Yearn
Privacy Policy
7 September 2026
This translation is provided to help you understand the service. The French version prevails. French reference version
This text describes what Yearn does with your data. It follows how the service works: each duration and recipient listed here corresponds to something verifiable in the app.
Who is responsible
Jonathan Ibor, an individual residing in France, is the data controller. Yearn is an independent project developed and operated alone. For any question or to exercise your rights: jonathan.ibor@gmail.com. You will receive a reply within one month at most, in accordance with the GDPR.
What Yearn collects, and why
| Data | Why | Legal basis |
|---|---|---|
| Email address and Google account identifier | To recognise you from one session to another. The Google identifier, not the email address alone, is used as the key, because two providers may return the same address and linking them could create an account takeover risk. | Contract performance |
| Date of birth | The service is reserved for adults and networks also require this. It is a barrier, not a targeting criterion. | Legal obligation and contract |
| Declared profile: age range, gender, gaming habits, monthly budget | To suggest offers for which you are eligible and avoid surveys that would reject you after several minutes. Each question is optional. | Consent |
| Daily goal, started offers, reported time | To operate the service and calculate the hourly rate shown to everyone. Your reported times feed a collective median. | Contract performance |
| Ledger entries: earnings, cancellations, redemptions | To keep the balance, justify each movement and keep evidence in case of a dispute with a network. | Contract and legitimate interest |
| Sessions: device, dates, token fingerprint | To keep you signed in and allow remote session revocation. The token itself is never stored: only its SHA-256 fingerprint is stored. | Contract and security |
| IP address and user-agent when opening an offer | Sent to the network, which requires them to show offers available in your country and detect fraud. | Contract and legitimate interest |
| Consents: what you accepted, when and under which text version | To prove that an agreement was given. A consent is added; it never overwrites the previous one. | Legal obligation |
What Yearn does not do
- Your email address is never sent to the networks. They receive only a Yearn technical identifier, your IP address and your user-agent.
- No data is sold, rented or transferred.
- No advertising tracker or analytics cookie is added on the site or in the app.
- No automated profiling producing legal effects concerning you is carried out.
Google sign-in
Yearn uses Google Sign-In. When you sign in, Google sends Yearn your email address and a stable account identifier, and nothing else: no contacts, calendar or mailbox content.
Google learns that you sign in to Yearn. It does not learn which offers you open, your earnings or your redemptions: that information stays on Yearn’s server.
Who receives data
| Recipient | Role | What it receives | Where |
|---|---|---|---|
| OVH | Server and database hosting | Nothing beyond what is stored, which it does not access | France |
| Authentication | The fact that you sign in to Yearn | European Union and United States | |
| CPX Research | Survey provider | A Yearn technical identifier, your IP address, your user-agent and profile criteria you chose to fill in | Germany |
Other networks may be added, including outside the European Union. None will receive more than what is described above, and this page will be updated before any new transfer.
How long data is kept
- Your account, profile and goals are kept while the account exists and disappear when you delete it.
- Sessions are kept for thirty days and then automatically deleted; you may close a session from the app.
- Ledger entries and conversion evidence may be kept after account deletion because they justify paid amounts and disputes.
- Consents are kept after deletion as proof that an agreement was given and later withdrawn.
- Reported times are kept detached from you and feed the public median.
Your rights
Access, portability and deletion are available from the app. Account, profile, goals, consents and ledger can be exported in a machine-readable format.
Other rights such as rectification, restriction, objection and withdrawal of consent can be exercised by writing to jonathan.ibor@gmail.com. If the response does not satisfy you, you may contact the CNIL.
Minimum age
Yearn is reserved for people aged 18 or over. A birth date is requested when the account is created and an account cannot be created below that age.
Security
All traffic uses HTTPS. Session tokens are stored hashed, never in plain text. Gift card codes are encrypted in the database and the key is not in the database.
The database is not reachable from any public network. Shared secrets used with networks are removed from server logs.
Changes
Any material change will be announced in the app before taking effect, and the date at the top of this page will indicate the applicable version.