Overview
Yentl is a source-anchored speech and media analysis tool. This Privacy Policy explains what data is processed, by whom, on what legal basis, and what rights you have. You can browse Yentl without an account. Running an analysis session — live listening, uploads, or link checks — requires signing in, so we can keep the service safe and fair. Sessions save locally in your browser first; when you are signed in, saved sessions can also be stored in Yentl's database so they can be restored on another device. API requests may temporarily process audio, media, transcript text, claims, sources, and analysis so the app can work.
Data retention
What Yentl keeps, where it lives, and how you remove it:
| Data | Where | Retention | You delete it by |
|---|---|---|---|
| Live mic audio | Streamed to Deepgram | Not stored by Knowlium | Ending the session |
| Uploaded media | Vercel Blob (private) | Deleted after transcription | Automatic; support on failure |
| Transcripts, claims, findings | Your browser | Until you clear it | Delete session / clear site data |
| Saved sessions (signed in) | Neon database | Until you delete them | Delete session / delete account |
| Account identifiers | Clerk / Neon | Account lifetime | Account deletion |
| Speaker-labels consent record | Neon database | Kept as proof of consent (no audio/voice data) | Request deletion via privacy contact |
Speaker labels (biometric processing)
Yentl has an optional speaker labels feature for live microphone sessions. When enabled, the transcription provider (Deepgram) analyzes voice characteristics to tell speakers apart and returns a speaker number for each spoken segment. This may constitute processing of a biometric identifier under certain U.S. state laws (e.g. Illinois BIPA, Texas CUBI, Washington RCW 19.375).
- Off by default. Speaker labels are disabled unless your deployment enables the feature and you turn them on.
- Live microphone only. They never run on uploaded files, YouTube, media links, pasted text, or server-side batch transcription.
- Consent required. Turning them on requires you to confirm, each session, that every participant has agreed to speaker separation.
- No voiceprints stored. Yentl uses the speaker numbers only to label speakers during your live session. It does not create, store, or share a voiceprint or biometric template, and the speaker numbers are not retained after your session ends.
- We keep a record of your consent.When you turn speaker labels on, Yentl writes a durable consent record so we can show the attestation was made: the consent version, a timestamp, the “live-room” scope, and either your account ID (if signed in) or a one-way hash of your IP address. This record never contains audio, transcripts, or any voice data. It is retained as our record of your consent; you can request its deletion at the address below.
For EU users, this is special-category data under GDPR Article 9; the in-session confirmation is the Article 9(2)(a) explicit-consent basis. Use speaker labels only for people physically in the room with you, never for recorded calls, uploads, or broadcasts.
Processors (subprocessors)
Yentl uses the following named processors. There are no unnamed third parties:
- Deepgram— Processes audio for transcription, including live audio and uploaded or linked media. Audio is processed on Deepgram's US-based servers. Deepgram is a US-based processor covered by the EU-US Data Privacy Framework and Standard Contractual Clauses (SCCs). See Deepgram Privacy Policy.
- Anthropic— Processes transcript text for fact-checking, bias/fallacy analysis, and source citation. Anthropic is a US-based processor. Yentl's use of Anthropic's commercial API is covered by Anthropic's Data Processing Agreement (DPA) and SCCs (auto-incorporated in Commercial ToS since January 1, 2026). See Anthropic Privacy Policy.
- Vercel — Hosts the Yentl web application and routes API requests via Vercel AI Gateway. Vercel may also temporarily handle uploaded media or media URLs during transcription workflows. Vercel operates a global edge network (US/EU/global). Vercel maintains a DPA and SCCs for EU data subjects. See Vercel Privacy Policy.
- Clerk— Provides authentication and account identity when sign-in is enabled for a deployment. Clerk may process account identifiers, email addresses, session cookies, and related metadata. Browsing Yentl's public pages does not require an account; running a fact-check session does.
- Neon — Provides the Postgres database used for account-synced saved sessions when the cloud backend is configured. Synced records include serialized session data, source metadata, timestamps, and the saved-session display name.
Full subprocessor details are available at /subprocessors.
Lawful basis for processing (GDPR)
For EU/EEA users, Yentl's processing is based on:
- GDPR Art. 6(1)(a) — Consent: You give explicit consent before any recording begins (via the session consent gate).
- GDPR Art. 9(2)(a) — Explicit consent for special-category data: Audio may incidentally contain special-category data (health, political views, religion, sexual orientation, ethnicity). Explicit consent is obtained before processing begins.
You may withdraw consent at any time by ending your session. Withdrawal does not affect the lawfulness of processing already completed.
Data retention
Saved sessions are local-first. If you use the Save button, the session snapshot is stored in this browser's IndexedDB so it can appear in the saved sessions library. Clearing site data, changing browsers, or using another device can remove or hide browser-local saves. If you are signed in and account sync is configured, Yentl also stores the serialized session, source metadata, timestamps, and display name in its database so the session can be listed, restored, renamed, deleted, and exported from another device.
Yentl server routes may temporarily process media, transcript text, and analysis while a request runs. Deepgram, Anthropic, Vercel, and Clerk, Neon, and any deployment-specific provider may retain API request, account, or database metadata per their own retention policies. Refer to their respective privacy policies for details.
Cross-border data transfers
Yentl uses processors based in the United States. Cross-border transfers are covered by:
- EU-US Data Privacy Framework (DPF) — where the processor is DPF-certified (Deepgram).
- Standard Contractual Clauses (SCCs) — for US-based processors and deployment-specific auth/database providers where incorporated into their respective agreements.
- UK International Data Transfer Agreement (IDTA) — for UK data subjects.
- Audio transcription is processed on Deepgram's US-based servers under the safeguards above; Yentl does not currently offer EEA-resident audio processing.
Your rights under GDPR
EU/EEA data subjects have the following rights:
- Right of access (Art. 15) — request a copy of personal data held about you.
- Right to rectification (Art. 16) — correct inaccurate data.
- Right to erasure(Art. 17) — request deletion of your data (“right to be forgotten”).
- Right to data portability (Art. 20) — receive your data in a structured, machine-readable format.
- Right to restriction (Art. 18) — restrict processing in certain circumstances.
- Right to object (Art. 21) — object to processing based on legitimate interests.
- Right to lodge a complaint — with your national supervisory authority (e.g., CNIL in France, ICO in the UK, DPC in Ireland).
Note: Because Yentl v1 session saves are local to your browser, most saved-session access, erasure, and portability actions are handled by your local library, exports, or browser site-data controls. To exercise rights regarding request metadata or processor-handled data, email privacy@yentl.it.
California residents — CCPA notice
California residents have rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), including the right to know, delete, and opt out of the sale of personal information. Yentl does not sell or share personal information as defined by the CCPA/CPRA — there is no sale for an opt-out signal to opt you out of. No ad trackers, no data brokers, no exceptions.
Quebec — Law 25 acknowledgment
Quebec's Act respecting the protection of personal information in the private sector (Law 25 / Bill 64) applies to processing of Quebec residents' personal information. Yentl's local-first save model minimizes account-backed personal data retention unless the user signs in and uses account sync, consistent with Law 25 data minimization principles.
Contact
The data controller for Yentl is Knowlium LLC, a New York limited liability company.
For privacy questions, data-rights requests, processor questions, or consent and retention concerns, email privacy@yentl.it or use the contact page.