legal · version 1.0
Privacy Policy
This policy explains, in plain English, how personal data is handled across yooi.me and Yooi services that link to this page.
Effective and last updated: 18 July 2026
Short version: only provide data you are comfortable using with the relevant service. Personal data is not sold or rented, and it is not used for cross-context behavioural advertising. Data is disclosed to service providers and others when needed to operate, secure, and support the services, as described below.
1. Scope, controller, and contact
This policy applies to the yooi.me portal and to any website, app, or other Yooi service that links to it (together, the “Services”). Yee Fei, based in Singapore, is the operator of yooi.me and the controller or organisation responsible for the personal data covered by this policy, except where an app-specific notice identifies another party or role. Yee Fei is also the public privacy contact and person responsible for data-protection matters for the Services.
A linked app may have an additional privacy notice because its data, providers, features, or legal obligations differ. That app-specific notice controls to the extent it conflicts with this general policy. Third-party sites and services reached through links have their own privacy practices.
Questions and privacy requests may be sent to yeefei@yooi.me with “Privacy request” in the subject line. Please identify the Yooi service involved, but do not email passwords, full payment-card numbers, identity documents, or other unnecessary sensitive data.
2. Personal data collected and where it comes from
The data involved depends on which Services and features are used:
- Account and identity data. Clerk provides authentication and session services. This can include an account identifier, email address, name, profile details, sign-in method, session information, and authentication or security events. Where central Yooi account features are enabled, Convex may hold a Clerk authentication identifier (authId), email, name, role, app-access records, service tier, and summary usage records.
- Contact and support data. The contact form collects an email address, message, and opportunity type. Submissions are transmitted through Resend and delivered to a Gmail inbox. Emails, support requests, feedback, and related correspondence are also processed.
- Service and transaction data. A linked app may process app settings, feature activity, plan or entitlement data, usage totals, payment or transaction references, and customer support history. Full card details are generally handled by the payment provider identified in the app-specific notice rather than by the portal.
- User content and AI data. Depending on the linked app, this can include files, text, images, audio, prompts, instructions, configuration, generated outputs, and feedback about those outputs. The app-specific notice describes its content and AI providers.
- Technical, device, and security data. Hosting, authentication, database, and security providers may automatically receive IP address, request and response metadata, date and time, referring and requested URLs, browser and device type, operating system, language, approximate location inferred from IP, cookie or session identifiers, performance diagnostics, and security logs.
- Video interaction data. A YouTube player is loaded only after a visitor selects play. YouTube then receives the IP address, browser/device details, the page and video requested, and interaction data under Google’s own terms. A YouTube-hosted thumbnail may be requested before play, which can reveal ordinary request data such as an IP address, but the embedded player is not loaded then.
Data comes directly from users; from their browser or device; from Clerk and other providers used to sign in or run a selected app; from payment, AI, and integration providers identified by that app; and from security or hosting systems that generate operational records. If someone supplies data about another person, they should have a lawful basis to do so and direct that person to the relevant notice.
3. Required and optional data—and what happens if it is not provided
- An email address and authentication data are required to create or use an account where sign-in is enabled. Without them, account-only features and cross-app access cannot be provided.
- An email address and message are required for the portal contact form so the enquiry can be understood and answered. The opportunity type has a default value and helps route the enquiry.
- Fields marked required in a linked app are needed to provide the requested feature, complete a transaction, satisfy security or legal checks, or administer an account. If they are omitted, that feature or transaction may not work. Other profile fields, integrations, feedback, and marketing choices are voluntary unless the app says otherwise.
- Browser controls can block strictly necessary cookies, but sign-in, fraud prevention, and account features may then fail. A visitor can decline to play an embedded YouTube video and use the rest of the page.
4. Why data is used and the relevant legal grounds
The grounds below apply where the relevant law requires a lawful basis. More than one ground can apply, and local law may describe the ground differently.
| Purpose | Data typically used | Ground, where applicable |
|---|---|---|
| Create accounts; authenticate; provide app access, features, outputs, support, and transactions. | Account, content, app access, tier, usage, transaction, and correspondence data. | Perform a contract or take requested pre-contract steps; consent where specifically requested. |
| Operate, troubleshoot, measure, and improve the Services and understand aggregate use. | Usage summaries, technical logs, diagnostics, feedback, and limited account or content data where needed. | Legitimate interests in operating and improving reliable services, balanced against user rights; consent where required. |
| Protect users and Services; prevent abuse, fraud, and security incidents; enforce terms. | Identity, session, request, device, usage, content flags, and security-event data. | Legitimate interests in safety and integrity; performance of a contract; compliance with legal obligations. |
| Respond to enquiries and communicate service, policy, billing, or security information. | Contact details, correspondence, account, app, and transaction references. | Requested pre-contract steps, contract performance, legitimate interests in support, or legal obligation. |
| Maintain records; handle disputes; exercise or defend legal claims; meet tax, accounting, regulatory, and lawful-request duties. | Relevant account, transaction, correspondence, content, and log records. | Legal obligation and legitimate interests in accountability and legal claims. |
| Send optional direct marketing where offered. | Name, email, preferences, and engagement data. | Consent where required; otherwise a permitted legitimate interest, always subject to applicable opt-out rights. |
Where processing relies on legitimate interests, those interests are assessed against the nature of the data, reasonable expectations, impact, and available safeguards. Where it relies on consent, consent can be withdrawn prospectively, without affecting processing already lawfully carried out.
5. When data is disclosed and who receives it
Personal data is disclosed only as reasonably needed for the purposes above, subject to appropriate contractual, technical, and organisational controls where required. Recipient classes include:
- Authentication providers: Clerk for account, session, and sign-in services.
- Database and backend providers: Convex where central account, access, tier, or usage features are enabled.
- Communications providers: Resend transmits contact-form email, and Google’s Gmail receives and stores it.
- Infrastructure providers: hosting, content-delivery, domain, monitoring, security, and error-diagnostic providers that process request, device, and operational data.
- Media providers: Google/YouTube after a visitor chooses to play an embedded video, as described above.
- App-specific providers: AI model, storage, analytics, integration, and payment providers identified in the linked app’s notice.
- Professional and institutional recipients: auditors, insurers, accountants, lawyers, and other advisers under duties of confidentiality; courts, regulators, law enforcement, or public authorities where disclosure is reasonably believed to be legally required or necessary to protect rights, safety, and integrity.
- Business-change recipients: a prospective or actual buyer, successor, financing party, or restructuring adviser, subject to confidentiality and applicable law. Users will be notified if a change materially affects how their data is controlled.
6. AI features and user content
Some linked apps may send prompts, files, instructions, or related context to an AI provider and return generated output. The app-specific notice should identify the categories of content and relevant providers, explain any material provider choices, and describe whether content is retained or used for model improvement where applicable.
Do not submit confidential business information, regulated records, special-category or sensitive personal data, another person’s data, or content a user lacks the right to provide unless the app explicitly supports that use and appropriate permissions and safeguards are in place. AI output can be inaccurate, incomplete, or reveal unintended information; it should be reviewed before use or disclosure. Reports of problematic output may be investigated using the relevant prompt, output, account, and technical records where available.
8. International data transfers
Yee Fei operates from Singapore. Providers and users may be located in other countries, so data can be processed outside the user’s state, province, or country, including in Singapore, the United States, and locations where the relevant provider maintains personnel or systems. Those places may have different privacy laws.
Where required, reasonable steps and recognised transfer mechanisms are used to protect transferred data. Depending on the route and law, these may include adequacy decisions, contractual commitments, Singapore PDPA comparable-protection obligations, the EU Standard Contractual Clauses, the UK International Data Transfer Addendum or Agreement, and supplementary technical or organisational measures. Details of the mechanism relevant to a user may be requested, subject to redaction of confidential and security-sensitive terms.
9. How long data is kept
Data is kept only for as long as reasonably needed for the purposes in this policy, then deleted or de-identified where practicable. No single period applies to every record. Retention decisions consider:
- whether an account or requested service remains active and the data is needed to provide it;
- the amount, nature, and sensitivity of the data and the risk of harm from unauthorised use;
- the time needed to answer an enquiry, provide support, investigate abuse, maintain security, or resolve a dispute;
- legal, tax, accounting, contractual, recordkeeping, limitation-period, and regulatory requirements;
- app settings, user deletion requests, and the retention practices described in an app-specific notice; and
- whether the purpose can instead be met with aggregated or de-identified data.
In practice, account and access records are generally needed while an account is active; app content is tied to the life of the requested feature and applicable app settings; contact correspondence is kept while an enquiry and reasonable follow-up remain relevant; and request, diagnostic, and security logs are kept for an operationally useful period based on security and troubleshooting needs. Transaction and legal records may need to remain longer. Deletion from live systems may not immediately remove restricted backup copies, and limited data may be retained to document a request, prevent fraud, meet law, or establish, exercise, or defend claims.
10. Security and personal-data incidents
Reasonable administrative, technical, and organisational measures are used according to the nature of the Service and data. These can include managed authentication, access controls, provider due diligence, encrypted transport, logging, data minimisation, software maintenance, and incident response. Users should protect their sign-in methods, use strong unique credentials, and report suspected misuse.
No internet transmission, software, or storage system is completely secure, so absolute security cannot be promised. If a personal-data breach occurs, it will be investigated, contained, and documented, and affected people and regulators will be notified when and within the time required by applicable law. Notices may describe the event, likely consequences, response measures, and practical protective steps, subject to security and law-enforcement constraints.
11. Privacy rights, requests, verification, and appeals
Depending on applicable law, a person may have rights to ask for access to or a copy of personal data; correction; deletion; restriction or objection; portability; withdrawal of consent; information about processing and recipients; or review of certain solely automated decisions. A person may also complain to a privacy regulator. These rights are not universal or absolute: identity, legal exceptions, other people’s rights, technical feasibility, and retention duties can affect the response.
Submit a request using the contact in section 1 and state the country or region, relevant Service, account email, right being exercised, and enough detail to locate the data. To protect users, reasonable verification may be requested—for example, signing in, replying from the account email, confirming recent non-sensitive account details, or providing limited additional evidence. Identity documents should not be sent unless specifically requested through an appropriate channel. An authorised agent may be asked for proof of authority and the user may be asked to verify directly, where allowed.
Requests will be answered within the period and without a fee required by applicable law. A reasonable fee or refusal may apply to manifestly unfounded, excessive, repetitive, or legally exempt requests where the law permits. If a request is denied, the response will explain the reason and any available internal appeal or regulatory complaint path. To appeal where applicable, reply to the decision with “Privacy appeal” and explain why it should be reconsidered. No one will be unlawfully discriminated against for exercising a privacy right.
12. Direct marketing and service messages
The contact form does not by itself enrol a person in marketing. If optional promotional email is offered, it will be sent only as permitted by applicable law and will include a way to unsubscribe. Consent-based marketing can also be stopped by contacting the address in section 1. Opting out of marketing does not stop necessary account, transaction, security, support, or policy messages.
13. Children
The Services are intended for people aged 18 or older and are not directed to children. Personal data is not knowingly collected from a child through the Services. A parent or guardian who believes a child has provided personal data should contact the address in section 1 so the circumstances can be reviewed and appropriate action taken.
14. Regional information
Singapore (PDPA)
For Singapore’s Personal Data Protection Act 2012, Yee Fei is the organisation responsible for the data described here. Data is collected, used, and disclosed for purposes a reasonable person would consider appropriate in the circumstances and on the basis of consent, deemed consent, legitimate interests, or another exception where the PDPA permits. This policy does not rely on deemed consent or an exception where express consent is legally required.
Individuals may request access to personal data in the organisation’s possession or control and information about its use or disclosure during the period provided by law, and may request correction. Consent may be withdrawn on reasonable notice, subject to legal or contractual consequences, which will be explained before the withdrawal is completed. Reasonable access fees may apply with advance notice where permitted. Overseas transfers are subject to steps intended to provide a standard of protection comparable to the PDPA. Concerns should first be sent to the privacy contact in section 1; unresolved concerns may be raised with Singapore’s Personal Data Protection Commission.
Malaysia (PDPA)
For individuals in Malaysia, the English sections of this policy and the Bahasa Malaysia notice below form the personal data notice for purposes of Malaysia’s Personal Data Protection Act 2010. The English and Bahasa Malaysia texts should be read together. If they are inconsistent, applicable law determines the effect of each version.
Notis Perlindungan Data Peribadi (Bahasa Malaysia)
Pengawal data dan skop. Yee Fei, yang berpangkalan di Singapura dan mengendalikan yooi.me, memproses data peribadi bagi portal yooi.me serta perkhidmatan Yooi yang memaut kepada notis ini. Notis khusus aplikasi akan terpakai jika terdapat percanggahan bagi aplikasi tersebut. Pertanyaan, permintaan akses atau pembetulan, dan aduan boleh dihantar ke yeefei@yooi.me.
Kategori data. Data yang mungkin diproses termasuk nama, alamat e-mel, ID pengesahan Clerk/authId, profil dan sesi akaun, peranan, akses aplikasi, tahap pelan, ringkasan penggunaan, mesej dan rekod sokongan, rujukan pembayaran atau transaksi, kandungan pengguna, fail, arahan atau “prompt” AI, output yang dijana, tetapan, alamat IP, jenis pelayar/peranti, sistem operasi, pengecam kuki atau sesi, URL, masa permintaan, log prestasi dan keselamatan, serta data interaksi video selepas video YouTube dimainkan.
Tujuan pemprosesan. Data digunakan untuk mendaftar dan mengesahkan akaun; menyediakan ciri, akses, kandungan, output, sokongan dan transaksi yang diminta; menjawab pertanyaan; mengurus tahap pelan dan penggunaan; mengendalikan, menyelenggara, mengukur dan menambah baik perkhidmatan; mencegah penipuan, penyalahgunaan dan insiden keselamatan; menguatkuasakan terma; menyimpan rekod; mematuhi kewajipan undang-undang, cukai, perakaunan atau kawal selia; mengurus pertikaian dan tuntutan; dan menghantar pemasaran pilihan hanya apabila dibenarkan undang-undang.
Sumber data. Data diperoleh daripada anda atau orang yang menyerahkannya bagi pihak anda; pelayar, peranti dan penggunaan anda; Clerk; penyedia pengehosan, keselamatan, pangkalan data dan komunikasi; serta penyedia pembayaran, integrasi atau AI yang dikenal pasti dalam notis aplikasi berkaitan. Data teknikal tertentu dijana secara automatik apabila permintaan dibuat kepada perkhidmatan.
Kelas pihak ketiga. Data boleh didedahkan kepada Clerk; Convex jika ciri akaun pusat digunakan; Resend dan Gmail/Google bagi borang hubungan; penyedia pengehosan, rangkaian penghantaran kandungan, pemantauan dan keselamatan; YouTube/Google apabila anda memilih untuk memainkan video; penyedia AI, storan, integrasi dan pembayaran yang dinyatakan oleh aplikasi; penasihat profesional, juruaudit dan penanggung insurans; pihak berkuasa apabila diwajibkan atau dibenarkan undang-undang; dan pihak berkaitan urus niaga korporat yang tertakluk kepada kerahsiaan. Data peribadi tidak dijual atau disewakan.
Data wajib, data sukarela dan pilihan. E-mel dan data pengesahan adalah wajib bagi ciri yang memerlukan akaun. E-mel dan mesej adalah wajib untuk menghantar borang hubungan; jenis peluang mempunyai nilai lalai untuk membantu mengarahkan pertanyaan. Medan yang ditanda wajib dalam aplikasi diperlukan untuk ciri, transaksi, keselamatan atau pematuhan yang dinyatakan. Jika data wajib tidak diberikan, akaun tidak dapat dibuat, borang tidak dapat dihantar, atau ciri/transaksi berkaitan mungkin tidak dapat disediakan. Data profil pilihan, maklum balas, integrasi dan pemasaran adalah sukarela. Anda boleh memilih untuk tidak memainkan video YouTube atau tidak menerima pemasaran pilihan. Menyekat kuki pengesahan yang amat diperlukan boleh menyebabkan log masuk tidak berfungsi.
Akses, pembetulan dan penarikan balik. Tertakluk kepada Akta Perlindungan Data Peribadi 2010 dan pengecualiannya, anda boleh meminta akses kepada data peribadi dan meminta data yang tidak tepat, tidak lengkap, mengelirukan atau tidak terkini dibetulkan. Anda juga boleh menarik balik persetujuan bagi pemprosesan yang berasaskan persetujuan dengan memberi notis munasabah. Sila gunakan alamat e-mel di atas, nyatakan perkhidmatan dan akaun berkaitan, dan berikan maklumat yang mencukupi untuk mengesahkan identiti. Jika terpakai, anda juga boleh meminta data dihantar kepada pengawal data lain, tertakluk kepada kebolehlaksanaan teknikal dan keserasian format. Kesan praktikal atau undang-undang penarikan balik akan diterangkan; sesetengah perkhidmatan mungkin tidak dapat diteruskan selepas itu.
Pemindahan ke luar Malaysia. Data boleh diproses di Singapura, Amerika Syarikat, atau negara tempat penyedia berkaitan mengendalikan sistem atau kakitangan. Langkah munasabah, kontrak dan mekanisme pemindahan yang dikehendaki undang-undang akan digunakan untuk melindungi data, dengan mengambil kira negara penerima dan jenis data.
Penyimpanan. Data disimpan hanya selama yang munasabah diperlukan bagi tujuan di atas. Tempoh ditentukan berdasarkan jangka hayat akaun atau ciri, penyelesaian pertanyaan dan pertikaian, keselamatan dan pencegahan penipuan, jenis serta sensitiviti data, tetapan aplikasi, permintaan pemadaman, dan kewajipan undang-undang, cukai, perakaunan atau kontrak. Selepas itu, data akan dipadam atau dinyahkenal pasti jika praktik, tertakluk kepada sandaran terhad, tuntutan undang-undang dan kewajipan penyimpanan.
Pengakuan bahawa notis ini telah dibaca bukan persetujuan menyeluruh bagi semua pemprosesan. Persetujuan khusus akan diminta secara berasingan apabila diperlukan oleh undang-undang.
EEA, United Kingdom, and Switzerland
Yee Fei is the controller for data covered by this policy. The legal grounds are mapped in section 4. Depending on the applicable GDPR or Swiss law, individuals may have rights of access, rectification, erasure, restriction, objection, portability, and withdrawal of consent, and the right not to be subject to a qualifying solely automated decision with legal or similarly significant effects. The Services do not presently use personal data to make such qualifying decisions unless an app-specific notice says otherwise.
If EU or UK law requires a local representative because a Service intentionally offers services to or monitors people there, the representative's details will be added before that activity begins. An individual may complain to the data-protection authority for their habitual residence, workplace, or alleged infringement; UK residents may contact the Information Commissioner’s Office, and Swiss residents the Federal Data Protection and Information Commissioner. International-transfer safeguards are described in section 8. A person may object at any time to direct marketing and may object to legitimate-interest processing based on their particular situation, subject to grounds allowed by law.
California and other US states
The categories described in section 2 correspond, depending on use, to identifiers; customer-record information; internet or electronic-network activity; commercial information such as plan and transaction references; professional information in an enquiry; approximate geolocation inferred from IP; audio, visual, or similar user content; account credentials and payment-related data that may be treated as sensitive; and inferences such as access level or suspected abuse. Sources, business purposes, and recipient categories are described in sections 2, 4, and 5. These categories may be disclosed for business purposes to the provider and recipient classes in section 5.
Personal information, including sensitive personal information, is not sold. It is not shared for cross-context behavioural advertising. Because the Services do not currently conduct that tracking, they do not respond differently to legacy browser “Do Not Track” signals. Sensitive personal information is not used to infer characteristics beyond purposes permitted without a right-to-limit notice. Consequently, there is currently no sale or cross-context advertising sharing to opt out of. If this changes, legally required “Do Not Sell or Share,” limit-use, and Global Privacy Control choices will be honoured where legally required.
Subject to the law and its applicability thresholds and exceptions, residents may request confirmation or access, specific pieces or categories of information, correction, deletion, portability, a list of certain third parties, opt-out of covered sale, targeted advertising, or profiling, and limits on certain sensitive-data uses. They may use an authorised agent and may appeal as described in section 11. California residents may also request information about categories collected, disclosed, sold, or shared. Requests are verified and handled as described in section 11, without unlawful discrimination.
Canada
Personal data is handled on the basis of meaningful consent where required, or another basis permitted by applicable federal or provincial law. Individuals may request access to and correction of their information, challenge compliance, and withdraw consent subject to legal or contractual restrictions and reasonable notice. A withdrawal may mean a requested feature can no longer be provided. Concerns can be sent to section 1’s contact and may be raised with the Office of the Privacy Commissioner of Canada or the applicable provincial privacy commissioner. Service providers outside Canada may be subject to lawful access in their location.
Australia and New Zealand
Yee Fei is the privacy contact and, where the New Zealand Privacy Act applies, the contact responsible for privacy matters. Subject to the Australian Privacy Act 1988, New Zealand Privacy Act 2020, their applicability rules, and available exceptions, individuals may request access to and correction of personal information and complain about its handling. Complaints should first be sent to section 1’s contact with enough detail to investigate. If unresolved, a complaint may be made to the Office of the Australian Information Commissioner or New Zealand Office of the Privacy Commissioner, as applicable. Overseas disclosures and the safeguards used for them are described in sections 5 and 8; provider locations can change and app-specific notices may give further detail.
15. Changes to this policy and contact
This policy may change as the Services, providers, or law change. The version and effective date at the top will be updated. Material changes will receive additional notice appropriate to their significance—for example, an in-service notice or email where contact details are available and the law requires it. Consent will be requested before a new use where required; continued use will not be treated as consent when consent must be express.
Questions, complaints, rights requests, and requests for information about transfer safeguards can be emailed to yeefei@yooi.me.