Yecho Privacy Policy
Version: 1.2 Effective date: August 29, 2026
Yecho is a personal tool for notes, to-dos, reminders, and review. We design the product around two principles: data stays on your device by default, and external capabilities are used only when you choose to enable them. This Policy explains how Yecho handles your information and which features send data to Apple, our feedback service, or a third-party service that you configure.
1. Operator and Contact Information
Yecho is operated by Chentao Fan. For privacy-related questions, email xxxkkk0101@foxmail.com.
2. Data Processed on Your Device
The following content that you enter or generate in Yecho is stored on your device by default:
- Text notes, text produced by speech transcription, to-dos, reminder times, projects, topics, tags, summaries, status, and review information;
- On-device settings, such as reminder preferences, AI service configurations, calendar sync preferences, and cached membership status;
- Runtime logs and on-device diagnostic information used to help troubleshoot issues when you choose to submit feedback.
Data that is processed only on your device and is not sent to our servers or a third-party service is not data that we collect from you.
3. Permissions and System Services
Yecho requests permissions only when the relevant feature needs them:
- Microphone: used when you record a voice note;
- Apple Speech Recognition: used to convert voice notes into text;
- Notifications: used for standard reminders on individual to-dos that you set;
- AlarmKit: used to sound, stop, and snooze an alarm when you expressly choose an alarm-style reminder;
- Full access to Apple Calendar: used, when you enable Apple Calendar sync, to display calendar events and to create, update, or remove linked events for Yecho items with an exact time.
Apple provides these system capabilities. Apple's rules and settings apply to Apple's processing of data in its services.
4. iCloud Sync
Yecho uses on-device storage by default. Purchasing or restoring a membership does not automatically enable iCloud. Only when your membership entitlement is active, you expressly enable “iCloud Sync” in Yecho Settings, and iCloud is available does the app attempt, after you next fully quit and reopen it, to use your private Apple CloudKit database to sync SwiftData records between devices signed in to the same Apple ID. Turning the switch off or losing the membership entitlement returns the app to on-device storage after the next full quit and reopen. When Settings shows that the iCloud account is available or enabled, that reflects only the configuration status for that session; it does not prove that a particular record has been uploaded or reached another device.
5. Bring Your Own AI Provider (BYOK)
Yecho Pro can connect to an AI provider, Base URL, API Key, and model that you configure. The API Key is stored in the on-device Keychain. Configuration and model tests send only synthetic test content and do not contain your personal notes.
Online AI data access is off by default. Before Yecho sends personal content to a third-party AI provider, the AI Data & Privacy screen identifies the configured provider, Base URL, and model and asks you to authorize each data category separately: (1) the full text that you type or paste, and (2) the full text produced from a voice transcription. When you authorize a category and use online organization, Yecho sends that full text, together with the current local date, time, and time zone, directly to the configured provider endpoint. Yecho does not send the original audio recording, your images, Apple Calendar data, the on-device database, or diagnostic logs to the AI provider.
You can revoke either data-category authorization at any time. Changing the configured provider, Base URL, or model invalidates the existing authorization and requires a new authorization before personal content can be sent. If no usable AI service is configured or the relevant category is not authorized, Yecho applies on-device rules or skips cloud-based recognition.
The provider's own policies govern whether it retains data, uses data for model training, supports deletion, or processes data across borders. Because you may configure different third-party providers, Yecho and its developer cannot uniformly verify or control those practices. The developer cannot access or store your third-party API Key through Yecho and does not make data-processing commitments on behalf of the provider. Review the provider's privacy policy before enabling access.
6. Apple Watch Companion
The Apple Watch companion uses Apple WatchConnectivity to exchange quick-capture drafts, to-do summaries, and completion or postponement actions with the paired iPhone. The Watch may temporarily store lightweight drafts that have not yet been confirmed as delivered and a recent to-do snapshot. The iPhone is the writer of the primary data. This channel does not send an API Key to the Watch, and the Watch does not call online AI services. These device-to-device data are not provided to the Yecho operator.
7. On-Device Diagnostics, Interaction Analytics, and User-Initiated Exports
Yecho records runtime logs and a fixed set of interaction events on your device to help troubleshoot issues and improve the product. Interaction events contain only page, control, action, and result IDs. They do not record titles, body text, voice content, contact information, API Keys, exact dates, or item IDs, and they are retained for no more than 14 days by default. These on-device files are not uploaded automatically. You can view, clear, or choose to export them in Advanced Settings.
A product-analysis export includes original text, segmentation results, confidence, parsing source, and correction history. It is generated only after you tap Export and is not sent to us automatically. Treat an export as sensitive material and decide for yourself whether to share it with another person or an external service.
8. Feedback and Support
When you submit feedback in the app, it is sent to https://ctfanstudio.com/api/yecho/feedback. A submission may include:
- The feedback text that you enter;
- Contact information that you choose to provide;
- App version, build number, system name, system version, device model, language, and region;
- A diagnostic summary that you choose to include;
- Image attachments that you choose to add.
The diagnostic summary filters field names that are obviously sensitive, but it may still reflect some runtime state. Do not include passwords, keys, identification documents, payment-card details, health records, or other highly sensitive information in feedback text or attachments.
The current Yecho client does not provide a verified server-side automatic-deletion API and does not state a fixed retention period. We use feedback to investigate issues, respond to users, and improve the service. To ask about, correct, or request deletion of feedback records on the server, contact us at xxxkkk0101@foxmail.com. What can be done depends on actual service capabilities, whether a record can be identified, and applicable legal requirements.
The app stores no more than 20 feedback summaries, submission identifiers, and public-reply statuses on your device. When you open the feedback page or manually refresh replies, the app sends those submission identifiers to the reply endpoint to look up the corresponding public replies. Clearing app data removes the local history but does not mean that server-side records have been deleted.
9. Purchases and Membership
Yecho uses Apple StoreKit to process subscriptions, one-time purchases, and purchase restoration. Apple handles payment, renewal, refunds, and subscription management. Yecho reads only the transaction entitlement status needed to determine whether Pro features are available.
10. No Tracking or Advertising
Yecho does not include third-party advertising SDKs and does not use your data to track you across apps or websites.
11. Children
Yecho is intended for general personal-productivity use and is not specifically directed to children. If a parent or guardian believes that a minor submitted personal information through feedback, they may contact us at the email address in this Policy.
12. Your Choices
You can:
- Disable microphone, speech recognition, notification, calendar, and iCloud permissions in system settings;
- Disable calendar sync, enable or disable iCloud sync, revoke either AI data-category authorization, delete AI connections, omit diagnostic information, and change future sync conditions through membership status or Apple ID and iCloud settings;
- Delete on-device app data;
- Contact us by email regarding information that you submitted to our feedback service.
13. Policy Updates
If Yecho's data-processing practices change materially, we will update this Policy and display the new version in an appropriate place. By continuing to use an affected feature, you acknowledge the updated explanation.