Privacy Policy
Last updated October 2026 · Effective 2026-10-02 · Version 2
What changed: Yaap now runs on Railway, with uploaded files stored by Tigris underneath it, in place of Replit; the subprocessor list in the Privacy Policy and the Data Processing Addendum names them. Nothing else changes.
Scope
This policy explains what Yaap does with personal data. Yaap is operated by BlackHoodie LLC, 7 Adeline Drive, North Haven, CT 06473, United States. In this policy "we", "us", and "Yaap" mean BlackHoodie LLC, and "you" means the person reading it.
It covers yaapai.com, the Yaap application, and the text messages and emails sent through it. It was last updated in October 2026; the effective date and version number are at the top of this page.
A link to this policy sits in the footer of every public page and in the account menu inside the app. If you use assistive technology and cannot read any part of it, tell us through the privacy request form and we will get it to you another way.
Two other documents go with this one: our Terms of Use, and our Data Processing Addendum, which is the contract covering the data a business stores in its own workspace.
Two roles
Yaap plays two different roles with personal data, and which parts of this policy apply to you depends on which one.
We are the controller for the data of the people who sign up for Yaap: workspace owners, admins, and members, plus visitors to our website. That is your name, your email address, your phone number, your sign-in records, your billing records, and how you use the product. We decide what to collect and why, and all of this policy applies to you.
We are a processor for everything a business puts into its workspace: its customers, leads, deals, notes, tasks, messages, estimates, invoices, documents, files, and form submissions. That business decides what to collect and why. We act on its instructions, under the Data Processing Addendum.
If you are a customer of a business that uses Yaap and you want to see, correct, or delete what that business holds about you, ask the business — it controls the record and it can answer you fastest. You can also use our privacy request form: we will pass your request to the business and tell you that we have. We cannot decide it for them.
What we collect
We collect these categories of personal data.
- Account and sign-in data — your name, your email address, and the one-time codes we email you to sign you in. Yaap has no passwords, so we store none.
- Workspace data — the workspace name, your role in it (owner, admin, or member), and the settings you choose. For text messaging we also collect the business details the carriers require: legal name, business address, contact email and phone, an EIN if the business has one (sole proprietors are registered without one), and a description of how the business gets consent to text people.
- Billing data — your plan, your usage counts, invoices, and the record of the terms you accepted, with the wording shown to you, the date, your user account, and your IP address. Card numbers go straight to Stripe; we never see or store them.
- Content in a workspace — customers, leads, deals, notes, tasks, tags, estimates, invoices, inventory, subscriptions, documents, uploaded files, and any custom fields the business defines. We are a processor for this content.
- Messages — the text messages and emails sent and received through Yaap, including phone numbers, email addresses, the content, timestamps, and delivery status.
- E-signature records — when someone signs an estimate or a document, we record the typed or drawn signature, the signer's name and email address, the time, and the IP address the signature came from.
- Form submissions — whatever a business asks for on a form it publishes through Yaap, from the person who fills it in.
- Technical and security data — IP address, browser and device information, server logs, and an audit log of what happened in a workspace and who did it. API keys and webhook endpoints a workspace creates are recorded too.
- What you send us — the contents of a privacy request or a support email, including the address you write from.
Most of this comes from you, or from the business whose workspace you appear in. Some of it comes from the providers that run parts of Yaap: delivery and opt-out results from our text-messaging provider, delivery and bounce results from our email provider, and subscription and payout status from Stripe.
Please do not put Social Security numbers, driver's licence numbers, financial account credentials, health records, or payment card numbers into Yaap's notes, custom fields, or file uploads. Yaap does not ask for them and is not built to hold them.
Why we use it
We use personal data for these purposes.
- To run the product — store and show your records, send the messages you write, run the automations you build, produce estimates, invoices, and documents, and process the payments you set up.
- To sign you in and keep accounts secure — one-time codes, sessions, rate limits, abuse prevention, and audit logs.
- To bill you — subscriptions and metered usage, and to keep the record of what you agreed to.
- To support you — answering questions and fixing faults, which sometimes means our staff looking at the records involved.
- To keep the service working and improve it — error logs, performance data, and counts of how features get used. We do not build advertising or behavioural profiles.
- To meet legal duties and protect people — tax records, text-messaging consent and compliance records, responding to lawful requests, investigating abuse of the platform, and enforcing our Terms of Use.
- To transfer the business, if it is ever sold or merged — on the terms set out in Sharing below, and only after we have told workspace owners.
Communications we send you. Sign-in codes, billing notices, receipts, trial and renewal reminders, security alerts, service notices, and notices that these documents have changed are transactional messages. They are part of running your account, so you cannot opt out of them while the account exists — a sign-in code with an unsubscribe link would lock you out of your own workspace. We do not send marketing email without your consent, and any marketing email we ever send will carry an unsubscribe link that works.
AI processing
Yaap includes an assistant. It reads the plain-English instructions an owner types in the app or sends by text, and it carries out actions in that workspace: creating a customer, drafting an invoice, sending a message the owner approves.
To do that, we send the instruction and the workspace records needed to answer it to Anthropic, PBC, which runs the Claude models Yaap uses. Anthropic holds the inputs and outputs of those calls for a limited period under its commercial terms, to deliver the service and check for misuse, and then deletes them. It is a processor for us and may not use the content for anything else.
We do not use your personal data to train large language models, and our AI provider does not train its models on the content we send it.
The assistant acts on instructions a person gives it. It does not make legal decisions, or decisions of similar significance, about any individual: it does not score, rank, or profile people, and it takes no part in decisions about credit, employment, housing, insurance, education, or access to essential services. Actions that move money or send something to a customer need the owner's confirmation before they run.
Yaap's assistant is an AI system. It can make mistakes. Check important facts, amounts, and dates before you rely on them, and review any message or document it drafts before it is sent.
Our Terms of Use say more about that.
Text messaging
Businesses use Yaap to text their own customers. The business collects the consent, outside Yaap, and is responsible for it. We register each business's messaging campaign with the carriers under that business's own name and send its messages through Telnyx, our text-messaging provider.
Reply STOP to any text sent through Yaap and the carrier network and our messaging provider stop that number from being texted, and the opt-out is recorded there. Reply HELP to any text sent through Yaap for help with the messages you are receiving. If you ask a business to stop in any other way — in a reply that does not say STOP, or in person — that business must honour it, and our Terms of Use require it to.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes.
All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
We never sell mobile information.
We pass phone numbers and message content to Telnyx only to deliver the messages a business sends and to receive the replies. Nobody else gets them for marketing or promotional purposes.
Where data lives
Yaap runs in the United States. The application is hosted by Railway in the United States, and the database by Neon, now part of Databricks, in Amazon Web Services' us-east-1 region. Stripe, Telnyx, Resend, and Anthropic process our data in the United States as well.
Those providers may use staff or infrastructure in other countries to support their own services; their privacy policies, linked in the table above, say what they do. We do not otherwise move personal data out of the United States.
Yaap is offered to businesses in the United States, and this policy is written for United States law.
Retention
We keep personal data for as long as we need it to run Yaap and to meet our legal duties, and no longer. In practice:
| What | How long we keep it |
|---|---|
| Everything in a workspace — customers, leads, deals, notes, tasks, messages, estimates, invoices, documents, and uploaded files | While the workspace exists. Export what you need — signed documents especially — before you delete it, because we will not have a copy afterwards. |
| The record of the terms you accepted and of your billing | Three years after we write the record, or one year after the subscription ends, whichever is later. These records survive workspace deletion, because they are the proof of what was agreed. |
| Audit logs — who did what in a workspace | While the workspace exists. |
| Privacy requests and what we decided | Long enough to handle the request, answer any appeal, and show that we did. |
| Your account record — name, email address, and sign-in history | While you belong to a workspace, and after that only for as long as other records still refer to it. Ask through the privacy request form and we will delete it or strip it of anything that identifies you. |
| Delivery records held by our text and email providers | Under those providers' own retention rules, which their privacy policies describe. |
Some records outlive a deletion request because the law requires it: tax and payment records, the consent records above, and anything we are told to preserve for a legal claim or an investigation. When that happens we keep only what we must and tell you why.
When a workspace is deleted
When an owner deletes a workspace today, its content is deleted straight away and cannot be recovered — by you or by us. There is no grace period and no copy to restore from, so export whatever you need, signed documents especially, before you delete it.
Security
We follow industry-standard security practices. Traffic to Yaap is encrypted in transit. Each workspace's secrets — the credentials and keys it stores — are encrypted at rest under a key derived for that workspace alone. Access to production data is limited to the people who need it to operate and support the service. Every change made through Yaap is written to an audit log, with who made it and when, and the application scopes every query we run on your behalf to your own workspace, so one workspace's records are not returned to another.
No system is perfectly secure, and we do not claim to follow any named security framework or hold any security certification.
If there is a breach. If we discover a breach of security affecting personal data, we tell the affected business immediately, because that business owns the records. Where the duty to notify falls on us, we notify affected Connecticut residents without unreasonable delay and no later than 60 days after we discover the breach, and we notify the Connecticut Attorney General no later than we notify residents.
Your rights and how to use them
If you are a Connecticut resident — and in most cases if you live in another state with a comprehensive privacy law — you have these rights over the personal data we hold as controller.
- Know and access — ask whether we process personal data about you, and get a copy of it.
- Correct — have anything inaccurate fixed.
- Delete — have your personal data deleted, except what we must keep by law (see Retention).
- Take it with you — get a portable copy. Customers, invoices, and estimates export as CSV from inside the app at any time; ask through the form for anything else.
- Opt out of the sale of personal data or targeted advertising — there is nothing to opt out of, because we do neither, but we will record and honour the request anyway.
- Withdraw consent — wherever we relied on your consent, you can take it back.
- Appeal — if we turn a request down, you can appeal the decision.
How to make a request. Use the privacy request form. We email you a link to confirm the request really came from the address you gave; open it and we start work. That link is the only verification we normally ask for. Requests are worked and answered by the owner of the platform, from that form.
How long we take. We answer within 45 days of getting the request. If it is complex we may take one further 45 days, and we will tell you the reason within the first 45. We honour a request to opt out of sale or targeted advertising, and a withdrawal of consent, within 15 days. Requests are free once every 12 months; if requests are repeated or excessive we may charge a reasonable fee or decline, and we will say which and why.
Appeals. If we deny a request, our answer tells you why, tells you how to appeal, and gives you a reference number. Submit the appeal on the same form, choose "Appeal a previous decision", and quote that reference. We answer appeals in writing within 60 days. If we deny your appeal, you can complain to the Connecticut Attorney General online at https://portal.ct.gov/ag/sections/privacy.
Requests about a business's own records. If your request concerns what a business keeps in its workspace, we pass it to that business, tell you we have, and help the business answer it. The business makes the decision.
California, Texas, and other states
California. If you are a California resident, the California Consumer Privacy Act gives you rights over the personal information we hold. It covers the work contact details of people who use Yaap for their employer — name, work email, work phone, job title — the same as any other personal information. You can ask us to tell you what we collect and why, get a copy, have it corrected, and have it deleted, and you can appoint an authorised agent to ask on your behalf. We will not treat you differently for asking. We do not sell or share personal information as those words are defined in that law, we have not done so in the past twelve months, and we do not use or disclose sensitive personal information beyond what is needed to provide the service, so there is nothing to limit. The categories we collect, the reasons, the sources, and who we disclose to are the ones set out above in What we collect, Why we use it, and Sharing. Make a California request the same way as any other: the privacy request form.
Texas. If you are a Texas resident, the Texas Data Privacy and Security Act gives you the same core rights — know, access, correct, delete, take a portable copy, and opt out of sale, targeted advertising, or profiling that produces legal or similarly significant effects. Again, we sell nothing, run no targeted advertising, and do no such profiling. Use the same form, with the same 45-day window and the same appeal route. If we deny your appeal, you may also complain to the Texas Attorney General.
Other states. Residents of the other states with comprehensive privacy laws have broadly the same rights, and we handle every request the same way regardless of where you live: same form, same windows, same appeal. If your state's law gives you a right this policy does not name, ask for it and we will apply it.
Global Privacy Control. We do not sell personal data and we run no targeted advertising, so an opt-out preference signal such as Global Privacy Control has nothing to switch off here. If we ever did either, we would treat the signal as a valid opt-out. You can also send us an opt-out through the privacy request form at any time, and we will record it.
Children
Yaap is a tool for businesses. It is not directed at children, we do not market it to them, and we do not knowingly collect personal data from them. If you believe a child's personal data has reached Yaap, tell us through the privacy request form and we will delete it.
A business using Yaap is responsible for the data it puts into its own workspace, including any data about people under age.
Changes
We update this policy when the product or the law changes. The month it was last updated (October 2026), the effective date, and the version number appear at the top of this page, so you always know which text you are reading.
If a change is material, we email every workspace owner at least 30 days before it takes effect and publish the new text here in the meantime. Until the effective date this page shows the version still in force, with a link to the upcoming one; from that date it shows the new version, with a link to the previous one.
If you do not agree with a change, you can cancel before it takes effect. Our Terms of Use say how.
Contact
For anything about privacy — any of the rights above, a question about this policy, or a complaint — use the privacy request form. It is the fastest route and every request through it is tracked and answered.
For help with the product, email support@support.yaapai.com.
For legal notices, write to BlackHoodie LLC, 7 Adeline Drive, North Haven, CT 06473, United States.
BlackHoodie LLC operates Yaap at yaapai.com.