Skip to content

Privacy Policy

Version: 2026-08-12
Last updated: 2026-08-12
Contact: security@yaper.io

Note: This is an agent-drafted operational policy. It reflects how Yaper Workspace currently handles your data. It has not been reviewed by legal counsel. For questions or requests, email security@yaper.io.


1. Who We Are

Yaper Workspace ("Yaper", "we", "us") is a teacher productivity platform at yaper.io. It gives language teachers a connected workspace — classes, lesson plans, reports, resources, and each student's context in one place.


2. Data We Collect

Account Information

  • Email address, name, and password (hashed; never stored in plaintext).
  • Organization membership and role when you are part of a team.

Teaching Content

  • Student records: names, notes, progress summaries, and session data you enter.
  • Lesson plans, class reports, and curriculum materials you create.
  • Chat messages with Yaper Assistant and AI-generated proposals you review and accept.

Canva Connect Integration

  • When you connect your Canva account via OAuth, we store an access token and refresh token.
  • Tokens are encrypted at rest using Fernet symmetric encryption (AES-128 in CBC mode with HMAC-SHA256 authentication) before being written to the database.
  • We use tokens only to create designs and folders in Canva on your behalf.
  • When you disconnect Canva, we revoke the token at Canva's API and delete the token record from our database. No token data is retained after disconnection.

Automatically Collected Data

  • Server access logs (IP address, user-agent, request path, timestamp) for security and debugging.
  • We do not use tracking pixels, ad networks, or behavioral analytics.

3. How We Use Your Data

  • To operate and deliver the Yaper Workspace service.
  • To generate AI-assisted lesson plans, reports, and design briefs — always requiring your review and explicit acceptance before anything is saved.
  • To send transactional emails (verification, password reset, invitations) via Resend.
  • To improve and debug the service.

We do not sell your data. We do not share it with third parties except as described in Section 4.


4. Third-Party Sub-Processors

| Sub-processor | Purpose | Region | |---|---|---| | Netlify | Web frontend hosting | US/EU | | Railway | API backend hosting | US | | Supabase | PostgreSQL database hosting | US | | Resend | Transactional email | US | | Canva (on connect) | Design creation via OAuth | Global | | LLM providers (OpenAI, Anthropic, or configured provider) | AI text generation | Varies |

When lesson plans or class notes are used as context for AI generation, we minimize the student personally identifiable information (PII) sent to LLM providers. Raw student data is not used to train third-party models.


5. Student and Minor Data

Yaper Workspace is used by teachers who may work with students who are minors. Teachers are responsible for obtaining any necessary consent from students or their guardians before entering student data into the platform. We process student data only as directed by the teacher account holder.

We minimize the PII included in prompts sent to LLM providers. We do not directly market to or profile students.


6. Data Retention

  • Account data is retained while your account is active.
  • Student records are retained until you delete them or close your account.
  • AI proposals that were rejected or never accepted are retained for audit purposes for up to 90 days, then purged.
  • Server logs are retained for up to 30 days.

You may request deletion of your account and all associated data at any time by emailing security@yaper.io. We will process the request within 30 days.


7. Security

We use industry-standard safeguards: TLS in transit, encrypted tokens at rest, parameterized database queries, and tenant-isolated data access. Access to production data is restricted to authorized personnel.

No system is perfectly secure. If you discover a vulnerability, please report it responsibly to security@yaper.io.


8. Cookies

We use a single session cookie (HTTP-only, Secure) to maintain your login session. We do not use analytics or advertising cookies.


9. Your Rights

Depending on your jurisdiction, you may have the right to access, correct, export, or delete your personal data. Submit requests to security@yaper.io.


10. Changes to This Policy

We will update this page when the policy changes and revise the "Last updated" date. Continued use after a change constitutes acceptance of the new policy.


11. Contact

Questions about this policy or data requests:
security@yaper.io

Document version: 2026-08-12