Privacy Policy
YadoriLink is a peer-to-peer folder sync tool. This policy explains what the hosted YadoriLink coordination service (control.yadori.link) and this website do with personal information. YadoriLink is pre-1.0 beta software, and this policy describes how it works today.
1. Who is responsible
YadoriLink is operated by an individual, Jumpei Takiyasu (“I”). Questions, access requests and deletion requests: me@juntaki.com. My postal address is disclosed without delay on request sent to that email address.
2. The short version
- Your file contents, file names and folder paths are never uploaded to the coordination service. Files are transferred between your authorised devices end-to-end encrypted; where a direct connection is not possible they pass through third-party encrypted relays (iroh public relays), which can see network metadata but not contents (section 5).
- The service stores the minimum needed to let your devices find and authorize each other: your Google account identifier and email address, your devices, and the folder groups and access rules between them.
- I do not sell personal information, show ads, or run analytics or trackers. This website sets no cookies and makes no requests to third parties.
3. What the coordination service stores
Account
When you sign in with Google, the service asks Google for the openid and email scopes only. It stores your Google account identifier (the sub value), your email address and the time the account was created. It does not store a password, and it does not access your Google contacts, Drive or other Google data.
Devices
For each device you register: a device name (by default your computer’s host name, which you can change), the device’s public signing key, when it was created, whether it is currently online and when it was last seen, and the network addresses it reports so that your other devices can reach it (IP addresses and ports, and relay addresses). Private keys stay on the device.
Folder groups and sharing
For each folder group: its identifier, the name you gave it, its owner, and when it was created. For access control: which devices belong to which group, their role and storage mode, invitations (stored as hashed codes with role and expiry), and a signed log of access changes. Other members of a group you share can see the group name and the names of the devices in it.
Sign-in and device credentials
The service issues tokens that are bound to a cryptographic key held by each device. It stores the records needed to issue and revoke them (identifiers are stored as hashes where possible), a short-lived record of the Google sign-in result while a sign-in completes, and a permanent, append-only list of revoked credentials (identifiers, time and reason) so a revoked credential can never be revived, for example after a database restore.
Operation records
Records of membership operations (such as removing a device) and of forced overrides you perform (device identifier, action, folder group identifiers, time).
Abuse protection
To limit abuse, the service keeps short-lived request counters keyed by the source IP address (and by account). Counters cover a window of about a minute and are cleaned up afterwards.
Logs
The service runs on Cloudflare Workers with Cloudflare’s logging enabled. Logs can contain request metadata (such as IP address and URL path) and error messages that include internal identifiers. They are retained according to Cloudflare’s own settings; I do not define a separate retention period.
Beta invitations
If you join with a beta invitation code, the service stores a hash of the code, its cohort and which account used it.
4. What it does not do
- It never receives file contents, file names, folder paths, or the list of files you sync.
- It has no analytics. Aggregate service metrics are disabled by default; if enabled they are fixed, coarse counters that carry no account, device, IP address or path.
- Optional crash and error reporting is disabled on the service. If it is enabled in future, it is opt-in on your device and accepts only a redacted report: software version and channel, an error category, the subsystem and the top stack frame, with no account attached. Your IP address is used only to rate-limit submissions and is not saved with the report. No automatic deletion period is built in for these reports.
5. Device-to-device transfer
Synced data goes between your authorized devices over end-to-end encrypted connections, directly where possible. When two devices cannot connect directly (for example behind strict firewalls), traffic can pass through public relay servers of the iroh project, which are operated by its developers and not by me. A relay forwards encrypted packets; it can see the IP addresses and device identifiers involved and the timing and volume of traffic, but not file contents. Devices in the same group exchange file names and changes with each other, because that is what syncing is.
6. Updates and downloads
Update manifests and the Linux package repository are served from control.yadori.link, backed by Cloudflare R2; no account is needed. Cloudflare handles those requests as described in section 3 (Logs). Installers are also downloaded from GitHub Releases, which is governed by GitHub’s own privacy statement.
7. Data on your devices
Your synced files, the local sync state and your device credentials are stored on your own devices and are not copied to the service.
8. Why information is used
To provide sign-in, register your devices, let them find each other, enforce who may sync which folder group, prevent abuse, keep the service running and secure, and answer your requests. I do not use it for advertising or profiling.
9. Third parties
- Google: sign-in (identity verification).
- Cloudflare: hosting of this website and the service (Workers, D1 database, Durable Objects, R2 storage) and DNS. Cloudflare operates globally, so data may be processed in countries outside Japan.
- GitHub: source code and release downloads.
- iroh relay servers: packet relaying as described in section 5.
I do not sell your information. I do not provide it to third parties other than the following: the processors listed above; the people you share a folder group with, who can see the group name and device names (section 3); and where required by law.
10. Retention and deletion
Account, device and sharing records are kept while your account exists. The only built-in expiry periods apply to temporary sign-in and invitation records and to the request counters above.
You can request deletion in the CLI (yadorilink account delete request, then confirm) or in the desktop app under “Account & Data…”. After you confirm, there is a grace period (7 days by default) in which you can cancel. When it ends, your account, devices, folder groups you own, their access entries, invitations you created and all credentials are deleted, and devices that you shared with lose access. Folders already on your devices are not touched. Only a marker with a random identifier and a timestamp remains, and revocation records (section 3) are kept. During the beta the automatic final step may not yet be switched on; if your grace period has ended and your account still exists, email me and I will complete the deletion. Cloudflare may keep restorable backups for a limited period under its own policy.
11. Your rights
- Access / export:
yadorilink account export(or the desktop app) gives you a JSON copy of your account, devices, folder groups, sharing entries and account events. - Deletion: as in section 10.
- Correction, disclosure, suspension of use: email me. I will respond after confirming that the request comes from the account holder.
12. Security
Connections to the service use HTTPS. Access tokens are bound to device keys (DPoP), revoked credentials are recorded in a permanent revocation ledger, invitation codes and credential identifiers are stored as hashes, and device private keys never leave the device. Service secrets are held as Cloudflare Worker secrets, and the operator console is reachable only behind Cloudflare Access. No system is perfectly secure; report vulnerabilities to me@juntaki.com.
13. Children
YadoriLink is not directed to children under 16, and I do not knowingly collect their information.
14. Changes
I may update this policy as the software changes. The effective date above shows the latest version; for material changes I will say so on the website or the project page.
15. Contact
Jumpei Takiyasu — me@juntaki.com