Privacy Policy
Yokharita
This Privacy Policy explains what information Yokharita (operated by Erebos Lab) collects, how it is used, who it is shared with, and the choices you have. By using Yokharita you agree to the practices described here.
Data-safety summary
At a glance, here is the data the app collects, whether it is linked to your identity, and whether it is used to track you across other companies’ apps and websites.
| Data category | Linked to you | Used for tracking | Purpose |
|---|---|---|---|
| Contact Info | Yes | No | Collected only if you create an optional account: to sign you in and save your programs and profile. Browsing and searching the catalog work without an account. |
| User Content | Yes | No | Power the eligibility matcher and your saved list. When you are signed in, this content is stored on our backend so it syncs across devices; the session token is kept on your device. |
| Usage Data (First-party) | Yes | No | Return catalog results and power “similar programs.” Handled by our own backend; no third-party analytics SDK is used. |
What we collect
Contact Info
- Email address
- Full name / display name
Collected only if you create an optional account: to sign you in and save your programs and profile. Browsing and searching the catalog work without an account.
User Content
- Programs you save or favorite
- Your student eligibility profile (the exam scores, preferences, and details you enter for matching)
- Program-fit / eligibility analyses generated for you
Power the eligibility matcher and your saved list. When you are signed in, this content is stored on our backend so it syncs across devices; the session token is kept on your device.
Usage Data (First-party)
- Program search queries and the programs you view
Return catalog results and power “similar programs.” Handled by our own backend; no third-party analytics SDK is used.
What we do NOT do
- You can browse and search the catalog without an account; profile and saved data are collected only when you sign in.
- Ads are OFF by default — the AdMob SDK is env-gated off and collects no advertising identifier unless the owner explicitly opts in (with an App Tracking Transparency prompt).
- No third-party analytics or crash/diagnostics SDK is used; notifications are local only, with no push server.
- No location, microphone, camera, or contacts access — those permissions are explicitly blocked.
- We do not sell your personal information.
Third parties who process your data
We share data only with the processors below, each bound to use it only to provide their service to us. Items marked "unverified" are placeholders we must confirm and name before this policy is treated as final.
- yok API (first-party backend, Cloudflare) — Program catalog, search, saved favorites, your eligibility profile, and program-fit analyses — your account data lives here when you sign in
How we use your information
- Operate and personalize the app and its core features.
- Maintain your account, authenticate sessions, and provide support.
- Process payments and manage subscriptions/entitlements.
- Keep the service secure and prevent fraud and abuse.
- Comply with legal obligations and enforce our Terms of Service.
- Improve the product through aggregated, de-identified analytics.
Data retention
We keep personal information only as long as needed to provide the service. Account data is retained while your account is active and for a short recovery window after deletion, then deleted or anonymized. Billing records are retained as required by tax and accounting law. Backups are purged on a rolling basis.
Your rights and choices
Depending on your jurisdiction you may access, correct, export, or delete your personal data, object to or restrict certain processing, and withdraw consent. You can delete your account and its server-side data from within the app, or by emailing us. We respond within 30 days.
Children’s privacy
The app is not directed to children under 13 (under 16 in the EEA/UK) and we do not knowingly collect their data. If you believe a child has provided us data, contact us and we will delete it.
Security
We use industry-standard safeguards including TLS in transit, encryption at rest for sensitive fields, hashed passwords, least-privilege access, and audit logging. No system is 100% secure; please use a strong, unique password.
Changes to this policy
We may update this policy. Material changes will be reflected by a new "Last updated" date and, where required, announced in the app.
Contact
Privacy questions? Email [email protected].