Last updated: 8 September 2026
Yap ("Yap", "we", "us") is a mobile app that lets a group of friends propose plans and answer them quickly.
Yap is operated by Jaidev Singh Narula as an individual, based in Singapore. There is no company behind Yap — "we" throughout this policy means one person.
Under Singapore's Personal Data Protection Act 2012 ("PDPA") an individual acting in anything other than a personal or domestic capacity is an "organisation", so the PDPA's obligations apply to us in full, and we are the party responsible for the personal data described here.
As required by section 11(3) of the PDPA, a Data Protection Officer has been designated:
Jaidev Singh Narula [email protected]
That address is monitored. It is the fastest way to reach a person about anything on this page.
Yap is available worldwide. We are based in Singapore, so the PDPA governs how we handle your personal data.
If you are in the European Economic Area or the United Kingdom, the GDPR and UK GDPR also apply to us because we offer the app to people there. Section 10 sets out the additional rights you have. Nothing in this policy takes away a right you have under the law of the country you live in.
Under the PDPA we may collect, use and disclose personal data with your consent, or where an exception applies. The right-hand column below says which we rely on.
"Deemed consent — contractual necessity" (PDPA s.15) covers data you provide so that we can give you the service you asked for. "Legitimate interests" (First Schedule, Part 3) covers a narrow set of things like security and preventing abuse, where the benefit outweighs any adverse effect on you.
| What | Why we need it | Basis |
|---|---|---|
| Display name | So your friends know who fired a yap or said yes | Deemed consent — contractual necessity |
| Profile photo (planned, not in the app yet) | Same | Consent |
| Group names | To label your groups | Deemed consent — contractual necessity |
| Plan details — what, where, when | The plan itself | Deemed consent — contractual necessity |
| Messages in a plan | Group chat on a confirmed plan | Deemed consent — contractual necessity |
| Your answers (in / not in) | To count who is coming | Deemed consent — contractual necessity |
| Reports you submit about content or people | To act on abuse | Legitimate interests |
The "where" field is free text. You choose what goes in it. Please do not put anything there you would not want the other members of that group to read.
You sign in with Apple or Google. From them we receive:
If you use Sign in with Apple you may choose Apple's Hide My Email option, in which case we only ever receive a relay address and never your real one. We recommend it.
We use the email address to identify your account and, if we need to, to contact you about the service. We do not send marketing email. We never receive your password.
| What | Why we need it | Basis |
|---|---|---|
| Push notification token — an identifier for your device's notification channel | To deliver the notification the app exists to send | Deemed consent — contractual necessity, plus your device permission |
| Platform (iOS or Android) | To route the notification correctly | Deemed consent — contractual necessity |
| Time zone | So "8pm" means 8pm where you are | Deemed consent — contractual necessity |
| Timestamps — when you joined, answered, posted | To order events and run the fuse | Deemed consent — contractual necessity |
| Server logs and error reports | To keep the service working and secure | Legitimate interests |
On the time zone. We read your device's time-zone setting. This is not a location: it tells us you are in, say, Asia/Singapore, which is true of about six million people. We need it because a plan happens at one instant but has to be described in each person's local clock time, and because we hold notifications during quiet hours (11pm–8am) where you are.
For the avoidance of doubt, Yap does not collect or process:
We use no cookies or similar tracking technologies in the app.
Notifications are the core of Yap — the app is close to useless without them.
They are sent only about plans in groups you belong to, and they are service messages, not marketing. Your device asks permission before we can send any, and you can turn them off at any time in your device settings. We hold non-urgent notifications during quiet hours (11pm–8am in your time zone) and we cap how many we send about any single plan.
We do not make marketing calls or send marketing SMS, so Singapore's Do Not Call provisions are not engaged.
This matters enough to state plainly, because it is the app's central design rule:
These are enforced by row-level security in our database — the data is not retrievable by other users at all, rather than merely hidden in the interface.
We do not sell personal data and we do not share it for anyone else's marketing.
We use the following service providers, who handle data on our instructions:
| Provider | What they do | Where |
|---|---|---|
| Supabase (Supabase Inc.) | Hosts our database, authentication and server functions | Frankfurt, Germany (eu-central-1) |
| Expo (650 Industries, Inc.) | Relays push notifications to Apple and Google | United States |
| Apple (Apple Inc. / Apple Distribution International) | Sign in with Apple; delivers notifications via APNs | United States / Ireland |
| Google (Google LLC / Google Asia Pacific Pte. Ltd.) | Google Sign-In; delivers notifications via FCM | United States / Singapore |
We may also disclose personal data where required by law — for example under a court order or a lawful request from a regulator or law enforcement agency — or to establish, exercise or defend legal claims.
Where your data physically lives. The database is hosted in Frankfurt, Germany. So although we are based in Singapore, your account, your groups, your plans and your messages are stored inside the European Union and are covered by the GDPR's protections at rest.
Transfers out of Singapore. Under the PDPA's Transfer Limitation Obligation (section 26 and Regulation 26 of the PDP Regulations 2021), personal data is transferred overseas only where the recipient is bound by legally enforceable obligations to protect it to a standard comparable to the PDPA. For the EU that standard is met by the GDPR itself; for the others it is met by their written data processing terms. Where a transfer also involves EEA or UK data leaving the EU — notifications routed through Expo, Apple and Google in the United States — the Standard Contractual Clauses and the UK Addendum apply. Ask and we will point you at the specific terms.
A note on notification content. The text of a notification — for example "🌕 Sam wants to yap — Spoons, 8pm" — passes through Expo, then Apple or Google, to reach your lock screen. That is how push notifications work on both platforms; there is no way to deliver one without it. Bear it in mind when you name a plan.
The PDPA's Retention Limitation Obligation says personal data must not be kept once the purpose has been served and there is no legal or business need for it.
Stated plainly, because a policy that promises a schedule it does not run is worse than one that does not: Yap does not currently delete anything automatically. What is true today is:
| Data | What actually happens |
|---|---|
| Your account and profile | Kept until you delete your account, then removed immediately |
| Groups you belong to | Kept while you are a member |
| Plans, answers and messages | Kept for as long as the group exists. No automatic expiry yet |
| Plans that were dropped | Deleted at the point they are dropped, and never shown to anyone |
| Push tokens | Removed when you sign out or delete your account |
| Queued and sent notification records | Kept. No automatic expiry yet |
| Reports of abuse | Kept, so repeat behaviour is visible |
| Server logs | Kept as long as the hosting provider retains them |
Scheduled deletion is planned, and this section will be updated to state the specific periods when it exists. Deleting your account removes your data regardless of any of the above — see section 12.
You may:
Email [email protected]. We will respond as soon as reasonably possible, and within 30 days where we can. If we need longer we will tell you why and when to expect an answer. Access requests may attract a reasonable fee, which we will tell you about before doing the work.
If you are unhappy with how we handle your personal data, tell us first — we would rather fix it. You also have the right to complain to the Personal Data Protection Commission (PDPC) at pdpc.gov.sg.
Because we offer Yap to people in the EEA and UK, the GDPR and UK GDPR apply to that processing. In addition to section 9 you have the right to erasure, restriction of processing, data portability, and to object to processing based on legitimate interests. You will not be subject to any decision based solely on automated processing; Yap makes none.
Where this policy says "deemed consent — contractual necessity", the equivalent GDPR lawful basis is Article 6(1)(b), performance of a contract. Where it says "legitimate interests", the equivalent is Article 6(1)(f).
You may lodge a complaint with your local supervisory authority, or with the UK Information Commissioner's Office at ico.org.uk.
We do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not process it for cross-context behavioural advertising. You may request access to or deletion of your personal information using the same routes as section 12, and we will not discriminate against you for asking.
In the app: Account → delete account. It asks once, then does it.
Without the app: email [email protected], or use the page at https://yapsignal.com/legal/delete-account. We will verify it is you before acting.
When you delete your account we remove your profile, your group memberships, your answers, your messages and your device tokens.
Two things behave differently, and you should know before you press it:
Deletion is immediate and cannot be undone. Backups are overwritten on a rolling 30 day cycle, which is our hosting provider's default. We may retain a minimal record of a report of abuse where we need it to keep other people safe, or where the law requires it.
We use row-level security so the database itself refuses to return data to a user who should not see it, rather than relying on the app to hide it. Traffic is encrypted in transit (TLS); data is encrypted at rest by our hosting provider. Access to production systems is limited to one person and protected by two-factor authentication.
No system is perfectly secure. Under the PDPA's Data Breach Notification Obligation, if we suffer a data breach that is likely to result in significant harm to affected individuals, or that affects 500 or more individuals, we will notify the PDPC within 3 calendar days of assessing it as notifiable, and notify affected individuals as required. Where EEA or UK data is involved we will also notify the relevant supervisory authority within 72 hours.
Yap is not for children. You must be 18 or over to use it.
We do not knowingly collect personal data from anyone under 18. If you believe someone under 18 has an account, email [email protected] and we will delete it.
If we change this policy we will update the date at the top and, where the change is significant, tell you in the app before it takes effect.
Jaidev Singh Narula, Data Protection Officer [email protected] · general enquiries [email protected]
A postal address is available on request, and is published on the app's Google Play listing as Google requires.