Skip to content
YGFBowl-to-Build
How it worksFAQRedeem

Privacy notice

YGF processes only the information needed to provide this promotional AI service, deliver wallet access, prevent fraud, and restore access.

Do not submit SSNs, payment card numbers, medical data, or confidential school information.

What YGF processes

YGF processes an account identifier, redemption activity, and prompts you submit to provide this promotional AI service. A scan-first guest wallet uses a Supabase anonymous user identifier; YGF receives an email only if you later link or use an email-based account.

History stores task type, generated title, an optional user-saved result, usage, and timestamps.

If you create a developer key, YGF stores a keyed digest, a short prefix and last four characters, ownership, expiry, revocation, and usage/accounting records. YGF does not store the full plaintext key.

Agent request accounting stores a keyed request fingerprint, selected allowlisted model, status, credits, provider cost, and timestamps. The raw request prompt is not stored in a separate database column.

Why it is processed

This information is used to provide the promotional AI service, deliver wallet access, prevent fraud, and restore access.

Sharing

Supabase processes authentication, account identifiers, and campaign database records on YGF’s behalf.

To generate a website or Agent result, YGF sends the prompt you submit, a non-PII HMAC safety identifier, and the minimum request context needed directly to OpenAI. OpenAI processes that request to return an output. The OpenAI credential remains on YGF’s server.

The privacy and staff issue-report forms send the email and request text you enter to Formspree. Formspree may also process technical request data under its own privacy terms while delivering the message to YGF.

Current retention facts

HMAC-derived abuse signals rotate every five minutes. Persisted redemption-attempt rows have an explicit per-record expiry. Raw IP addresses and full plaintext codes are never stored.

Event metadata has a 90-day retain_until default.

Wallet credits expire after 14 days, but that is not the same as record deletion.

Raw request prompts are not stored in a separate prompt column. Saved web outputs persist when explicitly saved.

YGF sends store:false with OpenAI Chat Completions, which disables application-state storage but is not a zero-retention promise. OpenAI's default abuse-monitoring logs may retain request content for up to 30 days. OpenAI API data is not used for training by default unless the account opts in. Zero Data Retention is not claimed as configured.

A successful Agent response payload is stored in Postgres for a logical 15-minute idempotent replay window. A provider response can repeat or echo submitted input, so the replay payload can contain text derived from the request even though the raw request prompt is not stored as its own field.

After the logical replay window expires, response payload tombstoning is lazy and may be delayed while the gateway is idle. A reviewed, indexed, bounded scheduled cleanup job is still a production launch gate and is not claimed as configured.

Personal API key plaintext is returned only when a key is created or rotated. Only its keyed digest and non-secret display metadata persist.

A guest wallet remains tied to this browser until an identity is linked. Clearing browser site data can permanently remove access. Supabase anonymous-user cleanup is not automatic in this codebase.

The current beta has no fixed deletion deadline or self-service deletion for account, redemption, ledger, history, saved-output, or privacy/contact records.

A manager-approved, technically enforced retention/deletion schedule is a launch gate before accepting live redemptions.

Long-lived dietary or allergy histories are avoided unless they are truly needed.

Sensitive information

AI outputs may be inaccurate—review before relying on them.

Do not submit SSNs, payment card numbers, medical data, or confidential school information.

Food suggestions are informational only. Please confirm ingredients/allergens with YGF staff.

University relationship

This promotion is offered by YGF for the USC community and is not sponsored, endorsed by, or administered by the University of Southern California.

Privacy contact

This form sends the email and request text you enter to Formspree. Formspree may also process technical request data under its own privacy terms while delivering the message to YGF.

TermsPrivacyCreator kitStaff help

For the USC community. Not affiliated with or endorsed by USC.