Table of Contents
- 1. WHO WE ARE AND HOW TO REACH US
- 2. WHAT THIS POLICY COVERS
- 3. THE SHORT VERSION
- 4. AT A GLANCE
- 5. GUIDE MODE AND BUTTERFLY MODE: HOW THE TWO SIDES OF YOUR ACCOUNT RELATE
- 6. CATEGORIES OF PERSONAL INFORMATION WE COLLECT
- 7. SENSITIVE PERSONAL INFORMATION
- 8. WE DO NOT SELL YOUR PERSONAL INFORMATION AND WE DO NOT SHARE IT FOR ADVERTISING
- 9. WHY WE ARE ALLOWED TO USE YOUR INFORMATION
- 10. HOW LONG WE KEEP THINGS
- 11. AUTOMATED AND AI FEATURES, AND WHAT THEY CANNOT DO
- 12. VOICE FEATURES AND THE MICROPHONE
- 13. SERVICE PROVIDERS AND OTHER RECIPIENTS
- 14. WHERE YOUR DATA IS PROCESSED: INTERNATIONAL TRANSFERS
- 15. REPORTING, BLOCKING, AND WHAT WE DO ABOUT IT
- 16. THE CONTROLS YOU ACTUALLY HAVE IN THE APP
- 17. DELETING YOUR ACCOUNT, AND WHAT DELETION DOES AND DOES NOT REMOVE
- 18. HOW WE SECURE YOUR INFORMATION - AND WHERE IT IS WEAKER THAN YOU WOULD ASSUME
- 19. RIGHTS-INFRINGING CONTENT AND REMOVAL REQUESTS
- 20. YOUR CALIFORNIA PRIVACY RIGHTS
- 21. YOUR PRIVACY RIGHTS IN OTHER U.S. STATES
- 22. HOW TO SUBMIT A PRIVACY REQUEST
- 23. JAPAN: PURPOSES OF USE AND YOUR RIGHTS UNDER THE APPI
- 24. JAPAN: INFORMATION TRANSMITTED FROM YOUR DEVICE TO OUTSIDE PARTIES
- 25. JAPAN: 18-AND-OVER AND PROHIBITED SOLICITATION
- 26. AGE REQUIREMENT AND MINORS
- 27. APPLE APP STORE PRIVACY LABELS
- 28. CHANGES TO THIS POLICY
- 29. CONTACT
- 30. WHAT WE CORRECTED IN THIS VERSION
Version 3.2.0
Effective September 17, 2026
This version replaces the Privacy Policy dated August 25, 2026 in its entirety.
What changed in 3.2.0: section 6.4 now describes the copies our servers make of the media you upload, and what the app keeps in a cache on your device. Sections 3, 13, 14 and 23 now state correctly where your data is kept: our database is in the United States, the files you upload are stored in Japan, and our backend runs in Taiwan.
What changed in 3.1.0: section 12 now covers direct one-to-one voice and video calls, including that they are neither recorded nor retained, and what we do store about a call. Section 18 has been updated to reflect access rules that have since been tightened.
This policy explains, in plain language, what personal information YoYo collects, why we collect it, who we give it to, how long we keep it, and what you can make us do about it. It covers both sides of the app: Guide Mode, the dating and date-planning side, and Butterfly Mode, the pseudonymous social side.
We have written this document to be read, not skimmed past. Where the honest answer is that something is not deleted, that a protection applies more narrowly than you might assume, that a control is not built yet, or that an automated system is imperfect, we say so instead of making a promise we cannot keep. Several statements in the previous version of this policy were wrong. We found them by going back through the code and checking every factual claim against what the software actually does. The corrections are listed in section 30 rather than buried, because you are entitled to know which things we previously told you that were not true.
1. WHO WE ARE AND HOW TO REACH US
YoYo is operated jointly by two affiliated companies, which act as joint controllers of your personal information and are jointly responsible for the practices described here:
YoYo LLC (United States)
453 S Spring St STE 400, PMB 1290
Los Angeles, CA 90013, United States
YoYo KK, Ltd. (Japan)
566 Tensho Office Hamamatsucho Daimon, Eagle Hamamatsucho
2-7-17 Hamamatsucho, Minato-ku, Tokyo 105-0013, Japan
For every purpose in this policy - privacy rights requests, requests for a copy of your data, questions about this policy, complaints, reports of objectionable content or abusive users, requests to remove content that infringes your rights, and requests to delete your account from outside the app - the single published contact address is:
support@yoyodatingapp.com
We accept correspondence at that address in English and in Japanese. Japanese-language complaints and requests are handled by YoYo KK, Ltd. in Japanese. You may also write to either postal address above. We aim to acknowledge every message within 3 business days, and we respond to reports of objectionable content and abusive users on the timeline described in section 15.
YoYo KK, Ltd. is the personal information handling business operator for users in Japan for the purposes of the Act on the Protection of Personal Information, and the Tokyo address above is its registered office. The name of its representative director is recorded in the company's entry in the Japanese commercial register; if you write to support@yoyodatingapp.com and ask for it, we will tell you without delay.
2. WHAT THIS POLICY COVERS
This policy applies to the YoYo mobile application on iOS and Android, to the backend services that support it, and to the correspondence you send us at the contact address above. YoYo is available in Japan and the United States and is offered in English, Japanese and Chinese.
YoYo is for adults aged 18 and over only. See section 26.
This policy does not apply to third-party services you reach through YoYo. When you tap through to a venue's own website or booking page, that venue and its website operator handle your information under their own policies, not this one. The same is true when we submit a booking to a venue at your request, which section 13 describes.
There is no advertising in YoYo, no advertising SDK, and no analytics or attribution SDK other than Google Analytics for Firebase, which we use to understand how the app itself is performing. There is no payment processing in the app today: YoYo does not collect, receive or store card numbers, bank details or any other payment credentials, we do not use any payment processor, and there are no in-app purchases or subscriptions in either mode.
3. THE SHORT VERSION
If you read nothing else, read this. Every line here is expanded on later, and every line is something we checked against the code rather than assumed.
- We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We have not done either in the preceding twelve months. There is no ad network, tracking SDK, attribution SDK or data broker anywhere in this app.
- We do not track you across other companies' apps and websites, so we do not show the App Tracking Transparency prompt.
- We do not record the audio of voice matches or party rooms. That audio is carried live by Agora and never reaches our servers.
- Your profiles, messages and the rest of your account data are stored in the United States, including for users in Japan, because that is where our database is. The photos, videos and identity documents you upload are stored in Japan, and our backend runs in Taiwan. Section 14 explains exactly what that means and who receives it.
- If you grant location permission, your precise coordinates are stored on your account record, and any signed-in YoYo user's copy of the app can read that record. So can your date of birth, your phone number and your email address. Section 18 explains this properly. It is the single most important thing in this document about how your data is protected, and it is not as tight as you would probably assume.
- We also keep a GPS history log - a dated list of coordinates - separately from your current location. The previous version of this policy said we did not. It was wrong. See 6.6.
- Text you write is sent to OpenAI for automated moderation. That includes posts, comments, party room titles, profile text and the chat messages you send in both modes. The previous version of this policy said comments and room titles were not sent. It was wrong. See 6.16 and section 11.
- Butterfly Mode is pseudonymous toward other users. It is not anonymous toward us. Your Butterfly profile is stored under the same account identifier as your dating profile, so we can connect the two. We say so plainly in section 5 rather than letting you assume otherwise.
- If you ask us to make a restaurant booking, your name, phone number, email address and any dietary or allergy note go to Browser Use, Inc., the company that runs the automated booking browser for us, and then to the venue, which is an independent business. Section 13 sets it out.
- Some events send an email to YoYo staff through a company called Resend. An ID verification submission sends your name, your account email address and your account identifier. A failed booking sends your name and your account email. The previous version of this policy did not mention Resend at all. See 6.24.
- We collect crash diagnostics that include your account identifier, the screen you were on, and a trail of your last few actions in the app. Today this record is not deleted when you delete your account. We are telling you that instead of hiding it. See 6.20 and 17.
- There is no "download my data" button in the app. Email us and we will produce your data by hand. See section 22.
- There is no in-app switch to turn off product analytics. It is on for everyone. See 6.19.
- You can delete your account from inside the app, from either mode, and deletion covers both Guide Mode and Butterfly Mode and is genuinely thorough. Section 17 lists exactly what it removes, the safety records it deliberately does not, and the one record it misses.
4. AT A GLANCE
This is the summary table. It is short by design; section 6 is the complete version, category by category. "Kept until you delete your account" means there is no automatic expiry - the information sits there for as long as you have an account.
LOGIN AND ACCOUNT
What: email address, name, sign-in identifier, sign-in provider, date of birth.
Why: to make and secure your account, and to enforce the 18+ rule.
Kept: until you delete your account.
Who else sees it: Google (Firebase), Apple if you use Sign in with Apple.
DATING PROFILE
What: photos, bio, gender, preferences, height, job, school, habits, interests.
Why: to show your profile and to run matching.
Kept: until you clear the field or delete your account.
Who else sees it: other YoYo users, OpenAI (text and photos, for moderation).
PRECISE LOCATION
What: your GPS coordinates, plus city and country worked out from them, plus a dated history log of past coordinates.
Why: nearby venues, map results, distance in matching, country pool.
Kept: current position is overwritten; the history log is kept until you delete your account.
Who else sees it: Google Maps and Places, Apple's geocoder, and - for your current coordinates - any signed-in YoYo user's app, which uses them to compute distance.
MESSAGES AND POSTS
What: the full text of your chats, posts, comments, room chat and Board posts, plus images and video.
Why: to deliver and publish what you write.
Kept: until you delete them or delete your account. Party room chat is purged one hour after the room closes.
Who else sees it: the people you sent them to, OpenAI (text and post images, for moderation), Expo (the first 40 characters of a Guide Mode message, inside the push notification).
BUTTERFLY PROFILE
What: handle, avatar, planet, interest tags, and your five-answer quiz result stored as five numbers.
Why: to give you a pseudonymous presence and to match you.
Kept: until you delete your account.
Who else sees it: other Butterfly users see handle, avatar, planet and tags. OpenAI sees tags and planet when you ask for icebreakers.
GOVERNMENT ID
What: the photo of the ID you upload, the type, and the review decision.
Why: optional verification, which unlocks accepting invitations, Quick Date and hosting rooms.
Kept: the record until you delete your account. The image itself has no automatic purge - ask us and we will delete it.
Who else sees it: the YoYo staff member who reviews it. An email goes to staff saying you submitted one, with your name, email and account identifier - but never the image.
BOOKINGS
What: booking name, phone, email, party size, date, time, and any dietary or allergy note.
Why: to make the reservation you asked for.
Kept: until you delete your account.
Who else sees it: Browser Use Inc., the venue itself, and - if the robot fails - a YoYo staff member who reads it and telephones the venue.
VOICE
What: channel identifiers, seat and room state, who was in the room, timestamps. Not the audio.
Why: to connect the call and to moderate rooms.
Kept: room chat and membership are purged 1 hour after the room closes; voice match records 60 minutes after the call.
Who else sees it: Agora, which carries the live audio between participants and does not store it for us.
CRASHES AND DIAGNOSTICS
What: device model, OS version, app version, the screen you were on, your account identifier, a session identifier, and a breadcrumb trail of your recent actions.
Why: to find and fix bugs.
Kept: indefinitely. This one is not currently deleted when you delete your account. See 6.20.
Who else sees it: Google (Firebase), and Resend plus YoYo staff for the summary alert email.
SAFETY RECORDS
What: reports you file and reports about you, blocks, moderation decisions - including, for an automatically redacted message, up to the first 1500 characters of what was written.
Why: to keep people safe and to stop banned users coming back.
Kept: after your account is deleted. Deliberately. See 6.23 and 17.
Who else sees it: YoYo moderators, and law enforcement where legally required.
5. GUIDE MODE AND BUTTERFLY MODE: HOW THE TWO SIDES OF YOUR ACCOUNT RELATE
This is the most important thing to understand about privacy in YoYo, so we are putting it near the top.
Guide Mode is the dating side. It uses a real profile: your name, your photos, your age, and the profile attributes you choose to fill in.
Butterfly Mode is the pseudonymous side. It uses an automatically generated handle in the form of an adjective, a noun and two digits, one of sixteen supplied illustrated avatars, a five-question personality quiz result, an assigned planet, and three to eight interest tags. Butterfly Mode contains no photographs of you and no real name.
Toward other users, these two identities are kept apart, and we have built that separation deliberately rather than relying on people not looking. Your Butterfly Mode profile is stored as a separate record from your Guide Mode dating profile. It carries no photograph, no real name and no pointer to your dating profile. No feature in the app joins them. There is no cross-mode reveal and no "find this person's dating profile" function. The two chat systems share no storage at all. Butterfly Mode chats and Guide Mode chats never appear in each other's lists. Your like history is readable only by you. Your follow list can only be queried as your own. Another user cannot use YoYo to work out which Guide Mode profile belongs to which Butterfly Mode handle.
Anonymous posts are held to the same standard, and more carefully than you might expect. When you publish in the Square without a visible author, the post document does not contain a hidden author field that a determined person could read - the field is not there at all. The true author is recorded in a separate private record attached to the post which no user, including you, can read from the app under any circumstances. The rules require that private record to be written before the post exists, so the two cannot be raced apart. And when someone reports an anonymous post, the report itself is unreadable by every client, precisely because the report resolves the true author. Reporting an anonymous post cannot be used to unmask its writer.
We should be precise about what the separation is and is not. It is a separation of content and of what other users can reach. It is not a claim that the Butterfly Mode profile record is hidden. Like any social profile, it is visible to other signed-in Butterfly Mode users who you have not blocked - that is what makes it a social profile.
Toward us, they are the same account, and we want to state the mechanism rather than the reassurance. Your Butterfly profile is stored under the same account identifier as your dating profile. One privileged read on our side joins a Butterfly handle to a real name, a photograph, a date of birth, a phone number and a set of coordinates. Blocks and reports are keyed by that same identifier across both modes. One push token on your account serves both modes. Your Butterfly country is copied from the country worked out from your Guide Mode location. Your starting Butterfly interest tags are seeded from your Guide Mode interests. And hosting a Butterfly party room requires the verified status you earn by submitting a government ID in Guide Mode.
We do this for safety, security, abuse prevention, enforcement of our Terms, and compliance with law. We are telling you plainly because the alternative - implying that Butterfly Mode is anonymous to YoYo as well as to other users - would be untrue. Anonymity in YoYo means pseudonymity toward other users. It does not mean invisibility to us.
Blocking, honestly described. The two modes give you different tools, and they do not connect. Butterfly Mode has a full block: it takes effect immediately, works in both directions, is enforced by our servers rather than by the app, and covers the Square, comments, Butterfly profiles, Butterfly matching, Butterfly chat and Butterfly voice. Guide Mode has no equivalent. What it has is Hide User, which takes that person out of your match deck; Unmatch, which ends the match, deletes the conversation and removes each of you from the other's deck; and Report User, which sends the account to our safety team.
Two specific things follow from that, and neither is obvious. First, nothing you do in one mode carries across to the other. Blocking someone in Butterfly Mode does not hide them from your Guide Mode deck, and hiding someone in Guide Mode does not block them in Butterfly Mode. If someone is bothering you in both places you have to act in both places. Second, Guide Mode's Hide User is one-way: the app adds a person to your hidden list and there is no screen anywhere that takes them off it again. If you hide someone by accident, write to us and we will remove them for you.
Reporting is genuinely shared: a report filed in either mode goes to the same queue and the same review team. A direct block control for Guide Mode, and an unhide control, are on our list, and we will update this policy when they ship.
6. CATEGORIES OF PERSONAL INFORMATION WE COLLECT
For each category we state what it is, where it comes from, why we use it, who receives it, and how long we keep it or the criteria we use to decide. Unless a shorter period is stated, information tied to your account is kept for as long as your account exists and is then handled as described in section 17.
Where we say a category is "disclosed to Firebase", we mean that it is stored in or processed by Google's Firebase platform (Authentication, Cloud Firestore, Cloud Storage, Cloud Functions, Analytics, Cloud Messaging, App Check and Remote Config) acting as our service provider under contract. Firebase underlies essentially all storage in YoYo, so it is a recipient of every category below and we do not repeat it each time.
6.1 Account and identity data
What: your email address, your first and last name, the account identifier issued when you sign up, the sign-in method you used (Apple, Google or email and password), and, if you sign in with Apple, the Apple user identifier and the email address Apple provides, which may be a private relay address if you chose to hide your email.
Source: you, and Apple or Google if you use their sign-in.
Why: to create and secure your account, to authenticate you, to contact you about your account and about safety matters, and to respond to your requests.
Disclosed to: Firebase Authentication; Apple or Google, for the sign-in you chose; OpenAI, which receives free profile text you write so that an automated model can screen it, as described in 6.16; Resend and YoYo staff, in the specific alert emails described in 6.24.
Retention: until you delete your account. Then handled under section 17.
Note: your account record is readable by any signed-in YoYo user. Section 18 explains why and what that means.
6.2 Date of birth and age
What: your date of birth, entered at sign-up, and the age derived from it.
Source: you.
Why: to enforce the 18-and-over requirement, to display your age on your Guide Mode profile, and to apply age-based matching preferences.
Disclosed to: nobody outside our service providers, but see the note below. Your age, not your date of birth, is what is displayed to other users on your profile.
Retention: until you delete your account.
Note: your date of birth sits on your account record, which any signed-in YoYo user's app can read. The interface never shows it to them, but the data is reachable. See section 18.
6.3 Guide Mode dating profile attributes
What: the fields you choose to complete, which may include gender, the gender or genders you want to be matched with, your preferred age range, height, occupation, school, workplace, education level, smoking, drinking and dietary preferences, interests, preferred date types, and your free-text profile bio.
Source: you. Gender, the gender you want to be matched with, and your age range are the fields matching runs on, and Guide Mode cannot work without them. Everything else beyond what is needed to create an account is optional, and you can edit or clear it at any time from your profile.
Why: to display your profile to other users and to power matching, which scores candidates on distance, shared saved venues, shared interests, recent activity and profile completeness.
Disclosed to: other YoYo users, to the extent the field appears on your profile; OpenAI, which receives your free profile text so that an automated model can screen it, as described in 6.16. Not disclosed to any third party for that party's own purposes.
Retention: until you clear the field or delete your account. Cleared fields are overwritten, not archived.
Note: some of these fields are sensitive personal information. See section 7. Your dietary preference in particular travels further than the rest - see 6.11.
6.4 Photos and video
What: your Guide Mode profile photographs, and any images and videos you post, comment with or send in chat. Butterfly Mode posts take up to four images per post, or one video, currently capped at one hour.
Source: you, from your device camera or photo library. We ask for photo library and camera permission for this purpose only. We do not read your photo library beyond the items you select.
Why: to display your profile, to publish the content you choose to publish, and to deliver the messages you choose to send.
Disclosed to: other YoYo users, as determined by where you put the photo; OpenAI, which receives your Guide Mode profile photographs when you upload them and the images you post in the Square, together with the generated poster frame of a video you post, so that an automated moderation model can screen them. Images you send inside a chat are not sent to OpenAI and are not machine-screened.
How the image actually reaches OpenAI, because it matters: we do not upload the file to OpenAI. We hand OpenAI a link to the file in our storage, and OpenAI's servers fetch it themselves. The link contains an access token, which means it works without being signed in to YoYo. Anyone who obtains that link string can retrieve the image. We treat those links as secrets and do not publish them, but you should know that is the mechanism.
Photo copies our servers make: so that pictures load quickly, our backend functions make a copy of each of your Guide Mode profile photographs and of each image in your Butterfly Mode posts, no larger than 640 pixels on its longest side, and the app shows that copy where a picture is displayed small, such as in chat lists, avatars and post grids. While a full-size picture is loading, the app may briefly show the copy in its place. Location and device details embedded in the file, such as where and on which phone the picture was taken, are removed from the copy. Your original file is kept unchanged and is still shown where a picture is displayed full size, and wherever a copy could not be made.
Videos shrunk on your device: before a Butterfly Mode video is uploaded, the app makes a copy of it on your device, no larger than 1920 pixels on its longest side, with HDR video converted to standard dynamic range and location and device details removed. That copy is the file we upload and store; the video as you recorded it stays on your device. If the app cannot make the copy, the video is uploaded as recorded. The upload starts as soon as you choose a video, before you post it; if you remove the video or do not post it, it is deleted from our storage automatically, normally within two days.
Video copies our servers make: for a Butterfly Mode video of 120 seconds or less, our backend functions make a copy for playback, no larger than 1920 pixels on its longest side and no higher than 5 megabits per second, with HDR video converted to standard dynamic range, together with a copy of the video's poster frame no larger than 1280 pixels on its longest side. The post is then played from that copy. Location and device details embedded in the file are removed from the copy. The file you uploaded is kept unchanged in our storage. Longer videos, videos that already meet these limits, and any video we cannot convert, are played from the file you uploaded.
Where the copies are made and kept: the copies are made in Taiwan and stored beside the originals in Japan, as section 14 explains. Each copy is deleted together with the file it was made from, including when your account is deleted, as section 17 explains.
What the app keeps on your device: so that the same video is not downloaded twice, the app keeps videos you have played, and videos it has begun loading ahead of time, in a cache on your device of up to 1 GB, removing the least recently used first. When you sign out, the app clears this video cache. If clearing fails, for example because a video is still open, the cached videos stay on your device until the cache removes them to make room for newer ones or you delete the app. Photos the app has shown or loaded ahead of time are also kept in the app's image cache on your device; the app does not clear that cache when you sign out, and it is removed when you delete the app. The illustrated Butterfly Mode avatars are built into the app or downloaded ahead of time; they are artwork we provide, not photographs of anyone.
Retention: profile photos are kept until you replace or remove them or your account is deleted. Posted content is kept as described in 6.13. Chat images are kept as described in 6.15. Orphaned Butterfly media files are swept from storage every six hours once they are more than a day old.
6.5 Precise location
What: your device's coordinates - latitude, longitude and an accuracy figure - when you grant location permission, plus the city and country name worked out from them.
Source: your device, with your permission. You can refuse or later withdraw location permission in your device settings; distance-based features degrade or stop working if you do.
Why: precise location is used to find venues near you, to show venue results on the map, and to calculate the distance component of matching. City and country are used to determine which country pool you match in, including Butterfly Mode, which matches only within your own country.
Where it is captured: only while the app is open and on screen. YoYo requests foreground location permission only. We do not ask for and cannot receive background location, and the app is not configured to collect location while it is closed or in the background.
Disclosed to: Google Maps and Google Places, which receive your coordinates and search terms directly from your device in order to return venue results; Apple, whose on-device geocoding service receives your raw coordinates in order to return the city and country name; and other users, in a way you should understand before you grant the permission.
That last point, in full. Your most recent coordinates are stored on your account record. Any signed-in YoYo user's copy of the app can read that record, and that is how the distance to you is calculated - on their device, from your coordinates. We do not show anyone a map pin of you, an address, or a number of degrees latitude in the interface. But the data is there to be read, including by someone you have not matched with. If you do not want that, turn location off for YoYo in your device settings. Nearby ranking and nearby venue suggestions stop working; the rest of the app continues.
Retention: your current location is a single value that is overwritten each time it updates. See 6.6 for the separate history log.
Note: precise geolocation is sensitive personal information. See section 7.
6.6 Location history log
What: a separate, dated log of past coordinates. Each entry holds your account identifier, a timestamp, the coordinates as a geographic point, the accuracy figure, your platform, and app and SDK version numbers.
Source: your device. This log is written when the app performs a forced location refresh, which happens on iOS.
Why: it was built as an operational record of location updates. In practice nothing in the app reads it back. We are keeping the disclosure rather than the justification, because the honest position is that this log exists and is written, not that it earns its place.
Disclosed to: Firebase. No client can read this log back, and your app can only add entries for your own account.
Retention: there is no automatic expiry. Entries accumulate for as long as your account exists, and are deleted when you delete your account.
Correction: the previous version of this policy stated that we do not build or keep a location history trail. That was wrong. This is that trail.
Note: precise geolocation is sensitive personal information. See section 7.
6.7 Phone number
What: a phone number and the country code you selected with it.
Source: you.
Why: to complete restaurant bookings on your behalf, and - through the country code - as one of the signals used to decide which market you start in.
Disclosed to: Browser Use, Inc. and the venue, when you ask for a booking; the YoYo staff member who completes a booking by hand when the robot fails.
Retention: until you remove it or delete your account.
Note: your phone number sits on your account record, which any signed-in YoYo user's app can read. See section 18.
6.8 Push notification tokens and settings
What: the push token issued to your app installation - an Expo push token, which Expo maps on to Firebase Cloud Messaging on Android and the Apple Push Notification service on iOS - together with the date it was last updated, your device platform, and your notification on/off setting.
Source: your device and the platform.
Why: to deliver notifications you have asked for.
Disclosed to: Expo, Inc., whose push service we send notifications through, and then Google (FCM) and Apple (APNs) for final delivery.
What travels inside the notification: in Guide Mode, a new-message push carries the first 40 characters of the actual message text in its body, so that you can see what arrived without opening the app. That preview passes through Expo and through Apple's or Google's push service on its way to you. Butterfly Mode pushes do not carry message text at all - they carry a handle and a fixed phrase.
Retention: tokens are refreshed and replaced by the platform, and are removed when they become invalid or when your account is deleted. We also keep a delivery receipt for each push, recording your account identifier, the ticket identifier, the delivery status and a short fragment of the token, so that we can tell when a token has gone stale. Those receipts are deleted with your account.
6.9 Consent records
What: whether you accepted the Terms of Service, this Privacy Policy and the Cookie Policy, when, and which version; and whether you have viewed the FAQ.
Source: you, when you accept.
Why: to demonstrate that you agreed, and to know when to ask you again after a material change.
Disclosed to: nobody outside our service providers.
Retention: until you delete your account.
6.10 Reservations and reservation attempts
What: a record of each booking and each booking attempt: the venue including its name, address, phone, website and place identifier, the date, time and party size, the name, phone number and email submitted, which time slots were tried, the status and the outcome.
Source: generated when you use YoYo Reservations.
Why: to make the booking, to tell you whether it succeeded, and to investigate failures and disputes.
Disclosed to: Browser Use, Inc., which runs the automated browser; the venue and its booking platform, as described in 6.11 and section 13; and Resend plus YoYo staff, in the alert email described in 6.24 when a booking fails.
Retention: kept while your account exists so that you and we can look up past bookings, and deleted with your account. Where a booking sits in another user's records because you were going together, we remove your identifier from their copy and keep the booking itself, so their record does not break.
6.11 The manual booking queue, and the human who reads it
What: when the automated browser cannot complete a venue's booking form, the attempt goes into a queue that a person works through. The queue entry holds the plan and account identifiers, why the robot stopped, the last page it reached, the venue details, the reservation date, time and party size, the slots already tried, a summary of what the agent did, and a customer block containing your name, your phone number, your email address and your special requests - which is your saved dietary preference, verbatim.
Source: generated from your profile and your booking request.
Why: so that a member of the YoYo team can finish the booking by hand, including by telephoning the venue.
Disclosed to: the YoYo staff member who works the queue. We are stating this in its own category rather than in a footnote because a person reading your name, phone number, email address and dietary notes is a materially different thing from a machine processing them.
Retention: kept while the booking is live. When you delete your account, a queue entry that has already been completed or cancelled is deleted outright; an entry still in progress is cancelled, your identifier is removed, and the customer block is overwritten with a placeholder rather than left in place.
Note: dietary and allergy information can reveal health or religious information. It is sensitive. See section 7.
6.12 YoYo Calendar and device calendar access
What: the date events YoYo creates for you when a plan or reservation is confirmed, the events you create yourself in the YoYo calendar, and a single stored flag recording whether you turned on device calendar sync. Each stored event holds a title, start and end times, an all-day flag, where it came from, the plan or reservation it refers to, the matched user if there is one, the venue and any note.
Source: you, and YoYo's own booking flow.
Important, and it runs in two directions. Reading: if you turn on calendar sync, YoYo reads events from your device calendar on the device, for display only, in a rolling three-month window. Those device calendar events are not uploaded to our servers today and are not stored by us; only the on/off flag is stored. We have a server function capable of importing them, but nothing in the app calls it, and if that changes we will update this policy first. Writing: when a date invitation is accepted, YoYo writes that date into your device calendar as an event named after the venue, with the venue address as the location. That write happens whenever you have granted calendar permission, not only when the sync switch is on, and it goes into your default writable calendar - so if that calendar is shared with anyone, they can see the entry. You can turn sync off in the app, revoke calendar permission in your device settings, and delete or edit the written event yourself.
Disclosed to: your matched partner, for events you share with them.
Retention: YoYo calendar events are kept until you delete them or delete your account. When you delete your account we also remove the matching entry from your date partner's calendar, so they are not left with a plan pointing at nobody.
6.13 Butterfly Mode pseudonymous profile
What: your generated handle, which cannot be changed after it is created; your chosen avatar, which is one of sixteen supplied illustrations; your five-question quiz answers, stored as five numbers each between 0 and 3; the version of the quiz you took; your assigned planet; your three to eight interest tags; your country; your last-active timestamp; and server-maintained counters for followers, following, unread notifications and inactivity.
Source: generated for you, plus the quiz answers and tags you choose. Your country is copied once from the country worked out from your Guide Mode location. Your first set of tags is seeded once from your Guide Mode interests. Neither of those copies runs again afterwards.
Why: to give you a pseudonymous presence, to power same-country matching and the drifting candidate field, and to run the inactivity flag.
Disclosed to: other Butterfly Mode users, in the form of your handle, avatar, planet and tags; OpenAI, where your tags and planet are used to generate icebreaker suggestions (see 6.16).
Retention: until you delete your account. You can change your avatar, planet and tags at any time, and retake the quiz once every seven days. The handle is permanent.
Inactivity: if you do not use Butterfly Mode for a set number of days, your profile is flagged as dusty. That flag makes you eligible to be dust-wiped by other users; it does not delete anything.
6.14 The private authorship record for anonymous posts
What: the account identifier of the true author of a post published without a visible author, stored in a private record attached to the post.
Source: generated when you publish anonymously.
Why: moderation, enforcement of our Terms, letting you delete your own anonymous post, erasing your anonymous posts when you delete your account, investigating reports, and responding to valid legal process.
Disclosed to: nobody. No user can read it, and the rules deny that read to every client without exception. It is accessible only to authorized YoYo personnel and, where legally required, to a court or authority acting under valid process.
Retention: for as long as the post exists. When you delete your account, this record is what we use to find your anonymous posts and erase them.
6.15 Posts, comments, likes, follows, and chat messages
What: your text posts of up to 500 characters with up to four images or one video; comments of up to 300 characters; likes; your follow graph; party room chat of up to 200 characters; and your private messages of up to 2000 characters in both modes, including text and any images, plus sender, recipient, timestamps, read state, and a flag marking a message as AI-assisted if you sent a suggested opener unchanged.
Source: you and the people you talk to.
Why: to publish what you choose to publish, to build feeds, to deliver conversations, and to operate moderation.
Disclosed to: the people you sent them to or published them to; OpenAI, which receives the text of your posts, comments, party room chat, party room titles, profile text and private messages in both modes for automated moderation, and the images in your posts and the poster frame of your videos; Expo, for the 40-character Guide Mode message preview described in 6.8.
Retention: content stays up until you delete it, until you delete your account, until we remove it under our Terms, or until it is removed following a report. Party room chat is different - it is purged one hour after the room closes, along with the room's membership, ban and mute lists. Deleting your account removes your posts and comments including the anonymous ones, your likes, your follow relationships in both directions, and your conversations and messages in both modes. A copy of a conversation remains with the other participant, because their copy is also their own record. Copies other users have saved or screenshotted are outside our control. Where content has been the subject of a report, we retain the report as described in 6.23 even after the content is gone.
6.16 AI feature inputs and outputs
What: everything submitted for automated moderation, which is your post text and post images, your comment text, your party room chat text, your party room titles, your profile free text and handle, your Guide Mode profile photographs, the poster frames of videos you post, and the text of the private messages you send in either mode; the messages you send to YoYo Date Coach and its replies; and the interest tags, planets and recent conversation messages used to generate Butterfly Mode icebreaker suggestions.
Source: you, and the content you submit or exchange.
Why: to provide the moderation, coaching and suggestion features.
Disclosed to: OpenAI, which processes this content as our service provider through its commercial API, not a consumer product, in order to return a moderation result, a coaching reply or a set of suggestions. We do not send OpenAI your email address, your date of birth, your identity document, your phone number or your coordinates.
Correction: the previous version of this policy said OpenAI does not receive comments or party room titles. That was wrong. Both are sent, and both have always been sent.
Retention: your YoYo Date Coach sessions are stored in full - your messages, the model's replies, the whole conversation, the model name, the token count, and whether you gave the answer a thumbs up or down. They are kept until you delete your account and are deleted with it. Cached icebreaker suggestions are deleted with the conversation and with your account. Moderation scores and decisions are kept with the moderated item.
Note: a Date Coach transcript is readable only by the person whose transcript it is. No app can create or delete one, and the only part an app can change is the thumbs up or down you give an answer - the conversation itself cannot be altered from a client at all.
6.17 Matchmaking records
What: in Guide Mode, the score computed for a candidate pair from distance, shared saved venues, shared interests, recent activity and profile completeness. In Butterfly Mode, your entry in the match queue - which carries your account identifier, mode, country, quiz vector, tags and timestamps and expires after 60 seconds - your match results, a seven-day cooldown record so you are not shown the same person again immediately, and a daily quota counter.
Also: a permanent, append-only log of every Butterfly pairing, recorded as a pair of account identifiers. It exists so that we can later study which pairings worked, and it is not read by any feature you use.
Source: generated by our systems.
Why: to order candidates, to run daily limits and cooldowns, and to study match quality.
Disclosed to: nobody outside our service providers. Other users see the resulting ordering, never the underlying numbers.
Retention: scores and queue entries are transient. The pairing log is kept until you delete your account, and is deleted with it.
6.18 Identity mapping for Butterfly Mode
What: two internal lookup records that map your account identifier to an internal Butterfly identifier and back again.
Source: generated when your Butterfly profile is created.
Why: so that Butterfly features can refer to you without carrying your account identifier around.
Disclosed to: nobody. Both records are denied to every client in both directions - no app can read or write them. Your Butterfly identifier reaches your own device only as a claim inside your sign-in token.
Retention: deleted when you delete your account.
6.19 Product analytics
What: device model, operating system version, app version, language and region, and event records describing how features are used - a screen opened, a notification tapped, a location refreshed, an account deleted. Many of these events carry your account identifier as a parameter alongside the event, and are also tied to an installation identifier issued by Google.
Source: your device.
Why: to keep the app working, to measure whether features are used, and to detect abuse.
Disclosed to: Google, as our analytics provider. Not disclosed to advertising networks or data brokers, because we do not use any.
There is no opt-out today, and we are not going to pretend otherwise. Analytics collection is switched on unconditionally when the app starts. There is no setting for it, no toggle, and no consent prompt. Turning it off requires a change to the app, which is on our list. Until then, the honest statement is: if you use YoYo, product analytics is on.
Retention: governed by the retention schedule set on our Google Analytics property rather than by anything in the app, and deleting your YoYo account does not reach it. If you want your analytics records deleted, write to us and we will make the request to Google on your behalf.
One specific case worth naming: when you delete your account and choose a reason from the list, that reason is sent to Google Analytics as an event. It is not attached to your name, but it is attached to the analytics identity of your installation. If you would rather not tell us, you can pick nothing meaningful; the deletion proceeds either way.
6.20 Crash and error diagnostics
What: two things. First, error records tied to your account, holding your account identifier, the type of error, the message, the screen, device information and whether it was fatal. Second, a separate crash-signature store, where identical crashes are grouped together and each stored sample holds the time, your account identifier, the screen you were on, the app version and build number, your operating system version, your device model, a session identifier, a trail of your recent actions in the app, and the error message, alongside a list of recent reporters and up to 4000 characters of stack trace.
Source: your device, automatically, when something goes wrong.
Why: to find and fix bugs. We ship this app without direct access to your device, and this pipeline is how we learn that something is broken.
Disclosed to: Firebase; and Resend plus YoYo staff for the summary alert email described in 6.24, which carries the error and the screen rather than the whole sample.
Access: you cannot read this store, and neither can any other user - the rules allow writing and deny reading to everyone, including the person who reported the crash.
Retention, stated plainly because this is the weakest point in our deletion story: the account-tied error records are deleted when you delete your account. The crash-signature store is not. There is no scheduled expiry and no deletion step, so your account identifier, the screens you visited and your breadcrumb trail survive in it after your account is gone. This is an omission on our part, not a decision, and the previous version of this policy did not mention this store at all. We are building the deletion step. In the meantime, if you delete your account and want these records removed as well, write to support@yoyodatingapp.com and we will remove them by hand and confirm that we have.
6.21 Activity and usage logs
What: a log of significant actions you take in the app, each holding your account identifier, the action, a timestamp, some metadata about it, your platform, your operating system version and your device model.
Source: your use of the app.
Why: to debug behaviour, to understand feature flow, and to investigate abuse.
Disclosed to: nobody outside our service providers.
Retention: no automatic expiry; kept until you delete your account, and deleted with it.
6.22 Presence and activity timestamps
What: a last-active timestamp, updated roughly once a minute while Butterfly Mode is open, plus activity timestamps used for the recent-activity component of matching and for the inactivity flag. Inside a party room, your membership record is updated while the app is open, so that the room knows you are still connected.
Source: your use of the app.
Why: to show whether a person is currently around, to rank candidates, and to close abandoned rooms.
Disclosed to: other users, only as coarse presence, never as a raw log.
Retention: presence is a single value that is continuously overwritten; we do not keep a historical presence log. Room membership records are purged one hour after the room closes.
6.23 Reports, blocks and moderation records
What: reports you file and reports filed about you, including the reported item, the reason, the reporter, the reported user, any voice channel or room identifier, the review outcome, and any enforcement action taken; your block lists; automated moderation decisions; and records of content removals, restrictions and account terminations.
Something specific you should know about what a report contains. When our automated moderation redacts a message you sent, it opens a report automatically, and that report's description includes up to the first 1500 characters of the message text itself. So the report does not merely record that something was blocked - it records what was written. Because reports are retained after account deletion, the text of a redacted message can outlive the account of the person who wrote it. "We keep the report" and "we keep what you wrote" are different promises, and the second one is the true one.
Source: you, other users, and our automated moderation.
Why: to investigate and act on reports, to make blocking work, to hide content that has reached three distinct reporters pending review, to detect repeat offenders and ban evasion, to defend ourselves in a dispute, and to comply with legal obligations.
Disclosed to: authorized YoYo moderators; law enforcement or a court where we are legally required to disclose; the counterparty in a dispute only to the extent necessary. Reports are unreadable by every client, without exception, because a Butterfly report resolves the true author of an anonymous post.
Retention: this is the category we deliberately keep after account deletion, and we want to be exact about why. Reports are retained in both directions and flagged to show that the account concerned has been deleted, so a moderator can tell a departed account from a live one. Blocks placed against a deleted account are retained too, so that they keep protecting the person who placed them; blocks that a departing user placed on others are deleted. Bans and mutes you collected in other people's rooms stay with those rooms. We do this because deletion would otherwise be a way to erase the record of what you were reported for, or to shed a ban by deleting and re-registering. The legal basis is explicit: section 1798.105(d) of the California Consumer Privacy Act permits us to retain personal information needed to detect security incidents and to protect against malicious, deceptive, fraudulent or illegal activity, and the Act on the Protection of Personal Information permits retention necessary to protect the life, body or property of a person. Reports that resulted in no action are retained for a shorter period sufficient to identify patterns of repeat reporting.
6.24 Staff alert emails
What: when certain things happen, our backend sends an email to a small list of YoYo staff addresses through Resend, an email delivery company. Two of those emails carry your personal information:
- When you submit a government ID for verification, the email states your name, your account email address, your account identifier, the identifier of the verification record, and the time. The ID image itself is deliberately never attached or linked.
- When a booking fails and needs a person, the email states your name, your account email address, your account identifier, the venue and the requested slot. Your phone number is deliberately left out of the email; the staff member opens the queue entry to get it.
A third alert reports a new crash signature and carries the error and the screen rather than your identity.
Source: generated by our backend from your account record.
Why: government ID review and failed bookings both need a person, promptly, and email is how that person finds out.
Disclosed to: Resend, Inc., which transmits the message; and the YoYo staff mailboxes on the recipient list, which currently sit on the yoyodatingapp.com and yoyodatingapp.jp domains. The recipient list is configurable by us without shipping a new app version.
Retention: an email, once sent, sits in Resend's delivery logs and in the recipients' mailboxes. Deleting your account does not reach either. If you want a specific alert email deleted from our mailboxes, write to us and we will delete it.
Correction: the previous version of this policy did not mention Resend or these emails at all.
6.25 ID verification documents
What: a photograph of a government-issued identity document that you upload, the document type you selected, the review status, the reviewing decision, the timestamp, and basic device and app version information captured with the submission.
Source: you, voluntarily. Verification is optional and nothing in the app requires it. It produces the verified status, which is recognized in both modes and which is required to accept a pending date invitation, to use Quick Date, and to host a Butterfly party room.
Why: to confirm that a real, accountable adult is behind the account, to reduce impersonation and fraud, and to gate features that carry a higher risk of abuse.
How it is reviewed: by a person at YoYo, who opens the record in our administrative console, looks at the document, and marks it approved or rejected. There is no reviewer screen inside the app and no automated identity check. We do not operate facial recognition and we do not generate or store a face template, fingerprint, voiceprint or other biometric identifier from your document or your photos.
Disclosed to: the YoYo staff who carry out the review; Resend and the staff mailboxes, for the notification email described in 6.24, which never contains the image. Your identity document is never shown on your profile, never returned in any feed, search, candidate list or match result, and never sent to any third party for that party's own purposes. In particular it is never sent to OpenAI.
How it is protected, honestly: the record that points at your document is locked down - it sits in its own access-controlled area that only you and our backend can read. The file itself is stored in an owner-only area. But the record contains a link to the file, and that link carries an access token, which means the link works on its own without being signed in. The record is the real control. We say this rather than claim the file is protected by two independent locks, because it is not.
Retention: the verification record is kept until you delete your account and is deleted with it, together with the stored file. There is no automatic purge at the moment the review finishes, and we are not going to describe a control we have not built. If you want the document image removed at any time, including right after review or after your account has been deleted, write to support@yoyodatingapp.com and we will remove it and confirm.
Note: identity document information is sensitive personal information. See section 7.
6.26 Voice session records
What: the channel identifier for a voice match or party room, the numeric voice identifier assigned to each participant, seat and membership state, host actions such as mute, kick and ban, room title and category, and start, join and end timestamps. If a report is filed about a voice session, the channel or room identifier is captured with the report so we can tell which session it concerned.
What it is not: the audio. YoYo does not record the audio of voice matches or party rooms. Voice runs live between participants through Agora, our real-time voice provider. Our servers never receive the audio stream, there is no recording facility switched on, and there is therefore no recording for us to keep, review, produce or lose.
Source: generated by the voice features when you use them.
Why: to place you into the right call, to enforce seat limits and host moderation, to close abandoned rooms, to apply rate limits, and to investigate reports.
Disclosed to: Agora, Inc., which receives the channel name, a numeric identifier we mint for the session - not your YoYo account identifier - and an access token, and which carries your live audio between participants while you speak; other participants, who see your handle, avatar and seat.
Retention: a room's chat, membership, ban and mute records are purged one hour after the room closes. A voice match record is purged 60 minutes after the call ends. Both are deleted with your account if they are still around.
6.27 Saved venues, Collections, Date Plans, invitations and the Venue Board
What: the venues you save, the Collections you build from them, the date plans you create or accept including the venue details, the date, the time, the party size and any note, the invitations you send and receive, and the posts and replies you write on the Venue Board.
Source: you, together with the venue information Google Places returns for the venues you choose.
Why: to let you keep and revisit venues and plans, to coordinate a date with the other person, to publish what you choose to post, and to score the shared-saved-venues component of matching.
Disclosed to: the other person in a plan or an invitation; other YoYo users, for what you post on the Board; OpenAI, which receives the text of your Board posts for the automated screening described in 6.16.
Retention: until you delete the item or delete your account. Date plans are the exception, and we corrected this entry in this version. A plan that is only yours - one you created for yourself with no other person on it - is deleted outright when you delete your account. A plan you share with someone else is not deleted, because deleting it would break their copy; instead it is flagged to show that one side's account is gone. Your account identifier stays on that shared plan. It no longer resolves to anything, because your account record is gone, so nobody can turn it back into your name or your photograph. But we are not going to describe that as "stripped of your name", because the identifier is still physically there. If you want a specific shared plan removed, delete it in the app before you delete your account, or ask us and we will remove it.
6.28 Rate limit counters
What: a counter per person, per protected action, per day, recording how many times you have used something we limit.
Source: generated by our backend.
Why: to stop abuse, spam and cost attacks.
Disclosed to: nobody outside our service providers.
Retention: yesterday's counters are not swept away automatically; they are deleted when you delete your account.
6.29 Support and legal correspondence
What: the content of messages you send to support@yoyodatingapp.com, including any information you attach, and our replies.
Source: you.
Why: to answer you, to verify and process privacy requests, to handle complaints and takedown requests, and to keep a record that we handled them.
Disclosed to: nobody outside YoYo and our professional advisers, except where the correspondence itself has to be forwarded, as a copyright counter-notification does under section 19.
Retention: kept for as long as needed to resolve the matter and thereafter for the period during which we may need to demonstrate that we responded, which for privacy rights requests is at least twenty-four months as required by California law.
7. SENSITIVE PERSONAL INFORMATION
Some of the information above is treated as sensitive under California law and equivalent categories under other U.S. state laws, and as 要配慮個人情報 or otherwise specially protected information in Japan. In YoYo, the sensitive categories are:
- Precise geolocation, collected only with your permission and used for venue discovery, map results and distance in matching. This includes the history log described in 6.6.
- Government-issued identification information, namely the identity document you upload for optional verification.
- Information revealing sexual orientation, which is inherent in a dating profile that states your gender and the gender you are looking for, and which is also revealed by the content you choose to publish.
- The contents of your private communications - the messages you exchange with other users in either mode - which California law treats as sensitive where we are not the intended recipient, and we are not the intended recipient of a message you send to another user. We handle message content only to deliver it, to keep the conversation available to you, to run the pre-send check described in section 11, and to act on a report.
- Dietary and allergy notes, if you choose to save them, because they can reveal health information and, in some cases, religious observance. These do not stay inside YoYo. When you ask for a booking they are sent to Browser Use, Inc., typed into the venue's own booking form as an allergy or special-request note, and read by a YoYo staff member if a person has to finish the booking. That is a wider circulation than any other profile field, and it happens because a restaurant needs to know. If you would rather it did not travel, leave the field blank and tell the restaurant yourself.
- Your YoYo Date Coach conversations, to the extent you discuss your own life in them. They are readable only by you; see 6.16.
We collect these only for the purposes described in section 6. We use and disclose them only to provide the features you asked for, to keep the service safe and secure, to detect and act on unlawful conduct, and to comply with law. We do not use or disclose sensitive personal information to infer characteristics about you, and we do not use or disclose it for any purpose that gives you a right to limit its use under California law. Because of that, there is no "limit the use of my sensitive personal information" link to click. If you disagree with our assessment, write to us and we will apply the limitation anyway.
We do not sell sensitive personal information, we do not share it for cross-context behavioral advertising, and we do not use it for advertising or profiling of any kind.
We do not use facial recognition and we do not collect or store biometric identifiers such as face templates, fingerprints or voiceprints. The five numbers that make up your Butterfly personality quiz result are your answers to five multiple-choice questions, not a measurement of you.
8. WE DO NOT SELL YOUR PERSONAL INFORMATION AND WE DO NOT SHARE IT FOR ADVERTISING
YoYo does not sell personal information, as "sell" is defined in the California Consumer Privacy Act, and does not share personal information for cross-context behavioral advertising, as "share" is defined in that Act. We have not sold or shared personal information in the preceding twelve months, and we have no plans to. We checked this against the code rather than against our intentions: there is no advertising SDK, no attribution SDK, no data broker integration and no advertising identifier anywhere in the app.
We do not sell personal data under the equivalent definitions in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Maryland or any other U.S. state privacy law, and we do not process personal data for targeted advertising or for profiling that produces legal or similarly significant effects.
Because we do not track you across other companies' apps and websites, we do not present the Apple App Tracking Transparency prompt, and there is nothing for it to ask you about.
Selling and sharing are not the same thing as the reservation disclosure described in section 13. When you ask us to book a table, we hand your booking details to that venue so it can hold the booking. We receive nothing for it, it happens only at your request, and it is not a sale or a share in the sense those laws use. We describe it plainly rather than hide it inside a service-provider list.
We are required to give you a way to opt out of sale and sharing even though we do neither. If you send us one, we will record it. See section 22.
9. WHY WE ARE ALLOWED TO USE YOUR INFORMATION
Different laws frame this differently, so here is the same answer in both frames.
Under California and other U.S. state law, we process personal information because you asked for a service and we are providing it, and for the business purposes listed in section 20. Where a law requires your consent before we process sensitive data, section 21 sets out exactly which consent covers which category and how you withdraw it.
Under Japan's Act on the Protection of Personal Information, we specify our purposes of use in advance and process within them. Section 23.1 is that list. We do not use your personal information for a purpose outside it without telling you and, where required, obtaining your consent.
In practice we rely on four grounds, and it is useful to know which is which:
- You asked for the feature. Matching, chat, posting, bookings, calendar entries, voice, coaching and icebreakers all exist because you used them. This covers most of what is in section 6.
- We have to keep the service safe. Moderation, reporting, blocking, rate limits, ban evasion detection and retained safety records rest on this. This is why moderation is not something you can switch off, and why some records survive your account.
- We have to keep the service working. Authentication, crash diagnostics, error logs and analytics rest on this.
- The law requires it. Age verification, breach notification, responses to lawful legal process, and records we must keep to demonstrate compliance.
Where a use rests on your consent - location permission, microphone permission, calendar permission, photo library access, uploading a government ID - you gave that consent at the point we asked, and you can withdraw it in your device settings or by clearing the field. Withdrawing it stops the future use; it does not undo what was already done.
10. HOW LONG WE KEEP THINGS
Section 6 gives the period or the criteria for each category. Read that first. The summary is this.
Three things expire on a schedule, automatically: party room chat, membership, bans and mutes, one hour after the room closes; voice match records, 60 minutes after the call ends; and orphaned Butterfly media files, swept every six hours once they are more than a day old.
Almost everything else has no schedule. It is kept until you delete your account. That is a deliberate design - a dating app that quietly deleted your matches after a year would be a worse product - but it means "how long do you keep it" has the same answer for most of this document, and the answer is "as long as you have an account".
Three things survive account deletion: safety records, as described in 6.23 and section 17; shared date plans and other people's records that name you, flagged rather than deleted; and the crash-signature store described in 6.20, which is an omission we are fixing rather than a decision.
The criteria we apply when deciding are:
- How long we need the information to provide the feature you are using.
- Whether it forms part of another person's record too, as a conversation does.
- Whether it is needed to keep people safe, to enforce our rules, or to stop a banned user coming back.
- Whether we are legally required to keep it, or need it to establish, exercise or defend a legal claim.
- Whether it has already been distributed to other users, which limits what deletion can achieve.
When information is no longer needed under any of those criteria, it is deleted or irreversibly de-identified.
11. AUTOMATED AND AI FEATURES, AND WHAT THEY CANNOT DO
We are required to describe these accurately, and we want to. The single most important thing in this section is that automated moderation in YoYo does not cover everything and is not guaranteed where it does, and we are going to tell you exactly where it applies and where it does not.
What is screened. Text is submitted to an OpenAI moderation model on the following surfaces: posts in the Square, comments, private messages in both Guide Mode and Butterfly Mode, party room chat, party room titles, and profile free text including your handle. Images are submitted for posts in the Square and for Guide Mode profile photographs. This is a wider list than the previous version of this policy gave, and the previous list was wrong rather than merely incomplete.
Pre-publication moderation of posts. A post in the Square is created in a pending state and is not visible to anyone else until it has been scanned. If the scan clears it, it becomes public; if not, it is blocked and you get a generic notification. Thresholds are set by us and adjusted on our servers.
How chat moderation actually behaves, which is worth understanding. Your message is checked as it is sent. Two consequences follow. First, if the moderation service is slow, unavailable or over its rate limit, the check degrades to a local-only screen rather than blocking you from using the app - so during an outage, less is caught. Second, because we deliver your message quickly rather than holding it, a message can already have been delivered and pushed to the other person before the model comes back and redacts it. The recipient may have seen it. The redaction still happens, and a report is still opened.
Where there is no automated screening at all. Images sent inside a chat are not screened. Live voice is not screened - the audio never reaches our servers, so there is nothing for a model to read, and this is a property of how the feature is built rather than a setting we could switch on. Video is not screened frame by frame: only the still poster frame is checked, every frame after the first is unchecked, and the poster frame is generated by the sending device rather than verified by us against the clip it is attached to. Given that a video can run to an hour, please read that as a real limit and not a formality.
In all of those places, and in every place where the checks above degrade, what protects you is the 18-and-over requirement, optional identity verification and the verified status that gates room creation, the in-app reporting tools, the quick flag in chat, blocking, the automatic hiding of an item once three distinct users have reported it, and human review with removal of the content and ejection of the offending user within 24 hours of a substantiated report.
Automated moderation makes mistakes in both directions - it blocks acceptable content and it misses unacceptable content. We moderate in good faith. We do not author user content and we do not guarantee that everything you see has been correctly reviewed.
Reports and auto-hiding. When an item reaches three distinct reporters it is automatically hidden pending human review. That is a volume trigger, not a judgment that the content is bad.
YoYo Date Coach. A conversational advisor built on an OpenAI model, capped per session with a further daily limit. It gives general dating suggestions. It is not a therapist, a counselor, a lawyer or a safety service, it does not know anything about the person you are dating beyond what you tell it, and its output can be wrong. Your sessions are stored in full - see 6.16, including the access note there.
Butterfly Mode icebreakers. Up to three suggested opening messages generated from the two participants' tags and planets and the recent messages of that conversation. Suggestions are rate-limited, cached, filtered to remove contact details, and moderated before you see them. Nothing is sent on your behalf; you choose whether to send one. If you send a suggestion unchanged it is flagged as AI-assisted.
The reservation agent. YoYo Reservations attempts to complete a booking on a venue's own public booking site using the details you provided. The agent is an AI-driven automated browser operated for us by Browser Use, Inc., a service provider in the United States, which receives the booking details in order to fill in the form. It frequently fails, because venue sites vary. When it fails, the attempt goes to a manual queue and a member of the YoYo team completes the booking by hand, including by telephoning the venue, which means a person reads your name, phone number, email address and dietary note. The agent is instructed never to enter payment-card details and to stop if a venue requires a card. A reservation is only confirmed when the venue confirms it, and a venue can refuse.
None of these features makes a decision about you that produces a legal or similarly significant effect. Moderation decisions that restrict or remove content or an account are reviewable by a human; write to the contact address to ask for review.
12. VOICE FEATURES AND THE MICROPHONE
Butterfly Mode includes two live voice features: a timed voice match between two matched users, where identities are revealed only if both people consent before the timer expires, and party rooms with microphone seats plus an audience, moderated by the host.
We request microphone permission so that you can speak in these features. The microphone is used only while you are in a voice match, on a party room mic seat, or on a call, and never for advertising, profiling or listening to your surroundings. Audio and microphone features work only while the app is open, and are suspended when the app is moved to the background or closed. If you leave the app in the background, or are inactive, for about five minutes, your seat goes to someone else who is listening. What a room keeps about you is presence, not sound.
YoYo does not record voice match or party room audio. There is no stored recording of what you say. Your live audio does travel through Agora's real-time network in order to reach the other participants, which is what section 24 discloses; it is carried, not kept.
One current limitation you should know about. Who is allowed to speak in a room is enforced by the app and by our database rules, rather than by the voice network itself. We are tightening that. In the meantime, treat a party room as a place where an unexpected voice is possible, and use the host controls and the report button if it happens.
You must not record other participants. Some jurisdictions we operate in, including California, require the consent of every party to a recorded conversation. Recording, streaming or otherwise capturing another participant's voice without their consent is prohibited by our Terms and may be a criminal offense. If you believe you were recorded without consent, report it at the contact address.
If you report something that happened in a voice session, please report it from within the session or note the room, because the channel identifier captured with the report is the only durable handle we have on which conversation you mean.
YoYo also includes one-to-one voice and video calls. In Guide Mode you can call someone you have matched with, from inside your chat. In Butterfly Mode you can call someone once your conversation is open, which means once they have replied to your first message.
For a video call we also ask for camera permission. We ask before the call is placed rather than after, so that you are never left in a ringing call you cannot actually complete. The camera is used only while you are on a video call.
We do not record calls and we do not keep them. There is no stored audio or video of a call of either kind. As with rooms, your live audio and video travel through Agora's real-time network in order to reach the other person; they are carried, not kept.
We do keep a short record about each call, which is not the same thing as the call itself. That record holds who called whom, which mode the call belonged to, whether it was voice or video, the conversation it was placed from, when it started, whether it was answered, and how it ended. We use it to make calling work at all, because it is what causes the other phone to ring and what stops two calls colliding; to show you a missed call afterwards; and to enforce a daily limit on how many people one account can ring. Finished calls are deleted about an hour after they end.
A call you did not answer can leave something you find later: a notification in Butterfly Mode, or a message in the conversation in Guide Mode. A call you declined does not leave one, because you already saw it.
Calls in Guide Mode require both people to be verified. Calls in Butterfly Mode do not, because Butterfly Mode does not ask you for identity documents at all. What it asks instead is that the other person has replied to you.
You must not record the other person on a call, for the same reasons set out above for voice rooms.
13. SERVICE PROVIDERS AND OTHER RECIPIENTS
We disclose personal information for a business purpose to the following providers, each under a contract that limits them to processing it for us. This list is complete as of the effective date.
Google (Firebase platform). Firebase Authentication holds account credentials and identifiers. Cloud Firestore holds profiles, posts, comments, chats, calendar entries, reports, blocks and the rest of the database. Cloud Storage holds photos, video, poster frames and identity documents. Cloud Functions runs our backend logic, including matching, moderation, reservations, voice token issuance, and making the media copies described in 6.4. Google Analytics for Firebase receives usage and diagnostic events, including your account identifier on many of them. Firebase Cloud Messaging delivers push notifications and receives push tokens. App Check receives attestation data. Remote Config delivers configuration to the app. Our database is located in the United States, Cloud Storage is located in Japan, and Cloud Functions runs in Taiwan. Google runs Firebase Authentication only from data centers in the United States. Google Analytics for Firebase, Firebase Cloud Messaging, App Check and Remote Config run on Google's global infrastructure and may process data in any country where Google has data centers.
Google (Maps and Places). Receives your coordinates and your venue search terms in order to return maps, venue results, venue details and venue photographs. Your device makes these calls directly to Google, not through our servers. Used in Guide Mode only.
Apple. Provides Sign in with Apple, in which case Apple gives us an account identifier and an email address that may be a private relay address; delivers push notifications through the Apple Push Notification service; provides the on-device calendar interface used when you turn on calendar sync; and provides the on-device geocoding service that converts your raw coordinates into a city and country name, which means Apple receives those coordinates. Apple also distributes the app through the App Store. YoYo has no in-app purchases, no subscriptions and no payments of any kind today.
OpenAI. Receives content submitted for automated moderation, which is your post text and images, your comment text, your party room chat, your party room titles, your profile free text and handle, your Guide Mode profile photographs, the poster frames of the videos you post, and the text of the private messages you send in both modes. Images are handed over as a link that OpenAI's servers fetch themselves, as described in 6.4. It also receives the inputs and outputs of YoYo Date Coach and of Butterfly Mode icebreakers, which include your interest tags, your planet and the recent messages of the relevant conversation. Processing is performed through OpenAI's commercial API as our service provider, for the sole purpose of returning a result to us. We do not send OpenAI your email address, your date of birth, your identity document, your phone number or your coordinates.
Agora. Provides the real-time voice transport for voice matches and party rooms. Receives the channel name, a numeric participant identifier we mint for the session - which is not your YoYo account identifier - an access token, connection quality information, and your live audio while you are speaking. Audio passes between participants in real time; it is not recorded by us and no recording facility is enabled.
Expo, Inc. Provides the app runtime and the on-device media picking and compression used when you select a photo or video. Expo Application Services delivers over-the-air updates, receiving your installation and runtime identifiers, app version, platform and device model each time the app checks for one. Expo's push service relays our notifications to Apple's and Google's push services, receiving your push token and the contents of the notification - including, in Guide Mode, the first 40 characters of the message that triggered it.
Resend, Inc. Delivers the staff alert emails described in 6.24. Receives the recipient addresses and the body of the message, which for an ID verification alert contains your name, your account email address and your account identifier, and for a failed booking alert contains your name, your account email address, your account identifier, the venue and the slot. It never receives your identity document image.
Browser Use, Inc. (browser-use.com), United States. Operates the AI-driven automated browser that completes a venue's own booking form for you when you use YoYo Reservations. Receives, only when you ask for a booking, the first name, last name and full name on your account, your phone number, your reservation email address, the venue and its booking page, the date, the time, the party size, and any dietary or allergy note you have saved, all of it as plain text inside the instruction we send. It is instructed never to enter payment-card details.
Venues and the booking platforms they use. This one is different from everything above, and we are separating it out so that it is not buried. When you ask us to make a reservation, we submit your booking to the venue or to the online booking platform that venue uses. What is submitted is the name used for the booking, a contact telephone number, an email address, the party size, the requested date and time, and any dietary or allergy note, which the agent is specifically instructed to enter into the venue's allergy or special-request field. The venue and its booking platform are not our service providers. They receive that information as independent businesses and handle it under their own privacy practices in order to hold, confirm, change or cancel your booking, and we do not control what they do with it afterwards. This happens only when you ask for a booking. If you would rather not share those details, do not use YoYo Reservations - you can still find the venue in YoYo and book with it yourself.
Beyond these providers, we may disclose personal information:
- to another user, where you have chosen to share it with them;
- to law enforcement, a regulator or a court, where we are legally required to do so or where disclosure is necessary to prevent imminent physical harm;
- to our professional advisers where necessary to obtain legal or accounting advice; and
- to an acquirer, in the event of a merger, acquisition or sale of assets, in which case we will tell users before their information becomes subject to a different policy.
Apart from the reservation disclosure described above, which happens only at your request, we do not disclose personal information to any party for that party's own independent commercial purposes. We do not disclose personal information to advertising networks, attribution companies or data brokers, because we do not use any.
Two things also worth naming, because they are places your information ends up that are not a "recipient" in the usual sense. Our backend writes operational logs to Google Cloud Logging, and those logs can contain account identifiers and short fragments of message text. And the instruction we send to Browser Use for a booking sits in that company's task history; nothing in our system deletes it.
14. WHERE YOUR DATA IS PROCESSED: INTERNATIONAL TRANSFERS
YoYo runs on Google Cloud infrastructure in more than one location. Our database is configured in a multi-region location in the United States. The files you upload - photos, videos, poster frames and identity documents - are stored in Cloud Storage in Tokyo, Japan. Our backend functions, which read and write that data and make the media copies described in 6.4, run in Taiwan. This means that if you are in Japan, your account record, your profiles, your messages and the rest of our database are stored in the United States, not in Japan, from the moment you create your account, and that your data is processed in Taiwan whenever our backend works on it. Firebase Authentication, which holds your sign-in credentials, runs only in the United States, and Google Analytics for Firebase, Firebase Cloud Messaging, App Check and Remote Config may process data in any country where Google has data centers, as section 13 explains. Your data is handled by the providers named in section 13, all of which are United States companies, with the exception of Agora's global real-time network, which routes voice traffic through the region nearest to the participants, and of the venues you ask us to book, which are in the country you are booking in.
The United States does not have a single comprehensive national data protection law equivalent to Japan's Act on the Protection of Personal Information. Protection instead comes from a combination of federal enforcement against unfair or deceptive practices by the Federal Trade Commission, sector-specific federal laws, and comprehensive state privacy laws in California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Maryland and other states, which give consumers rights of access, correction, deletion and opt-out. California law, which applies to YoYo LLC as a business based in Los Angeles, is the strictest of these and is enforced by the California Privacy Protection Agency and the California Attorney General. Taiwan, where our backend functions run, has a comprehensive national personal data protection law, the Personal Data Protection Act. Neither the United States nor Taiwan is the subject of an adequacy-equivalent designation by Japan's Personal Information Protection Commission, which is why we set out the recipients and safeguards specifically in sections 23.3 and 23.7.
The safeguards we rely on are: written data processing agreements with each provider that restrict them to processing on our instructions and for our purposes; contractual confidentiality and security obligations; encryption of data in transit and at rest; access limited to authorized personnel; and the providers' own published security and privacy programs.
By using YoYo from Japan you are asking us to provide a service that necessarily operates on this infrastructure. Section 23.3 contains the specific disclosure required by the Act on the Protection of Personal Information.
15. REPORTING, BLOCKING, AND WHAT WE DO ABOUT IT
This section is here because safety and privacy are the same conversation.
You can report a profile, a post, a comment, a chat, a party room or a voice match from inside the app, and in Guide Mode you can flag a message directly from the chat. Reporting works the same way in both modes and all reports go to one queue and one review team.
Butterfly Mode has a full block, enforced by our servers, which takes effect immediately across every Butterfly Mode surface and in both directions. Guide Mode does not have a block control today: it has Hide User, Unmatch and Report User, which section 5 describes exactly, and Hide User cannot currently be undone from inside the app. Nothing you do in one mode carries across to the other. We would rather you knew that than assume a protection you do not have.
We commit to reviewing reports of objectionable content and abusive behaviour promptly and, where a report is substantiated, to removing the content and ejecting the offending user within 24 hours of the report. Content that has been reported by three distinct users is hidden automatically pending that review. We may also warn, restrict, suspend or terminate an account, and we terminate repeat infringers.
Reports are retained after account deletion, and, as 6.23 explains, an automatically generated report contains the text of the message that triggered it. If you file a report, what you reported becomes part of a safety record that can outlive both accounts.
If you cannot reach the in-app reporting tools, or if you want to escalate, write to support@yoyodatingapp.com. You may write in English or Japanese.
16. THE CONTROLS YOU ACTUALLY HAVE IN THE APP
We list only controls that exist today, and we say plainly where one does not.
- Profile editing. You can add, change or clear any optional Guide Mode profile field, including the sensitive ones, from your profile screens. This is the strongest right the app actually implements.
- Photos. You can add, replace, reorder and remove your profile photos.
- Butterfly profile. You can change your avatar, your planet and your interest tags at any time, and retake the personality quiz once every seven days. Your handle cannot be changed after it is created - not by you and not by us on request, because it is what other people know you by.
- Incognito Mode. When on, you are hidden from other users' candidate lists and you do not see theirs. Invisibility is two-way.
- Blocking, in Butterfly Mode. Effective immediately across Butterfly Mode, in both directions, and reversible. See section 5.
- Hide User, Unmatch and Report User, in Guide Mode. There is no block control today, and Hide User cannot be undone in the app - ask us and we will undo it for you. See section 5.
- Reporting. Reports content or a user for review, from either mode, into one queue.
- Notifications. An in-app switch turns YoYo push notifications on or off, and it is honoured by our servers before a notification is sent rather than only on your device. Your device settings also control notification permission independently. In Butterfly Mode the notifications centre continues to show in-app rows even with push off, so turning push off does not mean losing the information.
- Calendar sync. A toggle controls whether YoYo reads your device calendar for on-device display. Turning it off stops the reading; revoking calendar permission in device settings also stops it. Note that YoYo writes accepted dates into your device calendar whenever calendar permission is granted, independently of this toggle.
- Location permission. Managed in your device settings. YoYo continues to work without it, with reduced venue and distance features.
- Microphone permission. Managed in your device settings. Required only for voice features.
- Identity verification. Entirely optional.
- Anonymous posting. You choose per post whether your handle is shown, subject to section 5.
- Account deletion. Available in the app from either mode, described in section 17.
Controls that do not exist, stated so you do not go looking:
- There is no in-app data download. Ask us and we will produce your data by hand. See section 22.
- There is no product analytics switch. See 6.19.
- There is no way to opt out of content moderation. That is deliberate.
- There is no "Data Sharing Preferences" screen and no advertising opt-out, because we do not sell, share or advertise.
17. DELETING YOUR ACCOUNT, AND WHAT DELETION DOES AND DOES NOT REMOVE
You can delete your YoYo account from inside the app. In Guide Mode the control is in account settings. In Butterfly Mode it is under the far-right tab, the one showing your avatar, then Settings, then Delete Account. Both routes lead to the same deletion flow. There is also a deletion request page on our website, so you can start the process without installing the app, and you can write to support@yoyodatingapp.com from the email address on the account. We acknowledge an emailed request within 3 business days, verify that it comes from the account holder, and complete the deletion within 30 days of verifying you, sooner where we can. A request made that way deletes exactly what a deletion made inside the app deletes.
How it actually works, because the timing matters. Deleting your account signs you out and removes your sign-in credentials, and that removal is what triggers the full purge on our servers. The purge runs in two stages - Butterfly Mode first, then Guide Mode - and it works through dozens of separate steps. Most of it completes in seconds. Any step that does not complete is recorded, and a process that runs every thirty minutes picks up whatever was left and finishes it.
We are being careful with the words here. "Immediately and permanently" would not be accurate. "We begin immediately, and a scheduled process completes anything the first pass could not" is. If you ever want to know whether your deletion completed, write to us and we will check the record and tell you.
What deletion removes. Deletion covers both modes and is genuinely thorough.
From Butterfly Mode it removes your profile and its private records; your public profile mirror; the posts you published under your handle and the posts you published anonymously, which we find through the private authorship record described in 6.14 - this is the one place we use that record to erase rather than to enforce; your comments, including comments you left on other people's posts; every like pointing at your posts and every like you gave; your follow relationships in both directions; the blocks you placed on other people; your conversations, their messages and the cached icebreaker suggestions; your notifications, and notifications on other people's bells that were about you; the party rooms you hosted, including their chat, membership, ban and mute lists, and your messages in other people's rooms, including the permanent founding rooms that never close; your moderator grants in other people's rooms; your room memberships; your voice match records; your matchmaking queue entries, results, cooldowns and quota; the pairing log entries naming you; the dust wipes you sent; your Butterfly images and video in storage; and the internal identity mapping described in 6.18.
Before any of that, your profile is flagged so that you drop out of the candidate pool within one polling cycle, and any live room you were hosting is closed with its seats cleared. You go dark first and are erased second, so nobody is talking to a ghost while the purge runs.
From Guide Mode it removes your public Quick Date board entries; your join requests in both directions; your chats, all their messages and any files attached to them, and your identifier is removed from every remaining participant's chat list; your solo date plans; your reservation attempts; your matches; your notifications in both directions; your activity logs; your YoYo Date Coach sessions; your identity verification record and the document file itself; your feedback; your error records; your push delivery receipts; your location history log; your rate limit counters; your saved plans; your calendar events, including the matching entry on your date partner's calendar; your saved venues and Collections; your reservations; and finally your entire user record and everything beneath it, with a check afterwards that confirms it is actually gone.
Your Firebase Authentication account is deleted, so you can no longer sign in. Deletion is permanent. It is not a deactivation, we cannot undo it, and we will not restore a deleted account from backup.
What deletion does not remove, and why. We are describing this honestly rather than promising total erasure.
- Reports, in both directions, kept and flagged to show that the account has been deleted. This includes, for an automatically generated report, the text of the message that triggered it. The legal basis is set out in 6.23.
- Blocks placed against your account, kept so that they carry on protecting the other person after you leave. Blocks you placed on others are deleted.
- Bans and mutes you collected in other people's rooms, which belong to those rooms.
- Shared date plans, flagged rather than deleted, with your account identifier still on them, as explained in 6.27. Solo plans are deleted.
- Bookings that merely name you because you were going with someone else. Your identifier is removed from their copy and the booking is kept, so their record survives.
- Your handle and avatar as they appear inside other users' notification history, which age out on their own.
- A booking in the manual queue that is still in progress, which is cancelled and redacted rather than deleted.
- Hidden and blocked lists belonging to other users that contain your identifier. We deliberately do not edit a survivor's protection list to tidy up after the person they were protected from.
- The crash-signature store described in 6.20. This one is an omission rather than a decision, and it is the one place where the honest answer is that we do not currently reach your data. Write to us and we will remove it by hand.
- Records we must keep by law, or that we need to establish, exercise or defend a legal claim.
- De-identified and aggregated data that can no longer be linked to you.
- Your product analytics history at Google, described in 6.19, which our deletion process does not reach. Ask us and we will make the request to Google.
- Backup copies held by our infrastructure provider. Deleted data can persist in routine encrypted backups for a period after it is removed from the live service, on that provider's schedule rather than ours.
- Staff alert emails already sent, described in 6.24.
Timeframe. Deletion of your records from the live service is immediate to near-immediate in both modes, with a scheduled process finishing anything that did not complete on the first pass, running every thirty minutes. Uploaded Butterfly images and video are also swept by a housekeeping process, so an orphaned file can remain in storage for up to about a day. Party room seat state clears within about five minutes.
If deletion appears not to have worked, or if you want to check what remains, write to us and we will tell you.
18. HOW WE SECURE YOUR INFORMATION - AND WHERE IT IS WEAKER THAN YOU WOULD ASSUME
We are going to do this section in two halves, because a security section that only lists strengths is not information.
What we do. All communication between the app and our backend is encrypted in transit, and stored data is encrypted at rest on Google Cloud infrastructure. Access to production data is limited to personnel who need it. Administrative operations run through server-side functions rather than direct client access, so counters, verification status, moderation state and other protected fields can only be written by our backend. Per-user rate limits apply to sensitive backend functions. Several collections are locked down individually and correctly: your government ID record is readable only by you and our backend; your Date Coach transcripts are readable only by you; your location history log is readable by no client at all; reports are readable by no client at all; the private authorship record for anonymous posts is readable by no client at all; the Butterfly identity mapping is denied to every client in both directions; and the crash store accepts writes but allows nobody to read it back. Your Butterfly block is enforced by our database rules rather than by the app, so it cannot be bypassed by a modified client.
Where it is weaker, stated plainly. Our access rules carry a legacy default that grants any signed-in user read and write access to collections that have not yet been given rules of their own. We have been moving collections off that default one at a time - user records, chats, government IDs, reports, blocks, crash reports, staff configuration and several others are now individually governed. Two things follow that you should know:
- Your user record is now individually governed, but the rule reads "any signed-in user may read it". Writing is tightly constrained, but reading is not owner-only. That means another signed-in YoYo user's app can read the fields on your account record, including your precise coordinates, your date of birth, your phone number and your email address. The app's interface does not display those to them. The data is nonetheless reachable. This is the single most important sentence in this document.
- Several other collections are also still on it, including date plans, matches, notifications, reservations and feedback. Crash records and join requests have also come off it: both still accept a write from a signed-in user, which is what they are for, but no client can read either of them back.
We are telling you this rather than describing an ideal state. These are on our list to close, and this policy will be updated when they are.
App Check, which lets our backend distinguish a genuine copy of the app from an automated script, is built into the app and wired up, but enforcement is currently switched off while older installs catch up. Switching it on now would lock out users on older builds. So it is a control that exists and is not yet doing work, and we would rather say that than claim protection we are not applying.
Tokenised file links. Photos and identity documents are stored as files with links that carry an access token. A link like that works on its own, without being signed in. We treat those links as secrets, and the database record that holds a link is itself access-controlled - but the file-level permission is not what protects it. See 6.4 and 6.25.
Live voice is not screened and, with the way voice is built, cannot be. See section 11.
No system is perfectly secure, and we do not claim ours is. Use a strong, unique credential, and do not share account access.
Breach notification. If we discover a security incident affecting your personal information, we will investigate it, take steps to contain it, and notify you and the relevant authorities where the law requires. In Japan that means reporting to the Personal Information Protection Commission and notifying affected individuals in the cases specified by the Act on the Protection of Personal Information, which for a reportable incident means a preliminary report promptly and a full report thereafter. In the United States that means notifying affected residents and, where applicable, state attorneys general within the deadlines set by state breach notification laws. We will tell you what happened, what information was involved, what we have done, and what you can do.
19. RIGHTS-INFRINGING CONTENT AND REMOVAL REQUESTS
If content on YoYo infringes your rights - if it defames you, invades your privacy, publishes your personal information without consent, uses your photograph without permission, or infringes your copyright - you can ask us to remove it.
Send the request to support@yoyodatingapp.com with: your name, postal address, telephone number and email address; identification of the specific content, with enough detail for us to find it, such as the handle, the post and the approximate time; a description of the right you say is being infringed and why; and a statement that the information in your request is accurate.
If your claim is a copyright claim under United States law, your notice must also contain the following, because the Digital Millennium Copyright Act requires it: your physical or electronic signature; identification of the copyrighted work you say has been infringed, or, where a single notice covers several works on the service, a representative list of them; identification of the material you say is infringing, and information reasonably sufficient to let us locate it; your address, telephone number and, if available, email address; a statement that you have a good faith belief that the use of the material in the manner complained of is not authorized by the copyright owner, its agent or the law; and a statement that the information in the notice is accurate and, under penalty of perjury, that you are the copyright owner or are authorized to act on the owner's behalf. A notice missing these elements may not be effective, and we may ask you to supply what is missing. Under section 512(f) of title 17 of the United States Code, knowingly making a material misrepresentation that material is infringing, or that it was removed by mistake, can make you liable for damages, including costs and legal fees.
Our designated agent to receive notifications of claimed copyright infringement is:
DMCA Designated Agent
YoYo LLC
453 S Spring St STE 400, PMB 1290
Los Angeles, CA 90013, United States
support@yoyodatingapp.com
We acknowledge requests promptly and, in principle, notify you of our decision within 14 days of receiving a complete request, faster where the content is plainly unlawful, involves a minor or presents a risk of harm. We may notify the person who posted the content that a removal request was made, and give them the substance of the request, so that they can respond. Where the content was posted anonymously, we do not disclose the author's identity to you; we act on the content.
If we remove or disable access to material in response to a copyright notice, we will take reasonable steps to notify the person who posted it, and that person may send us a counter-notification. A counter-notification must contain: their physical or electronic signature; identification of the material that was removed and the location at which it appeared before it was removed; a statement, under penalty of perjury, that they have a good faith belief the material was removed or disabled as a result of mistake or misidentification; and their name, address and telephone number, together with a statement that they consent to the jurisdiction of the United States District Court for the judicial district in which their address is located, or, if their address is outside the United States, for any judicial district in which YoYo LLC may be found, and that they will accept service of process from the person who filed the notice or that person's agent. That last point matters here, because many YoYo users are in Japan and the statute treats a claimant outside the United States differently.
On receiving a compliant counter-notification we will send a copy to the person who filed the original notice, tell them that we will restore the material in 10 business days, and restore the material not less than 10 and not more than 14 business days after we received the counter-notification, unless we are first told that the original claimant has filed an action seeking a court order to restrain the alleged infringement.
We terminate, in appropriate circumstances, the accounts of users who are repeat copyright infringers.
This procedure is also how requests are made under Japan's framework for handling information that infringes the rights of others through a platform, and we handle Japanese-language requests in Japanese.
20. YOUR CALIFORNIA PRIVACY RIGHTS
This section applies to California residents under the California Consumer Privacy Act as amended by the California Privacy Rights Act. This policy, together with the just-in-time disclosures in the app, is our notice at collection.
Categories of personal information we have collected in the preceding twelve months:
- Identifiers: your name, email address, account identifiers, Apple or Google sign-in identifiers, device identifiers, installation identifiers, session identifiers and push tokens.
- Customer records information as described in section 1798.80 of the Civil Code: your phone number and your reservation email address.
- Protected classification characteristics: age and date of birth, gender, and information revealing sexual orientation as described in section 7.
- Commercial information: your reservation activity, your saved venues, your Collections and your date plans.
- Internet and network activity information: app usage, feature interactions, screens visited, breadcrumb trails and diagnostics.
- Geolocation data, including precise geolocation and a history of it.
- Audio and visual information: the photographs and videos you upload, and the live audio carried between participants during a voice match or party room - noting that we do not record that audio and hold no recording of it.
- Professional or education information, only where you volunteer occupation, workplace, school or education level on your profile.
- Inferences: the matching scores, personality vector, planet and pairing history described in 6.13 and 6.17.
- Sensitive personal information as listed in section 7.
Sources: you; your device; other users, where they report or interact with you; Apple or Google, where you use their sign-in; Google Places, for the venue information attached to venues you save; and our own systems, which generate identifiers, scores and records.
Business purposes: providing and maintaining the service, matching, publishing your content, delivering messages and notifications, making reservations, safety and content moderation, security and fraud prevention, debugging, analytics to improve the app, responding to you, and complying with law. These are set out per category in section 6.
Categories of recipients: the service providers named in section 13; venues and their booking platforms, where you ask us to make a reservation; other users, for what you choose to share and, as section 18 explains, for the fields on your account record that any signed-in user's app can read; and legal or governmental recipients where required.
Disclosure for a business purpose in the preceding twelve months: we have disclosed each of the categories listed above to the service providers named in section 13 for the business purposes listed above. We have disclosed identifiers and customer records information - specifically the booking name, telephone number, email address and any dietary note - to venues and their booking platforms where a user asked us to make a reservation.
Retention: stated per category in section 6, with the criteria summarized in section 10.
Sale and sharing: we do not sell personal information and we do not share it for cross-context behavioral advertising, and have not in the preceding twelve months. See section 8.
Your rights:
- To know what personal information we have collected about you, the categories, the sources, the purposes, the categories of recipients, and the specific pieces of information.
- To obtain a copy of your personal information in a portable and, to the extent technically feasible, readily usable format. There is no download button in the app. Ask us at the contact address and we will assemble it by hand and send it to you. Section 22 gives the timeline.
- To delete personal information we have collected from you, subject to the exceptions in the statute, which are described honestly in section 17.
- To correct inaccurate personal information. Most profile information you can correct yourself in the app; section 16 lists what you cannot.
- To opt out of sale and of sharing for cross-context behavioral advertising. We do not do either, so there is nothing to opt out of, but we will record your preference if you send one.
- To limit the use and disclosure of sensitive personal information. We do not use or disclose it for purposes that trigger this right, as explained in section 7, so no link is required. Ask and we will apply the limitation anyway.
- To be free from discrimination for exercising your rights. We do not deny service, charge a different price, or provide a different level of quality because you exercised a privacy right. We do not offer financial incentives for personal information.
How to exercise them is in section 22.
21. YOUR PRIVACY RIGHTS IN OTHER U.S. STATES
If you live in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Maryland, or another state with a comprehensive consumer privacy law, you have rights to confirm whether we process your personal data and to access it, to correct inaccuracies, to delete it, to obtain a portable copy of data you provided to us, and to opt out of targeted advertising, the sale of personal data, and profiling in furtherance of decisions producing legal or similarly significant effects. As stated in section 8, we do not engage in targeted advertising, sale, or that kind of profiling, so those opt-outs have no work to do here, but we will honour any preference you send. Some states also give you the right to obtain a list of the third parties to whom we have disclosed personal data; section 13 is that list.
Consent to process sensitive data. Where your state law requires your consent before we process sensitive data, we rely on the consent you give when you choose to provide it, and each kind can be withdrawn.
- Data revealing sexual orientation. You give this consent when you create a Guide Mode dating profile and tell us your gender and the gender or genders you want to be matched with. We are not treating that as an optional extra, because it is the information the matching feature exists to act on and Guide Mode cannot work without it. You withdraw that consent by deleting your Guide Mode profile or your account.
- Precise geolocation. You give this consent by granting location permission and withdraw it by revoking that permission in your device settings. Withdrawing it stops new collection; the history log described in 6.6 is removed when you delete your account, or sooner if you ask us.
- Government identification information. You give this consent by choosing to upload an identity document for optional verification, which nothing in the app requires you to do. You withdraw it by asking us to delete the document.
- Health-adjacent dietary and allergy information. You give this consent by filling in the dietary field, knowing from section 7 where it travels, and you withdraw it by clearing the field.
Maryland residents. The Maryland Online Data Privacy Act allows sensitive data to be collected and processed only where that is strictly necessary to provide or maintain a product or service you requested, and it prohibits selling sensitive data outright. We process gender and gender preference because matching is the product you asked for and cannot run without them. Precise geolocation, identity verification and dietary notes are collected only where you have separately chosen to supply them for a specific feature you asked for, they are used for nothing beyond the purpose stated for them in section 6, and they are never used for advertising or for profiling. We do not sell sensitive data in Maryland or anywhere else.
Our analytics provider, Google Analytics for Firebase, offers optional advertising features - Google signals, ads personalisation, and links to Google advertising products - which would send data to Google for advertising purposes. YoYo does not advertise and does not use those features. We keep them switched off in our Google Analytics configuration and we check that configuration before each release. If we ever turned any of them on, that would be a sale or a share as the laws described above define it, and before it took effect we would update this policy, tell you, and give you the opt-out this policy says you would have.
Appeals. If we refuse your request, in whole or in part, we will tell you why, and you may appeal. Send an appeal to support@yoyodatingapp.com with the subject line "Privacy Request Appeal", the original request, and why you think our decision was wrong. A person who was not involved in the original decision will review it. We will respond in writing within 45 days of receiving the appeal, explaining the outcome and the reasons for it. If we deny the appeal, we will give you a method of contacting your state attorney general to submit a complaint. This appeal process is available to residents of every U.S. state, not only those whose law requires it.
22. HOW TO SUBMIT A PRIVACY REQUEST
Send your request to support@yoyodatingapp.com, or by post to either address in section 1. Tell us which right you are exercising and, if you are not writing from the email address on the account, enough information for us to find your account.
Please read this first, because it is the honest position: there is no self-service data export in YoYo. No download button, no export screen, no automated report. When you ask for a copy of your data, a person at YoYo assembles it from our systems by hand and sends it to you. That is slower than a button, it is why we ask for the full response window, and it is a gap we intend to close.
Verification. Before we act on a request to know, delete or correct, we must be reasonably confident you are who you say you are. Normally, sending the request from the email address registered to the account, and confirming a detail only the account holder would know, is enough. For requests for specific pieces of personal information, or for anything touching sensitive personal information, we apply a higher standard and may ask for an additional confirmation. We use information you give us for verification only for that purpose, and we delete it afterwards. If we cannot verify you, we will tell you, and we will treat the request as a request about categories rather than specific pieces where the law allows.
Authorized agents. You can use an authorized agent. The agent must provide written, signed permission from you, and we may contact you directly to confirm that you authorized the request and to verify your identity, unless the agent provides a valid power of attorney.
Timing. We acknowledge requests within 10 business days and respond substantively within 45 calendar days. Where a request is complex or we have received many, we may extend by a further 45 days, for a maximum of 90 days in total, and we will tell you within the first 45 days if we do. For Japanese requests under section 23.5 we aim to respond within 30 days. There is no charge, unless a request is manifestly unfounded or excessive, in which case we will tell you why before doing anything.
Do Not Track and Global Privacy Control. YoYo is a mobile app, not a website, and it does not respond to browser Do Not Track signals because it does not receive them. We do not sell or share personal information, so there is no sale or sharing for an opt-out preference signal such as Global Privacy Control to switch off. If you send us a Global Privacy Control signal or an equivalent statement in writing, we will treat it as a valid opt-out request and record it, even though our answer is that we were not doing the thing you are opting out of.
23. JAPAN: PURPOSES OF USE AND YOUR RIGHTS UNDER THE APPI
This section applies to users in Japan and is provided under the Act on the Protection of Personal Information (個人情報の保護に関する法律). The business handling personal data is YoYo KK, Ltd., at the Tokyo address in section 1, together with YoYo LLC.
23.1 Purposes of use (利用目的)
We use personal information for the following purposes and no others without your consent or a legal basis:
- to register, authenticate and administer your account, and to check that you are 18 or over;
- to display your profile and content to other users as you have chosen;
- to operate matching, the Venue Board, Collections, the YoYo Calendar, Quick Date, and the Square;
- to deliver chat messages;
- to operate Butterfly Mode, including pseudonymous profiles, same-country matching, voice matches and party rooms;
- to make restaurant and venue reservations you request, including where a member of our team completes the booking by hand;
- to provide YoYo Date Coach and icebreaker suggestions;
- to provide venue search, maps and venue information;
- to send notifications you have asked for;
- to moderate content, investigate reports, operate blocks, prevent and act on abuse, impersonation and fraud, and enforce our Terms;
- to verify identity where you choose to be verified;
- to alert our own staff by email when a submission or a booking needs a person, as described in 6.24;
- to maintain, secure, debug and improve the app, including through crash diagnostics and usage analytics;
- to study the quality of matches we produce, using the pairing log described in 6.17;
- to respond to your enquiries, complaints and requests; and
- to comply with laws, regulations and lawful requests from public authorities.
23.2 Provision to third parties (第三者への提供)
We do not provide personal data to third parties for their own purposes without your consent, except where the Act permits or requires it: where required by law; where necessary to protect a person's life, body or property and it is difficult to obtain consent; where specially necessary for public health or the sound upbringing of children and it is difficult to obtain consent; or where cooperating with a national or local government body performing statutory functions and obtaining consent would impede that performance. Provision to the providers listed in section 13 is entrustment of handling (委託) within the scope of the purposes of use, not third-party provision, and we supervise those providers under contract. We do not use joint use (共同利用) arrangements other than between YoYo LLC and YoYo KK, Ltd., which jointly use all of the categories in section 6 for the purposes in 23.1 under the joint responsibility of YoYo KK, Ltd. for users in Japan.
One provision to a third party does occur, and only at your request: when you ask us to make a reservation, we provide the name used for the booking, a contact telephone number, an email address, the party size, the requested date and time, and any dietary or allergy note to the venue, or to the booking platform that venue uses, so that the venue can hold and confirm your booking. The venue then handles that information for its own purposes under its own practices. Your use of YoYo Reservations is the consent for that provision, and you can avoid it entirely by contacting the venue yourself instead. We keep records of provision to third parties as the Act requires, and you may request disclosure of those records under 23.5.
23.3 Provision to third parties in foreign countries (外国にある第三者への提供)
From the moment you create your account, the personal data in our database is stored and processed in the United States of America, the files you upload are stored in Japan, and our backend functions process your personal data in Taiwan. Our database is located in the United States; there is no copy of it in Japan. Section 14 explains these locations, including the Firebase services that may process data in other countries, and 23.7 describes the regime in Taiwan. The recipients are:
- Google LLC (United States) - Firebase Authentication, Cloud Firestore, Cloud Storage, Cloud Functions, Google Analytics for Firebase, Firebase Cloud Messaging, App Check, Remote Config, Cloud Logging, and Google Maps and Places.
- OpenAI, L.L.C. (United States) - content moderation, YoYo Date Coach, icebreaker suggestions.
- Agora, Inc. (United States) - real-time voice transport, which may route through servers in the region nearest the participants.
- Apple Inc. (United States) - Sign in with Apple, push delivery, and the on-device geocoding that receives your coordinates.
- Expo, Inc. (United States) - over-the-air app updates and relay of push notifications, including their contents.
- Resend, Inc. (United States) - delivery of the staff alert emails described in 6.24, which contain your name, account email address and account identifier.
- Browser Use, Inc. (United States) - the automated browser that completes venue booking forms, which receives the booking name, telephone number, email address, venue, date, time, party size and any dietary note, and only when you ask for a booking.
- YoYo LLC (United States) is also a joint controller.
Separately, where you ask us to make a reservation at a venue outside Japan, the booking details described in 23.2 are provided to that venue in the country concerned.
Information about the data protection regime of the United States: the United States has no single comprehensive national personal data protection law and no independent national data protection supervisory authority of general jurisdiction. Protection derives from Federal Trade Commission enforcement against unfair and deceptive practices, sector-specific federal statutes, and comprehensive state privacy laws, principally the California Consumer Privacy Act as amended, which applies to YoYo LLC and is enforced by the California Privacy Protection Agency and the California Attorney General, and equivalent laws in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Maryland and other states. Those laws provide rights of access, correction, deletion, portability and opt-out broadly comparable in kind, though not identical in scope, to the rights under the Act on the Protection of Personal Information. United States public authorities may in some circumstances obtain access to data held by United States companies under legal process.
Measures taken by the recipients: each recipient is bound by a written data processing agreement restricting it to processing on our instructions and for our purposes; each is contractually obliged to maintain confidentiality and appropriate security; data is encrypted in transit and at rest; access is limited to authorized personnel; and each recipient maintains a published information security programme. We review these arrangements periodically and will take necessary action if a recipient's handling ceases to meet the required standard. You may request further information about these measures at the contact address in 23.6.
23.4 Personal-related information (個人関連情報)
Some identifiers we send to service providers - such as installation identifiers, device identifiers, session identifiers and push tokens - may constitute personal-related information rather than personal data in the recipient's hands. We do not provide personal-related information to any third party for the purpose of that third party linking it to a person as personal data, and we do not permit our providers to do so. We do not provide such identifiers to advertising networks or data brokers, because we use none. Note that our analytics events frequently carry your account identifier alongside the installation identifier, which means that, in Google's hands, that data is not merely personal-related; we treat it as personal data.
23.5 Requests for disclosure, correction and suspension of use (開示等の請求手続)
You may request disclosure of the purposes of use of your retained personal data, disclosure of the data itself including disclosure of records of third-party provision, correction, addition or deletion of inaccurate data, and suspension of use, erasure or suspension of third-party provision on the grounds permitted by the Act. You may also request that disclosure be provided electronically.
To make a request, write to support@yoyodatingapp.com with the subject "個人情報 開示等請求", or by post to YoYo KK, Ltd. at the address in section 1. State which request you are making and provide enough information for us to identify your account. We will verify your identity, normally by confirming that the request comes from the email address registered to the account together with one further account detail. A request may be made through a representative, who must provide written authorization from you; for a statutory representative, documents evidencing that status. We do not charge a fee for these requests. We respond without undue delay and normally within 30 days. As section 22 explains, disclosure is assembled by hand rather than produced by an automated export, which is why we ask for the full period. If we decline a request in whole or in part, we will tell you the reason.
Where you ask us to suspend use or erase data, we may decline to the extent the Act permits, in particular where retention is necessary to protect the life, body or property of a person. Section 17 explains the places where we rely on that: retained reports, retained blocks, and records that belong to another user as much as to you.
23.6 Complaints (苦情の申出先)
Complaints about our handling of personal information should be sent to support@yoyodatingapp.com, in Japanese or English, or by post to YoYo KK, Ltd., 566 Tensho Office Hamamatsucho Daimon, Eagle Hamamatsucho, 2-7-17 Hamamatsucho, Minato-ku, Tokyo 105-0013. We will respond in Japanese to Japanese-language complaints.
You may also make a complaint to the Personal Information Protection Commission (個人情報保護委員会), which supervises businesses handling personal information in Japan, at its published contact details.
23.7 Security control measures (安全管理措置)
We take the following measures:
- Organizational: defined responsibility for personal data handling; internal rules on handling, access and incident response; a route for reporting incidents to management; periodic review of handling.
- Human: confidentiality obligations on personnel and contractors; instruction on handling personal data; access limited to those whose role requires it.
- Physical: personal data is not held on portable media in the ordinary course; devices used to access production data are access-controlled and screen-locked.
- Technical: server-side enforcement of database and storage rules; server-only writes to protected, moderation and verification fields; denial of client reads on reports, anonymous authorship records, the Butterfly identity mapping and the crash store; encryption in transit and at rest; per-user rate limiting on backend functions; application attestation through Firebase App Check, which is implemented but not yet enforcing, as section 18 states.
- Known weaknesses under remediation: a legacy access default still grants read and write access to some collections to any signed-in user, and the user record is readable by any signed-in user. Section 18 sets this out in full. We consider disclosing this more useful to you than describing an ideal state.
- External environment: personal data is held in the United States, where our database is located, and in Japan, where the files you upload are stored, and it is processed in Taiwan, where our backend functions run. Some of the Firebase services named in section 13 may also process data in other countries where Google has data centers, and Google does not tell us in advance which ones. The measures we take in respect of the data protection regime of the United States are described in 23.3. Taiwan has a comprehensive national law, the Personal Data Protection Act, which governs the collection, processing and use of personal data by businesses and gives individuals the right to inquire about and review their data, to obtain copies, to have it supplemented or corrected, to have its collection, processing or use stopped, and to have it deleted. We take the measures in this section with that regime in mind.
23.8 Retention of retained personal data (保有個人データ)
Retention periods and the criteria we apply are set out per category in section 6 and summarized in section 10.
24. JAPAN: INFORMATION TRANSMITTED FROM YOUR DEVICE TO OUTSIDE PARTIES
This section is provided under the external transmission rules of the Telecommunications Business Act (電気通信事業法の外部送信規律). It tells you which outside parties the app causes your information to be sent to, what is sent, and why. Where information reaches a party by way of our own backend rather than directly from your device, we list it anyway, because what matters to you is where it ends up.
Google LLC - Firebase Authentication, Cloud Firestore, Cloud Storage, Cloud Functions and App Check. Sent: your account identifier and authentication token, the content of the requests you make and the data you create or read, your photos and videos when you upload them, device and app version information, and an App Check attestation token. Purpose: to run the app.
Google LLC - Google Analytics for Firebase. Sent: an installation identifier, your account identifier, device model, operating system version, app version, language, region, and event records describing which screens and features you use, plus crash and error diagnostics. Purpose: to measure how the app is used, to find and fix faults, and to improve the product. Not used for advertising and not shared with advertising networks. There is no in-app switch to stop this.
Google LLC - Firebase Cloud Messaging. Sent: your push token and device information. Purpose: to deliver push notifications you have asked for.
Google LLC - Firebase Remote Config. Sent: an installation identifier, app version and device information. Purpose: to deliver configuration to the app without an update.
Google LLC - Google Maps and Google Places. Sent, directly from your device: your coordinates when you have granted location permission, your venue search terms, the map area you are viewing, and place identifiers. Purpose: to display maps and to return venue results, venue details and venue photographs in Guide Mode.
Apple Inc. Sent: for Sign in with Apple, the authentication request and the credentials you approve; for push notifications, the notification payload and your device token; and, for geocoding, your raw coordinates, which the operating system's geocoder resolves into a city and country name. Purpose: authentication, notification delivery, and turning coordinates into a place name.
Expo, Inc. (Expo Application Services), United States. Sent: on each launch, your installation and runtime identifiers, app version, platform and device model, so that the app can check for and download an over-the-air update; and, for push notifications, the Expo push token issued to your installation together with the contents of the notification, which Expo relays to the Apple and Google push services. In Guide Mode that content includes the first 40 characters of the message that triggered the notification. Purpose: to deliver app updates and push notifications.
OpenAI, L.L.C. Sent, by way of our backend: your profile free text and handle, your Guide Mode profile photographs, the text and images of the posts you submit in the Square, your comments, your party room chat, your party room titles, the poster frames of videos you submit, the text of your Venue Board posts, the text of the private messages you send in either mode, the messages you send to YoYo Date Coach, and, for icebreaker suggestions, the interest tags and planets of the two participants and the recent messages of that conversation. Images are sent as a link that OpenAI fetches itself. Purpose: automated content moderation, the YoYo Date Coach advisor, and Butterfly Mode icebreaker suggestions. Your email address, date of birth, phone number, identity document and coordinates are not sent. Images inside a private chat are not sent.
Agora, Inc. Sent: the voice channel name, the numeric participant identifier we mint for the session, an access token, connection and network quality information, and your live audio stream while you are speaking in a voice match or on a party room seat. Purpose: to carry real-time voice between participants. The audio is not recorded by YoYo.
Resend, Inc., United States. Sent, by way of our backend and only when a triggering event occurs: for an ID verification submission, your name, your account email address and your account identifier; for a failed booking, your name, your account email address, your account identifier, the venue and the requested slot; for a new crash signature, the error and the screen. Purpose: to email the YoYo staff who have to act on it. Your identity document image is never sent.
Browser Use, Inc., United States. Sent, by way of our backend and only when you ask us to make a reservation: the first name, last name and full name on your account, your telephone number, your reservation email address, the venue and its booking page, the date, the time, the party size and any dietary or allergy note you have saved. Purpose: to run the AI-driven automated browser that completes the venue's own booking form on your instruction. It is instructed never to enter payment-card details.
Venues and their booking platforms. Sent, by way of our backend or of the automated browser and only when you ask us to make a reservation: the name used for the booking, a contact telephone number, an email address, the party size, the requested date and time, and any dietary or allergy note. Purpose: to hold and confirm your booking. Unlike the parties above, a venue is not processing on our behalf; see section 13.
You can stop some of these transmissions by not granting or by revoking the relevant permission in your device settings - location, microphone, photos, notifications - by turning notifications off in the app, or, in the case of venues, by not using YoYo Reservations. Transmissions to Firebase Authentication, Cloud Firestore, Cloud Storage, Cloud Functions and App Check cannot be switched off while you use the app, because they are the app. Transmission to Google Analytics for Firebase cannot currently be switched off either, as 6.19 explains.
25. JAPAN: 18-AND-OVER AND PROHIBITED SOLICITATION
YoYo is for adults aged 18 and over. Age is checked by date of birth at sign-up, and identity verification with a government-issued document is available and optional. YoYo has not filed a notification as an internet dating service provider under the Act on Regulation on Soliciting Children by Using Opposite-Sex Introduction Services on the Internet, and this policy does not claim otherwise.
Soliciting a minor is prohibited. So is any posting or message that solicits sexual conduct in exchange for money or other consideration, including compensated dating (援助交際), or that offers or seeks prostitution or any other unlawful sexual service. Accounts that do this are terminated and reported to the authorities where required. If you believe a user is a minor, report the account immediately through the in-app reporting tool or at support@yoyodatingapp.com.
26. AGE REQUIREMENT AND MINORS
YoYo is an adult service. You must be 18 or older to create an account.
Here is exactly what we do, stated precisely, because "we verify every user is 18 or over" would not be true and we are not going to write it. We require a date of birth at sign-up. We check that date of birth against the 18-year threshold, and an account whose date of birth resolves to under 18 is blocked from the service, including from Butterfly Mode, which reuses the same date of birth rather than asking again. Where an older account has no readable date of birth on file, our check returns "unknown" and allows access rather than locking out an adult over a missing field. That is a deliberate choice about legacy accounts, and it means our gate is a date-of-birth check, not a proof of age. Optional identity verification with a government document is the stronger check, and it is available to anyone who wants it.
YoYo is not directed to children, we do not knowingly collect personal information from anyone under 18, and the United States Children's Online Privacy Protection Act does not apply to us because we do not operate a service directed to children under 13.
If we learn that an account belongs to someone under 18, we terminate that account and delete the personal information associated with it, retaining only the minimal record needed to prevent the same person re-registering and to comply with any reporting obligation. If you are a parent or guardian and believe a minor has created an account, write to support@yoyodatingapp.com with enough detail to identify the account and we will act on it as a priority.
27. APPLE APP STORE PRIVACY LABELS
Apple requires us to summarise our data practices on the App Store product page. Those labels are a summary; this policy is the detail, and where the label is coarser than the truth, this document governs.
Data used to track you: none. We do not link your data to data from other companies' apps and websites for advertising or measurement, and there is no tracking SDK in the app.
Data linked to you: contact information (name, email address, phone number); user content (photos, videos, posts, comments, messages, audio in the sense that live voice passes through, and other user content); identifiers (account identifier, device identifier, installation identifier); usage data (product interaction); diagnostics (crash data, performance data, and the breadcrumb trails described in 6.20); location (precise and coarse); health and fitness, only to the extent your dietary or allergy note qualifies; sensitive information (sexual orientation, as inherent in a dating profile, and government identity document); purchases: none; financial information: none; contacts: none; browsing history: none; search history, only in the sense of the venue searches you run.
Data not linked to you: none that we claim, because almost everything in YoYo is attached to your account. We would rather over-declare here than under-declare.
28. CHANGES TO THIS POLICY
We update this policy when what we do changes, and also when we discover that what we previously wrote was not accurate. When we make a material change - a new category of personal information, a new purpose, a new recipient, or a change that reduces your rights - we will tell you before it takes effect, by an in-app notice and, where appropriate, by email to the address on your account, and we will give you the opportunity to review it. For changes that require your consent under applicable law, we will ask for it rather than assume it from continued use. Non-material changes, such as clarifications and corrections, take effect when posted.
Several things in this policy are described as not built yet or not yet enforcing: a purge step for the crash-signature store, an automatic purge for uploaded identity documents, a block control and an unhide control in Guide Mode, a self-service data export, an in-app analytics switch, App Check enforcement, and the closing of the legacy access default described in section 18. We will update this policy and bump its version when each of those changes, rather than quietly leaving stale text in place.
The current version number and effective date are at the top of this document.
29. CONTACT
Questions, complaints, privacy rights requests, requests for a copy of your data, reports of objectionable content or abusive users, requests to remove content that infringes your rights, and requests to delete your account from outside the app:
support@yoyodatingapp.com
YoYo LLC
453 S Spring St STE 400, PMB 1290
Los Angeles, CA 90013, United States
YoYo KK, Ltd.
566 Tensho Office Hamamatsucho Daimon, Eagle Hamamatsucho
2-7-17 Hamamatsucho, Minato-ku, Tokyo 105-0013, Japan
We reply in English and Japanese.
30. WHAT WE CORRECTED IN THIS VERSION
We rewrote this policy by going back through the software and checking every factual claim against what the code actually does. The following statements in the previous version were wrong, and we are listing them rather than quietly replacing them.
- We said OpenAI does not receive comments or party room titles. It does, and always has. Both are submitted for automated moderation. See 6.16 and section 11.
- We said we do not build or keep a location history trail. We do. A dated log of coordinates is written and kept. See 6.6.
- We did not mention Resend or the staff alert emails at all. An ID verification submission and a failed booking each send your name and account email address to a small list of staff addresses through a third-party email service. See 6.24.
- We did not mention the crash-signature store at all, and it is not reached by account deletion. See 6.20.
- We said date plans stay in the app after deletion, stripped of your name, photographs and profile. Both halves were inaccurate: a plan that is only yours is now deleted outright, and a shared plan keeps your account identifier on it rather than having it stripped. See 6.27.
- We described our security without saying that a legacy access rule leaves your account record - including your coordinates, date of birth, phone number and email address - readable by any signed-in user. See section 18.
- We said App Check confirms that a request came from a genuine copy of the app. It is implemented but not currently enforcing. See section 18.
- We described reports as records of what was reported, without saying that an automatically generated report includes up to the first 1500 characters of the message text itself. See 6.23.
- We said the deletion reason you give is retained separately from your profile for up to twenty-four months. In fact it is sent to Google Analytics as an event, tied to the analytics identity of your installation. See 6.19.
- We offered an in-app analytics posture we do not have. There is no analytics switch. See 6.19.
- We did not name Apple as a recipient of your raw coordinates, which it receives through the on-device geocoder. See section 13.
- We described videos as up to 30 seconds. The current limit is one hour, which makes the poster-frame-only moderation limit more significant, not less. See 6.4 and section 11.
- We described the 18+ gate without saying that an account with no readable date of birth is allowed through rather than blocked. See section 26.
- We described Guide Mode's Hide User without saying that it cannot be undone from inside the app. See section 5.
- We said our database, storage and backend functions were all in the United States. Our database is, but the files you upload are stored in Japan and our backend functions run in Taiwan. See section 14.
None of these corrections change what YoYo does. They change what we told you about it, which is the part we control, and getting it wrong is the thing we most wanted to fix.