Privacy Policy
Last updated: May 2026
Who we are
Yurocket (“we”, “us”, “the service”) is a lead-enrichment and outbound-email automation tool. We're reachable at arslan.j@yurocket.com. This page explains what data we collect, why, who we share it with, and how to delete it.
What we collect
- Account information. Your email address, an encrypted password (handled by Supabase Auth), and any name / avatar you provide via Google sign-in.
- Workspace content. Workbooks, tables, columns, cells, sequences, campaigns, brand profiles, tasks, agents, tags, and other content you create or upload.
- Integration credentials. API keys you connect (e.g. Instantly, Anthropic) are encrypted at rest using AES-256 before being stored.
- Usage events. A minimal record of which features you use (e.g. AI prompts run, exports created) so we can diagnose issues and plan capacity. We do not sell this data.
- Cookies. An authentication session cookie from Supabase Auth, an active-workspace preference cookie (
yr_active_ws), and standard hosting cookies from Vercel. We don't use third-party advertising or analytics cookies.
Why we collect it
- To provide the service you signed up for.
- To authenticate you, secure your account, and prevent abuse.
- To send transactional emails — workspace invitations and password resets.
- To run the AI / HTTP / integration columns you explicitly invoke (each run is initiated by you).
- To respond to support requests you send us.
We do not use your data to train AI models or sell it to third parties.
Service providers we share data with
We rely on the following sub-processors to run the service. Each only sees the data necessary for their function:
- Supabase — authentication and database hosting (your account, workspace data, RLS-scoped access).
- Vercel — application hosting and serverless functions.
- Anthropic — when you run an AI column, the prompt you wrote and the cell data it references is sent to Anthropic's Claude API. Anthropic does not train on this data per its API terms.
- Instantly — when you push leads to Instantly or attach a sequence, the lead data and message bodies you wrote are sent to Instantly via API.
- Resend — transactional email delivery for invitations and password resets.
- Google — only if you choose “Continue with Google”. We receive your email address, name, and avatar from Google; no other Google account data.
Data security
- All traffic is over HTTPS.
- Database access is gated by row-level security so members of one workspace can't see another's data.
- Integration API keys are encrypted with AES-256-GCM before storage; only the application can decrypt them at use time.
- Passwords are never stored in plain text — Supabase Auth hashes them with bcrypt.
Your rights
You can:
- Access all of your workspace data directly in the app at any time.
- Export tables and sequences via the built-in export features.
- Delete any workspace, workbook, table, or row from inside the app. To delete your entire account, email arslan.j@yurocket.com and we'll erase your account plus all owned workspaces within 30 days.
- Withdraw consent for Google sign-in by removing Yurocket from your Google Account permissions (myaccount.google.com → Security → Third-party apps).
Retention
Account and workspace data is retained as long as you maintain an active account. On deletion request, we erase the account and all workspaces you own within 30 days. Backups roll off within 90 days. Aggregated, non-identifying usage statistics may be retained indefinitely.
International transfers
Our database is hosted in ap-south-1 (Mumbai). Our sub-processors (Vercel, Anthropic, Resend, Google) may process data in other regions. By using the service you consent to these transfers.
Changes
If we make material changes to this policy we'll email workspace owners at the address on file before they take effect. Minor wording fixes will be silently updated and reflected by the “Last updated” date above.
Contact
Questions, requests, or complaints: arslan.j@yurocket.com.