Privacy Policy
YIRI stores as little as the product needs, and this page names all of it.
Last updated July 2026. Material changes are announced in the changelog.
What YIRI stores
An account is an email address, a password (stored only as a hash), and the discoveries you chose to archive with the journeys that led to them. Exploring as a guest uses an anonymous session with no email attached; registering converts that same session, so nothing is copied anywhere new. Joining with a membership code records that the code was redeemed and by which account — nothing about the code itself is stored against you beyond that.
Authentication
Authentication and data storage run on Supabase, which processes your email address, password hash, and session tokens on YIRI’s behalf. Sessions are kept in a secure browser cookie so you stay signed in between visits.
YIRI sends transactional email only — confirmation when you register and a link when you reset your password. Delivery goes through Resend, which processes the recipient address for that purpose. No newsletters, no marketing, and your address is never shared beyond the processors named here.
Human verification
Registration is protected by Cloudflare Turnstile, which may process connection and browser signals to tell people from bots. A passed check sets a short-lived cookie (yiri_human, ten minutes) so a recoverable error doesn’t make you solve the check again.
Playback
Music plays through SoundCloud’s embedded player. While a record plays, SoundCloud may set its own cookies under its own privacy policy — YIRI neither sees nor controls what it collects.
Future subscriptions
If YIRI introduces paid subscriptions, payment will be handled by a dedicated payment processor — card details will never touch YIRI’s servers — and this policy will be updated before any payment feature goes live.
Your data, your call
You can delete your account from the account page, which removes your email, credentials, and archive. For any question about your data, write to hello@yiri.world.