Legal

Security & Data Practices

Version 1.0 · Effective 4 October 2026 · Last updated 4 October 2026

1. How we protect your data

  • Authentication is handled by our managed cloud authentication service.
  • Projects and assets are private to your account by default; staff do not routinely view private assets, but authorised access may be needed for support, safety, legal complaints or incidents.
  • Payment card data is processed by Stripe and never touches our servers in full.
  • Private work is not used in our marketing without permission or to train Yoruvi-owned generative models; Higgsfield API training opt-out is enabled.
  • Acceptable-use rules, real-person declarations when applicable and rights-complaint handling support responsible use.

2. Your part

Use a unique password, keep your sign-in credentials private, and sign out on shared devices. Tell us immediately at hi@yoruvi.com if you suspect unauthorised access.

3. Incidents

If a personal-data breach occurs that is likely to risk your rights and freedoms, we will notify the ICO and affected users as required by UK GDPR.

4. Reporting a vulnerability

Security researchers can email hi@yoruvi.com with the subject “Security — Yoruvi”. Please give us a reasonable opportunity to investigate and fix before public disclosure. We do not claim particular certifications, encryption algorithms or uptime guarantees here.

Questions about this document? Email hi@yoruvi.com.