Privacy Policy

Effective: August 31, 2026

This Privacy Policy explains how YET collects and uses personal data through the YET mobile application, website and related services. The data controller is Tommaso Savorana, based in Italy and operating YET. Privacy requests: info@yet.social.

1. Data we collect

Account and authentication

Email address, unique username, display name, authentication provider, email-verification status, password credentials managed by Firebase Authentication, passkey credentials, account creation date, acceptance records for legal terms and security information. YET does not receive your Google or Apple account password.

Profile information

Profile image, biography, links and other details you choose to provide. Optional details may include date of birth or age, nationality and place of residence. The app identifies which fields are public. Email address, authentication data, notification tokens and account-security settings are private and are not displayed on public profiles.

Events and social activity

Events you create, edit, attend, save, share, comment on or collaborate on; event title, category, image, location, dates, links, visibility and invitation lists; followers, following, blocks, collaboration responses, reports and notification interactions. Public events and public profile information may be visible to signed-in users and, where a share link is opened, may be represented on the public YET website. Private events are restricted according to their invitation and access settings.

Location

With permission, the app may use precise or approximate device location to calculate distance, find nearby events and set a home-area view. You may instead select a city manually. Event creators may publish an event location, which becomes visible according to the event's visibility. You can change iOS location permissions at any time.

Chats, comments and support

Messages, shared-event references, comments, conversation participants, read state and timestamps are processed to deliver inbox features. Current YET chats are protected by authenticated access controls and encryption in transit and at rest, but they are not end-to-end encrypted. Support emails, moderation reports and their attachments may be retained to answer requests and investigate safety issues.

Device, notification and technical data

Push tokens, notification preferences, app and operating-system version, device identifiers used for security, App Check attestations, server logs, IP-derived security information, request timestamps, crash or diagnostic data and records needed to detect abuse, maintain availability and troubleshoot errors. YET also records a limited, allowlisted set of first-party product interactions, such as sessions, event views, shares, attendance changes and feature use. These records do not include message contents, email addresses, precise location or advertising identifiers.

2. Why we process data

3. Notifications

If enabled, YET may notify you about messages, follows, event invitations, collaboration requests, comments, attendance, event changes and reminders before, during or near the end of events. Default preferences are created with an account and can be changed in the app. iOS settings can disable all push notifications.

4. Who receives data

We disclose only what is reasonably necessary to:

We do not sell personal data. We do not disclose private chats to advertisers.

5. International transfers

Providers may process data outside Italy or the European Economic Area. Where required, transfers rely on an adequacy decision, Standard Contractual Clauses or another lawful safeguard. Provider documentation contains further information about their processing locations and safeguards.

6. Retention

We retain account and content data while your account is active and as needed to provide the Service. Deleted content is removed from active systems according to operational schedules and may remain temporarily in secure backups. Security logs, support correspondence, abuse reports and enforcement records may be retained for a limited period where needed to prevent repeat abuse, resolve disputes, establish legal claims or comply with law. Raw allowlisted product-interaction records are automatically scheduled for deletion after 90 days; longer-lived aggregate counters contain no message content, email address, precise location or advertising ID. We periodically review data that is no longer required.

7. Account deletion

You can initiate deletion in the app. The deletion flow is designed to remove the authentication account, active profile, private account record, device tokens, passkeys, user-linked product analytics, relationship records, uploaded media and content controlled solely by that account. Some conversation or collaboration records may retain a neutral tombstone where necessary to preserve another user's conversation or event integrity. Legally required, security and backup retention described above may continue for a limited period. You may also contact info@yet.social.

8. Your rights

Subject to applicable law, you may request access, correction, deletion, restriction, portability or objection, and may withdraw consent without affecting earlier lawful processing. Contact info@yet.social. We may need to verify your identity before acting. You may lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali) or your local supervisory authority.

9. Security

YET uses authenticated access controls, separate private account records, Firestore and Storage security rules, TLS network encryption, encryption at rest provided by infrastructure services, App Attest/App Check for supported requests, limited server credentials and monitoring. No system is completely secure. Use a unique password, enable available account-security features and report suspected compromise promptly.

10. Children

YET is not intended for children under 14. We do not knowingly collect their data. If you believe a child under 14 created an account, contact us so we can investigate and take appropriate action.

11. Website cookies and analytics

The current public website does not use advertising or marketing cookies. Strictly necessary storage or request data may be used for security and delivery. See the Cookie Policy. If non-essential analytics, advertising or campaign tracking is introduced, YET will update its notices and obtain consent where required before activating it.

12. Changes and contact

We may update this policy as YET, providers or law change. Material changes will be communicated where appropriate and the effective date will be updated. Questions and rights requests may be sent to info@yet.social.

Controller: Tommaso Savorana, operating YET, Italy.