YooYoo Privacy Policy
Last Updated: 2026-05-27 · Version: 1.0 Draft
YooYoo ("we", "our", "the Platform") values your privacy. This Privacy Policy describes how we collect, use, share, retain, and protect your personal information, and the rights you have under applicable law.
Please read this Policy in full before using YooYoo. If you do not agree with any provision, please do not use the Service.
1. Information We Collect
1.1 Information You Provide
| Category | Content |
|---|---|
| Registration | Email, phone number (optional), password (hashed) |
| Identity Profile | Nickname, birthdate, gender, nationality, city, native language, target languages |
| Personal Profile | Bio, interest tags, religion (optional), zodiac (optional), height (optional), education (optional), occupation (optional), relationship goals |
| Avatar & Photos | Photos you upload (up to 9) |
| Chat Content | Text / voice / image / video / gift messages sent and received, recall records |
| AI Inputs | Text you submit for AI polish / suggest / icebreaker |
| Payment | Order records via Apple IAP / Google Play / Stripe (card numbers do not reach us) |
| KYC Materials (optional) | National ID / passport / driver's license + liveness video (held by Sumsub etc.; we only store hash) |
| OV Withdrawal Account (if applicable) | Linked local bank / e-wallet account (KMS-encrypted) |
| Reports | Content of your reports about other users |
| Support Logs | Conversations with AI / human support |
1.2 Information We Collect Automatically
| Category | Content |
|---|---|
| Device | Device type, OS, app version, browser type, screen size |
| Device Fingerprint | Synthesized from above (for risk control; doesn't directly identify person) |
| Network | IP address (for geographic inference + risk control), network type |
| Geolocation | Precise coordinates if you grant browser / device permission; otherwise city-level via IP |
| Activity Logs | Login times, browsing, clicks, Like, Match, message send times (not content) |
| Performance / Errors | Page load times, crash logs, request latency |
| Cookies & Similar | See §7 |
1.3 Information We Receive from Third Parties
- Third-party login (if enabled): Apple / Google / Facebook / Line basic info (with your authorization)
- KYC providers (Sumsub / Onfido): verification results
- Payment channels: order status, refunds, risk signals
- Risk partners: blacklist / fraud alerts
2. How We Use Information
| Purpose | Legal Basis |
|---|---|
| Provide core service (registration, matching, chat) | Performance of contract |
| Automatically translate your messages | Contract + your consent |
| AI assistants generating icebreakers / polish / support | Contract + your consent |
| Content moderation and anti-fraud | Legitimate interest + legal obligation |
| Account security (risk control) | Legitimate interest + legal obligation |
| Payment processing and refunds | Contract + legal obligation |
| KYC and liveness verification | Legitimate interest + legal obligation |
| Notifications and marketing emails / push (with your permission) | Your consent (revocable anytime) |
| Personalized recommendations | Legitimate interest |
| Improve product / A/B experiments (anonymized) | Legitimate interest |
| Legal obligations (law enforcement, regulatory) | Legal obligation |
| Disputes and appeals handling | Legitimate interest + legal obligation |
3. Information Sharing
We do not sell your personal information for commercial purposes.
We share information only in the following circumstances:
3.1 With Third-Party Service Providers (Minimum Necessary)
| Provider | Data Shared | Purpose |
|---|---|---|
| Anthropic (Claude) / OpenAI / DeepSeek | Messages you submit for AI processing | AI assistants |
| DeepL / Google Cloud Translation / Aliyun | Messages to translate | Real-time translation |
| Sumsub / Onfido | KYC documents + liveness | Identity / liveness verification |
| Stripe / dLocal / PayMongo / Xendit / Apple / Google | Payment order info | Payment processing |
| LiveKit Cloud | Video call signaling + media streams | Real-time AV |
| SendGrid | Email address + content | Email delivery |
| Twilio | Phone + SMS content | SMS delivery |
| APNs / FCM | Device token + notification preview | Push notifications |
| Hive Moderation / Microsoft Content Moderator | Uploaded images / text | Content moderation |
| Sentry / OpenTelemetry / Datadog | Error stacks (PII-free) + metrics | Error / performance monitoring |
| Cloudflare | Network request basics (IP / UA) | CDN + WAF + DDoS |
| GrowthBook | User bucketing identifier (hash) | Feature flags / A/B |
Each provider has a Data Processing Agreement (DPA), bound by GDPR / national standards.
3.2 With Law Enforcement / Regulators
- Cooperate with lawful, properly authorized requests
- Proactive disclosure in emergencies (life safety, child protection)
- Disclosures audited; post-fact notification to users when not legally prohibited
3.3 With Affiliates / Successors
- Currently no affiliates
- Future M&A: your data transfers with the policy; successor must maintain at least equivalent protection
3.4 Public / Semi-Public Content
Fields you actively make public (nickname, age, city, bio, public photos, interest tags) are visible to other users. Private photos visible only to matches. Chat content visible only to you and the recipient (+ minimum moderation staff).
4. Cross-Border Data Transfer
YooYoo servers primarily located in [Singapore / Tokyo or other overseas regions].
4.1 Data Flows
See privacy/DATA-FLOW.md (engineering doc); user-facing summary:
| Your Data | Primary Location | Cross-Border Flow |
|---|---|---|
| Account & profile | Primary region | No proactive cross-border |
| Chat messages | Primary region | Temporary flow to EU/US during translation API (DPA-protected) |
| AI inputs | Primary region | Temporary flow to Anthropic US |
| KYC documents | Sumsub multi-region | Closest node based on your country |
| Payment orders | Primary region | Exchanged with payment channel US/EU nodes |
4.2 Legal Basis
- EU Users: Standard Contractual Clauses (SCCs) + IDTA
- Singapore PDPA: Per this policy + DPAs
- Thailand PDPA / Malaysia PDPA / Philippines DPA / Vietnam Cybersecurity Law / Indonesia GR 71: Assessed per local law; localization plans where required (see POLICY-NOTES.md P-05/06)
4.3 Your Choice
You may request your data be removed from specific third-party providers (except compliance retention).
5. Data Retention
| Data | Retention | Deletion |
|---|---|---|
| Active account profile | Until you close account | 30-day cooldown then deleted |
| Chat messages | Default 180 days (you can set 30) | Automatic |
| Voice message files | 90 days | Automatic |
| Video call recordings (if enabled) | 90 days | Automatic |
| Liveness videos | 30 days | Automatic |
| KYC records | 5 years (compliance) | Automatic |
| Risk event logs | 365 days | Automatic |
| Payment orders & ledger | 5 years (compliance) | Automatic |
| Audit logs | 365 days | Automatic |
| Notification history | 90 days | Automatic |
| Translation cache (hash) | 30 days | Automatic |
| AI logs | 90 days (30% sampled) | Automatic |
| Your data export link | 7 days | Automatic |
| Account cancellation cooldown | 30 days reversible | User-initiated |
6. Your Rights
Under GDPR, PDPA, PIPL, and other applicable laws, you have:
6.1 Right of Access
View all your data via Settings → Privacy → My Data.
6.2 Right to Rectification
Edit profile fields anytime (some key fields like birthdate have edit limits).
6.3 Right to Erasure / Right to be Forgotten
Account closure:
- 30-day cooldown (reversible)
- PII deleted after cooldown (except compliance retention)
- Anonymized / aggregated data not affected
6.4 Right to Data Portability (GDPR Art. 20)
Export all your data (JSON + media ZIP):
- 30-day email link delivery
- Includes content you generated
- Others' content (e.g., their messages in chats): nicknames, IDs, avatars anonymized or trimmed (see POLICY-NOTES P-10)
6.5 Right to Object (GDPR Art. 21)
Object to:
- Marketing / push (immediate effect)
- Automated decisions (AI compatibility scoring → see §10 EU User Note)
6.6 Right to Restriction (GDPR Art. 18)
Request we pause processing (without deletion) in specific cases. Submit via ticket.
6.7 Right to Withdraw Consent
Withdraw any "consent-based" processing anytime. Doesn't affect prior lawful processing.
6.8 Right to Complain
File complaints with your local data protection authority (EU DPAs, Singapore PDPC, etc.).
6.9 How to Exercise
- In-app:
Settings → Privacy → ... - Email:
dpo@yooyoo.app - Response within 30 days (GDPR) / per local law
7. Cookies & Tracking
7.1 Categories We Use
| Category | Purpose | Default |
|---|---|---|
| Necessary | Login session, CSRF, language preference | On, not disable-able |
| Functional | Theme, video volume, draft | On, disable-able |
| Analytics | Anonymous page stats | Off in EU (consent required); other regions on, disable-able |
| Marketing | (Currently none) | Off |
7.2 Your Choices
- EU users see Cookie banner with granular consent
Settings → Privacy → Cookiesto adjust anytime- Browser settings can also block (some features may break)
8. Minors
8.1 Age Floor: Service prohibits users under 18. Birthdate checked at registration; double-checked at KYC.
8.2 Suspected minors: Account frozen + manual review.
8.3 Children: We do not knowingly collect information from children under 13. If discovered, deleted immediately.
8.4 Parent / guardian: If you find your minor child has registered, contact dpo@yooyoo.app; we will assist with deletion.
9. China Mainland Users
9.1 YooYoo operates outside the PRC; servers overseas.
9.2 We do not proactively transfer user data to Chinese mainland authorities; we will evaluate any lawful, properly authorized cross-border judicial / regulatory request and act per applicable law.
9.3 China Mainland users' data is stored on overseas servers; this is not "data export" in the PIPL sense because the service is offshore from the start.
9.4 ToS §16 "China Mainland Access Notice" governs prerequisite consent.
10. EU Users (GDPR + AI Act)
10.1 Controller: The YooYoo operating entity [overseas company] is your data controller.
10.2 DPO: dpo@yooyoo.app
10.3 Legal Basis: See §2 for each processing purpose.
10.4 Cross-Border: See §4.
10.5 AI Act (2024 / 2025 phased in): Our AI assistants and personalized compatibility scoring may fall within "automated decision making":
-
AI-based compatibility scoring disabled by default for EU users
-
Opt in via privacy settings
-
You may request human review of any AI decision anytime
10.6 Representative: If applicable, we will appoint an EU representative (GDPR Art. 27).
10.7 ODR: EU consumers may file disputes at https://ec.europa.eu/consumers/odr .
11. Vietnam / Indonesia / Thailand / Philippines / Malaysia / Singapore Users
11.1 Vietnam (Cybersecurity Law 2018)
We assess data localization per Vietnam law. See POLICY-NOTES.md P-05 (option A/B/C, finalized later).
11.2 Indonesia (PP 71/2019, OJK)
For Indonesian users:
- Indonesian-language version has paid / earnings features disabled by default
- Data localization per PP 71 assessment (POLICY-NOTES P-06)
11.3 Thailand (PDPA)
Per Thailand PDPA; rights similar to GDPR.
11.4 Philippines (DPA)
Per Philippine Data Privacy Act (RA 10173); NPC complaint right.
11.5 Malaysia (PDPA 2010)
Per Malaysia PDPA.
11.6 Singapore (PDPA)
Per Singapore PDPA; PDPC complaint right.
12. Data Security Measures
| Layer | Measure |
|---|---|
| Transit Encryption | TLS 1.2+ enforced site-wide; HSTS |
| At-Rest Encryption | DB / Storage / Backup all AES-256 (KMS-managed) |
| Field-Level Encryption | ID hash, refresh token hash, payout account encrypted |
| Access Control | Least-privilege; RBAC; sensitive access requires 2FA + reason + audit |
| Network Isolation | VPC + SG + WAF |
| Monitoring | Sentry + OpenTelemetry + real-time alerts |
| Backup | Daily full + WAL incremental; cross-region backup |
| DR Drills | Quarterly |
| Pentest | Before launch + quarterly |
| Dependency Scan | Dependabot / Snyk continuous; high CVE patched within 7 days |
| Audit Logs | Immutable; retained ≥ 1 year |
See security/THREAT-MODEL.md + ops/OBSERVABILITY.md (engineering docs).
13. Data Breach Response
In case of a breach affecting your rights:
- We notify relevant DPAs within 72 hours (GDPR Art. 33)
- High-risk: direct notification to you (email / push)
- Public report if necessary
14. Policy Changes
14.1 We may revise this Policy from time to time.
14.2 Material Changes (affecting your rights): At least 30 days before effective date via email + push + in-app. You must re-consent to continue use.
14.3 Minor / translation edits: Notification only.
14.4 Historical versions viewable on this page.
15. Contact
- DPO: dpo@yooyoo.app
- Support: support@yooyoo.app
- Website: https://yooyoo.app
- Security: security@yooyoo.app
End of Policy
This document is an AI-drafted preliminary version pending review by qualified legal counsel. It must be reviewed and revised by professional law firms before deployment.