Skip to content
Y Yappiely
EN English JA 日本語
Privacy Policy Terms of Service
Launch legal draft This document takes effect at commercial launch after operator details, contact channels, service providers, retention operations, billing rules, jurisdiction, and legal review are finalized.

Privacy Policy

Draft version 0.1. Last updated July 18, 2026.

Yappiely is a hosted commenting service that website owners can embed on their websites. This draft explains how Yappiely handles personal information when an owner uses the dashboard, a reader uses an embedded comment widget, or someone contacts Yappiely.

The website embedding Yappiely may have its own privacy policy and may independently determine how comments and visitor information are used. Questions about a publisher’s use of information should be directed to that publisher.

1. Operator and contact details

Yappiely’s legal operator name, postal address, privacy contact, security contact, hosting region, and required regional representatives will be published before this draft becomes effective.

Until those details and a privacy-request workflow are available, this page is informational and should not be treated as an effective privacy notice.

2. Information Yappiely collects

Owner account information

When a website owner signs in through GitHub or Google, Yappiely may receive and store:

  • name;
  • email address;
  • avatar or profile-image URL;
  • GitHub or Google account identifier;
  • OAuth access token;
  • authentication provider; and
  • account and session timestamps.

Owners may also provide profile details, website domains, discussion descriptions, publishing and moderation settings, embed configuration, and support communications.

Comment and discussion information

When a reader comments or replies, Yappiely stores information including:

  • display name;
  • comment or reply content;
  • page URL and site domain;
  • parent and reply relationships;
  • submission and update timestamps;
  • visibility, deletion, and review status;
  • moderation decisions, categories, reasons, confidence, provider and model metadata, latency, and audit history where applicable; and
  • selected reaction option and reaction timestamps; and
  • owner replies and moderation actions.

Comments may contain personal information that a commenter chooses to include. Commenters should not submit passwords, credentials, financial details, government identifiers, health information, or other sensitive information.

Visitor and technical information

When a reader submits a comment or reply, Yappiely collects or generates:

  • one global pseudonymous visitor identifier and any merged token aliases;
  • current IP address and global last-seen time;
  • comment and reaction activity linked across Yappiely sites;
  • browser and request metadata normally included in HTTP requests;
  • rate-limit and abuse-prevention signals; and
  • error, security, and operational logs.

A publisher can view a visitor’s global identifier, current IP address, global last-seen time, and linked activity, but only activity associated with that publisher’s own sites.

Public comment responses do not expose IP addresses, visitor identifiers, OAuth data, or moderation-review timestamps.

When a widget loads, Yappiely records one token-deduplicated view for that discussion. The stored view record contains an opaque SHA-256 token digest and does not store an IP address. The request IP may be used to limit new view-token issuance. View totals are discussion engagement counts, not general page-view or traffic analytics.

Browser local storage

The embedded widget uses browser local storage inside the Yappiely iframe to remember:

  • light or dark theme preference;
  • the reader’s submitted display name;
  • one global visitor token;
  • discussion-keyed view tokens; and
  • pending comments hidden while awaiting review.

Yappiely does not currently provide a commenter account or public cross-site profile. The global visitor token can link comment and reaction activity across Yappiely sites, although browser storage partitioning may limit continuity. A reader can clear this data through browser settings, although doing so may remove pending-comment state, view deduplication, and continuity information.

Support and business communications

If someone contacts Yappiely, the service may store the person’s name, email address, organization, message, attachments, and information needed to respond.

Payment information

Billing and checkout are not currently implemented. If paid plans launch, this section will be updated to identify the payment processor and explain the billing contact, transaction, tax, and payment-status information Yappiely receives. Yappiely is not intended to receive full payment-card numbers directly.

3. How information is used

Yappiely uses information to:

  • create and authenticate owner accounts;
  • provide, operate, maintain, and secure the service;
  • associate discussions with the correct site and page;
  • publish, hide, organize, and display comments and replies;
  • let owners administer sites and participate with a verified Owner identity;
  • provide moderation queues, visitor history, filters, and audit records;
  • count token-deduplicated discussion views and reactions;
  • detect abuse, enforce rate limits, investigate incidents, and protect public endpoints;
  • provide optional AI-assisted moderation;
  • respond to support requests and service communications;
  • monitor reliability and diagnose errors;
  • enforce the Terms of Service;
  • comply with legal obligations and valid legal requests; and
  • process billing if paid services launch.

The working policy commits Yappiely not to sell personal information for money or use comment content to build cross-site behavioral advertising profiles. This commitment becomes effective only when the final policy is published.

4. AI-assisted moderation

If a publisher enables automoderation, Yappiely may apply deterministic rules and then send information to a configured AI moderation endpoint when no rule resolves the submission.

The AI request may include:

  • commenter display name;
  • comment content;
  • page URL;
  • site domain and site identifier;
  • display name and content of a parent or referenced comment; and
  • technical prompt and model settings.

AI-assisted decisions can be inaccurate. Clear spam may be hidden automatically, while suspicious or unavailable decisions may require human review. Publishers retain moderation control.

The production AI provider, processing location, retention policy, model-training terms, and transfer safeguards will be disclosed before this draft becomes effective.

5. Legal grounds

Where applicable law requires a legal basis, the final policy may rely on:

  • contract, to provide Yappiely to website owners;
  • legitimate interests, to operate and secure the service, prevent abuse, support publishers, and maintain discussion integrity;
  • consent, where required for optional storage, communications, or other processing;
  • legal obligations; and
  • establishing, exercising, or defending legal claims.

A publisher embedding Yappiely is responsible for identifying its own legal basis and providing any notice or consent required for its use of Yappiely.

6. How information is disclosed

Yappiely may disclose personal information to:

  • the publisher responsible for the site where a comment, reaction, or discussion view occurred, with linked visitor activity restricted to that publisher’s sites;
  • hosting, infrastructure, content-delivery, security, monitoring, support, and communications providers;
  • GitHub or Google for owner authentication;
  • AI moderation providers when automoderation is enabled;
  • future payment and tax providers;
  • professional advisers;
  • authorities or other parties when required by law or reasonably necessary to protect rights and safety; and
  • a buyer, investor, successor, or adviser during a merger, financing, reorganization, or asset transfer.

The final policy will identify current subprocessors or link to a maintained subprocessor list.

7. International transfers

Yappiely and its providers may process information outside the country where a user lives. The final policy will identify the primary hosting region and applicable contractual or legal transfer safeguards.

8. Retention and deletion

A final retention schedule is not yet operationally verified. Before this draft becomes effective, Yappiely must define and implement retention for:

  • owner accounts and site configuration;
  • comments, discussions, global visitor records, reactions, view-token digests, and moderation history;
  • OAuth access tokens;
  • security and rate-limit logs;
  • support communications;
  • billing and tax records; and
  • production backups.

Owners can delete their accounts through the dashboard. Account deletion removes owned sites and associated discussions from active application data, subject to any backup, security, dispute, and legal-retention rules stated in the final policy.

An owner may replace a deleted parent comment with an immutable “[deleted]” tombstone so replies remain understandable. The original content is no longer publicly displayed, while structural metadata may remain.

Yappiely does not currently provide a generic customer-facing export tool.

9. Security

Yappiely uses technical and organizational measures intended to protect information, but no internet service is completely secure. The final policy will identify a security contact and describe the production security and incident-response process.

OAuth access-token storage is under review. Before launch, Yappiely must encrypt retained tokens at the application level or stop retaining tokens that are not required after sign-in.

10. Individual rights and choices

Depending on location, a person may have rights to request access, correction, deletion, restriction, objection, portability, withdrawal of consent, or review by a data-protection authority.

Because commenters do not have Yappiely accounts, a request may need to include the site domain, page URL, display name, approximate submission date, and comment text. Yappiely may coordinate with the relevant publisher and verify the request.

A dedicated privacy contact and request-verification workflow will be published before this draft becomes effective.

11. Regional disclosures

The final policy will include disclosures required for the operator’s launch markets, which may include:

  • Japan’s Act on the Protection of Personal Information;
  • the GDPR and UK GDPR;
  • Swiss data-protection law; and
  • applicable United States state privacy laws.

The operator’s legal identity, processing roles, international-transfer details, representatives, and appeal process must be finalized before these sections become effective.

12. Children

Yappiely is not directed to children under 13, and owner accounts are intended for adults. Publishers operating child-directed sites must not enable Yappiely unless they have established a legally compliant notice and parental-consent process and received any approval Yappiely requires.

13. Third-party websites

Yappiely may appear on websites it does not operate and may link to third-party content. Yappiely is not responsible for a publisher’s or third party’s privacy practices. Users should review the policy of the relevant website.

14. Changes

When the final Privacy Policy becomes effective, Yappiely may update it to reflect changes in the service, law, or data practices. Material changes will receive any additional notice required by law.

15. Contact

The legal operator, postal address, privacy email, security email, and regional contact details will be added before this draft becomes effective.

Yappiely home Privacy Policy Terms of Service © 2026 Yappiely