Skip to content
Yito.ai

Privacy Policy

Read how yito collects, uses, stores, shares, and protects personal data across its AI creative workspace, account, payments, analytics, and support.

Last updated: 2026-07-27

Contracting operator
Mindepy, LLC
Registered address
131 Continental Dr, Suite 305, Newark, DE 19713, New Castle County, United States
Governing jurisdiction
Delaware, United States

Scope and Controller

This Policy explains how the contracting operator identified above processes personal data when you visit yito.ai, create an account, generate or publish content, connect a commerce service, pay, contact support, or join an organization. Privacy requests can be sent to contact@yito.ai.

Data We Process

Depending on the features you use, we process:

  1. Account and organization data — name, email, authentication status, roles, memberships, preferences, and security events.
  2. Prompts, uploads, and outputs — text, product URLs, images, video, audio, faces, voices, brand material, generated media, settings, and related metadata. This material may contain personal or biometric characteristics even though yito does not use it to uniquely identify a person.
  3. Generation and provider records — model, task and callback identifiers, status, cost and credit estimates, consent snapshot, failure codes, and technical records required for delivery, reconciliation, and abuse investigation.
  4. Commerce connections — merchant identifiers, encrypted authorization credentials, imported catalog records, and approved publishing results.
  5. Billing data — order, subscription, credit, amount, currency, status, provider reference, refund, and limited method metadata. Hosted payment providers receive full payment details; yito does not store full card numbers.
  6. Device, log, and attribution data — IP address, browser and device information, timestamps, requested pages, diagnostics, cookie or session identifiers, referring page, and campaign parameters.
  7. Support and safety data — messages, authorization evidence, reports, appeals, fraud signals, and actions taken.

We receive data from you, authorized organization members, connected services, authentication and payment providers, AI providers, and ordinary service telemetry.

Why We Process Data

We process data to perform the service contract; authenticate and protect accounts; route, store, and deliver generations; calculate and reconcile credits and provider costs; operate payments, subscriptions, collaboration, publishing, and support; prevent fraud, infringement, and harmful AI use; comply with law; and improve reliability and product experience.

Where applicable, the legal basis is performance of a contract, compliance with law, legitimate interests in operating and protecting the service, or consent. You may withdraw consent for future processing, but withdrawal does not make earlier processing unlawful.

AI Providers and Other Recipients

The selected workflow can send prompts, uploads, settings, callback identifiers, and required technical metadata to the configured AI provider. The current code supports provider adapters for Kie, WaveSpeed, fal, and Replicate, plus OpenRouter for limited analysis features. Provider availability and routing can change; only the data required for the selected operation should be sent.

We may also disclose necessary data to hosting, storage, database, authentication, email, analytics, support, commerce, fraud-prevention, and payment providers; authorized members of your organization; a recipient you choose through a public link or connected channel; professional advisers; or authorities when legally required. We do not sell personal information.

Some recipients may process data in another country. Where required, we use an appropriate transfer mechanism and supplementary safeguards.

Visibility, Storage, and Retention

New signed-in generations are private by default. A private artifact requires owner authorization and uses private, no-store responses. If you deliberately make an artifact public or share a public link, others may access or redistribute it.

Prompts, tasks, outputs, provider identifiers, consent snapshots, billing evidence, and audit records are retained for service delivery, security, disputes, reconciliation, and legal obligations. Account closure redacts or anonymizes eligible active account and generation data, while necessary billing, fraud, audit, dispute, backup, and legal records may remain for their required period. We delete or anonymize data when it is no longer needed, subject to backups and legal holds.

Security and AI Provenance

We use access controls, encryption in transit, encrypted storage for supported credentials, authorization checks, audit records, and operational monitoring. No internet service can guarantee absolute security.

Generated media responses identify the content as AI-generated and link to a permission-matched machine-readable provenance sidecar. The current sidecar is not an embedded content credential and is not cryptographically signed. Do not treat it as proof of identity, consent, ownership, or authenticity.

Cookies, Analytics, and Communications

Essential storage supports security, sessions, language, and product state. Optional analytics and support tools follow the choices and configuration described in the Cookie Policy. Transactional messages cover sign-in, security, billing, and support. Marketing messages, when enabled, include an unsubscribe route where required.

Your Choices and Rights

Depending on your location, you may request access, correction, deletion, restriction, objection, portability, consent withdrawal, or review of a decision. You can manage some account, visibility, billing, and cookie settings in the product. Send other requests to contact@yito.ai from the account email and describe the request. We may verify identity and retain a minimal record of the request.

You can also report an unauthorized face, voice, avatar, impersonation, privacy violation, or other harmful content. Include the exact yito URL or artifact identifier and supporting evidence without sending unnecessary sensitive data.

Children

yito is not directed to children, and users must be at least 18 or the legal age of majority where they live. Do not submit a minor's face or voice for cloning, face swap, synthetic performance, or sexualized content.

Changes and Contact

We may update this Policy when the service, providers, or law change. Material changes will be identified by the updated date and, where appropriate, an in-product or email notice.

Questions, rights requests, or safety reports can be sent to contact@yito.ai.