Privacy
Last updated: 24 August 2026
This page is written by Niclas Eriksson, trading as YogoLogo, who is responsible for everything described on it. You can write to hello@yogologolife.com about any of it, and every “write to us” below means that address.
The app's standing sentence is “Nothing leaves this device unless you ask.” Creating an account is the asking. This page says what happens after you ask, and what happens if you never do.
The short version
Use the app without an account and we hold nothing of yours. Make one, and we hold your email and one copy of your record, kept on our server as a readable file that we are able to read, until you delete it.
If you never make an account
We hold nothing about you. No account, no copy, no analytics, no counting, no cookie from us, and no third party running in the page. Everything you build lives in your own browser, on your own device.
The app is served by Cloudflare, and any host sees the ordinary request data serving a page involves: your IP address, your browser and the time. That is not a profile and we do not build one.
If you make an account
An account exists so that one copy of your record, the tree you are growing, how you have been showing up, your values, your goals and your purpose, is kept for you. Here is everything the account side holds:
- Your email address, with when the account was made and last used. Kept until you delete the account.
- When you ask for a sign-in link: a note of the address it went to and a fingerprint of the link's code, kept for twenty minutes. We keep the fingerprint, not the code, so a copy of our database could not be used to sign in as you.
- While you are signed in: a fingerprint of your session's code, for up to a year.
- One copy of your record, the copy we keep: what your record on this device held the last time keeping ran. One copy per account, replaced each time keeping runs; we keep no history and no older versions of it. Our host's own backups are a separate matter, described under deleting, below.
- Brief counters on the sign-in door, against the email address and the network address a request came from, kept for about an hour, so nobody can flood it.
There is no log of what you do in the app: no page views, no feature counts, no record of which parts of it you open.
Signing in sets the app's one and only cookie. It is how your browser stays signed in, and it lasts up to a year. The law asks for a cookie banner only when cookies are not strictly necessary for the service you asked for; this one is, so there is no banner. There is no analytics cookie and no third-party cookie.
Accounts are for people aged 13 and over, which is the age UK law lets someone agree to a service like this for themselves. Under that age, practise without one; nothing of yours is held then, so there is nothing to agree to.
The copy, and who can read it
Here is the sentence this page stands on: the kept copy is a readable file, and we are able to read it.
Nobody does. Reading a person's record is no part of running the app, nothing we use ever shows us one, and we have no reason to look. But being unable and not doing are different things, and you should know which one is true here: this is a statement about our conduct, not about impossibility. We open the copy we keep only when you ask us to.
Cloudflare, where the copy sits, encrypts everything it stores as a matter of course. That is a real safeguard against someone making off with the disks it lives on. It does not stop us, so we will not offer it to you as a promise.
If that trade is not one you want, practising here stays open without an account. What an account adds is keeping what you make: saving your own breaths and sequences, and one copy of your record on our server.
Who else touches it
Two companies help run this, and they are the whole list. Nothing is sold, shared, rented or given to anyone else, and there is no marketing platform in the loop.
- Cloudflare hosts the app and the database the copy sits in, and encrypts what it stores.
- Resend sends exactly one kind of email, the sign-in link, so it sees the address a link goes to. It is sent from hello@yogologolife.com.
Both are American, so your copy does not stay in the UK. It sits in Cloudflare's database and may be held outside the country. Cloudflare is certified under the UK extension of the EU-US Data Privacy Framework, the arrangement the UK recognises for sending personal data to American companies, and commits to the standard contract clauses the law provides as a fallback. Resend is never given your record, only the address a sign-in link goes to.
The two permissions
When you ask for a sign-in link, two tick boxes sit under the email box. Both start off, they are separate, and an account never signs you up to anything by itself.
- Anonymous counting. Permission to include you in anonymous totals of which parts of the app get used, never what you write. Nothing is counted yet; the tick records your permission ahead of it.
- Letters. Permission to write to your address about the app. No letters are being sent today; the tick records that they would be welcome.
You can take either back at any time. There is no switch for it in the app yet, so write to the address at the top and we will change it. When there is a switch it will sit in your account panel, and this page will say so.
Deleting, your rights, and the legal part
Delete my account removes, in one action: the kept copy, every signed-in session, and the account itself. Nothing is held back, and we keep no history of our own for anything to survive in. Everything on your own device stays exactly where it is.
One limit on that, which we did not choose and cannot switch off. Our database provider, Cloudflare, keeps its own rolling backups of the whole database, so that it could be recovered after an accident. Deleted rows sit inside those backups until they age out, which takes up to thirty days, and we cannot reach into them or shorten that window. So deletion is immediate and final in the live database, and complete everywhere within a month.
Sign out keeps the account but stops the keeping from that moment; nothing more is sent until you sign in again. The copy already kept stays as it is.
Your record is always yours to take. “Bring back the copy we keep” fetches it from our server into the app, and it sits in your account panel. If you want the copy we keep as a file to keep yourself, write to us and we will send you one.
You also have the legal rights that come with all of this: to see what we hold, correct it, take it away, limit what we do with it, and object. In this app most of them are buttons rather than requests; for anything that is not, write to the contact line above. If you are unhappy with how we have handled any of it, you can complain to the Information Commissioner's Office, the UK's data protection regulator.
UK data protection law asks us to name a lawful basis for each thing we hold:
- Your email and your session: contract. You asked for an account, and it cannot work without them.
- The kept copy: contract. Keeping it is the whole service the account provides.
- The two permissions: consent, freely given, off by default, and yours to withdraw.
- The rate counters, and the ordinary request records our host keeps: legitimate interests, keeping the door working and not abused.