Legal
Privacy Policy
What Yaap handles, where it goes, and the choices you have.
Draft prepared September 12, 2026
Draft for review
This document is being prepared for launch and is not yet an effective policy. Operator details and final hosted service policies are still being confirmed.
Who this covers
This notice describes how Yaap handles information when you visit its website, create an account, contact support or use the hosted analytics service.
The legal operator’s name and address will be included in the final notice. For questions about this notice, contact us.
When a customer uses hosted Yaap to measure their website, that customer decides what to collect and why. Yaap processes that analytics data on their behalf. The customer’s own privacy notice explains their use of the data.
With self-hosting, the installation operator controls the infrastructure and database. Installing Yaap does not give the Yaap project access to that database. Contact the operator of the website you visited about data held in their installation.
Information handled
- Accounts: name, email address, password hash, verification and recovery records, sessions and website access permissions. Authentication records can include IP addresses and browser information.
- Analytics: page paths, timestamps, referring domains, supported campaign labels, device and browser categories, approximate geography and custom events with properties supplied by the website operator. Identified tracking also supports visitor journeys and session attribution.
- Payment attribution: when configured by a customer, transaction references, amounts, currencies, refunds and attribution identifiers. These records are separate from the customer’s Yaap subscription.
- Subscription billing: customer and subscription references, plan, payment status, billing periods and usage records. Checkout collects payment details through the billing provider.
- Support and operations: information you include in requests and technical records needed to investigate errors, deliver the service and protect accounts.
The analytics pipeline derives coarse geography and device categories from incoming requests. Raw IP addresses and raw user-agent strings are not put in the analytics queue. This does not mean that hosting infrastructure or authentication records never process them.
Website operators should keep personal details out of page paths, event names, campaign labels and custom properties.
Cookies and browser storage
Signing in uses session cookies. The dashboard also stores your theme preference in your browser.
In full analytics mode, the tracker stores a random visitor ID in local storage for 180 days from creation and a session ID in the tab’s session storage. Sessions renew after 30 minutes without a tracked event. These identify a browser or session, not a verified person. IDs are hashed with a site-specific input and server secret before entering the analytics queue.
Anonymous mode sends events without accessing visitor or session storage. Paused mode stops collection. Enabling tracking does not itself record consent; website operators control when collection and identifiers are allowed.
Yaap includes optional analytics for its own homepage, using the same tracker with identifiers enabled when configured. Collection is paused on other pages, including account and dashboard pages. Previously created browser identifiers may remain stored.
You can clear stored data using your browser controls. To change a website’s tracking choices, use that website’s privacy controls or contact its operator. See the tracking guide for the available modes.
How information is used
Account and operational information supports signing in, managing websites and permissions, delivering reports, handling support, protecting the service and administering subscriptions. Customer analytics is used to produce the reports that customer requests.
The final notice will identify the applicable legal basis for each purpose, including contract performance, legal obligations, legitimate interests and consent where relevant. Website operators are responsible for establishing the basis for analytics on their own websites.
Providers and data locations
Yaap runs on Cloudflare infrastructure. An installation can store data in Cloudflare D1 or PostgreSQL. Cloudflare can also deliver transactional email when configured. Hosted subscriptions integrate with Polar for checkout and billing.
The final hosted provider list will identify the production database provider, processing locations and applicable safeguards for international transfers. An infrastructure provider’s global presence is not a promise that data stays in a particular country.
Self-hosted operators choose and manage their own providers. Third-party services you connect handle information under their own terms and privacy notices.
Retention and deletion
Analytics and payment history have separate retention settings. Self-hosted installations can disable automatic retention; in that case, records remain until the operator deletes them or enables a retention policy.
Browser identifier lifetimes are described above. They do not determine how long server-side analytics records remain.
The final hosted notice will specify analytics retention, account closure and post-cancellation deletion timelines, along with retention of backups, support, operational and billing records. Cancelling a subscription does not itself delete the analytics history.
Your choices and rights
Depending on applicable law, you may request access to, correction, deletion or a portable copy of your personal information, and restriction of its processing. You may also withdraw consent where processing relies on it.
You may have the right to object to processing based on legitimate interests. contact us to raise an objection or another privacy request. Identity or authority may need to be verified before information can be disclosed or changed.
For analytics collected by another website, contact that website’s operator first. They control the collection and can identify the relevant installation. You may also complain to the data protection authority in your jurisdiction.
Changes to this notice
The date at the top identifies this version. The final notice and any subsequent updates will be published here, with additional notice of material changes where required.