Privacy
In short
YAAPI Agent acts on the platforms you connect — Google Analytics, Tag Manager, BigQuery, Google Sheets and Google Ads; Meta, TikTok, Snapchat, LinkedIn and HubSpot; Adobe Analytics; dbt Cloud and GitHub — from instructions you write in plain language. To do that, the content of your conversations — including the configuration the agent reads from your accounts — is sent to the model provider that produces the replies — Anthropic by default, or OpenAI if you switch the chat to OpenAI in Settings. Those calls are made with your own key, under your own agreement with that provider, when you have saved one; a deployment may provide a default key for people who have not, and calls then run under the operator's agreement with that provider. A connected assistant runs on your subscription with its own provider. What leaves, to whom, and for how long is set out just below.
If you work on your own clients' accounts, you remain responsible for what you put into the tool. Do not enter data your agreements do not allow you to share with a subprocessor.
What leaves, and who receives it
Three destinations, three different regimes. They are usually conflated, so they are separated here.
| Recipient | What reaches them | Under whose account | Kept for how long |
|---|---|---|---|
| Anthropic — or OpenAI, if you chose it | Your messages, and the results of the calls made for you | Yours — your own API key in the chat here, of whichever provider you picked; your own subscription when you reach this application from Claude, ChatGPT or Cursor. The operator's when you have saved no key and the deployment answers with its default one | Set by that account, not here — see below |
| The platforms you connect | The API requests issued on your behalf | Yours — the credential from your own Google Cloud project for the Google products, your own Adobe credential, your own dbt Cloud and GitHub tokens; the grant you gave on Meta, TikTok, Snapchat, LinkedIn or HubSpot | That platform's own API logs, under your own settings there |
| This application | Your conversations, the technical log, the action log and the approvals you were asked for | Ours — the database and the application itself run in the European Union; credentials encrypted, conversation text encrypted as well | The windows listed under Retention below |
Configuration, and measurement data
Most of what the agent reads is configuration: the names and identifiers of your properties, streams, containers, tags, triggers and dimensions. An audit, an inventory or a bulk correction involves nothing else, and as a rule none of it describes a person — though a tag name, a user list or an account's user roster can.
Measurement data — report rows, query results, spreadsheet contents, CRM records — reaches the model only when you ask for a report, run a query or import a file, and it may well include people's data: user identifiers, contact records, transaction rows. The copy this application keeps of what came back lives in the tool-call log, for the tool-call window under Retention below. If that is more than you want to send, leave BigQuery, Sheets, HubSpot and the reporting side of Analytics disconnected: what is not connected cannot be read, so the question is settled by the connection rather than by trust.
What is collected
- Account — email, name and picture from your Google profile, used to identify you in the app.
- Conversations — your messages, the agent's replies, and the files you upload. The copy kept here is abridged, with secrets and email addresses masked before it is written; the full transcript lives in your browser, as described further down.
- Technical log — the tool and API calls made on your behalf, their status, duration and token usage.
- Action log — for every write to your accounts, what was changed and where, so you can retrace it. Clone and bulk-patch operations also record the previous values, which lets those be rolled back by hand.
- Approvals — when the agent, or an assistant connected over MCP, asks to make a change that needs your say-so, the exact operations it proposed are kept so you can read them before deciding, together with your decision and how each one went.
- Credentials — the OAuth client secret or service account key of your Google Cloud project, the tokens you grant through it and on every other platform you connect, your Adobe credential, your dbt Cloud and GitHub tokens, and your Anthropic or OpenAI key, all encrypted at rest.
- Contact form — the name, email address, company and message you send from the public site, so a message is not lost when the email relaying it fails.
- Notices to the operator — the person running this deployment is emailed when an account is created, when a trial starts, and daily about trials ending, with the account's email address. These are the operator's own records of who is using the service, and they are not passed on.
- Error reports — when something breaks, the error text, the page it happened on and technical context go to the error-monitoring service listed under Subprocessors; message bodies, tool payloads and request bodies are stripped before they leave.
Secrets, tokens and private keys detected in logged content are masked before being written to the database, and email addresses in it are partly masked.
Your own Google Cloud project
Signing in uses this application's own Google sign-in and asks for your name, email and picture only. Every call to a Google product is then made with a credential from your own Google Cloud project — an OAuth client or a service account you create there and register in Settings.
The practical consequences: Google counts those calls against your project's API quotas, not against a pool shared with other users; BigQuery work is billed to your project; the calls appear in your project's own API dashboards and audit logs; and removing the credential, here or in the Cloud Console, cuts the agent off entirely. Google Ads is the one exception: its API additionally requires a developer token that belongs to this deployment, and the daily operation budget attached to that token is shared by everyone who uses Google Ads here.
Your client secret or key is used only to send you to Google's consent screen, to renew the tokens you grant there, or to mint tokens for the service account. It is never sent anywhere but to Google, and never shown again once saved.
The model that writes the replies
Which rules cover your conversation depends on how you reach the agent. The two routes do not answer to the same terms, and the difference is worth settling before you put a client account through either one. Everything below is the providers' policy, not ours; their own documentation is linked at the end of this section so you can check it rather than take our word for it.
In the chat here — your API key, commercial terms
Replies come from Anthropic's models — or from OpenAI's, if you switch the chat to OpenAI — called with your own API key, which you add in Settings. Usage is billed to that key under your own agreement with the provider — the same arrangement as your Google Cloud project, at the other end of the conversation. Only the provider you selected receives anything; the other key, if you saved one, is not used.
A deployment may hold a default key of its own, used for anyone who has not saved one. Your conversation then reaches the same provider under the operator's agreement with it rather than yours — the commercial terms still, with the retention figures below, but an account you do not control. Settings says which key is answering; saving your own takes precedence the moment it is saved.
- Anthropic states that on the API, conversation content — your prompts and the model's outputs — is not retained by default. The exception is the models they designate as Covered Models, which require a 30-day retention period and which you would have to select yourself.
- Retained data is never used to train their models without express permission, which an organisation gives by opting in to a programme for that purpose.
- An organisation can arrange zero data retention with Anthropic. It is granted per organisation through their sales team after an eligibility review, not from a settings page, and the Covered Models above are excluded from it.
- Organisations handling health data can instead sign a business associate agreement and enable HIPAA readiness, which Anthropic describes as the arrangement to use for protected health information.
- Under any of these, Anthropic reserves the ability to retain data where the law requires it, or where their trust and safety systems flag a session — for up to two years in that case.
From a connected assistant — their account, their rules
When Claude, ChatGPT or Cursor reaches this application as a tool, the conversation never passes through here at all. Your assistant runs it under your account with that provider, and this application only answers the tool call: it receives the request, runs it against your Google accounts, and returns the result into a conversation it does not hold. What it keeps of that exchange is the tool call it answered and any approval you gave, for the windows under Retention below. The rules that apply to the conversation itself are that account's — not ours, and not the ones attached to your API key above.
Route by route, provider by provider
The same conversation — your instructions, and the configuration the agent reads back from your accounts — answers to different rules depending on where it runs. The table states each provider's published policy as of September 2026; the links at the end of this section go to the source, which prevails over this summary.
| Where you work | Whose account the model runs on | Used to train models? | Kept by the provider |
|---|---|---|---|
| The chat here Anthropic API | Your API key, under Anthropic's commercial terms | No — never without express permission | Not retained by default; 30 days for the models Anthropic designates as Covered Models; zero retention on request, per organisation |
| The chat here OpenAI API — only if you switched to it | Your API key, under OpenAI's business terms | No — API data is not used for training by default | Up to 30 days for abuse monitoring, then deleted; zero data retention on request for eligible organisations |
| Claude Free, Pro or Max | Your personal subscription, under Anthropic's consumer terms | Your own setting: the account holder chooses | Follows that choice — five years when training is allowed, 30 days when it is not |
| Claude Team or Enterprise | Your organisation's workspace, under the commercial terms | No | 30 days by default, or the retention your administrators set |
| ChatGPT Free, Plus or Pro | Your personal account, under OpenAI's consumer terms | Yes by default, until « Improve the model for everyone » is turned off in Data Controls | Conversations stay in your history until you delete them; deleted and temporary chats are removed within 30 days |
| ChatGPT Business, Enterprise or Edu | Your organisation's workspace, under OpenAI's business terms | No by default — including what connected apps return | Set by your administrators; deleted conversations removed within 30 days |
| Cursor | Your Cursor account; every request passes through Cursor's servers, even with your own model key, before reaching the model provider Cursor selects | Not with Privacy Mode on; with it off, Cursor may store prompts and conversations and train on them | With Privacy Mode on, Cursor says it holds zero-retention agreements with its model providers; models outside those agreements are marked as such |
- Every provider keeps a safety exception. Anthropic, OpenAI and Cursor each state that content flagged by their abuse classifiers, or subject to a legal obligation, may be retained beyond the figures above — Anthropic says for up to two years in that case.
- A zero-retention arrangement does not extend to tools. Anthropic says so explicitly of third-party MCP servers, and asks that those services be reviewed on their own terms. This application is one of them: what it holds is governed by the retention stated further down this page, whatever your assistant is set to.
- What the model sees is the same on every route. The configuration read from your accounts — and the measurement data, when you ask for a report or a query — lands in the conversation, and the conversation is kept, or not, by the provider on the row above. Choosing the route chooses the regime.
The practical rule: if you work on accounts that are not your own, connect this application from your organisation's workspace, never from a personal subscription. That single choice decides whether your client's configuration lands under commercial terms or under a personal training setting, and it is made inside your assistant, before anything reaches us.
The providers' own documentation
Anthropic:
- API and data retention — what the API retains, zero data retention, HIPAA readiness, and the models that require retention.
- How long organisation data is stored and how long personal data is stored — the current figures, at the source.
- Is my data used to train models — the consumer and commercial answers side by side.
- Your personal Claude privacy settings and an organisation's data and privacy settings — where the choice above is actually made.
- Commercial terms, consumer terms and the privacy policy.
- Anthropic Trust Center — certifications and compliance artefacts, for a security review that asks for them.
OpenAI:
- Enterprise privacy — the business, enterprise and education commitments: no training by default, administrator-set retention, deleted conversations removed within 30 days.
- Data Controls FAQ — the personal-plan training switch, and Temporary Chats.
- Developer mode and MCP apps — how ChatGPT reaches a tool like this one, and the approvals it asks for.
Cursor:
- Data use and privacy overview — what Privacy Mode changes, and the zero-retention agreements behind it.
Google permissions requested
You choose between two grants when you connect each product, and you can switch later from Settings. These permissions are requested through your own project's OAuth client.
Read-only — the default
The agent can audit, report and export, and cannot change anything. For every product except Google Ads this is enforced by Google itself, not by this application: the token carries no write permission, so no instruction hidden in a file you import and no defect in this code can produce a write. Google Ads publishes no read-only permission, so there the same refusal is enforced by this application before anything is sent.
| Permission | Why |
|---|---|
| Analytics — read | Audit your GA4 configuration and pull reports |
| Tag Manager — read | Inventory your containers, workspaces and tags |
| Google Cloud — read-only | Run SELECT queries on BigQuery. Google publishes no BigQuery-specific read scope, so this is the narrowest one that still allows querying |
| Sheets — read only | Import your spreadsheets as a data source |
| Google Ads | Report on campaigns and audit account structure. Google publishes a single Ads permission covering read and write, so on a read-only connection this application refuses every change before it is sent |
Read and write
Needed for configuration work. Every write is recorded in the action log with the previous values.
| Permission | Why |
|---|---|
| Analytics — read, edit, manage users | Audit and configure your GA4 properties |
| Tag Manager — edit containers and versions | Create and modify tags, triggers and variables |
| Tag Manager — publish | Publish a version, only when you explicitly ask for it |
| BigQuery | Query and load your datasets |
| Sheets — read only | Import your spreadsheets as a data source |
| Google Ads | Audit and change campaigns, budgets and account structure, each change requiring your explicit approval |
You can revoke this access at any time from your Google account, independently of this application.
Retention in this application
This section is about this application's own database, hosted in the European Union — and nothing else. What Anthropic keeps is governed by the account you bring and described above; what the platforms you connect keep is in your own accounts there. Neither of those arrangements reaches this table: a zero-retention agreement with your model provider does not shorten what is listed here, and the windows here do not lengthen what they keep. The figures are read from the running configuration, not typed in, so this page cannot quote a policy the application has stopped applying.
Deleted nightly
A cleanup runs every night and removes what has passed its window; busy hours may run it earlier. What follows is what it removes.
- Conversations and their messages — what you wrote, what the agent replied, and the conversation entry itself once its messages are gone: 30 days.
- Tool calls — what the agent asked of your accounts, and what came back: 14 days.
- API calls made on your behalf — method, path without its query string, status, duration: 30 days.
- Errors: 14 days.
- Token usage: 90 days.
- Action log — every change written to your accounts, with the previous values where a rollback needs them: 180 days.
- Approvals — the operations you were asked to approve, your decision and the outcome: 180 days after the decision. A request nobody decided expires after a day and is removed 7 days later.
- Disconnected credentials — the secret is erased the moment you disconnect; the record that a connection existed (which platform, which permissions, when) follows the action log: 180 days.
- Contact-form messages: 365 days.
- Uploaded and generated files — on their own expiry, a matter of days.
- The marker left by a deleted account (see Your rights below): 365 days after the trial it records ended.
Kept until you act
- Your account — email, name, picture and settings — until you delete it from Settings.
- Credentials — until you disconnect here, or revoke the grant in the account that issued it. Disconnecting erases the stored token at once. For the Google products, the grant itself is also revoked at Google when the last of your Google connections goes — Google revokes a grant as a whole, so revoking it while Tag Manager is still connected would cut that off too. You can revoke it yourself at any time from your Google account.
- The working copy in your browser — see the section on browser storage below; it is on your device, and clearing the site's data removes it.
Security
- Credentials encrypted at rest with AES-256-GCM, with key rotation supported.
- Message content is also encrypted at rest.
- Session held in an encrypted cookie, sent over HTTPS only.
- Every record is tied to its account: no cross-account access.
- The agent's outbound calls cannot reach internal addresses.
Subprocessors
| Recipient | Role | Data involved |
|---|---|---|
| Anthropic | Language model (default) | Conversation content and the results of the calls the agent makes for you — under your own key, or under the operator’s agreement when the deployment’s default key answers. |
| OpenAI | Language model (only if you choose it) | The same, only when you switch the chat to OpenAI. |
| The platforms you connect | Google (Analytics, Tag Manager, BigQuery, Sheets, Google Ads), Meta, TikTok, Snapchat, LinkedIn, HubSpot, Adobe Analytics, dbt Cloud, GitHub | The requests issued on your behalf under the permissions you granted, to those you connected and no other. |
| Vercel | Hosting (EU region) | Technical request logs; cookieless page counts on the marketing site only. |
| Google Ireland (Google Analytics, Google Ads) | Audience and advertising measurement — only with your consent | Pages seen and actions taken on the marketing site and in the application, as counts and categories: never the text of a message, the name of a property, container or account, nor your address. Your account is known to it only as a keyed, unreadable identifier. Google Ads receives the sign-up as a conversion, from that same measurement. |
| LinkedIn Ireland, Meta Platforms Ireland | Advertising measurement — marketing site only, only with your consent | Visits to the marketing site and clicks on “Sign in”, so a campaign can be judged; nothing from inside the application. |
| Neon | Database (EU region) | Everything this application stores, listed under “What is collected”. |
| Resend | Transactional email | Your address and name for account notices; the name, address, company and message you type into the contact form. |
| Sentry | Error monitoring | Error text, the URL it happened on and technical context; never message bodies, tool payloads or request bodies. |
Anthropic, OpenAI and the platforms you connect are reached with the credentials you bring, under your own agreements with them — except when the deployment's default model key answers for you, as described above. They are listed here regardless, so that nothing about where your work goes is left implicit.
Cookies and browser storage
One cookie is strictly necessary: your session, which is what keeps you signed in. It is set without asking, because nothing works without it. Everything below is set only after you have said yes, and refusing costs you nothing.
Measurement — Google Analytics, on the marketing site and in the application. It counts pages seen and actions taken: a message sent, a change approved, a plan compared, how long a turn took, which kinds of product a request reached. It never receives the text of a message, the name of a property, container or account, nor your email address; your account is known to it only as a keyed, unreadable identifier. Cookies _ga and _ga_*, kept for at most thirteen months.
Advertising — Google Ads, LinkedIn and Meta, on the marketing site only. They tell us whether a campaign brought you here and whether it led to a sign-in. Nothing runs from inside the application: what these platforms learn about a sign-up comes from the measurement above, which carries no identity of yours. Their cookies (_gcl_*, li_fat_id, _fbp) are kept between one and thirteen months.
Your choice is asked once, on the first visit, and kept for six months in a cookie of ours (yaapi_consent) that both yaapi.net and agent.yaapi.net read, so you are not asked twice. When you refuse, none of these tags is loaded and nothing is sent to them. You can change your mind at any time from in the footer of the site, in Settings under Data & privacy, or right here.
The app also keeps a working copy of your data in your browser's own storage, on your device: the conversation history the chat displays, and a few preferences such as the active conversation and what you have already seen. That copy is never read back by the platform. Deleting a conversation removes it, and clearing the site's data in your browser removes all of it.
Your rights
- Access and portability — the “Export my data” button in Settings produces a JSON file of every record this application holds about you, complete: your account and settings, conversations and messages as kept here, tool and API calls, token usage, the action log, errors, files and attachments by name, exports in progress, which credentials exist (provider, permissions, dates — never the secrets), the assistants you authorised over MCP, the approvals you were asked for with their operations, and whether the deletion marker below exists for your address.
- Erasure — “Delete my account” in Settings immediately and permanently removes your account and everything tied to it in this application, including any contact-form messages sent from your address. What outlives it: a hashed, unreadable identifier with your free-trial dates, so that deleting an account does not grant a new trial (legitimate interest — abuse prevention), deleted twelve months after the trial ended; error reports already sent to the error-monitoring service and the host's technical logs, for their own retention windows; the delivery logs of the notices emailed to you, at the email provider; and the operator's own notices about your account (signup, trial), which are their records.
- Withdrawing consent — change your cookie choice from “Cookie settings” (footer, Settings, or the cookies section above); disconnect a platform from Settings, remove your project credential there, revoke the grant from your Google account or the platform's own settings, or delete the OAuth client or key in your Google Cloud project; or remove your model provider key from Settings.
Questions: support@yaapi.net