Privacy Policy

This policy explains what information air.build handles, why we use it, when it is shared, and the choices available to you.

Effective: August 28, 2026Last updated: August 28, 2026

Overview

air.build is operated by Yellow Plus Inc. ("air.build," "we," "us," or "our"). This Privacy Policy applies to the air.build apps, website, and related services (together, the "Service").

By using the Service, you acknowledge the practices described below. Your use of air.build is also governed by our Terms of Service. If you use air.build for an organization, that organization may control its workspace and the content in it.

Information we collect

Account and profile information

When you create or use an account, we may receive your name, email address, profile image, unique account identifiers, authentication information, team membership, and preferences. If you sign in through Apple, Google, or GitHub, we receive the information that provider makes available according to your settings and authorization.

Projects, conversations, and files

We process the content you choose to create, import, upload, or share through the Service. This can include project names and settings, source code and repositories, prompts, chat messages, replies, approvals, attachments, images, build inputs and outputs, logs, screenshots, App Store materials, and related metadata. Content shared in a team workspace is visible to the people and agents authorized for that workspace.

Connected services

If you connect GitHub, Apple Developer, App Store Connect, an AI provider, or another supported service, we process the account identifiers, authorization information, connection status, and service data needed to perform the actions you request. This may include repository data, Apple team and app information, signing and release metadata, and scoped access tokens or other authorization materials required for the connection. We use this information to perform, secure, and troubleshoot the connected features you authorize.

Usage, plan, and quota information

We process account-level records about AI, search, build, and simulator usage, including model token counts, cost or credit events, plan status, and quotas. We use these records to measure usage, administer plans and limits, prevent abuse, and operate the Service.

Device, usage, and diagnostic information

We may process device and app information such as device identifiers, device name and type, operating system, app version, language, IP address, request time, requested URL, browser headers, security events, feature interactions, build status, and diagnostic logs. If you enable notifications, we process a push notification token, notification content, and delivery status. We use this information to operate, secure, troubleshoot, and improve the Service.

Permissions and optional device features

Some features may ask for access to notifications, camera, microphone or dictation, photos, or files. With your permission, air.build uses notifications to deliver service events; the camera and photo library to capture or select images and attachments; the microphone or dictation feature to create prompts or messages; and the file picker to select files you choose to upload. We access these resources only when you invoke the corresponding feature. You can change access in your device settings. Content you capture, dictate, select, or upload is handled as project content under this policy.

Browser features

When you or an agent uses a browser feature, the requested URL, page content, screenshots, and interactions may be processed by the browser service and the destination website to perform the request.

Website and communications

If you join a waiting list, contact support, or communicate with us, we process the information you provide, such as your email address, message, submission time, and related correspondence. Our hosting provider may also process standard request and security logs. The website does not currently use advertising cookies, cross-site tracking, or third-party behavioral analytics.

How we use information

We use account information to authenticate users and administer accounts, teams, and workspaces; project and conversation content to provide the requested collaboration, build, simulator, device, release, and AI features; connected-service data to perform, secure, and troubleshoot authorized integrations; and device, usage, and diagnostic information to operate, secure, debug, and improve the Service. We also use relevant information to respond to support requests, measure service usage, detect fraud or abuse, comply with law, and establish, exercise, or defend legal claims.

Where applicable, we rely on the performance of our agreement with you, your consent, our legitimate interests in operating and protecting the Service, and compliance with law.

AI processing

To provide an AI-assisted feature, air.build sends your prompt and the project context needed for that request—such as relevant conversation history, code, files, images, or tool results—to the provider used for the feature. Air.build may use OpenRouter to route requests or provide access to hosted models. If you use a provider through your own account or custom endpoint, the request is sent to the provider you choose. Supported options may include Anthropic, OpenAI, Moonshot AI, xAI, Cursor, and other providers you configure. Do not submit content that you are not authorized to use or disclose.

Air.build does not use your content to train models owned by air.build. AI providers may retain or use inputs and outputs under their own terms, privacy policies, and the settings that apply to your account or the requested model. Review those terms before using an AI feature.

How we share information

We do not sell or rent personal information, and we do not share it for cross-context behavioral advertising.

We may disclose information in these circumstances:

  • People you collaborate with. Content and account details are shared with members of the teams and projects you join, according to their permissions.
  • Service providers. We use providers that support cloud infrastructure, storage, authentication, notifications, communications, AI processing, search, browser tools, and security. These providers receive information needed to perform the relevant service. When a provider processes personal information on our behalf, we require it to use appropriate safeguards and protect that information consistently with this policy and applicable law. Depending on the features enabled or requested, processing paths may include Google Cloud for service infrastructure, OpenRouter for hosted AI and routing, and Exa for search and content retrieval.
  • Services you connect or direct us to use. When you connect or direct air.build to use a third-party service—including Apple, Google, GitHub, an AI provider, a custom endpoint, or an external website—we exchange the information needed to perform your request. That provider or website handles information under its own terms and privacy policy. AI and browser services may use additional downstream providers.
  • Legal and safety reasons. We may disclose information where reasonably necessary to comply with law, respond to valid legal process, investigate abuse, or protect rights, safety, and the integrity of the Service.
  • Business changes. Information may be transferred as part of a merger, financing, acquisition, reorganization, or sale of assets, subject to appropriate protections.

Data retention and deletion

We retain account information and project content while your account or workspace is active and for as long as reasonably needed to provide the Service, maintain security and reliable operations, resolve disputes, comply with law, and enforce our agreements. Retention depends on the type of record, its operational purpose, the controls available to the account or workspace, and applicable legal requirements.

When you delete a team or project through an available control, related database records may be deleted while project archives, build records, logs, stored objects, and backups remain for operational, recovery, security, or legal purposes. Some downstream copies may not be removed immediately. Information already sent to collaborators, Apple, GitHub, an AI provider, an external website, or another service may remain under that recipient's controls and retention rules.

Air.build does not currently provide an in-app control for deleting your entire account. You may request access, correction, or deletion of personal information by emailing support@yellowplus.app. We will assess the request, verify your authority, and delete or de-identify information where required and reasonably possible, subject to workspace control, other users' rights, security needs, legal obligations, and technical retention cycles.

Disconnecting an integration stops future actions through that connection where supported. You may also need to revoke air.build's authorization in the provider's settings. We may retain limited connection records where needed for security, audit, legal compliance, or dispute resolution. Disabling notifications stops future notifications but does not itself delete your account or other Service data.

Your choices and rights

Depending on where you live, you may have the right to request access to, correction of, deletion of, or a copy of your personal information; object to or restrict certain processing; withdraw consent; or appeal a decision about a privacy request.

You can withdraw optional permissions in your device settings, disable notifications, disconnect supported integrations, revoke a provider's authorization through that provider, leave a workspace, or contact us to exercise a privacy right. We will stop future processing that depends on the withdrawn consent or authorization where reasonably possible. Withdrawal does not affect processing that already occurred lawfully or information that must be retained for another lawful reason.

You may unsubscribe from marketing or waiting-list messages using the instructions in the message or by contacting us. We will not discriminate against you for exercising a privacy right. We may need to verify your identity or authority before completing a request.

Data security

We use reasonable administrative, technical, and organizational safeguards designed to protect the information we handle. We limit access according to operational need and consider the privacy and security practices of service providers that process information for us. No internet transmission or storage system is completely secure, so we cannot guarantee absolute security.

Children's privacy

air.build is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal information, contact us so we can review and remove it.

International transfers

We and our service providers may process information in countries other than the one where you live, including countries where our service infrastructure and providers operate. Where required, international transfers are handled according to applicable law.

Changes to this policy

We may update this policy as air.build changes. We will post the revised version on this page and update the date above. If a change materially affects how we use personal information, we will provide additional notice where required.

Contact us

For privacy questions or requests, email support@yellowplus.app. Please include "air.build privacy request" in the subject line and avoid sending credentials or other sensitive information by email.