Privacy Policy
This policy explains what Yallery, Inc. collects when you use the YEngine generation API and the console at dashboard.yallerylabs.com, why, and what you can do about it. It is written to be read, not to be survived.
1. What we collect
| What | Why | Kept |
|---|---|---|
| Email address, and company name if you give one | To identify the account and to reach you about it | While the account exists |
| Password hash | To sign you in. We never store the password itself | While the account exists |
| API key hashes | To recognise your keys. We cannot recover a key from this | While the key exists |
| Prompts and files you send | To generate what you asked for | See section 3 |
| Generated outputs | To deliver them to you at a URL | See section 3 |
| Call records: model, size, timing, price | To bill you and to show your usage | 7 years, for accounting |
| Payment records | To take payment and issue receipts | 7 years, for accounting |
| Server logs: IP address, request time, response status | To operate the service, find faults and stop abuse | 30 days |
We do not use advertising trackers, and we do not run analytics that profile you. The only cookie the site sets is yl_lang, which remembers the language you chose. It carries no identifier.
2. What we never do with your content
We do not train models on your prompts, inputs or outputs. We do not sell them, we do not share them with other customers, and we do not publish them as examples without asking you first in writing.
Our staff do not read your prompts as a matter of routine. Someone may look at a specific job if you ask us to investigate it, or if we are required to by law.
3. How long we keep prompts and outputs
Today we keep them indefinitely. Generated files stay in our object storage so the URLs we returned to you keep working, and the prompt is stored with the job record. We would rather tell you that plainly than publish a deletion promise we do not yet keep.
You can ask us to delete the content of your account at any time by writing to [email protected], and we will do it within 30 days. Records we must keep for accounting — what was billed, when, and how much — survive that deletion, because the law requires them.
4. Who else processes your data
Running the Service means handing parts of it to other companies. These are all of them:
| Who | What they receive | Where |
|---|---|---|
| DigitalOcean | Everything: our servers, database and file storage | United States, Germany |
| RunPod | Prompts and input files, while a GPU generates the result | United States, Europe |
| Pruna AI | Prompts and input files for the hosted image models | European Union |
| OpenAI | Only the prompt text of a video-retake call, which is expanded into a fuller motion description before generation | United States |
| Stripe | Your email and payment details. Card numbers go to Stripe directly and never touch our servers | United States |
| SendGrid (Twilio) | Your email address, to deliver account mail such as a password reset | United States |
| Cloudflare | Your IP address and request metadata, as the network in front of our servers | Global |
We do not sell personal data to anyone, for any purpose.
5. Where your data goes
We are a United States company and our infrastructure spans the United States and the European Union. If you are in the EEA or the UK, using the Service means your data is transferred to the United States. Where a transfer needs a legal basis, we rely on the European Commission’s Standard Contractual Clauses with the providers above.
6. Your rights
Wherever you are, you can ask us to show you the personal data we hold about you, correct it, delete it, or send it to you in a portable form. If you are in the EEA or the UK you also have the right to object to processing and to complain to your local data protection authority.
One address for all of it: [email protected]. We answer within 30 days. We will ask you to write from the address on the account, because that is the only way we can tell it is you.
7. Security
Traffic is encrypted in transit. Passwords are stored as bcrypt hashes and API keys as SHA-256 hashes, so neither can be read back out of our database. Webhook deliveries can be signed with a secret you create, so your server can verify a call really came from us.
No system is perfect. If we discover a breach affecting your personal data, we will tell you and the relevant authority without undue delay.
8. Children
The Service is not for anyone under 18, and we do not knowingly collect data from children. If you believe a child has an account here, write to us and we will remove it.
9. Changes
If we change this policy in a way that materially affects you, we will email the address on your account before it takes effect. The date at the top always says when it last changed.
10. Contact
Yallery, Inc.
22125 Northeast 13th Place, Sammamish, WA 98074, United States
[email protected]