Your learning data should be understandable.
This notice explains what YOVA stores across the public Study Profile and alpha, why it uses that information, and which controls are available.
Alpha version · Updated September 8, 20261. What YOVA collects
For the public YOVA Study Profile, YOVA stores the email you submit; your 12 scored habit answers and resulting profile; the study goal, school level, and energy window you provide; your confirmation that you are at least 13; and whether your required waitlist confirmation is pending or confirmed. You can also request to join the waitlist from the landing page without completing the profile. A waitlist request stores its status and consent source. While a confirmation request can still be used, YOVA stores a one-way hash of its one-time token, not the raw token. Earlier Study Profile versions allowed an optional short response and separate choices about launch updates or beta testing. Those earlier responses and choices may remain with an existing lead or report until they are deleted. YOVA may also store campaign and source information, including UTM values, the referring site's hostname, a broad mobile, tablet, desktop, or unknown device category, and basic progress events such as the question number reached or the share-image format chosen. Earlier Study Profile versions may have stored a Meta click identifier with an existing lead or report until it is deleted. YOVA no longer records new Meta click identifiers or loads Meta Pixel. YOVA does not store the raw browser user agent for this first-party device breakdown. Analytics events do not contain your email, answers, private report token, confirmation token, or an earlier optional response. The browser creates an anonymous Study Profile visitor ID in page memory. When a completed quiz opens its private report in a new page load, the browser places that ID in session storage for a one-time handoff, removes it when the matching report loads, and uses it to connect the report-view event to the same funnel. If that navigation is interrupted, the handoff can remain until the tab closes or you clear site data. Other new page loads create a new browser-side visitor ID. First-touch campaign information is saved in this browser, treated as expired after 30 days, and deleted the next time YOVA reads it. YOVA uses it while current so a later report or waitlist request can be attributed to the original visit. A bounded visitor ID may be stored with an accepted progress event and associated with a response or waitlist request created from the same funnel.
While you complete the Study Profile, YOVA saves your unfinished answers and selected context in this browser so you can continue after a refresh. This draft does not include your email. An unfinished draft is kept for seven days after its latest save. If you return after that, YOVA deletes it instead of restoring it. Submitting, restarting, or retaking the profile clears it sooner.
In the alpha, YOVA may store your account email and first name; onboarding preferences; learning goals, plans, and schedules; session completion, timing, quiz outcomes, confidence feedback, and interruptions; uploaded files and extracted text; tutor conversations; support requests; and limited technical or product events, including the same broad device category, needed to operate and improve the product.
While a guided session is open, YOVA may save a small recovery checkpoint in your browser and, for signed-in accounts, in your YOVA account. It contains completed work and results, active study time, completion feedback, and the session version needed to reopen the right lesson. If a repair step is waiting, it also keeps the concept and a short reference answer needed to show that step again. It does not contain an unfinished typed answer, tutor draft, or partially generated lesson text.
Technical error reports contain only limited labels such as the affected product area, route, time, and an internal request reference. They do not contain your study material, tutor messages, typed answers, arbitrary error messages, or technical stack traces. Private Study Profile report routes are reduced to a generic route label before a browser error report is sent.
A typed free-response answer inside a guided learning session may be sent to OpenAI for a one-time comparison with YOVA's reference answer. YOVA does not save that session response in its database; it saves only the resulting concept outcome, confidence, and support context. The Study Profile itself is scored using fixed rules, not AI.
2. How YOVA uses it
YOVA uses Study Profile information to create your report, keep it locked while confirmation is pending, and reopen it after you confirm. To continue after the quiz, you must select the unchecked waitlist box and request the confirmation email. Selecting it asks to join the YOVA waitlist and receive YOVA launch emails. The request remains pending until you open its private confirmation page and select the confirmation button. Opening the page alone does not join the waitlist or unlock the report. The confirmation email is a transactional message sent in response to your request.
YOVA does not send marketing waitlist campaigns before working unsubscribe controls and bounce and complaint suppression are in place and tested. After confirmation, you can unsubscribe from launch emails at any time. You can request removal of a pending or confirmed waitlist record using the contact method in section 4.
For the private alpha, YOVA uses information to authenticate you, save your work, create plans and activities, personalize the size and structure of future sessions, restore tutor context, prevent abuse, diagnose failures, provide support, and understand whether the core learning flow is useful. A limited authorized YOVA operator may review individual lead and account records when needed for support, invitations, email delivery, and launch operations.
YOVA asks about practical study behavior and support needs, not diagnoses. A Study Profile is based on your own answers. It is not a medical, neurological, psychological, or psychometric diagnosis. YOVA does not treat one answer or interruption as a permanent fact about your ability, and legacy diagnosed-condition answers are excluded from AI planning context.
3. AI and service providers
Relevant instructions, learning context, bounded excerpts from source material, and a typed session answer submitted for formative feedback may be sent to OpenAI to generate plans, guided activities, explanations, questions, tutor replies, or an answer comparison. Uploaded material and learner responses are treated as untrusted content, not as instructions to the system.
YOVA currently relies on Supabase for authentication, database storage, and private file storage; OpenAI for private-alpha generation and formative answer checks; Vercel for application hosting; and, when enabled, Resend for the transactional Study Profile confirmation email. These providers process data as needed to deliver their part of the service.
4. Your controls
Providing an email, affirming that you are at least 13, selecting the unchecked waitlist consent box, and completing the emailed confirmation step are required to access a new Study Profile report. Selecting the box requests YOVA launch emails, and you can unsubscribe at any time after confirmation. You can also request a waitlist place from the landing page without completing the profile. Opening the private confirmation page alone does not join the waitlist or unlock a report. Each unlocked report link works without sign-in. Anyone with the link can view that report, so do not post it publicly.
You can clear saved campaign information using your browser's site-data controls.
Inside You, Download my YOVA data creates a portable JSON copy of the account, learning profile, goals, plans, schedules, session evidence, tutor conversations, saved material text, support requests, bounded product and error records, and sanitized service-usage counters available to YOVA when you request it. Work still waiting to sync from another device may not appear.
The account export does not include a separate public Study Profile report, waitlist record, or anonymous Study Profile progress event. The self-service file includes uploaded file names and extracted text, but not the original uploaded files. It does not include your password, sign-in tokens, provider logs, or private security records. To prepare the file, current-device state is temporarily uploaded and merged with available cloud data. YOVA normally removes the private export file and temporary device input within about one hour; if cleanup is delayed or fails, deletion is retried. Each signed download link lasts no more than five minutes. Bounded export job, timing, file-size, and rate-limit metadata may be retained to operate and protect the control.
Archiving a learning goal removes it from current-work surfaces without deleting its history. You can restore an archived goal later. From the archived goal, Delete permanently removes that goal, its sessions and results, linked tutor conversation and deadlines, and attached materials; it does not remove your account, profile, or other goals.
Once you save an export file, the copy is controlled by your device; resetting or deleting data in YOVA cannot remove that downloaded copy. Reset learning data removes learning data and private uploads while keeping your login identity. Delete YOVA account requires recent email verification and permanently removes the login identity together with its account learning data, tutor conversations, support requests, technical records, and private uploads. Private file cleanup is durable and retried if Storage is temporarily unavailable; until it succeeds, a bounded cleanup receipt keeps only the account ID and exact private file paths needed for removal.
A separate public Study Profile report, pending or confirmed waitlist record, or anonymous progress event is not linked to the authenticated account and is not removed by the account-deletion control. For privacy questions, a broader access request, or deletion of a public Study Profile record, email hello@yovaapp.com with the subject “YOVA privacy or deletion request” and identify the email used.
5. Retention and security
Study Profile leads, waitlist confirmation records, and prior report versions are kept while reasonably needed to operate the prelaunch program, preserve the private reports requested by participants, document confirmation status, learn from aggregate response patterns, or meet legal and security obligations, unless deletion is requested. First-touch campaign information is kept in this browser for up to 30 days. An unfinished browser draft is kept for seven days after its latest save and is cleared sooner when you complete, restart, or retake the profile. A pending confirmation token expires after a limited period. Its one-way hash is removed when the request expires, is replaced, or cannot be delivered. After confirmation, a one-way consumed-token receipt supports safe retries for up to 15 minutes. It may remain in the confirmation record after that window, but no longer authorizes confirmation and is cleared when a later request for the same address is processed. Alpha learning data is kept while your account remains active unless you remove it. Limited support or security records may be retained when reasonably needed to resolve a request, prevent abuse, or meet legal obligations.
YOVA stores only a one-way hash of each Study Profile report token and usable waitlist confirmation token, keeps these public-funnel tables behind row-level security, and marks private report and confirmation pages not to be indexed or cached. YOVA also uses account authentication, password hashing through its authentication provider, database ownership rules, private file storage, server-only credentials, validation, application rate limits, and database-backed email cooldowns. No online system can promise perfect security.
6. Age and changes
YOVA is intended for people age 13 or older. The public signup flow requires an affirmation that the person is at least 13. If you are under the age of majority where you live, use YOVA only with permission from a parent or legal guardian. This notice may change as YOVA develops; the updated date at the top will change when it does.