YOffice is built privacy-first. Optional data uses are off by default, you can export or delete your data at any time, EU data residency is the default, and you stay in control of how your information is used to train AI — which it isn't, unless you opt in.
Data is hosted in the EU by default, with full GDPR data-subject rights.
Analytics, crash reporting, marketing, and AI-training consents all start switched off.
Download your data on request, and delete your account with a 30-day grace period.
Consents are versioned and changes are recorded in an activity audit log.
YOffice supports two sign-in methods. Choose whichever fits your team — both are available everywhere.
| Method | Notes |
|---|---|
| Email + password | Create an account with an email and password. Sign-up includes a consent gate before your account is active. |
| One-tap sign-in with your Google account, scoped to your email and basic profile. |
After signing in you pick an organization; YOffice then issues a per-organization token that authorises your requests to that tenant. See Organizations for the multi-org model.
When you sign up, YOffice asks for consent before activating your account. Required agreements must be accepted; optional data uses are off unless you turn them on.
| Consent | Default | What it covers |
|---|---|---|
| Terms of Service | Required | Accepting the terms of use. |
| Privacy Policy | Required | How your data is handled. |
| Data Processing | Required | Processing of personal data per the DPA. |
| Analytics | Off by default | Product-usage analytics. |
| Crash reporting | Off by default | Crash diagnostics to improve stability. |
| Marketing | Off by default | Product and marketing communications. |
| AI training | Off by default | Whether your data may be used to improve AI models. |
Adjust any optional consent at any time in Settings → Privacy & data. Consents are versioned — if a policy changes materially you'll be asked to re-consent — and cookie consent can be revisited too.
Exercise your right of access with a data-subject access request. In Settings → Privacy & data, choose Download my data and YOffice prepares an export of your personal data for you to download.
Your data is not used to train AI models unless you explicitly opt in — the AI-training consent is off by default. You can review and revoke it any time from Privacy & data. Note that when you use a self-hosted model, inference stays entirely on your own infrastructure (see below).
Account deletion is deliberate and reversible during a grace window:
Go to Settings → Privacy & data and choose Delete account.
You type a confirmation to acknowledge the action — there's no accidental single-click deletion.
Re-enter your password to prove it's really you.
Your account enters a 30-day grace period before permanent deletion, so you can change your mind.
Organization data is hosted in the EU by default. This supports GDPR compliance and a Data Processing Agreement. Talk to us about requirements for other regions or a dedicated deployment.
Your data is encrypted in transit over TLS 1.2+ — including API calls, real-time LiveKit media (DTLS-SRTP transport encryption), and file transfers — and hosted on EU infrastructure (Germany). Stored secrets such as integration credentials and LLM/API keys get an extra layer of application-level encryption (AES-256-GCM), and once you save them they're never shown in plaintext again — so they stay safe.
For strict data-sovereignty needs, YOffice is a managed cloud service, but the parts that touch your content most directly can run on your own infrastructure: point AI inference at a locally-running Ollama instance, and run LiveKit media on your own servers. With a self-hosted model, prompts, messages, and documents never leave your network — even when using AI.
| Right | How to exercise it |
|---|---|
| Access & portability | Settings → Privacy & data → Download my data. |
| Rectification | Update your profile details in Account settings. |
| Erasure | Settings → Privacy & data → Delete account (30-day grace). |
| Withdraw consent | Toggle any optional consent off at any time. |
Workflow and AI-agent activity — plus a running cost summary — is recorded in an Activity log under Settings → Organizations, so admins can review usage over time.
YOffice publishes its full legal documents, linked from within the app: Privacy Policy, Terms of Service, Data Processing Agreement, Cookie Policy, and the list of Sub-processors.
Security is a partnership. If you spot a potential issue, we'd love to hear from you at security@yoffice.ai ahead of public disclosure. We welcome good-faith researchers and never pursue legal action against them.