Scope and who is responsible
This Privacy Policy explains how Yazora ("Yazora", "we", "us", or "our") handles personal data when you use our website, web, desktop, or mobile applications, workspaces, and related services (together, the "Service").
If you use Yazora through an organization or a team workspace, that organization may control the workspace content and account settings it manages. Its own privacy notices may also apply.
Information we collect
We collect information you provide, information created while you use the Service, and limited technical information needed to operate and secure Yazora.
- Account and profile data, such as your name, email address, authentication identifier, profile image, chosen sign-in method, language, and settings.
- Workspace content, including documents, tables, drawings, files, comments, links, publications, membership details, roles, permissions, and related metadata.
- Technical and security data, such as IP address, browser, device and operating-system details, app version, request times, sync state, diagnostics, and security or audit events.
- Messages and support information you choose to send to us.
How we use information
We process personal data when it is necessary to provide the Service you requested, pursue legitimate interests such as security and reliability, comply with law, or act on your consent where consent is required.
- Create and manage accounts, authenticate users, and remember essential preferences.
- Save, synchronize, organize, search, share, publish, export, and restore workspace content.
- Enable collaboration, permissions, workspace administration, and security auditing.
- Provide support, maintain reliability, prevent abuse, and comply with legal obligations.
- Improve the Service using aggregated feedback and operational information.
Local-first storage and synchronization
Yazora is local-first. The Service stores working copies, caches, and preferences on your device so you can continue working with limited or no connectivity. When you are signed in and a connection is available, eligible workspace data is synchronized with our cloud services.
- Clearing browser or app storage can remove local copies and preferences, but it does not automatically delete content already synchronized to the cloud.
- Local work that has not synchronized may be lost if the app, browser data, or device storage is removed.
- When you deliberately publish a document, the published snapshot and required assets can be accessed through its public link until you withdraw it. Later private edits are not added to that publication until you choose to update it.
Optional AI features
AI features are optional. When you request an AI writing action, Yazora sends the selected text, limited surrounding document context, action settings, and necessary request or usage information through a Yazora service to Google's Gemini API. Yazora does not send your entire workspace merely because AI features are available.
- Only use AI actions when you are comfortable sending the relevant text for external processing.
- Avoid including secrets, highly sensitive personal data, or information you are not authorized to share.
- Google's handling, retention, and possible product-improvement use of AI content can vary by service tier and region under its current terms.
Cookies and device storage
Yazora uses browser or device storage for essential functions such as authentication persistence, language selection, offline content, caches, and synchronization queues. We do not currently use third-party advertising cookies on the Yazora landing site.
Your browser, operating system, or device settings may let you clear this data. Doing so can sign you out, reset preferences, or remove unsynchronized local content.
Data retention
We keep account and synchronized workspace data while your account or workspace is active and for as long as needed to provide the Service. Deleted items, backups, security records, and workspace audit events may remain for a limited period based on product configuration, recovery needs, fraud prevention, dispute resolution, or legal requirements.
When information is no longer needed, we delete it, anonymize it, or isolate it until deletion is possible. Public content can remain available until its publication is withdrawn.
Security and international transfers
We use access controls, encryption in transit, provider security features, and operational safeguards designed to protect personal data. No service can guarantee absolute security, so please use a strong password, protect your devices, and report suspected account misuse.
Our providers may process information in countries other than where you live, including the United States. Where required, we rely on appropriate contractual or legal safeguards for international transfers.
Your privacy rights
Privacy rights vary by location. We may need to verify your identity and authority before completing a request. Some data may be retained where the law permits or requires it, including for security, legal claims, or the rights of other people.
- Ask whether we process your personal data and request access to it.
- Correct incomplete or inaccurate data.
- Request deletion, restriction, or objection where the law provides.
- Request a portable copy of eligible data.
- Withdraw consent for future processing where consent is the legal basis.
- Complain to your local data-protection authority.
Children
Yazora is not directed to children under 16, and we do not knowingly collect their personal data without valid authorization. If you believe a child has provided personal data contrary to this policy, contact us so we can review and take appropriate action.
Changes to this policy
We may update this policy as Yazora, our providers, or applicable laws change. We will post the revised policy here and update the date above. If a change materially affects your rights, we will provide additional notice where required.
Contact us
For privacy questions or requests to access, correct, export, or delete personal data, email info@yazora.app. Please describe your request and the account or workspace it concerns. Do not send passwords or confidential document content by email.