Privacy Policy

We reserve the right to modify or replace these Terms of Service at any time at our sole discretion. In the event of a significant change, we will notify you through on-site announcements or via the email address associated with your account. Please note that any updated terms will not be considered accepted until you manually review and provide your explicit consent upon your next visit to the site. If you choose to decline the updated terms, you will be prompted for a final confirmation, after which your account and all associated data will be permanently deleted from our systems.

calendar_clock

latest update

Mar 02, 2026

YokaiVerse incorporates a "Privacy-by-Design" architecture as its core operational philosophy. We believe that digital privacy is not a feature but a fundamental right; therefore, our entire infrastructure is built to ensure that sensitive user data remains exclusively under your own control through advanced encryption and minimalist data collection practices.

End-to-End Encryption (E2EE) & Zero-Knowledge Storage

Our commitment to security begins at the source. All personal data is subjected to local encryption on your device before it ever reaches our infrastructure. By utilizing a Zero-Knowledge Storage model, YokaiVerse servers only host encrypted strings for which we do not possess the decryption keys. This ensures that neither our staff nor any third-party entities can access or read your private information in plain text under any circumstances.

Data Collection, Usage & Algorithmic Privacy

YokaiVerse strictly limits data collection to what is necessary for platform integrity. We maintain mandatory security logs, including IP addresses and login timestamps, solely for the purpose of fraud prevention and security auditing. While diagnostics and error reports are disabled by default, users may manually opt-in to assist our technical troubleshooting. Furthermore, while we record site actions to improve your navigation experience, this algorithmic tracking remains entirely optional and can be deactivated through account settings at your discretion.

Secure Handling of Third-Party API Keys

When you integrate your own AI provider keys (such as OpenAI or Gemini), YokaiVerse treats this data with the same rigorous encryption protocols applied to personal information. We function as a secure bridge; we do not log the content of the requests sent to your AI providers, nor do we store these keys in a format accessible to our internal systems.

Data Retention, Purge Cycles & Permanent Deletion

We adhere to a strict "right to be forgotten" policy. Upon a user's request to delete their account, a 15-day window is initiated during which all encrypted personal information and metadata are permanently and irreversibly destroyed. For active accounts, we maintain a 30-day purge cycle where non-essential behavioral data and temporary security logs are automatically wiped. Once these periods conclude, data recovery is technically impossible as both the encrypted strings and associated keys are removed from our infrastructure.

Third-Party Disclosures & Contextual Advertising

YokaiVerse maintains a strict policy against the sale of user data. To support the platform, we may share aggregated, non-identifiable information with advertising partners. These advertisements are strictly contextual, meaning they are served based on the content currently being viewed rather than individual user tracking or behavioral profiling.

Parental Control & Minor Safety

For users under the age of 18, YokaiVerse implements a transparent safety framework. When a Parental Control link is active, specific usage data—including watch history and search terms—will be accessible to the linked Parent/Guardian account. By opting into a Minor account, the user and their legal guardian consent to this visibility, which is designed to ensure a safe digital environment for younger audiences.

Policy Updates & Mandatory Consent

To ensure our users are always informed, any update to this Privacy Policy will trigger an automatic reset of all consent states. Upon your next login following an update, you will be required to review the revised terms. You will have the choice to either accept the new policy to continue your service or decline the changes, which will immediately initiate the 15-day permanent deletion process for your account and all associated data.

International Data Transfers & BYOK Responsibility

Through our "Bring Your Own Key" (BYOK) feature, content translation is processed by third-party AI providers according to your specific API configurations. By providing these keys, you acknowledge that your data may be processed in jurisdictions outside of your residency. YokaiVerse acts solely as a technical intermediary and assumes no liability for the data handling practices of these external providers.

8.1

User-Side Security & Self-XSS Prevention

Through our "Bring Your Own Key" (BYOK) feature, content translation is processed by third-party AI providers according to your specific API configurations. By providing these keys, you acknowledge that your data may be processed in jurisdictions outside of your residency. YokaiVerse acts solely as a technical intermediary and assumes no liability for the data handling practices of these external providers.

KVKK Compliance & Data Subject Rights

As a Türkiye-based project, YokaiVerse operates under the exclusive jurisdiction of the Law No. 6698 on the Protection of Personal Data (KVKK). Regardless of your physical location, you acknowledge that your data is processed in accordance with Turkish legal standards. Users hold the right to information, correction, and erasure as outlined in Article 11 of the KVKK. Please note that due to our E2EE architecture, we cannot provide "plain text" versions of your data in response to access requests, as we do not possess the means to decrypt it.

Law Enforcement Cooperation & Legal Necessity

In compliance with the judicial and executive bodies of the Republic of Türkiye, YokaiVerse will provide available security logs (IP addresses and timestamps) if presented with a valid legal warrant regarding cybercrime or fraud. Our ability to cooperate is limited by our 30-day purge cycle; we can only provide logs that exist at the time of the request. While behavioral data is purged quickly, basic security logs may be retained longer if mandated by local law or necessary for investigating significant security breaches.

Hybrid Storage Architecture

We utilize a two-tier storage system designed to balance security with performance without the use of marketing cookies. Tier 1 consists of Security-Critical Cookies (Session Tokens, Encryption Keys, and API Keys) which are encrypted and protected with HttpOnly, Secure, and SameSite=Strict flags to prevent XSS attacks. Tier 2 utilizes Local Storage for non-sensitive preferences, such as Dark Mode settings, video player configurations, and UI layouts, ensuring a seamless and personalized experience upon every visit.

Data Breach Notification & Global Standards

In the event of a security compromise, YokaiVerse is committed to notifying affected users and relevant data protection authorities within the timeframes mandated by local and international regulations. While anchored in KVKK, we respect the fundamental principles of the GDPR (EU) and CCPA/CPRA (USA), offering data portability and erasure rights to all users globally to ensure that our Turkish legal base never compromises the security of our international community.