|Home

Privacy Policy

Last Updated: August 11, 2026 Version: 2.2.0 Effective Date: August 11, 2026


1. Introduction

Sertaç Fırat ("YAPL", "we", "our", or "us") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, store, and protect your information when you use our project management platform and related services ("Service").

This Privacy Policy applies to all users of our Service and complies with:

  • General Data Protection Regulation (GDPR) - EU Regulation 2016/679
  • California Consumer Privacy Act (CCPA) - California Civil Code Section 1798.100 et seq.
  • Other applicable data protection laws and regulations

By using our Service, you agree to the collection and use of information in accordance with this Privacy Policy.


2. Data Controller

The data controller responsible for your personal data is:

Sertaç Fırat (Sole Proprietorship) Email: privacy@yapl.app Legal Contact: legal@yapl.app Data Protection Officer: dpo@yapl.app Address: Altıntepe Mah. Ali Paşa Sk. No:5, Maltepe/İstanbul, Turkey

If you have any questions about how we handle your data or wish to exercise your data protection rights, please contact us using the details above.


We process your personal data under the following legal bases (GDPR Article 6):

3.1 Contractual Necessity (Article 6(1)(b))

Processing necessary to perform our contract with you (Terms of Service), including:

  • Account creation and management
  • Service delivery and support
  • Billing and subscription management

3.2 Legitimate Interests (Article 6(1)(f))

Processing necessary for our legitimate business interests, including:

  • Service improvement and analytics
  • Security and fraud prevention
  • Marketing to existing customers (with opt-out rights)

3.3 Legal Obligation (Article 6(1)(c))

Processing necessary to comply with legal obligations, including:

  • Tax and accounting requirements
  • Regulatory compliance
  • Response to lawful requests from authorities

3.4 Consent (Article 6(1)(a))

Processing based on your explicit consent, including:

  • Optional marketing communications
  • Non-essential cookies
  • Third-party integrations

You may withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.


4. Data We Collect

4.1 Information You Provide (Account Data)

During Registration:

  • Full name
  • Email address
  • Company name
  • Workspace name
  • Password (encrypted and hashed)

During Service Use:

  • Project information (names, descriptions, dates)
  • Task and milestone data
  • Team member information
  • Comments and communications
  • A profile picture, if you upload one
  • Settings and preferences

4.2 Information We Collect Automatically

Usage Data:

  • IP address
  • Browser type and version
  • Device information (type, operating system)
  • Pages visited and features used
  • Time and date of access
  • Time spent on pages
  • Referring website addresses

Authentication and Security Data:

  • Login timestamps
  • Session information
  • Device fingerprints (for security purposes)

Cookies and Tracking Technologies:

  • Essential cookies (authentication, security)
  • Preference cookies (language, settings)
  • Analytics cookies (with consent)

4.3 Information from Third Parties

Payment Processors:

  • Payment method information (tokenized)
  • Billing address
  • Transaction history

Sign-in providers (if you sign in with Google or Slack):

  • Your name and email address from that account
  • Authentication tokens
  • A link to your profile picture. We store the web address only and display the image from there — we do not copy the picture onto our systems

5. How We Use Your Data

We use your personal data for the following purposes:

5.1 Service Provision

  • Create and manage your account
  • Provide access to the platform
  • Process and fulfill service requests
  • Facilitate team collaboration
  • Store and manage your project data

5.2 Communication

  • Send transactional emails (account notifications, password resets)
  • Respond to your inquiries and support requests
  • Send service updates and announcements
  • Marketing communications (with consent or opt-out rights)

5.3 Service Improvement

  • Analyze usage patterns and trends (aggregated data)
  • Identify and fix bugs
  • Develop new features
  • Improve user experience

5.4 Security and Fraud Prevention

  • Detect and prevent unauthorized access
  • Monitor for suspicious activities
  • Enforce our Terms of Service
  • Protect against fraud and abuse
  • Comply with legal obligations
  • Respond to lawful requests from authorities
  • Enforce our legal rights
  • Resolve disputes

6. Data Sharing and Disclosure

6.1 We Do NOT Sell Your Data

We do not sell, rent, or trade your personal data to third parties for marketing purposes.

6.2 Service Providers

We share data with trusted service providers who assist us in operating our Service:

Infrastructure Providers:

Security:

  • Cloudflare (Turnstile — checks that sign-in and sign-up forms are being used by a person rather than an automated script; receives your IP address and a one-time token at that moment) - Cloudflare Privacy Policy

Payment Processors:

Email Services:

Error Monitoring:

All service providers are contractually obligated to:

  • Process data only as instructed by us
  • Implement appropriate security measures
  • Comply with GDPR and applicable data protection laws

We may disclose your data when required by law or to:

  • Comply with legal processes (subpoenas, court orders)
  • Respond to government requests
  • Enforce our Terms of Service
  • Protect our rights, property, or safety
  • Prevent fraud or illegal activities

6.4 Business Transfers

In the event of a merger, acquisition, or sale of assets, your data may be transferred to the acquiring entity. We will notify you of any such change and your options regarding your data.

We may share your data with third parties when you explicitly consent, such as:

  • Connected services you authorize (such as Slack or an AI agent — see Section 6.6)
  • Sharing project data with external collaborators
  • Public features you choose to use

6.6 Connected Services You Authorize (Slack and AI Agents)

Some features let you connect YAPL to services you choose. Data flowing to these services is disclosed at your direction and is governed by the recipient's own terms — these services are not our subprocessors, and we do not control how they process the data you direct to them.

Slack. If a workspace owner installs the YAPL Slack app, notifications and digests containing workspace content — task names, plan names, project names, and the names of the people who acted — are delivered into the connected Slack workspace, and replies to slash commands are shown inside Slack. To operate the integration we store: encrypted Slack bot tokens, the mapping between Slack and YAPL user accounts, and a log of the messages we sent (retained for 30 days). If the integration is disconnected or a user is unlinked, encrypted tokens are retained for 90 days for audit purposes and then permanently deleted. Slack's processing of content inside your Slack workspace is governed by your organization's own agreement with Slack. You can disconnect Slack or unlink your account at any time under Settings > Integrations > Slack.

AI agents (MCP connector). You may authorize an AI agent client — for example Anthropic's Claude, or any other client supporting the Model Context Protocol — to access YAPL on your behalf. Authorization uses the OAuth 2.1 standard: you sign in with your own YAPL account and explicitly approve each client. The client receives your basic identity (name and email address) and expiring access tokens; it never receives your password. An authorized client can read and change exactly what your own account can — no more — and everything it reads is transmitted to that client's operator (for example, Anthropic for Claude), whose own terms and privacy policy govern their processing of that data. Any compatible client may request access, but no client gains access without your explicit sign-in and approval. You can review every authorized client and revoke its access at any time under Settings > Integrations > MCP Connectors; revocation takes effect immediately.


7. Data Retention

7.1 Active Accounts

We retain your data for as long as your account is active and you continue to use our Service.

7.2 Inactive and Expired Accounts

We do not delete accounts for inactivity alone. What matters is your subscription:

  • While your subscription is active — or cancelled but still within the period you paid for — your data is kept.
  • When a subscription expires, through cancellation, trial end, or payment failure, your workspace becomes read-only immediately and its data is permanently deleted 90 days later. We email you before that: 7 days after expiry, then again 7, 3 and 1 day before deletion. Reactivating at any point in that window stops the deletion.

This is set out in full in section 10.5 of our Terms of Service.

7.3 Account Deletion

When you delete your account:

  • Your account and everything in it is deleted from our active systems immediately
  • Deletion is permanent and cannot be undone — we cannot recover a deleted account
  • Residual copies remain in our encrypted daily database backups, which are kept for 7 days and then overwritten. Uploaded files are not included in those backups at all, so a deleted profile picture is gone immediately
  • Your name and email address are also stripped from our authentication records at the same moment, so the record that an account signed in or was deleted survives without naming you
  • Records of the consents you gave are the exception: we keep those for 7 years (see 7.5), stored against a one-way fingerprint of your email address rather than the address itself
  • A short list of operational and security records is not held against your account and is deleted on its own fixed schedule instead, which can run on past the day you delete. Section 7.4 lists every one of them, and how long each is kept

7.4 Operational and Security Records

Alongside your account and its contents, we keep a small number of records in order to run the Service, keep it secure, and honour the commitments above. Each one is either deleted, or stripped of the details that identify you, once it reaches the age below. A job runs every day to apply these periods; they are enforced automatically rather than being a target we aim at.

RecordHow long we keep it
Sign-in attempts — the email address entered, the time, and whether it succeeded90 days
Sign-up attempts90 days
Security audit records — which account did what, and when12 months
Devices you have signed in on — device type, browser, operating system180 days after you last signed in on that device
Invitations you sent or received30 days after the invitation is accepted or expires
Invitation attempts, recorded to catch abuse90 days
Support requests you send us2 years
Feedback you leave on our documentationThe feedback itself is kept; the IP address and browser details attached to it are removed after 90 days
Slack invite requests30 days after the request is approved, rejected, or expires
Records of signing in, signing out, changing your password, and account creation or deletion12 months
Newsletter subscription recordsKept for as long as the list exists — see below. The IP address and browser details captured at signup are removed after 1 year
Workspace and plan activity history30 days on Trial, 90 days on Basic, 365 days on Professional

Where a record is under a legal hold — because it is relevant to a legal claim or an official investigation — it is kept past the period above until the hold is lifted. Section 7.5 covers this.

Three of these need spelling out, because they do not work the way you might expect:

Sign-in and sign-up attempt records are not linked to your account. They are recorded against whatever email address was typed into the form, which often belongs to nobody who ever registered with us. Because there is no account attached to them, we cannot connect them to you in response to a request, and they cannot be singled out to be kept or held back. They are deleted 90 days after the attempt, without exception.

Removing a Slack connection does not erase it on the spot. When you remove the link between your YAPL account and your Slack user, we stop using that link immediately and mark it removed. The Slack details we had stored — your Slack email address, display name, and profile image address — are deleted 30 days after that.

Unsubscribing from the newsletter keeps your address, on purpose. If we deleted it we would have no way of knowing you had asked to be left alone, and a later import could add you back. Your address therefore stays on a suppression list for as long as we run a newsletter, used for nothing except making sure you are never emailed again. You can ask us to remove it outright at privacy@yapl.app, accepting that we then lose the record of your objection.

We may retain certain data longer when required by law:

  • Financial records: 7 years (tax compliance)
  • Legal proceedings: Duration of proceedings plus 1 year
  • Consent records: 7 years (GDPR compliance)

7.6 Anonymized Data

We may retain anonymized, aggregated data indefinitely for analytics and service improvement. This data cannot be used to identify you personally.


8. Data Security

We implement industry-standard security measures to protect your data:

8.1 Technical Measures

  • Encryption in Transit: TLS 1.3 for all connections
  • Encryption at Rest: AES-256 encryption for stored data
  • Password Security: Bcrypt hashing with salt
  • Two-Factor Authentication: Optional MFA for enhanced security

8.2 Organizational Measures

  • Access Control: Role-based access with principle of least privilege
  • Employee Training: Regular security awareness training
  • Security Audits: Periodic security assessments and penetration testing
  • Incident Response: Documented procedures for breach notification

8.3 Multi-Tenancy Security

  • Row-Level Security (RLS): Database-level isolation between workspaces
  • Data Segregation: Each workspace's data is logically separated
  • Access Validation: Every request validates workspace membership

8.4 Limitations

While we implement robust security measures, no system is 100% secure. We cannot guarantee absolute security but will:

  • Notify you of breaches within 72 hours (GDPR requirement)
  • Take immediate action to mitigate risks
  • Provide guidance on protective measures

9. Your Data Protection Rights (GDPR)

Under the GDPR, you have the following rights:

9.1 Right to Access (Article 15)

You can request:

  • Confirmation of whether we process your data
  • A copy of your personal data
  • Information about how we use your data

How to exercise: Contact privacy@yapl.app or use the account settings page.

9.2 Right to Rectification (Article 16)

You can request correction of inaccurate or incomplete data.

How to exercise: Update your profile in account settings or contact us.

9.3 Right to Erasure / "Right to be Forgotten" (Article 17)

You can request deletion of your data when:

  • Data is no longer necessary for the purposes collected
  • You withdraw consent (for consent-based processing)
  • You object to processing (for legitimate interest processing)
  • Data was unlawfully processed

How to exercise: Delete your account or contact privacy@yapl.app.

Exceptions: We may retain data when required by law or for legal claims.

9.4 Right to Restriction of Processing (Article 18)

You can request we limit processing when:

  • You contest the accuracy of data
  • Processing is unlawful but you don't want deletion
  • We no longer need the data but you need it for legal claims
  • You object to processing pending verification

How to exercise: Contact privacy@yapl.app.

9.5 Right to Data Portability (Article 20)

You can request your data in a structured, machine-readable format (CSV, JSON).

How to exercise: Use the data export feature in account settings or contact us.

9.6 Right to Object (Article 21)

You can object to:

  • Processing based on legitimate interests
  • Direct marketing (including profiling)
  • Processing for scientific/historical research

How to exercise: Adjust settings or contact privacy@yapl.app.

9.7 Right to Withdraw Consent (Article 7(3))

For consent-based processing, you can withdraw consent at any time.

How to exercise: Adjust settings or contact privacy@yapl.app.

9.8 Right to Lodge a Complaint

You can file a complaint with your local data protection authority if you believe we violated your rights.

EU Supervisory Authorities: List of EU DPAs


10. International Data Transfers

10.1 Data Location

Your data is primarily stored in:

  • Primary Region: European Union (Frankfurt, Germany)
  • Backup Region: European Union (same region as primary database)

10.2 GDPR Compliance for Transfers

When we transfer data outside the EEA, we ensure adequate protection through:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy Decisions for countries with equivalent protection
  • Service Provider Certifications (e.g., SOC 2, ISO 27001)

10.3 Your Control

Enterprise customers can request data residency in specific regions (subject to availability).


11. Cookies and Tracking Technologies

We use essential cookies for:

  • Authentication and session management
  • Security features
  • Service functionality
  • Load balancing

Duration: Session cookies (deleted when you close browser) or up to 30 days.

With your consent, we may use analytics cookies to:

  • Understand how you use our Service
  • Identify popular features
  • Improve user experience

Analytics Provider: We do not currently use third-party analytics. If implemented, we will use privacy-friendly solutions (e.g., Plausible, Fathom).

We do not currently use marketing or advertising cookies. If we implement them, we will:

  • Request explicit consent
  • Provide granular control
  • Respect Do Not Track signals

You can control cookies through:

  • Browser Settings: Block or delete cookies
  • Our Cookie Banner: Manage preferences on first visit
  • Account Settings: Update cookie preferences anytime

Note: Blocking essential cookies may affect Service functionality.


12. Children's Privacy

Our Service is not intended for children under 18 years of age. We do not knowingly collect personal data from children.

If you are a parent or guardian and believe your child has provided us with personal data, please contact us immediately at privacy@yapl.app. We will promptly delete such data.


13. Changes to This Privacy Policy

13.1 Notification of Changes

We may update this Privacy Policy to reflect:

  • Changes in our practices
  • Legal or regulatory requirements
  • New features or services

We will notify you of material changes by:

  • Email notification to your registered address
  • In-app notifications
  • Prominent notice on our website

13.2 Effective Date

Changes take effect 30 days after notification unless:

  • Required by law to take effect immediately
  • Changes are favorable to you (effective immediately)

13.3 Version History

We maintain a version history of this Privacy Policy. Previous versions are available upon request.


14. California Privacy Rights (CCPA)

If you are a California resident, you have additional rights under the CCPA:

14.1 Right to Know

You can request:

  • Categories of personal information collected
  • Sources of personal information
  • Business purposes for collection
  • Categories of third parties we share data with
  • Specific pieces of personal information we collected

14.2 Right to Delete

You can request deletion of your personal information, subject to legal exceptions.

14.3 Right to Opt-Out of Sale

We do not sell personal information. If this changes, we will provide an opt-out mechanism.

14.4 Right to Non-Discrimination

We will not discriminate against you for exercising your CCPA rights.

14.5 Authorized Agent

You may designate an authorized agent to make requests on your behalf.

How to exercise CCPA rights: Contact privacy@yapl.app.


15. Contact Us

For privacy-related questions, concerns, or to exercise your rights, contact us:

Privacy Team: Email: privacy@yapl.app Subject: "Privacy Inquiry - [Your Concern]"

Data Protection Officer: Email: dpo@yapl.app

Legal Department: Email: legal@yapl.app

Mailing Address: Sertaç Fırat (Sole Proprietorship) Altıntepe Mah. Ali Paşa Sk. No:5, Maltepe/İstanbul, Turkey

Response Time: We aim to respond to all inquiries within 30 days.


16. Supervisory Authority

If you are in the EU/EEA and believe we have not addressed your concerns, you have the right to lodge a complaint with your local supervisory authority.

Find your supervisory authority: EDPB Member List


By using YAPL Project Management, you acknowledge that you have read, understood, and agree to this Privacy Policy.