Privacy policy
Last updated: July 18, 2026
1. Who we are
YoDataSet (“we,” “us,” “our”) provides a platform that cleans, structures, and prepares files for AI model training and business use. This policy explains what data we collect, how we use it, and the choices you have.
2. What we collect
- Account data: name, email, password (hashed), and organization (if provided).
- Uploaded files: any images, PDFs, audio, or spreadsheets you upload for cleaning.
- Processing metadata: file names, sizes, processing timestamps, confidence scores, and cleaning actions applied.
- Usage data: pages visited, features used, and API calls made.
- Payment data: handled by our payment processor. We do not store full card numbers ourselves.
- Technical data: IP address, browser type, and device information.
3. How we use your data
- To process and clean the files you upload.
- To operate, maintain, and improve the platform.
- To communicate with you about your account or changes to the service.
- To detect abuse, fraud, or violations of our terms.
- To comply with legal obligations.
4. Your uploaded files, specifically
- Your files are processed solely to generate the cleaned dataset you requested.
- We do not use your uploaded files to train YoDataSet’s own models or any third-party models, except where you explicitly opt in (for example, to improve accuracy for your specific use case).
- Files are automatically scanned for personally identifiable information (PII) on upload; detected PII can be redacted at your option.
- Some processing steps (OCR, audio transcription) are performed using third-party AI providers. See Section 5.
5. Third-party subprocessors
We use the following categories of subprocessors to operate the service:
- Authentication, database, and file storage: Supabase (hosted on AWS, EU-West-1 region).
- Audio transcription: Groq (Whisper large-v3 model).
- Payment processing: a PCI-compliant payment processor (details shown at checkout).
Each subprocessor is contractually bound to protect your data and use it only to provide the relevant service to us.
6. Data retention and deletion
- Uploaded files and processed datasets are retained until you delete them or close your account.
- You can permanently delete any file, dataset, or your entire account at any time from Settings.
- Deleted data is removed from active systems within 30 days and from backups within 90 days.
- Files processed via the anonymous trial are automatically deleted after 24 hours.
7. Your rights
Depending on your location, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Delete your data.
- Export your data in a portable format.
- Object to or restrict certain processing.
- Withdraw consent where processing is based on consent.
To exercise these rights, contact us using the details in Section 12. We will respond within 30 days, or the timeframe required by applicable law.
8. Security
- All data is encrypted in transit (TLS) and at rest.
- Access to production systems is restricted and logged.
- We conduct periodic security reviews of our infrastructure and dependencies.
- No system is 100% secure; we will notify affected users of any confirmed data breach as required by applicable law.
9. International data transfers
Your data is processed primarily in the European Union (AWS EU-West-1 via Supabase). Where data is transferred internationally, we rely on appropriate safeguards such as Standard Contractual Clauses and our subprocessors’ adequacy commitments to protect transferred data.
10. Children's privacy
YoDataSet is not directed at individuals under 18. We do not knowingly collect data from children.
11. Changes to this policy
We may update this policy from time to time. Material changes will be notified via email or an in-app notice before taking effect.