Privacy Policy
Last updated: July 21, 2026
This policy explains what Yubikiri collects and why. We keep it short and honest.
1. What we collect
- Account data — name, email, Discord profile info (if you sign in with Discord), and profile fields you choose to add.
- Commission data — briefs, terms acknowledgments, milestones, revisions, room comments and translations, collaborator records, reviews, and files you upload.
- Payment metadata — connected Stripe account status, checkout identifiers, milestone amounts, currencies, and payment status. Yubikiri does not store full card details or hold funds.
- Notifications — in-app notifications; optional email digests; optional Discord DMs; optional browser push subscription endpoints if you enable them.
- Usage data — basic analytics (for example page views via Vercel Analytics), cookies/local storage needed to run the Service, and technical logs needed to secure it. See Cookies.
- Waitlist emails — if you join the founding-artist waitlist.
- Moderation reports — the reporting account, reported artist, selected reason, details, timestamps, and staff review status.
2. How we use it
Each use maps to the category above, in the same order:
- Account data — to authenticate you, show your profile, and send transactional email (invites, notices, and feedback replies). If you explicitly opt in, we may also send high-signal commission notifications by Discord DM to your linked Discord account.
- Commission data — to run commission rooms, stage approvals, delivery, public track records, and (when you choose) making-of pages, share pages, per-file records, or Keepsake records.
- Payment metadata— to show milestone payment status, connect optional Stripe Checkout, and confirm payouts go to the artist's Stripe account. We never store full card numbers or hold funds.
- Notifications — to alert you about room activity you care about, using only channels you enable.
- Usage data — to operate, secure, and improve the Service, and to prevent abuse.
- Waitlist emails — to contact you about founding invites and launch updates you signed up for.
- Moderation reports — to investigate reports, enforce the human-made artwork policy and other rules, and document staff decisions.
We do not sell your personal data. We do not use your artwork to train generative AI models.
3. Who we share with
We use processors to operate the Service. They process data only to provide those services, for example:
- Hosting and edge (Vercel)
- Database (Neon / Postgres)
- File storage (S3-compatible object storage)
- Email delivery (transactional email provider)
- Payments (Stripe Connect / Checkout)
- Sign-in and optional DMs (Discord)
- Optional EN/JA comment translation (DeepL)
- Analytics (Vercel Analytics)
Stripe processes checkout and payout data when optional staged payments are used. Discord receives the notification text needed to deliver an opted-in DM. When EN/JA room translation is enabled, comment text may be sent to DeepL to produce a convenience translation; the original remains authoritative. Developer webhooks you configure send only the event payloads you subscribe to, to URLs you provide. We may disclose information if required by law or to protect users from serious harm or fraud.
4. Public information
Artist public pages (handle, bio, stats, reviews you leave) are visible on the internet by design. Public delivery fingerprints and Keepsake tags can expose limited process metadata about a completed final, but not the client identity, brief, or price. Commission room contents are private to authorized participants unless you choose to share links or publish outcomes. Report details and reporter identities are not public; authorized staff use them for moderation.
5. Retention
We retain account and commission records while your account is active and as needed for legitimate operations, disputes, and legal obligations. You may request deletion by contacting us; some records may be retained where required (for example fraud prevention, abuse prevention, and moderation history).
6. Security
We use industry-standard hosting and access controls. No system is perfectly secure — please use strong account protections on Discord/email and avoid uploading highly sensitive personal data into briefs.
7. Your choices
- Update profile information in the dashboard
- Enable or disable Discord DMs, email digests, and browser push in notification settings (off by default where optional)
- Request access or deletion via the contact form (topic: Privacy), or email the inbox in §9 below
- Stop using the Service and sign out at any time
8. Children
The Service is not directed at children under 13 (or the higher age required in your region). Do not use Yubikiri if you are under that age.
9. Contact
Privacy questions: contact form, or copy the inbox:
hello@yubikiri.artRelated: Terms · Cookies · Copyright & IP