1. Who we are
YoBench is a desktop productivity application and the website at yobench.tech ("YoBench", "we", "our", "us"). YoBench is developed and maintained as an independent project.
For any privacy-related question — including data subject requests, access, correction, or deletion — write to contact@yobench.tech. The official source of YoBench is the website yobench.tech.
2. Summary
In short:
- The YoBench desktop application is local-first. Notes, passwords, schedules, files, and other data you create stay on your computer unless you explicitly enable an integration that sends them elsewhere.
- YoBench has no account system of its own and does not use "Sign in with Google". Google APIs are only requested for specific features you turn on: Gmail when you connect a Gmail mailbox in the Email module, and Google Drive when you choose Drive as the destination for YoBench backups.
- The local YoBench database is encrypted at rest with SQLCipher (AES-256), and backup archives uploaded to Google Drive remain in this encrypted form. We never see the contents of your data.
- We do not sell or rent personal data, and we do not use Google user data — including Gmail messages — for advertising, profiling, or for training artificial intelligence or machine learning models.
- The website yobench.tech uses Yandex Metrika to count visits and measure aggregate usage.
3. What data we collect
3.1. Gmail integration (Email module).
When you choose to connect a Gmail account inside the Email module of YoBench, the application requests the following OAuth scopes:
- https://mail.google.com/ — full IMAP and SMTP access required for an email client to read, organize, and send mail
- openid and email — to identify which Gmail address has been connected, so the connected mailbox is shown clearly inside the Email module
With these scopes, depending on the actions you take inside YoBench, the application can:
- Read and list your messages, threads, labels, and attachments
- Mark messages as read, unread, archived, starred, or deleted
- Compose and send mail on your behalf, including drafts and replies
- Modify message labels, folders, and filters
YoBench acts as a desktop email client. Messages, attachments, drafts, and metadata fetched from Gmail are processed and stored locally on your computer in the application database, which is itself encrypted at rest. They are not uploaded to YoBench servers and are not shared with any third party.
You can disconnect a Gmail account at any time from the Email module settings, and revoke YoBench's access from your Google Account permissions page. Once disconnected, the locally stored messages for that account can be deleted from the application.
3.2. Google Drive integration (backups).
When you enable backups to Google Drive in the Settings module, the application requests the following OAuth scopes:
- https://www.googleapis.com/auth/drive.file — a non-restricted, per-file Drive scope. With this scope the application can only access files it has created itself or that you have explicitly opened with it; it cannot list, read, or modify any other content in your Drive.
- openid and email — to identify which Google account has authorized the backup destination, so the right account is shown next to the backup configuration.
On top of the technical limitation enforced by drive.file, you provide YoBench with a specific folder ID inside your Drive. All backup uploads and reads are filtered by that folder ID, so YoBench only writes to and reads from the folder you have designated.
Backup archives are snapshots of the YoBench application database. The database is encrypted at rest with SQLCipher (AES-256), and the snapshot uploaded to Drive remains in this encrypted form — the contents of the archive cannot be read without your master password. The archive may contain copies of your local YoBench data such as notes, schedules, settings, and other module data, depending on what you have selected for backup.
You can disable Drive backups at any time in Settings, delete uploaded backups directly from your Google Drive, and revoke YoBench's access from your Google Account permissions page.
3.3. Locally on your device.
The desktop application stores all module data — notes, task lists, calendar events, browser bookmarks, file transfer history, cached email content, configuration — in a single SQLite database located in the application data directory on your computer.
The database is encrypted at rest with SQLCipher using AES-256. The encryption key is derived from your master password through Argon2id (a memory-hard key derivation function). Sensitive credential fields — OAuth tokens, IMAP/SMTP passwords, SSH keys, S3 secrets — are additionally encrypted at the field level with AES-256-GCM before being written to the database. The master password is never stored in plain form: a temporary cached copy used during the session is held in your operating system's secure credential store (macOS Keychain, Windows DPAPI, or the freedesktop secret service on Linux) and removed when you sign out.
None of this local data is transmitted to YoBench servers. You can change the data directory or delete it at any time from the application settings.
3.4. On the website.
- Yandex Metrika collects anonymized analytics: page views, session duration, browser and operating system information, and approximate location based on IP address.
- A small set of first-party cookies is used for language preference and session continuity. No advertising or cross-site tracking cookies are set.
- When you submit the contact form, we receive the name, email, and message you provide. The message is delivered to contact@yobench.tech for a human reply.
- Standard server logs (IP address, user agent, requested URL, timestamp) are retained for security and debugging.
3.5. What we do not collect.
- We do not collect the contents of your local notes, passwords, Gmail messages, or other module data from the desktop application.
- We do not maintain a server-side database of YoBench desktop users.
- We do not perform analytics inside the desktop application unless you explicitly opt in.
- We do not read, scan, or use your Gmail messages or your Drive files for advertising, profile building, or training artificial intelligence or machine learning models.
4. How we use Google user data
We use data obtained through Google APIs strictly for the user-facing features that you authorize, and we process it on your device. The mapping between scopes and features is direct and one-to-one:
- https://mail.google.com/ + openid + email — used solely to power the in-app Gmail email client in the Email module: reading, listing, sending, organizing, and searching your mail. The Gmail address of the connected mailbox is shown inside the Email module so you know which account is active. All processing of Gmail content happens locally on your computer. Gmail content is not stored on YoBench servers and is not transferred to any third party.
- https://www.googleapis.com/auth/drive.file + openid + email — used solely to upload YoBench backup archives to a folder in your Google Drive and to download them again when you restore. The drive.file scope and a per-destination folder ID together prevent the application from listing, reading, or modifying any other files in your Drive.
Google user data is never used for advertising, profile building, market research, retargeting, or for training, evaluating, or fine-tuning artificial intelligence or machine learning models. This applies in particular to Gmail messages and to the contents of backup archives stored on Drive.
5. Limited Use disclosure (Google API Services User Data Policy)
YoBench's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
The Gmail scope (https://mail.google.com/) used by YoBench is classified by Google as a Restricted Scope. The Drive scope (drive.file) is non-restricted and grants per-file access only. The Limited Use commitments below apply to all data obtained through Google APIs:
No advertising. We do not use Google user data — including Gmail messages, attachments, and Drive content — to serve advertisements, including personalized, retargeted, contextual, or interest-based advertising. We do not transfer Google user data to advertising networks or data brokers.
No AI / ML training. We do not use Google user data — including Gmail messages, attachments, and Drive content — to train, evaluate, fine-tune, or otherwise improve any artificial intelligence or machine learning model, whether developed by us or by any third party.
In addition:
- We use Google user data only to provide or improve user-facing features that are prominent in YoBench — the Email module (for Gmail data) and the backup feature (for Drive data).
- We do not transfer Google user data to others except as necessary to provide or improve those user-facing features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets — in which case we will require the new entity to follow this policy.
- We do not allow humans to read Google user data, except: with your affirmative agreement for specific messages; when necessary for security purposes (such as investigating abuse); to comply with applicable law; or where the data has been aggregated and anonymized for internal operations.
6. How we share data
We do not sell your personal information.
We share personal data only:
- With infrastructure providers strictly necessary to operate the website — web hosting, transactional email delivery for the feedback form, and IP geolocation services for region-aware content.
- With law enforcement or government authorities when legally required, and only to the extent required.
- With your explicit consent, when you enable a third-party integration inside the desktop application (for example, an AI provider, a Git host, an SMTP server, or cloud storage).
Subprocessors used by the website yobench.tech:
- Web hosting and transactional email delivery for the feedback form — the hosting provider for yobench.tech. No Google user data flows through this provider.
- Yandex Metrika — anonymized traffic analytics on the website only. Not used in the desktop application. Not connected in any way to Google user data.
- DB-IP — offline IP-to-country database used to render region-aware website content. No Google user data is involved.
When you connect Google services from the desktop application, the application calls Google APIs directly from your device. Google itself processes those requests in line with its own privacy policy. YoBench does not place a server between you and Google for Gmail or Drive data.
When you enable any other third-party integration inside the desktop application (such as an AI provider, an alternative IMAP/SMTP server, an FTP host, or an object storage), data sent to that service is governed by that service's own privacy policy. YoBench does not intermediate or store that data on our side.
7. Data retention and deletion
- Local data on your computer is stored until you delete it. Uninstalling the application or deleting the data directory removes it permanently.
- Gmail messages stored locally for the Email module are kept on your device until you disconnect the account, sign out, or delete them from the application. They are never copied to YoBench servers.
- Google Drive backup archives created by YoBench live in your own Google Drive. You can delete them at any time directly from Drive; YoBench does not retain a separate copy on its servers.
- Google OAuth access and refresh tokens are stored locally on your device, encrypted at the field level (AES-256-GCM) within the encrypted application database, and are kept only for as long as the integration is active. Revoking access from your Google Account permissions page invalidates the tokens immediately.
- Feedback form messages are retained in our email inbox for as long as needed to respond and follow up. You can request deletion by writing to contact@yobench.tech, and we will action it within 30 days.
- Server access logs are retained for up to 30 days, then rotated.
- Yandex Metrika analytics retention is governed by Yandex's privacy policy.
Deletion requests sent to contact@yobench.tech are processed within 30 days. We will confirm in writing once the requested data has been removed.
8. Your rights
Depending on your jurisdiction, you may have rights to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request deletion of your data
- Withdraw consent at any time
- Lodge a complaint with a data protection authority
To exercise any of these rights, write to contact@yobench.tech. We will respond and action your request within 30 days of receipt.
For Google account data specifically, you can also revoke our access at any time on your Google Account permissions page. After revocation, we will delete any associated data we held about you.
9. Security
Encryption at rest:
- The application database that holds all module data — including locally stored Gmail content, calendar events, notes, and configuration — is encrypted with SQLCipher (AES-256). The encryption key is derived from your master password using Argon2id, a memory-hard key derivation function (64 MB memory cost, 3 iterations).
- Sensitive credential fields — Google OAuth access and refresh tokens, IMAP and SMTP passwords, SSH keys, S3 secrets, FTP passwords — are additionally encrypted at the field level with AES-256-GCM using a key that lives only inside the encrypted database.
- During an active session a temporary copy of the master password is held in your operating system's secure credential store via Electron safeStorage — macOS Keychain, Windows DPAPI, or libsecret on Linux. It is removed when you sign out.
- Backup archives uploaded to Google Drive are SQLCipher-encrypted snapshots of the local database. Their contents cannot be read without your master password.
Encryption in transit:
- All Google API calls (Gmail, Drive) use HTTPS with TLS, as enforced by Google.
- IMAP, SMTP, and other network integrations use TLS where supported by the remote server.
- The website uses HTTPS for all traffic.
Other safeguards:
- YoBench has no remote account system, so there is no server-side password that could be compromised.
- OAuth uses the PKCE (RFC 7636) flow, so authorization codes cannot be replayed.
- Backup archives on disk are written with restrictive file permissions where the operating system supports it.
No method of transmission or storage is 100% secure. We follow industry best practices but cannot guarantee absolute security.
10. Children
YoBench is not directed to children under 13 (or under 16 in the European Economic Area). We do not knowingly collect personal data from children. If you believe a child has provided us personal data, please contact us at contact@yobench.tech and we will delete it.
11. International data transfers
When you connect a Gmail mailbox or enable Google Drive backups, the OAuth handshake and the subsequent Gmail and Drive API calls go through Google's infrastructure and are processed in accordance with Google's privacy policy. Depending on Google's routing, this may include data centers outside your country.
The yobench.tech website itself is hosted on third-party infrastructure that may be located outside your country. Only website-level data — server logs, feedback form messages, anonymous Yandex Metrika analytics — is processed by this infrastructure. Google user data does not flow through it.
12. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you in the application or on the website. Your continued use of YoBench after a change indicates your acceptance of the updated policy.
13. Contact
For privacy questions, data subject requests, or any other concerns related to this policy, write to contact@yobench.tech.