Home/Docs/Security & Privacy
🔒 Privacy by design

Security & Privacy

YOffice is built privacy-first. Optional data uses are off by default, you can export or delete your data at any time, EU data residency is the default, and you stay in control of how your information is used to train AI — which it isn't, unless you opt in.

🇪🇺

EU data residency

Data is hosted in the EU by default, with full GDPR data-subject rights.

🙅

Off by default

Analytics, crash reporting, marketing, and AI-training consents all start switched off.

📦

Your data, exportable

Download your data on request, and delete your account with a 30-day grace period.

📜

Audited & versioned

Consents are versioned and changes are recorded in an activity audit log.

Signing in

YOffice supports two sign-in methods. Choose whichever fits your team — both are available everywhere.

MethodNotes
Email + passwordCreate an account with an email and password. Sign-up includes a consent gate before your account is active.
GoogleOne-tap sign-in with your Google account, scoped to your email and basic profile.

After signing in you pick an organization; YOffice then issues a per-organization token that authorises your requests to that tenant. See Organizations for the multi-org model.

Consent & the sign-up gate

When you sign up, YOffice asks for consent before activating your account. Required agreements must be accepted; optional data uses are off unless you turn them on.

ConsentDefaultWhat it covers
Terms of ServiceRequiredAccepting the terms of use.
Privacy PolicyRequiredHow your data is handled.
Data ProcessingRequiredProcessing of personal data per the DPA.
AnalyticsOff by defaultProduct-usage analytics.
Crash reportingOff by defaultCrash diagnostics to improve stability.
MarketingOff by defaultProduct and marketing communications.
AI trainingOff by defaultWhether your data may be used to improve AI models.
You can change your mind

Adjust any optional consent at any time in Settings → Privacy & data. Consents are versioned — if a policy changes materially you'll be asked to re-consent — and cookie consent can be revisited too.

Privacy & data
Product analytics
Crash reporting
Marketing emails
Use my data to train AI
⬇ Download my dataDelete account
Privacy & data — optional consents off by default, with Download my data and account deletion

Download my data (DSAR)

Exercise your right of access with a data-subject access request. In Settings → Privacy & data, choose Download my data and YOffice prepares an export of your personal data for you to download.

AI-training opt-out

Your data is not used to train AI models unless you explicitly opt in — the AI-training consent is off by default. You can review and revoke it any time from Privacy & data. Note that when you use a self-hosted model, inference stays entirely on your own infrastructure (see below).

Deleting your account

Account deletion is deliberate and reversible during a grace window:

30-day
Grace period before permanent deletion — so you can change your mind
  1. Open Privacy & data

    Go to Settings → Privacy & data and choose Delete account.

  2. Confirm by typing

    You type a confirmation to acknowledge the action — there's no accidental single-click deletion.

  3. Re-authenticate

    Re-enter your password to prove it's really you.

  4. 30-day grace period

    Your account enters a 30-day grace period before permanent deletion, so you can change your mind.

Data residency

Organization data is hosted in the EU by default. This supports GDPR compliance and a Data Processing Agreement. Talk to us about requirements for other regions or a dedicated deployment.

Encryption

Your data is encrypted in transit over TLS 1.2+ — including API calls, real-time LiveKit media (DTLS-SRTP transport encryption), and file transfers — and hosted on EU infrastructure (Germany). Stored secrets such as integration credentials and LLM/API keys get an extra layer of application-level encryption (AES-256-GCM), and once you save them they're never shown in plaintext again — so they stay safe.

Self-hosting & local AI

For strict data-sovereignty needs, YOffice is a managed cloud service, but the parts that touch your content most directly can run on your own infrastructure: point AI inference at a locally-running Ollama instance, and run LiveKit media on your own servers. With a self-hosted model, prompts, messages, and documents never leave your network — even when using AI.

📱
YOffice app
Web / Mobile / Desktop
🖥️
Auth + Tenant servers
Your infrastructure
🗄️
PostgreSQL
Your database
🤖
Ollama (local LLM)
AI runs on your hardware
Traffic stays within your private network
Self-hosted stack — all components run inside your network when paired with a local model

Your GDPR rights

RightHow to exercise it
Access & portabilitySettings → Privacy & data → Download my data.
RectificationUpdate your profile details in Account settings.
ErasureSettings → Privacy & data → Delete account (30-day grace).
Withdraw consentToggle any optional consent off at any time.

Activity audit log

Workflow and AI-agent activity — plus a running cost summary — is recorded in an Activity log under Settings → Organizations, so admins can review usage over time.

Legal & policies

YOffice publishes its full legal documents, linked from within the app: Privacy Policy, Terms of Service, Data Processing Agreement, Cookie Policy, and the list of Sub-processors.

ℹ️
Responsible disclosure — we welcome it

Security is a partnership. If you spot a potential issue, we'd love to hear from you at security@yoffice.ai ahead of public disclosure. We welcome good-faith researchers and never pursue legal action against them.