YULA Lab
Privacy

We respect your data.

Notice version: 2026-09-06

Data handling varies by product and version. Open the relevant privacy information below, or contact us with questions about access, correction or deletion.

This site's own measurement

This section covers both yulalab.com and links.yulalab.com. On yulalab.com, Vercel Analytics loads only in the Vercel hosting configuration; it does not load in other hosting environments. When enabled, it counts page views in aggregate, sets no cookies, and does not track visitors across sites. It does not run on links.yulalab.com.

On top of that we have written our own funnel record, measuring how many people a product page sends on to that product's own store or site; both sites use the same record. Funnel recording depends on configuration. In the enabled flow, the recorded fields are: event name (from a fixed list), event version number, product short name, language, page path without any query string, campaign tags if present (utm_source/medium/campaign/content), the address of the outbound link clicked (with its query string and fragment removed), that link's class (store / web / internal), and a timestamp. Each record also carries a session pseudonym, a random record identifier and the retention expiry date. Nothing outside that list is stored.

This record does not store IP addresses or browser fingerprints and does not request fields for names, email addresses, messages or in-product data. Field names and accepted formats are constrained in the application and database. Campaign tags and page paths must not contain personal information. The only value identifying a visitor is a pseudonym derived from a random token that is erased when your tab closes, re-derived daily; it is not reversible and does not link two different days together. Raw records have a 30-day retention period; expired records are removed when the authorized cleanup job runs.

When you write to us

There is no contact form on the site today: the contact page shows our email address directly, so writing to us means an ordinary email that never enters a database here. The section below describes what will happen when a form does open — written before it opens, because describing it afterwards would be too late. Go to the contact page.

When a form does open, the complete list of what is stored is: your name, your email address, your company if you choose to give one, what you are writing about (product, working together, partnership, press, or a data request), which product if it is about one, your message itself, the page language, the status of the request on our side, the date the record was created, the retention expiry date, a random record identifier, and a matching value that stops sending the same message twice from creating two records.

Your consent is kept as its own record: which dated version of the notice you accepted, when you accepted it, and the lawful basis. We store it this way rather than as a 'consented' checkbox because a checkbox cannot answer what you consented TO — editing this page later would retroactively re-describe what you actually agreed to.

A separate delivery queue is used to send you a receipt and route your message to the right person. That queue does NOT carry the text of your message — it carries the record number, language, what the enquiry is about, and where it should go. The retention period is 30 days for queue records and 180 days for contact records; the relevant date is stored on each record. Delivered notifications may have their retention date extended to allow at least 24 hours after delivery. Expired records are removed when the authorized cleanup job runs.

Shared Framework

Data categories, third parties, retention periods and the scope of rights requests are addressed in the relevant product privacy information. The Motion page provides general scope information for products in development; contact us for app- and version-specific details.