Yellow and Black

Docs Policies

Privacy notice

Effective October 4, 2026. Shrinav Loka, Ashburn, Virginia, United States operates Yellow and Black. For privacy requests, email support@yellowandblack.dev.

Information and purposes

We process account names, email addresses and password hashes for sign-in, verification and recovery; project and hashed API-key records for access; and model/session identifiers, timestamps, task text, labels, request counts, timings and charges to provide inference, show usage, diagnose failures and settle bills. Verification and password-reset messages are sent through our email provider. We use essential authentication cookies; the application does not require advertising cookies.

Camera images, robot state and task instructions pass through our gateway to Modal for inference. Actions return through the service. Our hosted offer does not enable diagnostic payload capture or use customer observations to train models. Provider handling still applies: Modal documents retention of Function inputs and outputs for up to seven days. This service uses Functions; it is not a zero-retention endpoint.

Stripe processes checkout and payment details. Our platform keeps payment identifiers, amounts, statuses and ledger entries for accounting, disputes and recovery. We do not receive or store full payment-card numbers through the hosted checkout.

We retain security/account/deletion events and a keyed trial-eligibility record to prevent repeated promotional claims, secure accounts and avoid reactivating deleted access after a restore. A keyed identity is pseudonymous, not a promise of anonymity.

Providers and locations

Provider Role and information
Microsoft Azure US-hosted application, database, encrypted backups, registry and operational monitoring; account/session/payment metadata and service metrics
Modal GPU inference in our selected US placement; observations, task instructions, outputs and worker operational metadata
Google Workspace Verification, recovery and support email, including addresses and message contents
Stripe Payment processing and fraud/compliance handling under its own privacy terms
ntfy Operator incident notifications containing operational status; observation payloads and credentials are not intended to be included

US compute placement is not a promise that every provider's account, support or operational systems remain exclusively in one jurisdiction. Providers process information to supply their services, subject to their applicable terms. We may also disclose information when legally required, to address fraud or security incidents, or at your direction. We do not sell customer observations or account data.

Retention and deletion

  • Account information remains while the account is active. Account deletion blocks access and revokes credentials first; identifying account fields are then scrubbed as cleanup proceeds.
  • Central session task text and labels are scheduled for redaction 30 days after closure. Worker reports and copied session summaries undergo related cleanup. An unavailable worker can leave cleanup pending; the deletion receipt distinguishes pending from completed work.
  • Modal Function inputs and outputs can remain for up to seven days under its provider policy. Deleting an account does not immediately remove these copies.
  • Payment/ledger records and terms/rate acceptances remain after deletion for accounting, disputes and agreement evidence. Minimal security/deletion records remain for incident response and safe recovery. There is currently no fixed automatic purge period for these retained records; contact us to request review, subject to legal and operational retention needs.
  • The keyed trial-eligibility record and promotional issuance total remain after deletion while needed to enforce the trial program. They are not reset by making another account. Requests to review this retention can be sent to the privacy contact.
  • Encrypted backups are separate historical copies and are not rewritten for individual account deletion. Our routine database-backup configuration uses seven-day managed recovery; exported backup objects, versions and snapshots are scheduled for expiry after 31 days under the storage lifecycle policy. Restores require deletion/security reconciliation before access is re-enabled. Provider deletion and failed-cleanup delays can extend the time until every copy is removed.

No immediate-erasure promise applies to pending payments, backups or information that must be retained for legal obligations or disputes.

Your controls

The account console supports export and deletion. Export includes stored account, usage, billing and acceptance information, excluding credentials and internal operator notes. A deletion receipt records progress after account access is disabled. Deletion includes the credit-forfeiture acknowledgment described in our terms, without removing legally required refund rights. You can revoke project keys; revocation is not a physical emergency stop.

You may contact us about access, correction, deletion or other rights applicable to your circumstances. We may need to verify your identity before responding. Do not email passwords, API keys, payment-card numbers or private observation recordings.

Protection and updates

We use HTTPS, hashed passwords/API keys, restricted service access and encrypted backups. These measures do not constitute a compliance certification or a guarantee against every incident. The service is intended for adult developers and organizations and is not directed at children. Changes to this notice are dated here; material changes to service terms use the account acceptance flow.

Updated 2026-10-04 · View as markdown