Privacy Policy

Last updated 11 August 2026

Yakin Elevate (“Elevate”, “we”) is operated by [Yakin Technologies — registered legal entity name], [registered address]. This policy explains what we collect, why, how long we keep it, and how to make us delete it.

Elevate is a business tool. It reads a customer’s mailbox and calendar to build a picture of their working relationships. That means we necessarily process information about third parties — the people our customers correspond with — who have not signed up themselves. Section 6 covers how we treat them.

1. Data you give us directly

  • Account details: your name, email address, and a password. Passwords are stored only as a scrypt hash — we cannot read yours, and neither can anyone with a copy of our database.
  • Workspace content: anything you type into Elevate — notes, deals, tasks, documents you upload.

2. Data from Google, and exactly what we do with it

If you connect a Google account, Elevate requests two read-only permissions and no others:

  • gmail.readonly — to read message metadata and content from your mailbox.
  • calendar.readonly — to read calendar events.

These permissions do not allow Elevate to send, modify, or delete anything. From your mailbox we store the sender and recipients, the subject, the message body, and the timestamp. From your calendar we store the event title, start and end times, location, and attendee list.

We do not read or store calendar event descriptions. They routinely contain dial-in credentials and private notes that are irrelevant to what Elevate does, so the code excludes them before anything is written.

We use this to identify the people you deal with, score how strong each relationship is, and produce recommendations that cite the specific messages and meetings behind them. That is the entire purpose.

3. Limited Use of Google user data

Yakin Elevate’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, data obtained from Google APIs is never:

  • used for advertising of any kind;
  • sold, rented, or licensed to anyone;
  • used to train, fine-tune, or improve generalised or non-personalised artificial-intelligence or machine-learning models;
  • transferred to third parties except as required to operate the service (see section 5), to comply with law, or with your explicit consent.

Humans do not read your Google data. The only exceptions are where you have given explicit permission for a specific issue, where it is necessary for security purposes such as investigating abuse, or where the law compels it.

4. Artificial intelligence

Elevate’s recommendations are produced by a deterministic rules engine running on your own data. No third-party model is involved in deciding what to recommend.

A language model may be used for one narrow task: wording a draft message you have asked for. When that happens, the model receives only the facts needed to write it — a name, an organisation, and the dates of prior contact — and the output is shown to you for approval. Nothing is sent to anyone on the strength of a model’s output alone.

Our model providers do not use content submitted through their APIs to train their models. If no model provider is configured, Elevate writes drafts from templates and makes no external calls at all.

5. Who else processes your data

We use a small number of sub-processors, each for one job:

  • Neon — managed PostgreSQL database hosting.
  • Vercel — application hosting.
  • [your email provider] — delivery of transactional email and any outreach you approve.
  • [your model provider] — draft wording only, as described in section 4. Omitted if not configured.

6. People who did not sign up

When you connect a mailbox, Elevate creates records for the people you correspond with. They are not our customers and have not agreed to anything.

We process their information on the basis of the legitimate interest of a business in maintaining a record of its own commercial relationships, limited to what is necessary for that purpose. We do not enrich these records from external data brokers, build profiles for anyone other than the customer whose mailbox they came from, or share them between customers.

If you are one of these people and want your details removed, write to privacy@yakinelevate.com. We will identify the customer holding the record and act on it.

7. Security

  • OAuth tokens are encrypted with AES-256-GCM before they are written to the database. A copy of the database without our application key does not grant access to any mailbox.
  • Session tokens, password-reset links, and shared document links are stored only as hashes. We hold no reusable copy of any of them.
  • Every workspace’s data is scoped and queried separately.
  • Consequential actions, including everything performed on your behalf automatically, are recorded in an append-only audit log.

8. How long we keep things

Ingested messages and events are retained while your account is active, because relationship history is what the product is for. Disconnecting a Google account immediately revokes and deletes the stored tokens and stops all further access; data already ingested remains until you delete it or close your account.

Closing your account deletes your workspace and everything in it, including all ingested mail and calendar data, within 30 days. Expired sessions, spent reset tokens, and lapsed invitations are pruned automatically.

9. Your rights

You may request access to your data, correction, deletion, a portable copy, or restriction of processing, by writing to privacy@yakinelevate.com. We respond within 30 days. If you are in the UK or EEA you may also complain to your local supervisory authority.

10. Changes

If we change what we collect or what we do with it, we will update this page and tell account holders by email before the change takes effect.

11. Contact

[Yakin Technologies — registered legal entity name], [registered address]. Email privacy@yakinelevate.com.

See also our Terms of Service.