- We collect only what we need to run YUPiTi and reach you. Card numbers never touch YUPiTi.
- No ad trackers, no session recording, no keystroke logging, and no Google Fonts: our fonts load from our own servers.
- We never sell or share your information for advertising.
- Face ID and fingerprints stay on your phone. We never see them.
- You can see, export, fix or delete your data at any time.
1. This site (yupiti.app)
When you fill out the Lock In Early form we collect your name, business name, email, phone (optional), what you do, team size, how clients pay you today, your starting point and any note you add. The form is processed by our host, Netlify, and emailed to us so we can reply.
This site does not use advertising trackers, third-party analytics cookies or session recording. Fonts are served from our own domain, so your visit doesn't reach Google or any font service. It stores one small setting in your browser so the intro animation plays only once per visit.
2. Inside YUPiTi
To run your pay pages, portals and books, YUPiTi stores:
- Your business details: name, logo, colors, services, prices and team logins.
- Your clients' details: names, emails, phone numbers, invoices, payments received and notes you add.
- Crew details: names, contact info, invoices and payout records. For tax forms we keep only the last 4 digits of a tax ID, never the full number.
- Receipts and files you upload to Books or portals.
- Security and activity: who changed what and when, sign-ins, whether an invoice link was opened, and basic technical logs to keep the Service secure.
What we don't store: card numbers, bank passwords, full tax IDs, or your keys in readable form. Card details go straight to your payment provider. Keys you connect live in your host's secret settings, or are encrypted with AES-256 if you paste one in (see our Security page).
3. The YUPiTi app
- Face ID / fingerprint: handled entirely by your phone. YUPiTi only learns yes or no; we never receive biometric data.
- Notifications: if you turn them on, we store your phone's push token and which alerts you want, and deliver them through Apple or Google.
- Camera and photos: used only when you tap Scan or attach a receipt. The photo is stored privately with your books.
- You can delete your account from Settings → This phone → Delete my account.
4. Sign-in and 2-step verification
If you turn on 2-step verification we store the phone number or email you choose for codes, or an authenticator-app key that we keep encrypted. Codes are sent through our text and email providers. We only use these details to sign you in and to send security alerts.
5. AI features
AI helpers are optional and use a provider you connect (Anthropic's Claude or OpenAI's ChatGPT, with your own key). When you use one, the text of that request goes to that provider. YUPiTi first removes emails, phone numbers and long numbers. The provider's own privacy terms apply to what it receives.
6. How we use information
- To run the Service: send invoices, reminders, receipts and notifications, show your board and books, and pay your crew.
- To support you and tell you about changes to your account.
- To keep the Service secure and prevent fraud.
Your clients' information is used only to serve your business. We don't market to your clients, and we don't combine your data with other businesses' data.
7. Who we share it with
Only the services that make YUPiTi work, and only what each one needs:
- Hosting and storage: Netlify.
- Payments: the processors you connect, such as Square or Stripe; Plaid if you connect a bank.
- XRP Ledger: if you accept XRP or RLUSD, we read the public XRP Ledger for payments to your address and fetch the XRP price from public price services (CoinGecko, Coinbase, Kraken). Nothing about your clients is sent to them. Ledger payments are public by nature: anyone can see the amounts and addresses on the ledger.
- Email and texts: Resend (email), Twilio (texts and sign-in codes), and Mailchimp or similar if you connect them for your own campaigns.
- Phone notifications: Apple Push Notification service and Google Firebase Cloud Messaging.
- AI: the AI provider you connect, only when you use an AI feature.
- Law: if we are legally required to, and we will tell you unless the law forbids it.
We never sell or rent personal information, and we don't share it for cross-context behavioral advertising.
8. Texts and email
Marketing texts and emails only go to people who opted in and confirmed they're 13 or older. Every marketing email has a one-click unsubscribe link, and every text honors STOP. Invoice, receipt and security messages are sent because you have an account or a job with the business.
9. How long we keep it
Every kind of data has a time limit. An automatic cleanup runs every night, before the nightly backup.
- Your clients, invoices, books and files: while your account is active; you can delete any item at any time. Paid invoices and their payment records are deleted automatically 7 years after they were paid (a common tax record-keeping period). Export anything you need to keep longer.
- “Invoice opened” tracking: 12 months.
- “I sent it” payment notes: until you confirm or dismiss them, and never more than 45 days.
- Activity and security log: 12 months. IP addresses are cut down to the general area (for example 73.24.x.x) before they're saved.
- Anti-abuse counters for forms: 2 days.
- Sign-in codes: expire in 10 minutes. “Trust this device” lasts 30 days.
- Phone notification tokens: until you turn notifications off or remove the device; tokens that stop working are deleted automatically.
- Tester answers and demo reviews: 24 months, except a review you agreed to have featured, which stays while it's on our site and is removed when you ask.
- Mailing lists: until the person unsubscribes. They're then marked do-not-contact, so they're never added back by mistake. If they're also a client of the business, their client record follows the first rule above.
- Keys you connect: encrypted, and deleted the moment you disconnect.
- Bank connections (when available): only the deposit details needed to match a payment (date, amount, sender name and memo), kept 90 days; the connection is deleted within 24 hours after you disconnect.
- yupiti.app sign-up form: 12 months if we don't start working together.
- Backups: 30 days, then permanently deleted. Backups never contain passwords, sessions or keys.
- After you cancel or the Service ends: kept 1 year so you can export it or come back, then deleted from live systems; backups roll off within 30 more days.
- If you ask us to delete your account: we send you an export, then erase it within 30 days of your confirmation, unless the law requires us to keep something.
10. Your choices and rights
- See, export or correct your information.
- Ask us to delete it.
- Opt out of any marketing messages.
Email hello@yupiti.app and we will respond within 30 days. Depending on where you live (for example California), you may have additional rights to know, delete and correct your information and to not be discriminated against for using them; we honor those requests the same way. If you are a client of a business that uses YUPiTi, you can also contact that business directly.
11. Kids
YUPiTi is built for businesses and isn't directed at children under 13. Our sign-up and review forms ask people to confirm they are 13 or older, and we don't knowingly collect information from younger children. If you think a child has given us information, email us and we will delete it.
12. Security
Data is encrypted in transit, passwords are hashed with scrypt, authenticator keys and any pasted keys are encrypted with AES-256, sign-ins are rate-limited and logged, and 2-step verification is available on every account. Nobody at YUPiTi can read your password or your keys. See our Security page for more.
13. Changes
If we change this policy, we will update the date at the top and tell active customers about any material change.