Skip to content

Legal

Privacy Notice

Yogfile is designed around pseudonymous accounts and data minimization. This Notice explains what that means in practice, what our infrastructure providers receive, and the choices and rights available to you.

Effective
19 August 2026
Version
2.0
In this document

No advertising profile

We do not sell personal data, display behavioral advertising, use cross-site analytics, or use files to train a general-purpose AI model. A pseudonymous account still processes personal data when files, names or activity can relate to a person.

01Who we are

Yogfile is operated by SYFRAH CONSULTING, a company incorporated under French law, registered under SIREN number 953 278 553, with its registered office at 229 rue Saint-Honoré, 75001 Paris, France. SYFRAH is the data controller for the processing described in this Notice unless section 10 says that we act as a processor.

Privacy questions and rights requests may be sent to privacy@yogfile.com. Do not send your complete account number, MFA secret or recovery codes by email.

02Our privacy model

Yogfile does not require a name, email address or third-party identity provider to create an account. The account is identified by a randomly generated 16 digit credential. This reduces the identity data we collect, but it does not make the account or its activity anonymous.

The server stores a keyed blind index of the account number and its last four digits, not the complete number. The complete number is sent to the API when you sign in and may be kept locally by the web app or native application so that you can retain access.

03Data we process

  • Account and authentication data: the keyed account index, last four digits, plan, timestamps, sessions, encrypted MFA secret, hashed recovery codes, and authorized-device hashes, labels and expiry dates.
  • Files and drive metadata: content, names, folders, size, declared type, content hash, lifecycle dates, versions, previews, ownership references and sharing settings.
  • Usage data: stored bytes, uploads, signed-link records, aggregate view and download counters, and limits consumed.
  • Network and security data: an IP address held temporarily for rate limiting, pseudonymized report identifiers, request timestamps, routes, status codes, technical errors and security events. We do not attach raw IP addresses to account or file records.
  • Communications: information you choose to send to support, privacy or abuse contacts, including your email address and evidence attached to a request.
  • Third-party data: personal data that you or an authorized agent place in a file, file name, drive name or public link.

For account-creation rate limiting, an IP address may remain in volatile memory for up to one hour. An abuse report stores a keyed, pseudonymized identifier derived from the IP so the same source cannot repeatedly report the same file. Pseudonymization reduces risk but is not the same as anonymization.

04Why we process data and our legal bases

PurposeLegal basis
Create accounts; authenticate; store, synchronize, preview, share and retrieve filesPerformance of our contract
Apply rate limits; secure accounts; prevent fraud and abuse; defend legal claimsOur legitimate interests and those of users
Measure capacity and service operation through proportionate counters and monitoringOur legitimate interest in operating Yogfile
Respond to lawful orders and regulatory dutiesCompliance with a legal obligation
Answer a support or rights requestContract, legitimate interest or legal obligation, depending on the request

Where we rely on legitimate interests, we consider the need for the processing, its effect on users and the safeguards available. You may object as explained in section 11.

05Files, storage and public links

File contents are protected in transit and stored through the Nauka storage system using content addressing and erasure coding. Erasure coding improves resilience; it is not encryption. Yogfile is not end-to-end encrypted, and authorized SYFRAH personnel can technically access content where necessary to operate the Service, investigate abuse, comply with law or provide support. Encrypt a sensitive file before uploading if the operator must not be able to read it.

A Yogfile file URL is a capability link. Anyone who obtains it may view public metadata, download the file and share the link or a copy. Yogfile does not provide a public directory or cross-account search, but that does not make a shared link private. Copies made by recipients remain outside our control.

A public-page view and a download increment aggregate counters attached to the file. Those counters are not associated with the viewer's account, IP address or device by Yogfile.

06Browser storage and connected clients

We do not use advertising cookies or cross-site analytics. The web app uses browser storage strictly necessary for account access: the complete account number and four-digit display suffix may remain in local storage until you choose “Forget this account” or clear site data; a session token is kept in session storage and expires within 24 hours; and an authorized-device token may remain in local storage for up to 90 days.

The Yogfile MCP connector does not maintain a user database. Authorization codes, refresh tokens and client registrations are encrypted, and access tokens are short-lived Yogfile sessions. When the connector uploads for you, bytes pass through it on the way to storage and are not retained there. We do not receive or store your AI conversation unless you deliberately place it in a file.

When you connect an AI client or another third-party application, that service receives data and credentials at your direction. Its own terms and privacy notice apply, and you should revoke its access when no longer needed.

07Operational monitoring

We use a restricted Discord channel to monitor service operation and aggregate usage. Each completed upload generates an operational notification containing only the completion time, file size, declared content type and upload channel, such as the web app, HTTP API, MCP connector or Finder. It does not contain the account number, IP address, file contents, file name, drive name or public URL.

Once a day, we send aggregate totals, including numbers of accounts, active drives, uploads, active files, stored bytes, public-page views and downloads. The report may also include the file name, drive name and view count of up to five files whose public metadata page has already been viewed. Sequences resembling a 16 digit account number are masked before sending. User-chosen names may still contain personal data, so never place a secret in a file or drive name.

Monitoring events first enter a durable delivery queue. Successfully delivered queue records are removed after 90 days; an event not yet delivered remains while delivery is retried. Access to the Discord channel is restricted. Delivered messages are reviewed and removed when no longer needed for operational investigation, normally within 90 days. We do not use this information for advertising or individual profiling.

08Recipients, providers and international transfers

Personal data is accessible to authorized persons who need it to operate, secure, support or lawfully administer Yogfile. Our current principal providers are:

Cloudflare, Inc.Website delivery, network security and edge infrastructureMay process data outside the EEA
Hetzner Online GmbHEuropean compute, API and storage-node infrastructureEuropean Economic Area
Discord, Inc.Restricted operational monitoring channelMay process data outside the EEA

Providers act under their applicable contractual and data-protection terms. Where personal data is transferred outside the European Economic Area, we rely on an applicable adequacy decision or appropriate safeguards such as the European Commission's Standard Contractual Clauses, with supplementary measures where required. You may request information about the safeguard relevant to your data from privacy@yogfile.com.

We may also disclose data where required by law, a valid binding order, or where necessary to protect a person's vital interests or establish, exercise or defend legal claims. We do not provide voluntary bulk access to user files.

09Retention and deletion

  • Active files: until you delete them or the lifecycle period you chose expires.
  • Trash and replaced versions: normally 30 days unless you purge them sooner.
  • Incomplete uploads: normally removed after 24 hours.
  • Database recovery snapshots: up to seven days.
  • Sessions and devices: sessions expire within 24 hours; device authorizations expire after 90 days.
  • Signed-link records and view/download counters: attached to the file record and removed when that file is permanently deleted, subject to legal retention.
  • API service logs: normally 14 days on the API host; infrastructure providers may retain their own security logs under their documented policies.
  • Abuse reports: retained while needed to investigate the report, prevent repeat submissions, defend decisions and meet legal duties. The pseudonymized reporter identifier may remain attached to the report until the related file record is deleted.
  • Accounts and drives: until you request deletion or we lawfully close the account. We do not currently delete an account merely because it is inactive.

A permanent deletion may be delayed where data must be preserved to comply with law, a binding order, security or fraud investigations, or the establishment or defence of legal claims. We restrict the preserved data and delete it when the reason ends.

10When we are a controller and when we are a processor

SYFRAH acts as an independent controller for account credentials, service usage, authentication, security, abuse prevention, support and operational metrics.

Where a business customer uploads personal data for its own purposes, that customer is the controller of the data inside its files and SYFRAH processes it on the customer's documented instructions, subject to the Service and an applicable data processing agreement. Business customers that need an agreement under Article 28 GDPR may contact privacy@yogfile.com before uploading regulated personal data.

11Your data-protection rights

Subject to the conditions and exceptions provided by law, you may request access, rectification, erasure, restriction and portability of personal data, and object to processing based on our legitimate interests. Where processing relies on consent, you may withdraw it without affecting earlier lawful processing.

Because Yogfile does not ask for your civil identity, the safest way to exercise rights relating to an account is through an authenticated Yogfile session. You may also email us, but do not disclose the complete account number. We may ask for proportionate information necessary to verify control of the account and will not request an identity document where account authentication is sufficient.

If data cannot be linked to an identifiable person, we are not required to collect extra identifying information solely to answer a request. You may provide information that lets us locate it. You may lodge a complaint with the French data-protection authority, theCNIL, or another competent supervisory authority.

12Security, incidents, children and changes

We use measures designed to protect personal data, including encrypted transport, restricted service permissions, keyed account indexes, hashed recovery credentials, encrypted MFA secrets, short-lived sessions and limited-retention recovery snapshots. No service can guarantee absolute security. You remain responsible for protecting account credentials, MFA factors, recovery codes and public links.

We document personal-data breaches and notify the competent authority and affected people where required by law. Because Yogfile does not ordinarily hold contact details, we may use a prominent in-service or public notice where direct communication is impossible and the law permits it.

Yogfile is not directed to persons under 18 and we do not knowingly invite children to create accounts. Contact us if you believe a child has provided personal data through the Service.

We may update this Notice to reflect changes in the Service, providers or law. We will identify the new version and effective date and provide prominent notice of a material change where reasonably possible.

Privacy contact

SYFRAH CONSULTING
229 rue Saint-Honoré, 75001 Paris, France
privacy@yogfile.com

See also the Terms of Service and Abuse and Content Notices policy.