yaxbe

Privacy Policy

Last updated: 27 August 2026

This explains what personal data Yaxbe handles, why, and what you can do about it. It covers two different groups of people, and the difference matters, so it is stated first.

Two groups of people, two different roles

If you have a Yaxbe account, we are the controller of your account data. We decide what to collect and why, and this policy explains it.

If you received a document built with Yaxbe, you probably have no relationship with us at all. The firm that sent it decides what data goes in and what happens to it. They are the controller. We are their processor, acting on their instructions. If you want your data changed or removed, ask them first. If you cannot reach them, contact us at privacy@yaxbe.com and we will help.

What we collect

From people with an account

  • Account data. Name, work email, organization name, role, and authentication identifiers. Authentication is handled by WorkOS; we do not store passwords.
  • Usage data. Which pages you visit in the product, actions you take, and technical data such as IP address, browser, and device type, used to operate and secure the service.
  • Support correspondence. What you send us when you ask for help, and anything you send to our published addresses.

From content you put into Yaxbe

  • Your business content. Scope, deliverables, rates, templates, and clause libraries.
  • Your clients’ contact details. Names, email addresses, job titles, and organization names of the people you send documents to.
  • Material used to build a scope. Call transcripts and recordings, email threads, documents, spreadsheets, and images you provide us to build a structured scope. There is no upload feature in the product today — this material does not go into Yaxbe’s own systems. Instead, you send it directly to the Yaxbe team member who builds your scope (see “AI processing” below). This may contain personal data about people neither of us has a direct relationship with.

You control all of it. We process it to provide the service.

From people who receive a document

This is the part most easily overlooked, so it is stated plainly.

When a firm sends a statement of work through Yaxbe, we record:

  • the recipient’s name and email address, supplied by the firm
  • when the document was opened, and by whom, and we show that to the firm
  • which options the recipient selected, and when they changed the selection
  • comments the recipient writes
  • on acceptance: the recipient’s name, title, the exact version accepted, a timestamp, IP address, and browser identifier, retained as evidence of what was agreed and by whom

The reading and selection activity is shown to the sending firm. If you have received a document, the firm that sent it can see that you opened it and when.

We collect this because a statement of work is a commercial document and both parties need a reliable record of who agreed to what. The IP address and browser identifier exist specifically so an acceptance can be evidenced later.

AI processing

Turning discovery material into a structured proposal is done by a person, not an automated pipeline. That person works outside Yaxbe’s own systems — the material never enters our infrastructure, and no system Yaxbe operates sends your material to a model provider.

Send this person only material you are comfortable sharing with an individual outside your own systems, to the same standard you would apply before emailing it to someone directly.

Why we process it

  • To provide the service you asked for. Performance of our contract with you.
  • To keep it secure and working, including fraud prevention and abuse detection. Our legitimate interest.
  • To bill you. Performance of contract, and legal obligation for tax records.
  • To communicate about the service. Legitimate interest for service messages; consent for anything promotional, which you can withdraw at any time.
  • To keep a record of what was agreed. Legitimate interest of both the sending firm and the recipient, and the substance of the service itself.

Who we share it with

We do not sell personal data and we do not show advertising.

Our sub-processors:

ProviderWhat they handleWhere
VercelApplication hostingUnited States (San Francisco)
SupabaseDatabase hostingUnited States (US West)
WorkOSAuthenticationUnited States
ResendTransactional emailUnited States (N. Virginia)
AnthropicProcesses discovery material an operator submits from their own account — not sent by Yaxbe’s own systems. See “AI processing” above.See “AI processing” above
Google WorkspaceEmail and correspondence with us, including discovery material a firm sends to build a scopeUnited States

We do not currently process payments through a billing processor. This section will name one, and describe what it handles, when billing goes live.

We will keep this list current. Customers with a Data Processing Agreement receive notice before we add a sub-processor.

We may also disclose data if the law requires it, or to protect the rights and safety of people using the service. If we are compelled to disclose customer data we will tell the customer unless we are prohibited from doing so.

How long we keep it

  • Account and content data: for as long as the account is open, then at least 30 days after closure so you can export it, then deleted.
  • Acceptance records: retained for seven years, because they evidence an agreement. Deleting them on request would defeat their purpose, and both parties also received a copy by email at the time.
  • Billing records: as long as tax and accounting law requires.
  • Enquiries that do not become accounts: two years, then deleted.
  • Logs: 30 days.

Your rights

Depending on where you live, you may have the right to access, correct, delete, or export your personal data, to object to or restrict processing, and to complain to a regulator.

If we are the controller, contact us at privacy@yaxbe.com and we will respond within 30 days.

If we are a processor, meaning your data reached us because a firm sent you a document, contact that firm. We will help them respond, and we will help you reach them if you cannot.

We do not discriminate against anyone for exercising these rights.

Security

Data is encrypted in transit and at rest. Each customer’s data is isolated at the database level, not only in application code. The application connects with credentials that hold no direct table privileges of their own. Access to production systems is limited to those who need it.

No system is perfectly secure. If a breach affects your personal data we will notify you and any regulator as the law requires, without undue delay.

Report a security issue to security@yaxbe.com.

International transfers

Our infrastructure is in the United States. If you are outside the United States, using Yaxbe means your data is transferred there.

For transfers from the European Economic Area, the United Kingdom, and Switzerland we rely on the Standard Contractual Clauses, incorporated into our Data Processing Agreement, together with the UK Addendum where applicable.

Children

Yaxbe is a business product and is not directed at anyone under 18. We do not knowingly collect data from children.

Changes

We will post changes here and update the date above. If a change materially affects you and we have your email, we will tell you before it takes effect.

Contact

privacy@yaxbe.com

Yaxbe LLC
7533 S Center View Ct Ste N, West Jordan, Utah 84084