This Privacy Policy explains how Brick and Yarn, LLC ("Y2K," "we," "us," or "our") handles information through the y2k: 2000s photo editor App, y2kapp.com, support communications, and related services.
1. Key privacy points
- Photo and video editing occurs on your device. The editing workflow does not upload imported media to Y2K.
- The App uses Google Firebase Analytics for pseudonymous usage and reliability measurement and contacts remote services to obtain stickers and catalog data.
- Images or stickers you choose to save can remain in the App's local storage after you close it. Saving a custom sticker does not publish it to other users. An explicit community submission sends the chosen edited sticker to our servers for review. Suggested hashtags are generated on your device; this does not upload your sticker.
- Apple processes App Store payments and Google processes Google Play payments. Y2K does not receive your full payment-card details.
- The website uses privacy-oriented Vercel Web Analytics and Vercel hosting logs.
- If you submit a sticker report, Y2K receives the selected catalog identifier and reason plus limited app, locale, and anti-abuse data. If you choose Other problem, you also send a brief explanation; the report does not include your imported media or the sticker image.
- If you apply for a role, Y2K receives the contact details, responses, links, and, for Head of Growth, Product Intern, or General applications, the resume you submit.
- The Services do not contain third-party advertising.
2. Photos, videos, projects, and device storage
When you select a photo or video using your device's media picker, the App receives the item you choose so it can edit it locally. Temporary media copies may be created in the App sandbox while you edit or export. If you choose to save a creation to the in-App gallery or save a custom sticker, the file and basic metadata such as a local identifier, filename, date, and aspect ratio are retained on your device until you delete them or uninstall the App.
Device-stored data may be included in device or cloud backups according to your settings. If you share an output, your device's sharing services and the destination you select handle it under their own terms. Y2K does not automatically receive the media you share.
On-device sticker tag suggestions
y2k analyzes the sticker on your device to suggest hashtags from our catalog vocabulary. The sticker is not sent to an AI service for this analysis. On Android, Google Play services may download the image-labeling model to your device before suggestions become available. Google’s ML Kit SDK also collects device and app information, identifiers, and performance and usage diagnostics, including model-download and labeling events. This is separate from the sticker image, which stays on your device for tag analysis.
Suggestions are optional. They do not publish your sticker or change your caption unless you select them. Only choosing to post sends your edited sticker and submission details to our servers for review.
Community accounts and submissions
When you choose to sign in, Supabase and your sign-in provider process your account identifier, email (including a private relay address when provided), authentication credentials or tokens, and basic provider profile data. We use these to authenticate you, protect your account, and manage submitted stickers. We do not display your account name or email in the catalog. Email sign-in uses a one-time code rather than a y2k password; Cloudflare delivers these sign-in emails. Provider access needed for account deletion is protected on our servers.
Submitting sends only your chosen edited sticker, caption, title, and tags. We record your rights confirmation, accepted policy versions, submission dates, review decisions, and status. The standard sign-in and posting flows do not ask for your date of birth or country of residence; accepting the Terms is not a verified age check. Supabase stores account and moderation data. Cloudflare processes submitted images, and Cloudflare and Bunny.net store normalized sticker copies in private storage. Authorized reviewers use our Vercel-hosted dashboard. We strip image metadata when generating catalog images and do not retain the unprocessed upload as a separate original. Approved artwork and moderator-reviewed catalog metadata are delivered publicly. We keep the contributor’s caption and hashtags separately from the public catalog fields, which reviewers can edit to improve search.
Community reports contain the sticker reference, category, optional details, and whether you reported a sticker or contributor. You can report without an account; the app does not attach your sign-in identity to the report. Network providers receive ordinary request metadata; a salted network hash is used for rate limiting. Report receipt secrets, hidden-sticker choices, and guest contributor blocks remain on your device. If you sign in, contributor blocks can also be stored with your account. Community search queries are sent to our search service to return results; they are not added to our custom analytics events.
You may make a submitted sticker private through its options in Profile → Stickers. Request account deletion in Settings → Delete Account or through our account deletion page. New access to your community stickers stops when an authenticated deletion request is accepted. A background process removes associated active image files, captions, titles, hashtags, original submitted metadata, consent and account records, and provider credentials. Caption and hashtag changes kept in routine moderation history are also cleared. Your private device library is kept. Deletion does not cancel an Apple or Google subscription, erase other users’ exports, or immediately erase provider backups. Limited pseudonymous moderation, security, and legal records may be retained for the purposes and periods described below.
3. App analytics and identifiers
The App initializes Google Firebase Analytics. Firebase Analytics may process a randomly generated app-instance identifier, a device vendor identifier where available, app and OS version, device category, language, approximate region derived from network information, session and screen activity, and automatically measured purchase or subscription events.
Y2K also records events such as onboarding progress, paywall views and selections, subscription plan and trial-eligibility state, successful purchases, catalog refresh outcomes, provider reliability, and cache performance. We use this information to understand feature use, diagnose failures, maintain the catalog, and improve the Services. Our custom catalog telemetry is designed not to include imported media, search text, sticker filenames, asset URLs, or payment-card details.
4. Catalog and sticker delivery
The App requests catalog information and sticker files from Y2K's infrastructure and content-delivery providers, including Cloudflare, Bunny.net, and, in earlier app versions, Google Firebase. Those requests can involve IP address, timestamp, requested URL or asset identifier, response status, and standard network/device headers. Sticker manifests and assets may be cached on your device for performance and offline resilience.
5. Purchases and subscriptions
Apple's StoreKit and App Store process iOS y2k plus purchases; Google Play Billing processes Android purchases. The applicable store handles payment credentials. The App receives product and localized price information, offer eligibility, purchase or entitlement information, and subscription state to unlock features, restore purchases, and measure subscription performance. Apple's and Google's privacy notices govern their respective processing.
6. Website analytics and hosting
y2kapp.com is hosted on Vercel and uses Vercel Web Analytics. Analytics data may include page or route, timestamp, referrer, filtered query parameters, coarse geolocation, browser, operating system, and device type. Vercel Web Analytics does not use third-party cookies and uses a request-derived visitor hash that resets daily. Vercel's hosting and security systems may separately process IP addresses and request logs.
7. Support, legal notices, and sticker reports
If you email support, send a legal notice, or otherwise contact us, we receive the information you provide, such as your email address, name, message, attachments, and relevant technical details. We use it to respond, investigate, protect rights and safety, and comply with law. A copyright notice may also include a mailing address, telephone number, signature, statements about authority and accuracy, identification of protected works, and locations of the material at issue.
For premium stickers and earlier catalog versions, the App sends a one-time report identifier, a random app-install identifier, the catalog sticker and release identifiers, the selected reason, app version and build, and locale. Delivery infrastructure also receives ordinary network and security metadata such as IP address and request headers. Y2K stores the report and moderation history together with keyed, one-way hashes of the app-install and network identifiers for abuse prevention. If you select Other problem, the reporting flow requires a normalized explanation of 1–500 characters so authorized reviewers can understand and investigate the concern. The reporting flow does not send the sticker image, your imported media, your name, or your email address unless you type such information into that explanation field. Do not include sensitive, private, financial, medical, account, or contact information. Do not send copies of suspected child sexual abuse material; identify the sticker instead.
8. Career applications
If you apply through our Careers pages, we receive your name, email address, application responses, and any social, portfolio, or personal website links you choose to provide. Head of Growth, Product & Engineering Intern, and General applications also require a resume. Do not include sensitive information that is not relevant to evaluating your application.
We use application information to evaluate your candidacy, contact you, administer our hiring process, prevent submission abuse, protect our systems, and comply with law. Delivery infrastructure processes ordinary network metadata; before storage, Y2K converts the requesting network address into a server-salted, one-way hash used for rate limiting and does not store the raw address with your application.
Application responses and resume metadata are stored in Supabase. Resume files are stored in a dedicated private Cloudflare R2 bucket and are available only to authorized Y2K staff through our protected Vercel-hosted internal dashboard. We retain them while considering the application, for a reasonable period for future opportunities, and as needed for legal, security, or recordkeeping obligations. You may request deletion or correction by emailing [email protected] with “Careers Privacy” in the subject, subject to applicable retention duties.
9. How we use information
- provide editing, catalog, purchase, export, and support functions;
- authenticate software responses and protect service integrity;
- measure reliability, usage, subscriptions, and product performance;
- debug errors, prevent abuse, and secure the Services;
- investigate safety, privacy, and intellectual-property reports; and
- comply with law and enforce our agreements.
Depending on your location and the activity, our legal basis may be performance of a contract, your consent, our legitimate interests in operating and improving the Services, or compliance with legal obligations.
10. When information is disclosed
We disclose information to service providers that operate the Services, including Apple, Google Play, Google Firebase, Cloudflare, Bunny.net, Supabase, Vercel, and communication providers; when you direct us to share an export; to professional advisers under appropriate duties; in a corporate transaction; or when reasonably necessary to comply with law, prevent harm, or protect rights and security.
For sticker reports, Cloudflare processes the request in transit, Supabase stores the bounded report record and the corresponding Other explanation, and authorized Y2K reviewers access report details through the Vercel-hosted internal dashboard. Access is limited to personnel and providers who need it for moderation, security, legal compliance, or service operation.
For legal-rights complaints, we may share the notice and relevant correspondence, including identifying and contact information, with the person or provider responsible for the material and professional advisers when reasonably necessary to investigate and respond. Avoid including unrelated sensitive information in a notice. We do not promise anonymity for a legal notice.
We do not sell personal information or use App information to show third-party ads in the App. We do not send imported photos or videos to analytics providers. On-device tag suggestions do not upload your sticker. Explicit sticker submissions described above are separate from analytics.
11. Retention
Local gallery items, saved stickers, settings, recents, and caches remain on your device until you delete them, clear them through available App controls, uninstall the App, or the operating system evicts cache data. Device or cloud backups may retain copies under the applicable backup provider's policies and your settings.
Analytics, hosting logs, purchase records, and support or legal communications are retained for the periods reasonably needed for the purposes above, under configured provider settings, and as required by law. Firebase Analytics event-level retention and deletion are governed by our Analytics settings and Google's controls; aggregated reports may remain after event-level data expires. Vercel's analytics visitor hash resets after 24 hours, while aggregated page statistics may be retained longer.
We ordinarily keep a rejected or moderation-removed sticker privately for up to 30 days so we can review an appeal; it is not available in the public catalog. Withdrawals and account-deletion requests enter a shorter background cleanup process. A documented legal preservation requirement can delay deletion of a specific item. An unfinished upload expires after 24 hours. Required backups may take longer to expire under provider policies.
Sticker reports, moderation decisions, and related audit history are retained for as long as reasonably necessary to investigate the report, protect users and rights holders, prevent repeated abuse, resolve disputes, and comply with legal obligations. The explanation submitted with an Other problem report is retained and access-controlled with the report record for those purposes. Anti-abuse hashes are not intended to identify you directly and are retained only for those security and integrity purposes.
12. Your choices and privacy rights
- Use your device's photo picker and permission settings to limit or revoke media-library access.
- Delete in-App gallery items and saved stickers with App controls.
- Manage y2k plus through Apple Account or Google Play subscription settings, depending on where you purchased.
- Contact [email protected] with "Privacy" in the subject to request access, correction, deletion, or to exercise other applicable privacy rights.
Depending on where you live and the processing involved, you may also have the right to object to or restrict processing, receive or transfer certain personal information in a portable format, withdraw consent where processing relies on it, and complain to your local data-protection authority. Withdrawing consent does not affect processing that was lawful before withdrawal. These rights are subject to applicable legal conditions and exceptions.
The current App does not provide an in-App Firebase Analytics opt-out. Account identity is not automatically linked to all analytics records, so we may need a relevant app-instance identifier to locate pseudonymous analytics data and may not be able to connect it to your name or email. We will honor verified requests as required by applicable law.
13. International processing
Y2K and its providers may process information in the United States and other countries whose laws may differ from yours. Where required, we use contractual or other legally recognized safeguards for international transfers.
14. Security
We use reasonable technical and organizational measures designed to protect information. No storage or transmission method is completely secure, so we cannot guarantee absolute security.
15. Children
The Services are intended for people age 13 and older and are not directed to children under 13. Do not create an account or submit content if you are under the applicable minimum age. Minors must have their parent or guardian review and agree to the Terms where required. If you believe a child under 13 has provided information to us, contact [email protected] so we can investigate and take appropriate action.
16. Changes to this Policy
We may update this Policy as the Services or law change. We will post the revised Policy with a new effective date and provide additional notice when required, including before materially expanding our collection or use of personal information.
17. Contact
Brick and Yarn, LLC
Website: www.y2kapp.com
Privacy and support: [email protected]
Copyright notices: [email protected]