YET LEGAL
Privacy Policy
Effective: August 31, 2026
This Privacy Policy explains how YET collects and uses personal data through the YET mobile application, website and related services. The data controller is Tommaso Savorana, based in Italy and operating YET. Privacy requests: info@yet.social.
1. Data we collect
Account and authentication
Email address, unique username, display name, authentication provider, email-verification status, password credentials managed by Firebase Authentication, passkey credentials, account creation date, acceptance records for legal terms and security information. YET does not receive your Google or Apple account password.
Profile information
Profile image, biography, links and other details you choose to provide. Optional details may include date of birth or age, nationality and place of residence. The app identifies which fields are public. Email address, authentication data, notification tokens and account-security settings are private and are not displayed on public profiles.
Events and social activity
Events you create, edit, attend, save, share, comment on or collaborate on; event title, category, image, location, dates, links, visibility and invitation lists; followers, following, blocks, collaboration responses, reports and notification interactions. Public events and public profile information may be visible to signed-in users and, where a share link is opened, may be represented on the public YET website. Private events are restricted according to their invitation and access settings.
Location
With permission, the app may use precise or approximate device location to calculate distance, find nearby events and set a home-area view. You may instead select a city manually. Event creators may publish an event location, which becomes visible according to the event's visibility. You can change iOS location permissions at any time.
Chats, comments and support
Messages, shared-event references, comments, conversation participants, read state and timestamps are processed to deliver inbox features. Current YET chats are protected by authenticated access controls and encryption in transit and at rest, but they are not end-to-end encrypted. Support emails, moderation reports and their attachments may be retained to answer requests and investigate safety issues.
Device, notification and technical data
Push tokens, notification preferences, app and operating-system version, device identifiers used for security, App Check attestations, server logs, IP-derived security information, request timestamps, crash or diagnostic data and records needed to detect abuse, maintain availability and troubleshoot errors. YET also records a limited, allowlisted set of first-party product interactions, such as sessions, event views, shares, attendance changes and feature use. These records do not include message contents, email addresses, precise location or advertising identifiers.
2. Why we process data
| Purpose | Typical legal basis |
|---|---|
| Create accounts, authenticate users and provide events, profiles, chats and notifications | Performance of our agreement with you |
| Personalise nearby and following feeds | Performance of our agreement; permission for device location |
| Prevent spam, fraud, account abuse and security incidents | Legitimate interests and legal obligations |
| Moderate reports, enforce rules and protect users | Legitimate interests, contractual enforcement and legal obligations |
| Send essential account and service email | Performance of our agreement and legitimate interests |
| Improve reliability using aggregate product and diagnostic information | Legitimate interests, with consent where required |
| Send marketing or use advertising tracking in the future | Consent where required; not active on the current website |
3. Notifications
If enabled, YET may notify you about messages, follows, event invitations, collaboration requests, comments, attendance, event changes and reminders before, during or near the end of events. Default preferences are created with an account and can be changed in the app. iOS settings can disable all push notifications.
4. Who receives data
We disclose only what is reasonably necessary to:
- other users, based on profile, event and collaboration visibility;
- service providers, including Google Firebase and Google Cloud for authentication, database, storage, hosting, server functions and messaging; Apple for App Store, Sign in with Apple, device services and push delivery; Resend for transactional and support email; and GoDaddy for domain and DNS services;
- professional advisers or authorities, where necessary to establish rights, respond to lawful requests, prevent harm or comply with law;
- a successor organisation, in a merger, financing, reorganisation or transfer, subject to applicable confidentiality and notice requirements.
We do not sell personal data. We do not disclose private chats to advertisers.
5. International transfers
Providers may process data outside Italy or the European Economic Area. Where required, transfers rely on an adequacy decision, Standard Contractual Clauses or another lawful safeguard. Provider documentation contains further information about their processing locations and safeguards.
6. Retention
We retain account and content data while your account is active and as needed to provide the Service. Deleted content is removed from active systems according to operational schedules and may remain temporarily in secure backups. Security logs, support correspondence, abuse reports and enforcement records may be retained for a limited period where needed to prevent repeat abuse, resolve disputes, establish legal claims or comply with law. Raw allowlisted product-interaction records are automatically scheduled for deletion after 90 days; longer-lived aggregate counters contain no message content, email address, precise location or advertising ID. We periodically review data that is no longer required.
7. Account deletion
You can initiate deletion in the app. The deletion flow is designed to remove the authentication account, active profile, private account record, device tokens, passkeys, user-linked product analytics, relationship records, uploaded media and content controlled solely by that account. Some conversation or collaboration records may retain a neutral tombstone where necessary to preserve another user's conversation or event integrity. Legally required, security and backup retention described above may continue for a limited period. You may also contact info@yet.social.
8. Your rights
Subject to applicable law, you may request access, correction, deletion, restriction, portability or objection, and may withdraw consent without affecting earlier lawful processing. Contact info@yet.social. We may need to verify your identity before acting. You may lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali) or your local supervisory authority.
9. Security
YET uses authenticated access controls, separate private account records, Firestore and Storage security rules, TLS network encryption, encryption at rest provided by infrastructure services, App Attest/App Check for supported requests, limited server credentials and monitoring. No system is completely secure. Use a unique password, enable available account-security features and report suspected compromise promptly.
10. Children
YET is not intended for children under 14. We do not knowingly collect their data. If you believe a child under 14 created an account, contact us so we can investigate and take appropriate action.
11. Website cookies and analytics
The current public website does not use advertising or marketing cookies. Strictly necessary storage or request data may be used for security and delivery. See the Cookie Policy. If non-essential analytics, advertising or campaign tracking is introduced, YET will update its notices and obtain consent where required before activating it.
12. Changes and contact
We may update this policy as YET, providers or law change. Material changes will be communicated where appropriate and the effective date will be updated. Questions and rights requests may be sent to info@yet.social.
Controller: Tommaso Savorana, operating YET, Italy.