Yecho Privacy Policy

Version: 1.2 Effective date: August 29, 2026

Yecho is a personal tool for notes, to-dos, reminders, and review. We design the product around two principles: data stays on your device by default, and external capabilities are used only when you choose to enable them. This Policy explains how Yecho handles your information and which features send data to Apple, our feedback service, or a third-party service that you configure.

1. Operator and Contact Information

Yecho is operated by Chentao Fan. For privacy-related questions, email xxxkkk0101@foxmail.com.

2. Data Processed on Your Device

The following content that you enter or generate in Yecho is stored on your device by default:

Data that is processed only on your device and is not sent to our servers or a third-party service is not data that we collect from you.

3. Permissions and System Services

Yecho requests permissions only when the relevant feature needs them:

Apple provides these system capabilities. Apple's rules and settings apply to Apple's processing of data in its services.

4. iCloud Sync

Yecho uses on-device storage by default. Purchasing or restoring a membership does not automatically enable iCloud. Only when your membership entitlement is active, you expressly enable “iCloud Sync” in Yecho Settings, and iCloud is available does the app attempt, after you next fully quit and reopen it, to use your private Apple CloudKit database to sync SwiftData records between devices signed in to the same Apple ID. Turning the switch off or losing the membership entitlement returns the app to on-device storage after the next full quit and reopen. When Settings shows that the iCloud account is available or enabled, that reflects only the configuration status for that session; it does not prove that a particular record has been uploaded or reached another device.

5. Bring Your Own AI Provider (BYOK)

Yecho Pro can connect to an AI provider, Base URL, API Key, and model that you configure. The API Key is stored in the on-device Keychain. Configuration and model tests send only synthetic test content and do not contain your personal notes.

Online AI data access is off by default. Before Yecho sends personal content to a third-party AI provider, the AI Data & Privacy screen identifies the configured provider, Base URL, and model and asks you to authorize each data category separately: (1) the full text that you type or paste, and (2) the full text produced from a voice transcription. When you authorize a category and use online organization, Yecho sends that full text, together with the current local date, time, and time zone, directly to the configured provider endpoint. Yecho does not send the original audio recording, your images, Apple Calendar data, the on-device database, or diagnostic logs to the AI provider.

You can revoke either data-category authorization at any time. Changing the configured provider, Base URL, or model invalidates the existing authorization and requires a new authorization before personal content can be sent. If no usable AI service is configured or the relevant category is not authorized, Yecho applies on-device rules or skips cloud-based recognition.

The provider's own policies govern whether it retains data, uses data for model training, supports deletion, or processes data across borders. Because you may configure different third-party providers, Yecho and its developer cannot uniformly verify or control those practices. The developer cannot access or store your third-party API Key through Yecho and does not make data-processing commitments on behalf of the provider. Review the provider's privacy policy before enabling access.

6. Apple Watch Companion

The Apple Watch companion uses Apple WatchConnectivity to exchange quick-capture drafts, to-do summaries, and completion or postponement actions with the paired iPhone. The Watch may temporarily store lightweight drafts that have not yet been confirmed as delivered and a recent to-do snapshot. The iPhone is the writer of the primary data. This channel does not send an API Key to the Watch, and the Watch does not call online AI services. These device-to-device data are not provided to the Yecho operator.

7. On-Device Diagnostics, Interaction Analytics, and User-Initiated Exports

Yecho records runtime logs and a fixed set of interaction events on your device to help troubleshoot issues and improve the product. Interaction events contain only page, control, action, and result IDs. They do not record titles, body text, voice content, contact information, API Keys, exact dates, or item IDs, and they are retained for no more than 14 days by default. These on-device files are not uploaded automatically. You can view, clear, or choose to export them in Advanced Settings.

A product-analysis export includes original text, segmentation results, confidence, parsing source, and correction history. It is generated only after you tap Export and is not sent to us automatically. Treat an export as sensitive material and decide for yourself whether to share it with another person or an external service.

8. Feedback and Support

When you submit feedback in the app, it is sent to https://ctfanstudio.com/api/yecho/feedback. A submission may include:

The diagnostic summary filters field names that are obviously sensitive, but it may still reflect some runtime state. Do not include passwords, keys, identification documents, payment-card details, health records, or other highly sensitive information in feedback text or attachments.

The current Yecho client does not provide a verified server-side automatic-deletion API and does not state a fixed retention period. We use feedback to investigate issues, respond to users, and improve the service. To ask about, correct, or request deletion of feedback records on the server, contact us at xxxkkk0101@foxmail.com. What can be done depends on actual service capabilities, whether a record can be identified, and applicable legal requirements.

The app stores no more than 20 feedback summaries, submission identifiers, and public-reply statuses on your device. When you open the feedback page or manually refresh replies, the app sends those submission identifiers to the reply endpoint to look up the corresponding public replies. Clearing app data removes the local history but does not mean that server-side records have been deleted.

9. Purchases and Membership

Yecho uses Apple StoreKit to process subscriptions, one-time purchases, and purchase restoration. Apple handles payment, renewal, refunds, and subscription management. Yecho reads only the transaction entitlement status needed to determine whether Pro features are available.

10. No Tracking or Advertising

Yecho does not include third-party advertising SDKs and does not use your data to track you across apps or websites.

11. Children

Yecho is intended for general personal-productivity use and is not specifically directed to children. If a parent or guardian believes that a minor submitted personal information through feedback, they may contact us at the email address in this Policy.

12. Your Choices

You can:

13. Policy Updates

If Yecho's data-processing practices change materially, we will update this Policy and display the new version in an appropriate place. By continuing to use an affected feature, you acknowledge the updated explanation.

© 2026 Chentao Fan. Contact: xxxkkk0101@foxmail.com