Product Privacy Policy
In-product data handling, AI model data practices
# DOCUMENT 04: Product Privacy Policy
1. Purpose
This Product Privacy Policy describes how Yugality processes personal data and user-generated content specifically within the Product environment — i.e., once you are logged in and actively using the AI tools. This document supplements the main Privacy Policy (Document 01).
2. Data Processed Within the Product
2.1 Uploaded Documents
Legal documents, contracts, court filings, regulatory submissions, or any other files you upload are processed by Yugality's AI engine to generate the requested outputs. These documents may contain personal data of third parties (e.g., your clients). You, as the controller of such third-party data, are responsible for ensuring a lawful basis exists for sharing such data with Yugality.
2.2 Query and Prompt Data
Queries, instructions, and prompts submitted to the AI are logged to: (a) generate your requested output; (b) maintain your session history within the platform; and (c) detect abuse or misuse of the platform. Queries are not used to train AI models.
2.3 AI Output Data
AI-generated outputs are stored in your account workspace for your access during the active subscription period.
3. AI Model Sub-Processors
Yugality uses third-party AI model APIs to power its legal intelligence features. These sub-processors process queries and document excerpts solely to generate outputs; they do not store or train on user data under our contractual terms with them. The identities of current sub-processors are disclosed in our DPA (Document 05) and upon request.
4. No Training on User Data — Absolute Commitment
YUGALITY ABSOLUTELY AND UNCONDITIONALLY CONFIRMS THAT NO USER-UPLOADED DOCUMENTS, QUERIES, PROMPTS, OR AI OUTPUTS ARE USED TO TRAIN, FINE-TUNE, EVALUATE, OR OTHERWISE IMPROVE ANY AI MODEL — WHETHER OPERATED BY YUGALITY OR ITS SUB-PROCESSORS. This commitment applies retroactively to all data processed since the platform's inception.
5. Data Isolation
Each subscriber's data is logically isolated from other subscribers' data through role-based access controls, tenant-level data partitioning, and query-level access restrictions. No subscriber can access another subscriber's data.
6. Retention Within the Product
- Active session data: Retained for 30 days after session end unless deleted by user.
- Workspace files and AI outputs: Retained for the subscription term plus 30 days post-termination.
- Anonymised usage analytics: Retained for 24 months.
7. User Controls
- Delete individual documents or AI outputs from your workspace at any time.
- Clear your query history through account settings.
- Request full data export in machine-readable format by contacting privacy@yugality.com.
- Request account deletion, which triggers permanent data erasure within 30 days.
