Privacy
What we collect, why we are allowed to, and what we will never do with it.
Last updated 11 September 2026
The short version
- We collect what we need to run your account and your workspace, and very little beyond that.
- Our investor catalog holds business-context information about investors in their professional capacity, compiled from public and licensed sources. If that is you, you can have it corrected or removed, and you do not have to give us a reason.
- We do not sell your data. We do not sell access to you. We never tell an investor who has been looking at them.
- No advertising cookies, no third-party trackers, no consent banner — because there is nothing to consent to.
The rest of this page is the detail. It is written to be read rather than survived; if any of it is unclear, email privacy@yellowtail.club and we will explain it properly.
Who we are
Yellowtail provides investor research and fundraising software, and is operated from the United Kingdom. For everything described on this page, Yellowtail is the data controller — except for the content you put into your own workspace, where you are the controller and we process it on your behalf. Reach us about any of it at privacy@yellowtail.club.
What we collect from you
- Account data. Your name, email address, and the workspace and projects you belong to. We need this to give you an account and to know what you are allowed to see.
- What you put in. The companies, people, lists, pipelines and notes you create in your workspace. This is yours; we store it so the product works.
- Access requests. If you use the request-access form, we keep what you typed — your name, email, company and the answers you gave — so we can reply and decide whether we can help.
- Support correspondence. Emails you send us and our replies, so a conversation does not have to start again every time.
- Technical logs. Standard server logs, including IP address and browser user agent, kept briefly for security and debugging.
Why we are allowed to use it
Under UK and EU data protection law we need a lawful basis for each thing we do. Ours are:
- Performing our contract
- Running your account, hosting your workspace, keeping you signed in, and supporting you when something goes wrong.
- Legitimate interests
- Keeping the service secure and working, compiling and maintaining the investor catalog, understanding which parts of the product get used, and contacting you about your account. We have weighed each of these against your rights and you can object at any time.
- Your consent
- Anything optional we ask you for outright, such as marketing email. You can withdraw it whenever you like, and withdrawing it does not affect anything done beforehand.
- Legal obligation
- Keeping records we are required to keep, and responding to lawful requests from an authority.
The investor catalog
Most of the personal data we hold is not about our customers. It is about investors — the partners, principals and analysts at investment firms — because that catalog is what the product is for. We would rather be precise about it than vague.
What we hold. For a person in the catalog we may hold their name, job title, employer, public professional profiles and accounts, the sectors, stages and geographies they work in, and the investments and public statements attributed to them. It is information about people acting in a business capacity, not about their private lives. We do not collect special-category data and we do not want it.
Where it comes from. Public and licensed sources: company websites and team pages, regulatory and company filings, funding announcements and the trade press, public professional profiles, public posts on platforms such as X and LinkedIn, conference and event listings, and published interviews and podcasts. Where a customer adds a contact of their own, that record stays inside their workspace and is not added to the shared catalog.
Our basis for it. Legitimate interests. Investors publish this material in order to be found by founders, founders need it in order to raise money, and keeping it in one accurate, dated place is the entire point. We have documented that assessment and will share it on request.
If you are in it and would rather not be. Email privacy@yellowtail.club. You can ask what we hold, have it corrected, have it deleted, or object to being in the catalog at all. We do not require a reason, we will confirm when it is done, and we will not quietly put you back at the next refresh.
How signals are put together
We use automated systems, including large language models, to read public posts and articles, judge whether they say anything meaningful about investment intent, and turn what does into a signal with a date and a link to the source. The same systems suggest tags and contribute to a fit score.
Three things worth saying about that. Outputs are suggestions attached to a source you can open, not conclusions you are asked to take on trust. The providers we use are contractually barred from training their models on what we send them. And nothing in the product makes a decision that produces a legal or similarly significant effect on anyone — a fit score is a reading recommendation, and a person decides what to do about it.
What we will never do
- Sell your personal data, or your workspace content, to anybody.
- Sell access to you. Investors cannot pay to appear in your results, and there is no paid placement anywhere in the catalog.
- Tell an investor that you looked at them, added them to a list, or moved them along a pipeline.
- Use your workspace content to train a third party model, or let private notes in one workspace influence results in another.
- Run advertising trackers, build ad audiences, or hand your data to a data broker.
Who processes data for us
Only the providers we need in order to operate. Each is bound by a data-processing agreement to act on our instructions and nothing else.
- Vercel
- Hosting for this site and the application.
- Supabase
- Our database and authentication provider — where your account and workspace data lives.
- Trigger.dev
- Runs our scheduled background work, including keeping the catalog up to date.
- Cloudflare
- Network protection, and object storage for the raw source material sitting behind a signal.
- Collection and language-model providers
- Gather public material and classify it into signals. Bound not to train on what we send, and not to retain it beyond the request.
- Email delivery
- Sends the transactional mail the product depends on: sign-in, invitations, and account notices.
We keep this list current rather than hiding behind a category. If you would like to be told when it changes, email privacy@yellowtail.club and we will add you to that note.
Where it is held, and for how long
- Workspace and account data
- Kept while your account is open, then deleted within 30 days of closure — a short window so an account closed by mistake can still be recovered.
- Catalog records
- Kept while the information remains accurate and relevant, and revisited as the sources change. Removed on request.
- Raw source material
- The original post or page behind a signal, kept up to 12 months so a signal can be re-checked or reclassified without going back to the source.
- Access requests
- Up to 24 months, so we can pick a conversation back up where it left off.
- Technical logs
- Up to 90 days.
- Backups
- Encrypted, on a rolling 35-day cycle. A deletion reaches the backups as they age out.
Data is stored on infrastructure in the European Union and the United States. Where personal data leaves the UK or the EEA it moves under the UK International Data Transfer Addendum or the European Commission's standard contractual clauses, with a transfer risk assessment behind it.
How we protect it
Every workspace is isolated in the database itself, by row-level security policies that Postgres enforces — not by application code remembering to check. A query that asks for another workspace's rows comes back empty. It is the most important control we have, and it is deliberately the one furthest from a developer's mistake.
Around that: encryption in transit and at rest, production access limited to a named handful of people and protected by multi-factor authentication, secrets held in a managed store, and review before anything ships. If a breach affects personal data we will notify the relevant supervisory authority within 72 hours, and tell you without undue delay where the law requires it — or where you would obviously want to know.
Your rights
Whether you are a customer or someone in the catalog, you can ask us for:
- Access — a copy of what we hold about you.
- Rectification — correction of anything wrong or out of date.
- Erasure — deletion, where we have no overriding reason to keep it.
- Objection — an end to processing we base on legitimate interests, including being in the catalog at all.
- Restriction — a pause while a disagreement is worked out.
- Portability — your workspace data in a machine-readable form. You can also export it yourself from inside the app.
Email privacy@yellowtail.club. We will respond within 30 days and we do not charge for it. If you are not satisfied with the answer you can complain to the Information Commissioner's Office in the UK, or to your national supervisory authority in the EU — though we would much rather you told us first and gave us the chance to fix it.
Cookies
We set the cookies the product needs to function and nothing else: a session cookie so you stay signed in, and a preference cookie that remembers whether you chose light or dark. Both are first-party, and neither follows you anywhere. We do not use advertising cookies and we do not run third-party trackers on this site.
Children
Yellowtail is a business tool and is not intended for anyone under 18. We do not knowingly collect data about children; if you believe we have, tell us and we will delete it.
Changes
If we change this notice in a way that matters, we will tell account holders by email before it takes effect and say plainly what changed. The date at the top always reflects the current version, and we keep the previous ones if you would like to see what moved.
Questions, requests, corrections and complaints all go to the same address: privacy@yellowtail.club. A person reads it.