← hYYa ai

Privacy Policy

Last updated: 3 October 2026 · hYYa ai by hYYa Apps

Overview

Privacy is built into hYYa ai at the architecture level — not as an afterthought. hYYa Vault mode runs on your device and is offline by default — your hYYa Vault conversations never reach hYYa’s servers, and every path that uses the network is optional and named in section 1. hYYa Cloud mode transmits only what is necessary to produce your AI response, nothing more. hYYa Cloud is encrypted in transit (TLS 1.3) and at rest, but it is not end-to-end encrypted — cloud AI requires the model provider to read your prompt to generate a reply. For on-device privacy, use hYYa Vault.

1. hYYa Vault Mode — What hYYa Collects

hYYa collects nothing from hYYa Vault. All AI inference, conversation history, memory, and documents are processed and stored entirely on your device. hYYa operates no server that receives them, and deleting the app removes everything.

That is a statement about what hYYa receives, not a claim that the app never uses the network. hYYa Vault works with no internet connection, and every AI feature runs on your device. Nothing you type, store or open is sent anywhere unless you turn on an online feature. The app does go online in the cases below:

  • Starting the app while signed in — if you have signed in to a hYYa Cloud account, hYYa Vault refreshes that session with hYYa’s own servers when it launches, so it knows your plan is still current. This goes to hYYa, not to a third party. It is the only path here that repeats on its own, and it stops when you sign out.
  • Downloading an AI model — when you install a local model, hYYa Vault downloads it from Hugging Face. When you ask it to check for new models, it reads the model list from GitHub (GitHub Pages); on Android it also asks Hugging Face whether a model you have installed has a newer version. These are file and list downloads; no personal data is sent.
  • Adding your first document — the first time you add a document to a DataLens lens or a hYYa Vault chat, the app asks before it downloads its on-device search model from Hugging Face (about 0.5 GB on Mac, iPhone and iPad; 135–252 MB on Android). Older versions of the app download it without asking and may check Hugging Face for updates to it; updating the app stops both. No personal data is sent.
  • On Android, Google’s built-in parts — Android’s browser engine, which draws the app’s screens, checks with Google for updates the first time the app opens and for autofill hints while you type. Google’s ML Kit, which reads scanned pages on your phone, then sends Google basic diagnostics: device model, Android version, app version, a random install ID and speed figures. Neither sends your text.
  • Signing in to a hYYa Cloud account — optional, and the gate for the online features below. hYYa Vault then reads your account’s plan so it knows what to offer you. Your on-device conversations are not sent. Signing in, with or without a paid plan, enables Web Search, Connections and cloud DataLens; BYOK requires hYYa Cloud Ultra.
  • Switching to hYYa Cloud — an explicit switch you make. Anything you do in hYYa Cloud mode is covered by section 2 below, including cloud DataLens.
  • Web Search — optional, and off unless you turn it on. Your search terms are sent to hYYa, which runs the search and returns the results — the request carries the query only. Your documents and your conversation are never sent with it.
  • Your own provider API key (BYOK) — optional, and available on hYYa Cloud Ultra. Used only for the online features you choose to run under your own key.

This list is checked by watching what the app actually does on the network, not only by reading its code — that is how several of the paths above were found. hYYa keeps it current as the app changes. It does not cover your device’s own services: app store, updates and crash reports — and, on iPhone and iPad, the Safe Browsing list that Safari also uses, which iOS may refresh when an app opens — are run by Apple or Google, not by hYYa. If you want to confirm any of this rather than take hYYa’s word for it, turn the online features off and watch the app’s network activity, or run it with Wi-Fi off.

2. hYYa Cloud Mode — What hYYa Collects

When you use hYYa Cloud mode, hYYa collects:
  • Email address — stored in Supabase to manage your account and send sign-in codes.
  • Conversation messages — routed via OpenRouter to the AI model provider that generates your response (e.g. Anthropic, Google, xAI, DeepSeek). These providers do not use your messages to train their models. If you add your own provider API key (BYOK), that key is encrypted at rest on hYYa’s servers (AES-256), never shown again after you save it, and used only to send your messages directly to that provider under your own key — across chat and DataLens. You can remove a saved key at any time in Settings → API Keys.
  • DataLens documents — if you upload documents to a DataLens, their text is stored in Supabase and sent to Google’s embedding API so hYYa can search and reason over them. Used only to power your DataLens.
hYYa does not collect your photo library, contacts, location, or any data you have not explicitly shared in a conversation.

3. Payments

Purchases on the web are handled by Polar, as Merchant of Record. Purchases in the hYYa ai app are handled by Apple (the App Store, on iPhone, iPad and Mac) or Google (Google Play, on Android). hYYa never sees or stores your card number, bank details or payment credentials — you enter them with Polar, Apple or Google, each of which processes payment data under its own privacy policy and sends your receipts. When you buy in the app, hYYa receives the store’s record of the purchase — which product, the store’s reference numbers for the order, and the hYYa account it was bought for — so it can confirm the purchase with the store, add it to your account, and act on later changes such as a renewal, cancellation or refund. The app stores list this as “Purchase history”.

4. Third-Party Services

  • Vercel — hosts the hYYa web app and processes your requests in transit; it does not retain your conversation content.
  • Supabase — hYYa’s database and file storage: your account, conversations, memory, and DataLens documents are stored here, protected by row-level security.
  • OpenRouter — routes your hYYa Cloud conversation messages to the AI model provider that generates your response. OpenRouter does not retain your prompts, and hYYa configures routing to exclude providers that train on your data.
  • AI model providers (such as Anthropic, Google, xAI, DeepSeek, and Moonshot) — receive your message content in order to generate the response. They are not sent your hYYa account identity, and do not use your messages to train their models.
  • TypeSafe AI — helps hYYa understand what you’re asking for. It sees only short pieces of your text, isn’t told who you are, and doesn’t train on it. Not used when you chat with your own API key.
  • Google — for DataLens, generates embeddings for the documents you upload and reads (OCR) any images you add, so they can be searched. Used for that processing only.
  • Composio — only if you turn on Connections: securely stores the authorization for the apps you connect (e.g. Gmail, Google Calendar, Outlook, Notion) and relays read-only data into your chat at your request. SOC 2 Type 2; tokens are encrypted and isolated per user. Inactive unless you connect an app.
  • Google (Gemini Live) — only if you use voice: real-time voice runs through Google’s Gemini Live service. Audio streams directly between your device — your browser, or the hYYa ai app — and Google and does not pass through hYYa’s servers; the voice assistant also uses Google Search to answer real-time questions. Active only during a voice session.
  • Polar — processes purchases made on the web, as Merchant of Record. No card data touches hYYa servers.
  • Apple (App Store) and Google (Google Play) — process purchases made in the hYYa ai app, under their own terms and privacy policies, and send hYYa the record of each purchase described in section 3. No card data touches hYYa servers.
  • GitHub — hosts the list of on-device AI models hYYa Vault can install (GitHub Pages). Contacted when you ask hYYa Vault to check for new models. It receives the request for that list, and nothing about you.
  • Hugging Face — hosts the on-device AI models themselves. Contacted when you install one, and on Android also when you check for new models, to see whether one you have installed has a newer version. It receives those requests, and nothing about you.
  • Resend — delivers account and billing emails (sign-in codes, subscription notices).

5. Data hYYa Never Sells

Your data is never sold, rented, or shared with third parties for marketing or advertising purposes. Ever.

6. Security

All data in transit uses TLS 1.3. Authentication is passwordless — sign-in uses a one-time code emailed to you, and no passwords are stored. Supabase enforces row-level security so each user can only access their own data.

7. Your Rights

You can delete your account and all associated data at any time from the Settings screen, or via our contact form at hyya.com/#contact. Deletion from the Settings screen is immediate — your conversations, files, and account data are erased right away, and a subscription bought on the web is cancelled. A subscription bought through the App Store or Google Play is not cancelled by deleting your account: cancel it in your Apple Account or in Google Play, or the store keeps billing you. Emailed requests are actioned promptly.

8. Subscription End & Data Retention

If your paid subscription ends — whether you cancel or it lapses — you can still sign in; your account simply no longer has a plan. Your conversations and DataLenses are retained for 60 days so you can resume exactly where you left off if you reactivate, and hYYa sends reminder emails during that window, including a final notice before deletion. After 60 days without reactivation, your conversations and DataLenses are permanently deleted. You can reactivate anytime from the pricing page, or delete your data sooner from the Settings screen.

9. Age Requirement

hYYa ai is intended for users 18 years of age or older. hYYa does not knowingly collect data from anyone under 18. If hYYa learns it has collected data from a user under 18, that data is deleted promptly.

10. Changes to This Policy

This policy may be updated as the service evolves. Material changes will be notified via email or in-app notice. Continued use after changes constitutes acceptance.

11. Contact

Privacy questions or data requests: hyya.com/#contact.
Terms of ServiceRefund PolicyHome