Legal
Security & Data Practices
Version 1.0 · Effective 4 October 2026 · Last updated 4 October 2026
1. How we protect your data
- Authentication is handled by our managed cloud authentication service.
- Projects and assets are private to your account by default; staff do not routinely view private assets, but authorised access may be needed for support, safety, legal complaints or incidents.
- Payment card data is processed by Stripe and never touches our servers in full.
- Private work is not used in our marketing without permission or to train Yoruvi-owned generative models; Higgsfield API training opt-out is enabled.
- Acceptable-use rules, real-person declarations when applicable and rights-complaint handling support responsible use.
2. Your part
Use a unique password, keep your sign-in credentials private, and sign out on shared devices. Tell us immediately at hi@yoruvi.com if you suspect unauthorised access.
3. Incidents
If a personal-data breach occurs that is likely to risk your rights and freedoms, we will notify the ICO and affected users as required by UK GDPR.
4. Reporting a vulnerability
Security researchers can email hi@yoruvi.com with the subject “Security — Yoruvi”. Please give us a reasonable opportunity to investigate and fix before public disclosure. We do not claim particular certifications, encryption algorithms or uptime guarantees here.
Questions about this document? Email hi@yoruvi.com.