YELW

YELW — Privacy Policy

Last updated: 15 July 2026 · Version: 1.0


At a glance (plain-language summary)

We wrote this for a young audience, so here is the short version. The full policy below is the binding one.

An Arabic-language version of this summary and of the full policy is made available in-app and at yelw.ai/privacy-ar; see §16.


1. Who we are (data controller)

YELW ("YELW", "we", "us", "our") is a Christian wellness application operated by YELW, a company registered in the Hashemite Kingdom of Jordan and based in Amman, Jordan (the "Controller").

YELW is the data controller for the personal data described in this policy. You can reach us using the contacts below.

Role Contact
Data controller YELW, Amman, Jordan
Privacy / data-protection contact & Data Protection Officer (DPO) privacy@yelw.ai
Legal / terms legal@yelw.ai
Security security@yelw.ai
General support support@yelw.ai
Website https://yelw.ai
EU/EEA representative (GDPR Art. 27) To be appointed as required; until individually named in this policy, reachable via privacy@yelw.ai
UK representative (UK GDPR Art. 27) To be appointed as required; until individually named in this policy, reachable via privacy@yelw.ai

Sign-in, account credentials, and age verification for YELW are handled by our shared Identity Service (see §4), which is operated on our behalf and governed by this policy as it applies to YELW.

If you are in the EEA, the UK, or another region with a data-protection authority, you have the right to complain to your local regulator (see §13).

2. Scope of this policy

This policy explains how YELW collects, uses, shares, and protects personal data when you use the YELW mobile app and the YELW website (yelw.ai, app bundle ai.yelw.app). It does not cover third-party services you reach from a link we provide, or the practices of a church, ministry, or youth group you engage with outside YELW.

3. Ages, and who may use YELW

4. The Identity Service — the shared account

Your account identity (email, display name, date of birth, password, and any Google/Apple sign-in identifiers) is created and held by our shared Identity Service, not by YELW's own feature database. YELW receives from that service only a signed token identifying you by an account identifier and, when needed for the age-gate, your date of birth and the derived minor flag. YELW stores that date of birth on its own settings record only to enforce the minor protections without re-querying identity on every request.

We never receive or store your password in any form; the Identity Service stores it hashed (irreversibly transformed), never in plain text.

5. What data we collect, and where it comes from

5.1 Categories

Category Examples Source
Account & identity Email, display name, date of birth (age-gating), hashed password, optional Google/Apple sign-in identifiers You, via the Identity Service
Onboarding profile Your onboarding answers: faith stage, wellness/body goals, current emotional / mood state, interests, daily rhythm, and a companion name You
Wellness & activity Habits and habit logs, mood check-ins, gratitude entries, quiz and flashcard progress, audio-progress, creative works (Icon/Poem), daily missions, devotional and Scripture-reading progress You, as you use the app
Gamification Coins, XP, streaks, badges, and redemption records. Coins are earned, not bought — they cannot be purchased with real money. Generated as you use the app
Special-category — religious Your Christian faith engagement is pervasive across the app (faith stage, devotional use, Scripture interaction, doubt questions). This reveals religious belief. Processed on the basis of explicit consent (GDPR Art. 9(2)(a)); for a minor below the applicable digital-consent age, that consent is authorised by the parent/guardian. You
Special-category — health Mood / emotional-state data and mental-health signals (mood check-ins, counselor use, distress signals), treated as health data. We do not sync with external health apps (e.g. Apple Health / Google Fit) in this version. Processed on the basis of explicit consent (GDPR Art. 9(2)(a)); for a minor below the applicable digital-consent age, that consent is authorised by the parent/guardian. You
Private, encrypted content Your journal entries and your Safe-Doubt conversations You
Guardian-consent data For a minor account: the guardian's email address and the consent-record lifecycle (pending / confirmed, timestamps) You (the minor) and your guardian
Technical / diagnostic App and device diagnostics necessary to run and secure the service, logs, and network/connection diagnostics (not location) Automatically, as you use the app

5.2 What we do not do

6. AI features — your content stays in-house

YELW includes an AI companion, a faith-AI, and a supportive counselor feature, along with mood-matched encouragement, the Safe-Doubt guide, and devotional tailoring. All of this AI runs on YELW's own self-hosted inference infrastructure. No prompt, message, journal entry, or doubt question is ever sent to any third-party AI or LLM provider (such as OpenAI, Google, or Anthropic).

Two hard boundaries are enforced in code:

  1. Personalization uses only derived, minimised signals — for example a mood label ("anxious") or your faith stagenever the raw text of your private journal or Safe-Doubt conversations. Raw private-surface content never enters any recommendation, analytics, or model-training pipeline. Your private journal and Safe-Doubt text are never used to train AI.
  2. Safety is computed by us, not delegated to the model. Deterministic distress signposting runs on defined signals and is shown independently of the AI's output — so the support resource appears regardless of what the AI does, and is never withheld, throttled, or paywalled. However, YELW does not guarantee that every instance of distress will be detected.

AI output is faith-based encouragement and reflection. It is not professional, medical, or clinical advice (§8).

For users in the EEA/UK we must state a legal basis for each purpose; for special-category data (religion, health) we must also state an Article 9 condition. The table below does that. For MENA jurisdictions, the corresponding PDPL basis (consent, or a statutory ground) is noted in §14.

# Purpose Data used GDPR / UK GDPR legal basis GDPR Art. 9 condition (special-category)
1 Provide the core service (create your account, run the app, save your work) Account, non-special-category onboarding, activity Contract (Art. 6(1)(b)) — (any special-category onboarding element — religious belief, mood/wellbeing treated as health — relies on explicit consent under purposes 2 and 4, not on contract)
2 Deliver faith content & personalization (devotional, companion, mood-matched content) Faith stage, mood label, interests Consent (Art. 6(1)(a)) Explicit consent (Art. 9(2)(a)) for the religious/health inference; you choose to use these features
3 Private journaling & Safe-Doubt space Encrypted journal / doubt content Consent (Art. 6(1)(a)) Explicit consent (Art. 9(2)(a)) — you actively create this content in an encrypted, owner-only space
4 Mood tracking & Soul counselor (health-adjacent) Mood check-ins, emotional state Consent (Art. 6(1)(a)) Explicit consent (Art. 9(2)(a))
5 Distress response & duty of care Mood/doubt distress signals Legitimate interests (Art. 6(1)(f)) — protecting users, especially minors; and legal obligation where escalation is mandated Explicit consent (Art. 9(2)(a)) for the underlying feature and, in a crisis, vital interests (Art. 9(2)(c))
6 Guardian consent (email-based verification) for minors Guardian email, consent record Legal obligation (Art. 6(1)(c)) / Consent (Art. 6(1)(a)) Not applicable (consent metadata, not special-category content)
7 Security, abuse & capacity protection Technical, diagnostic, rate-limit data Legitimate interests (Art. 6(1)(f)) — securing the service
8 Comply with law (respond to lawful requests, keep required records) As required Legal obligation (Art. 6(1)(c)) Art. 9(2)(f)/(g) as applicable

Special-category data (religion; mood/wellbeing as health). Special-category data — data revealing religious belief, and mood/wellbeing data treated as health data — is processed on the basis of explicit consent (GDPR Art. 9(2)(a)), not under contract. For a minor below the applicable digital-consent age, that explicit consent is authorised by the parent/guardian through the guardian-consent step (§9.3).

Withdrawing consent. Where we rely on consent (purposes 2–4), you may withdraw it at any time — by turning off the relevant feature, deleting the content, or deleting your account (§13). Withdrawal does not affect processing already carried out.

No incompatible re-use. We do not use your data for a new, incompatible purpose without a fresh basis. In particular, private-surface content is purpose-locked to your own private use.

8. Safety, mental-health & crisis

9. Children & minors

Because YELW's audience skews young and includes minors, we design as if minors are present, and we build high-privacy protections in by default and server-side.

9.1 Age thresholds by regime

Regime Position we apply
US — COPPA No accounts under 13. We do not knowingly collect personal data from a child under 13.
EU/EEA — GDPR Art. 8 (GDPR-K) Minimum age 13. Where a member state sets a higher digital-consent age (up to 16), for users below that age we obtain the consent of the holder of parental responsibility (via email-based verification) before consent-based processing.
UK — UK GDPR / DPA 2018 & the Age-Appropriate Design Code (Children's Code) Minimum age 13; parental consent (via email-based verification) for consent-based processing below the UK digital-consent age; the Children's Code standards applied by default (see §9.4).
Jordan — PDPL Processing of a minor's data on the basis of guardian consent, in line with Jordanian law.
Saudi Arabia — PDPL Processing of a minor's data on the basis of guardian consent, in line with Saudi law.
UAE — PDPL Processing of a minor's data on the basis of guardian consent, in line with UAE law.

Across every market, an account for a user below the applicable minimum age will not be activated, and any account we determine to belong to an under-13 user is removed.

9.2 Minor protections we enforce (built in, server-side)

For any account the trusted date of birth shows to be a minor (under 18) — and, on a fail-safe basis, for any account whose age we cannot verify — YELW applies the locked-down posture automatically:

At sign-up, a minor provides a guardian's email. YELW emails the guardian a one-time, expiring confirmation link (valid for 72 hours, single-use). Until the guardian clicks it and confirms, the minor's elevated activities remain blocked server-side. This email-based verification is proportionate to the low-risk processing involved.

This guardian-consent step is a GDPR Article 8 / local digital-consent-age mechanism for minors aged 13–17. It is not a COPPA under-13 verifiable-parental-consent flow: under-13 users are blocked entirely and no under-13 account is created.

The guardian's window is strictly limited. A guardian may confirm consent and exercise the minor's data rights (access, correction, export, deletion). A guardian never gains access to the minor's private journal or Safe-Doubt content — those remain the young person's own and are encrypted to them alone. Where guardian oversight is active on an account, we make that fact visible to the young person.

9.4 The UK Children's Code

Where the UK Age-Appropriate Design Code applies, YELW follows its standards: high privacy by default, data minimisation, no detrimental use of children's data, no nudge techniques that push a child to weaken privacy or over-use, transparency a child can understand, and a Data Protection Impact Assessment covering the faith + health + minors processing.

10. Retention

We keep personal data only as long as needed for the purpose it was collected for, then delete or irreversibly anonymise it.

11. Recipients, sub-processors & data location

We disclose personal data only to:

We do not disclose personal data to advertising networks or data brokers, and we do not send content to any third-party AI/LLM provider.

Sub-processor (category) Purpose Location
DigitalOcean Application + database hosting EU — Frankfurt, Germany
Cloudflare Object storage + content delivery (CDN) Global CDN; origin data in the EU
Third-party email delivery provider Transactional + guardian-consent email Under a data-processing agreement

Data location & international transfers. Personal data is primarily hosted in the EU (Germany). YELW is MENA-focused and offered globally through the App Store and Google Play. Where personal data is transferred across borders (for example to a processor outside the EEA/UK or a MENA jurisdiction), we rely on an appropriate transfer mechanism — such as the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, an adequacy decision, or the applicable PDPL transfer basis — and apply supplementary safeguards where needed.

12. Security

No system is perfectly secure; we cannot guarantee absolute security, but we work to protect your data proportionately to its sensitivity. To report a security concern, contact security@yelw.ai.

13. Your rights & how to exercise them

Subject to your region's law, you may have the right to: access your data, correct it, delete it, export/port it, restrict or object to processing, withdraw consent, and not be subject to solely automated decisions with legal or similarly significant effect. YELW does not make such solely-automated decisions about you; personalization is a convenience feature you can turn off.

Two of these are self-service, in-app, right now:

To exercise any other right, contact privacy@yelw.ai. We will respond within the period your law requires (for GDPR/UK GDPR, within one month, extendable for complex requests). For a minor, a verified guardian may exercise these rights on the minor's behalf — except access to the minor's private journal / Safe-Doubt content, which stays private to the young person.

We do not charge for exercising your rights except where a request is manifestly unfounded or excessive, as your law allows. If we cannot verify your identity we may ask for more information before acting.

Complaints. EEA/UK users may lodge a complaint with their supervisory authority (UK: the Information Commissioner's Office; EU: your national data protection authority). Users in Jordan, Saudi Arabia, and the UAE may complain to the competent data-protection authority in their country. We would appreciate the chance to resolve your concern first — please contact privacy@yelw.ai.

14. Regional provisions

15. Changes to this policy

We may update this policy. For material changes we will give prominent notice in-app and, where required, seek fresh consent (especially for children's data). The "last updated" date at the top shows the current version; we keep prior versions available on request.

16. Language & Arabic version

YELW is offered in English and Arabic. An Arabic-language translation of this policy and of the at-a-glance summary is provided at yelw.ai/privacy-ar and in-app. If there is any conflict between versions, the English version governs for legal interpretation, except where a market's law requires the local-language version to prevail (in which case that version governs in that market).

17. Governing law & contact

Governing law and forum. This policy and any dispute relating to it are governed by the laws of the Hashemite Kingdom of Jordan, and the competent courts of Amman, Jordan have jurisdiction, without prejudice to any mandatory data-protection rights or local remedies available to you under the law of your country of residence.

Contact.