Policy
Privacy
What Yaad collects, why, and where it goes.
What we collect
- Account info: your email address, display name, and handle.
- GitHub App installation data (installation id, connected account) when you connect GitHub to publish software.
- Software you publish: name, description, repository, categories, tags, and the build/detection metadata needed to run it.
- Usage events (feed views, Try clicks, installs, and similar) used to power trending/recommendation features and detect abuse.
- Files you upload to your own personal instance of a piece of software (CSV, JSON, or plain text) — stored privately, accessible only to you, and deleted when you remove that personal instance.
- Feedback and reports you submit, and content you post (notes, reviews, timeline posts).
- Prompts sent to AI-assisted features (the Dockerfile-generation helper, the in-app chat assistant) — these are routed to our AI provider to generate a response; see "AI features" below.
Why we collect it
To operate your account, run the software you publish or try, show you a relevant feed, detect and rate-limit abuse of shared infrastructure, and respond to feedback and vulnerability reports. We don't sell personal data.
Who we share it with
Running this product means real infrastructure providers process data on our behalf. The current list:
- Supabase — database, authentication, file storage, and real-time sync.
- Fly.io — runs published software and personal instances as real containers.
- Vercel — hosts the Yaad application itself.
- Resend — sends transactional email (sign-in links, notifications).
- GitHub — repository access via the Yaad GitHub App, when you connect it.
- OpenAI (and a configured fallback provider, when enabled) — AI features route prompts through our AI gateway to generate responses.
AI features
When you use an AI-assisted feature, the relevant prompt/context is sent to our AI gateway and routed to a model provider (OpenAI, or a configured fallback) to generate a response. We don't send your account password or unrelated private data to the model. We don't use your content to train our own models.
Retention and deletion
You can remove software you've published, delete reviews/posts you've written, and remove your personal instance of any software at any time — removing a personal instance deletes the files you uploaded to it. If you want your account and associated data fully removed, contact us using the address on the security page.
Contact
Questions about this policy or your data: use the security contact listed on the security page.