Legal

Privacy
Policy

Effective: April 7, 2026Last updated: September 22, 2026

FileYield Inc., a Delaware corporation ("FileYield," "we," "us") operates fileyield.com (the "Service"). This Privacy Policy explains what data we collect, how we use it, and your rights. By using the Service, you agree to this Policy.

1. Who We Are

FileYield Inc. is a Delaware corporation with its principal place of business in Arizona. We operate a listing and messaging platform connecting sellers of datasets with AI companies and other buyers. FileYield does not host or transfer the actual data sold between parties — we facilitate discovery, matching, messaging, and an audit trail.

Contact: support@fileyield.com

2. Information We Collect

We collect the following categories of information:

2.1 Account & Contact Data

  • —Name and email address
  • —Hashed password and authentication tokens
  • —Account role (buyer or seller)
  • —Phone number, when you provide it
  • —Company name and role, when provided

2.2 Marketplace Data

  • —Listings you publish: titles, descriptions, formats, volumes, sample metadata, pricing, compliance attestations
  • —Buyer requests: descriptions of data sought, budget ranges, intended use cases
  • —Messages exchanged between buyers and sellers on the platform
  • —Offers, counter-offers, and saved listings
  • —Your interactions with the AI listing advisor and buyer/seller AI assistants

2.3 Dataset Files and Outreach

We collect listing descriptions, requests, account details and messages, not the underlying dataset files. File and sample uploads are not currently supported. In-app assistants do not place calls or send SMS. See Section 4.

2.4 Usage & Analytics

  • —Pages viewed, links clicked, time on page, referrer URLs
  • —Session recordings via PostHog (anonymized; sensitive inputs masked where feasible)
  • —Funnel and conversion events
  • —Feature flag exposure data
  • —Search queries and filter usage

2.5 Technical Data

  • —IP address, approximate geolocation derived from IP
  • —Browser type, operating system, device identifiers
  • —Cookies, local storage, and similar technologies (see Section 6)
  • —Server logs (Vercel, Supabase) for security and abuse prevention

2.6 Inferred & Derived Data

  • —Research-query embeddings used to search the research catalog
  • —Inferred interests and recommendations based on activity
  • —Aggregated marketplace statistics

2.7 Payment Data (when applicable)

When payments become available, payment card data will be tokenized and processed by Stripe. FileYield never stores raw card numbers, CVV codes, or full bank account numbers.We retain only the last four digits, token IDs, and transaction metadata.

3. How We Use Your Information

  • —To operate the marketplace: list datasets, accept buyer requests, surface matches, deliver messages
  • —To run brokered outreach: when you opt in as a seller, we may surface approved listing descriptions to relevant potential buyers via lawful outreach channels
  • —To provide AI features: the listing advisor, buyer assistant, and seller assistant process your inputs to suggest categories, draft listings, and answer questions
  • —To send transactional and account emails (verification, notifications, password resets)
  • —To send marketing emails about FileYield features (you may opt out at any time)
  • —To analyze usage and improve the Service
  • —To detect fraud, abuse, and security threats
  • —To comply with legal obligations (tax, regulatory, court orders)
  • —To enforce our Terms of Service and Acceptable Use Policy

4. Voice & Outreach Availability

The in-app AI assistants do not place calls, send SMS, or start outreach campaigns. Message tools prepare drafts for your review. Self-service paid outreach is not currently available.

If a separate calling or outreach service is introduced, its availability, processing, consent and recording disclosures must be provided before use. This policy is not a statement that calling or recording is currently operating.

5. Legal Bases for Processing (GDPR)

For users in the European Economic Area, United Kingdom, or Switzerland, our legal bases are:

  • —Contract: to provide the Service you have signed up for (Article 6(1)(b))
  • —Legitimate interests: to improve the Service, prevent fraud, and run brokered outreach to consenting parties (Article 6(1)(f))
  • —Consent: for marketing emails, optional cookies, and call recording where required (Article 6(1)(a))
  • —Legal obligation: to comply with tax, regulatory, and law-enforcement requirements (Article 6(1)(c))

6. Cookies & Tracking Technologies

We use the following categories of cookies and similar technologies:

  • —Strictly necessary: authentication cookies, CSRF tokens, session cookies
  • —Functional: preference cookies (theme, language)
  • —Analytics: PostHog cookies for product analytics, session recording, and feature flags
  • —Security: cookies set by Vercel and Supabase for fraud and abuse detection

You can manage cookies through your browser settings. Disabling strictly necessary cookies will break parts of the Service.

7. AI Processing & Third-Party Models

FileYield uses third-party AI providers (including OpenRouter and its model providers) to power features such as AI Discovery and the buyer/seller assistants. Your messages, conversation context, listing drafts, questions, and relevant tool results are transmitted through OpenRouter to model providers for processing. The provider returns a response which we display to you.

Research queries are also sent through OpenRouter for embeddings used to search our research catalog. OpenRouter and the selected model providers have their own retention and data-use policies. We do not promise zero retention or that every provider excludes inputs from training. Do not submit personal records, protected health information, credentials, or confidential datasets.

AI outputs may be inaccurate. They are not legal, financial, medical, or professional advice. You are responsible for reviewing AI-generated content before relying on it.

8. How We Share Your Information

We share information with the following categories of recipients:

8.1 Service Providers (Processors)

  • —Supabase — database and authentication; no underlying dataset upload feature
  • —Vercel — hosting, edge functions, analytics, logging
  • —PostHog — product analytics, session recording, feature flags
  • —OpenRouter and its model providers — assistant inference and research-query embeddings
  • —Twilio (or equivalent) — SMS and voice calling infrastructure
  • —Resend — transactional email delivery when configured
  • —Apollo — contact management for inbound leads that permit sharing; contact sync does not enroll you in an outreach sequence
  • —Stripe — payment processing (when active)
  • —Firecrawl — public web research (does not process user data)

Provider processing is subject to the applicable service terms and privacy policies. Available integrations do not mean that every listed service is active for every user.

8.2 Other Marketplace Users

When you list data, your listing (and the associated company name, if provided) is visible to buyers. When you message another user, your messages are visible to that user. When a connection results in a deal, FileYield may share contact details with both parties so they can transact directly.

8.3 Legal & Safety

We may share information when required by law (subpoena, court order, regulatory request) or when necessary to investigate fraud, protect rights, or prevent imminent harm.

8.4 Business Transfers

If FileYield is acquired, merges, or sells substantially all of its assets, your data may be transferred as part of the transaction. We will notify you of any such transfer and any resulting changes to this Policy.

FileYield does not sell personal information for monetary consideration as defined by CCPA. See Section 11 for California-specific rights.

9. Data Retention

  • —Account data: while your account is active, plus 7 years after closure for legal and tax records
  • —Listing and request data: while active, plus 3 years after archival
  • —Messages and offers: indefinitely while the conversation thread is active; archived after account closure
  • —Voice call recordings: up to 90 days, then deleted unless retained for a specific legal reason
  • —SMS message logs: 1 year
  • —PostHog analytics events: 12 months
  • —Server access logs: 90 days
  • —Vector embeddings: while the underlying listing or request exists

10. Your Rights (GDPR)

If you are in the EEA, UK, or Switzerland, you have the following rights under the GDPR:

  • —Access: request a copy of the personal data we hold about you (Article 15)
  • —Rectification: correct inaccurate data (Article 16)
  • —Erasure: request deletion of your data (Article 17)
  • —Restriction: limit how we process your data (Article 18)
  • —Portability: receive your data in a structured, machine-readable format (Article 20)
  • —Objection: object to processing based on legitimate interests, including direct marketing (Article 21)
  • —Withdraw consent: where processing is based on consent, you may withdraw at any time
  • —Lodge a complaint with your local data protection authority

To exercise any of these rights, email support@fileyield.com. We will respond within 30 days.

11. Your Rights (CCPA / California)

If you are a California resident, you have additional rights under the CCPA / CPRA:

  • —Right to know what personal information we collect, use, and share
  • —Right to delete personal information we hold about you
  • —Right to correct inaccurate personal information
  • —Right to opt out of the sale or sharing of personal information (FileYield does not sell)
  • —Right to limit use of sensitive personal information
  • —Right to non-discrimination for exercising your rights

To exercise these rights, email support@fileyield.com. You may also designate an authorized agent to make a request on your behalf.

12. Children’s Privacy

FileYield is not directed to children under 16. We do not knowingly collect personal information from anyone under 16. If we learn we have collected data from a child under 16, we will delete it promptly. If you believe a child has provided us data, contact support@fileyield.com.

13. International Transfers

FileYield is headquartered in the United States, and your data is processed in the U.S. and in other countries where our processors operate. If you are located in the EEA, UK, or Switzerland, you should be aware that the U.S. may not provide the same level of data protection as your home jurisdiction. We are working toward implementing Standard Contractual Clauses and other appropriate safeguards for international transfers; until those are in place, you should consider whether the Service is right for you given your local data protection requirements.

14. Security

We use encryption in transit (TLS), encryption at rest provided by our hosting and database providers, role-based access controls, and audit logging. Access to production data is limited to authorized personnel. We are an early-stage company and have not yet undergone formal security certifications such as SOC 2 or ISO 27001. No system is 100% secure. We cannot guarantee absolute security, and you use the Service at your own risk.

15. Changes to This Policy

We may update this Policy from time to time. When we do, we will update the “Last updated” date above and, for material changes, notify you by email or in-app banner at least 14 days before the changes take effect.

16. Contact Us

Questions, concerns, or rights requests: support@fileyield.com

FileYield Inc.
A Delaware corporation
[Mailing address — TBD before launch]

This is a draft policy that has not been reviewed by legal counsel. Consult a qualified attorney before relying on these terms for actual business operations. The terms above reflect FileYield’s intended practices but are subject to revision before public launch.