legal

privacy policy

last updated DD MMM 2026 effective DD MMM 2026 version 1.0

the short version

  • You hold a button and talk. We turn that audio into text, rewrite it in the mode you picked, and hand it back.
  • Audio is sent to our processors to be transcribed, then deleted within N hours. We keep the text, because that's the feature.
  • Your transcripts are processed by third-party AI providers. They are named in section 5.
  • The keyboard needs Full Access to send audio for transcription. Without it, the keyboard still types — it just can't rewrite.
  • We do not sell your data, use it for advertising, or use your voice to train anyone's model unless you switch that on yourself.
  • You can delete a single transcript, all of them, or your whole account, from inside the app.

This summary is here to help. Where it and the full policy disagree, the full policy is what governs.

who we are

Legal entity name ("yap", "we", "us"), registered at registered office address, CIN / registration number, is the data fiduciary and controller responsible for the yap app and the yap keyboard extension.

This policy covers the yap iOS app, the yap keyboard extension, and this website. It does not cover the apps you paste into — once text is on your clipboard and you send it, that app's own policy applies.

what happens to your voice

This is the part most people actually want to know, so it goes first.

  1. You hold the button. Recording starts only while the button is held, and the app shows a visible recording indicator the entire time. Nothing is captured when you are not holding it. yap does not listen in the background, does not use a wake word, and has no always-on mode.
  2. The audio is uploaded over an encrypted connection to our speech-to-text processor to be turned into a transcript.
  3. The transcript is rewritten by an AI language model in the mode you chose — boss, casual, roast, rizz, hindi, or one you wrote yourself.
  4. The rewrite comes back to your device and goes on your clipboard. The original transcript and the rewrite are saved to your yap history so you can search and paste them again.
  5. The audio recording is deleted from our processors and our systems within N hours. We do not build an archive of your voice.

What we cannot do. Because a rewrite has to be generated somewhere, we do see the text of what you said. If something should never leave your device, don't yap it — type it.

what we collect

Categories, sources and uses
CategoryWhat it isHow we get itWhat we use it for
Voice recordings The audio you record by holding the yap button. Directly from you, while you hold the button. Producing a transcript. Deleted after processing.
Transcripts & rewrites The text of what you said and each rewritten version. Generated from your recording. Delivering the feature; your searchable history.
Custom modes Tone instructions you write yourself. Directly from you. Applying your mode to future rewrites.
Account data Email address, and the Apple or Google identifier you signed in with. From you and from your chosen sign-in provider. Authenticating you; syncing your history across your devices.
Device & app data Device model, OS version, app version, language, locale, crash logs. Automatically from the app. Fixing crashes; keeping the app working on your device.
Usage data Counts and timestamps — rewrites used, modes chosen, features opened. Automatically from the app. Understanding which features earn their place; enforcing usage limits.
Support messages Whatever you send us, plus the diagnostics you choose to attach. Directly from you. Answering you.

What we do not collect

  • Anything you type on the keyboard. The yap keyboard does not log, transmit or analyse your keystrokes. Guideline 4.4.1 of the App Store rules permits a keyboard to collect activity only to improve that user's own keyboard on their own device, and we collect less than that: nothing.
  • Your contacts, photos, location, or health data. yap never asks for these permissions.
  • Advertising identifiers. yap contains no advertising and no third-party ad or tracking SDKs. We do not use the App Tracking Transparency framework because we do not track you across other companies' apps and websites.

why we're allowed to

Under India's Digital Personal Data Protection Act, 2023 we process your personal data on the basis of the consent you give when you sign up and when you grant microphone access. For users in the UK and EEA, our lawful bases under the GDPR are:

  • Performance of a contract — processing your recordings and transcripts is the service you asked for.
  • Consent — microphone access, optional model-improvement sharing, and any marketing email. Each of these can be withdrawn without losing access to the core app.
  • Legitimate interests — keeping the service secure, preventing abuse, and fixing crashes.
  • Legal obligation — where we are required to retain or disclose something by law.

who else sees it

We share the minimum needed to make yap work. Every provider below is bound by a written agreement requiring them to protect your data to at least the standard set out in this policy, to process it only on our instructions, and not to use it for their own purposes.

Third-party AI. Your transcripts are sent to third-party AI providers to be rewritten. Apple's Guideline 5.1.2(i) requires us to say so plainly and to get your permission first — so we ask for it during onboarding, before your first recording, not buried in a settings screen.

Processors and sub-processors
ProviderPurposeWhat it receivesRegion
Speech-to-text vendorTranscriptionVoice recordingregion
AI model providerRewriting into modesTranscript textregion
SupabaseAuthentication, database, storageAccount data, transcriptsregion
AppleSign in with Apple, push notifications, App StoreAccount identifier, device tokenGlobal
GoogleGoogle Sign-InAccount identifierGlobal
Crash / analytics vendorCrash reporting, product analyticsDevice and usage dataregion

We may also disclose data where we are legally compelled to, or to protect the rights and safety of our users. If yap is ever acquired or merged, your data may transfer with the business — we will tell you before that happens and this policy will continue to apply until we give you notice of a new one.

Model training

Your recordings and transcripts are not used to train AI models by default, and our provider agreements prohibit our processors from training on your content. If we ever offer you the option to contribute recordings to improve accuracy — particularly for Hinglish and Indian-accented speech, where general models perform badly — it will be a separate opt-in that is off until you turn it on, and you can turn it back off at any time.

the keyboard and full access

Custom keyboards on iOS run in a sandbox with no network connection unless you grant them Full Access in Settings. This is worth understanding properly, because keyboards are the most sensitive extension iOS allows.

Without Full Access

The yap keyboard types. You get the full character keyboard, the globe key to switch back to any other keyboard, and your locally stored transcripts to paste from. It cannot reach the internet, so it cannot record or rewrite anything.

With Full Access

The keyboard can send your recording for transcription and fetch the rewrite, and can sync your history. That is all the permission is used for.

What we never do with Full Access. We do not read, store, transmit or analyse anything you type on the keyboard — not passwords, not card numbers, not messages, not the contents of the field you're typing into. We do not log which apps you use it in. Full Access is used exclusively for the network calls described above.

You can revoke Full Access at any time in Settings → General → Keyboard → Keyboards → yap, and the keyboard will keep working as a keyboard.

permissions we ask for

Every permission, and what it's for
PermissionWhyIf you say no
MicrophoneTo record what you say when you hold the yap button.You can still read, search, edit and paste from your existing history. You can't make new recordings.
Speech recognitionTo convert your recording into text.Same as above.
Keyboard Full AccessNetwork access for the keyboard, as described in section 6.The keyboard types and pastes; it can't rewrite.
NotificationsOptional. Only for things you asked for — a finished long rewrite, or a reply from support.Nothing is withheld. yap works fully without notifications.

Every recording is accompanied by an on-screen indicator, and iOS shows its own microphone indicator in the status bar. Nothing is ever recorded without both.

how long we keep it

Retention periods
DataKept for
Voice recordingsUntil transcription completes, then deleted within N hours.
Transcripts & rewritesUntil you delete them, or N days after you delete your account.
Account dataWhile your account exists, then deleted within 30 days.
Crash & diagnostic logsN days.
Aggregate usage countsRetained in de-identified form with no link back to you.
Support correspondenceN months after your issue is closed.
Records we must keep by lawAs long as the relevant law requires, and no longer.

Backups are on a rolling N-day cycle, so deleted content can persist in encrypted backups for up to that long before it ages out.

deleting and withdrawing

You do not have to email anyone to get your data out of yap.

  • One transcript — swipe it in your history and delete. Gone from your device immediately and from our servers within N hours.
  • Everything at onceSettings → Privacy → Delete all transcripts.
  • Your whole accountSettings → Account → Delete account. This is available inside the app, permanently deletes your account and content, and does not require you to contact support. Apple requires in-app account deletion under Guideline 5.1.1(v), and we think it should be table stakes anyway.
  • Withdraw consent — revoke microphone access or Full Access in iOS Settings at any time; turn off model-improvement sharing in the app. Withdrawing consent stops future processing but doesn't undo processing already lawfully carried out.
  • Take it with youSettings → Privacy → Export my data gives you a machine-readable file of your transcripts and account details.

Full step-by-step instructions, including how to request deletion without opening the app, are on the data and deletion page.

your rights

Depending on where you live, you have some or all of the following rights: to know what we hold, to get a copy, to correct it, to erase it, to restrict or object to processing, to withdraw consent, to data portability, and to complain to a regulator. yap does not carry out automated decision-making that has legal consequences for you.

India. Under the Digital Personal Data Protection Act, 2023 you may access, correct, complete, update and erase your data, nominate someone to exercise your rights if you can't, and take an unresolved complaint to the Data Protection Board of India — but you must raise it with our Grievance Officer first (section 15).

UK and EEA. You may complain to your national supervisory authority, or to the lead supervisory authority if we have one.

California. You may request disclosure of the categories and specific pieces of personal information we hold, request deletion or correction, and opt out of "sale" or "sharing" — we do neither, so there is nothing to opt out of. We will not discriminate against you for exercising any of these rights.

We respond within 30 days. We may need to verify who you are first, and we will only ever do that using data we already hold.

age and children

yap is rated age rating on the App Store and is not directed at children.

India is stricter than most places, and this matters for yap. The DPDP Act treats anyone under 18 as a child, and requires verifiable parental consent before processing their data — plus a prohibition on behavioural monitoring and targeted advertising directed at them. A product aimed at a young Indian audience has to answer this directly rather than copy a US policy that stops at 13.

Our position: state the minimum age and the age-assurance mechanism — e.g. "you must be 18+ to create a yap account, confirmed at sign-up", or the verifiable parental consent flow if under-18s are allowed. This must match the App Store age rating and the Terms.

If you believe a child has given us personal data without the consent required where they live, contact us at privacy@yap.app and we will delete it.

security

  • Everything in transit is encrypted with TLS 1.2 or better. Stored data is encrypted at rest.
  • Access to production data is limited to staff who need it, behind multi-factor authentication, and is logged.
  • The keyboard extension holds no credentials of its own and talks only to our API.
  • Add: pen-test cadence, vulnerability disclosure contact, breach notification commitment. Under the DPDP Act, a personal data breach must be reported to the Data Protection Board and to affected users — name the timeline you're committing to.

No system is perfectly secure, and we won't pretend otherwise. If you find a vulnerability, please tell us at security@yap.app before telling anyone else, and we'll credit you.

where data goes

yap is built in India. Our processors operate in list countries/regions, so your data may be processed outside the country you live in.

Where we move personal data out of the UK or EEA, we rely on UK International Data Transfer Agreements or the EU Standard Contractual Clauses, with a transfer risk assessment on file. Transfers out of India are made in accordance with section 16 of the DPDP Act and any restrictions the government notifies.

changes

When this policy changes we update the date at the top and keep the previous version available at archive URL. If a change materially affects how we use your data, we will tell you in the app or by email before it takes effect, and where the law requires it we will ask for your consent again rather than assume it.

contact and grievances

Privacy questions, rights requests, or complaints:

  • Emailprivacy@yap.app
  • Grievance Officer (required under the DPDP Act) — name, designation, email, phone
  • Postregistered office address
  • Everything else — the support page

We aim to acknowledge within N working days and resolve within 30.


Not legal advice, and not ready to publish. This is a drafted policy structured against Apple's App Review Guidelines 5.1.1 and 5.1.2, the DPDP Act 2023, and the UK/EU GDPR. Every highlighted item is an unresolved fact that only you can supply, and the whole document needs review by a qualified Indian privacy lawyer before it goes live. Guideline 2.1(a) also means App Review will reject a submission whose linked pages still contain placeholder text.