Yutova
How it works Inside Yutova Privacy Pricing FAQ
Get Yutova
Your Privacy

Privacy Policy

Last updated: August 13, 2026

Welcome

You're trusting Yutova with some of your most private thoughts — burnout, anxiety, heartbreak, the things you don't always say out loud. We take that seriously. This Privacy Policy explains what information we collect, why, the legal basis we rely on, how it's used, and what control you have over it.

Mariam Dabaghyan IE (“Yutova,” “we,” “us,” or “our”) provides an AI-assisted journaling and reflection application, and acts as the data controller for the personal information described in this policy. If anything here is unclear, contact us at help@yutova.com.

Our Commitment

Protecting your privacy isn't a formality for us — it's central to whether this product can do what it's meant to do. People won't write honestly if they don't feel safe, so keeping your data safe and private is treated as a product requirement, not just a policy.

Why We Store Data

We store your data on secure cloud infrastructure rather than only on your device, for a few practical reasons: cross-device access, protection against data loss (device-only encryption risks permanent loss if a device or key is lost), and reliability.

1. Information We Collect

  • Account information: Email address and any other information you provide when creating an account.
  • Onboarding responses: Your answers to onboarding questions — what brought you to Yutova, journaling style preference, what progress means to you, your preferred reflection cadence, how you identify and your age range, which parts of life come up for you most, and any free-text notes — including if you choose to skip some or all of them.
  • Journal entries: The content you write in the app.
  • Voice recordings: If you use voice journaling or its transcription.
  • AI-generated content: Reflections, patterns, suggestions, and other output generated based on your entries and onboarding responses.
  • Automatically collected information: Device type and operating system (only when contacting support), IP address, general usage data, and crash/diagnostic data.
  • Biometric authentication: If you enable Face ID/Touch ID/passcode lock, we receive only a success/failure signal from your device. Your actual biometric data never leaves your device.

2. Special Category Data

Your journal entries and reflections may reveal information about your mental or emotional health. In some jurisdictions (notably the EU/UK under GDPR Article 9), this may be treated as special category data, which requires a higher standard of protection than ordinary personal data.

Where this applies, we rely on your explicit consent — given when you create an account and begin journaling — as our basis for processing this category of data. You may withdraw this consent at any time by deleting your account (Section 10), which stops further processing and begins the deletion process described there.

3. Legal Basis for Processing

Depending on the processing activity, we rely on the following legal bases under applicable data protection laws:

  • Providing the core Service (entries, reflections, account): Performance of a contract with you.
  • Special category data (journal/emotional content): Explicit consent (see Section 2).
  • Security, fraud prevention, and legal compliance: Legitimate interest / legal obligation.
  • Analytics and service improvement: Legitimate interest (using aggregated and anonymized data).
  • Marketing communications (if applicable): Consent, which you may withdraw at any time.

4. How We Use Your Information

  • To provide the Service: Generating your reflections, displaying your entry history, and applying your cadence and other preferences.
  • To maintain the Service: Diagnosing technical issues, ensuring compatibility, and keeping the app running reliably.
  • To improve the Service: Using aggregated, anonymized usage data. We do not use identifiable journal content to train or fine-tune any AI model, under any circumstance (see Section 5).
  • To protect Yutova and its users: Preventing fraud, enforcing our Terms of Service, and meeting legal obligations.
  • To personalize your experience: Tailoring reflections, suggestions, and Library recommendations to your entries and stated preferences.

We do not use your journal entries or reflections for advertising targeting, and we do not sell your personal information.

5. AI Processing

To generate your reflections, your journal entries and relevant context are processed by OpenAI's commercial API. Processing is stateless and ephemeral — your data is transmitted only to generate that specific response and is not retained or used to train any AI model, under our agreement with OpenAI. Data sent is limited to what's needed to generate your reflection.

6. Other Third-Party Services

We use a limited set of third-party services to operate and improve Yutova:

  • Cloud data storage: Supabase, hosted on AWS. See Section 9 for encryption and security details.
  • AI Processing: OpenAI — see Section 5.
  • Analytics & crash reporting: Yutova does not embed any third-party analytics, behavioral tracking, or crash-reporting SDKs — see Section 7 for the website-specific cookie policy, which is the only place any tracking technology is used.
  • Email & Support: Hostinger — Processes support requests and user feedback transmitted over encrypted SSL/TLS connections — journal entries and reflection content are never sent to these tools.

Each third-party provider has its own privacy practices governing the data it processes on our behalf.

7. Cookies & Tracking Technologies

If you visit our website (https://yutova.com) rather than the app itself, we may use cookies and similar technologies for strictly necessary website operations and website analytics. You can manage or disable cookies at any time through your browser settings.

Mobile App Exemption: This section does not apply to the Yutova mobile application itself, which does not use cookies, advertising identifiers, or third-party behavioral tracking tools.

8. Non-Disclosure of Sensitive Journal Content

We do not sell, share, or otherwise distribute your journal entries, reflections, or any content that could identify you personally, except where required by law (for example, in response to a valid legal order). This is a core commitment, not a fallback position.

9. Data Security

We implement robust technical and organizational measures designed to protect your personal information against unauthorized access, loss, or alteration:

  • Encryption in Transit & at Rest: All data transmitted between the app, website, and our servers is encrypted in transit using industry-standard Transport Layer Security (TLS 1.3). Stored database records and backups are encrypted at rest using AES-256 encryption on secure AWS/Supabase cloud infrastructure.
  • Client-Side Content Protection: Your private journal reflections and sensitive entries are additionally protected with authenticated 256-bit encryption (XSalsa20-Poly1305), with encryption keys stored securely in your device’s hardware-backed Keychain / Secure Enclave.
  • Access Control & Row-Level Security: Access to our database is governed by strict Row-Level Security (RLS) policies, ensuring each user’s data is isolated and accessible only by their authenticated account. Internal administrative access is restricted to authorized personnel under least-privilege principles and multi-factor authentication.
  • Biometric Lock: You can enable optional on-device biometric security (Face ID, Touch ID, or Device Passcode) in the app settings to restrict access to sensitive actions.
  • Ongoing Security Practices: We maintain security through automated vulnerability scanning, regular dependency updates, secure coding standards, and continuous infrastructure monitoring.

10. Data Retention & Deletion

You may delete your account at any time from within the app's Settings.

Upon deletion, your account data and journal content will be deleted immediately.

You may also request deletion by contacting us at help@yutova.com.

We retain different categories of data for different periods based on why we need them — for example, account data is retained while your account is active, and anonymized/aggregated analytics data may be retained longer since it no longer identifies you:

  • Journal Entries, Reflections & AI Insights: Lifetime of your active account (or until manually deleted by you).
  • Account Profile & Preferences: Lifetime of your active account.
  • Encryption Keys & Biometric Credentials: Lifetime of your active account.
  • Customer Support Inquiries & Feedback: Up to 12 months from submission.

11. Your Privacy Rights

You have the right to:

  • Access your personal information
  • Correct inaccurate or incomplete information
  • Request deletion of your account and associated data

To exercise these rights, please contact us via help@yutova.com email address.

12. Children's Privacy

Yutova is not directed at children under 13 years old and we do not knowingly collect data from children under that age.

13. Incident Response

In the event of a data breach affecting your personal information, we will notify relevant supervisory authorities within 72 hours of becoming aware, where GDPR's breach-notification timeline applies, and will notify affected individuals without undue delay where the breach poses a high risk to your rights and freedoms.

14. Changes to This Privacy Policy

We reserve the right to modify this privacy policy at any time. If we make material changes to this policy, we may notify you here, by email, or by means of a notice on our home page.

15. Contact Us

Mariam Dabaghyan IE, Email: help@yutova.com

Yutova

© 2026 Yutova. All rights reserved.

Product How it works Inside Yutova Pricing FAQ
Company & Legal About us Support Privacy Policy Terms of Use
Download App Store Android — Coming soon
Almost there

Coming soon

Yutova is launching soon. We'll let you know when it's ready to download.