Last updated: October 1, 2026. Version: privacy.2026-10-01.3.
What changed in this version
- Dated the provider-route status evidence and separated platform-use policy from automated enforcement.
- Explained review of available communication records for spam, fraud, harassment, and other misuse, including patterns across contacts.
- Clarified founder and appointed staff review through beta and V1, with a record of who, why, and when.
- Clarified that operational logs may contain ordinary customer content and that hard-secret redaction is not a content-free-log guarantee.
- Distinguished provider no-training rules, route-specific Zero Data Retention checks, and information You.one keeps for your continuity.
- Clarified manual export, disconnection, Memory forgetting, and deletion requests without promising unverified deletion deadlines.
What this page covers
Segeren Studio LLC, a Wyoming limited liability company, operates You.one and is responsible for this Privacy Policy. Wyoming currently lists the company as administratively dissolved after a missed annual report; we plan to reinstate it. In this policy, "we" and "us" refer to Segeren Studio LLC.
You.one is built to help regular people make progress in real life. This page is meant to tell you, directly, what data the product uses today and where it can go.
This Privacy Policy describes how we handle personal information today. You.one keeps your record so Ava can remember and help. AI providers that receive customer content must be barred from training on it. Zero Data Retention at a provider does not mean You.one stores nothing. We update this policy when our practices materially change and summarize the changes near the top.
Account age
You.one accounts are currently for people who are at least 18 and have reached the age of majority where they live. People who do not meet this rule should not create an account. If we learn that an ineligible person created an account, we may restrict it and review or delete the information associated with it, subject to legal and security retention needs. A parent or guardian can contact us through the privacy request page.
What you share with You.one
When you use You.one, you may share what you type, tap, or submit. That can include the situation you want help with, answers you choose, freeform notes, feedback, your name, or your saved location.
If you put something into You.one, assume it may be processed to run the experience.
What we may store in your browser
Some product state is stored locally in your browser so You.one can feel continuous, even though parts of the experience may also be sent to our backend or service providers when needed.
- your name and saved home location
- appearance and product preferences
- where you left off, saved answers, and screens you can return to
- session or visit IDs that help keep a visit together
What may go to our systems and service providers
Our last recorded route checks, on September 23–24, found customer AI routes restricted while we verified their processing paths. That is dated evidence, not a new verification of every live route. For a supported route, prompts, answers, and recent context needed for the feature may be sent through our Production SpaceXAI account with Zero Data Retention (ZDR) enabled. The table below describes those checks and distinguishes held routes from a separately authorized call that may finish through another service whose ZDR coverage is not yet verified. If a route cannot serve a feature, that feature may be unavailable; we do not silently send customer content to a different AI provider without verified equivalent protection.
Some public pages currently use Google Analytics, which can set analytics cookies and send client or session identifiers, page views, and related device or campaign information to Google before you reach a beta invitation. Accepting the beta Terms does not control this public analytics. We also use or may enable other telemetry and diagnostic tools, including Vercel Analytics or hosting logs, PostHog, and Sentry, to understand quality, reliability, and whether the product is helping. Depending on the tool and route, that can include IP addresses, cookies or session IDs, pages viewed, buttons pressed, forms submitted, campaign and referral information, device and rough geography data, conversion events, error data, screen or route metadata, and in some cases transcript snapshots or request details used for debugging.
Session replay is currently off while we verify its safeguards. If enabled later, we plan to mask public form inputs, but replay could still contain other things you type or see on screen.
Communications and misuse review
The Terms of Service explain permitted and prohibited communications. Cold sales outreach, spam, prank calls, impersonation, harassment, and attempts to evade restrictions are prohibited. These rules apply to channels as they become available; this policy does not announce new communication features.
To investigate and respond to a complaint or other suspected misuse, authorized staff may review relevant available account and communication records, including the requested task, recipient details, timing, contact attempts, outcomes, complaints, and call recordings or transcripts where they were lawfully collected. These records can include information about people you contact, such as their number and any refusal they give. Where we keep a refusal or opt-out record to prevent unwanted contact, it includes the scope expressed by the recipient. A review may consider several contacts together and relevant links between suspected abusive accounts, subject to access restrictions. Staff must not use this review to expose one person’s private content to another. This is part of the service-operation and safety review described below, subject to the narrower connected-service access rules. It is not permission to record a call without required notice or consent, to train a model, or to collect unrelated information. Our rules do not guarantee that every misuse will be detected or prevented. These records follow the retention and request limits in this policy.
Staff review, operational logs, and replay
Joshua Segeren and the people he appoints may review content you put directly into You.one to support you, debug problems, keep the service working, address safety issues, and evaluate and improve the product during beta and V1. This review is authorized through the Terms you accept, subject to any additional consent required by law. Our review policy requires a record of who deliberately reviewed your content, why, and when, with access limited to the purpose of the review. Current access records include the actor and time, but a reason is not yet captured consistently. We are improving those records; this policy does not represent that every current review has a complete reason record. This is not permission to train or fine-tune a model.
Ordinary customer content may remain in operational logs and diagnostics. We try to redact hard secrets, including passwords, payment-card numbers, tokens, and API keys. We do not promise that every secret is successfully removed or that logs are content-free. Do not put hard secrets in ordinary product fields.
This general authorization does not permit staff to read individual messages, files, or other content obtained from a connected Google account for general product research. Google data has the narrower access rules described below. If session replay is enabled, authorized staff may review it for the disclosed purposes.
Session replay is a planned beta feature. If enabled, it can capture screens, screenshots, and text outside masked fields. Do not enter passwords, one-time login codes, payment details, or other secrets into ordinary product fields. We will enable beta replay only after verifying sensitive-field masking and exercising its deletion process. We will disclose its verified retention periods before enabling it. Replay kept for an approved support or safety case and technical diagnostics have separate retention needs. We are still verifying and reducing retention across our systems and providers; this version does not promise a fixed deletion period for those records. Until those replay safeguards are verified, beta replay stays off.
You can use our privacy request form to ask for a copy or deletion of the information connected to you. You can disconnect an optional service separately. Disconnecting a service does not automatically erase what Ava has learned from it; you can ask us to correct or forget that saved understanding or to delete your account.
Other service providers
If you create or use an account-backed experience, authentication and account data may go through Clerk. If you search for or confirm a location, those requests may go through Google Maps. If you use our contact or privacy-request form, SendGrid delivers your message to our You.one mailbox and a founder backup Gmail mailbox. The separate feedback form sends a report through SendGrid to configured feedback recipients and may also store a copy in Vercel Blob or Trello when enabled. We handle these messages and reports manually and retain them as needed to process and document them, subject to applicable law and deletion requests. Public forms use IP addresses to limit abuse. If you leave an optional tip, payment may go through either Stripe or Venmo depending on your choice.
New beta calls are currently held. An earlier call request may still finish. For that call, Twilio can process the phone numbers and both parties' audio and is configured to record the connected conference from its start. A separate Calls service can process the audio for live transcription. You.one may keep the recording, transcript, call status, and provider receipts for your account. Session-replay controls do not cover call recordings; we are still verifying retention and deletion for calls and their providers. You can request deletion through our privacy request form. The primary SpaceXAI account's Zero Data Retention setting does not cover Twilio or the separate Calls service. Participants must receive any notice or consent process the applicable law requires; the recording description here does not waive their rights.
We do not sell personal information or share it for cross-context behavioral advertising. Before starting either practice, we will update this policy and obtain any consent the law requires. Google Signals and ads personalization are not part of the default You.one analytics setup.
Your data, memory, and model training
The content you put in You.one remains yours. We use it as this policy describes; sharing it with Ava does not make it training material. You.one does not train AI models on customer content, and we do not permit our AI providers to train on it.
Remembering context is different from training a model. You.one stores conversations, files, and saved context so you can return to your work. Relevant context may be sent to an AI provider when Ava needs it to respond. That does not change the underlying model or teach it your information for use with other people.
Example: If you ask Ava to help plan a move, You.one may save your conversation and use your budget and moving date in a later response. Keeping those details for your own continuity is not model training.
What AI providers receive and keep
We are working to certify every API that sends or processes customer content, for every data type used on that route. The review covers the actual account and credential, model, endpoint, tools, and any onward processing. A text check does not certify voice, images, files, or Calls. Our aim is to complete those checks for V1. If an available feature has an incomplete check, this policy must identify the feature, what is verified, and what remains unverified. A provider’s account setting alone does not establish complete coverage. We do not silently move customer content to another provider or route whose protections have not been verified.
AI providers process the information needed to generate a response. This may include your request, relevant conversation history, and selected content from files or connected services. AI processing can also support background features, not just messages you send directly to Ava.
Processing-status checkpoint: September 24, 2026. Availability statements in this table describe the last recorded checks. Incomplete checks are disclosed as incomplete; account-level ZDR does not certify every feature.
- Use case
- Text and chat
- AI provider
- SpaceXAI
- What You.one does
- Customer AI requests are currently held while we verify and activate each route. When a supported text route opens, it may send the request and context needed through our Production SpaceXAI account. Saved chats stay in You.one.
- What we can verify about the provider
- Account-level ZDR is active. For supported requests, SpaceXAI's terms say request and response content is processed transiently and deleted by the earlier of response delivery or one hour after the request completes. We are still verifying every text route.
- Use case
- Text and chat
- AI provider
- OpenAI, Groq, Anthropic
- What You.one does
- Does not send customer content to these providers while equivalent ZDR remains unverified.
- What we can verify about the provider
- We have no account-level ZDR proof for these providers. OpenAI's standard API abuse logs may retain content for up to 30 days; no-training alone is not ZDR.
- Use case
- Speech and voice
- AI provider
- SpaceXAI
- What You.one does
- Board voice typing is unavailable while we verify its processing route. Calls are not released for beta; a call already authorized before the hold may still finish through a separate service. You.one may keep its recording and transcript.
- What we can verify about the provider
- Our primary Production account has ZDR enabled, but we have not verified ZDR coverage for every voice route or the separate Calls service account.
- Use case
- Speech and voice
- AI provider
- OpenAI, Groq
- What You.one does
- Does not send customer audio or transcripts to these providers while equivalent ZDR remains unverified.
- What we can verify about the provider
- We have no account-level ZDR proof for these voice routes.
- Use case
- Images
- AI provider
- SpaceXAI
- What You.one does
- Customer image analysis and generation are currently unavailable while we verify those routes. If enabled later, compatible requests may send image inputs through the verified account. Any generated media we keep will be stored by You.one.
- What we can verify about the provider
- The account has ZDR enabled. Under ZDR, provider-stored image outputs and file IDs are unavailable; compatible generated images must be returned inline, such as base64. We are still verifying every image route.
- Use case
- Images
- AI provider
- OpenAI
- What You.one does
- Does not send customer images to OpenAI while equivalent ZDR remains unverified.
- What we can verify about the provider
- We have no account-level ZDR proof for OpenAI image routes.
This table concerns AI-provider retention of request and response content, not the conversations and files You.one saves for you. Account-level ZDR does not prove that every model, endpoint, tool, or input type uses a supported request. No-training and zero-retention are different protections.
SpaceXAI: We enabled Zero Data Retention for our Production SpaceXAI account on September 22, 2026 and verified it using the account used by our live service. Under its ZDR terms, supported request and response content is processed transiently and deleted by the earlier of response delivery or one hour after the inference request completes. This replaces the ordinary 30-day retention period for that content. Non-content account, billing, and operational records are separate.
ZDR applies to supported requests through that account. We are verifying which You.one features and input types use those requests. Features that require SpaceXAI to keep content are restricted or unavailable.
Our SpaceXAI setting does not apply to OpenAI or any other provider. Each route and data type needs its own protection and verification record; the table identifies the restrictions and incomplete checks recorded at that checkpoint. Some features may be unavailable while that work is open. An available feature with incomplete certification must have its specific processing and retention limits disclosed here; that disclosure does not itself establish ZDR. We do not describe all data processing in You.one as zero-retention: You.one and our operational service providers still keep the records needed to run the product.
You can read SpaceXAI’s Enterprise Terms, section 3.4, xAI's API security documentation, and OpenAI's data controls.
What stays with You.one
Provider deletion does not delete your saved information in You.one. We keep customer records in storage we control, including through our hosting and storage providers, so you can continue your conversations and work over time. Those providers still process data to operate the service; ZDR at an AI provider does not mean no company ever stores your information.
Example: When you ask Ava about an uploaded document, the relevant content may be processed to answer your question. Your saved document and conversation can remain in You.one after the AI provider deletes its processing copy.
Temporary conversation caching can make replies faster and reduce repeated processing. It is separate from both model training and your long-term saved history. We review the actual provider feature and its retention behavior before treating a cache as compatible with our privacy commitments.
The access, diagnostics, and deletion limits elsewhere in this policy still apply. A no-training commitment does not mean that support staff can never access content or that every operational record disappears immediately.
Google account connection
Connecting Google is optional. When you choose Connect Google, You.one may request access to the Google products shown in the consent screen, including Gmail, Drive, Calendar, Contacts, and Tasks. You can grant only some requested access; You.one treats that as a valid partial connection and shows which products are connected, declined, unavailable, still syncing, or need attention.
The connection lets Ava stay oriented to the email, files, meetings, contacts, and changes you authorize so you do not have to explain the same context repeatedly. It does not give Ava unlimited authority. Reading connected content does not by itself authorize Ava to send a message, make a call, buy, publish, permanently delete provider content, or take another consequential external action.
For Gmail, You.one stores account-scoped mailbox metadata across the authorized mailbox, including message and thread identifiers, dates, sender and recipient headers, subject, labels, snippets, attachment metadata, provider state, and deletion records.
For recent messages, it may also store normalized message bodies and raw message copies, depending on the connection's sync mode, for up to the most recent 24 months. The full normalized and raw copies are encrypted by You.one before private file storage. Searchable message text is stored separately in our account-scoped database; it is not the encrypted private-file copy described above. Older message bodies and attachment content are retrieved and cached when you or Ava need them for an authorized feature.
For Drive and other connected Google products, You.one stores the provider identifiers, metadata, change history, and content needed for synchronization, search, retrieval, and the features you use. Google remains the canonical source for Google files and records.
Connection credentials and tokens are encrypted in a private credential vault and are kept separate from mirrored source content. Our credential-handling paths are designed to keep passwords, one-time codes, cookies, OAuth tokens, and authorization headers out of the Board, Activity, search documents, model context, and ordinary application logs. We try to redact hard secrets; a secret entered into an ordinary product field may still appear in a log.
Source synchronization, parsing, and indexing are separate from Ava’s use of connected context. When an Ava feature needs connected content, only relevant authorized evidence is retrieved for that interaction or background task. You.one may send that selected evidence to approved AI service providers to provide the feature for you. Google user data is not sold, used for advertising, or used to train generalized models across users.
You.one's use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements. Staff do not read individual Google messages or files for general beta research. A person may view specific Google content only after your affirmative agreement to that specific review or when necessary for security or legal compliance. Aggregated Google-derived data may be used for internal operations where Google's policy permits it.
How we use data
- run the guided experience
- remember your settings and resume progress
- improve quality, safety, speed, and reliability
- learn where people get stuck and what actually helps
- process feedback and optional payments
- synchronize and retrieve content from services you choose to connect
- help Ava understand authorized context and provide features for you
The goal is to be practical, clear, and helpful, not to collect data for its own sake.
These purposes remain within the Terms authorization and any additional consent required by law. They do not override the narrower limits on connected Google data described above. Public analytics is separate from beta participation.
Privacy controls today
Privacy controls are manual today. Through our privacy request form, you can ask to access or export your information, correct it, forget saved Memory, delete connected-source copies, or delete your account. You can also disconnect an optional service. We may need enough detail to identify your records and verify the request.
Deleting source copies and forgetting saved Memory are separate requests; disconnecting a service does not automatically do both. Our deletion process is intended to reach relevant derived search indexes and caches and prevent deleted information from returning through a restore or reconnect. Backups, provider records, security records, and information we must keep by law have separate limits. We explain applicable exceptions when handling your request. We are verifying this process and do not yet promise fixed completion or backup-expiry periods.
For California residents
If you are in California, you can ask us to tell you what we have connected to you, correct it, delete what we control, or stop any sale or targeted-advertising share if that ever applies.
For now, send a privacy request. These requests are handled manually for now, with possible provider retention limits.
For Canada residents
You can ask to access or correct personal information we control through the same privacy request form. We handle requests manually under the law that applies where you live. Our named service providers may process your information in the United States or other countries where they operate; that information may be subject to the laws of those places.
Your choices and cautions
You can clear local You.one data by clearing this site's browser storage and cookies. You can also choose not to submit feedback or payment details.
You can ask us to review, correct, or delete information connected to you by sending a privacy request. Because this is manual today, include the email, account, browser/session details, or other context we can use to find the relevant records.
You can disconnect Google at any time. Disconnecting revokes the connection, stops new synchronization, and begins the applicable deletion process for the mirrored source data You.one controls. It does not automatically erase excerpts already saved in a You.one conversation or what Ava learned from connected content; you can ask us to correct or delete that saved understanding. Disconnecting You.one never deletes the original email, file, calendar, contact, task, or other content from Google.
If something is highly sensitive, share as little as possible. You.one is an AI-powered product. It can be useful, but it can also be wrong. It is not an emergency service, crisis service, or a substitute for a qualified professional.
If you have a privacy question, send a privacy request. For other feedback, contact us.
Changes to this policy
Each version has its date, version identifier, and a summary of changes near the top. We update this policy when our data practices materially change. We explain what changed in plain language, with examples where they help, and give notice by email or in the product when a change materially affects your rights or how we use your information. We will ask for a new affirmative choice when applicable law requires one; continuing to use You.one alone does not authorize a new use that requires separate consent.
September 25, 2026: Clarified that public analytics can run before a beta invitation; distinguished replay limits from call-record retention; and described the separate searchable Gmail text copy.
September 25, 2026: Clarified Twilio's role and the audio and records from an earlier call request that may finish during the current beta hold.
September 25, 2026: Clarified that public Google Analytics is active, separated other service providers from beta research, and aligned material-change notice with the Terms.
September 25, 2026: Clarified how recent Gmail body copies and searchable text are stored.
September 24, 2026: Named Segeren Studio LLC as the operator of You.one and the party responsible for this policy.
September 24, 2026: Clarified that customer AI text and image routes are currently held while their provider privacy checks are completed.
September 24, 2026: Clarified Google-data staff access, current diagnostic-retention uncertainty, Canadian requests, and the separate Calls service exception.
September 23, 2026: Added a provider comparison table that makes the unverified OpenAI and other-provider retention limits explicit, clarified the beta voice hold, explained why session replay is off pending safeguards, and distinguished the contact/privacy-request and feedback delivery routes.
September 22, 2026: Added our verified xAI ZDR activation, explained why remembering your context is not model training, and distinguished provider deletion from the records You.one keeps for you. This update does not claim ZDR for every provider.