Legal & safety
Privacy Policy
Last updated August 31, 2026
1. Introduction and Data Controller
YallAmigo is a mobile application operated by a self-employed individual (trabajador autónomo) based in Spain (“we,” “our,” or “us”). This Privacy Policy is provided in compliance with Regulation (EU) 2016/679 (General Data Protection Regulation, “GDPR”), Spain’s Ley Orgánica 3/2018 de Protección de Datos Personales y garantía de los derechos digitales (“LOPDGDD”), and Ley 34/2002 de Servicios de la Sociedad de la Información y de Comercio Electrónico (“LSSI-CE”).
The Data Controller (Responsable del Tratamiento) for the personal data processed through the App is:
YallAmigo
Operated by a self-employed individual (autónomo) registered in Spain
Contact email: admin@yallamigo.com
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the YallAmigo mobile application (the “App”). By downloading, installing, or using the App, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the App.
2. Information We Collect
2.1 Information You Provide Directly
- Account Information: When you register, we collect your email address, username, display name, and password (stored securely using industry-standard hashing).
- Profile Information: Your preferred language for message translation, app display language, and optional avatar image.
- Messages and Content: Text messages, voice messages (audio recordings), images, and files you send through the App.
- Guest Information: If you join a conversation as a guest (without creating an account), we collect the display name and preferred language you provide.
2.2 Information Collected Automatically
- Device Information: Device type, operating system version, and unique device identifiers for push notifications.
- Usage Data: Features used, conversation participation, message timestamps, and audio usage statistics (duration of voice messages sent per day).
- IP Address: Collected during authentication, guest session creation, and content policy acceptance for security and abuse prevention purposes.
- User Agent: Browser or app client information collected during session creation.
- Online/Offline Status: Your last seen timestamp is recorded when you connect to or disconnect from the App.
- Advertising Measurement (Android app): The Android app includes the TikTok App Events SDK so we can measure whether our advertising brings new users. It may collect your device’s advertising identifier, app install and launch events, and in-app actions such as registration, login and subscription purchases (including price and currency). If you are logged in, a hashed (irreversible) form of your user ID, username and email may be sent to improve measurement accuracy. You can reset or delete your advertising ID at any time in Android Settings › Privacy › Ads.
2.3 Information from Third-Party Services
- Push Notification Tokens: We receive device tokens from Apple Push Notification Service (APNs) and Google Firebase Cloud Messaging (FCM) to deliver push notifications.
- In-App Purchase Data: If you subscribe to a paid plan, we receive purchase verification data from Apple App Store or Google Play Store. We do not receive or store your payment card details.
2.4 Contacts (Address Book) — Processed On Your Device Only
If you use the “Invite friends” feature in the Android app, the App asks for your permission to read your device’s contact list. Your contacts are used only on your device to let you choose who to invite and to pre-fill your own messaging app (for example SMS or WhatsApp) with the invitation. Contact names and phone numbers are never transmitted to, collected by, or stored on our servers, and are never shared with third parties. Declining the permission does not block you: you can still share invite links through your device’s share menu. You can revoke the permission at any time in your device settings. If you choose to translate your invitation message before sending it, only the message text you typed is sent to our servers for translation — never your contacts.
3. How We Use Your Information
We use the information we collect for the following purposes:
- Provide Core Services: To facilitate real-time messaging, translate messages between languages using AI, transcribe voice messages, and manage conversations.
- AI Translation: Your message content is sent to third-party AI providers to be translated. The primary provider is DeepSeek; when it is unavailable we route the request through OpenRouter to an alternative model (currently models operated by DeepSeek, Qwen, Google or OpenAI). The providers and models we use can change — section 10 lists the ones in use today. We do not use your messages to train any model; each provider processes what it receives under its own terms.
- Audio Transcription: Voice messages are sent to OpenAI’s speech-to-text service to produce a transcript, which is then translated in the same way as a text message.
- Account Management: To create and manage your account, authenticate your identity, reset passwords, and process subscription purchases.
- Notifications: To send push notifications about new messages, friend requests, guest join requests, and other relevant activity.
- Content Moderation: To detect and prevent policy violations, harmful content, and abuse. Moderation logs may include IP address and content hash information.
- Security: To prevent fraud, abuse, and unauthorized access, including rate limiting and IP-based security measures.
- Service Improvement: To understand usage patterns, diagnose technical issues, and improve the App’s functionality.
4. How We Share Your Information
We do not sell your personal information. We share your information only in the following circumstances:
- With Other Users: Your display name, username, avatar, online status, and messages are visible to other participants in your conversations. Your email address is visible on your profile to facilitate friend requests.
- AI Providers: Message text is transmitted to our translation providers (DeepSeek directly, or OpenRouter when we fall back to another model). Voice recordings, transcripts and message content are transmitted to OpenAI for speech-to-text and content moderation. These providers process data according to their own privacy policies and data processing agreements. We may change providers; section 10 is kept current.
- Cloud Storage: Files, images, and audio recordings you share are stored on Linode Object Storage (Akamai) with industry-standard security.
- Email Services: Your email address is shared with Mailgun for transactional emails such as password reset requests.
- Push Notification Services: Device tokens are shared with Apple (APNs) and Google (FCM) to deliver push notifications.
- Advertising Measurement: On Android, the advertising identifier, app events (install, launch, registration, login, subscription purchases) and hashed user identifiers are shared with TikTok for Business to measure ad campaign performance, under TikTok’s Business Products (Data) Terms. We do not share your message content, contacts or media with TikTok.
- Legal Requirements: We may disclose your information if required by law, regulation, legal process, or governmental request.
- Safety: We may disclose information to protect the safety of our users, the public, or our services.
5. Data Storage and Security
- Storage Location: Your data is stored on managed cloud infrastructure operated by Linode/Akamai. The PostgreSQL database is reached only over encrypted (TLS) connections.
- Encryption in Transit and at Rest: Traffic between your device and our servers is encrypted with TLS, as is the connection between our servers and the database. YallAmigo does not provide end-to-end encryption, and we do not apply our own encryption layer to stored content: messages, transcripts and translations are held in readable form in the database so they can be translated, delivered and searched, and uploaded files are held in object storage. Any storage-level encryption is whatever our infrastructure providers apply.
- Password Security: Passwords are hashed using industry-standard cryptographic algorithms (bcrypt) and are never stored in plain text.
- Authentication Tokens: We use JSON Web Tokens (JWT) for session management with short-lived access tokens (15 minutes) and longer-lived refresh tokens (7 days).
- Sensitive Data on Device: Authentication tokens are stored in your device’s secure storage (iOS Keychain / Android Keystore) and not in plain text.
- File Storage: Uploaded files and media are stored under randomly generated, unguessable object names and are served only through time-limited presigned URLs.
While we implement commercially reasonable security measures, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security of your data.
6. Guest Users
YallAmigo allows unregistered users (“guests”) to join conversations via invite links without creating an account. If you use the App as a guest:
- We collect only the display name and preferred language you provide, along with your IP address and user agent for security purposes.
- Guest sessions have limited durations: pending sessions expire after 7 days, and approved sessions expire after 24 hours.
- The conversation host can end or revoke your guest session at any time.
- Messages sent as a guest are stored in the conversation and are visible to all conversation participants.
- Guest sessions do not require an email address or password.
7. Children’s Privacy
The App is not intended for anyone under the age of 18. We require all users to be at least 18 years old, which exceeds the minimum age of digital consent in Spain (14 years under Article 7 of the LOPDGDD) and in all other jurisdictions where the App is offered.
We do not knowingly collect personal information from anyone under 18. If we become aware that we have collected personal information from a child below the required age, we will take steps to delete such information promptly. If you believe a child has provided us with personal information, please contact us at admin@yallamigo.com.
8. Your Rights and Choices
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access: You can view your profile information, messages, and conversation history within the App at any time.
- Correction: You can update your display name, username, and language preferences through the App’s Profile settings.
- Deletion: You can delete your account and all associated data through the App’s settings (Profile > Delete My Data). This action is permanent and removes your account, messages, files, and all personal data from our servers in compliance with GDPR and applicable data protection regulations.
- Data Portability: You may request a copy of your personal data by contacting us.
- Notification Preferences: You can enable or disable push notifications through your device settings or within the App.
- Language Preferences: You can change your preferred translation language and app display language at any time.
Legal Basis for Processing (RGPD Art. 6)
Under the GDPR (RGPD) and LOPDGDD, we process your data on the following legal bases:
| Processing Activity | Legal Basis (Art. 6 RGPD) |
|---|---|
| Account registration and management | Contract performance (Art. 6.1.b) |
| Messaging, translation, and transcription | Contract performance (Art. 6.1.b) |
| Subscription and payment verification | Contract performance (Art. 6.1.b) |
| Push notifications | Consent (Art. 6.1.a) |
| Security, fraud prevention, rate limiting | Legitimate interest (Art. 6.1.f) |
| Content moderation | Legitimate interest (Art. 6.1.f) and legal obligation (Art. 6.1.c) |
| Service improvement and diagnostics | Legitimate interest (Art. 6.1.f) |
| Guest session (unregistered users) | Consent (Art. 6.1.a) - provided at time of joining |
Your Rights under RGPD / LOPDGDD
Under the GDPR and LOPDGDD, you have the following rights, which you may exercise by contacting admin@yallamigo.com:
- Right of access (Art. 15 RGPD) - obtain confirmation of whether your data is being processed and access to it.
- Right to rectification (Art. 16 RGPD) - correct inaccurate or incomplete personal data.
- Right to erasure (Art. 17 RGPD) - request deletion of your personal data (“right to be forgotten”). Available in-app via Profile > Delete My Data.
- Right to restriction of processing (Art. 18 RGPD) - request limitation of processing in certain circumstances.
- Right to data portability (Art. 20 RGPD) - receive your data in a structured, machine-readable format.
- Right to object (Art. 21 RGPD) - object to processing based on legitimate interests.
- Right to withdraw consent (Art. 7.3 RGPD) - withdraw consent at any time where processing is based on consent.
- Right to lodge a complaint - with the Agencia Española de Protección de Datos (AEPD) at www.aepd.es, or with your local supervisory authority.
We will respond to your request within one month, as required by the RGPD. This period may be extended by two further months for complex requests.
For California Residents (CCPA)
Under the California Consumer Privacy Act, you have the right to know what personal information we collect, request deletion of your data, and opt out of the sale of personal information. We do not sell personal information.
9. Data Retention
- Account Data: Retained for as long as your account is active. When you delete your account, all personal data is permanently removed.
- Messages: Retained for the duration of the conversation’s existence. Conversation owners can permanently delete conversations, which removes all associated messages and files.
- Guest Sessions: Guest session data is retained for the duration of the session (maximum 24 hours after approval, 7 days if pending). Expired sessions are automatically cleaned up.
- Audio Files: Voice messages are retained as part of the conversation. Daily audio usage statistics are tracked for subscription limit enforcement.
- Security Logs: IP addresses, moderation logs, and security-related data may be retained for up to 90 days for abuse prevention.
- Translation Cache: Translated message content may be cached temporarily to improve performance and reduce redundant API calls.
10. Third-Party Services
The App integrates with the following third-party services, each governed by their own privacy policies:
| Service | Purpose | Data Shared |
|---|---|---|
| DeepSeek | AI text translation (primary provider) | Message text content |
| OpenRouter | AI text translation — routes to a fallback model (currently DeepSeek, Qwen, Google or OpenAI models) when the primary provider is unavailable | Message text content |
| OpenAI | Audio transcription (speech-to-text), content moderation | Audio recordings, message content |
| Google Firebase (FCM) | Push notifications (Android) | Device tokens, notification content |
| Apple Push Notification Service | Push notifications (iOS) | Device tokens, notification content |
| Linode / Akamai | File and media storage | Uploaded files, images, audio |
| Mailgun | Transactional emails | Email address |
| Apple App Store / Google Play | In-app purchase verification | Purchase receipts (no payment card data) |
| TikTok for Business (App Events SDK, Android only) | Advertising attribution and campaign measurement | Advertising ID, app install/launch and in-app events (registration, login, subscription purchase value), hashed user ID/username/email |
11. Content Moderation
To maintain a safe environment, the App may use automated content moderation to detect harmful or policy-violating content. This includes:
- Automated scanning of message content using AI-based moderation tools.
- Content hashing to detect repeated policy violations.
- Logging of moderation events, including IP address and user agent, for audit and appeals purposes.
- Account restrictions (temporary or permanent freezing) for severe or repeated violations.
You will be notified if your content is flagged or if action is taken on your account. You may contact us to appeal any moderation decision.
12. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that differ from those in your jurisdiction. When we transfer data internationally, we implement appropriate safeguards to protect your information, including standard contractual clauses where applicable. In particular, the AI providers named in section 10 are established outside the European Economic Area — DeepSeek in China, OpenRouter and OpenAI in the United States — so message content sent for translation, transcription or moderation is processed there.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy within the App or on our website with an updated “Last updated” date. We encourage you to review this Privacy Policy periodically for any changes. Your continued use of the App after any modification to this Privacy Policy constitutes your acceptance of the modified policy.
14. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
YallAmigo
Operated by a self-employed individual (autónomo) based in Spain
Email: admin@yallamigo.com
Website: https://yallamigo.com
For EEA residents, you may also lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos - AEPD) at www.aepd.es if you believe your data protection rights have been violated.
Questions? Write to admin@yallamigo.com.