01 / Privacy policy

Privacy, plainly.

Last updated: September 2026

01 / Controller

Introduction

Yonoo is operated by Collegium.House GmbH. We respect your privacy and explain here how we collect, use, and safeguard information when you use our AI chat service.

02 / Information

What we collect

03 / Use

How we use information

04 / Providers

Third-party AI providers

Yonoo may route requests to providers including OpenAI, Anthropic, Google, Perplexity AI, xAI, Meta via Groq, DeepSeek, Z.ai (Zhipu AI), nscale and Infercom SCS. Providers and sub-processors can change; the full current list with entities, processing locations and transfer bases is Annex 3 of our enterprise data processing agreement. Your messages are sent to the provider selected to generate a response, and that provider’s terms and privacy practices apply.

Where the models run. Of the 14 published models, six have a confirmed US location. Two — DeepSeek V4 and GLM-4.7 — are operated by providers established in China, for which no adequacy decision exists. The other six are served by nscale, which publishes infrastructure in Norway, the United Kingdom and the United States; Yonoo has not yet received written evidence identifying which region serves its account and these models, so they are not classified as EU/EEA-hosted. Infercom provides an additional route outside the published 14 and states that it runs in Munich. The shared user interface has no customer-admin model policy. A partner API credential can be locked to the fixed nscale/Infercom roster, but that lock does not prove nscale’s serving region and the application and account database remain US-hosted. nscale also has no identified Article 28 agreement, so the reviewed DPA stays unsigned until that gap is closed or a narrower lock excludes nscale. Written hosting attestations are being sought from both providers and are not yet in place.

05 / Storage

Storage and security

An earlier version of this page said chat history was kept only in your browser and never stored on our servers. That was not accurate for signed-in accounts, and we have corrected it rather than left it standing.

06 / EU AI Act

AI Act information summary

Yonoo is ordinarily the provider of an AI system that orchestrates third-party models; it does not train foundation models. A customer that uses Yonoo within its own organisation is ordinarily the deployer. The precise allocation of roles depends on the configuration and use case, and is settled for each deployment in the enterprise contract and data processing agreement. Our enterprise assistance and document-analysis use cases are not intended for prohibited practices under Article 5 of Regulation (EU) 2024/1689 and are not marketed for high-risk Annex III purposes, unless a specific deployment is contractually scoped and assessed for that purpose.

Users are informed that they are interacting with an AI system. AI-generated output is identifiable, and model attribution is shown in-product. Outputs are decision support, not automated decisions: a human-review path exists, and customers remain responsible for final decisions. Models can err. We provide evidence and traceability where available so output can be checked.

Our data-governance approach operates alongside the privacy commitments in this policy. Enterprise source content remains within the agreed deployment boundary. The Act applies in stages: the prohibited-practice rules in Article 5 have applied since 2 February 2025, the obligations for providers of general-purpose AI models since 2 August 2025, and the Article 50 transparency duties for AI systems from 2 August 2026, with further high-risk provisions following from 2 August 2026 and 2 August 2027. We track these dates as they apply to each deployment.

This is an information summary, not legal advice. Deployment-specific obligations are settled in the applicable enterprise contract and data processing agreement. For AI Act questions, contact hello@yonoo.ai.
07 / Your rights

Control and retention

You may request access, correction, deletion, portability, objection to certain processing, and withdrawal of consent where applicable. Account information and your saved conversations are retained while your account is active. You can delete individual conversations yourself at any time. To delete your account and its whole history, email us — there is no self-service delete button in the product yet, so we carry it out for you. A conversation held only in your browser can be cleared there. Enterprise records are separate: deployment audit entries expire under the deployment's configured retention window, while the legacy enterprise-source content log has no automatic expiry and is removed manually on the organisation's written instruction. Deleting an account does not itself clear either separate record. Contact privacy@yonoo.ai.

08 / Cookies

Cookies and local storage

We use browser local storage for preferences, anonymous message counts, and — when you are not signed in — the conversation itself. We do not use tracking cookies for advertising purposes.

09 / Changes

Changes and contact

We may update this policy and will post the revised date here. For privacy questions, contact privacy@yonoo.ai.