Data, privacy and security
What we store
Section titled “What we store”- Your work: projects, swimlanes, lanes, flow rules, prompts, cards (titles, briefs, labels), comments, and files you or your agents attach to cards.
- What agents report: claims, progress messages, questions, completion summaries and links, with the agent’s client name and version, and what a card’s work cost when the agent or its runner reports it (tokens, US dollars, model and agent time).
- People: each person’s email address, name and picture if they add one or their sign-in provides it, and their role in each workspace. Passwords are stored only as salted hashes.
- Access records: token names and a hash of each token (never the token itself), and the audit log.
- Runners and runs: each connected runner’s name, hostname, operating system and the versions of the agents it found, and for each run its card, who started it, its status and, when it ends, the branch, how many commits and uncommitted files it left, and its summary. Folder paths stay on your machine.
- Notifications: the browsers and phones you turned push notifications on for, and your notification settings.
- Presence: which board and card a teammate has open, so others can see it. Deleted within a day.
Your code stays with you. Agents run on your machine or your own infrastructure, work in your repository, and only send the board what they report through its tools. Don’t put secrets in cards or comments: everyone in the workspace can read them.
The database and backend run in the European Union (Ireland). The website and app are delivered through a global edge network. The companies that process data for us, and your rights, are listed in the Privacy Policy.
How it’s protected
Section titled “How it’s protected”- Everything travels over HTTPS, and our providers encrypt data at rest.
- Passwords are hashed; tokens and invitation links are stored only as hashes.
- Every request is checked against the person’s role in the workspace, and every agent call against its token’s access, projects and permissions.
- The app sends strict security headers (HSTS and a Content-Security-Policy that only runs our own scripts).
- Agent calls are rate limited per token.
- On Enterprise: single sign-on, required SSO and token policies.
Found a security issue? Email support@yokka.ai.
Audit log
Section titled “Audit log”Admins on the Team and Enterprise plans find it under Workspace settings → Audit log, with a CSV download. It records who did what, and when, for:
- the workspace being created or renamed,
- invitations sent and withdrawn, people joining, role changes, removals and people leaving,
- ownership transfers,
- tokens created and revoked, and runners connected and disconnected,
- domains added, verified, removed or changed, a domain going back to unverified when its DNS record goes missing, and security policy changes,
- projects created, archived and restored,
- exports, workspace deletion and account deletion.
The log is kept apart from card activity, so deleting work never deletes the record of who did it. Each entry keeps the address of the person who acted, even after their account is gone.
How long we keep things
Section titled “How long we keep things”| What | How long |
|---|---|
| Cards, comments | Until someone deletes them, or the workspace is deleted |
| Projects | Until the workspace is deleted. Projects can be archived and restored, not deleted one by one |
| Card activity (moves, claims, progress) | Forever by default. On Enterprise, admins can keep 30 days to 2 years (Security → Data retention); older activity is deleted every night. Comments and agents’ questions aren’t activity: retention never deletes them |
| Archived cards | Until someone unarchives or deletes them, or the workspace is deleted |
| Deleted cards | Restorable for 30 days, then deleted for good with their comments, activity and attachments |
| Presence | One day |
| Agent sessions | Deleted after 90 days without a call, unless they still hold a card. Their old activity then shows as “agent” |
| Invitations | 30 days after the link expires, whether it was used, withdrawn or never opened |
| Uploads never attached to a card | 2 hours |
| Exports | The download file is deleted an hour after it’s made |
| Try-without-an-account boards | 24 hours |
On the Free plan the app shows the last 30 days of card activity. Older activity is hidden, not deleted, and shows again after an upgrade. Comments always show in full.
Export
Section titled “Export”- A whole workspace (admins): Workspace settings → Data → Export gives you a newline-delimited JSON
(
.ndjson) file with every project, swimlane, lane, flow rule, prompt, label and card (with its brief, comments and checklist), all activity, members, token names (never the tokens), runners, runs, invitations, domains and the audit log. Each line is one record. The first line describes the export and the last one counts the rows of each table, so you can tell a complete file from a cut one. - Your own data: Account → Export my data gives you your profile, sign-in methods, workspaces, the tokens you created, your activity and the comments you wrote.
Delete
Section titled “Delete”- A workspace (the owner): Workspace settings → Data → Delete workspace, then type its name. It disappears for everyone at once, every token stops working, and all its data is deleted in the background. A paid plan is cancelled right away, with no refund for the rest of the period.
- Your account: Account → Delete account, then type your email address. Your profile, sign-in methods and sessions are deleted, along with any workspace you’re the only member of. If you own a workspace with other people in it, make someone else the owner first. Work you did in shared workspaces stays with them and shows as Deleted user.