Draft — not yet reviewed by a lawyer.
This document describes how YieldOS actually works today and is
published so it can be checked. It is not legal advice. Passages marked
like this are decisions that have not been made yet.
The short version
- Your shop's records — including your customers' details — belong to you. We hold
them to run the service and for nothing else.
- We do not sell personal information, and we do not use your customers' data to
advertise anything.
- Each shop's data is isolated from every other shop's in the database itself, not
only in application code.
- The assistant sends what it retrieves to an AI provider in order to answer. That is
described in full below, because it is the part people are most likely to be
surprised by.
1. The two different roles we play
This distinction decides who you should ask about what, so it comes first.
- For your shop's own account — the business name, your staff's names
and email addresses, your subscription — we are the controller. We decide
how that information is used, and you can ask us about it directly.
- For your customers' information — the homeowners you quote and
invoice — we are a processor acting on your instructions. You decide what is
collected and why. A homeowner asking to see or delete their record should ask the
shop that holds it; we will help that shop respond, but we will not act on their
records without them.
2. What we hold
About your shop and its staff
- Business name, address, time zone, trade.
- Each user's name, email address, role, and sign-in identity.
- Subscription status and, when card payments are enabled, an identifier issued by the
payment processor. We never see or store card numbers.
- An audit trail of who changed what and when, which is retained even after a person
leaves so that the history stays attributable.
About your customers, entered by you
- Name, service address, phone number, email address.
- Quotes, invoices, payment records, job and appointment history.
- Equipment installed at the property, and notes your staff record about the work.
- Messages sent to them through the service.
Technical
- Server logs, including IP address and the requests made. Recipient addresses and
phone numbers are masked in logs rather than written in full.
- A sign-in session cookie, and small amounts of browser storage for your own
preferences (theme, sidebar). No advertising or cross-site tracking cookies.
3. Why we hold it
To provide the service you are paying for, to keep it secure, to bill you, and to meet
legal obligations such as retaining financial records. We do not profile your customers
and we do not sell data to anyone.
4. Who else it reaches
Only the providers needed to run the service:
| Who | What they do for us | What reaches them |
| Oracle Cloud Infrastructure | Runs the application server and the database | All of it |
| Cloudflare | Serves the web app, terminates TLS, stores encrypted database backups | Web traffic; encrypted backups |
| Zitadel (self-hosted) | Sign-in and account identity | Staff names, email addresses |
| MailStack | Sends email on a shop's behalf | Recipient address and message contents |
| Groq | Runs the assistant's conversational model | The question asked, and the records the assistant retrieves to answer it |
| OpenRouter | Runs scheduled background analysis (weekly summaries, catalogue enrichment) | Catalogue and job-history text |
Not currently enabled, and listed so the table stays honest as they are:
text messaging (Twilio) and card payments (Stripe). This page will be updated before
either is switched on.
We may also disclose information where the law requires it. If we are ever compelled to
hand over a shop's data, we will tell that shop unless we are legally prohibited from
doing so.
5. The assistant and other AI features
Stated separately because it is the least obvious thing this product does with data.
- When someone at your shop asks the assistant a question, the question and the
records it retrieves in order to answer are sent to an AI provider (see the table
above). Those records can include customer names, addresses and job history.
- Scheduled background analysis — weekly summaries, catalogue enrichment — sends
catalogue and job-history text to an AI provider.
- The assistant can only reach data the person asking could already reach. It re-checks
that person's permissions on every step; it does not have privileges of its own.
- We do not permit these providers to train models on your content.
[To be confirmed in writing against each provider's terms.]
6. Where it lives
Data is stored in the United States. If you or your customers are elsewhere, using the
service involves transferring information there.
7. Keeping it separate, and keeping it safe
- Every tenant's rows are separated by database-level row security, so isolation does
not depend on application code getting a filter right. It is tested continuously.
- Traffic is encrypted in transit. Where we hold a third-party access token on
your behalf, it is encrypted at rest with a key held separately.
- Access is by named account with role-based permissions, and administrative access to
the servers is restricted.
- Every change to a record is written to an audit trail.
No system is perfectly secure. If a breach affects your data we will notify you without
undue delay and tell you what we know.
8. How long we keep it
- Live data: for as long as your account is open. Records are
deactivated rather than destroyed when you remove them, so that history and audit
trails remain intact.
- Backups: taken nightly, transferred over an encrypted connection
to object storage that encrypts them at rest, retained for 14 days, then deleted.
Data you delete persists in backups until those expire.
- After you close your account: we delete your data on request. Without
a request, it is removed within [retention period — not yet
decided] of closure.
9. Your rights
Depending on where you live you may have the right to access, correct, export or delete
personal information, and to object to some processing. To exercise them:
- If you are a shop using YieldOS, contact us.
- If you are a homeowner whose details are in a shop's account,
contact that shop. They control the record; we act on their instructions. If you
cannot reach them, contact us and we will try to help.
We will not discriminate against you for exercising any of these rights.
10. Children
The service is for businesses and is not directed at children. We do not knowingly
collect information from anyone under 16.
11. Changes
We will post changes here and update the date at the top. Material changes will be
notified in the app or by email before they take effect.
12. Contact
[contact address]