Privacy Policy
Última actualización
Este documento solo está disponible en inglés. La versión en inglés es la que rige.
This policy describes what Yoke stores, why it is stored, who else can see it, and what you can do about it. It is written to be read, not to be survived.
1Who we are
Yoke is an invoicing application for freelancers and small service businesses. Where this policy says "we", it means the operator of Yoke. Where it says "you", it means the person who holds a Yoke account.
You can reach us about anything in this policy at support@byttech.org.
2What this policy covers
It covers the Yoke mobile app, the Yoke server that the app syncs with, the public invoice pages we generate when you share an invoice with a client, and this website.
It does not cover what your own clients do with an invoice after you have sent it to them, or any service you reach through a link we did not create.
3Data you give us to have an account
To sign in you give us an email address and a name. If you sign in with an email and password, we store a cryptographic hash of that password and never the password itself.
If you sign in with Google or Apple instead, we store no password at all — the field is empty for your account. What we store is the provider's name and the stable identifier that provider uses for you. We do not receive or keep your Google or Apple password, and we do not keep the sign-in tokens they issue beyond the moment we verify them.
Sign in with Apple lets you hide your real address behind a relay address that forwards to you. If you use it, the relay address is the only address we ever have, and that is fine — everything works the same way.
4Data you enter about your own business
Yoke is built around the idea that one person may run several businesses, so each brand you create holds its own name, address, logo, tax details, and default currency. You choose all of it and you can change or delete any of it.
5Data you enter about your clients
This is the part of the policy that deserves the most attention, because it is the only data in Yoke that is about someone who never agreed to anything with us.
When you add a client, write an invoice, or log time against a project, you are entering information about other people and organisations: names, addresses, email addresses, what you did for them and what they owe. That information is yours to control. You decide what to enter, you decide how long it stays, and you can delete it.
In data-protection terms: for that information you are the controller and we are a processor acting on your instructions. We store it, we render it into invoices and PDFs, and we send it where you tell us to send it. We do not use it for anything of our own.
If one of your clients asks you to remove their details, you can do that in the app without contacting us, and the change reaches our servers the next time your device syncs.
6Data created as you use Yoke
Working in the app produces records: documents and their line items, payments you record, projects and their milestones, time entries, recurring schedules, and reminder settings. It also produces a log of the changes your devices have made, which is what lets the same account work on more than one device and offline.
When you email an invoice from Yoke, we keep a record of that message so it is not sent twice and so we can tell you whether it was delivered.
When you share an invoice link, we record when that link was first opened. That is what turns an invoice's status to "viewed". It is a timestamp, not a profile: we do not record who opened it, from where, or how many times.
7Technical data
Our servers process the IP address of requests in order to apply rate limits — the mechanism that stops someone guessing their way into an account. It is used for that and discarded; it is not attached to your account or used to work out where you are.
Signing in issues a session token to your device. It expires, and signing out revokes it.
8Everything we store, in one table
| What | Where it comes from | Why |
|---|---|---|
| Email address, name | You, at sign-up | Identifying your account, contacting you about it |
| Password hash | You, if you use a password | Signing you in. The password itself is never stored |
| Sign-in provider and its identifier for you | Google or Apple, if you use them | Recognising you on the next sign-in without a password |
| Brand details, logo, tax settings, currency | You | Appearing on the invoices you issue |
| Clients, invoices, estimates, payments, projects, time entries | You | Being the application. This is the work product Yoke exists to hold |
| Sync history for your devices | Your devices | Offline editing and multi-device use |
| Sent-email records | Emails you send from Yoke | Delivery status, and not sending the same invoice twice |
| First-opened timestamp on a shared invoice link | Your client opening the link | Showing you that the invoice was seen |
| Session tokens | Signing in | Keeping you signed in; revoked on sign-out |
| IP address of requests | Your network | Rate limiting. Not retained, not linked to your account |
9Who else touches your data
Two, and no others:
- Resend, which delivers the email Yoke sends on your behalf. An invoice email necessarily passes through it, including the recipient address and the invoice contents.
- a third-party hosting provider, which runs the servers the database and its backups sit on.
We do not sell data, we do not share it with advertisers or data brokers, and we do not hand it to anyone else except where the law requires it of us.
10Where your data is stored
The database and its backups sit on servers rented from a third-party hosting provider. Backups run once a day and are deleted automatically after 14 days, so a copy of deleted data never lingers longer than that.
A copy of your own data also lives on each device you use Yoke on — that is what makes it work without a connection. Removing the app from a device removes that copy.
11How long we keep it
For as long as your account exists. When you ask us to delete your account, we remove the account and the data belonging to it; the copies inside backups fall away as those backups rotate, within 14 days.
12What we do not do
Worth stating plainly, because most apps cannot:
- There is no advertising in Yoke and no advertising identifier.
- There is no third-party analytics or crash-reporting SDK in the app.
- This website loads no third-party resources at all — no external fonts, no scripts, no embedded content. Nothing on it can observe you but us.
- There are no tracking cookies. We do not build a profile of you and we have nothing to sell to anyone who would want one.
13Your choices and your rights
Most of your data is directly editable in the app — that is the fastest way to correct or remove something.
Beyond that, you can ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete your account entirely. Write to support@byttech.org from the address on the account and we will act on it. Depending on where you live, local law may give you these rights explicitly; we apply them to everyone regardless.
14Children
Yoke is a tool for running a business and is not directed at children. We do not knowingly hold data about them.
15Changes to this policy
If we change it, the date at the top of this page changes with it. If a change materially affects what happens to your data, we will tell you rather than leaving you to notice.
16Contact
Questions, requests, or complaints: support@byttech.org.