Privacy policy.
Yachito reads your notes, and some of those notes are the most private things you will ever write down. This page says exactly what leaves your computer, where it goes, and how to take it back. It is written from the code, not from a template.
Last updated 28 September 2026. Applies to the Yachito desktop app for Mac and Windows, yachito.com, and the Yachito account service.
The short version
- Your notebook is plain markdown files on your own disk. We do not have a copy unless you turn on sync, and then we hold only ciphertext we cannot read.
- When you chat, the context for that message goes to the AI model you chose. A local model keeps it on your machine. A cloud model (Claude via Yachito Cloud, or your own Claude or OpenAI key) sends it to that provider for the length of the request.
- We do not read your conversations. The Yachito Cloud gateway forwards your request and records token counts. It does not store what you said or what the model answered.
- Usage analytics in the app are off by default and never carry content, file names, or prompts when on.
- To delete everything we hold, email hello@yachito.com. There is no self-serve delete button yet; we say so below rather than pretend.
Who we are
Yachito is made by Tallboy Consulting, Inc. We are the data controller for the account service and this website. For anything on this page, write to hello@yachito.com.
What stays on your computer
Everything the companion knows about you lives in a folder of markdown
files, by default ~/Documents/Yacho/, or an existing
notebook folder you point it at. Your notes, journal, dreams, tasks,
the profile the companion builds about you, and its memory files are
all ordinary text files there. You can open them in any editor, back
them up however you like, and take them with you if you stop using
Yachito.
App settings, including any API keys you paste in, are stored in a
settings.json file in the app's data folder on your
machine. Keys in that file are not encrypted at rest; they are
protected by your user account and disk encryption, the same as any
other file you own.
Optional integrations read local sources and leave them local:
- Calendar and Reminders (Mac) are read through the system's scripting interface after you grant permission in macOS. Events are summarized into the companion's context; they are not sent anywhere except as part of a chat message, under the rules in the next section.
- Dictation (Mac) uses Apple's speech recognition, on-device when your system supports it.
- GitHub issues, if you connect a repository, are fetched with your own
ghlogin and written into your notebook's Sources folder.
What goes to an AI model, and when
Yachito does nothing with your notes until you talk to it. When you send a message, the app assembles the context that message needs: your message, recent conversation, relevant notes the companion has decided to read, and your profile and memory files. That context goes to whichever model you chose in Settings. There are three choices, and they differ in where the data goes.
A local model
With oMLX, Ollama, or any OpenAI-compatible server running on your own
machine, the request goes to localhost and nothing leaves
your computer. This is the option to pick if that matters most to you.
Your own API key
With your own Claude or OpenAI key, the app calls that provider directly from your computer. We are not in the path and do not see the request. That provider's privacy terms apply (Anthropic, OpenAI).
Yachito Cloud
The free trial and the paid plan use our gateway, which forwards your request to Anthropic's Claude API with our key. For each request the gateway records the model used, input and output token counts, the number of server-side web searches, and a hash of your device token, so we can meter usage and bill correctly. It does not store the content of the request or the response. Requests are forwarded as they arrive and streamed straight back to you.
Anthropic processes the request under its commercial terms, which state that API inputs and outputs are not used to train its models. Anthropic may retain API data briefly for abuse monitoring; see its privacy center for the current retention window.
Web search
If you add your own Tavily key, the companion's web searches go from your computer to Tavily. On the paid plan, searches run inside Anthropic's API as part of the same request. Either way, the search query is generated by the model from your conversation, so treat it as something that can carry context.
Sync
Sync is optional and off until you enable it. When it is on, your notebook is encrypted on your device before anything is uploaded, and our server stores only the result.
- Each file is encrypted with XChaCha20-Poly1305 under a key derived from a notebook key that is generated on your device and stored in the macOS Keychain or Windows Credential Manager. The notebook key never reaches our server in a form we can use.
- File names and paths are also hidden: the server sees an opaque id per file, plus its size and the time it last changed.
- Adding a second device is done device-to-device with a short code you type. The server relays a sealed envelope it cannot open; the code itself never reaches us.
- Your recovery code, shown once when you enable sync, unlocks an escrowed copy of the notebook key. The escrow is encrypted under a key derived from the code, and the code has enough entropy that we cannot guess it. If you lose every device and the recovery code, your synced notebook cannot be recovered by us or anyone.
What that means in practice: a copy of our database would give someone your encrypted blobs and the sizes and timing of your edits, and nothing else. The operator of the service, including the person who wrote this page, cannot read your notes.
When you delete a file on a synced device, the server keeps a tombstone (the id, with the content removed) so your other devices learn about the deletion. You can revoke any device from Settings; its access ends immediately.
Your account
You need an account only for Yachito Cloud and sync. Sign-in is handled by Clerk; we store the account id Clerk gives us, the email address on it, and the invite code you redeemed. Each device you pair gets a long-lived token; we store a hash of it, the device's name and platform, when it was created, and when it was last seen.
If you subscribe, payment is handled by Stripe. We never see your card number. We store your Stripe customer id, subscription id, plan, and current period end so the app knows what you are entitled to. Stripe's privacy policy covers the payment itself.
The free trial issues a token without an account. We store a hash of the token, a truncated hash of the network address it was minted from (to limit trials per network), and the date it started.
Analytics and telemetry
In the app
Usage telemetry is off by default. Onboarding asks once; you can change your answer in Settings at any time. When it is on, the app sends a small set of named events (app opened, onboarding step reached, model type chosen, a chat turn happened, a feature was used, a usage cap was hit, an error class occurred) to PostHog, with the app version and your OS major version. Each event is tied to a random install id that is minted the first time an event is sent and is never linked to your email, account, or device token.
The app enforces an allowlist of properties per event at runtime, so message text, note content, file names, and prompts cannot ride along even by mistake. There is no analytics SDK, no autocapture, no session recording, and no cookies in the app.
On the gateway
For every Yachito Cloud request, the gateway sends PostHog one event with the model, token counts, and computed cost, keyed by a prefix of your device-token hash. This is how we watch our own costs. It carries no content.
On this website
yachito.com uses PostHog for page views and button clicks, with session recording disabled. The download page also fetches a small release manifest so it can show what's new. If you join the waitlist, we store the email address you enter, the name if you give one, which page you signed up from, and the platform you picked.
Operator notifications
A waitlist signup sends the founder a push notification containing the new total count, not your email. In-app feedback sends the first 200 characters of your message, because that is the point of feedback. The full feedback message is stored with your account email if you are signed in, the app version, and a truncated hash of your network address used to limit how many can be sent per day.
Who processes data on our behalf
| Service | What it handles | When |
|---|---|---|
| Anthropic | Chat requests and responses | Yachito Cloud, or your own Claude key |
| OpenAI | Chat requests and responses | Only with your own OpenAI key |
| Tavily | Web search queries | Only with your own Tavily key |
| Railway | Hosts the account service and its Postgres database | Account, trial, sync, billing state |
| Clerk | Sign-in and session | When you link an account |
| Stripe | Payment | When you subscribe |
| PostHog | Usage events (see above) | Website; gateway; app only if you opt in |
| Cloudflare | Serves app downloads and update manifests | Downloading or updating the app |
| Vercel | Hosts yachito.com | Visiting this site |
Local models, Apple Calendar and Reminders, dictation, and GitHub via your own login are not processors of ours; that data does not pass through us.
Retention and deletion
Your notebook on your own disk is yours; deleting the folder deletes it. Nothing on our side is automatically purged except short-lived operational rows: pairing codes and sync enrollment envelopes expire after ten minutes, and rate-limit counters after an hour.
Account rows, device records, encrypted sync blobs, trial records, usage counters, feedback, and waitlist entries are kept until you ask us to remove them. There is no self-serve account deletion yet. Email hello@yachito.com from the address on your account and we will delete your account, devices, sync data, and usage records, and remove you from the waitlist, within 30 days. Stripe retains payment records for as long as tax law requires; we will cancel any subscription as part of the same request.
You can turn off sync, revoke devices, disable telemetry, and switch to a local model at any time from Settings, without contacting us.
Consent and choices
- Cloud model: chosen during onboarding, changeable in Settings. Switching to a local model stops all AI traffic leaving your machine.
- Sync: off until you enable it and save a recovery code.
- Telemetry: off until you turn it on.
- Calendar, Reminders, microphone: granted through the operating system's permission prompts and revocable there.
- Web search: only when you add a key or subscribe.
Yachito is not directed at children under 13, and we do not knowingly collect their data.
Changes to this page
When the code changes in a way that affects what this page says, the page changes with it and the date at the top moves. Material changes will also be noted in the release notes shipped with the app.