Privacy policy
What Yawp keeps, and why.
Yawp is an assistant that makes phone calls and sends email on your behalf. Doing that requires holding real content — the errands you delegate, the calls it makes, the mail it sends. This page says exactly what is collected, who touches it, and how to make it go away.
Effective 2026-09-19 · Yawp · [email protected]
What we collect
- Account data — your name and email address, managed through our sign-in provider (Clerk).
- Errand content — the briefs you delegate: goals, constraints, contact details of the people you ask Yawp to reach, and the conversation you have with your assistant.
- Call data — for calls Yawp places or answers: the numbers involved, timing, and live transcripts. Call audio passes through our telephony provider in real time so it can be turned into text, and the assistant's side of the call is turned back into speech by a voice synthesis provider. Yawp states on the call that it is an AI assistant.
- Email content — messages Yawp sends on your behalf and replies it receives, including the approval drafts you review. Every outbound message carries a visible disclosure line.
- Standing facts — facts you type on the dashboard about yourself or your household (a name, an address, a date of birth, a member id and the like) so the assistant can use them on errands. Each fact carries a sharing rule you set: shareable with anyone the assistant contacts, or ask first. A fact marked ask first is withheld: the assistant is given the label but never the saved value, and is told not to guess it. There is not yet a way to release it for a single errand. Facts are stored encrypted at rest, and they are never inferred from your mail, your calls or your messages — every one is typed in by you.
- Usage and billing — which errands ran, what they consumed, and subscription state. Card details go directly to Stripe; we never see the number.
- Technical logs — request logs and diagnostics that keep the service working, including a short-lived trace of what our voice pipeline actually said aloud on a call.
How we use it
To run your errands — that is the product. Errand content is sent to large-language-model providers to draft messages and conduct calls; call audio is transcribed to drive the live conversation; email content is transmitted to its recipients. We also use aggregate usage to operate, debug, and bill the service. We do not sell personal data, and we do not use your errand content to advertise to anyone.
What we don't do with your content
Three commitments, stated plainly because they are the ones products in this category most often reserve the right to break:
- We do not record your calls. Yawp keeps a written transcript so you can see what was said. It does not capture, store, or retain an audio recording of a call — not for quality review, not for model training, not at all. If that ever changes it will be an opt-in you are asked for first, and this page will say so before it does.
- We do not train models on your content. Nothing you delegate, say, send, or receive is used to train or fine-tune an AI model — ours or anyone else's. We send errand content to model providers only to carry out the errand in front of them, under business terms that bar them from training on it.
- We do not sell or share your content. We do not sell personal data, share it for cross-context behavioural advertising, or hand it to data brokers.
Who processes it
Yawp runs on a small set of processors, each for one job. Our own servers and databases run in the United States:
- Clerk — sign-in and account identity.
- Twilio — placing and carrying phone calls, and sending the text messages we use to reach you about an errand.
- Speech to text — turning what the other person says on a call into text the assistant can act on. Unless a specific engine is configured for a workspace, this is done by Twilio as part of carrying the call; when one is configured (Deepgram or Google), the call audio is sent there instead.
- Voice synthesis (ElevenLabs by default, and configurable) — turning the assistant's words into the voice heard on a call. What it speaks is generated from your errand, so it is sent there to be read aloud.
- Postmark — sending and receiving email.
- Stripe — subscriptions and payments.
- LLM providers (Anthropic; optionally OpenAI or Google, depending on configuration) — drafting and conducting conversations. Errand content is sent to them to do that work, under terms that bar training on it.
- Railway — hosting and databases.
- Inngest — scheduling the background work that moves an errand along. It receives identifiers and timings, not the content of your calls or messages.
We add a processor only when it does a job on this list, and this page changes when the list does. Some of these are configurable — the voice, the model, the mail provider — so the names above are the current defaults rather than the only ones we may ever use for that one job.
Calls and recording
Calls Yawp participates in are transcribed, and transcripts are kept with the errand so you can see what was said, for up to 365 days (see below). Audio is not recorded or retained. Yawp discloses on the call that it is an AI assistant, in a line composed by our code rather than by the model, so it cannot be talked out of saying it. You are responsible for only directing calls you are allowed to make — including any consent-to-record or notice rules that apply where you and the person you are calling live.
How long we keep it
Conversation content ages out automatically, 365 days after each item was created — measured per item, not per account, and enforced by a job that runs every 15 minutes:
- Call transcripts — deleted 365 days after the call. A transcript is removed whole, never in pieces: the clock starts from the last thing said on the call, so you never see half a conversation.
- Conversation turns — everything you and the assistant say to each other, on every other channel (the dashboard, text messages, a connected chatbot), deleted 365 days after the last turn in that thread, and by the same whole-thread rule.
- Email bodies — removed 365 days after the message. The envelope stays: who it was to and from, the subject line, when it was sent, and whether it was approved, sent, or bounced. That record is what keeps replies routed to the right errand and what shows a message was approved by a person.
- Low-level voice diagnostics — kept about 30 days, then deleted.
What is not on that clock, and stays for as long as your account is active so your history remains yours to consult:
- the errand record itself — its title, its goal and the context you gave it, its constraints and deadline, its status and its outcome;
- the errand's journal — the short notes Yawp writes as it works, including what it understood a call or a reply to have said;
- anything Yawp asked you and the answer you gave — the question it escalated, and your reply, in your own words;
- details captured from a call so the errand has a record of it: the short outcome summary, a confirmation or reference number, a name it was given, and any offer it declined on your behalf;
- the email envelope described above.
Some of that is content in its own right, which is why it is listed rather than summarised: an escalation prompt can quote what a receptionist said, and a confirmation number is as personal as the call that produced it. Nothing is removed while the errand it belongs to is still running, and a removal can run late — the window is when content becomes eligible to go, not a guarantee. Content attached to an errand or an approval that never finished can stay indefinitely.
Standing facts are not a record of an errand, so the 365-day window does not apply to them. They are kept until you delete them or the workspace is closed, and closing the workspace deletes them.
Closing your account removes your workspace data from the live systems; residual copies in backups age out on the backup schedule.
How we protect it
Everything travels over encrypted connections and is stored on managed, access-controlled infrastructure. API keys are stored only as one-way hashes and shown to you once, at creation — we cannot recover one for you, which is the point. Credentials you give Yawp for your own connected tools are encrypted before they are written down. Approval codes are single-purpose, expire within a day, and are deliberately never shown to the model, so the assistant cannot approve its own work.
No system is perfectly secure, and we will not pretend otherwise. If a breach affects your data we will tell you and the regulators who need to know, as the law requires.
Where your data is processed
Yawp is operated from the United States, and our own servers and databases run there. The processors above are US-based, though some of them operate globally and may handle data elsewhere. If you use Yawp from outside the United States, you are sending your data to the United States, whose privacy laws differ from your country's. Where that transfer needs a legal basis — for people in the UK, Switzerland, and the European Economic Area — we rely on the data protection terms we have with each processor, which use the European Commission's standard contractual clauses where those apply. Ask us and we will tell you what covers a given processor.
Your rights and choices
Wherever you live, you can ask us to do any of the following, and we will do it:
- See it — get a copy of the personal data we hold about you, in a portable format.
- Fix it — correct anything inaccurate or incomplete.
- Delete it — remove your data and close your account.
- Limit it — object to or restrict a particular use, or withdraw a consent you gave.
Email [email protected] from your account address. We answer within 30 days, we do not charge for it, and we will never treat you worse for asking. We may need to confirm it is really you before acting on a request. If you are in the UK or the European Economic Area and you think we have it wrong, you can complain to your national data protection authority; in California you may designate an authorised agent to ask on your behalf.
People Yawp contacts. Anyone who receives a Yawp message can reply asking not to be contacted, and the errand's owner is told to stop. They can also write to the address above to ask what we hold about them. See how Yawp works.
Children
Yawp places real phone calls and sends real email, and it is not for anyone under 18. We do not knowingly collect personal data from children. If you believe a child has given us data, write to the address above and we will delete it.
Changes and contact
When this policy changes, the effective date above changes with it. If a change materially affects how we handle content you have already given us, we will tell account holders before it takes effect rather than relying on you to re-read this page. Questions: [email protected].