Privacy Policy

Last updated: August 30, 2026

This policy is owned and published by Koi Gang Inc., a Delaware corporation ("we", "us", "the company"). We operate Yomlet ("the app"), which lets you save short-form videos and turns them into structured cards you can actually find and use. This policy covers the Yomlet website (yomlet.com), the web app, the iOS app, and the Android app if and when we offer one, and applies to account holders and to visitors without accounts. Yomlet is currently offered in the United States and is for adults 18 and over. This policy describes the information we collect, why we collect it, and what we do not do with it. We have tried to keep it specific and short.

Questions about this policy or how we handle your data: hello@yomlet.com.

What we collect

Except where noted, the following data is linked to your user identity in our database. None of it is used to track you across other companies' apps or websites. None of it is shared with advertising networks or data brokers.

  • Email address. You provide this at signup, or it arrives via Apple or Google when you use social sign-in (including Apple's relay address if you choose Hide My Email). We use it to identify your account, send password reset emails, and contact you when material things change.
  • Display name. Captured at signup, or from the Apple or Google response on first sign-in. Shown only to you inside the app; never displayed to other users. Like the rest of your account data, it is stored with the service providers listed under "Who receives your personal data."
  • User identifier. A persistent ID assigned by our authentication provider when you create an account. We use it to scope every database read and write to your account so other users cannot see your library.
  • Your content. The video URLs you submit, the captions and transcripts extracted from those videos, the thumbnails and still frames retrieved from them, the structured cards we produce (ingredients, steps, exercises, places, books, etc.), the folders you create, and the way you organise your library.
  • Purchase and subscription data. If you buy credit packs or subscribe to Unlimited, we and our purchase-management provider hold a record of what you purchased, when, the product identifier, and a transaction identifier, so we can grant and verify your entitlement. See "Purchases and subscriptions" below for detail.
  • Basic product analytics. In-app usage events (for example: opened the app, submitted a video, opened the Unlimited paywall) tied to your account identifier, so we can understand how the app is used and fix what's broken. Events may carry an approximate, city-level region derived from your IP address. See "Product analytics" below for detail.
  • Device and technical data. IP address, browser and device type (user-agent), platform (web, iOS, or Android where offered), and an approximate, city-level region derived from your IP address. This appears in our hosting provider's standard web access logs (not routinely linked to your account), in analytics events, in authentication and security logs, and in purchase events (device/platform only).
  • Support correspondence. If you email us, we keep the correspondence (your email address and what you wrote) for as long as needed to resolve the issue and keep a record of it.
  • Deletion-request records. If you delete your account, we keep a short audit record of the deletion itself. See "Account deletion" below.

What we don't collect

We do not request GPS or device-location data, and we do not collect or track your precise location. Like most online services, our hosting provider receives your IP address in operational logs, and our analytics may derive an approximate, city-level region from it. We do not collect your contacts, your microphone or camera input, or your browsing or search history outside of the app. We do not access HealthKit, fitness sensors, medical records, or any health information from your device; submitted videos may nevertheless contain health- or fitness-related content (a workout video, a recipe), which we process only as part of creating its card. We do not access your device's photo library. (We do process images from the videos you submit — the video's public thumbnail and still frames — but nothing from your device's photos or camera.) We do not collect your payment card details directly — those go to Apple or Google when you make a purchase; see "Purchases and subscriptions" below. We do not embed advertising SDKs, and we do not use your data to build an advertising profile or engage in cross-app tracking. We do not show an Apple App Tracking Transparency prompt because there is no cross-app tracking to ask permission for.

How we use what we collect

Every category of data above exists to power the product. Specifically:

  • Account management. Signing you in, sending password resets, contacting you about your account.
  • Running the app. Showing your saved videos, the cards we extracted from them, your folder organisation. Scoping each query to your account.
  • Processing submissions. When you submit a video URL, we retrieve the video's public caption, transcript, thumbnail, and selected still frames; pass them through our video-processing infrastructure; send them to language-model providers for extraction; and store the structured result alongside the original URL. The recipient categories below describe who is involved.
  • Granting and verifying purchases. Confirming a credit pack or subscription purchase went through, applying the credits or Unlimited status to your account, and keeping a record in case of a billing dispute or restore-purchases request.
  • Understanding and improving the app. Product analytics events tell us which features get used, where people get stuck, and whether new features work as intended.

We do not use your data to personalise advertising or build a profile of you outside the app, and we do not train AI models on your data ourselves. The AI providers that process submitted videos do so under API terms that do not permit them to use that content to train or improve their models; see "Who receives your personal data." Your content is not sold.

Who receives your personal data

We share personal data with the following categories of recipients. Except where noted, they act as data processors on our behalf and handle data under agreements that restrict their use of it to running our service.

  • Authentication and database hosting. Stores your email, display name, user identifier, and content.
  • Website and backend hosting. Standard web access logs (IP address, user-agent, request paths) for serving the app and basic security.
  • Video-processing infrastructure. The workflow service that runs your submissions receives the video URL you submitted, your user identifier, and an internal charge reference, so the finished cards (or an automatic credit refund if processing fails) land on the right account.
  • Content retrieval. Services that fetch the public page of a submitted video. They receive the video URL and, in the course of the fetch, handle that video's public page content — caption, transcript, thumbnail, and frames. They do not receive your account information.
  • Language-model providers. Captions, transcripts, and visual frames from submitted videos are sent to large language models to produce structured cards. We do not include your personal account information in those requests. We use these providers on API terms under which submitted content is not used to train or improve their models; they may retain request logs for a limited period for abuse monitoring and legal compliance.
  • Transactional email delivery. Password resets and account confirmation. Receives your email address only.
  • Purchase and subscription management. Receives your app-level user identifier, purchase and subscription events, and device/platform information. Never receives your payment card details. See "Purchases and subscriptions" below.
  • App-store payment processing (Apple's App Store and Google Play). Named because you transact with them directly: they process the payment itself when you buy a credit pack or subscribe, and they hold your payment card details. We never see or store them. For payments, Apple and Google act as independent companies responsible for their own data practices, not as our processors; their own privacy policies apply to what they collect.
  • Product analytics. In-app usage events tied to your account identifier. See "Product analytics" below.
  • Email hosting. Support correspondence sent to our contact address is received and stored by our email hosting provider.

Data is hosted primarily on infrastructure in the United States.

Other disclosures

Beyond the service providers above, we may disclose personal data in a few ordinary business situations:

  • Legal process. To courts, regulators, or law enforcement in response to a subpoena, court order, or other valid legal demand, or where disclosure is required by law.
  • Safety, fraud, and enforcement. To investigate fraud or abuse, respond to a security incident, enforce our terms, or establish or defend legal claims.
  • Professional advisers. To lawyers, accountants, auditors, or insurers under confidentiality obligations, where needed for their advice or services.
  • Business transfers. In connection with a merger, acquisition, financing, or sale of assets, including due diligence for one, your data may be disclosed to the parties involved and transferred to a successor, which remains bound by this policy or one materially like it.
  • De-identified data. We may create and use aggregated or de-identified statistics (for example, how many videos were saved this month) that do not identify you.

Saved videos link out to the platforms that host them; when you follow one, that platform's own privacy practices apply.

Purchases and subscriptions

Yomlet sells consumable credit packs and a monthly auto-renewing Unlimited subscription, through Apple's App Store on iOS and, where the app is available on Android, Google Play billing. Here is exactly how that data flows:

  • Apple and Google hold your payment details. When you buy a credit pack or subscribe, your card details are entered into and processed by Apple's or Google's own payment system. Neither Yomlet nor our purchase-management provider ever receives or stores your card number, expiry, or billing address.
  • A purchase-management service processes the purchase event. We use a specialised subscription and purchase management provider. It receives the purchase receipt from Apple or Google, validates it, and reports back the product purchased, the price and currency, and a transaction identifier, along with your Yomlet account identifier (not your email or name) so the purchase can be tied to your account.
  • We keep transaction records for entitlement and audit. We store the transaction identifier, product identifier, purchase date, and store (App Store or Play Store) against your account. This lets us grant you the credits or Unlimited access you paid for, verify a "restore purchases" request, and investigate a billing dispute if one comes up. We do not use this data for any purpose beyond running the purchase and subscription system.
  • Refunds generally go through the store. Because Apple and Google process the payment, refund requests are generally handled through them: Apple refunds are granted by Apple, and Google Play refunds are handled by Google, though we can issue Play refunds where store rules or law call for it. We never receive your payment card details. See the Terms of Use for how to request one.

Product analytics

We use a third-party product-analytics service to understand how people use Yomlet: which features get opened, where submissions fail, and whether changes we ship actually help. Analytics events are tied to your account identifier (not your name or email), and event data is limited to product usage — things like "session started," "video submitted," or "paywall opened" — plus device and technical properties, including an approximate, city-level region derived from your IP address. Free-text you type, your email address, and your display name are deliberately excluded from analytics events by design.

Our analytics provider is a product-analytics tool, not an advertising or cross-app tracking service. We do not use it to build an advertising profile of you, sell your data, or share it with data brokers, and it does not receive your saved-video content or personal identifiers beyond the internal account ID.

How we keep it secure

We use reasonable administrative, technical, and organisational safeguards designed to protect your data, though no system can be guaranteed perfectly secure. Traffic between the app and our backend is encrypted in transit via HTTPS. On iOS, your authentication tokens are stored in the system Keychain. Our database enforces row-level security rules designed to prevent a query from one user's account reading another user's data. Purchase and entitlement records are designed to be writable only by our server, not directly by the app, to prevent tampering with credits or subscription status. We use only standard, system-provided encryption; we do not implement our own cryptographic algorithms.

Data retention

We retain personal information only for as long as necessary for the purposes described in this policy or as required by law. Account and content data are kept while your account is active and deleted from our database when you delete your account (see "Account deletion" below). Analytics events, web access and security logs, video-processing logs, and support correspondence are retained under our and our providers' standard retention practices. Transaction records held by Apple, Google, and our purchase-management provider persist under their own terms, and minimal transaction records may be kept where tax, accounting, fraud-prevention, or dispute rules require it. Routine provider backups expire on standard rolling schedules; deleted data ages out of them rather than being individually removed.

Your choices and rights

For requests made by email, we may first verify that you control the account (typically by requiring the request to come from, or be confirmed via, the account's email address), and we may decline requests where the law allows, telling you why. If you are unhappy with how we handled a request, reply and ask for it to be escalated.

  • Access and export. You can request a copy of the data we hold about your account by emailing hello@yomlet.com. We will reply within a reasonable time, and in any case within any period required by applicable law.
  • Account deletion. You can delete your account at any time from inside the app (menu → Profile → Delete account). This is permanent. What is deleted and what remains falls into clear categories: your account, library, folders, usage records, and the purchase and entitlement records in our database are deleted; transaction records that tax, accounting, fraud-prevention, or dispute rules require us or our providers to keep are retained separately, without an active link to a Yomlet account; analytics events lose their connection to any identifying data we hold; routine provider backups expire on rolling schedules rather than being individually purged; and we keep a limited audit record of the deletion itself (a hashed account identifier, the request's IP address and device string, and the outcome), used only for fraud-prevention and security purposes such as detecting abuse of the deletion endpoint. If you no longer have access to the app, email hello@yomlet.com and we will delete your account within a reasonable time, and in any case within any period required by applicable law.
  • Corrections. You can edit your display name in-app. For other corrections, email us.
  • Opt-out of communications. Transactional emails (password reset, account confirmation, purchase receipts) are required to operate the app. We do not send marketing emails today; if that changes, you will be able to opt out from any such email.

Age requirement

Yomlet is for adults 18 and over; our Terms of Use require it. The app is not directed to children, and we do not knowingly collect data from anyone under 18, including children under 13. If you believe someone under 18 has created an account, contact us and we will delete it.

Do Not Track and cross-site collection

The website and app use cookies and similar local-storage technologies for two purposes only: keeping you signed in, and the product analytics described above. We do not use third-party advertising cookies. Our service does not respond to browser "Do Not Track" signals: we do not track you across other companies' websites or apps in the first place, so there is no cross-site tracking for such a signal to switch off. We do not permit third parties to collect personal information about your activity over time and across different websites through our service.

Changes to this policy

Changes to this policy take effect when posted on this page, with the "Last updated" date revised. For significant changes to how we handle your data, we will aim to notify you by email. We will not retroactively apply materially expanded data practices to data collected under an earlier version of this policy without notifying you and, where the law requires it, obtaining your consent. Non-material changes (wording, formatting, clarifications that do not change practice) may be made without notice.

Contact

Questions, requests, or concerns about this policy or how we handle your data: hello@yomlet.com.

Koi Gang Inc.
1207 Delaware Ave #4043
Wilmington, DE 19806
United States