Privacy
Magneum Industries LLC operates YipYap (Language) and its companion integrations.
What we collect
- An opaque account identifier; sign-in via Apple or Google. Your email is contact metadata only and never merges or binds accounts.
- The vocabulary items you create or import, your instruction language, exact target language and script, and level.
- Bounded learning events. Provider integrations can submit only five kinds; two additional response/reveal events are reserved for a separately authenticated YipYap review surface. Vocabulary membership and origin do not prove exposure, recall, correctness, or mastery.
- Integration records, hashed credentials and authorization codes, and content-free support case records. Raw tokens are never stored. ChatGPT and hosted-Claude OAuth access expires after 30 days and must be reconnected because no refresh token is issued; Claude Code and Codex local-plugin pairing access remains until you revoke it or delete your account.
- Content-free security audit records for scope grants, integration revocation, exports, and account-deletion request/completion. They contain closed authorization and lifecycle facts, not email, credentials, request metadata, vocabulary, conversations, or free text.
What we never collect
We do not request or store full conversations with your AI assistant, prompts, provider credentials, or payment data. Transcript-shaped fields are refused. Closed fields limit what can be sent, but cannot prove that an AI did not copy or paraphrase a bounded vocabulary word or meaning from a conversation; Skill minimization rules and service validation and abuse controls apply.
Telemetry and retention
Infrastructure invocation logs ordinarily contain only function name, timing, and status and are retained 30 days. A completed, approved MCP transport probe recorded 14 historical entries containing only fixed phase, header-state, and protocol enums plus a short one-way fingerprint of a random session identifier. It never recorded a raw session identifier, bearer token, account or integration identity, request or tool content, or vocabulary; the observer has been removed, and those historical entries follow the same 30-day log policy. A current remote-MCP teaching reply may receive one random, identity-free workflow handle in its tool results so the same reply can pass it unchanged through the ordered status, settings, context, and bounded proposal calls. The handle is not an OAuth token or customer identifier, must not be shown to you or carried into another reply, and authorizes nothing without the separately reverified credential and binding. The service never logs or stores the raw handle. Private operational rows contain only its one-way domain-separated digest and the minimum account, integration, provider, credential-hash, scope, phase, and active-language binding needed to keep one reply coherent. A workflow authorizes work for at most five minutes and is deleted on completion, replacement, or failure. Expiry refuses immediately; physical deletion occurs on the next guarded use or daily cleanup and may lag with scheduler timing. Your vocabulary and account settings persist until you delete them. ChatGPT and hosted-Claude OAuth access tokens expire after 30 days and calls refuse immediately at expiry; daily bounded authorization cleanup removes expired hashed OAuth session rows later, so physical removal may lag. Claude Code and Codex local-plugin pairing rows have no OAuth issuer, audience, resource, token-provider, or expiry fields, have no time expiry, and remain until explicit revocation or account deletion. They do not match OAuth expiry cleanup. No refresh token is stored or issued in this phase. Provider-suggestion and provider-render events expire after 180 days; learner-confirmation and YipYap review events expire after 730 days. Provider-event and teaching-profile replay receipts expire after 30 days. Pairing codes expire after 10 minutes, OAuth codes after 5 minutes, My Lexicon page cursors after 24 hours, and verified support cases after 30 days. Page cursors are deterministically reused for the same account and page boundary instead of being created on every repeat read. Learner-history cleanup runs every 15 minutes and processes up to eight bounded pages per run for each of events and provider replay receipts. Reaching an expiry makes a record eligible for deletion; scheduler timing or a larger backlog may delay physical removal. Legacy event counters are backfilled atomically from valid stored sequence state on their first retention pass. Service-owned retention scan cursors advance across each page and resume across runs so an early blocked account cannot indefinitely starve later eligible records; they are not customer export data and are deleted with the account named by their current scan position.
Your rights
To request an export or deletion, sign in and create a verified support case in the app, then email its case ID to support@magneum.co. Email is only the conversation channel and never proves account ownership. Exports contain every exportable customer record as one document: account and Learning Mode state, personal vocabulary, retained learning events with a flag stating whether any older events have aged out, integrations and grants, settings, baseline migration data, hidden-content identifiers, verified support cases, and active-account security-audit history. They explicitly exclude authorization artifacts (session tokens, pairing codes, OAuth codes) and rebuildable internal operational artifacts (derived mobile views, idempotency receipts, lexical-normalization indexes, page cursors, migration control records, export leases, deletion jobs, mcp_reply_cycles, retention_worker_cursors, and account_deletion_tombstones). Deletion first locks the account against further access and recreation, then removes your account data, prior security-audit history, account-bound top-level session tokens, pairing codes, OAuth codes, MCP reply-session and credential-cycle rows, support and teaching-profile receipts, retention-worker cursor rows, ordinary internal artifacts, and your Firebase sign-in principal. A failed deletion remains locked while a durable job retries; after repeated failures it remains quarantined and fail-closed for authenticated support/operator fulfillment. Email alone cannot authorize that work. The only disclosed post-completion artifacts are a content-free deletion-completed receipt, which expires 30 days after completion, and a separate content-free tombstone containing only a schema and expiry. The tombstone is written for 30 days at request and refreshed to a full 30 days at completion; cleanup rechecks its current expiry before removing it. The service also uses one content-free malformed-job sweep checkpoint containing only a schema, last deterministic deletion-job identifier, and server update time. It is covered by the excluded deletion-jobs category, moves across bounded runs, and is removed if it points to the completing job. The server-side deletion path does not yet perform the separate fresh-token step needed to revoke Sign in with Apple; that app-flow step remains deferred. Any connected AI integration stops receiving data the moment its access is revoked on your account.
Recovery copies
We retain protected database recovery copies for up to seven days. Deleted live records may remain in those copies until that recovery window expires. Recovery copies are not used for ordinary service access. Before a restored system is put into use, completed account deletions and revoked integration access must be reapplied.
Subprocessors and data location
Google Cloud / Firebase. Account and vocabulary records in Firestore are stored in Google's United States multi-region (nam5). The account service's Cloud Functions run in Iowa, United States (us-central1).