes, moods, or wellness content.
Accessibility preferences (on-device only)
Eight toggles in Settings → Accessibility (VoiceOver hints, Voice Control labels, Larger Text, Reduce Transparency, Caption text size, High Contrast, Differentiate Without Color, and Larger Tap Targets) are stored on your device using the operating system's secure local storage. They are not uploaded to our servers, not synced across your devices, not used for analytics, and not sold to third parties. Uninstalling the app deletes these preferences along with the app itself.
How we use your data
- Service delivery: create routines, reflections, stories, voice, check-ins, notifications, social-feed features, subscription state, and support responses.
- Personalization: use your profile, recent moods, completions, habits, and learned patterns to make future output more relevant. Personalized Memory controls whether the learned-memory layer is used and updated; explicit profile answers remain separate until you edit or delete them.
- Safety: detect crisis language, show care resources, moderate names/photos/posts, and prevent harmful or abusive use.
- Security: detect and prevent abuse, rate-limit sensitive actions, enforce device-account limits, and protect subscriptions.
- Product improvement: only when you turn on Help improve Yovel, collect first-party Firebase Analytics events, and include your activity in anonymous, de-identified aggregate feature-usage counts, so we can see which features are useful. Turning it off excludes you from both.
- Legal compliance: respond to lawful requests from authorities and comply with subscription, tax, consumer-protection, and data-protection obligations.
We do not use your data for third-party advertising. We do not sell your data. If you separately opt in to Yovel product-update emails, your email address is used only for those direct communications. Yovel does not train its own AI models on your data or sell your data for model training. Third-party AI processors handle submitted content under the service terms applicable to Yovel's account and service tier. Personalized Memory personalizes your own Yovel experience; it is not third-party model training.
Who we share data with
Yovel does not track you across other companies' apps and websites, and we do not use third-party advertising or cross-app tracking SDKs. Firebase Analytics is first-party usage analytics and runs only while “Help improve Yovel” is on. Sentry is configured without default PII, console or network breadcrumbs, or intentional attachments of notes, moods, or wellness content. The other processors we use are listed below.
Yovel requires processors that receive personal data to provide the same or equivalent protection described in this policy and limits them to the service purposes listed below. If a production account or service tier cannot meet that requirement, Yovel will not send personal data to it.
- Anthropic (AI text generation and moderation): our backend sends prompts to Anthropic for routine generation, AI Coach reflections, weekly insights, mood reflections, sleep stories, Now Moment suggestions, display-name moderation. For weekly insights and mood reflections, the wire payload is a structured summary, not your raw mood-note text. Three paths can send text you wrote: the crisis-safety check during routine generation, short recent-note excerpts inside AI Coach recap prompts, user-typed place labels or sleep-story mood notes when those features need them. Anthropic's commercial API is configured so it does not train on this data. We do not send your Firebase UID or email to Anthropic.
- Google Cloud Vision (avatar moderation): when you upload an avatar, our backend sends the image bytes to Google Cloud Vision SafeSearch to detect nudity, sexual, violent, or unsafe image content before anything is published. The call runs server-side from Cloud Functions; no Vision API key is shipped in the app.
- Google Gemini (avatar and social-post moderation): after SafeSearch, our backend sends avatar image bytes to Google's Gemini API for a semantic check of weapons, hate symbols, drugs, and as a sexual/violence backstop. Before a proposed social post is published, its body text is also sent to Gemini for safety moderation. Yovel sends no Firebase UID or email with either request, never logs raw image bytes or proposed post text, and fails closed if moderation is unavailable. Google processes these requests under the Gemini API terms applicable to Yovel's production credential and service tier.
- ElevenLabs (Pro voice synthesis): when a Pro subscriber or active trial user taps Listen, our backend sends a short voice script and limited context such as first name, time of day, mood scale, sleep hours, and weather category to ElevenLabs to generate audio. We do not send mood notes, message text, full name, email, or Firebase UID. Generated audio and its short transcript are cached in Firebase Storage for up to 1 hour and also deleted immediately when you delete your account. Streaming playback uses a one-time Firebase session that can hold the short script for up to 5 minutes if playback never starts; consumed sessions are deleted immediately.
- Google Places: when you grant location and use place-aware features, Yovel's backend sends coordinates to Google Places to identify a place category. No Yovel account identifier is sent to Google Places.
- Apple WeatherKit: when weather-aware features are enabled, Yovel's backend sends coordinates to Apple WeatherKit to fetch current weather. No Yovel account identifier is sent to Apple WeatherKit.
- Apple / RevenueCat: Apple processes subscriptions as merchant of record. RevenueCat receives your Firebase user ID and subscription product to manage entitlements. Apple may retain purchase records under its own legal obligations even after you delete your Yovel account.
- Google Firebase: Firebase Authentication, Firestore, Storage, Cloud Functions, Cloud Messaging, and Firebase Analytics are operated by Google and store or process Yovel account data. Cloud Functions can process operational invocation metadata, including the function name and caller network IP address, for request delivery, security, and service operations under Google's applicable retention policies.
- Google Sign-In: if you choose Continue with Google, Google authenticates you and returns only what is needed to create your Yovel account, such as email address and display name/profile photo URL if available.
- Sign in with Apple: if you choose Sign in with Apple or Continue with Apple, Apple authenticates you and returns only what is needed to create or access your Yovel account, such as email address and, on the first authorization only, full name if you share it. Apple may provide a private relay email if you choose Hide My Email.
- Resend: when you sign up with email and password, Resend sends the email verification code to your inbox. Resend receives your email address and the message contents for that transactional email. When a social post is reported, Resend also sends a moderation notice to Yovel admins with report metadata such as reason, post ID, author UID, reporter UID, created time, and report ID; the reported post body is not included in that email. For the public contact form, Resend receives the sender’s name, email address, contact area, message type, and message text to deliver one message to the configured Dakkak Labs inbox; a confirmation is attempted for the sender. Contact messages are kept in the studio mailbox only as long as needed to respond, maintain necessary business records, resolve disputes, or meet legal obligations. Resend’s handling is governed by its service terms. Firestore TTL does not delete email copies.
- Sentry: pseudonymous crash and performance reporting. Reports can include operational diagnostics such as device model, OS version, stack trace, and app state. Yovel configures default PII off, disables console and network breadcrumbs, and is configured not to attach your email, Firebase UID, notes, moods, or wellness content.
- Cloudflare Turnstile: used on the public contact form and website star-rating widget to reduce spam. For the contact form, our backend sends Cloudflare the Turnstile response token and the request’s network IP address to validate the submission. Cloudflare processes that data under its privacy terms.
Voice synthesis with ElevenLabs
First name and contextual data (sleep hours, mood scale, weather, time of day) are sent to ElevenLabs for audio generation. No mood notes or message text are sent. Audio is cached in Firebase Storage for up to 1 hour to enable instant replay, then cleared. Streaming playback uses a one-time Firebase session that can hold the short script for up to 5 minutes if playback never starts; consumed sessions are deleted immediately. Audio and any remaining stream sessions are also deleted immediately when you delete your account. Pre-recorded voice samples for the picker are static MP3 files served from Firebase Storage.
Help improve Yovel (off by default)
If you opt in via Settings → Account → “Help improve Yovel,” the app turns on Firebase Analytics: first-party usage analytics showing which screens are visited and which features are used. This helps us improve the app and prompts at the product level.
Help improve Yovel is separate from Personalized Memory. Help improve Yovel is off by default and controls analytics collection. Personalized Memory controls whether Yovel learns from your own account activity to personalize your own experience. Neither setting sells your data or shares it with advertisers; data sent to feature-specific AI processors is described above and is not controlled by the analytics toggle.
You can opt in or out anytime in Settings. Turning Help improve Yovel off stops analytics collection on your device immediately. Analytics identifiers are reset when you delete your account.
When Help improve Yovel is on, we also keep an internal, de-identified count of how often each feature is used — for example, total mood check-ins, sleep sessions, or AI Coach recaps — combined across everyone who has opted in. These are plain whole-number totals with no identifiers and no personal content: never your chat or AI Coach text, mood values or notes, location, Apple Health data, voice, or anything you write. Only accounts with Help improve Yovel on are included, so turning it off removes you from these counts. Your essential account information, such as your email and sign-in, keeps working the same either way and is never part of these usage counts.
Legal bases for processing (GDPR / UK GDPR)
- Contract: we process the data needed to deliver Yovel to you (account, routines, completions, subscription).
- Consent: we process location, HealthKit data, marketing-email contact, and "help improve" data only with your explicit consent.
- Legitimate interest: we process basic security, fraud prevention, and crash-error logs to keep the service safe.
- Legal obligation: we retain certain data when required by law (e.g., subscription transaction records for tax purposes).
Your privacy rights
Depending on where you live, you have one or more of these rights:
- Access: see what data we hold about you. Email [email protected] and we will respond within 30 days.
- Rectification: correct inaccurate data.
- Erasure: delete your account-scoped data via Settings → Account → Delete account. This is immediate and irreversible for Yovel-controlled account data.
- Learned-memory reset: delete only the derived Personalized Memory layer, including Memory Center corrections and hidden-memory records, via Settings → Memory & AI → Reset Personalized Memory. This does not delete raw account history.
- Portability: receive a machine-readable copy of your data. Email us; we use an admin export process to prepare your account data.
- Restriction: limit how we use your data while we resolve a question.
- Objection: object to certain processing, such as legitimate-interest fraud prevention; we will review the request against our legal and security obligations.
- Withdraw consent: for consent-based processing such as location, health, marketing, Help improve Yovel, and Personalized Memory, you can withdraw or turn off the feature in Settings.
- Lodge a complaint: with your local data protection authority. EU residents: your local DPA. UK residents: the ICO. Brazilian residents: the ANPD. Maine residents: the Maine Office of the Attorney General, Consumer Protection Division, 6 State House Station, Augusta, ME 04333.
Account deletion
You can delete your account and account-scoped Yovel data anytime in Settings → Account → Delete account. Deletion is immediate and irreversible. We delete the data we control, including:
- Your Firebase Authentication record (email, sign-in history).
- Your user profile, preferences, ToS acceptance record, and Personalized Memory controls.
- Routines, mood entries, completion records, habits, habit logs, weekly insights, AI Coach recaps, mood-pattern reflections, sleep profile, and generated sleep stories tied to your account.
- Derived learned-memory records: adaptive-learning aggregate, weekly digests, monthly themes, yearly arcs, dynamic notes, Memory Center corrections, and hidden-memory records.
- Place lookup caches tied to your account, now moments, Home/Work pins, manual check-ins, and current check-in labels/feedback.
- Subscription state and Yovel-controlled usage counters, webhook event records, rate-limit counters, and active two-step login challenges.
- Device push notification tokens for each device you signed in on.
- In-app feedback you submitted.
- Public posts you authored, reactions tied to your account, reports you filed, and your block list in both directions.
- Your avatar files, including pending uploads and the published profile photo.
- The user-linked hashed device identifier on your account record; the raw device ID was never stored.
- Security event records linked to your account and crisis-resource rate-limit markers.
- Generated voice audio, transcript cache, and any remaining streaming voice sessions under your account.
Important caveats: deleting your Yovel account does not cancel an active Apple subscription; cancel it separately in Settings → [Your Apple ID] → Subscriptions. Apple may retain purchase records under its own legal obligations. A minimal server-only device-account fraud-prevention ledger may remain after account deletion to enforce the lifetime two-account creation limit. That ledger stores no raw device ID, email, name, wellness content, payment data, routines, mood entries, notes, or generated content.
Backups are retained as 14 daily backups and up to 12 weekly backups, then automatically purged. After those backups expire, we retain no Yovel-controlled account content outside the narrow fraud-prevention and legal records described in this policy.
Marketing emails
If you opt in at signup or in Settings → Account → "Email me product updates," we may send you occasional product-update emails (typically once a month or less). Every email has a one-click unsubscribe link in the footer. You can also turn it off in Settings anytime.
We send transactional emails (account verification, password reset, receipt) regardless of your marketing preference — those are required for the service to work.
Email updates list
If you ask for Yovel product-update emails from the website (for example, the email-updates form on the Yovel page), we store your request in a dedicated list so we can send you the updates you asked for. This list is separate from the app and is not linked to any Yovel account — signing up for updates does not create, or connect to, an app account.
- What we store — your email address, the timestamp of your request, the source page you signed up from, and whether the Cloudflare Turnstile anti-spam check passed. Nothing else.
- Why — only to send the product-update emails you asked for.
- Where — in a Firestore
emailSignupscollection, not tied to any Yovel account. - Never sold — we never sell, rent, or share this list with advertisers or other third parties.
- Opt-out — every product-update email includes a one-click opt-out.
- Deletion — email [email protected] to be removed from the list, and we honor the request within 30 days.
Children
Yovel is not directed to children. The minimum age to use Yovel is 13 (United States) or 16 (European Union, unless you have explicit parental consent). If we discover that a child below the minimum age has created an account, we will delete it.
How long we keep data
- Account data: for as long as your account exists, then deleted when you delete your account, subject to backups and narrow legal/security records below.
- Personalized Memory: derived learned-memory records, including Memory Center corrections and hidden-memory records, stay while your account exists unless you reset Personalized Memory. Turning Personalized Memory off stops use and new learned-memory writes but does not delete existing learned-memory records until you reset them or delete your account.
- Generated voice audio: cached for up to 1 hour for instant replay, then cleared by scheduled cleanup; also deleted immediately on account deletion.
- Streaming voice sessions: one-time Firebase session records can hold the short voice script for up to 5 minutes if playback never starts; consumed sessions are deleted immediately, and any remaining sessions are deleted on account deletion.
- Crash/error logs: 90 days, then automatically deleted.
- Security event records: TTL-expire after 30 days and account-linked records are deleted on account deletion.
- Website anti-spam rate-limit records: these records are no longer used after their configured cooldown or quota window. They are scheduled to expire 48 hours after the record is created or refreshed. Firestore processes TTL deletion asynchronously, so physical deletion may occur later.
- Backups: 14 daily backups and up to 12 weekly backups after account deletion, then automatically purged.
- Help improve Yovel analytics: collected only while opted in; analytics collection stops immediately when you turn it off, and identifiers reset on account deletion.
- Device-account fraud ledger: a minimal server-only ledger may remain after account deletion to prevent delete/recreate abuse and enforce the lifetime two-account creation limit. It stores no raw device ID, wellness content, payment data, routines, mood entries, notes, or generated content.
- Legal-record retention: subscription transaction records and tax/accounting records may be retained up to 7 years where required by law.
International data transfers
Yovel uses Firebase, hosted in the United States. When you use the service from outside the US (e.g., the EU, UK, Brazil, Australia), your data is transferred to the US. These transfers rely on Google's Standard Contractual Clauses, available at https://firebase.google.com/support/privacy.
Apple-grade privacy posture
Yovel is built to match Apple's first-party-app privacy bar:
- No App Tracking Transparency prompt — we don't track you across apps and websites.
- No advertising or cross-app tracking SDKs (no Mixpanel, Amplitude, Facebook Pixel, etc.); the only analytics is Firebase Analytics, off by default and controlled by the “Help improve Yovel” toggle.
- Data minimization: only what the feature needs, only when it needs it.
- Privacy-protective defaults: marketing off, location only when in use, HealthKit minimal scope.
- iOS privacy-manifest requirements are reviewed during release so Required Reason API declarations stay aligned with the shipped build.
- Strong encryption in transit and at rest, via Firebase.
Where Yovel is available
Yovel's website is available worldwide. The iPhone app is in active testing; public download or reviewer access will be linked from the Yovel page when ready. No matter where you are, you can reach us with privacy questions at [email protected].
We respond to data-protection requests under the law that applies in your region, including GDPR (EU/EEA), UK GDPR, LGPD (Brazil), PIPEDA (Canada), CCPA / CPRA (California), and equivalents in Australia, Japan, and elsewhere. Account deletion is available to anyone, anywhere, at no charge.
Changes to this policy
We will give you at least 30 days' notice — via email and an in-app banner — before any material changes take effect. The Last updated date at the top of this page will reflect the latest revision.
Recent versions
- v1.33 (2026-07-20) — Disclosed an internal, de-identified aggregate feature-usage count (anonymous whole-number totals such as mood check-ins or sleep sessions) computed once a night only from the activity of accounts that have Help improve Yovel on, containing no identifiers and no personal content, and used only to understand which features are valuable. Turning Help improve Yovel off excludes the account from these counts. No new third-party processor, tracking, advertising, or data sale was added.
- v1.32 (2026-07-18) — Documented the new website email-updates list: when you request product-update emails from the site, we store only your email address, request timestamp, source page, and Turnstile pass in a separate Firestore
emailSignupscollection that is not linked to any Yovel account, never sold, includes a one-click opt-out in every email, and is deleted on request within 30 days. No tracking, advertising, or data sale was added. - v1.31 (2026-07-18) — Added the evidence-backed app-owned Apple privacy-manifest inventory, separated Health from Fitness, reconciled personalization and analytics purposes including the existing optional product-update email use, configured Sentry diagnostics without default PII, and corrected the current avatar and social-post processors to Google Cloud Vision SafeSearch plus Google Gemini. No tracking, third-party advertising, or data sale was added.
- v1.30 (2026-07-18) — Corrected the disclosure for the existing website contact flow: Turnstile receives the verification token and request IP, Resend delivers contact details and message content, Firestore keeps only deterministic hashed quota keys with bounded metadata, and TTL deletion is asynchronous. No new processor, tracking, advertising, or data sale was added.
- v1.28 (2026-07-07) — Aligned the public availability wording with Yovel's current active iPhone testing state and clarified that public download or reviewer access will be linked from the Yovel page when ready. No new data collection, tracking, advertising, or data sale.
- v1.27 (2026-07-06) — Clarified short-lived streaming voice session retention. Streaming voice session URLs contain only an opaque session id; raw script text is sent in an authenticated request body and short-lived Firebase session records are deleted when consumed or on account deletion. No new tracking, advertising, or data sale.
- v1.26 (2026-07-06) — Clarified optional Apple Health write-back: when Apple Health is connected and permitted, sleep wind-down sessions can write Mindful Minutes back to Apple Health. No new tracking, advertising, or data sale.
- v1.25 (2026-07-02) — Added optional Mood factor chips to mood entries. They are bounded enum metadata stored on the existing mood entry, deleted with the account, and do not add a new third-party processor, tracking use, or App Store data category.
- v1.24 (2026-06-28) — Added the then-current social-post moderation disclosure. That historical Anthropic provider was replaced by Google Gemini and is superseded by v1.31; proposed social posts are checked server-side before publication, reported posts create server-only moderation queue aggregates, and social abuse counters are account-linked safety metadata deleted with the account. No tracking, advertising, or data sale.
- v1.23 (2026-06-20) — Narrowed the iOS privacy-manifest wording so the public policy does not overclaim beyond the tracked release source of truth. No new data collection, tracking, or advertising use.
- v1.22 (2026-06-20) — Corrected the authentication-processor disclosure to list Sign in with Apple alongside Google Sign-In. No new data collection, tracking, or advertising use.
- v1.21 (2026-06-19) — Added Personalized Memory controls, Memory Center correction/hide records, and learned-memory reset. Turning Personalized Memory off stops learned-memory use and new learned-memory writes. Reset deletes derived learned-memory records only; full account deletion deletes account-scoped stores. No new third-party AI training and no new advertising/tracking use.
- v1.20 (2026-06-18) — Added optional public profile photo/avatar disclosure and two-layer server moderation before publication. Google Cloud Vision SafeSearch was added as an avatar-moderation processor alongside the then-current Anthropic vision layer; v1.31 records its later replacement by Google Gemini. Avatar files are deleted on account deletion.
- v1.19 (2026-06-17) — Clarified device-account-limit retention: account deletion removes the user-linked device hash from the account, but a minimal server-only fraud-prevention ledger may remain to enforce the lifetime account-creation limit. The ledger stores no raw device ID, email, name, wellness content, payment data, routines, mood entries, notes, or generated content.
- v1.18 (2026-06-11) — Added backend retention and security hardening: scheduled cleanup for generated voice audio, TTL metadata for short-lived rate-limit and webhook records, immediate deletion of active two-step login challenges on account close, and an admin export process for data portability. No new third parties added.
- v1.17 (2026-06-10) — Added account-backed Reflection history for saved AI Coach recaps and mood-pattern reflections. These saved reflections survive reinstalling or signing back in, remain tied to the user's account, and are deleted when the user deletes the account. No new third parties added.
- v1.16 (2026-06-05) — Expanded the unified app-wide personalization profile to include optional adaptive preferences: indoor/outdoor fit, rough-weather comfort, movement intensity, social energy, preferred routine windows, and activity themes Yovel should use less often. Stored at
users/{uid}/personalization/core, saved through the same backend validation path, erased on account close, and folded into prompts sent to Anthropic on the same server-side path already disclosed. No new third parties added. - v1.15 (2026-05-29) — Disclosed the AI Coach 14-day correlation window, the server-derived adaptive-learning aggregate, and long-term memory summaries. The raw 14-day data does not leave the server; only bounded summaries/digests are included in prompts. No new third parties added.
Contact
Questions, requests, or complaints: [email protected]. We respond within 30 days.