Privacy

Last updated 28 September 2026

What is collected

Your email address, given when you sign in. It is used to send the six-digit sign-in code and, if ever needed, to reach you about your account.

What you choose to publish: display name, username, bio, and whether your profile is public. Your time zone, which decides which day a play belongs to and therefore your streak.

If you use Vivra, Motiv or Glyphi: what you tell the AI in the conversation, the details you give for your site, video or design — the name of your business, the contact details you choose to show, your colours —, the photos and files you add (logos, pictures, PDFs), your brand kit, and the sites, scripts, videos and designs made from them. Your brand kit (logo, colours, fonts, tone, details) is readable by the other apps of the suite you use, so they can apply it. A site you publish is public at the address you chose, until you take it offline.

If you use Ondra: the description of your business you give it, the posts you write or have written, the images and videos you upload or have made, when they are scheduled, and the social accounts you connect — their name, picture and the network's identifier, never your password. Once a post is published: its public numbers (reach, interactions) and the comments left under it, as the network reports them.

How you play: for each day and each door, what you played, when, and what it earned. The greens and XP ledgers, the projects you funded, and the draw tickets those produced.

What you do in the feed: your posts, the games you publish with the move log that allows them to be replayed, the hearts you give, and the accounts you follow. Who you follow is visible only to you; a public page shows a follower count and nothing more.

The public profiles you visit: one row per person visited and per day, so that they can be told somebody looked. They learn your name, not how many times nor at what hour. That trace is readable by nobody, serves only that notice, and is erased after thirty days. A profile set to private receives nothing and is not concerned.

The accounts you block, and the reports you send: the account concerned, the reason chosen and the sentence you add if you add one. A block is visible only to you. A report is read by the team and by nobody else — the person concerned learns neither that they were reported nor by whom: a report that can be seen is a report nobody dares to send.

If you connect a step source on the web: your daily step count, read from your device maker's servers, and the encrypted tokens that let us read it. In the phone app, the count is read on the device itself, from Apple Health or Health Connect, and only a daily total leaves it. Either way, a daily step count describes the physical activity of an identified person, so it is treated as health data under Article 9 of the GDPR. The legal basis is your explicit consent — the authorisation you gave at the maker or on the phone, and which you withdraw there or here.

In the phone app: an identifier the app draws for itself the first time it runs, which distinguishes two phones and authorises nothing; and, with every request that sends steps, an attestation issued by Apple or by Google that proves the request comes from this app, unmodified, on a genuine device. No advertising identifier is ever read. If you turn notifications on, the token your phone gives us to reach it.

If you take the YLC Pass: the subscription itself and the activation codes it entitles you to. No postal address is asked for — the subscription is digital, and nothing is shipped. No card is ever seen by us: a card payment is made on Whop's own page — or on Stripe's, for a subscription taken before 27 September 2026. A USDC payment made from the former YLC wallet before 28 September 2026 remains public on the Base network, like everything recorded there. For a subscription taken earlier through the App Store or Google Play, the store sends us a signed receipt carrying an identifier for your subscription and never your Apple or Google account. Whop, or Stripe, keeps for a card subscription the details it needs to charge and invoice it.

If you arrive through an affiliate link: the affiliate's Whop username, kept for thirty days in a cookie in your browser, then with your account once you sign in — the first affiliate stays attached to it. It is passed to Whop with each of your payments, so that Whop can credit that affiliate. Nothing else about you is sent to the affiliate by us.

If you become an affiliate: you connect your Whop account on Whop's own page; we keep its identifier and username with your account, and read from Whop the figures of your affiliate account to show them to you.

If you sign in to another app of the suite with your YLC account: the record of that sign-in — which app, and when you allowed it — kept by the sign-in service so that the app can recognise you next time.

If you link your Zealy account to take part in the community quests: the Zealy identifier of your account, kept with ours so that Zealy can ask whether a quest is done.

No analytics, no advertising identifiers, no tracking across other sites. Location only for Today's harvest, in the Walk door, and only while that screen is open: when you pick up an object, your position is sent once to check you are within 30 m of it, then discarded — it is never stored, logged or shown to anyone. We keep only which object you picked up, which is the same for your whole neighbourhood. Steps are counts, never a route.

Why

To run the game: the server replays every game from the moves it recorded, and that is what decides what a day was worth. Without them there is no score and no greens.

To keep it fair: the times at which a move was made are kept so that unusual patterns can be looked at by a person. They are never used to suspend an account automatically.

To show what you asked to show: a public profile exists because you set it to public, and shows only what this policy lists.

To count a day that was not played on a screen: steps are read on a schedule, or from the phone's own health store, because that is the only honest way to count them — nothing typed in a browser is ever accepted as a step.

To be sure a request comes from the app: the attestation says that the application is genuine and unmodified. It says nothing about who you are, it is checked once and kept no longer than the check.

To buy the impact a project funds: a purchase order exists because plastic has to be collected by somebody.

Who else sees it

Supabase hosts the database and handles sign-in. Vercel hosts and serves the application. Resend sends the emails, and receives the ones written to our contact address. Each of them processes data on our instruction and for no other purpose.

Crisp carries support: the chat bubble inside your account, and the messages sent to our contact address. It sees what you write, the address it comes from, your username, and the figures already shown to you in the sidebar — your greens, your XP, your level. It is a French company and it stores this in the European Union. There is no chat on the public site: it loads only once you are signed in — as a bubble on a computer, and on a phone or in the apps only when you open the chat from “Contact us”.

Microsoft Clarity measures how ylcnetwork.com is used — clicks, scrolling and the pages viewed, never what you type, which it masks — so we can improve the site. It loads only if you click “Accept” on the cookie banner, and nothing at all if you decline; the “Cookies” link at the bottom of every page changes your choice. It runs only on the public site, never inside your account or the apps. Microsoft keeps this data for up to 13 months.

Sentry receives error reports, so that we learn about a bug before someone has to write to us about it: what broke, on which page, and the kind of browser or phone. It receives no name, no email address and no IP address — the application is set to send none of them — and it records no screen. It stores the reports in the European Union, in Germany. We use it on the basis of our legitimate interest in keeping the service working.

Cloudflare Turnstile (Cloudflare, Inc., United States) guards the sign-in page: when you ask for a code, it checks that a person and not a program is asking. It receives technical signals from your browser and your IP address — never your email address — and answers with a one-time token that we pass on with your request.

Until 28 September 2026, each account received a wallet provided by Sequence (Horizon Blockchain Games Inc., Canada), on the Base network, and the creatures collected in The reef were recorded to it as non-transferable collectibles. This has stopped: no wallet is created and nothing is recorded any more. The address of a wallet created before that date remains stored with your account, and what was recorded on the public blockchain is permanent and visible to anyone who knows the address.

The pass and credit top-ups are paid on the website with Whop (Whop Inc., United States), on its own page, by card, Apple Pay or Google Pay. Whop is the merchant of record: it receives your email address, your country, the offer you chose, an internal identifier of your YLC account so that the payment reaches the right account, and the affiliate's username if you came through a link; it charges, invoices and collects VAT, under its own privacy policy. Subscriptions taken before 27 September 2026 are still handled by Stripe, or by Apple or Google for those taken through their store; a period paid in USDC before 28 September 2026 runs to its end with no provider involved. Card details never reach us. Greenspark buys the impacts a funded project pays for. Tremendous delivers a draw prize to the winner's email address.

Steps are read on the phone, from Apple Health or Health Connect, never written to: a one-way authorisation you grant in the phone's settings and can revoke there at any time. Nothing leaves the device but a daily count.

Apple and Google answer the attestation: we ask them whether this application, on this device, is genuine. They answer about the app and the device, never about you.

If you connect a step source on the web, Google (Google Health) or Oura, whichever you connected, sends us your daily step count: you authorised it on their own page, and you can disconnect it from the app or from them.

If you turn notifications on, Apple (on an iPhone) or Google (on an Android phone) delivers them: they receive the text of the notification and your phone's token, nothing else from us.

In the Post door, the idea you type for your image is sent to OpenAI (United States), which checks it against its usage rules and draws the image. It receives the idea only — never your name, your email address or your greens.

The map of Today's harvest is drawn with tiles from OpenFreeMap, which your browser fetches: like any server that sends an image, OpenFreeMap sees your IP address and which area of the map is shown.

Zealy runs the community quests. When it asks whether a quest is done, it sends us the identifier of your linked account and we answer yes, or no with a sentence it shows you; it receives nothing else about you from us.

Straby, published by the same company, YLC NETWORK FZC, is part of the suite of apps. For people who sign in to it with their YLC account, and for them only, it receives: your YLC account identifier, your email address, your username, whether your pass is active — its tier and, where there is one, the date it is paid up to — and which apps of the suite it unlocks; and, when you use AI in Straby, the balance of your AI credits, which it reads and spends from. It never receives your payments, your card or your greens. It receives this when you sign in, and may ask for it again later, server to server, to keep your pass up to date without you having to sign in again. We send it because you asked to use your account there.

What you do in Straby — your pages, your cards, your contacts — is Straby's own data, described in its own privacy policy at straby.app/legal/privacy. An app outside the suite would receive nothing without first asking your consent on a YLC page.

Vivra, Motiv and Glyphi, published by the same company, use AI models: Anthropic (United States) to hold the conversation and write the site, the script, the animation or the design, and OpenAI (United States) to create images and, in Motiv, the voice-over. They receive what you write in the conversation and the details you give for your site or video — never your account's email address, your payments or your greens — and, under their commercial terms, neither uses it to train its models. If you ask Vivra to show your Google reviews, Google receives the name of your business to find them. We send this because you asked for the site or the video to be made. Their screens, and the sites and videos they make, load fonts from Google Fonts — and, in Motiv, animation scripts from jsDelivr — in the browser that displays them: those servers see its IP address.

Ondra publishes through bundle.social (United States), which holds the approved applications with Meta, LinkedIn, TikTok, Pinterest and Google: it receives the posts you approve and their images and videos, and keeps the connection to the accounts you link. Ondra writes with Anthropic, makes images with OpenAI and videos with Higgsfield (United States); they receive the description of your business and what you ask for — never your account's email address or your payments.

Nothing is sold, rented, or shared with advertisers. Public profile pages are, by definition, visible to anyone — that is what making a profile public means, and it can be turned off at any time from the profile screen.

How long

As long as the account exists, except for the trace of a profile visit, which is erased after thirty days. There is no other automatic purge scheduled, and saying otherwise would be an undertaking that nothing enforces.

Your rights

If the GDPR applies to you, you may ask for access to your data, correction, erasure, a copy in a portable form, or restriction of processing. Display name, username, bio, time zone and profile visibility can be corrected yourself from the profile screen.

You delete your account yourself, from Profile and settings. If you have won a draw it is anonymised rather than deleted — your address, name, bio, username and photo are erased, and the row proving your win stays: a draw already held has to remain verifiable.

You may also complain to your local data protection authority.

Contact

Write to support@ylcnetwork.com. It reaches a person, not a queue.

Governing language

This document exists in several languages. **The English version governs**: it is the language it was drafted in, and the language of the applicable law. The other versions are courtesy translations; in case of divergence, the English version applies.

This clause does not deprive anybody of the mandatory provisions of their national consumer law, nor of the right to bring proceedings before the courts of their place of residence.