Privacy Policy
Last updated: October 9, 2026
yumori (the website at yumori.tv and the yumori mobile apps) is operated by UpLevel Technologies LLC (“we”, “us”). This policy explains what we collect, why, who processes it for us, and the choices you have. Short version: we collect what we need to run your account and your purchases, we don't sell your data, and we don't use advertising or cross-app tracking SDKs.
1. What we collect
- Account data — your email address, a password (stored only as a salted bcrypt hash; we never see or store it in plain text), display name, optional @handle and bio, and which bundled avatar you picked.
- Viewing activity — shows you save to My List, your watch progress (show, episode, position) and watch history, episodes you unlock, and likes/follows.
- Economy & purchases — your coin and gem balances and a ledger of every change (daily rewards, redeem codes, unlocks, purchases, refunds). For App Store purchases we store Apple's transaction ID, product ID and subscription expiry. Payments are processed by Apple; we never receive your card or billing details.
- Content you post — comments and replies, and reports you file about content or users, plus users you block.
- Notifications — in-app notifications we generate for you (replies, mentions, rewards).
- Security & technical data — sign-in sessions (with the device's user-agent string and timestamps), and IP addresses, used for rate limiting and abuse prevention and kept in short-lived counters (typically deleted within a day) and in server logs.
We do not collect your precise location, contacts, photos, microphone or camera data, and we do not use advertising identifiers (IDFA/AAID).
2. How we use it
- To create and secure your account, keep you signed in, and let you reset your password.
- To stream shows, remember where you left off, and show your list and history across devices.
- To credit purchases, rewards and codes, and to handle refunds Apple notifies us about.
- To run comments and community features, and to review reports and enforce our Community Guidelines.
- To prevent fraud and abuse (rate limits, suspensions) and to diagnose errors.
- To send service emails you need, such as password-reset links. We do not send marketing email without your consent.
Legal bases (where GDPR/UK GDPR applies): performance of our contract with you (running your account and purchases), our legitimate interests (security, abuse prevention, improving the service), and legal obligations (e.g. tax records for purchases, responding to lawful requests).
3. No ads, no tracking, no selling
yumori contains no third-party advertising SDKs and no cross-app or cross-site tracking. We do not sell or “share” personal information for targeted advertising as those terms are defined under California law, and we do not build advertising profiles.
4. Who processes data for us
We use a small number of service providers, under contract, only to run yumori:
- Railway — application hosting (our servers run here).
- Neon — managed Postgres databases (United States).
- Cloudflare — DNS and media storage/delivery (R2) for video and images.
- Apple — in-app purchases and subscriptions; Apple's own privacy policy governs payment data.
- Email delivery provider (Resend) — sends transactional emails such as password resets.
- Error monitoring (Sentry), when enabled — receives technical error reports that may include your account ID.
We may disclose information if required by law, to protect the safety of users or the public, or as part of a merger or acquisition (with notice to you).
5. Where data is stored
Data is stored and processed in the United States. If you use yumori from elsewhere, your data is transferred to the US; where required we rely on appropriate safeguards such as Standard Contractual Clauses.
6. How long we keep it
- Account, library and ledger data: for as long as your account exists.
- Sign-in sessions: up to 30 days of inactivity; password-reset links: 1 hour.
- Rate-limit counters (which include IP addresses): typically under 24 hours.
- When you delete your account we delete it immediately (see below). We keep one audit record of the deletion that contains only a one-way hash of your email — never the email itself.
7. Your choices and rights
- Access / portability — download a copy of your data any time: signed in on the web, open yumori.tv/api/me/export (the app uses the same endpoint).
- Correction — edit your display name, handle, bio and avatar in your profile.
- Deletion — delete your account in the app (Profile → Settings → Delete account) or on the web at yumori.tv/delete-account. This permanently removes your account, sessions, progress, saves, coin/gem ledger, unlocks, likes, follows, blocks and notifications. Your comments are anonymised (shown as “Deleted user”) so reply threads stay readable.
- Other rights — depending on where you live (e.g. EEA/UK, California) you may object to or restrict processing, or lodge a complaint with your data-protection authority. We don't discriminate against you for exercising your rights.
Deleting your yumori account does not cancel an App Store subscription — manage that in your Apple ID settings.
8. Security
We use TLS in transit, store passwords only as bcrypt hashes, store session tokens only as SHA-256 hashes, limit access to production systems, and rate-limit sign-in and other sensitive actions. No system is perfectly secure; if we learn of a breach affecting you we will notify you as the law requires.
9. Children
yumori is not directed to children under 13 and we do not knowingly collect personal information from them. If you believe a child under 13 has created an account, contact us and we will delete it.
10. Changes
We'll update this page when our practices change and change the “Last updated” date. For material changes we'll notify you in the app or by email.
11. Contact
UpLevel Technologies LLC · support@yumori.tv
Questions? Email support@yumori.tv · Support · Privacy · Terms