Legal document

Privacy Policy

Last updated: August 4, 2026

Yapio ("we", "us", or "our") operates the Mokaid platform at mokaid.io. This Privacy Policy explains what personal data we collect, why we process it, how we protect it, and your rights under:

  • the Israeli Protection of Privacy Law 5741-1981, as amended (including Amendment 13), and the Privacy Protection Regulations (Data Security), 5777-2017 (the "PPL"); and
  • where applicable, the EU/UK General Data Protection Regulation ("GDPR") and comparable international privacy laws.

By using the Mokaid platform, you acknowledge that you have read this Privacy Policy. If you do not agree, please do not use the service.

1

Data controller and database owner

The controller of personal data (and, under Israeli law, the database owner) for the Mokaid service is:

Yapio

Attention: Privacy inquiries

Chicago 136

Haifa

Israel

Email: contact@yapio.io

For privacy requests, contact us at contact@yapio.io. We will verify your identity before acting on certain requests.

2

Data we collect

We collect personal data depending on how you interact with Mokaid:

  • Account data — Full name, email address, password (hashed), optional profile photo, locale preferences.
  • Workspace and usage data — Actions on the platform, pages visited, session duration, feature usage, and interface events.
  • AI agent data — Instructions, assigned tasks, conversation history with agents, and produced outputs you generate while using the service.
  • Integration data — OAuth tokens and related metadata for third-party integrations you enable (e.g. GitHub, Google, Figma).
  • Payment data — Billing and payment metadata processed by our payment provider (Stripe). We do not store full payment card numbers on our systems.
  • Technical data — IP address, browser type, operating system, device identifiers, and server logs for security, fraud prevention, and debugging.
  • Communications — Messages you send to support or other contact channels.

We do not intentionally collect special-category data (e.g. racial or ethnic origin, political opinions, health data, biometric templates for identification) under GDPR, or sensitive information beyond what you voluntarily place in platform content. Please do not submit such data unless necessary for your legitimate use of the service.

3

Purposes and legal bases

We process personal data only for the purposes described below. For Israeli PPL purposes, processing is limited to the purposes for which the data was collected or compatible purposes permitted by law. Where GDPR applies, each activity rests on a legal basis under Article 6 GDPR:

PurposeLegal basis (GDPR)
Account creation and managementContract performance (Art. 6.1.b)
Providing platform features (incl. AI agents)Contract performance (Art. 6.1.b)
Transactional and service emailsContract performance (Art. 6.1.b)
Billing and subscription managementContract / legal obligation (Art. 6.1.b, c)
Security, fraud prevention, abuse detectionLegitimate interest (Art. 6.1.f)
Service improvement (aggregated / limited)Legitimate interest (Art. 6.1.f)
Marketing communications (opt-in)Consent (Art. 6.1.a)
Non-essential analytics cookiesConsent (Art. 6.1.a)
Complying with legal requirementsLegal obligation (Art. 6.1.c)
4

AI processing transparency

Mokaid uses artificial intelligence features (agents, models, and related tooling) to generate content and execute tasks you request. Content you provide (prompts, documents, instructions) and resulting outputs may be processed by us and by sub-processors solely to deliver those features. We do not sell your content to train public third-party foundation models for unrelated purposes. You remain responsible for what you submit to AI features and for reviewing outputs before relying on them.

5

Retention periods

We keep personal data only as long as needed for the purposes above or as required by law:

  • Active account data — For the duration of your contractual relationship with us.
  • Data after account closure — Approximately 30 days (grace period for reactivation), then permanent deletion or anonymization, except where legal retention applies.
  • Billing and tax records — Typically 7 years (and longer if required under Israeli tax or bookkeeping rules), in line with accounting and tax obligations.
  • Technical logs — Up to 90 days for security and debugging, unless needed longer for an investigation.
  • Marketing data (opt-in) — Until you withdraw consent or unsubscribe.
6

Sharing and recipients

We do not sell your personal data. We may share data only as follows:

  • Technical processors — Hosting (Render), database, email delivery, and infrastructure providers bound by written processing terms.
  • Payment provider — Stripe processes payments and related billing data under its own terms and privacy policy.
  • Third-party integrations — GitHub, Google Workspace, Figma, and similar services — only if you enable them and within the permissions you grant.
  • Legal and safety — Competent authorities, courts, or advisors when required by law, to protect rights, or in connection with a merger or corporate transaction (with notice where required).
7

International transfers

We and our processors may process data outside Israel, including in the European Economic Area, the United Kingdom, and the United States. For transfers that require safeguards, we rely on appropriate measures such as Standard Contractual Clauses (SCCs), adequacy decisions where available, and contractual/security obligations under Israeli and international law.

8

Cookies and similar technologies

Mokaid uses cookies and similar technologies as described in our Cookie Policy. Strictly necessary cookies run to provide the service. Analytics and other non-essential cookies are used only with your consent where required.

9

Data security

Taking into account the nature of the data and risks under the Israeli Privacy Protection Regulations (Data Security), we implement appropriate technical and organizational measures, including:

  • Encryption in transit — HTTPS / TLS for network traffic; passwords stored using modern hashing.
  • Access control — Least-privilege access for personnel and systems; authentication controls.
  • Monitoring and logging — Security-oriented logging and anomaly awareness on production systems.
  • Backups — Periodic backups with restore procedures appropriate to the service.

No method of transmission or storage is perfectly secure. If a personal data breach is likely to cause a risk to your rights, we will notify you and, where required, the Israeli Privacy Protection Authority and/or relevant EU supervisory authorities without undue delay (and, where GDPR applies, aiming to meet the 72-hour regulator notification standard where mandatory).

10

Your rights

Depending on applicable law (PPL, GDPR, or other), you may have rights including:

  • Access — Obtain confirmation and a copy of personal data we hold about you.
  • Rectification — Correct inaccurate or incomplete data.
  • Erasure / deletion — Request deletion, subject to legal retention and contractual needs.
  • Restriction or objection — Limit or object to certain processing, including direct marketing.
  • Portability (where GDPR applies) — Receive data in a structured, commonly used, machine-readable format.
  • Withdraw consent — Where processing is based on consent, withdraw it at any time without affecting prior lawful processing.

Exercise rights by emailing contact@yapio.io. We respond within a reasonable period (typically within one month under GDPR, subject to permitted extensions). You may also lodge a complaint with:

  • Israel — the Privacy Protection Authority (PPA) — https://www.gov.il/en/departments/the_privacy_protection_authority
  • EU / EEA — your local data protection supervisory authority (a list is available from the European Data Protection Board).
11

Controller / processor roles for workspaces

When you use Mokaid as a workspace for your organization, you (or your organization) may act as controller of personal data relating to your members and end-content. In that case, Yapio acts as a processor on your instructions. A Data Processing Agreement (DPA) is available on request at contact@yapio.io.

12

Children

Mokaid is intended for business and professional users who are at least 16 years old (or older where local law requires majority for binding contracts — typically 18). We do not knowingly collect personal data from children. If you believe a minor has provided us personal data, contact us so we can delete it.

13

Changes to this policy

We may update this Privacy Policy to reflect legal, technical, or product changes. The "Last updated" date at the top will change when we do. For material changes, we will provide notice by email or in-product communication within a reasonable time before the changes take effect where required by law.

14

Contact

For any question, request, or complaint about personal data protection:

Yapio

Attention: Privacy

Chicago 136

Haifa

Israel

Email: contact@yapio.io

© 2026 Yapio. All rights reserved. mokaid is a product of Yapio.