Yaqut Privacy Policy
Version 1.0 · Effective date: August 12, 2026 · Last updated: August 12, 2026
Yaqut ("Yaqut", "we", "us") is a creator operating system operated by Yaqut. This Privacy Policy explains what information we collect when you use Yaqut at yaqut.ai and related services, how we use it, who we share it with, and the choices you have. If you do not agree with this policy, please do not use Yaqut.
1. Scope
This policy covers the Yaqut web application, the Yaqut API, public viewer pages (such as watch links and overlays), and transactional emails we send. It does not cover the independent practices of third-party platforms you connect to Yaqut (such as YouTube or Instagram) — those are governed by each platform's own privacy policy.
2. Information you provide
- Account information. Email address, display name, password (stored only as a salted bcrypt hash — we never store or log your plaintext password), interface language, and workspace/organization names.
- Creator workspace information. Organizations, team memberships and roles, creator profiles managed inside a workspace, and settings you configure.
- Uploaded content and media. Videos, images, audio, thumbnails, captions, titles, descriptions, hashtags, and drafts you upload or create in Yaqut.
- Livestream data. Livestream configuration, stream recordings where you enable recording, live captions, and live chat data processed during a session.
- Transcripts and translations. Transcripts generated from your audio/video, machine translations of your content, and language settings.
- AI dubbing and voice data. Audio generated for dubbing, and voice-consent records. Voice cloning features require an explicit, logged consent step, and generated audio carries an audio watermark.
- Legal acceptance records. The Terms and Privacy Policy versions you accepted, when, in which language, and a privacy-conscious hashed representation of request metadata.
- Payment-related records. If you receive tips through Yaqut, we store tip amounts, currencies, and fee records. Card details are handled by the payment provider, not stored by Yaqut.
3. Information from connected platforms
You can connect third-party accounts such as YouTube (Google), Instagram and Facebook (Meta), TikTok, and Twitch. When you connect an account, Yaqut receives only the data allowed by the permissions (scopes) you grant, which may include:
- account identity (channel/page/profile name, ID, avatar),
- content metadata and publishing status for content you publish through Yaqut,
- comments, replies, mentions, and messages where you grant engagement permissions,
- performance metrics (views, likes, comments, watch data) where you grant analytics permissions,
- livestream configuration such as ingest settings and stream keys where you grant live permissions.
OAuth access and refresh tokens, and stream keys, are encrypted at rest (AES-256-GCM) and are never returned to the browser or written to logs. Disconnecting an account in Settings → Connections deletes Yaqut's stored credentials and, where the platform supports it, requests token revocation at the provider. You can also revoke Yaqut's access directly in the platform's own security settings. Metrics a platform does not report are stored as absent — never fabricated.
4. Google API disclosure
Where you connect a Google/YouTube account, Yaqut accesses Google user data only through official Google APIs and only per the scopes you grant: channel identity, video upload/publishing you initiate, livestream management you initiate, comment reading and replies you send, and video statistics. This data is used solely to provide the Yaqut features you use, is encrypted at rest, is not sold, and is not used for advertising. Yaqut's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. You can revoke Yaqut's access at any time at https://myaccount.google.com/permissions or by disconnecting in Yaqut; stored Google credentials are deleted on disconnect.
5. Automatically collected information
We collect standard security and operations data: IP-derived request metadata, device/browser type, timestamps, request logs, and structured application events (for example "registration succeeded" or "publish job failed"). Authentication uses a signed token stored in your browser. Public viewer pages may process session data needed for live translation delivery. We do not run third-party advertising trackers.
6. How we use information
- to provide Yaqut: hosting, processing, transcoding, captioning, translating, dubbing (where you enable it), publishing to platforms on your instruction, engagement inbox, analytics, and team workflows;
- to generate AI-assisted output such as transcripts, translations, moment suggestions, engagement triage, suggested replies, and performance insights — suggestions are drafts for your review, and Yaqut does not autonomously publish externally without an instruction from your workspace;
- to operate safety features such as moderation and consent/watermark records;
- to secure the service: authentication, rate limiting, fraud and abuse prevention, and auditing of sensitive actions;
- to communicate with you: transactional email such as password resets;
- to improve the product using aggregate, de-identified usage patterns;
- to comply with legal obligations.
7. AI processing
Some features send the minimum necessary content to external AI providers to produce the feature's output (for example audio to a transcription provider, or text to a translation provider). This happens only when the feature is enabled and used in your workspace. We do not claim that these providers never see your content — they process it as our service providers to deliver the feature. Consult each provider's terms regarding their data handling; we configure providers for service delivery, and we do not sell your content.
8. Service providers (subprocessors)
Depending on the features you use, data may be processed by: Railway (hosting and databases), Amazon-S3-compatible object storage (media files), Deepgram (speech-to-text), DeepL (translation), ElevenLabs (speech synthesis / dubbing), OpenAI (AI analysis such as moment detection, triage, and suggestions), LiveKit (live media transport), Resend (transactional email), payment providers (tips, where enabled), and the social platforms you connect (Google/YouTube, Meta/Instagram/Facebook, TikTok, Twitch). Each provider receives only the data needed for its function.
9. Data sharing
We share personal data only: with the service providers above; with platforms you explicitly connect and publish to; within your workspace according to team roles (for example a manager you work with can see workspace content per their role); when required by law; or to protect Yaqut and its users from fraud or abuse. We do not sell your personal data.
10. Data retention and deletion
We retain data while your account is active and as needed to provide the service. You can delete individual content and media from your workspace. You can delete your account in Settings → Account: this permanently deletes your user record and, for workspaces where you are the only member, the workspace and its data. Where a workspace has other members, ownership questions are resolved before deletion — contact support@yaqut.ai. Backups and audit records required for security or legal compliance may persist for a limited period after deletion. Disconnecting a platform deletes stored credentials but does not delete content already published on that platform.
11. Data export
You can request an export of your account data (profile, workspaces, memberships, connection metadata, content metadata, legal acceptances, usage records) from Settings → Account. Exports never include passwords, OAuth tokens, or stream keys.
12. Security
We use industry-standard safeguards: TLS in transit, AES-256-GCM encryption of provider credentials and stream keys at rest, bcrypt password hashing, single-use hashed password-reset tokens, role-based access control on every workspace resource, rate limiting, and audit logging of sensitive actions. No system is perfectly secure; report concerns to support@yaqut.ai.
13. International transfers
Our infrastructure is hosted in the European Union (Railway, EU region), and service providers may process data in other countries, including the United States. Where required, we rely on appropriate safeguards for such transfers.
14. Your rights
Depending on your location (including the EEA/UK under GDPR and certain US states), you may have the right to access, correct, delete, export (portability), restrict, or object to the processing of your personal data, to withdraw consent where processing is based on consent, and to complain to a supervisory authority. Yaqut provides self-service tools for access, correction, deletion, and export; for anything else, contact support@yaqut.ai. We respond to verified requests within the timelines required by applicable law. Where we process data to provide the service you requested, the legal basis is contract performance; security and product improvement rely on legitimate interests; optional features such as voice cloning rely on your explicit consent.
15. Children
Yaqut is not directed to children and requires users to be at least 16 years old (or older where local law requires). We do not knowingly collect personal data from children; if you believe a child has created an account, contact support@yaqut.ai.
16. Third-party platforms
Connected platforms operate under their own terms and privacy policies. Yaqut does not control, and is not responsible for, the independent data practices of YouTube/Google, Meta, TikTok, Twitch, or any other connected service. Content you publish to a platform is governed by that platform's rules from the moment it is published.
17. Changes to this policy
We may update this policy. Material changes will be versioned, dated, and presented in the product; where required, we will ask for renewed acknowledgement. The current version is always available at yaqut.ai/privacy.
18. Contact
Operator: Yaqut
Email: support@yaqut.ai