yeses.io

Privacy

Last updated 9 September 2026

yeses holds two kinds of personal data, and one of them belongs to people who never signed up. This page is mostly about them.

Who runs yeses

yeses is operated by an independent business trading as yeses.io. For anything on this page, a question, a correction, or a request to delete something, write to support@yeses.io. A person reads it.

The short version

  • We store what you upload for review, and the email addresses of the people you ask to review it.
  • We do not sell anything to anyone, and we run no ad tracking.
  • Five companies process data on our behalf. They are named below, with what each one holds.
  • You can delete your account yourself. Removing your projects and files currently requires an email; see Deleting things.

Account holders

If you sign up, we hold your name, your email address, and which organization you belong to. Authentication is handled by Clerk, so your password — if you use one — is theirs, never ours.

We also store what you create in the product: projects, uploaded files, approval flows, comments, and the record of every decision made on a review.

Reviewers who never signed up

This is the part worth reading carefully. When a customer asks someone to approve something, that person gets a link and approves it from there. They create no account and agree to no terms, because the whole point of the product is that they do not have to.

What we hold about a reviewer is only what the customer gave us:

  • Their email address, which is what their approval link identifies them by
  • Their name, if the customer provided one
  • Their decision — approved, or changes requested — and when they made it
  • Any comments they left on a file

If you are a reviewer and you want your address removed, write to support@yeses.io, and we will do it. You do not need an account to ask, and you do not need to go through the person who invited you.

What you can upload

Images up to 25 MB and PDFs up to 50 MB. They are stored by Convex and are reachable only through the product or through a reviewer's link.

Who else processes it

  • Clerk — accounts, sign-in, organization membership
  • Convex — the database and the uploaded files
  • Resend — sending review requests and reminders
  • PostHog — product and website analytics
  • Slack — notifications, and only for an organization that has connected it
  • Figma — reading files, and only for a person who has connected their own account
  • Cloudflare — hosting, DNS, and email forwarding

That is the entire list. These providers are based in the United States, so using yeses means data is transferred there.

If your team connects Slack

Slack is off until an organization admin turns it on, and none of this applies until they do. Connecting it is what puts Slack in the list above.

What is stored while a workspace is connected:

  • An access token for that workspace, which is what lets yeses post. It is never shown in the product and never sent to a browser.
  • The workspace and the channel, by name and by Slack's own identifier, so the settings page can tell you which one was picked
  • Who connected it, and when

Reviewer email addresses are sent to Slack. To work out whether a reviewer should be messaged on Slack or emailed, yeses asks Slack whether that address belongs to somebody in the workspace. It asks about one person at a time, at the moment it is about to contact them, and never uploads a list. The answer, a Slack user id or nothing, is kept so the same question is not asked twice.

This is the part that touches the reviewers described above, who never signed up for anything. Nothing else in the product sends their address to a third party for matching. If you would rather it did not happen, do not connect Slack.

Disconnecting clears those stored answers. It deletes the connection, tells Slack to revoke the token, and drops the record that an address did or did not match somebody in the workspace. There is no window where the connection is gone and the answers it produced are not. If there are too many to clear in one pass, the rest follow within moments, without anybody having to ask. The same happens on its own when Slack tells us the access has been revoked from your side.

yeses never reads your Slack messages, and asks for no permission that would let it.

If you connect Figma

Figma is off until you connect your own account, and none of this applies until you do. Unlike Slack, connecting Figma is something each person does for themselves — there is no organization-wide connection.

What is stored while your account is connected:

  • An access token and a refresh token for your Figma account, which is what lets yeses read files on your behalf. Neither is shown in the product or sent to a browser.
  • Your Figma email or handle, whichever Figma gives us, so the settings page can show you which account is connected
  • Who connected it, and when

The connection is read-only. yeses reads only the frames you choose to import, never a whole file automatically, and never writes anything into Figma.

Nothing about this touches the reviewers described above. Figma only ever sees the account you connected it with, and no reviewer's address is ever sent there.

Disconnecting removes yeses's copy of the token. Figma does not give us a way to revoke it on their end, so if you also want to withdraw access from Figma's side, remove yeses.io under Settings › Security in your Figma account yourself.

Cookies and analytics

PostHog sets one cookie, shared across yeses.io and app.yeses.io, so that a visit to the website and a later sign-in count as one person rather than two. It tells us which pages get read and which buttons get clicked. There is no advertising network involved, and nothing is sold on.

It is your choice. The banner on your first visit asks, declining is one click, and declining clears the cookie rather than merely muting it. You can change your mind at any time through Cookies in the footer of this site, or Cookie preferences in the app's settings.

One other cookie exists, and only to remember the answer you gave above so you are not asked on every page. Your light or dark theme is kept in the browser's own storage rather than a cookie, and never leaves your device.

Email

Review requests go out from notifications@yeses.io. Reviewers are reminded every two business days, up to three times, and then we stop. That limit is in the product itself, not a policy we promise to observe.

How long things are kept

Deleting a project or a file moves it to a trash, where it stays restorable for 30 days. After that, a scheduled job purges it permanently, and the stored file is deleted along with the record of it. Emptying the trash by hand does the same thing immediately.

Deleting things

You can delete your account yourself, at any time, from your account page in the product. That removes your sign-in and your profile.

It does not currently remove the projects, files, and reviews you created — those live in a separate system that account deletion does not yet reach. To have that removed as well, email support@yeses.io, and we will do it by hand. We would rather tell you that than let you assume otherwise.

Your rights

You can ask for a copy of what we hold about you, ask us to correct it, ask us to delete it, or object to how we use it. Write to support@yeses.io, and we will respond within 30 days. If you are not satisfied, you can complain to your local data protection authority.

Changes

If this page changes in a way that matters, the date at the top changes with it. yeses is early, and this page will get more specific as the product does.