Just Yuli — Privacy Policy
Draft — to be reviewed by a lawyer before publication. This document is not legal advice. Details in [square brackets] are still to be decided.
This is a translation for convenience. The Hebrew version is the binding one; where the two differ, the Hebrew prevails.
Updated: 20 September 2026
Yuli is a personal assistant that runs on your phone. This document says exactly what is kept, where, and what leaves the device. It is deliberately short: if anything here is unclear, that is our problem.
Who is responsible for the data
A.S. Golans Management and Holdings Ltd, company no. 517094181, Levi Eshkol 6, Modi'in ("the Company", "we"). Privacy enquiries: rafig@xspirit.co.il. This policy is written under the Israeli Protection of Privacy Law, 5741-1981, and its regulations.
The principle: your content stays on the phone
All of your content is stored on your phone alone, in an encrypted database. We have no server that holds it, and we have no copy.
That includes the messages she read, what she summarised, mail, the calendar and reminders, the shopping list, the contacts you tagged, what she learned about you, documents and reports, recordings, and your settings. Uninstalling the app deletes all of it.
We see none of it. We have no way to see it.
What is stored with us (Supabase)
To run accounts and subscriptions, the Company uses Supabase (servers in the European Union, Frankfurt). There, and only there, the following are stored:
| What | Why |
|---|---|
| Identity: account id, e-mail address, display name, sign-in method (e-mail and password, or Google) | Signing in and password recovery |
| Devices: the app's device id, model, app version, last use | Support, and preventing abuse of the account |
| Daily usage counts: number of model calls, seconds of speech, number of searches — numbers only | Daily quota and costs |
| Subscription: type, validity, payment status | Billing and cancellation |
| Problem reports you sent yourself: version, the sentence you wrote, and a redacted technical log | Fixing faults |
| Shared technical log (only while the "share the technical log with Rafi" switch is on): redacted technical lines, and a redacted crash report | Fixing faults for testers |
The password is stored at Supabase as a hash, not as text. Credit card details, if any, are kept only by the payment provider, not by us.
Never stored there: messages, mail, calendar, memories, contacts, documents, recordings or any other content of yours. The app does not write content there, and whoever runs the service sees only the table above.
What does leave the phone, and where to
To understand what was said and to answer in Hebrew, Yuli sends the minimum needed to these services, and nowhere else:
| To | What is sent | When |
|---|---|---|
| Anthropic (Claude) | The text of what you said, and of a message or mail that arrived — to classify, summarise or draft a reply. For mail with an attachment (PDF, Word, Excel, text): only the text extracted from it on the phone, from the start of the file up to about 6,000 characters — not the file itself | On every turn with her, and on every incoming message |
| ElevenLabs — transcription (only if you turned on "listen to voice messages", or shared a voice message with her) | The recording of a voice message, to turn it into text. No copy of it is kept by Yuli | When a voice message arrives in WhatsApp, or when you shared one |
| Anthropic — web search | The search words of a question you asked her to check, or of a piece of research you asked for — with no personal detail you did not say yourself | When you asked something that is not on the phone, or asked for a comparison or a report |
| ElevenLabs | The sentence she is about to say, to turn it into speech | On every sentence she says |
| Android speech recognition (usually Google) | Your voice while the microphone is open | When you speak to her |
| Google — Gmail (only if you connected it) | Read and send requests in your own mailbox | When she checks mail, or sends a reply you approved |
| Google Drive (only if you turned on backup) | An encrypted backup file, to a hidden app folder | Once a night, on charge and on Wi-Fi |
| Google Drive (only if you turned on "a copy in Drive" for reports) | The PDF of a report she prepared, to the folder "יולי - דוחות" | When a new report is ready |
| Meta — Facebook and Instagram (only if you connected a page) | Read requests for comments and messages on your page, and a post or reply you approved | When she checks the page, and when you sent something you approved |
| Open-Meteo | Rounded coordinates of the place you asked about (or of your location, if you asked "what's the weather") | When you asked about the weather |
| Bank of Israel / Frankfurter | The name of the currency only | When you asked about an exchange rate |
| Dicta (only if you turned on "automatic vowelling", experimental) | The sentence she is about to say, for vowelling | On every sentence she says |
| Supabase | Only what is in the "what is stored with us" table | On sign-in, once a day for the usage count, and once an hour for the technical log if the switch is on |
Not sent: your message history, your contact list, your calendar as a document. Anthropic and ElevenLabs do not train models on what is sent to them in this use, under their commercial terms [to be verified against the current contracts].
Gmail and Google: Yuli's use of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements. The information is used only to show you and summarise your own mail and to send what you approved; it is not passed to others, not used for advertising, and not read by humans. Attachments: an attachment to a mail she summarises is downloaded to the phone's memory only to extract text from it, and is not stored anywhere. The extracted text is kept encrypted in the app's cache for 24 hours (so she can answer "what does the document say?"), and is then deleted. Files over 10MB and images are not opened at all.
What does not happen
- Yuli does not record in the background. The microphone opens only when you touched her, and closes when you are done. ("Hey Yuli" — an experimental wake word, off by default — is recognised on the phone itself, and no sound leaves it.)
- Yuli sends nothing in your name without explicit approval — she always reads the draft out and asks "send it?".
- There are no ads, no tracking, no usage analytics, and no sale or transfer of information to a third party.
- Problem report: if you press "report a problem", a technical log is sent with every personal detail removed from it — all Hebrew text and every quotation are replaced with
[...]. You see what is being sent before it is sent. - Sharing the technical log (Settings → Help → "share the technical log with Rafi"): in the tester build the switch is on by default, and can be turned off at any moment. While it is on, once an hour, immediately after a crash and after "report a problem", the technical log of the last hours is sent to Supabase, compressed, up to 200KB. What is sent: versions, times, errors, and which part of the app ran. What is never sent: the content of messages and mail, names, phone numbers, e-mail addresses, file paths and any Hebrew or quoted text — all replaced with
[...]on the phone, before sending. Each account writes only to its own folder, and only the service administrator reads it. No line written before the switch was turned on is ever sent. The log is deleted after 14 days.
Permissions, and why
- Notification access — to read incoming messages and answer through them. Without it she hears nothing.
- Microphone — to talk to her.
- Notifications — to tell you something is waiting.
- Floating window — the bubble.
- Contacts — to know who wrote and whom to send to. The list never leaves the phone.
- Calendar (optional) — to see and write in the phone's calendar.
- Location (optional) — only if you saved "home" or "work" for a shopping reminder, or asked about the weather here.
- Gmail (optional) — reading and sending only. She does not label, delete or forward anything.
- A Facebook and Instagram page (optional) — only if you connected a business page of your own. Signing in happens on Meta's own page, in a browser tab; your password does not pass through us, and what is stored on the phone is an access token only. She reads comments and messages on the page, and posts or replies only after you approved. You can disconnect at any moment in Settings → Connections, and the token is then deleted from the phone.
Add-ons (beta, off by default)
Two add-ons run only if you turned them on in Settings → Add-ons, after an explanation. They can be turned off at any moment.
Automatic sending — an accessibility service. Android lets an app with an "accessibility service" see what is on the screen and press on the user's behalf. Yuli uses this only to press "send" in WhatsApp or in SMS, after you said "yes" to a particular draft: the service turns on for at most 15 seconds, looks only at that contact's chat screen, presses, checks the message went out, and returns. It does not read other screens, does not store what is on the screen, and sends nothing from it anywhere. Only a log of the sends (when, to whom, whether it worked) is kept in the app — on the phone alone.
Listening to voice messages and documents in WhatsApp — all-files access. To summarise a voice message or a document that arrived in WhatsApp, Yuli needs to read the file WhatsApp saved on the phone. The "all files access" permission lets her. She uses it only to find the file of the notification that just arrived (by name, time and length), in WhatsApp's media folders alone. A voice recording is sent for transcription (ElevenLabs), and a document is read on the phone and only its text is sent to Anthropic for a summary. Yuli keeps no copy of the file, and does not go to photos, videos or other files. Only a length and a file name are written to the technical log, never content.
Backup
The backup is encrypted on the phone before it goes up, with a key derived from the password you chose. We cannot open it, and neither can Google. If you forgot the password, the backup is lost — there is no way to recover it.
How long data is kept
- On the phone: until you delete it in the app, or delete the app.
- With us (Supabase): account and subscription details — as long as the account is active, and a further [90] days after it is closed (or longer if the law requires, for example accounting records — [7] years); usage counts — [24] months; problem reports — [12] months; shared technical log — 14 days.
- With the service providers: under their own policy for API use; for example Anthropic keeps requests for a limited period for security purposes [to be verified].
Your rights
- Access and correction: you may ask to see what is kept about you with us, and to correct it.
- Deletion: you may ask to delete the account and everything kept about it in Supabase. It is deleted within [30] days and we confirm by e-mail. The content on the phone is deleted when you delete it in the app or delete the app.
- Withdrawing permissions: every permission can be revoked in Android settings; the feature that leans on it simply stops working.
- Enquiries: rafig@xspirit.co.il. If you are not answered, you may approach the Israeli Privacy Protection Authority.
Security
The database on the phone is encrypted (SQLCipher), and the key is kept in the Android keystore. All traffic is encrypted (HTTPS). At Supabase, each user can reach only their own rows (Row-Level Security). No method is completely proof; if we learn of a security incident touching your data, we will notify you and the authority as the law requires.
Children
The app is not intended for children under [18], and we do not knowingly collect information about them.
Changes
If anything here changes, it will appear here and inside the app before the change takes effect.
Contact
A.S. Golans Management and Holdings Ltd · Levi Eshkol 6, Modi'in · rafig@xspirit.co.il
© 2026 A.S. Golans Management and Holdings Ltd. All rights reserved.