Privacy

In short

YAAPI Agent acts on the platforms you connect — Google Analytics, Tag Manager, BigQuery, Google Sheets and Google Ads; Meta, TikTok, Snapchat, LinkedIn and HubSpot; Adobe Analytics; dbt Cloud and GitHub — from instructions you write in plain language. To do that, the content of your conversations — including the configuration the agent reads from your accounts — is sent to the model provider that produces the replies — Anthropic by default, or OpenAI if you switch the chat to OpenAI in Settings. Those calls are made with your own key, under your own agreement with that provider, when you have saved one; a deployment may provide a default key for people who have not, and calls then run under the operator's agreement with that provider. A connected assistant runs on your subscription with its own provider. What leaves, to whom, and for how long is set out just below.

If you work on your own clients' accounts, you remain responsible for what you put into the tool. Do not enter data your agreements do not allow you to share with a subprocessor.

What leaves, and who receives it

Three destinations, three different regimes. They are usually conflated, so they are separated here.

RecipientWhat reaches themUnder whose accountKept for how long
Anthropic — or OpenAI, if you chose itYour messages, and the results of the calls made for youYours — your own API key in the chat here, of whichever provider you picked; your own subscription when you reach this application from Claude, ChatGPT or Cursor. The operator's when you have saved no key and the deployment answers with its default oneSet by that account, not here — see below
The platforms you connectThe API requests issued on your behalfYours — the credential from your own Google Cloud project for the Google products, your own Adobe credential, your own dbt Cloud and GitHub tokens; the grant you gave on Meta, TikTok, Snapchat, LinkedIn or HubSpotThat platform's own API logs, under your own settings there
This applicationYour conversations, the technical log, the action log and the approvals you were asked forOurs — the database and the application itself run in the European Union; credentials encrypted, conversation text encrypted as wellThe windows listed under Retention below

Configuration, and measurement data

Most of what the agent reads is configuration: the names and identifiers of your properties, streams, containers, tags, triggers and dimensions. An audit, an inventory or a bulk correction involves nothing else, and as a rule none of it describes a person — though a tag name, a user list or an account's user roster can.

Measurement data — report rows, query results, spreadsheet contents, CRM records — reaches the model only when you ask for a report, run a query or import a file, and it may well include people's data: user identifiers, contact records, transaction rows. The copy this application keeps of what came back lives in the tool-call log, for the tool-call window under Retention below. If that is more than you want to send, leave BigQuery, Sheets, HubSpot and the reporting side of Analytics disconnected: what is not connected cannot be read, so the question is settled by the connection rather than by trust.

What is collected

  • Account — email, name and picture from your Google profile, used to identify you in the app.
  • Conversations — your messages, the agent's replies, and the files you upload. The copy kept here is abridged, with secrets and email addresses masked before it is written; the full transcript lives in your browser, as described further down.
  • Technical log — the tool and API calls made on your behalf, their status, duration and token usage.
  • Action log — for every write to your accounts, what was changed and where, so you can retrace it. Clone and bulk-patch operations also record the previous values, which lets those be rolled back by hand.
  • Approvals — when the agent, or an assistant connected over MCP, asks to make a change that needs your say-so, the exact operations it proposed are kept so you can read them before deciding, together with your decision and how each one went.
  • Credentials — the OAuth client secret or service account key of your Google Cloud project, the tokens you grant through it and on every other platform you connect, your Adobe credential, your dbt Cloud and GitHub tokens, and your Anthropic or OpenAI key, all encrypted at rest.
  • Contact form — the name, email address, company and message you send from the public site, so a message is not lost when the email relaying it fails.
  • Notices to the operator — the person running this deployment is emailed when an account is created, when a trial starts, and daily about trials ending, with the account's email address. These are the operator's own records of who is using the service, and they are not passed on.
  • Error reports — when something breaks, the error text, the page it happened on and technical context go to the error-monitoring service listed under Subprocessors; message bodies, tool payloads and request bodies are stripped before they leave.

Secrets, tokens and private keys detected in logged content are masked before being written to the database, and email addresses in it are partly masked.

Your own Google Cloud project

Signing in uses this application's own Google sign-in and asks for your name, email and picture only. Every call to a Google product is then made with a credential from your own Google Cloud project — an OAuth client or a service account you create there and register in Settings.

The practical consequences: Google counts those calls against your project's API quotas, not against a pool shared with other users; BigQuery work is billed to your project; the calls appear in your project's own API dashboards and audit logs; and removing the credential, here or in the Cloud Console, cuts the agent off entirely. Google Ads is the one exception: its API additionally requires a developer token that belongs to this deployment, and the daily operation budget attached to that token is shared by everyone who uses Google Ads here.

Your client secret or key is used only to send you to Google's consent screen, to renew the tokens you grant there, or to mint tokens for the service account. It is never sent anywhere but to Google, and never shown again once saved.

The model that writes the replies

Which rules cover your conversation depends on how you reach the agent. The two routes do not answer to the same terms, and the difference is worth settling before you put a client account through either one. Everything below is the providers' policy, not ours; their own documentation is linked at the end of this section so you can check it rather than take our word for it.

In the chat here — your API key, commercial terms

Replies come from Anthropic's models — or from OpenAI's, if you switch the chat to OpenAI — called with your own API key, which you add in Settings. Usage is billed to that key under your own agreement with the provider — the same arrangement as your Google Cloud project, at the other end of the conversation. Only the provider you selected receives anything; the other key, if you saved one, is not used.

A deployment may hold a default key of its own, used for anyone who has not saved one. Your conversation then reaches the same provider under the operator's agreement with it rather than yours — the commercial terms still, with the retention figures below, but an account you do not control. Settings says which key is answering; saving your own takes precedence the moment it is saved.

  • Anthropic states that on the API, conversation content — your prompts and the model's outputs — is not retained by default. The exception is the models they designate as Covered Models, which require a 30-day retention period and which you would have to select yourself.
  • Retained data is never used to train their models without express permission, which an organisation gives by opting in to a programme for that purpose.
  • An organisation can arrange zero data retention with Anthropic. It is granted per organisation through their sales team after an eligibility review, not from a settings page, and the Covered Models above are excluded from it.
  • Organisations handling health data can instead sign a business associate agreement and enable HIPAA readiness, which Anthropic describes as the arrangement to use for protected health information.
  • Under any of these, Anthropic reserves the ability to retain data where the law requires it, or where their trust and safety systems flag a session — for up to two years in that case.

From a connected assistant — their account, their rules

When Claude, ChatGPT or Cursor reaches this application as a tool, the conversation never passes through here at all. Your assistant runs it under your account with that provider, and this application only answers the tool call: it receives the request, runs it against your Google accounts, and returns the result into a conversation it does not hold. What it keeps of that exchange is the tool call it answered and any approval you gave, for the windows under Retention below. The rules that apply to the conversation itself are that account's — not ours, and not the ones attached to your API key above.

Route by route, provider by provider

The same conversation — your instructions, and the configuration the agent reads back from your accounts — answers to different rules depending on where it runs. The table states each provider's published policy as of September 2026; the links at the end of this section go to the source, which prevails over this summary.

Where you workWhose account the model runs onUsed to train models?Kept by the provider
The chat here
Anthropic API
Your API key, under Anthropic's commercial termsNo — never without express permissionNot retained by default; 30 days for the models Anthropic designates as Covered Models; zero retention on request, per organisation
The chat here
OpenAI API — only if you switched to it
Your API key, under OpenAI's business termsNo — API data is not used for training by defaultUp to 30 days for abuse monitoring, then deleted; zero data retention on request for eligible organisations
Claude
Free, Pro or Max
Your personal subscription, under Anthropic's consumer termsYour own setting: the account holder choosesFollows that choice — five years when training is allowed, 30 days when it is not
Claude
Team or Enterprise
Your organisation's workspace, under the commercial termsNo30 days by default, or the retention your administrators set
ChatGPT
Free, Plus or Pro
Your personal account, under OpenAI's consumer termsYes by default, until « Improve the model for everyone » is turned off in Data ControlsConversations stay in your history until you delete them; deleted and temporary chats are removed within 30 days
ChatGPT
Business, Enterprise or Edu
Your organisation's workspace, under OpenAI's business termsNo by default — including what connected apps returnSet by your administrators; deleted conversations removed within 30 days
CursorYour Cursor account; every request passes through Cursor's servers, even with your own model key, before reaching the model provider Cursor selectsNot with Privacy Mode on; with it off, Cursor may store prompts and conversations and train on themWith Privacy Mode on, Cursor says it holds zero-retention agreements with its model providers; models outside those agreements are marked as such
  • Every provider keeps a safety exception. Anthropic, OpenAI and Cursor each state that content flagged by their abuse classifiers, or subject to a legal obligation, may be retained beyond the figures above — Anthropic says for up to two years in that case.
  • A zero-retention arrangement does not extend to tools. Anthropic says so explicitly of third-party MCP servers, and asks that those services be reviewed on their own terms. This application is one of them: what it holds is governed by the retention stated further down this page, whatever your assistant is set to.
  • What the model sees is the same on every route. The configuration read from your accounts — and the measurement data, when you ask for a report or a query — lands in the conversation, and the conversation is kept, or not, by the provider on the row above. Choosing the route chooses the regime.

The practical rule: if you work on accounts that are not your own, connect this application from your organisation's workspace, never from a personal subscription. That single choice decides whether your client's configuration lands under commercial terms or under a personal training setting, and it is made inside your assistant, before anything reaches us.

The providers' own documentation

Anthropic:

OpenAI:

  • Enterprise privacy — the business, enterprise and education commitments: no training by default, administrator-set retention, deleted conversations removed within 30 days.
  • Data Controls FAQ — the personal-plan training switch, and Temporary Chats.
  • Developer mode and MCP apps — how ChatGPT reaches a tool like this one, and the approvals it asks for.

Cursor:

Google permissions requested

You choose between two grants when you connect each product, and you can switch later from Settings. These permissions are requested through your own project's OAuth client.

Read-only — the default

The agent can audit, report and export, and cannot change anything. For every product except Google Ads this is enforced by Google itself, not by this application: the token carries no write permission, so no instruction hidden in a file you import and no defect in this code can produce a write. Google Ads publishes no read-only permission, so there the same refusal is enforced by this application before anything is sent.

PermissionWhy
Analytics — readAudit your GA4 configuration and pull reports
Tag Manager — readInventory your containers, workspaces and tags
Google Cloud — read-onlyRun SELECT queries on BigQuery. Google publishes no BigQuery-specific read scope, so this is the narrowest one that still allows querying
Sheets — read onlyImport your spreadsheets as a data source
Google AdsReport on campaigns and audit account structure. Google publishes a single Ads permission covering read and write, so on a read-only connection this application refuses every change before it is sent

Read and write

Needed for configuration work. Every write is recorded in the action log with the previous values.

PermissionWhy
Analytics — read, edit, manage usersAudit and configure your GA4 properties
Tag Manager — edit containers and versionsCreate and modify tags, triggers and variables
Tag Manager — publishPublish a version, only when you explicitly ask for it
BigQueryQuery and load your datasets
Sheets — read onlyImport your spreadsheets as a data source
Google AdsAudit and change campaigns, budgets and account structure, each change requiring your explicit approval

You can revoke this access at any time from your Google account, independently of this application.

Retention in this application

This section is about this application's own database, hosted in the European Union — and nothing else. What Anthropic keeps is governed by the account you bring and described above; what the platforms you connect keep is in your own accounts there. Neither of those arrangements reaches this table: a zero-retention agreement with your model provider does not shorten what is listed here, and the windows here do not lengthen what they keep. The figures are read from the running configuration, not typed in, so this page cannot quote a policy the application has stopped applying.

Deleted nightly

A cleanup runs every night and removes what has passed its window; busy hours may run it earlier. What follows is what it removes.

  • Conversations and their messages — what you wrote, what the agent replied, and the conversation entry itself once its messages are gone: 30 days.
  • Tool calls — what the agent asked of your accounts, and what came back: 14 days.
  • API calls made on your behalf — method, path without its query string, status, duration: 30 days.
  • Errors: 14 days.
  • Token usage: 90 days.
  • Action log — every change written to your accounts, with the previous values where a rollback needs them: 180 days.
  • Approvals — the operations you were asked to approve, your decision and the outcome: 180 days after the decision. A request nobody decided expires after a day and is removed 7 days later.
  • Disconnected credentials — the secret is erased the moment you disconnect; the record that a connection existed (which platform, which permissions, when) follows the action log: 180 days.
  • Contact-form messages: 365 days.
  • Uploaded and generated files — on their own expiry, a matter of days.
  • The marker left by a deleted account (see Your rights below): 365 days after the trial it records ended.

Kept until you act

  • Your account — email, name, picture and settings — until you delete it from Settings.
  • Credentials — until you disconnect here, or revoke the grant in the account that issued it. Disconnecting erases the stored token at once. For the Google products, the grant itself is also revoked at Google when the last of your Google connections goes — Google revokes a grant as a whole, so revoking it while Tag Manager is still connected would cut that off too. You can revoke it yourself at any time from your Google account.
  • The working copy in your browser — see the section on browser storage below; it is on your device, and clearing the site's data removes it.

Security

  • Credentials encrypted at rest with AES-256-GCM, with key rotation supported.
  • Message content is also encrypted at rest.
  • Session held in an encrypted cookie, sent over HTTPS only.
  • Every record is tied to its account: no cross-account access.
  • The agent's outbound calls cannot reach internal addresses.

Subprocessors

RecipientRoleData involved
AnthropicLanguage model (default)Conversation content and the results of the calls the agent makes for you — under your own key, or under the operator’s agreement when the deployment’s default key answers.
OpenAILanguage model (only if you choose it)The same, only when you switch the chat to OpenAI.
The platforms you connectGoogle (Analytics, Tag Manager, BigQuery, Sheets, Google Ads), Meta, TikTok, Snapchat, LinkedIn, HubSpot, Adobe Analytics, dbt Cloud, GitHubThe requests issued on your behalf under the permissions you granted, to those you connected and no other.
VercelHosting (EU region)Technical request logs; cookieless page counts on the marketing site only.
Google Ireland (Google Analytics, Google Ads)Audience and advertising measurement — only with your consentPages seen and actions taken on the marketing site and in the application, as counts and categories: never the text of a message, the name of a property, container or account, nor your address. Your account is known to it only as a keyed, unreadable identifier. Google Ads receives the sign-up as a conversion, from that same measurement.
LinkedIn Ireland, Meta Platforms IrelandAdvertising measurement — marketing site only, only with your consentVisits to the marketing site and clicks on “Sign in”, so a campaign can be judged; nothing from inside the application.
NeonDatabase (EU region)Everything this application stores, listed under “What is collected”.
ResendTransactional emailYour address and name for account notices; the name, address, company and message you type into the contact form.
SentryError monitoringError text, the URL it happened on and technical context; never message bodies, tool payloads or request bodies.

Anthropic, OpenAI and the platforms you connect are reached with the credentials you bring, under your own agreements with them — except when the deployment's default model key answers for you, as described above. They are listed here regardless, so that nothing about where your work goes is left implicit.

Cookies and browser storage

One cookie is strictly necessary: your session, which is what keeps you signed in. It is set without asking, because nothing works without it. Everything below is set only after you have said yes, and refusing costs you nothing.

Measurement — Google Analytics, on the marketing site and in the application. It counts pages seen and actions taken: a message sent, a change approved, a plan compared, how long a turn took, which kinds of product a request reached. It never receives the text of a message, the name of a property, container or account, nor your email address; your account is known to it only as a keyed, unreadable identifier. Cookies _ga and _ga_*, kept for at most thirteen months.

Advertising — Google Ads, LinkedIn and Meta, on the marketing site only. They tell us whether a campaign brought you here and whether it led to a sign-in. Nothing runs from inside the application: what these platforms learn about a sign-up comes from the measurement above, which carries no identity of yours. Their cookies (_gcl_*, li_fat_id, _fbp) are kept between one and thirteen months.

Your choice is asked once, on the first visit, and kept for six months in a cookie of ours (yaapi_consent) that both yaapi.net and agent.yaapi.net read, so you are not asked twice. When you refuse, none of these tags is loaded and nothing is sent to them. You can change your mind at any time from in the footer of the site, in Settings under Data & privacy, or right here.

The app also keeps a working copy of your data in your browser's own storage, on your device: the conversation history the chat displays, and a few preferences such as the active conversation and what you have already seen. That copy is never read back by the platform. Deleting a conversation removes it, and clearing the site's data in your browser removes all of it.

Your rights

  • Access and portability — the “Export my data” button in Settings produces a JSON file of every record this application holds about you, complete: your account and settings, conversations and messages as kept here, tool and API calls, token usage, the action log, errors, files and attachments by name, exports in progress, which credentials exist (provider, permissions, dates — never the secrets), the assistants you authorised over MCP, the approvals you were asked for with their operations, and whether the deletion marker below exists for your address.
  • Erasure — “Delete my account” in Settings immediately and permanently removes your account and everything tied to it in this application, including any contact-form messages sent from your address. What outlives it: a hashed, unreadable identifier with your free-trial dates, so that deleting an account does not grant a new trial (legitimate interest — abuse prevention), deleted twelve months after the trial ended; error reports already sent to the error-monitoring service and the host's technical logs, for their own retention windows; the delivery logs of the notices emailed to you, at the email provider; and the operator's own notices about your account (signup, trial), which are their records.
  • Withdrawing consent — change your cookie choice from “Cookie settings” (footer, Settings, or the cookies section above); disconnect a platform from Settings, remove your project credential there, revoke the grant from your Google account or the platform's own settings, or delete the OAuth client or key in your Google Cloud project; or remove your model provider key from Settings.

Questions: support@yaapi.net

Privacy — YAAPI Agent