Legal
Privacy Policy.
Yenkoh exists to help groups plan trips, not to monetise your data. This policy explains what we collect, why, who processes it on our behalf, and the rights available to people using Yenkoh globally.
Last updated 24 July 2026
Who we are
The data controller is Nigel Atta-Mensah, a sole trader based in the United Kingdom and trading as Yenkoh. We process personal data in accordance with UK GDPR and the Data Protection Act 2018. EU GDPR also applies where we offer Yenkoh to people in the European Economic Area.
Privacy questions and requests: hello@yenkoh.com.
The data we collect
- Account data: your email address, display name, profile photo, biography, sign-in history, and account settings.
- Optional audience details: the home-base city and country, age band, how you heard about Yenkoh, usual travel crew, and gender category you choose to provide. We do not collect an address, coordinates, date of birth, or free-text gender response in this part of your profile.
- Optional travel memory: if you turn on persistent travel memory, we keep short preference notes derived from details you pin, concierge conversations, and completed-trip activity. We record when you opt in, the notice version you accepted, and when you withdraw. Persistent memory is off until you opt in. We do not persist health, disability, religion, pregnancy, sobriety or recovery, sexual-orientation, or similar special-category facts in travel memory.
- Marketing consent: when you choose “Keep me posted”, we record when you gave consent. We use that choice only for Yenkoh's own email updates and may tailor those updates using the optional traveller-profile details you provide. You can withdraw consent at any time from Account or an email unsubscribe link.
- Application answers: the responses you give to questions Q1 to Q4 when you apply for membership, used to review your application.
- Launch waitlist data: your email address, requested tier, cohort, place-in-line status, acquisition source, and whether you opted into occasional product updates. Joining the waitlist does not create an account or take payment.
- Feedback and survey answers: responses you choose to send us about product-market fit, trip planning pains, and what would make Yenkoh more useful.
- Trip data: destinations you propose and vote on, shortlists, schedules, bookings, and trip preferences you share for AI planning (origin, budget, vibes, occasion, notes).
- Trip messages and photos: posts, replies, likes, and images you share in trip chat and on trip pages.
- Local Intel: practical place tips you choose to share, your declared relationship to the place, freshness and helpfulness signals, and moderation reports.
- Ledger data: expenses, amounts, currencies, splits, payment schedules, and who-owes-whom balances within your trips.
- Referral data: your referral code, who applied using it, and the status of any rewards.
- Payment status: your subscription plan, billing interval, and payment state. Card details never touch our servers; Stripe and Onelink collect and hold them. We store customer/subscription identifiers and the billing status Stripe sends us, not the card number or security code.
- Technical data: authentication cookies (see the Cookie Policy), session and anonymous analytics identifiers when you consent, sign-in events, request and error logs, device or browser information supplied in those logs, and one-way hashes of IP addresses used to rate-limit applications, waitlist joins, and sample-plan requests. We do not store the underlying IP address in those application and waitlist records.
Why we use it, and the lawful bases
- To provide the service (accounts, trips, chat, ledger, notifications): performance of our contract with you.
- To review applications and manage launch access: steps taken at your request before entering a contract, and our legitimate interest in operating supported launch cohorts.
- To manage the launch waitlist and reserve places: steps taken at your request before entering a contract, and our legitimate interest in opening cohorts fairly and without exceeding support capacity. Confirmation and place-available messages are service emails.
- To generate AI trip plans from the preferences and trip content you provide: performance of our contract with you.
- To remember preferences across trips: your consent. This optional processing stays off until you enable it. You can withdraw consent from Account at any time without losing access to the rest of Yenkoh.
- To share and moderate Local Intel for members planning the same place: performance of our contract and our legitimate interest in keeping shared guidance useful and safe.
- To process subscriptions and rewards: performance of our contract, and legal obligations around accounting records.
- To send service emails (application decisions, payment receipts and reminders, security notices): performance of our contract and our legitimate interest in keeping you informed.
- To secure and improve the service (logs, abuse prevention, authenticated-session measurement, aggregate product analysis, and AI cost and reliability records): our legitimate interests, balanced against your rights. Optional browser analytics and campaign attribution use your consent instead.
- To understand our audience in aggregate: legitimate interests in improving Yenkoh, planning relevant product and marketing work, and measuring how optional audience details are represented. These details never control access to a feature or a trip.
- To send Yenkoh marketing emails: your consent. We only use optional traveller-profile details to tailor those emails when you have chosen “Keep me posted”. You can withdraw consent at any time.
We do not sell your personal data, and we do not use it for third-party advertising.
Who processes data for us
We rely on a small set of service providers. Some act as our processors, while others act as independent controllers for data they collect to provide their services:
- Supabase: database, authentication, file storage, and realtime infrastructure. This is where your account, trip, message, and ledger data lives.
- Stripe and Onelink: merchant-of-record subscription payments, indirect tax, transaction support, receipts, and order management. Stripe is an independent controller for the payment, identity, billing-address, and support data it collects.
- Resend: transactional email delivery.
- Google: Gemini models generate trip plans and concierge replies; the Places API provides venue search results and photos. Google handles data under its Privacy Policy.
- Mapbox: location search when proposing destinations.
- SerpApi: flight price lookups for trip plans.
- Vercel: application hosting and privacy-respecting analytics.
We share with each provider only the data it needs for its function, and we will update this list if our providers change.
AI processing
When you or a trip admin uses an AI feature, the relevant trip preferences and itinerary content (for example destination, dates, budget, vibes, notes, shortlisted activities, and relevant published Local Intel) are sent to Google Gemini to generate plans and concierge responses. We send what the feature needs, not your whole account. Local Intel is labelled as untrusted member content and may be cited back to its source inside Yenkoh.
If you enable travel memory, relevant non-sensitive memory notes may also be included in a Gemini request so a plan or concierge reply can reflect preferences you asked Yenkoh to remember. Automated memory distillation removes sensitive source material before a request is sent, and proposed sensitive memory is rejected again before anything can be saved.
We do not use your personal data to train AI models, and our agreement with Google for these API services does not permit your prompts to be used to train Google’s models. AI output is stored against your trip so trip members can see it.
International transfers
Yenkoh is operated from the UK. Some providers process data in the UK, the EEA, the United States, or another country. A country may not provide the same legal protections as your home country.
For restricted transfers, we use the safeguard that applies to the transfer: an adequacy regulation or decision, the EU Standard Contractual Clauses, or the UK International Data Transfer Agreement or UK Addendum. We also assess supplementary measures where required. You can ask us for more information about the safeguard used for your data by emailing hello@yenkoh.com.
How long we keep data
- Account and trip data: kept while your account is active. When you delete your account we delete or anonymise your personal data within 30 days, except where we must keep it longer.
- Optional audience details: kept with your account while it is active. You can change or clear them from Account at any time; they are deleted or anonymised with the rest of your account data.
- Optional travel memory: kept while your account and memory setting remain active. Turning memory off immediately stops new learning and use. You can delete individual memory lines or forget all memory at any time; account deletion removes the memory and its consent state.
- Shared trip content: messages and expenses you contributed to a shared trip may persist for the rest of the trip members, with your identity removed, so shared records like the ledger stay coherent.
- Local Intel: published tips can remain available to members planning the same place until you remove them. Hidden, removed, and reported items may be retained for a limited period for moderation, abuse prevention, and audit purposes, with your identity anonymised when your account is deleted where practical.
- Application data: kept for up to 12 months after submission, then deleted or anonymised.
- Launch waitlist data: kept for up to 12 months after your latest waitlist interaction, then deleted. If you create an account, the waitlist handoff record may be deleted sooner when the account is deleted.
- Draft leads: sample-trip drafts and resume links are kept for up to 12 months, then deleted.
- Feedback and survey answers: kept for up to 24 months, then deleted.
- Product analytics and AI usage records: kept for up to 24 months, then deleted automatically. Optional identifiers stored on your device are cleared when you turn that category off.
- Consent records: kept while the related data is active and, where needed, for a limited period afterwards so we can demonstrate and honour your choice.
- Billing records: kept for 6 years after the relevant tax year, as required by UK law.
- Backups: routine encrypted backups roll off on a fixed cycle, normally within 35 days.
Your rights
Under UK GDPR and, where applicable, EU GDPR, you have the right to:
- access a copy of your personal data;
- have inaccurate data corrected;
- have your data erased;
- restrict how we process your data;
- receive your data in a portable format;
- object to processing based on legitimate interests, and to any direct marketing;
- not be subject to solely automated decisions with legal or similarly significant effects (we do not make any).
To exercise any of these, email hello@yenkoh.com. We respond within one month. You also have the right to complain to the Information Commissioner’s Office (ICO) at ico.org.uk or on 0303 123 1113. If you are in the EEA, you may instead complain to the data-protection supervisory authority in the country where you live, work, or believe an infringement occurred. We would appreciate the chance to resolve any concern first.
Security
We use access controls, row-level database policies, encrypted transport, provider-managed encryption at rest, least-privilege service credentials, rate limits, and audit records to protect personal data. No online service can promise absolute security. If a breach creates a risk to people, we assess notification duties and notify the relevant authority and affected people where the law requires it.
Cookies and local storage
We use essential cookies to keep the service working. Optional analytics and campaign attribution stay off unless you choose them. The full list of cookies and similar browser storage, their lifetimes, and how to change your choice is in the Cookie Policy.
Changes to this policy
If we make material changes to this policy we will notify you by email or in the app before they take effect. The date at the top shows when it was last revised.
Contact
Nigel Atta-Mensah trading as Yenkoh, 100A George Street, Croydon CR0 1GP. Email: hello@yenkoh.com.