Privacy Policy
Last updated: September 26, 2026
The short version
We collect the information needed to operate YEA/NAY, prevent abuse, moderate anonymous content, and keep the Service reliable. We do not display your identity to other users. Anonymous does not mean untraceable to our safety systems. We do not sell your personal information.
1. Who we are
YEA/NAY is operated by Mofako Labs LLC (“Mofako Labs,” “we,” “us,” or “our”), a Hawaii limited liability company. This Privacy Policy explains how we collect, use, disclose, retain, and protect information when you use YEA/NAY and related services.
Privacy contact: privacy@yeanay.io
Public privacy URL: https://www.yeanay.io/privacy.html
Account-deletion URL: https://www.yeanay.io/delete-account.html
2. Scope
This Policy applies to the YEA/NAY mobile applications, websites, support channels, and related services. It does not govern third-party services that provide their own privacy notices.
3. Information we collect
### 3.1 Anonymous account and eligibility information
We may collect:
- a randomly generated internal user identifier;
- authentication and session tokens;
- confirmation that you meet the minimum age requirement;
- the versions of the Terms, Community Guidelines, and Privacy Policy you accepted or acknowledged; and
- timestamps, app version, and platform associated with acceptance.
We do not need to show your legal name, email address, or social identity to other users. If V1 does not collect those fields, the production privacy disclosure must say so accurately.
### 3.2 Content and activity
We collect questions you draft or post, selected categories, votes, skips, result interactions, reports, block relationships, moderation actions, sharing events, and deletion requests. Reports may include the reason selected and optional information you provide.
### 3.3 Device, network, and security information
We may collect IP address, approximate region derived from IP, device and operating-system type, app version, language, timestamps, crash information, integrity or attestation results, and limited device signals used to detect abuse, secure sessions, enforce rate limits, and reduce ban evasion.
If we create a device-risk identifier, we will design it to minimize data, limit its purposes, and avoid accessing unrelated device content. We do not claim that uninstalling the app automatically erases server-side safety records.
### 3.4 Support communications
If you contact us, we collect the message, contact information you choose to provide, attachments, and information needed to respond or investigate.
### 3.5 Information we do not intend to collect in V1
Unless a future feature clearly requests it, V1 is not intended to collect your precise location, contacts, microphone recordings, photo library, payment-card details, or advertising identifier. Do not add an SDK or permission that collects these categories without updating this Policy, store disclosures, consent flows, and the data inventory first.
4. How we use information
We use information to:
- create and maintain anonymous accounts and sessions;
- display questions, accept votes, calculate results, and remember skips;
- enforce one-vote, rate-limit, and anti-spam rules;
- filter, investigate, and moderate content and conduct;
- process reports, blocks, appeals, and deletion requests;
- detect fraud, manipulation, ban evasion, security incidents, and technical abuse;
- provide support and important Service notices;
- monitor reliability, diagnose crashes, and improve features;
- comply with law and protect users, Mofako Labs, and the public; and
- create aggregated or de-identified statistics that do not reasonably identify a person.
We do not use a legal-policy checkbox as consent for optional advertising, cross-app tracking, contact access, precise location, notifications, or unrelated analytics.
5. Legal bases where applicable
Where laws such as the GDPR require a legal basis, we process information as necessary to perform our contract with you, pursue legitimate interests in operating and securing the Service, comply with legal obligations, protect vital interests in urgent safety situations, or obtain consent where consent is required. You may withdraw consent for consent-based processing, but withdrawal does not make prior lawful processing unlawful.
6. How we disclose information
We may disclose information:
- to vendors that host, authenticate, secure, analyze, or support the Service under contractual confidentiality and data-protection obligations;
- to professional advisers such as lawyers, auditors, and insurers;
- in connection with a merger, financing, reorganization, acquisition, bankruptcy, or transfer of assets, subject to appropriate protections;
- when required by valid legal process; or
- when reasonably necessary to address fraud, exploitation, credible threats, imminent serious harm, child safety, security incidents, or violations of our Terms.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising in V1. If that changes, we will update this Policy and provide legally required choices before the change applies.
Service providers
We use service providers to operate YEA/NAY, including hosting, database, and authentication (currently Supabase) and website hosting (currently Vercel). They process information only on our behalf. We do not use third-party advertising, analytics, or crash-reporting services in the app.
7. Data retention
We retain information only as long as reasonably necessary for the purposes described here, including safety, security, dispute resolution, and legal compliance. Our retention periods are:
| Data | Retention |
|---|---|
| Active anonymous account and settings | Until you or we delete it |
| Active questions | Until the 72-hour voting period ends or earlier deletion/removal |
| Closed questions and ordinary votes | 90 days after closing, then delete or irreversibly aggregate |
| Skipped-question history | Until question expiry, plus no more than 7 days |
| Block relationships | Until account deletion or unblock |
| Reports and moderation records | Up to 24 months; longer for severe abuse, litigation hold, or law |
| Security, integrity, and ban-enforcement records | Up to 12 months after last relevant activity; longer for repeated severe abuse |
| Legal acceptance records | Up to 6 years or the period required to establish or defend legal claims |
| Routine backups | Overwritten within 30–90 days |
We may retain de-identified or aggregated information that can no longer reasonably identify or single out a user.
8. Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of personal information; object to or restrict certain processing; withdraw consent; or complain to a privacy regulator.
Because YEA/NAY uses anonymous identifiers, we may need your active authenticated session, recovery code, or another secure method to verify that a request relates to your account. We will not collect unnecessary identity documents merely to process a request. If we cannot reasonably verify a request, we may be unable to disclose or delete account-specific information.
To exercise a right, use the in-app controls or contact privacy@yeanay.io. We will respond within the period required by applicable law.
9. Deleting your account and data
Before an anonymous account exists, the Delete My Data control is displayed in a disabled state because there is no server-side account to delete. After onboarding creates an account, the control becomes active in Settings.
To request deletion in the app:
1. Open More.
2. Open Settings.
3. Open Privacy Policy or Privacy & Data.
4. Select Delete My Data.
5. Review the consequences and confirm using the authenticated device/session.
You may also request deletion without reinstalling the app at https://www.yeanay.io/delete-account.html.
Deletion removes or de-identifies the active account and associated ordinary content according to the stated process. Limited information may remain temporarily in backups or longer where reasonably necessary for security, ban enforcement, fraud prevention, legal compliance, protection from harm, or establishment and defense of legal claims. The deletion confirmation must state what is deleted, what may be retained, and the applicable periods. Deleting the app from a device does not by itself delete server data.
10. International processing
We and our service providers may process information in countries other than where you live. Where required, we use recognized safeguards for cross-border transfers. Contact privacy@yeanay.io for information about applicable safeguards.
11. Security
We use administrative, technical, and organizational measures designed to protect information, including access controls, encryption in transit, restricted administrative privileges, logging, integrity checks, rate limits, and incident-response procedures. No system is perfectly secure, and we cannot guarantee absolute security.
12. Adults only
YEA/NAY is intended only for people age 18 or older. We do not knowingly permit children to use the Service. If we learn that a person under 18 has provided information, we may suspend the account and delete the information, subject to safety and legal retention. Contact privacy@yeanay.io if you believe a minor is using the Service.
13. Automated moderation
We may use automated tools to detect spam, threats, harassment, exploitation, personal information, or other policy violations and to prioritize human review. Automated signals may affect whether content is posted, distributed, or reviewed. Where required by law, we will provide information about significant automated decisions and available review rights.
14. Changes to this Policy
We may update this Policy when the Service, law, or our practices change. We will post the new version and effective date. We will provide prominent notice and request renewed acknowledgment or consent when required.
15. Contact and complaints
Mofako Labs LLC
Privacy: privacy@yeanay.io
Support: support@yeanay.io
You may also complain to the privacy or data-protection authority where you live. In Canada, information about privacy rights is available from the Office of the Privacy Commissioner of Canada.