Privacy
What Yoti keeps, and what stays on your side. Updated 30 September 2026.
Who this is
Yoti runs at yoti.run. Questions about your information go to hello@yoti.run.
An account
A workspace account stores your email, name, and a password. A session cookie keeps you signed in. If you use an app with an email code, we keep a hash of that code until you enter it, then delete the code. The session after that is another cookie.
What you make
Pages, notes, chats, and connectors are stored so you can open them again. A public page shows the name, the page, and counts such as visitors and signups. A private page is left off the public list. Chat replies are produced by a model. If you turn on web search, that question is also sent to a search step.
Journal
Journal text is scrambled in the browser before it is saved. The key stays on that device. An optional phrase wraps the key. Yoti does not have the key, so we cannot read the journal. An insight sends the entries you chose, once, to a model. The reply is scrambled with the journal.
X
Connecting X is optional. X asks you to approve the Yoti app, then we store the account name and the tokens X gives us. Those tokens are sealed on the server. We never see your X password. Yoti’s own account and a person’s account on one app are stored separately. Disconnect deletes our copy.
Payment
Credit purchases are handled by Stripe. Yoti does not store your full card number.
Cookies
We use cookies to keep a session, to remember an app sign-in, and for a few minutes while X is connecting. We do not use them to follow you around the web.
Who else handles it
The site is hosted on Cloudflare, which also runs the models. The database is Supabase. Mail for codes and sign-in goes through our mail provider. Stripe handles cards. X only sees a connection when you approve one.
How long, and deletion
We keep account and app data while you use Yoti. Email hello@yoti.run to ask for the account data we hold to be deleted. A journal on a device also has a local copy we cannot wipe for you.