YAPILAPI
Log inJoin YAPILAPI
All policiesTerms of servicePrivacy policyCommunity guidelinesSafety and minorsCreator and seller termsCopyright and takedownsCookie notice

Privacy policy

Last updated September 28, 2026

This policy explains what information YAPILAPI collects, why, who we share it with, how long we keep it and the choices you have. [Company legal name], [Registered address], is responsible for your information (the “controller”). Questions or requests: [privacy email address].

We don’t sell your personal information, and we don’t use it to track you across other companies’ apps and websites.

1. What we collect

When you create an account

  • Your email address, a password (we store only a scrambled form of it, never the password itself), your username and your name.
  • Your date of birth. Everyone gives it when they sign up (accounts made before we asked give it once, the next time they sign in). We use it to refuse people under 13, to protect people under 18 (see Safety and minors), and to check that people who sell, get paid or receive tips are 18 or older. We never show it on your profile.
  • Your language, and the invite code you used and who invited you, if any.
  • Later, if you add one, your phone number. To confirm it we send a code by text message through Twilio, and we keep a record of each code request (the number, time and IP address).
  • If you change your username: the old and new names and when you changed them. Your old name is held for you for 14 days, during which links and @mentions using it still lead to your profile and nobody else can take it.

What you share

  • Your profile: photo, cover photo, bio, name, pronouns, links (up to 5), interests, the kind of profile, the colours and layout you choose, the posts you feature, a profile song, your “Now” status, a city if you add one, and a country if you choose one. Your name, username, photo and bio are visible to everyone who can find you; a private account shows its posts only to approved followers. The city on the profile of someone under 18 is never shown to others.
  • To show the icon of the websites you link to, our server fetches each site’s small icon itself and keeps it for about a week. The linked site sees our server, not you or your visitors.
  • What you create: posts, reels, stories, comments, reactions, polls, boards, chapters, recaps, memories, events, communities, rooms, products, reviews, drops and live videos (which are recorded, so you get the recording and clips can be made), with the audience you choose. Drafts and scheduled posts are seen only by you until they are published. Earlier versions of edited posts and comments are kept, and people who can see the post can open them.
  • Event tickets: your tickets (from saying you’re going or buying one), who gave you one or whom you gave one to, and when you were checked in at the door and by whom. An event’s host and the co-hosts they choose see your name, ticket type and check-in time on its guest list; someone under 18 who isn’t their friend shows by first name only. The QR code on a ticket holds a code our server signs, not your details.
  • Messages and calls: we store your chats, voice messages, attachments, polls, shared lists, reminders and games in chats on our servers so we can deliver them. They are not end-to-end encrypted. Earlier versions of edited messages are kept so reports about them can be checked. View-once media is deleted once everyone has seen it, or after 14 days; disappearing messages are deleted when they expire (24 hours, 7 days or 90 days, as the chat chose). Calls go directly between devices where possible (otherwise through our relay server) and are not recorded; we keep a history of who called whom, when and for how long. Audio rooms are not recorded.
  • Messages you schedule with “Send later” are stored until their time, seen only by you, and then sent like any other message. Chat wallpapers and bubble colours are stored with the chat and seen by everyone in it.
  • Games in chats (Four up, Noughts, Word ladder and Chess): the board, each move (and chess draw offers), who played and who won. Only the people in the chat see them.
  • Sharing where you are: we ask your device for its location only when you tap “Share where I am” in a chat. A live share lasts 15 minutes, 1 hour or 8 hours, and ends sooner if you stop it, leave the chat, someone joins it, or you or someone in it blocks the other. While it runs we keep only the latest place (rounded to about 1 km if you choose “Approximate”) and send it only to the people in that chat; when it ends the place is deleted and we keep only that you shared, with which chat, and when. A location you send once stays like a message until you unsend it. Places are never written to our logs or product analytics, never shown to AI features, and your data download lists when you shared, not where. On the web, sharing stops if you close the page. The distance and direction to someone are worked out on your own device, and your position for them is never sent to us. “Open in maps” gives the place to the maps service you open (OpenStreetMap on the web, your phone’s maps app), only when you choose it.
  • Watch together: while people in a chat watch videos together, we keep the session, who joined and left, the queue of videos and where playback is.
  • Market: when you list something, we keep its photos, words, price, the area you wrote and, if you choose “Use my approximate location”, a place rounded to about 1 km. Nobody is ever shown that place: people see your area and a distance in whole kilometres, worked out on our servers. To show what is near you, the web asks your browser for your position only when you tap the button, rounds it to about 1 km before sending it, and we use it for that search only, without keeping it. We keep your saved listings, the chats you start about listings, offers and ratings. Nothing is paid through YAPILAPI: you meet and pay in person.
  • Questions (“Ask me”): if you turn on a question box, we keep its settings, the questions you receive and your answers. When you ask a question, we always store that it was you. If you ask “without your name shown”, the person you asked and everyone else can’t see who asked, and neither can their data download, but our moderators can see it when they review the question, and we can disclose it when the law requires it.
  • Photos, videos and voice notes: files can contain information added by your device, such as where and when they were taken and the camera used. We remove it before we store anything: the file we keep, and every size and copy made from it, has no location or device information.
  • Things you ask the assistant to remember (“assistant memory”), only if you turn it on. You can see and delete them in Settings.

What we make for you

  • Weekly wrap: unless you turn it off in Settings, on Sunday evening in your time zone we put together a private look back at your week (what you shared, new friends, communities you joined, events and places, songs you used and a moment from your own posts). For this we keep the time zone your device reports. Nothing is made for a week without activity. Only you see it, and you can delete it.
  • On this day: a card showing your own posts from this date in earlier years. It is worked out when you open the app and is not stored separately.
  • Catch me up: if the switch is on in Settings, we note when you open Pulse, so that after 12 hours or more away we can offer a summary of what your friends and the people you follow shared. Summaries and suggested chat replies are kept for 7 days so they can be shown again.

How you use YAPILAPI

  • Sign-ins and devices: for each session, your IP address, the type of device and browser, and when it was last used. Security events (sign-ins, failed sign-ins including the email address typed, password changes, username changes) with the IP address and device. You can see your sessions in Settings.
  • Sign-in alerts: for each account, a list of the devices it has signed in from, described as the browser or app and system (for example “Chrome on macOS”) and, when our network provider reports it, the country. When a sign-in comes from a device not on the list, we tell you in the app and, unless you turn it off in Settings, by email.
  • Activity: the posts and stories you view, reactions and saves, the feedback you give on your feed (“Show less like this”, muting), where you stopped in a reel, and events about actions you take (for example “created a post” or “joined a community”) with a few details about them, without your IP address. We use these to run your feed and to understand how YAPILAPI is used. If you turn off “Analytics” in Settings (Privacy), we stop recording these events for you and unlink the ones already recorded from your account.
  • Feed activity: which posts were on your screen and for how long, how much of a reel or video you watched, whether you finished or skipped it, when you shared a post or opened its author’s profile from it. Each post’s totals (how often it was seen, finished, skipped, shared and saved) help rank it for everyone. With “Personalization” on (Settings, Privacy), we also use your activity, likes, comments, saves, follows and feed feedback to learn which topics and creators you like, and to rank For you and Reels for you. When you turn Personalization off, we stop learning and delete what was learned; you can see what we learned in your data download.
  • Story views: the person who posted a story can see who viewed it.
  • Visits to business and place pages: which signed-in accounts visited on which day. Business owners see only totals (visitors per day), never who visited.
  • Time spent: the minutes you use YAPILAPI each day, for your own reminders and, if you are a supervised teen, for your family link.
  • Screenshots of view-once media: the phone app tells the sender, and we record that it happened.
  • Advertising: which sponsored posts were shown to you, clicked or hidden.
  • Your country, as reported by our network provider when you use YAPILAPI, or as you choose it in Settings. We use it to apply the law in your country, to check where music may be played, for sign-in alerts and, if you allow ads, to choose them. We don’t use your device’s location (GPS), except when you choose to share where you are in a chat (see above).
  • Your settings: for example who can message, comment on or mention you, quiet hours and their time zone, and notification choices.
  • Notifications: a token for each browser or phone where you turn on notifications.
  • Problems you report from Settings (Help): what you wrote, the page and the app version.

Contacts, only if you choose to find friends

When you look for friends from your contacts, the phone app turns each email address into a code on your phone before anything is sent, and names never leave your phone. On the web you can paste email addresses, which are coded in your browser. We compare the codes with those of accounts that allow it (adults with a confirmed email who kept “Let people who have my email find me” on), show you the matches, and don’t keep the codes; we only count how many were sent and matched. Phone numbers are not matched today.

Payments

When you pay, card details go straight to our payment provider: Stripe, or Paystack for payments in Nigerian naira, Ghanaian cedi, Kenyan shillings and South African rand. We send Paystack your email address with the amount. We keep your orders (what, how much, when, the provider’s reference), refunds, and the notifications the provider sends us about each payment, which can include your email address and the last digits and type of your card or bank. If you sell on YAPILAPI, we keep your products, drops, sales and payout requests (amount, currency, status, the provider’s reference), and where your payouts go: the reference Stripe or Paystack gives your account and, for a bank account, the bank’s name and the last four digits of the number (the full number stays with Paystack). If you ask to be reminded about a drop, we keep that you asked; the seller sees only how many people are waiting, never who. Units of a drop in an unpaid order are held for you for 15 minutes.

Safety

Reports you make or that are made about you, moderation decisions and appeals, and signals we use against spam and fake accounts (for example sign-ups from a throwaway email service or many sign-ups from the same network). Photos and videos may be checked automatically for nudity and violence (see section 3). Text in posts, comments, messages and questions is checked automatically by our own software for harmful content and spam.

Family links

If a guardian and a teen link their accounts, we store the link, the settings the guardian chose (who can message the teen, a daily reminder, quiet hours) and share the teen’s daily minutes with the guardian. Guardians never see messages or activity.

2. How we use it

  • To provide YAPILAPI: your account, profile, feed, messages, calls, events, shops and everything else you use.
  • To personalise it: your interests, who you follow and what you engage with decide what For you, Reels and Wander show and who we suggest you follow. Every post can tell you why you are seeing it. If you turn off “Personalization” in Settings (Privacy), these use nothing about you: they are ranked the same way for everyone, by how recent posts are and how many people engage with them. Your own filters (muted people and topics, “Not interested”) still apply.
  • To keep people safe: moderation, age protections, family links, regional rules, sign-in alerts, and preventing spam, fraud and attacks.
  • To process payments, refunds, drops and payouts.
  • To contact you: notifications you turned on, and emails to confirm your address, reset your password, alert you to a new sign-in or a change to your account’s security, and tell you about important changes. We don’t send marketing emails.
  • To show ads, only if you are 18 or older, turned on ads in Settings, aren’t supervised and don’t have Plus. They are chosen from your interests, language and country, never from your messages.
  • To make the optional AI features work when you use them (see “AI features” below).
  • To understand how YAPILAPI is used and improve it.
  • To comply with the law and respond to lawful requests.

Where the law requires a legal basis (for example in the European Economic Area and the United Kingdom), we rely on: our contract with you (to provide YAPILAPI); our legitimate interests (safety, security, preventing fraud, personalising and improving YAPILAPI), balanced against your rights; your consent (ads, contacts, assistant memory, notifications), which you can withdraw at any time; and legal obligations. [Legal bases to be confirmed by counsel for each country.]

AI features

These features are optional and only run when you use them (Catch me up runs when you open its card). What they produce is labelled as made with AI. What is sent to Anthropic, the company whose model answers:

  • Catch me up on Pulse and in communities: the text of recent posts you can see from the people and communities involved.
  • Suggested replies in chats: the last messages of the chat (up to 12) that you can see, including other people’s. None for view-once, voice, polls, lists or sensitive messages. On by default in one-to-one chats, off in groups and for people under 18; you can turn it off per chat or in Settings.
  • Suggest a description: the photo you want described, made smaller.
  • Suggest a caption: your draft text, your photos (made smaller) and, if Personalization is on, the text of a few of your recent posts. Using an idea marks the post as made with AI assistance.
  • See translation: the text you ask to translate. Summaries of a chat or a memory: the messages or posts in it that you can see. Captions and plans: the text you give. The assistants: your request, your interests, language and upcoming events, and what their tools find for you.

We keep a log of each request (the feature, when, whether it worked) without its content for 90 days, and keep translations so they aren’t made twice. [Confirm Anthropic’s retention and model-training terms for your account.] If automatic captions are turned on, the sound of the video goes to a speech-to-text provider ([Speech-to-text provider]).

3. Who we share it with

  • Other people, according to the audience you choose. Public content from public accounts of people 18 and over can be seen without an account, in link previews and in search engines. Content from people under 18 never is.
  • Apps you connect with “Sign in with YAPILAPI” can act for you within what you allowed (read, or read and write), but never reach your security settings, data download, payouts, privacy choices or assistant memory. Mini apps you open in a chat, community or event get a code that identifies you only to that app and, if they asked for it, your username, name and photo, and the names of the people in the chat. You can remove connected apps in Settings.
  • If you have a developer app, notifications about your own account (new followers, replies to your events, paid orders, your new posts) can be sent to the web address you set.
  • Companies that help us run YAPILAPI, only to do that work and under contract:
    • Hosting, database, cache and file storage: [Hosting providers].
    • An email delivery service, to send our emails: [Email provider].
    • Stripe and Paystack, for payments.
    • Twilio, to send phone confirmation codes.
    • Amazon Web Services (Rekognition), to check photos and frames of videos for nudity and violence, when turned on.
    • Anthropic, for the AI features described above.
    • A speech-to-text provider for automatic captions, when turned on: [Speech-to-text provider].
    • Expo, Apple and Google, to deliver notifications to phones, and your browser’s push service on the web. A notification carries a short line, such as a person’s name and what happened, not the content of your messages.
    • Our network provider, which handles traffic to YAPILAPI and tells us the country each request comes from: [CDN provider]. If we turn on performance tracing, technical records of requests (which can include IP addresses) go to [Tracing provider].
  • Some companies are contacted by your device directly and see your IP address: Jamendo or a music licensing partner, when you play a song from their catalogue (nothing loads before you press play); Google’s servers, which help calls connect (STUN); Stripe, whose payment form loads at checkout; and the developer of a mini app you open. The website’s fonts are served by YAPILAPI itself, not by Google.
  • Authorities, when the law requires it or to protect someone from serious harm, and specialised organisations when we find child sexual abuse material.
  • A buyer or successor, if YAPILAPI is sold or reorganised, under this policy.

4. Where it is stored

Our servers are in [Server region]. Some of the companies above process information in other countries, including the United States. Where the law requires it, we use safeguards such as the European Commission’s standard contractual clauses. [Transfer safeguards to be confirmed by counsel.]

5. How long we keep it

  • Your account and content: until you delete them or your account.
  • When you delete a post, story, comment, question, message or recap, it disappears right away and is erased for good, with its photos and videos, 30 days later. Content removed by our moderators is kept for 180 days first, for appeals and legal requests.
  • When you delete your account: your profile (name, photo, cover, bio, links, pronouns, city, country, colours and layout, featured and pinned posts, profile song and “Now” status), posts, reels, stories, comments, the messages you sent and the ones scheduled to send, questions you asked and received, weekly wraps, your photos, videos and voice notes (with every size and streaming copy made of them), live recordings, recap videos, connections, circles, interests, assistant memory, username history, the devices remembered for sign-in alerts, notification tokens and passkeys are removed right away, your account type and language go back to the defaults, and you are signed out everywhere. Backups are replaced within 30 days. Files of digital products you sold are kept so buyers can still download what they paid for. [Owner to confirm how long.]
  • A daily clean-up deletes, after these periods:
    • Sessions that expired or were signed out: 30 days.
    • Security events (sign-ins, failed sign-ins, password and two-step changes) with their IP address and device: 12 months.
    • Activity events (see “How you use YAPILAPI”): 13 months. The minutes you use YAPILAPI each day: 13 months.
    • Notifications: 12 months. Phone number checks: 90 days. The log of AI requests: 90 days.
    • Feed activity (what was on your screen, watched, finished, skipped or shared): 90 days. The order of a feed you are scrolling: 1 day.
    • AI summaries and suggested replies: 7 days.
    • Email and password reset links, sign-in challenges, download links and unfinished uploads: 7 days after they are used or expire.
    • View-once photos and videos that were never sent: 24 hours. The raw recording of a live on our video server: 2 days after it ends.
    • Our record of actions taken on accounts, money and moderation (the audit log): 2 years.
    • Records of payments, refunds, payouts, tips and paid subscriptions that ended: 7 years, for tax and accounting law. [Owner to confirm the period with an accountant for each launch country.] A download you bought stays in your purchases while your account and the product exist.
    • Reports, moderation decisions, appeals and the actions taken: 2 years after the case is closed, and for as long as an account stays suspended because of them.
    • Call history: 12 months. Games in chats: 12 months after they end. Watch together sessions: 90 days after they end.
    • Event tickets, and who gave a ticket to whom: 12 months after the event ended or was cancelled. The door’s log of scans and typed codes at an event: 90 days.
    • Market listings: 180 days after they end without being renewed, 12 months after they are sold, and 30 days after you delete them (180 days when our team removed them). Ratings stay while both accounts exist.
    • An earlier username: 30 days after the 14 days it is held for you end.
    • The devices remembered for sign-in alerts and the devices you signed in on: 13 months after they were last used.
    • Visits to business pages, the times you opened Pulse, who viewed a post or reel (the view count stays), and ad views and clicks: 13 months. When you hide an ad, that choice stays.
  • Your feed choices (“Show more”, “Show less”, muted topics and people) stay until you change them or delete your account. The law or people’s safety can require us to keep something longer, for example when it is evidence in an investigation.
  • Stories disappear from view after 24 hours (or the time you chose) and stay in your archive, visible only to you, until you delete them.

6. Your choices and rights

  • See and download your data: Settings, then “Download my data”, gives you a file with the information linked to your account: your account and profile, what you created and the messages you sent, your connections, purchases and sales, settings, and security records. Who asked you a question without their name shown stays out of it. If you need something that isn’t in it, write to [privacy email address].
  • Correct it: edit your profile and settings at any time.
  • Delete it: delete posts, questions and messages one by one, or your whole account in Settings (on the web: Privacy, then Delete my account; in the app: Your data, then Delete account).
  • Choose: who sees each post, a private account, who can message, comment on, mention or tag you, whether people with your email can find you, ads (off unless you turn them on), assistant memory (off unless you turn it on), personalization and analytics (on unless you turn them off, in Settings, Privacy), the AI helpers, the weekly wrap, sign-in alert emails, notifications and quiet hours, and hidden words.
  • Object, restrict, or withdraw consent, and complain to your data protection authority. Write to [privacy email address]; we answer within one month.

7. Children and teens

YAPILAPI is not for children under 13. We ask everyone’s date of birth when they sign up and don’t create an account for anyone under 13. If an existing account gives a date of birth under 13, it is closed straight away. If we learn in another way that someone under 13 has an account, we delete it; if you think this has happened, write to [safety email address]. Accounts of people under 18 get extra protections, described in Safety and minors, and people under 18 can’t sell, get paid or receive tips.

8. Security

We protect your information with encryption in transit (HTTPS), scrambled passwords, sessions that can be signed out from anywhere, two-step verification and passkeys, alerts when your account is signed in from a new device, limits on repeated attempts, and access to personal information only for the people at YAPILAPI who need it, with a record of what they do. No system is perfectly secure; if a breach puts you at risk, we tell you and the authorities as the law requires.

9. Cookies

The website uses one cookie, to keep you signed in. See the Cookie notice.

10. Changes

We update this policy when what we collect or how we use it changes, and tell you in the app or by email before an important change takes effect.

11. Contact

[Company legal name], [Registered address]. Privacy questions and requests: [privacy email address]. [Data protection officer and EU or UK representative, if required.]

Terms of service · Privacy policy · Community guidelines · Cookie notice · Legal and policies · © 2026 YAPILAPI