Privacy Policy
Last updated: June 5, 2026 · Applies to com.yaz.app
Yaz is a “save-for-later” app for links. This policy explains exactly what Yaz accesses, what it stores, where that data lives, and the choices you have - across the mobile app, the browser extension, and the optional sync backend.
The short version. Yaz works fully offline with no account, and your library stays on your device. If you turn on sync, your library is end-to-end encrypted on your device before it ever leaves it. We don’t sell your data, we don’t show ads, and we never receive readable copies of your saved links.
1. What Yaz collects
Links you choose to save
When you save a link, Yaz stores the information you give it: the URL, and - fetched automatically from the public page - its title, description, thumbnail/preview image, site name, and detected platform (e.g. TikTok, YouTube, Instagram). You can also add your own note, tags, title, folder, favorite flag, and reminder. Yaz acts only on links you explicitly save; it does not monitor your browsing or your other apps.
If you enable sync - your Telegram identity
Sync is optional and off by default. To sign in you authorize the Yaz Telegram bot, which provides the standard Telegram login fields: your Telegram user ID, username, display name, and profile photo URL. We use these to identify your account.
A session token
After login, a signed session token is stored securely on your device
(the OS keychain / expo-secure-store on mobile, or
chrome.storage.local in the extension) so you stay signed
in. It is sent over HTTPS to authenticate your sync requests.
If you join the beta - your email address
When you submit your email on this website to join the Google Play closed test, we store that email address solely to enroll you as a tester and send the invite. This is separate from the app itself and is covered in How data is used below.
2. What Yaz does not collect
- No browsing history, and no pages you didn’t explicitly save.
- No contacts, no location, no advertising identifiers.
- No third-party analytics or ad SDKs in the app.
- The Telegram bot cannot read your Telegram chats, messages, or contacts - a bot only ever sees messages and files you send directly to it.
3. How data is used
Your data is used only to provide the features you asked for:
- Saved links - to build, display, search, and organize your library.
- Telegram identity - to identify your account and let your devices sync.
- Session token - to keep you signed in and authorize sync requests.
- Beta email - to enroll you in the closed test and send the invite link.
We do not:
- sell, rent, or share your data with third parties for advertising;
- use your data for profiling, creditworthiness, or lending decisions;
- use your beta email for marketing unrelated to the test.
4. Where data is stored
- On your device. Your library is the source of truth and lives in on-device storage (SQLite). With sync off, your data never leaves your device.
- In your own Telegram chat (sync on). Your entire library is encrypted on-device and uploaded as a single encrypted file to your private chat with the Yaz bot. The readable bytes are never visible to us.
- In the Yaz backend (sync on). Our backend (Supabase) stores only a small per-user pointer record: your Telegram profile, a reference to the encrypted file, a version number, and the encryption key your own devices use to decrypt. It does not store your readable links.
- Beta email list. Tester emails submitted on this site are stored in our backend (Supabase) and used only as described above.
All network transmission uses HTTPS / TLS.
5. Third-party services
- Telegram - used for login/identity and as the storage location for your encrypted library file. Your use of Telegram is also governed by Telegram’s own privacy policy.
- Supabase - hosts the Yaz backend functions and the small pointer/email database.
- Link previews. To build a preview, the app fetches the public page of a link you save (its Open Graph / oEmbed metadata) directly from that site, the same way a browser would.
6. Security
- End-to-end encryption. When sync is on, your library is encrypted with XChaCha20-Poly1305 on your device. The encryption key is provisioned to your own devices over HTTPS; Telegram only ever receives ciphertext.
- Least-privilege backend. Database tables are locked so that only the server-side functions (which authenticate your session and scope every query to your account) can read or write.
- Secure on-device storage for your session token via the platform keychain.
No method of transmission or storage is 100% secure, but we design Yaz so that the most sensitive data - your actual saved content - is unreadable to us by default.
7. Retention & deletion
- Local data remains on your device until you delete links or uninstall the app.
- Synced data is retained until you delete it. Deleting a link syncs the deletion to your other devices and your Telegram backup.
- Account deletion removes your profile, the server pointer/key, and the encrypted backup in your Telegram chat - immediately and permanently, with no retained backups. See the Delete account & data page.
- Beta email. Email us to be removed from the tester list at any time.
8. Your rights & choices
- Use Yaz with no account - keep everything local.
- Disconnect sync at any time from the app or extension; this clears the session token from that device.
- Access & export - your full library lives on your device, and (when synced) in your own Telegram chat.
- Delete - remove individual links, or your whole account and data, at any time.
Depending on where you live, you may have additional rights (access, correction, deletion, portability). Contact us and we’ll help.
9. Children
Yaz is not directed to children under 13 (or the minimum age in your country), and we do not knowingly collect their data. If you believe a child has provided us data, contact us and we’ll delete it.
10. Google Play Data Safety summary
This table summarizes our practices to match Google Play’s Data Safety framework.
| Data type | Collected? | Purpose | Shared? |
|---|---|---|---|
| Email address (beta sign-up) | Yes, if you join the beta | Enroll tester & send invite | No |
| App identity (Telegram ID, name, username, photo) | Yes, if you enable sync | Account management & sync | No |
| Saved links & your notes/tags | Yes (on device; encrypted if synced) | App functionality | No (stored encrypted; we can’t read it) |
| Location, contacts, browsing history, ad IDs | No | - | No |
Data is encrypted in transit, you can request deletion, and we do not sell your data.
11. Changes to this policy
If we make material changes, we’ll update the “Last updated” date above and, where appropriate, notify you in the app. Continued use after an update means you accept the revised policy.
12. Contact
Questions, data requests, or deletion requests:
jossyfreelancer@gmail.com