Privacy Policy
Yote Innovations (“Yote”, “we”) · Effective 2026-07-16
Yote is a CRM and AI-assistant platform for AWS consultancies. This policy describes what we collect, how we use it, and the choices you have. Questions: info@goyote.ai.
Information we collect
- Account data — name, email, and role for signing in and workspace membership.
- Business data you enter — companies, contacts, opportunities, funding requests, invoices, project records.
- Google user data (only if you connect a Google account) — described in full below.
Google user data
When you connect a Google account, Yote requests the narrowest scopes for the features you enable:
- Calendar (calendar.events, calendar.readonly) — to read your free/busy times and upcoming events so scheduling assistance reflects your real availability, and to create calendar events you (or your workspace operator) explicitly approve. We do not edit or delete your existing events.
- Gmail read-only (gmail.readonly) — optional, and only when you explicitly enable inbox monitoring: your assistant watches your inbox for scheduling requests and drafts replies that a human approves before anything is sent. We never send mail from your Gmail account, never modify or delete messages, and never read mail for any other purpose.
- Basic profile (email address) — to identify which Google account you connected.
Limited Use disclosure: Yote’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide the user-facing scheduling and assistant features described above. We do not use Google user data for advertising, do not sell it, and do not transfer it to third parties except as necessary to provide these features (e.g., our cloud hosting provider), to comply with law, or as part of a merger/acquisition with equivalent protections. Humans do not read your Google data except with your explicit consent, for security purposes, to comply with law, or when aggregated/anonymized. Google user data is not used to train generalized AI or machine-learning models.
Data protection & security
Sensitive data — including all Google user data — is protected with the following mechanisms:
- Encryption in transit — all connections use TLS 1.2+ (HTTPS everywhere, including every call to Google APIs and between our services).
- Encryption at rest — OAuth refresh tokens are encrypted with AES-256-GCM using application-held keys before storage; the underlying database (Neon PostgreSQL) additionally encrypts all data at rest.
- Least-privilege access — we request the narrowest Google scopes for each feature, and Google user data is accessible in-app only to authenticated members of the owning workspace, with role-based controls; calendar/email content is further restricted to operator (admin) roles.
- Tenant isolation — every record is scoped to its workspace (tenant) at the query layer; no cross-tenant access paths exist.
- Minimal retention — we do not build a copy of your mailbox or calendar: calendar free/busy and event data are fetched on demand and not persisted beyond the immediate feature; only message metadata needed for scheduling threads is stored.
- Revocation & deletion — disconnecting an account deletes the stored token immediately; account deletion requests are honored within 30 days.
- Incident response — suspected incidents affecting user data are investigated immediately and affected users are notified without undue delay at their registered email.
AI processing of Google user data
Yote’s assistant features use large language models to power the user-facing functionality described above (answering availability questions, drafting scheduling replies a human approves). This processing complies with the Limited Use requirements:
- No training, ever — Google user data (raw, aggregated, anonymized, or derived) is never used by us, and is never permitted to be used by our AI providers, to create, train, improve, or fine-tune any machine-learning or artificial-intelligence model, foundational or otherwise.
- Providers under no-training terms — AI inference runs on Amazon Bedrock (Anthropic Claude models; AWS contractually does not use customer content to train models and does not share it with model providers), and, where a workspace configures them, the Anthropic API or OpenAI API on commercial terms under which inputs and outputs are not used for model training.
- Transient processing — Google user data sent to a model is used only to generate the immediate response for the requesting user and is not retained by us as model context beyond the conversation.
- Human approval — AI-drafted communications and calendar bookings execute only after explicit human approval.
Retention & deletion
You can disconnect a Google account any time in Settings — we stop all access immediately and delete the stored token. You can also revoke Yote from myaccount.google.com/permissions. To delete your account data entirely, email info@goyote.ai — we delete within 30 days except where law requires retention.
Changes
We’ll post updates here with a new effective date; material changes are announced in-app.