Last updated: July 19, 2026
YIPEE Labs AI ("YIPEE," "we," "us," or "our") operates the YIPEE website and authenticated product. This Privacy Policy describes the information we process when you visit the site, create an account, verify an identity, build a YIPEE Identity, create a production, participate in a Shared Production, or contact us.
1. Scope and who we are
This Policy applies to information YIPEE Labs AI processes for the YIPEE service. It does not replace the privacy notices of independent services such as Stripe, Supabase, fal.ai, or an app store, social platform, or other destination you choose to use outside YIPEE.
YIPEE is designed for adult identity-content creation. A verified person, a YIPEE Identity, and an approved production are separate states. Completing person verification does not give anyone automatic access to your reference material or authorize a production with your likeness.
For privacy questions or requests, contact privacy@yipee.ai. We will publish the applicable legal-entity, mailing-address, and jurisdiction-specific notices before paid commercial availability where they are required.
2. Information we process
Information you give us
- Account and workspace information, such as your email address, display name, sign-in credentials handled through the configured authentication service, workspace settings, and support communications.
- Identity and Vault material, such as the owner-bound reference images you submit, their review and routing metadata, checksums, and your production-use consent record. A YIPEE Identity may become Ready only after the required verified-adult, approved-reference, and consent gates are satisfied.
- Production material, such as prompts, scripts, approved still anchors, motion references, voice or dialogue references, project settings, shots, comments, approvals, generated outputs, and export requests.
- Discovery and collaboration settings, such as a profile's Private, Unlisted, or Public setting, exact handle where enabled, invite preferences, blocks, reports, roster decisions, and Shared Production activity.
- Billing and transaction records, such as Stripe customer, checkout, subscription, invoice, and configured product identifiers; plan/credit entitlement records; and the append-only credit ledger. We do not receive or store full payment-card numbers.
Information from verification and service providers
Stripe Identity performs hosted government-document capture, matching-selfie, and liveness checks. YIPEE receives the verification outcome and limited operational status needed to apply its rules, including a fixed 18+ fact where established. YIPEE does not copy government-ID images, ID numbers, or the verified date of birth into the YIPEE Vault.
Technical and security information
We process the technical information needed to deliver and secure the service, including server request and security events, authentication and authorization events, device/browser information supplied with a request, IP-derived network data, error reports, and audit records. We do not describe advertising or cross-site behavioral tracking as part of the current product. If non-essential analytics or cookies are added, this Policy and any required consent flow will be updated before use.
3. Why we use it
We use information to provide the service you ask for: create and secure an account, verify eligibility, maintain a YIPEE Identity, route an authorized reference packet, generate and review a production, operate credits and billing, enable approved collaboration, and respond to support requests.
We also use information to protect people and the service: enforce identity, consent, roster, block, licensing, credit, export, and abuse controls; investigate suspected misuse; maintain append-only decision records; prevent fraud; and comply with legal obligations.
Where a law requires a legal basis, our processing may be necessary to provide the requested service, to comply with law, for legitimate interests in security and service integrity, or with your consent. You may withdraw a consent where the product offers that control; withdrawal does not affect processing already completed or processing that has another lawful basis.
4. Who receives it
We do not sell or rent Identity Vault material, and YIPEE does not use your Identity Vault or production material to train a foundational model. We disclose information only as needed to operate the service, comply with law, or protect people and the platform.
Supabase
Authentication, Postgres records, row-level access controls, and private object storage.
Stripe
Hosted identity-verification outcomes, billing checkout, subscriptions, and payment events.
fal.ai / Seedance
Server-initiated video inference using only the approved provider packet for a requested production.
Vercel
Hosting, server-side route handling, and deployment infrastructure.
When a provider packet is submitted, YIPEE uses short-lived authorized media access and a one-way pseudonymous provider identifier rather than your YIPEE user ID, email address, handle, or a reusable identity profile. A provider may still process the reference files and prompt necessary to perform the requested inference under its own service terms and data-processing commitments.
Within YIPEE, other participants receive only the project, scope, and decision information necessary for the Shared Production. They cannot browse or download another participant's Identity Vault, raw voice material, or likeness authority. A Studio or licensee does not receive raw Vault material simply because it proposes or accepts a license request.
We may also disclose data to professional advisers, an acquirer or successor in connection with a corporate transaction, or government and law-enforcement authorities when required by law or reasonably necessary to protect rights, safety, and service integrity.
5. Identity, Vault, and production controls
Your Vault is private by default
Identity references live in private storage and are selected by the server for an approved production. The user-added anchor rules are intentionally different: anchors are context, costume, place, object, composition, motion, or style references by default—not sources for another person's identity. A reference containing a non-participant person must be reviewed, sanitized to exclude that person's identity, or rejected before generation.
Visibility is not permission
A Private identity is not discoverable. An Unlisted identity can resolve only through its exact handle. A Public identity may be searchable only inside the authenticated Discovery Center. None of those visibility settings permits a person to use your likeness. A block suppresses discovery, invites, license requests, new collaboration, and future unexercised use in either direction.
Shared Productions
Each participant separately accepts the current roster and scope. Material roster or brief changes reopen consent. A director may edit the governed draft only after unanimous appointment; a director cannot consent, approve identity use, or approve a final output for another participant. Only the authoritative current output version can be approved for export.
Enterprise Preview
YIPEE's Likeness Licensing ledger may record a proposed or accepted scope, but it is not production permission. Live business verification, payouts, licensed generation, external API access, and licensed export remain disabled until they are connected and tested end to end.
6. Your choices and rights
Depending on where you live, you may have rights to request access to, correction of, deletion of, or a copy of personal information; to object to or restrict certain processing; to withdraw consent; or to appeal a decision. You can also use available product controls to manage profile visibility, invitations, blocks, production-use consent, and eligible references.
To make a privacy request, email privacy@yipee.ai from the account email where possible and describe the request. We may need to verify your identity and authority before acting. We may retain or decline to change information where permitted or required by law, including to protect another participant's rights, preserve financial/audit records, prevent fraud, or resolve disputes. If you believe a request was not handled appropriately, you may also have a right to contact the privacy regulator in your place of residence.
7. Retention, deletion, and redaction
We retain personal information for as long as reasonably necessary to operate the service, maintain the records that make consent and credits auditable, meet legal obligations, resolve disputes, and enforce agreements. We do not publish a universal fixed retention schedule while the service's storage workers, provider configuration, and jurisdiction-specific retention program are still being finalized.
You may request deletion or revoke production-use consent through available controls or by contacting us. When an identity-redaction request is accepted, YIPEE first disables production use locally and then requests redaction for every non-redacted Stripe Identity verification session associated with that YIPEE Identity. Redaction is asynchronous and irreversible. Deletion or redaction may not immediately remove information that must remain in an immutable consent, security, financial, or legal record, and it may not undo outputs or permissions already lawfully exported or used before the request.
We will publish the applicable object, derivative, output, backup, and index deletion schedule before production launch. Until then, do not interpret a product control as a promise of instantaneous or universal erasure across every processor.
8. Security and international processing
YIPEE uses measures designed to reduce unauthorized access, including private storage boundaries, least-privilege access, server-owned authorization checks, short-lived signed media URLs, event verification, and append-only audit records. No system can guarantee absolute security. Keep your account credentials private, use a secure device, and tell us promptly if you believe your account has been compromised.
Our providers may process information in countries other than yours. Where required, we will use appropriate transfer safeguards and will provide additional information about those safeguards on request. Provider location and processing practices are also governed by the applicable provider's notice and agreement.
9. Adults only
YIPEE's self-service identity and production features are for people aged 18 or older. The proposed Family foundation is hard-disabled; it does not enable dependent discovery, licensing, persistent voice, or production generation. If you believe a minor has provided personal information to YIPEE, contact privacy@yipee.ai so we can investigate and take appropriate action.
10. Changes and contact
We may change this Policy as the product, its processors, or applicable law changes. For material changes, we will update the date above and provide additional notice where required. The current version controls from the date it is posted unless we state otherwise.
Questions, requests, and complaints about this Policy can be sent to privacy@yipee.ai.