YELW — Privacy Policy
Last updated: 15 July 2026 · Version: 1.0
At a glance (plain-language summary)
We wrote this for a young audience, so here is the short version. The full policy below is the binding one.
- What YELW is. A Christian wellness app — Body · Soul · Spirit — for young people. Available in English and Arabic, focused on the MENA region.
- The most private things stay the most private. Your journal and your Safe-Doubt conversations are encrypted and can be read only by you — never by a parent/guardian, a youth leader, another user, or an advertiser.
- Your questions are not sent to any outside AI company. All of YELW's AI runs on our own servers. Your private journal and doubt text are never used to train AI or to power recommendations.
- No ads. No selling your data. No cross-app tracking.
- If you're a minor (under 18), your account is private by default, and a parent/guardian must confirm consent before certain activities are unlocked.
- You must be at least 13 to have a YELW account.
- You are in control. You can download all of your data and permanently delete your account from inside the app, at any time.
- In a crisis, help is always free. We will never put a price, a limit, or a game between you and support.
An Arabic-language version of this summary and of the full policy is made available in-app and at yelw.ai/privacy-ar; see §16.
1. Who we are (data controller)
YELW ("YELW", "we", "us", "our") is a Christian wellness application operated by YELW, a company registered in the Hashemite Kingdom of Jordan and based in Amman, Jordan (the "Controller").
YELW is the data controller for the personal data described in this policy. You can reach us using the contacts below.
| Role | Contact |
|---|---|
| Data controller | YELW, Amman, Jordan |
| Privacy / data-protection contact & Data Protection Officer (DPO) | privacy@yelw.ai |
| Legal / terms | legal@yelw.ai |
| Security | security@yelw.ai |
| General support | support@yelw.ai |
| Website | https://yelw.ai |
| EU/EEA representative (GDPR Art. 27) | To be appointed as required; until individually named in this policy, reachable via privacy@yelw.ai |
| UK representative (UK GDPR Art. 27) | To be appointed as required; until individually named in this policy, reachable via privacy@yelw.ai |
Sign-in, account credentials, and age verification for YELW are handled by our shared Identity Service (see §4), which is operated on our behalf and governed by this policy as it applies to YELW.
If you are in the EEA, the UK, or another region with a data-protection authority, you have the right to complain to your local regulator (see §13).
2. Scope of this policy
This policy explains how YELW collects, uses, shares, and protects personal data when you use the YELW mobile app and the YELW website (yelw.ai, app bundle ai.yelw.app). It does not cover third-party services you reach from a link we provide, or the practices of a church, ministry, or youth group you engage with outside YELW.
3. Ages, and who may use YELW
- YELW is a general-audience application with a minimum age of 13. It is not submitted to or operated under Apple's Kids Category: it uses accounts, email and third-party (Google/Apple) sign-in, and personalised faith and wellness features, all of which fall outside the Kids Category. Users under 13 are not permitted.
- You must be at least 13 years old to create or hold a YELW account. We do not knowingly create accounts for, or collect personal data from, children under 13. We rely on self-declared date of birth together with proportionate age-assurance signals; where we identify an account belonging to someone under 13, we delete it. (This is our COPPA under-13 position for the United States and our global minimum-age floor.)
- Where a market's law sets a higher minimum age or age of digital consent, that higher floor applies in that market (see §9).
- Users under 18 are minors. Minor accounts are private by default, and a parent or guardian must confirm consent via email-based verification (proportionate to this low-risk processing) before certain elevated activities are unlocked (see §9). This guardian-consent step is a GDPR Article 8 / local digital-consent-age mechanism for minors aged 13–17; it is not a COPPA under-13 verifiable-parental-consent flow — under-13 users are blocked entirely.
- Every account holder self-declares a date of birth at sign-up, held by the Identity Service. YELW reads this trusted date of birth to seal the account's minor status server-side; a user cannot re-declare their age to YELW to escape those protections.
4. The Identity Service — the shared account
Your account identity (email, display name, date of birth, password, and any Google/Apple sign-in identifiers) is created and held by our shared Identity Service, not by YELW's own feature database. YELW receives from that service only a signed token identifying you by an account identifier and, when needed for the age-gate, your date of birth and the derived minor flag. YELW stores that date of birth on its own settings record only to enforce the minor protections without re-querying identity on every request.
We never receive or store your password in any form; the Identity Service stores it hashed (irreversibly transformed), never in plain text.
5. What data we collect, and where it comes from
5.1 Categories
| Category | Examples | Source |
|---|---|---|
| Account & identity | Email, display name, date of birth (age-gating), hashed password, optional Google/Apple sign-in identifiers | You, via the Identity Service |
| Onboarding profile | Your onboarding answers: faith stage, wellness/body goals, current emotional / mood state, interests, daily rhythm, and a companion name | You |
| Wellness & activity | Habits and habit logs, mood check-ins, gratitude entries, quiz and flashcard progress, audio-progress, creative works (Icon/Poem), daily missions, devotional and Scripture-reading progress | You, as you use the app |
| Gamification | Coins, XP, streaks, badges, and redemption records. Coins are earned, not bought — they cannot be purchased with real money. | Generated as you use the app |
| Special-category — religious | Your Christian faith engagement is pervasive across the app (faith stage, devotional use, Scripture interaction, doubt questions). This reveals religious belief. Processed on the basis of explicit consent (GDPR Art. 9(2)(a)); for a minor below the applicable digital-consent age, that consent is authorised by the parent/guardian. | You |
| Special-category — health | Mood / emotional-state data and mental-health signals (mood check-ins, counselor use, distress signals), treated as health data. We do not sync with external health apps (e.g. Apple Health / Google Fit) in this version. Processed on the basis of explicit consent (GDPR Art. 9(2)(a)); for a minor below the applicable digital-consent age, that consent is authorised by the parent/guardian. | You |
| Private, encrypted content | Your journal entries and your Safe-Doubt conversations | You |
| Guardian-consent data | For a minor account: the guardian's email address and the consent-record lifecycle (pending / confirmed, timestamps) | You (the minor) and your guardian |
| Technical / diagnostic | App and device diagnostics necessary to run and secure the service, logs, and network/connection diagnostics (not location) | Automatically, as you use the app |
5.2 What we do not do
- We do not use third-party advertising or cross-app tracking, and we serve no behavioural ads.
- We do not sell or rent personal data, and we do not "share" it for cross-context behavioural advertising.
- We do not send your content to any third-party AI provider (§6).
- We do not carry out behavioural profiling of children.
- We do not collect precise location.
6. AI features — your content stays in-house
YELW includes an AI companion, a faith-AI, and a supportive counselor feature, along with mood-matched encouragement, the Safe-Doubt guide, and devotional tailoring. All of this AI runs on YELW's own self-hosted inference infrastructure. No prompt, message, journal entry, or doubt question is ever sent to any third-party AI or LLM provider (such as OpenAI, Google, or Anthropic).
Two hard boundaries are enforced in code:
- Personalization uses only derived, minimised signals — for example a mood label ("anxious") or your faith stage — never the raw text of your private journal or Safe-Doubt conversations. Raw private-surface content never enters any recommendation, analytics, or model-training pipeline. Your private journal and Safe-Doubt text are never used to train AI.
- Safety is computed by us, not delegated to the model. Deterministic distress signposting runs on defined signals and is shown independently of the AI's output — so the support resource appears regardless of what the AI does, and is never withheld, throttled, or paywalled. However, YELW does not guarantee that every instance of distress will be detected.
AI output is faith-based encouragement and reflection. It is not professional, medical, or clinical advice (§8).
7. How and why we use your data — purposes and legal bases
For users in the EEA/UK we must state a legal basis for each purpose; for special-category data (religion, health) we must also state an Article 9 condition. The table below does that. For MENA jurisdictions, the corresponding PDPL basis (consent, or a statutory ground) is noted in §14.
| # | Purpose | Data used | GDPR / UK GDPR legal basis | GDPR Art. 9 condition (special-category) |
|---|---|---|---|---|
| 1 | Provide the core service (create your account, run the app, save your work) | Account, non-special-category onboarding, activity | Contract (Art. 6(1)(b)) | — (any special-category onboarding element — religious belief, mood/wellbeing treated as health — relies on explicit consent under purposes 2 and 4, not on contract) |
| 2 | Deliver faith content & personalization (devotional, companion, mood-matched content) | Faith stage, mood label, interests | Consent (Art. 6(1)(a)) | Explicit consent (Art. 9(2)(a)) for the religious/health inference; you choose to use these features |
| 3 | Private journaling & Safe-Doubt space | Encrypted journal / doubt content | Consent (Art. 6(1)(a)) | Explicit consent (Art. 9(2)(a)) — you actively create this content in an encrypted, owner-only space |
| 4 | Mood tracking & Soul counselor (health-adjacent) | Mood check-ins, emotional state | Consent (Art. 6(1)(a)) | Explicit consent (Art. 9(2)(a)) |
| 5 | Distress response & duty of care | Mood/doubt distress signals | Legitimate interests (Art. 6(1)(f)) — protecting users, especially minors; and legal obligation where escalation is mandated | Explicit consent (Art. 9(2)(a)) for the underlying feature and, in a crisis, vital interests (Art. 9(2)(c)) |
| 6 | Guardian consent (email-based verification) for minors | Guardian email, consent record | Legal obligation (Art. 6(1)(c)) / Consent (Art. 6(1)(a)) | Not applicable (consent metadata, not special-category content) |
| 7 | Security, abuse & capacity protection | Technical, diagnostic, rate-limit data | Legitimate interests (Art. 6(1)(f)) — securing the service | — |
| 8 | Comply with law (respond to lawful requests, keep required records) | As required | Legal obligation (Art. 6(1)(c)) | Art. 9(2)(f)/(g) as applicable |
Special-category data (religion; mood/wellbeing as health). Special-category data — data revealing religious belief, and mood/wellbeing data treated as health data — is processed on the basis of explicit consent (GDPR Art. 9(2)(a)), not under contract. For a minor below the applicable digital-consent age, that explicit consent is authorised by the parent/guardian through the guardian-consent step (§9.3).
Withdrawing consent. Where we rely on consent (purposes 2–4), you may withdraw it at any time — by turning off the relevant feature, deleting the content, or deleting your account (§13). Withdrawal does not affect processing already carried out.
No incompatible re-use. We do not use your data for a new, incompatible purpose without a fresh basis. In particular, private-surface content is purpose-locked to your own private use.
8. Safety, mental-health & crisis
- YELW is not a crisis service, not a medical or psychological service, and not a substitute for professional or clinical care. Its content — including AI-generated content — is for encouragement and reflection only.
- When we detect distress signals (for example in the Safe-Doubt space or a mood check-in), we show supportive resources and, where relevant, a region-appropriate crisis signpost, together with a clear "this is not professional care" message. These are never paywalled, throttled, or gamified.
- Handling of a distress event may involve retaining relevant context in an access-controlled safeguarding record and, where we are legally required or it is necessary to protect someone's life, escalating to the appropriate people or authorities (see purpose 5 above).
- In an emergency, contact your local emergency number or a crisis line immediately.
9. Children & minors
Because YELW's audience skews young and includes minors, we design as if minors are present, and we build high-privacy protections in by default and server-side.
9.1 Age thresholds by regime
| Regime | Position we apply |
|---|---|
| US — COPPA | No accounts under 13. We do not knowingly collect personal data from a child under 13. |
| EU/EEA — GDPR Art. 8 (GDPR-K) | Minimum age 13. Where a member state sets a higher digital-consent age (up to 16), for users below that age we obtain the consent of the holder of parental responsibility (via email-based verification) before consent-based processing. |
| UK — UK GDPR / DPA 2018 & the Age-Appropriate Design Code (Children's Code) | Minimum age 13; parental consent (via email-based verification) for consent-based processing below the UK digital-consent age; the Children's Code standards applied by default (see §9.4). |
| Jordan — PDPL | Processing of a minor's data on the basis of guardian consent, in line with Jordanian law. |
| Saudi Arabia — PDPL | Processing of a minor's data on the basis of guardian consent, in line with Saudi law. |
| UAE — PDPL | Processing of a minor's data on the basis of guardian consent, in line with UAE law. |
Across every market, an account for a user below the applicable minimum age will not be activated, and any account we determine to belong to an under-13 user is removed.
9.2 Minor protections we enforce (built in, server-side)
For any account the trusted date of birth shows to be a minor (under 18) — and, on a fail-safe basis, for any account whose age we cannot verify — YELW applies the locked-down posture automatically:
- Private by default. A minor's account is private by default; a minor cannot weaken these privacy defaults (and this version has no public surface in any case). This clamp is enforced on every settings write, not just at sign-up, and cannot be bypassed from the client.
- Private-surface device lock on. The journal and Safe-Doubt surfaces are protected behind a device lock that a minor cannot turn off.
- Elevated activities are gated on guardian consent (email-based verification) (below); until a guardian confirms, those activities remain locked — the gate fails closed.
- No behavioural advertising, and no engagement profiling — for any user, and never for minors — and no "you'll lose your streak" loss-aversion pressure.
9.3 Guardian consent (email-based verification)
At sign-up, a minor provides a guardian's email. YELW emails the guardian a one-time, expiring confirmation link (valid for 72 hours, single-use). Until the guardian clicks it and confirms, the minor's elevated activities remain blocked server-side. This email-based verification is proportionate to the low-risk processing involved.
This guardian-consent step is a GDPR Article 8 / local digital-consent-age mechanism for minors aged 13–17. It is not a COPPA under-13 verifiable-parental-consent flow: under-13 users are blocked entirely and no under-13 account is created.
The guardian's window is strictly limited. A guardian may confirm consent and exercise the minor's data rights (access, correction, export, deletion). A guardian never gains access to the minor's private journal or Safe-Doubt content — those remain the young person's own and are encrypted to them alone. Where guardian oversight is active on an account, we make that fact visible to the young person.
9.4 The UK Children's Code
Where the UK Age-Appropriate Design Code applies, YELW follows its standards: high privacy by default, data minimisation, no detrimental use of children's data, no nudge techniques that push a child to weaken privacy or over-use, transparency a child can understand, and a Data Protection Impact Assessment covering the faith + health + minors processing.
10. Retention
We keep personal data only as long as needed for the purpose it was collected for, then delete or irreversibly anonymise it.
- Personal data is kept while your account is active. This includes your account, onboarding, activity, gamification, and — encrypted — your journal and Safe-Doubt content.
- On account deletion, erasure is immediate and permanent. YELW performs a real, irreversible purge of every YELW record we hold for you, the journal and Safe-Doubt threads included. A short operational window of up to 30 days allows encrypted backups to cycle out.
- Inactive accounts are reviewed after 24 months and may then be closed and permanently purged.
- Guardian-consent records are kept for the life of the minor account as proof of consent.
- Distress / safeguarding records are access-controlled and kept only as long as necessary for the safeguarding purpose or as the law requires.
- Only minimal legal-hold / audit records are retained after deletion where the law requires, and no longer than the law requires.
11. Recipients, sub-processors & data location
We disclose personal data only to:
- Our own infrastructure and processors acting on our instructions under data-processing agreements — application and database hosting, object storage and content delivery, and transactional email delivery (including the guardian-consent email).
- Our Identity Service, for account authentication.
- Authorities or others where required by law or where necessary to protect a person's life or safety.
We do not disclose personal data to advertising networks or data brokers, and we do not send content to any third-party AI/LLM provider.
| Sub-processor (category) | Purpose | Location |
|---|---|---|
| DigitalOcean | Application + database hosting | EU — Frankfurt, Germany |
| Cloudflare | Object storage + content delivery (CDN) | Global CDN; origin data in the EU |
| Third-party email delivery provider | Transactional + guardian-consent email | Under a data-processing agreement |
Data location & international transfers. Personal data is primarily hosted in the EU (Germany). YELW is MENA-focused and offered globally through the App Store and Google Play. Where personal data is transferred across borders (for example to a processor outside the EEA/UK or a MENA jurisdiction), we rely on an appropriate transfer mechanism — such as the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, an adequacy decision, or the applicable PDPL transfer basis — and apply supplementary safeguards where needed.
12. Security
- Encryption in transit: TLS for all data in transit.
- Encryption at rest: the entire data store is encrypted at rest. In addition, your journal and Safe-Doubt content receive per-user encryption and are decrypted only when returned to the account that owns them. There is no server path that returns one user's private content to another user, to a guardian, or to a youth leader; an unreadable or key-rotated blob degrades gracefully rather than exposing content.
- Access control: access to systems and data is least-privilege and logged.
- Abuse & capacity protection: rate limits and per-account ceilings guard the service.
- No third-party AI exposure: as above, content is never transmitted to an external AI provider.
No system is perfectly secure; we cannot guarantee absolute security, but we work to protect your data proportionately to its sensitivity. To report a security concern, contact security@yelw.ai.
13. Your rights & how to exercise them
Subject to your region's law, you may have the right to: access your data, correct it, delete it, export/port it, restrict or object to processing, withdraw consent, and not be subject to solely automated decisions with legal or similarly significant effect. YELW does not make such solely-automated decisions about you; personalization is a convenience feature you can turn off.
Two of these are self-service, in-app, right now:
- Export your data. In the app you can download a complete export of your YELW data — including your own decrypted journal and Safe-Doubt entries — packaged for you and delivered only to you (authenticated to your account; there is no path for anyone else to obtain it). Export runs immediately.
- Delete your account. In the app you can permanently delete your YELW data. This runs a real, irreversible purge of every YELW record we hold for you, the journal and Safe-Doubt threads included, and runs immediately.
To exercise any other right, contact privacy@yelw.ai. We will respond within the period your law requires (for GDPR/UK GDPR, within one month, extendable for complex requests). For a minor, a verified guardian may exercise these rights on the minor's behalf — except access to the minor's private journal / Safe-Doubt content, which stays private to the young person.
We do not charge for exercising your rights except where a request is manifestly unfounded or excessive, as your law allows. If we cannot verify your identity we may ask for more information before acting.
Complaints. EEA/UK users may lodge a complaint with their supervisory authority (UK: the Information Commissioner's Office; EU: your national data protection authority). Users in Jordan, Saudi Arabia, and the UAE may complain to the competent data-protection authority in their country. We would appreciate the chance to resolve your concern first — please contact privacy@yelw.ai.
14. Regional provisions
- United States (COPPA). YELW does not knowingly collect personal data from children under 13, and does not permit accounts for under-13 users. We collect only what a feature needs, do not condition participation on unnecessary data, and serve no behavioural ads to children. Contact privacy@yelw.ai.
- EEA (GDPR). Legal bases are in §7; special-category data (religion, health) is processed under explicit consent or, in a crisis, a vital-interests condition. YELW will appoint an EU/EEA representative as required under GDPR Art. 27; until that representative is individually named in this Privacy Policy, they can be reached via privacy@yelw.ai.
- United Kingdom (UK GDPR + Children's Code). As for the EEA, plus the Children's Code standards in §9.4. YELW will appoint a UK representative as required under UK GDPR Art. 27; until that representative is individually named in this Privacy Policy, they can be reached via privacy@yelw.ai.
- Jordan (PDPL). We process personal data on the basis of your consent or another lawful basis under Jordan's Personal Data Protection Law, honour PDPL data-subject rights, and observe PDPL requirements on sensitive data (which includes data revealing religious belief and health data) and on cross-border transfer.
- Saudi Arabia (PDPL). We process personal data on the basis of your consent or another lawful basis under the PDPL, honour PDPL data-subject rights, and observe PDPL requirements on sensitive data (including data revealing religious belief and health) and on cross-border transfer.
- UAE (PDPL — Federal Decree-Law No. 45 of 2021). We process on a lawful basis, honour UAE PDPL rights, and observe its rules on sensitive personal data and cross-border transfer.
15. Changes to this policy
We may update this policy. For material changes we will give prominent notice in-app and, where required, seek fresh consent (especially for children's data). The "last updated" date at the top shows the current version; we keep prior versions available on request.
16. Language & Arabic version
YELW is offered in English and Arabic. An Arabic-language translation of this policy and of the at-a-glance summary is provided at yelw.ai/privacy-ar and in-app. If there is any conflict between versions, the English version governs for legal interpretation, except where a market's law requires the local-language version to prevail (in which case that version governs in that market).
17. Governing law & contact
Governing law and forum. This policy and any dispute relating to it are governed by the laws of the Hashemite Kingdom of Jordan, and the competent courts of Amman, Jordan have jurisdiction, without prejudice to any mandatory data-protection rights or local remedies available to you under the law of your country of residence.
Contact.
- Privacy contact / DPO: privacy@yelw.ai
- Legal / terms: legal@yelw.ai
- Security: security@yelw.ai
- General support: support@yelw.ai
- Data controller: YELW, Amman, Jordan
- EU/EEA and UK representatives (GDPR / UK GDPR Art. 27): to be appointed as required; until individually named in this policy, reachable via privacy@yelw.ai
- Website: https://yelw.ai