01 / Privacy policy
Privacy, plainly.
Last updated: September 2026
Introduction
Yonoo is operated by Collegium.House GmbH. We respect your privacy and explain here how we collect, use, and safeguard information when you use our AI chat service.
What we collect
- Email address: to identify an account and provide service updates.
- Chat messages: processed to provide AI responses. If you are signed in, your conversations are stored in our database against your account so your history is available on your other devices. If you are using the public site without an account, that conversation stays in your browser.
- Usage and device data: basic, anonymous usage statistics to operate and improve the service.
How we use information
- Provide and maintain the service and process chat requests through AI providers.
- Track free-tier message usage and process payments when you upgrade.
- Send opted-in service updates and improve the service.
Third-party AI providers
Yonoo may route requests to providers including OpenAI, Anthropic, Google, Perplexity AI, xAI, Meta via Groq, DeepSeek, Z.ai (Zhipu AI), nscale and Infercom SCS. Providers and sub-processors can change; the full current list with entities, processing locations and transfer bases is Annex 3 of our enterprise data processing agreement. Your messages are sent to the provider selected to generate a response, and that provider’s terms and privacy practices apply.
Where the models run. Of the 14 published models, six have a confirmed US location. Two — DeepSeek V4 and GLM-4.7 — are operated by providers established in China, for which no adequacy decision exists. The other six are served by nscale, which publishes infrastructure in Norway, the United Kingdom and the United States; Yonoo has not yet received written evidence identifying which region serves its account and these models, so they are not classified as EU/EEA-hosted. Infercom provides an additional route outside the published 14 and states that it runs in Munich. The shared user interface has no customer-admin model policy. A partner API credential can be locked to the fixed nscale/Infercom roster, but that lock does not prove nscale’s serving region and the application and account database remain US-hosted. nscale also has no identified Article 28 agreement, so the reviewed DPA stays unsigned until that gap is closed or a narrower lock excludes nscale. Written hosting attestations are being sought from both providers and are not yet in place.
Storage and security
- Chat history (signed in): stored in our database and scoped to your account. You can delete a conversation yourself; deleting your whole account and its history is done by us on request.
- Chat history (not signed in): kept in your browser only and cleared when you clear your browser data.
- Deployment audit trail: enterprise interaction metadata is recorded; question and answer text is included only where the deployment enables it. Retention is configurable and expired entries are purged automatically.
- Legacy enterprise-source content log: when its legacy source identifier is supplied, question, truncated response, model, supplied email and IP are written to a separate log with no automatic expiry; deletion is a manual operation on the organisation's written instruction.
- Account data: securely stored in our database with encryption.
- Payment data: processed by Stripe; we do not store card details.
An earlier version of this page said chat history was kept only in your browser and never stored on our servers. That was not accurate for signed-in accounts, and we have corrected it rather than left it standing.
AI Act information summary
Yonoo is ordinarily the provider of an AI system that orchestrates third-party models; it does not train foundation models. A customer that uses Yonoo within its own organisation is ordinarily the deployer. The precise allocation of roles depends on the configuration and use case, and is settled for each deployment in the enterprise contract and data processing agreement. Our enterprise assistance and document-analysis use cases are not intended for prohibited practices under Article 5 of Regulation (EU) 2024/1689 and are not marketed for high-risk Annex III purposes, unless a specific deployment is contractually scoped and assessed for that purpose.
Users are informed that they are interacting with an AI system. AI-generated output is identifiable, and model attribution is shown in-product. Outputs are decision support, not automated decisions: a human-review path exists, and customers remain responsible for final decisions. Models can err. We provide evidence and traceability where available so output can be checked.
Our data-governance approach operates alongside the privacy commitments in this policy. Enterprise source content remains within the agreed deployment boundary. The Act applies in stages: the prohibited-practice rules in Article 5 have applied since 2 February 2025, the obligations for providers of general-purpose AI models since 2 August 2025, and the Article 50 transparency duties for AI systems from 2 August 2026, with further high-risk provisions following from 2 August 2026 and 2 August 2027. We track these dates as they apply to each deployment.
Control and retention
You may request access, correction, deletion, portability, objection to certain processing, and withdrawal of consent where applicable. Account information and your saved conversations are retained while your account is active. You can delete individual conversations yourself at any time. To delete your account and its whole history, email us — there is no self-service delete button in the product yet, so we carry it out for you. A conversation held only in your browser can be cleared there. Enterprise records are separate: deployment audit entries expire under the deployment's configured retention window, while the legacy enterprise-source content log has no automatic expiry and is removed manually on the organisation's written instruction. Deleting an account does not itself clear either separate record. Contact privacy@yonoo.ai.
Cookies and local storage
We use browser local storage for preferences, anonymous message counts, and — when you are not signed in — the conversation itself. We do not use tracking cookies for advertising purposes.
Changes and contact
We may update this policy and will post the revised date here. For privacy questions, contact privacy@yonoo.ai.