Last updated 26 August 2026
Yappy (yappy.fyi) is a campaign-intelligence workspace run by its small founding team. Questions about this policy, or requests about your data, go to hello@yappy.fyi.
Three kinds of things, all only because the product needs them to work:
Your account. When you sign in with an email link or Google, our authentication provider (Supabase) stores your email address and a user id. We never see or store a password.
Your work. Campaigns, briefs, conversations and generated assets are stored in our database (Supabase, hosted in the EU) so they are there when you come back. They are scoped to your account.
Your API keys. Yappy runs on keys you bring for OpenAI, Tavily and fal. They are encrypted (AES-256-GCM) before they are written down, are never shown back to you or anyone else beyond their last four characters, and are used for exactly one thing: calling those services on your behalf when you run something. You can remove them at any time in Settings.
When you run a campaign step, the relevant content is sent to the services it needs — OpenAI for reasoning, Tavily for research, fal for rendering — under your own keys and their own privacy terms. Nothing is sent anywhere until you act.
No analytics or tracking scripts, no advertising, no selling or sharing of your data. Cookies are used for one purpose: keeping you signed in.
Remove any stored API key yourself in Settings. To delete your account and its data, email hello@yappy.fyi and we will do it promptly.
If this policy changes materially we will note it here with a new date.