Privacy Policy for YATFA
Last Updated: July 17, 2026
This Privacy Policy (the "Policy") explains how YATFA ("YATFA," "we," "us," or "our"), operated by Yatfa Inc., collects, uses, stores, and protects information about users ("you" or "your") when using our website yatfa.com, CLI tools, API, and associated agentic automation services.
We understand the value of your intellectual property and the confidentiality of your code. Our architecture is designed around the principle of data minimization.
1. Information We Collect
1.1. Account Information (Personal Data)
On Sign-Up: We collect your name, email address, and authentication data (including your GitHub account details when authenticating via OAuth).
Billing Information: Payment processing is handled by third-party certified payment processors. YATFA does not store your credit card or billing details on its servers.
1.2. GitHub Integration Data
To perform automated planning, code implementation, and reviews, our official GitHub App requests access to your selected repositories. This access includes:
- Source code (only within the scope of isolated task execution sessions);
- Pull requests and associated comments;
- Continuous Integration (CI/CD) status.
1.3. Usage Metrics and Technical Logs
Agent Usage: We track the compute each agent consumes — metered in Compute Credits (YATFA's unit of account, derived from the LLM tokens used) — for metering, limits, and billing purposes.
Technical Logs: Information about agent execution, error tracking (including Sentry integrations), execution times, and backlog queues.
2. How We Process Your Source Code (Our Guarantees)
Protecting your proprietary code is a core priority of the YATFA architecture. We adhere to the following rules:
No Permanent Storage: YATFA does not store your source code on its permanent database servers. Code is temporarily cloned into isolated Docker sandboxes solely for the duration of a specific task (Worker, Reviewer, or Researcher session) and is completely deleted immediately after the session ends.
No Model Training: We never use your source code, commit history, or pull request comments to train our own or third-party machine learning models.
Local Embeddings: Vector embeddings used for semantic search within your codebase and agent memory are generated and processed locally within our infrastructure. They are not transmitted to external third-party embedding generation services.
3. Third-Party Services and Data Transfer
To deliver our services, we may share limited information with the following categories of third-party processors:
LLM Providers (Large Language Model APIs): Agent tasks and code context are transmitted via API to third-party large language model providers, which may process this data outside your country of residence, including outside the European Economic Area. We route to providers whose commercial API terms restrict the use of customer data for model training. A current list of the providers we use is available on request.
Error Tracking Services (Sentry): Application error data may be sent to Sentry for debugging and platform maintenance.
Notifications (Telegram Bot API): If you enable the Telegram integration, technical status updates will be sent via the Telegram API to your designated account or chat.
4. Data Security
We implement strict technical and organizational security measures:
Sandboxed Execution: All agents run inside isolated Docker containers. They have no access to the host machine or other users' data.
Encryption: All data transmitted between the CLI, YATFA agents, and the platform is encrypted in transit using TLS and Secure WebSockets (WSS).
GitHub Authentication: We use the official GitHub App protocol with short-lived, automatically rotated tokens. We do not collect or store your personal GitHub passwords or permanent Personal Access Tokens (PATs).
5. User Rights (GDPR, CCPA, etc.)
Depending on your jurisdiction, you have the following rights regarding your personal data:
Right to Access and Export: You may request a copy of your personal data and project metadata stored on YATFA.
Right to Erasure ("Right to be Forgotten"): You have the right to request the complete deletion of your account, associated project metadata, agent memories, and knowledge bases.
Right to Withdraw Consent: You can revoke the GitHub App's access to your repositories at any time through your GitHub account settings, which will immediately stop YATFA from interacting with your code.
To exercise any of these rights, please send your request to: [email protected]. We will process your request within 30 days.
6. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our data processing practices or legal requirements. In the event of material changes, we will notify you via email or through your YATFA dashboard before the changes take effect.
7. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy, please contact us at:
Company Name: YATFA Inc.
Entity Type: Delaware C Corporation
Address: c/o Legalinc Corporate Services Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, USA
Email: [email protected]