Privacy Policy
Effective September 11, 2026
This Privacy Policy explains how YourAI Incorporated (“YourAI,” “we,” “us”), processes personal information through our website, desktop application, web portal, chat, organization knowledge library, connected services, and context tools. The information processed depends on the features you or your organization use. Our Terms of Service govern use of the service.
1. YourAI and your organization
When an organization provides YourAI to its personnel, it determines its purposes for using the service, membership, and access policies. We process customer content to provide the service under that organization's instructions and our agreement. We also process information for our own account administration, billing, support, service security, and legal obligations. The organization's workplace and privacy notices explain its own uses of information and supplement this policy. Neither this policy nor an organization's agreement removes rights or obligations under applicable law.
2. Information we process
Accounts and operations. We process names, email addresses, organization membership and roles, authentication records, enrolled-device identifiers and public keys, connection authorizations, policy-acceptance records, billing and transaction records, and support communications. Technical records can include connection information, device and application versions, timestamps, errors, security events, and service usage. Model usage records can include provider names, token counts, and charges.
Computer memory. While desktop memory is enabled with the required permissions, YourAI processes visible activity on an enrolled workplace computer. This can include the application and window title, action type and time, control labels, recognized on-screen text, and generated work narratives. Depending on the platform, screen reading follows interactions or periodic checks.
The automatic desktop memory process processes screenshots temporarily in memory for local text recognition and, when enabled, cloud model understanding; that pipeline does not save screenshot image files. Cloud understanding sends an active-window image, recognized text, action information, and recent narratives through our vision service to a model provider. An additional low-resolution image of the surrounding display may be included when privacy checks permit it.
The input-event listener does not retain typed characters, raw typing sequences, or clipboard contents as input values. Text visible on screen, including text you typed or pasted, can nevertheless be recognized and retained in text records and narratives. Named control keys and shortcuts may appear in action records.
Application and window-title exclusions are checked before reading screen information. Model-based sensitivity checks can omit content from the stored record, but occur after content is sent for analysis. These checks can miss sensitive information and do not guarantee that private information will never be processed. Detailed activity and summaries are stored locally; enrolled devices upload signed narrative batches for hosted retrieval and organization knowledge processing.
Chats, files, and setup. We process chat messages, conversation titles, attachments, extracted text, responses, relevant context and tool results, and conversation activity records. Setup conversations retain work-profile answers, company research, and progress, and can create personal or shared library documents. Conversation records and published knowledge are separate copies. Images you upload can be stored with a conversation and are separate from automatic desktop memory.
Connected services and workflows. Authorized connections can supply email, messages, documents, calendars, contacts, work records, and source metadata such as authors, timestamps, identifiers, and permissions. Integration providers can hold the credentials needed for those connections. Background agents may periodically read connected sources without a separate request for each item. Enabled workflows can process task instructions, reports, and communications. Explicit computer or browser tools can process actions and screenshots, including saved screenshot files. Imported audio or video can produce transcripts, speaker labels, and selected image frames.
Organization knowledge and inferences. We process pages supplied by members and information generated from authorized source material, including descriptions of people, teams, projects, relationships, procedures, and work activity. Automated processing may select the initial audience of generated pages. Source-service permissions and YourAI library permissions are separate and are not necessarily identical. Generated information can be inaccurate and should be reviewed before reliance.
MCP requests and oversight. For hosted context tools, YourAI records the exact authenticated MCP request and response, including tool arguments, search queries, returned context, diagnostics, user identity, organization, client, and timing. Desktop MCP diagnostics also record exact tool arguments and responses, queue them locally, and transmit them to our telemetry service when diagnostics are enabled. These records can contain private organization knowledge and personal computer context; they are not anonymous usage counts. Other operational diagnostics use a more limited schema.
These records support service security, troubleshooting, and company oversight for organization-managed computers under the applicable agreement and law. They may be accessed by authorized YourAI operators and organization representatives authorized under that agreement. The MCP interface does not itself give us the surrounding AI conversation, but a tool request or recorded on-screen activity can contain conversation text. YourAI chat receives the messages and files you submit to it.
Information can come from you, your organization, authorized devices and connected services, sign-in and payment providers, public sources used for research, and the operation of the service. It can concern coworkers, customers, correspondents, and other people who do not have YourAI accounts.
3. How we use information
We use information to authenticate users; administer accounts, permissions, subscriptions, and payments; create and retrieve work context; generate knowledge and answers; carry out authorized workflows; support users; maintain reliability; investigate errors and misuse; protect the service; perform the disclosed oversight functions; and meet legal obligations or resolve disputes. We do not sell personal information or use it for advertising.
We use AI services to process content for the features described here. Inference, generation of your organization's knowledge, provider model training, and storage of service records are different activities. This policy does not grant us permission to use customer content to train general-purpose models. Provider retention and training restrictions depend on the service, endpoint, account settings, and agreement; do not assume a service-wide zero-data-retention guarantee. Any zero-retention arrangement applies only to its covered processing and does not delete YourAI's narratives, chats, or audit records or copies held by an AI application you choose.
4. Who receives information
Your organization. Organization-wide library pages are available to its members. Team pages are available to the relevant team and administrators; personal library pages are available to their member and organization administrators. Ordinary personal chats use owner-scoped portal access. These access labels do not prevent authorized service operations, support, or lawful access. Generated pages, indexes, and downloaded copies can reflect an earlier publication or permission state.
Providers. We disclose information needed for hosting, authentication, payments, communications, support, security, model processing, search, and integrations. Depending on the feature, these include Hetzner hosting; Cloudflare and Anthropic for desktop vision; Anthropic for agent processing; OpenRouter and its selected model providers for chat and setup; TinyFish for search; Composio for connected-service access; Google or GitHub for sign-in; and Stripe for payments. Model services can receive prompts, images, attachments, retrieved context, and tool results. Search services receive search terms and selections. Providers processing information on our behalf are authorized to use it for their service to us; providers may separately process their own account, security, or transaction records under their applicable terms. Contact us for information about providers relevant to your organization's use.
Services you choose. An AI application authorized to use YourAI context tools receives results within the applicable access permissions. It can retain them under its own terms and your organization's arrangements. Connected services also process authorizations and requests. Disconnecting does not recall information already received by another service.
Legal and business circumstances. We may disclose information when reasonably necessary to comply with applicable law or valid legal process, protect people or service security, or establish, exercise, or defend legal claims. A proposed or completed business transfer, merger, or financing may involve disclosure subject to confidentiality and applicable legal safeguards. Such a transaction does not by itself authorize new uses inconsistent with applicable law or existing commitments.
Google-connected information. Our use and transfer of information received through Google APIs is subject to the Google API Services User Data Policy and applicable Google Workspace user-data requirements, including Limited Use restrictions. We authorize use for the connected user-facing features, not advertising, sale, or development or training of generalized or non-personalized AI models. Human access and onward transfers must comply with those restrictions; the general oversight provisions above do not authorize access prohibited by them.
5. Storage, security, and international processing
We use authentication, access restrictions, encrypted transport, and encryption appropriate to the relevant storage. Hosted workspace, chat, context, and hosted-MCP audit stores use server-volume encryption. The desktop activity database is encrypted; synchronized organization documents and pending desktop telemetry are separate local files that depend on device and operating-system protections. Hosted context, chat, and oversight records remain readable by the services processing them and personnel with authorized access.
Workspaces configured for additional organization-key encryption use that protection for workspace files. Recovery options determine whether YourAI holds recovery material; they do not make every service record accessible only to the customer. No system guarantees complete security, and encryption at rest does not prevent access by a running, authorized service.
Information may be processed in countries where we and our providers operate, which may have different data-protection laws. Where applicable law requires safeguards for international transfers, those requirements apply to our processing. Contact us about locations and safeguards relevant to your service; this policy does not promise storage exclusively in your country.
6. Retention and deletion
We retain information according to its purpose, the organization's instructions and applicable agreement, the sensitivity of the information, and legal requirements. Service content supports continuing retrieval and organization knowledge; security and oversight records support investigations and accountability; billing and legal records support accounting, disputes, and compliance. Retention must remain connected to those purposes, rather than permitting unrelated use.
By default, detailed desktop activity is kept for approximately 24 hours before compaction, and summaries for approximately one year. These settings are configurable and cleanup depends on the application running. Local compaction does not delete previously uploaded narratives or derived knowledge. Hosted source material, chats, setup records, knowledge history, audit records, and backups have separate lifecycles; these local periods are not server deletion deadlines.
Revoking a device or account, disconnecting a service, stopping desktop memory, or uninstalling the application does not automatically erase previously stored information. Organization offboarding can preserve archives and backups, and removing an account is not a complete content-erasure operation. Contact us to coordinate export, retention, or deletion of organization data. We assess requests under the applicable agreement and law, including necessary exceptions for security, legal holds, disputes, and recordkeeping.
Ordinary chat deletion removes the conversation and its attachments from the active chat store. Setup conversations and published setup knowledge have separate handling. A device's activity-wipe function does not remove every synchronized file, pending telemetry record, or server copy. Deletion and correction may need to address imported records, derived knowledge, history, indexes, audit records, and backups separately. Copies previously downloaded or returned to another service are not automatically recalled.
7. Workplace notice, controls, and sensitive information
YourAI is intended for authorized work on organization-managed computers. The organization must give personnel appropriate notice, establish a lawful basis, and provide choices or obtain consent where required before collecting work activity, connected-source access, or oversight. Accepting terms, granting operating-system permissions, and authorizing a connection serve different purposes; none alone satisfies every workplace or communications-privacy requirement.
Depending on your role and configuration, you or your administrator can manage members and connections, revoke devices and hosted AI authorizations, and change knowledge permissions. Desktop memory can be paused or stopped, and device exclusions and diagnostics can be configured. Some controls require administrator or command-line assistance. Disabling desktop diagnostics stops that telemetry and removes its pending queue; it does not remove earlier hosted records or turn off hosted MCP auditing.
Visible and imported information can include sensitive health, financial, legal, credential, or other personal information. Do not supply information you lack authority to process. Filters are not a guarantee of removal. Generated descriptions and inferences need appropriate review before consequential use. The service is intended for adult business users and is not directed to children. Contact us if you believe a child has supplied account information; incidental information about children in customer content also requires appropriate handling by the organization.
8. Privacy rights and requests
Depending on applicable law, you may have rights to access or obtain a copy of personal information, correct it, request deletion, portability or restriction, object to processing, withdraw consent where processing relies on consent, or complain to a relevant regulator. Rights can be subject to lawful exceptions. We do not unlawfully discriminate against people for exercising privacy rights.
Email support@yourai.com with your request and the account or organization involved. Do not send passwords or unnecessary sensitive documents. We may request reasonable information to verify identity or authority and protect other people's information. We will assess whether to respond directly or assist the responsible organization, respond within applicable legal time limits, and explain any applicable limitation. You may ask us to review a response or provide an authorized-agent request or appeal where applicable law permits. Contact your organization's privacy contact about its workplace uses; we can help route the request.
9. Cookies and browser storage
We use cookies for sessions and authentication flows and browser storage for interface preferences. Clearing or blocking necessary cookies can affect sign-in and service functions. Our service does not use personal information for advertising or cross-context behavioral advertising. We do not change these practices in response to a browser Do Not Track signal; legally applicable opt-out preference signals and rights still apply.
10. Changes and contact
We may update this policy as the service or our practices change. We will identify the current version by its effective date and provide appropriate notice of material changes. We will obtain additional consent where required by law; updating a policy does not by itself authorize a new use that needs separate permission.
Privacy questions, security reports, and requests: YourAI Incorporated, support@yourai.com.