Privacy Policy
Last updated: July 10, 2026
1. Information We Collect
We collect information you provide directly, including account registration details, organization settings, public profile settings, client and parent records, student records, class and slot records, booking and enrollment records, attendance and make-up records, payment records, uploaded payment slips, receipt settings, message templates, communications, notes, support requests, and audit records. We also collect technical information such as device, browser, log, session, security, and usage data.
2. Customer and Student Data
Businesses using Yarne may enter information about their own customers, parents, students, children, clients, trainers, or staff. For tutoring schools, this may include student names, nicknames, dates of birth, addresses, sibling counts, birth order, caregiver details, personality notes, special care notes, academic year, eligibility status, attendance, make-up history, class transfers, and enrollment or payment status. Yarne processes that information to provide the Service. The business using Yarne is responsible for giving required notices and obtaining required permissions or consents from the people whose data it enters into the Service.
3. How We Use Information
We use information to provide, secure, maintain, and improve Yarne; authenticate users; manage organizations; process customer portals and public inquiry forms; track bookings, enrollments, attendance, make-ups, transfers, payments, receipts, and reports; assign payment receiving accounts; send transactional messages, reminders, owner alerts, and portal invitations; provide support; detect abuse; investigate security events; and comply with legal, security, financial, and operational obligations.
4. Portals, LINE, and Messaging
Customer portals may use secure tokens to let parents or clients view records, add or update contact details, register students, enroll in classes, review payment instructions, upload payment slips, and access receipts. When LINE features are enabled, Yarne may process LINE user IDs, account-linking state, inbound and outbound messages, attachments, payment slip uploads, conversation records, and delivery or review status. Bank account details are shown only in authenticated or linked contexts, such as a secure portal or linked LINE conversation, and not on public profile pages.
5. Payment and Slip Processing
Yarne helps businesses track external payments, payment plans, assigned receiving accounts, receipts, slip uploads, and review status. Yarne does not initiate bank transfers, hold school funds, or process parent-to-school transfers directly. Payment account details, tuition decisions, refunds, discounts, transfer adjustments, and make-up or enrollment policy decisions remain the responsibility of the business using Yarne.
6. AI Processing
Payment slip images and related payment details may be sent to Anthropic's Claude API to extract payment amount, date, reference, payer, and confidence information. Yarne may also use AI to summarize records or help draft communications. AI output is used to support workflow automation and should be reviewed for important decisions.
If a business enables the LINE AI assistant, inbound and outbound LINE message content, conversation context, customer identifiers, and assistant state may be processed by Yarne and Anthropic so the assistant can answer questions, summarize recent context, detect escalation needs, and hand the conversation back to a person. Businesses can turn off the LINE AI assistant in their AI settings, and customers can ask the business or Yarne to delete or stop processing their conversation data where required by law.
If voice-message transcription or other optional AI tools are configured, audio or related content may be processed by OpenAI or another configured provider. AI features may be disabled by default for an organization and enabled only by the business owner or another authorized administrator.
7. Service Providers
Yarne may share limited data with service providers needed to operate the app, including Supabase for database, auth, and storage; Vercel for hosting; Anthropic for AI processing; OpenAI for optional voice transcription or other configured AI tools; Resend for transactional email; Stripe for subscription billing; LINE for messaging when enabled; PostHog for product analytics when configured; and Google for OAuth or workspace services when configured. We do not sell personal data.
8. Cookies and Analytics
We use cookies and similar technologies for authentication, security, session management, organization selection, language preferences, portal flows, and product analytics. We do not use advertising cookies in the Service.
9. Data Storage and Security
We use technical and organizational safeguards intended to protect data, including TLS in transit, provider-managed encryption at rest, role-based access controls, Row Level Security where applicable, audit logging, and private storage for uploaded payment slips. Sensitive operational records, such as payment slips, portal tokens, and account-linking data, are handled with additional access controls where applicable. No system is perfectly secure, and you are responsible for protecting your own account credentials.
10. Retention and Deletion
We retain information for as long as needed to provide the Service, comply with legal or financial obligations, resolve disputes, maintain security, and support business records. Student, enrollment, attendance, make-up, transfer, payment, receipt, and customer communication records may be retained while the business needs them for school administration, financial records, parent support, dispute resolution, or legal compliance. Account deletion removes associated organization data within a reasonable period unless retention is required by law, security, audit, backup, or legitimate business needs.
LINE conversation records and AI thread state are retained while needed to provide the Service, preserve business and support history, maintain security, or meet legal and audit obligations. Certain terminal delivery and automation job records are removed after 180 days. Audit logs may be retained for security, incident response, and financial accountability. Backups may retain deleted data for a limited period before normal rotation removes it.
11. International Processing
Yarne and its providers may process and store information in countries other than where you or your customers are located. By using the Service, you understand that information may be transferred to and processed in those locations. Businesses using Yarne should provide any location-specific notices or consents required for their customers, parents, students, staff, or clients.
12. Your Choices and Rights
Depending on your location, you may have rights to request access, correction, deletion, export, restriction, or objection related to personal data. To make a request, contact us using the email below. If your data is controlled by a business using Yarne, we may direct your request to that business.
13. Children's Information
Yarne is intended for use by businesses and adults, not for direct use by children. Tutoring schools or parents may enter student or child information into the Service for business administration. The business using Yarne is responsible for any required parental, guardian, or school consent and for complying with laws that apply to children's information.
Yarne is not intended to let children create their own Yarne accounts or submit data directly without adult involvement. Parent portal and public registration flows are intended for parents, guardians, adult clients, or authorized school staff.
14. School-Specific Notices and Translations
A school or business may provide additional privacy notices, enrollment terms, consent language, or translated summaries for its own customers. Those school-specific notices should be reviewed by the school and its legal advisors. If a translated summary is provided for convenience, the school should confirm whether the English text or the translated text controls for that relationship.
15. Changes to This Policy
We may update this Privacy Policy from time to time. The updated version will be posted here with a revised date.
16. Contact
Privacy questions or data requests: support@yarne.app.
