Yoloproof

Privacy policy

Last updated October 5, 2026

1. Who we are

This policy covers the Yoloproof website and service ("we", "us"). For questions about your data or to use your rights, write to hello@yoloproof.com.

2. What we keep

  • Your account: your email address, a hash of your password (never the password itself), your role in each account and your display settings.
  • Sign-in sessions: the IP address and browser of each signed-in session, so you can stay signed in and we can spot misuse.
  • Activity: a log of what changed in your account and who changed it, including changes made through API or MCP tokens. We store only a hash of each token.
  • What you test: the apps and environments you register, specs, tests, the test logins you give us (encrypted), run results, and screenshots, videos and traces of your app. These show whatever your app shows, which can include personal data in your app. Passwords and secret headers are removed from traces before we keep them.
  • Connected tools: when you connect Linear or GitLab, the access you grant and the ticket and merge request details the service reads.
  • Server logs: IP address, browser and the page requested, kept for a short time to run and protect the service.

3. Why we use it

  • To provide the service you signed up for: run your tests, show results, keep your account working (performance of a contract).
  • To keep the service and other people safe, find misuse and fix errors (legitimate interests).
  • To send emails you need, such as password resets, and the notes you choose to receive.

We do not sell your data, show ads, or use your content to train AI models.

4. Who else processes it

  • Hosting: Hetzner Online GmbH, on servers in the European Union.
  • AI providers (Google, Anthropic, OpenAI): only when AI features are turned on for your account, and only the content a feature needs, such as a page snapshot or a failed step.
  • Tools you connect, such as Linear and GitLab, receive what the service writes to them for you.

If one of these providers is outside the European Economic Area, the transfer is covered by the EU standard contractual clauses or an adequacy decision.

5. How long we keep it

  • Account and test data: while your account exists.
  • Screenshots and videos of runs: deleted after 30 days, except the ones kept as the evidence for a ticket.
  • When you delete your account, or ask us to, we delete its data from the service within 30 days, and from backups when they rotate out.

6. Cookies

We use cookies only to keep you signed in and to protect forms against forgery. Your light or dark theme choice is kept in your browser's local storage. There are no analytics, advertising or tracking cookies.

7. Your rights

You can ask for a copy of your data, ask us to correct or delete it, object to how we use it, or ask us to limit it, and you can take your data to another service. Write to hello@yoloproof.com; we answer within one month. You can also complain to the data protection authority where you live.

8. Security

Traffic is encrypted with TLS. Test logins and other secrets are encrypted in the database. Only a few people can reach the servers, with SSH keys only.

9. Changes

We may update this policy. The date at the top shows the last change. For a significant change, we tell account owners before it takes effect.