Yodler Privacy Policy (summary)
READABILITY OF YOUR MESSAGES: THE MOST IMPORTANT THING TO KNOW
Yodler supports two conversation modes:
• Standard mode (the default for every account): your message content is sent over
TLS and processed and stored on our servers (encrypted at rest under keys we
manage). This means the operator/admin CAN read Standard-mode content, for
support, debugging, and moderation. Every such access by an admin is audit-logged.
• End-to-end encrypted (E2EE) mode (a premium capability granted per user by an
admin): message content is encrypted on your device and can only be read on the
recipient's device. The operator holds ciphertext and metadata only and CANNOT
read this content.
The active mode is always shown in each conversation so you are never misled about
who can read it.
WHAT WE COLLECT AND HOW LONG WE KEEP IT
• Account data: username and email (no phone numbers).
• Device and message METADATA (timestamps, participants, delivery/read receipts).
• Standard-mode message content (operator-readable, as described above).
• Encrypted backups (opaque to us).
• Visitor analytics: IP address, geolocated country, browser/user agent, page path,
and session journey.
Messages are retained per the operator-configured retention window (default:
indefinite unless changed by the operator).
YOUR RIGHTS
You can access your data and erase your account (self-service account deletion),
which removes your accounts/devices/keys and drops undelivered messages addressed
to you.
Calls: 1:1 voice/video media is always end-to-end encrypted (DTLS-SRTP) and is
never readable by the operator in either mode.