Draft - Awaiting Lawyer Review.

YooYoo Privacy Policy

Last Updated: 2026-05-27 · Version: 1.0 Draft

YooYoo ("we", "our", "the Platform") values your privacy. This Privacy Policy describes how we collect, use, share, retain, and protect your personal information, and the rights you have under applicable law.

Please read this Policy in full before using YooYoo. If you do not agree with any provision, please do not use the Service.


1. Information We Collect

1.1 Information You Provide

CategoryContent
RegistrationEmail, phone number (optional), password (hashed)
Identity ProfileNickname, birthdate, gender, nationality, city, native language, target languages
Personal ProfileBio, interest tags, religion (optional), zodiac (optional), height (optional), education (optional), occupation (optional), relationship goals
Avatar & PhotosPhotos you upload (up to 9)
Chat ContentText / voice / image / video / gift messages sent and received, recall records
AI InputsText you submit for AI polish / suggest / icebreaker
PaymentOrder records via Apple IAP / Google Play / Stripe (card numbers do not reach us)
KYC Materials (optional)National ID / passport / driver's license + liveness video (held by Sumsub etc.; we only store hash)
OV Withdrawal Account (if applicable)Linked local bank / e-wallet account (KMS-encrypted)
ReportsContent of your reports about other users
Support LogsConversations with AI / human support

1.2 Information We Collect Automatically

CategoryContent
DeviceDevice type, OS, app version, browser type, screen size
Device FingerprintSynthesized from above (for risk control; doesn't directly identify person)
NetworkIP address (for geographic inference + risk control), network type
GeolocationPrecise coordinates if you grant browser / device permission; otherwise city-level via IP
Activity LogsLogin times, browsing, clicks, Like, Match, message send times (not content)
Performance / ErrorsPage load times, crash logs, request latency
Cookies & SimilarSee §7

1.3 Information We Receive from Third Parties


2. How We Use Information

PurposeLegal Basis
Provide core service (registration, matching, chat)Performance of contract
Automatically translate your messagesContract + your consent
AI assistants generating icebreakers / polish / supportContract + your consent
Content moderation and anti-fraudLegitimate interest + legal obligation
Account security (risk control)Legitimate interest + legal obligation
Payment processing and refundsContract + legal obligation
KYC and liveness verificationLegitimate interest + legal obligation
Notifications and marketing emails / push (with your permission)Your consent (revocable anytime)
Personalized recommendationsLegitimate interest
Improve product / A/B experiments (anonymized)Legitimate interest
Legal obligations (law enforcement, regulatory)Legal obligation
Disputes and appeals handlingLegitimate interest + legal obligation

3. Information Sharing

We do not sell your personal information for commercial purposes.

We share information only in the following circumstances:

3.1 With Third-Party Service Providers (Minimum Necessary)

ProviderData SharedPurpose
Anthropic (Claude) / OpenAI / DeepSeekMessages you submit for AI processingAI assistants
DeepL / Google Cloud Translation / AliyunMessages to translateReal-time translation
Sumsub / OnfidoKYC documents + livenessIdentity / liveness verification
Stripe / dLocal / PayMongo / Xendit / Apple / GooglePayment order infoPayment processing
LiveKit CloudVideo call signaling + media streamsReal-time AV
SendGridEmail address + contentEmail delivery
TwilioPhone + SMS contentSMS delivery
APNs / FCMDevice token + notification previewPush notifications
Hive Moderation / Microsoft Content ModeratorUploaded images / textContent moderation
Sentry / OpenTelemetry / DatadogError stacks (PII-free) + metricsError / performance monitoring
CloudflareNetwork request basics (IP / UA)CDN + WAF + DDoS
GrowthBookUser bucketing identifier (hash)Feature flags / A/B

Each provider has a Data Processing Agreement (DPA), bound by GDPR / national standards.

3.2 With Law Enforcement / Regulators

3.3 With Affiliates / Successors

3.4 Public / Semi-Public Content

Fields you actively make public (nickname, age, city, bio, public photos, interest tags) are visible to other users. Private photos visible only to matches. Chat content visible only to you and the recipient (+ minimum moderation staff).


4. Cross-Border Data Transfer

YooYoo servers primarily located in [Singapore / Tokyo or other overseas regions].

4.1 Data Flows

See privacy/DATA-FLOW.md (engineering doc); user-facing summary:

Your DataPrimary LocationCross-Border Flow
Account & profilePrimary regionNo proactive cross-border
Chat messagesPrimary regionTemporary flow to EU/US during translation API (DPA-protected)
AI inputsPrimary regionTemporary flow to Anthropic US
KYC documentsSumsub multi-regionClosest node based on your country
Payment ordersPrimary regionExchanged with payment channel US/EU nodes

4.2 Legal Basis

4.3 Your Choice

You may request your data be removed from specific third-party providers (except compliance retention).


5. Data Retention

DataRetentionDeletion
Active account profileUntil you close account30-day cooldown then deleted
Chat messagesDefault 180 days (you can set 30)Automatic
Voice message files90 daysAutomatic
Video call recordings (if enabled)90 daysAutomatic
Liveness videos30 daysAutomatic
KYC records5 years (compliance)Automatic
Risk event logs365 daysAutomatic
Payment orders & ledger5 years (compliance)Automatic
Audit logs365 daysAutomatic
Notification history90 daysAutomatic
Translation cache (hash)30 daysAutomatic
AI logs90 days (30% sampled)Automatic
Your data export link7 daysAutomatic
Account cancellation cooldown30 days reversibleUser-initiated

6. Your Rights

Under GDPR, PDPA, PIPL, and other applicable laws, you have:

6.1 Right of Access

View all your data via Settings → Privacy → My Data.

6.2 Right to Rectification

Edit profile fields anytime (some key fields like birthdate have edit limits).

6.3 Right to Erasure / Right to be Forgotten

Account closure:

6.4 Right to Data Portability (GDPR Art. 20)

Export all your data (JSON + media ZIP):

6.5 Right to Object (GDPR Art. 21)

Object to:

6.6 Right to Restriction (GDPR Art. 18)

Request we pause processing (without deletion) in specific cases. Submit via ticket.

6.7 Right to Withdraw Consent

Withdraw any "consent-based" processing anytime. Doesn't affect prior lawful processing.

6.8 Right to Complain

File complaints with your local data protection authority (EU DPAs, Singapore PDPC, etc.).

6.9 How to Exercise


7. Cookies & Tracking

7.1 Categories We Use

CategoryPurposeDefault
NecessaryLogin session, CSRF, language preferenceOn, not disable-able
FunctionalTheme, video volume, draftOn, disable-able
AnalyticsAnonymous page statsOff in EU (consent required); other regions on, disable-able
Marketing(Currently none)Off

7.2 Your Choices


8. Minors

8.1 Age Floor: Service prohibits users under 18. Birthdate checked at registration; double-checked at KYC.

8.2 Suspected minors: Account frozen + manual review.

8.3 Children: We do not knowingly collect information from children under 13. If discovered, deleted immediately.

8.4 Parent / guardian: If you find your minor child has registered, contact dpo@yooyoo.app; we will assist with deletion.


9. China Mainland Users

9.1 YooYoo operates outside the PRC; servers overseas.

9.2 We do not proactively transfer user data to Chinese mainland authorities; we will evaluate any lawful, properly authorized cross-border judicial / regulatory request and act per applicable law.

9.3 China Mainland users' data is stored on overseas servers; this is not "data export" in the PIPL sense because the service is offshore from the start.

9.4 ToS §16 "China Mainland Access Notice" governs prerequisite consent.


10. EU Users (GDPR + AI Act)

10.1 Controller: The YooYoo operating entity [overseas company] is your data controller.

10.2 DPO: dpo@yooyoo.app

10.3 Legal Basis: See §2 for each processing purpose.

10.4 Cross-Border: See §4.

10.5 AI Act (2024 / 2025 phased in): Our AI assistants and personalized compatibility scoring may fall within "automated decision making":


11. Vietnam / Indonesia / Thailand / Philippines / Malaysia / Singapore Users

11.1 Vietnam (Cybersecurity Law 2018)

We assess data localization per Vietnam law. See POLICY-NOTES.md P-05 (option A/B/C, finalized later).

11.2 Indonesia (PP 71/2019, OJK)

For Indonesian users:

11.3 Thailand (PDPA)

Per Thailand PDPA; rights similar to GDPR.

11.4 Philippines (DPA)

Per Philippine Data Privacy Act (RA 10173); NPC complaint right.

11.5 Malaysia (PDPA 2010)

Per Malaysia PDPA.

11.6 Singapore (PDPA)

Per Singapore PDPA; PDPC complaint right.


12. Data Security Measures

LayerMeasure
Transit EncryptionTLS 1.2+ enforced site-wide; HSTS
At-Rest EncryptionDB / Storage / Backup all AES-256 (KMS-managed)
Field-Level EncryptionID hash, refresh token hash, payout account encrypted
Access ControlLeast-privilege; RBAC; sensitive access requires 2FA + reason + audit
Network IsolationVPC + SG + WAF
MonitoringSentry + OpenTelemetry + real-time alerts
BackupDaily full + WAL incremental; cross-region backup
DR DrillsQuarterly
PentestBefore launch + quarterly
Dependency ScanDependabot / Snyk continuous; high CVE patched within 7 days
Audit LogsImmutable; retained ≥ 1 year

See security/THREAT-MODEL.md + ops/OBSERVABILITY.md (engineering docs).


13. Data Breach Response

In case of a breach affecting your rights:


14. Policy Changes

14.1 We may revise this Policy from time to time.

14.2 Material Changes (affecting your rights): At least 30 days before effective date via email + push + in-app. You must re-consent to continue use.

14.3 Minor / translation edits: Notification only.

14.4 Historical versions viewable on this page.


15. Contact


End of Policy

This document is an AI-drafted preliminary version pending review by qualified legal counsel. It must be reviewed and revised by professional law firms before deployment.