The free tools

The editor at /editor runs in your browser. Your edits stay in that browser and are not sent to us. The command line tool, and the agent you connect to it, run on your machine and send us nothing either.

Cloudflare, which serves this site, counts requests on its own servers so we can see how much the site is used. No script runs for that and no cookie is set. The site sets no cookie at all until you sign in.

What a workspace stores

  • Your email address, and a display name if you give one.
  • Your sessions, so that you stay signed in.
  • The practices and workspaces you belong to, and your role in each. The email address of anyone invited, until they accept or the invitation lapses.
  • The records in your workspaces, the layout of their maps, and their history: what changed, when, who changed it, and where the change came from, for example the editor or claude.ai.
  • The agents you have allowed to use a workspace, and your personal access tokens. Tokens and session ids are stored only as hashes, which cannot be turned back into the token.
  • The practice's Stripe customer and subscription ids, and its plan: free week, subscribed, payment failed or read-only.
  • A log of sign-ins: whether each one succeeded, when, and a hashed form of the IP address it came from, kept for 90 days.

What it does not store

  • Your prompts or your agent's conversations. An agent sends a workspace tool calls, such as "apply this change". The conversation stays with the agent's provider.
  • Card numbers or bank details. Those go to Stripe and Link, never to us.
  • Your IP address itself. Only a hashed form of it is kept, made with a secret so it cannot be turned back into the address: to limit how many sign-in emails can be sent, and in the sign-in log, which is kept for 90 days.
  • Anything about you from other sites. There is no analytics script, no tracking pixel, no advertising, and no link in our emails that tracks a click.

Cookies

One cookie, ym_session, keeps you signed in. It is set when you sign in, cannot be read by scripts, and expires 30 days after you last use the site. Signing out removes it.

The sign-in page, and the page where you allow an agent to use a workspace, run Cloudflare Turnstile. It checks that a person is asking, so the sign-in form cannot be used to send mail to strangers. Cloudflare's own privacy policy covers it.

Where it lives

Your account and your records are stored on Cloudflare's global network. Each workspace is placed near where it is first used and is not pinned to a country or region, so it may be stored and served outside Australia.

If a client needs a record held in one region, write to us. It is not offered yet.

Who else handles it

  • Cloudflare runs the servers, stores the data, sends our emails and runs Turnstile.
  • Stripe, through Link, handles payments as the merchant of record. When you subscribe, you give your card and billing details to Stripe on Stripe's own page, under Stripe's and Link's privacy policies. Stripe tells us whether a practice's subscription is active and how many seats it pays for. Receipts and refunds come from Link.
  • Your agent's provider, for example Anthropic for claude.ai or OpenAI for ChatGPT, sees what your agent reads from a workspace, under your own agreement with them.

Nobody else. We do not sell or rent personal information, and we do not use records to train models.

Security

Everything travels over HTTPS. The platform encrypts the database and each workspace's storage at rest. Session ids, sign-in links and tokens are hashed with a secret before they are stored.

Our logs keep request counts, the kind of each error, and whether a sign-in succeeded. One function strips tokens, sign-in links and email addresses from every log line before it is written.

Sign-in links last fifteen minutes and work once. Invitation links last seven days, work once, and can be cancelled by whoever may send them. An agent's access lasts 24 hours and renews for up to 30 days. Removing someone from a workspace disconnects the agents they connected to it, and you can disconnect any agent yourself from your account page.

Keeping and deleting

  • A workspace stays until an owner deletes it. A lapsed plan never deletes anything: the workspace becomes read-only and export keeps working.
  • An owner deletes a workspace from its settings page by typing its name. The record, its history and every agent connection to it are removed at once, for everyone. We keep no soft-deleted copy.
  • You delete your account from your account page. That removes your memberships, your sessions and your personal access tokens. If you are the only owner of a practice, the practice and its workspaces are deleted with your account and its subscription is cancelled at once, after the page offers you an export of every workspace.
  • Sessions end 30 days after you last use them. Sign-in links end after fifteen minutes, and invitation links after seven days. The sign-in log is kept for 90 days.
  • Our platform keeps recovery points for up to 30 days so that a workspace can be restored after a fault on our side. We do not use them to bring back what you deleted, and they expire on their own. A recovery point taken before a deletion is kept for up to 30 days like any other, and is never used to undo that deletion.
  • Stripe keeps its payment records under its own policy, and may delete a customer's payment records on request. Ask Link or Stripe, or write to us and we will pass the request on.

Your rights

You can ask for a copy of the personal information we hold about you, ask us to correct it, or ask us to delete it, by writing to hello@yarramate.dev. We answer within 30 days. Most of it you can also see, export or delete yourself from your account page.

Yarra Systems is a small business, which the Privacy Act 1988 (Cth) does not generally bind, and we follow the Australian Privacy Principles by choice. If you are in the European Union or the United Kingdom, you have rights under the GDPR and the UK GDPR to see, correct, delete and receive a copy of your personal information, to object to how we use it, and to complain to your own supervisory authority; write to the same address and we answer within the same 30 days. If you are not satisfied with our answer, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.

Workspaces are for work. They are not meant for children, and we do not knowingly hold a child's information.

Changes

If we change what we keep or who handles it, we update this page and its date, and email account holders before the change applies. For a material change, that email comes 30 days before.

Contact

hello@yarramate.dev, read by a person. Yarra Systems Pty Ltd, Melbourne, Australia.

The terms cover the service itself. Pricing is on its own page.