Effective date: 17 August 2026 · Last updated: 6 August 2026
The data controller for yeih is kikoship UG (haftungsbeschränkt), Friedenstraße 8, 10249 Berlin, Germany, registered at Amtsgericht Charlottenburg under HRB 280527, VAT identification number DE460174950. Contact: hello@yeih.ai.
This policy explains what personal data we collect, why we collect it, how we use it, and what rights you have under the General Data Protection Regulation (GDPR). yeih is directed at users in the European Union. Our infrastructure is hosted in Frankfurt, Germany (AWS EU-Central-1 via Supabase).
When you create an account via Google Sign-In, we receive your name, email address, and profile photo. We do not receive your Google password. Authentication is handled by Google and Supabase Auth.
Photos and documents are stored in Supabase Storage, hosted in the Frankfurt AWS region.
If you connect a mailbox, Nylas retrieves your messages and each one is checked to determine whether it is a purchase receipt. This check is performed by Anthropic's Claude model and by our own processing rules. We cannot identify receipts without examining messages, so this applies to every message in the connected mailbox, not only receipts.
For messages that are not receipts, we keep a limited record so the same message is not checked twice: the sender, subject, date, the classification result, and technical sender-verification details (DKIM, SPF and DMARC results). We do not retain the message bodies of non-receipt emails. Where a message contains no evidence of a purchase, any extracted details are discarded and no inventory item is created.
Items are added to your inventory only from messages containing evidence of a purchase, such as an order number, line item prices, or an invoice total.
Reading your mailbox and creating items are separate permissions, both controlled in Settings. Turning either off stops future processing.
For iCloud mailboxes, connection uses IMAP with an Apple app-specific password rather than the hosted sign-in flow used for Gmail and Outlook. The password is passed to Nylas, which uses it to connect to Apple's mail servers on our behalf. yeih does not store it: we keep only the connection reference and the mailbox address.
Disconnecting your mailbox does not delete anything. It stops future processing and removes our access to your email account, but the records described above, and any items already created, remain in your account. Deleting your yeih account deletes them.
These records are kept for as long as your account exists.
When an item is sold or deleted, yeih keeps a de-identified record of what the item was, what was paid for it, and what it was valued at. This record carries no link to your account: no user identifier, no item identifier, no serial number, and no photos or documents. Dates are reduced to month precision.
These records are used only in aggregate, to improve the accuracy of our valuations. Aggregate figures are shown only where at least five records exist for the same product, so no single record can be singled out through them.
The legal basis is our legitimate interests under Art. 6(1)(f) GDPR in improving valuation accuracy. You have the right to object to this processing at any time by contacting us. We describe this data as pseudonymised rather than anonymous: while we hold no means to link it back to your account, we do not claim it has been irreversibly anonymised.
yeih retrieves current market pricing from active eBay listings for similar items via the eBay Browse API. This is a read-only query using item names and categories. No personal data is sent to eBay.
Because eBay receives no personal data and processes nothing on our behalf, it is not one of our sub-processors. eBay acts as an independent controller and receives only non-personal product queries.
When you tag an item as For sale, your AI agent may broadcast it to the yeih buyer agent network. The following data is shared within the network:
Your full name, email address, and home address are never shared with buyer agents unless you explicitly confirm a connection.
Pseudonymised usage data including pages visited, session duration and device type, processed on PostHog's EU infrastructure, not linked to your name or email. You can opt out in Settings.
Payments are processed by Paddle, which acts as merchant of record and seller of record for all subscriptions. yeih does not store payment card details. From Paddle we receive only: confirmation of payment, subscription plan and billing period, and billing email address.
Sign-in events; item creation, deletion, and retagging; valuation requests; price confirmations; feedback submissions; introduction confirmations; and records of technical failures affecting your data. See section 04 for how these records are used and how long they are kept.
Account, inventory, and payment data are necessary to provide the yeih service.
Usage analytics help us improve the product. We also keep limited technical records of messages we have already checked: sender, subject, date, classification result and sender-verification details, so that the same message is not processed twice and so we can identify spoofed senders. You may opt out of analytics at any time.
To resolve delivery disputes and demonstrate that required notices were sent, we keep the rendered subject and body of transactional emails for 90 days after sending. This log contains the exact content the recipient received, including account or item details. Access is restricted to the company administrator, currently the sole director of kikoship UG. After 90 days the rendered body is purged, leaving only the send record (recipient, template, status, and timestamp).
Reading your mailbox and creating inventory items from it are separate permissions, each recorded when you give it. You can withdraw either at any time in Settings, or by disconnecting your mailbox.
We keep a short record of actions you take in yeih. This covers when you sign in, when you add, delete, or retag items, when you request a valuation, when you confirm a price, when you send feedback, when you confirm an introduction, and when a technical operation fails.
For deletions we record which item was deleted, so that we can answer your questions about missing data and restore items where possible. For all other actions we record how many items were affected, not which ones.
We do not log what you view, what you search for, or how you move around the app.
Our legitimate interests under Art. 6(1)(f) GDPR: operating a reliable service, diagnosing faults, answering your questions about your own account, and investigating suspected unauthorised access. We have assessed that this processing is limited to what is necessary for those purposes, that it records actions rather than the content of your data, and that it does not build a behavioural profile of you.
Activity records are deleted 45 days after the action they describe. They are also deleted immediately and permanently when you close your account.
You can request a copy of your activity records at any time. You can object to this processing under Art. 21 GDPR by writing to us at hello@yeih.ai.
We record sign-in events, deletions, and technical failures for security and data-integrity reasons, and we cannot switch these off while your account is open: without them we could not investigate unauthorised access or tell you what happened to data you have lost. You can ask us to stop recording the remaining categories, which are retagging, valuation requests, price confirmations, feedback submissions, and introduction confirmations, and we will do so.
We do not sell your data. Sub-processors are contractually bound to process data only on our instruction.
We use the following service providers to operate yeih. Each processes personal data on our instructions under a data processing agreement.
Google has two separate roles. When you sign in with Google, Google acts as an independent controller for that sign-in: we send it nothing, and it returns your name, email address and profile photo. Google is also the model provider behind the in-app assistant, where it acts as a sub-processor engaged by Lovable rather than a provider we contract with directly.
Lovable engages its own sub-processors to provide the platform, transactional email delivery and the in-app assistant.
Some of our providers engage their own sub-processors. Nylas publishes its list at nylas.com/security/subprocessors, and Lovable engages sub-processors including Google for the in-app assistant. Each is bound by onward-transfer obligations under the agreements described above.
Some of our providers are established outside the European Economic Area, or store or access personal data outside it. Where that happens, we rely on the following safeguards:
You can ask us for details of the safeguards applying to any specific provider by writing to hello@yeih.ai.
Contact hello@yeih.ai. We will respond within 30 days. You may also lodge a complaint with the Berliner Beauftragte für Datenschutz und Informationsfreiheit (BlnBDI) at datenschutz-berlin.de.
When an account is deleted we keep one record of the deletion itself, retained indefinitely. It exists so we can demonstrate that an erasure request was carried out, and it contains no identifying content: the internal account identifier, who initiated the deletion (you or an administrator), the timestamp, and the number of rows removed per data category. No email address, name, or inventory content is kept in it.
We will notify you by email at least 14 days before any material changes to this policy take effect.
For privacy questions or to exercise your rights: hello@yeih.ai