top of page

Privacy Policy

Yellow XR Privacy Policy

Last Updated: March 25, 2025

​
Information We Collect

At Yellow XR ("Company", "We", "Us", or "Our"), we are committed to safeguarding the privacy and security of our users ("you," "your," "therapist" or "client") while delivering cutting-edge AI-enhanced therapy experiences. We collect minimal information to ensure smooth operation while protecting user confidentiality.

  • Therapists: For therapists using the desktop application, we only collect your email address during account creation. No additional personal information is required.

  • Patients/Client: For clients using the VR application, we do not collect any personal information from clients during their VR experience. All interactions within the virtual environment, including AI-generated scenes, objects, and characters, remain completely anonymous and are not stored or tracked.
    If clients wish to request the deletion of any data that may have been unintentionally collected or stored (e.g., through customer support, website forms, or other channels), they can do so by contacting us. We are committed to honoring all data deletion requests in compliance with applicable privacy laws and regulations, regardless of location or circumstances.

  • AI Roleplay & Voice Data Security: When therapists and clients engage in roleplay with AI avatars, audio is transmitted via the open-standard WebRTC protocol with NIST-approved AES 128-bit encryption. The audio is processed in real-time to generate a response and is instantly destroyed—never stored—ensuring complete privacy and confidentiality.

Yellow XR is committed to safeguarding user privacy while leveraging AI-driven technology to enhance therapy sessions in a secure and confidential manner.


Information Use and Sharing

Account Information 

Some aspects of the Services require you to create a user account (“Account”) to access and use them. Your Account information is used to administer your account, provide, support, develop the Services, provide you with information and updates about the Services and your Account, and process any payments you may make through our third-party payment processing vendor.

Content You Submit

Throughout your use of the Yellow XR Services, you may submit various forms of additional information, text, audio, streams, or other materials. We use the content you submit to administer, support, and provide the Yellow XR Services.We only collect the therapist’s email address for communication purposes and account registration purposes. We do not collect any additional personal information, usage statistics, website traffic, your computer hardware and Internet connection, or your activities within the Services, communications, and usage. Our focus is solely on providing a high-quality user experience with minimal data collection.

Information We Collect Automatically

Through your use of the Services, there are certain types of Non-Personal Information that we will automatically collect with no direct input from you.

  • Logs and Usage Data: Like most other website providers, when you access or use the Services, we may collect your IP address, user agent, device and browser information, pages visited, links clicked, search terms, and interactions with results. We may also collect your location information, either by you explicitly granting this permission to the Services or by deriving your approximate location based on other information, including your IP address. We use this information to provide you with the best possible experience with the Services, understand user interactions with the Services, and monitor, improve, support, and develop the Services.

  • Cookies and Other Similar Technologies: We utilize cookies and other similar technologies within the Services. You can find out more about the use of cookies and your choices about their use in the Cookie Policy below.

Information Collected from Third Parties

Yellow XR does not actively or automatically gather any information from third parties (“Third Party Information”). We do not collect Third Party Information for any purpose, including provider profile verification or analytics and advertising purposes. All information we collect is limited to what you submit directly, such as the therapist's email address, and we do not integrate or combine data from third-party sources.

​

Additional Uses of Your Information

Service Providers

Yellow XR does not share any personal information with third-party vendors or service providers; Yellow XR uses Stripe for payment processing, however, we do not collect or store any payment information as all payment details are handled securely by Stripe. We do not share personal information with any other third-party vendors or service providers, and your information remains within the Yellow XR system, used solely for administering the services you request.

Compliance with Legal Requirements

Yellow XR may access, preserve, and share information about you, without consent, in response to government or law enforcement requests or legal processes (including subpoenas), if required to comply with applicable laws, protect the rights of Yellow XR, you, or a third party, or to prevent illegal, unethical, or potentially harmful activities. This may also include responding to legal requests from jurisdictions outside of the United States if we believe such a response is required by law in that jurisdiction and is consistent with internationally recognized standards. Additionally, Yellow XR may access, preserve, and share information if we believe it is necessary to detect, prevent, and address fraud, illegal activities, or to protect ourselves, you, or others, including as part of investigations. In cases where there is a risk of imminent harm, such as death or bodily injury, we may also take appropriate action to protect individuals. Information we receive may be retained for an extended period if it is subject to a legal request or obligation, governmental investigation, or if it is necessary to ensure compliance with our terms or policies, or to prevent harm.

​

Protection of Your Information

We implement commercially reasonable administrative, physical, and technical security measures designed to protect your information from unauthorized access. We cannot ensure the security of any information you transmit to us or guarantee that this information will not be accessed, disclosed, altered, or destroyed. We will make any legally required disclosures of any breach of the security, confidentiality, or integrity of your Personal Information.

​

Data Retention

We will retain your Personal Information for as long as it is necessary for legal and business purposes. If you cease being a user or otherwise terminate your account, we may retain your information in the event you wish to rejoin the Services, for anti-fraud or other business purposes, or other purposes we deem necessary. In the event we retain your information, it will be subject to the same provisions for protection and notification in the event of breach as an active user of the Services.

 

Use of Cookies

Yellow XR's website uses “cookies” to enhance your online experience. A cookie is a small text file placed on your device by a web server. We use only essential and default cookies provided by our website hosting platform, Wix. These cookies are used to improve site functionality and maintain a seamless experience during your visit.

  • Essential Cookies: These cookies are necessary for the basic functioning of the website and to ensure that you can access secure areas of the site. Without these cookies, the site may not perform properly.

  • Session Cookies: These cookies are temporary and are deleted once you close your browser. They help facilitate your experience while browsing, such as maintaining your session on our site.

  • Persistent Cookies: These cookies remain on your device until you delete them or they expire. They help us remember your preferences and settings across sessions to provide a more personalized experience.

  • No Third-Party Cookies: Yellow XR does not use cookies from third-party vendors or for targeted advertising purposes.

You can choose to accept or decline cookies. Most web browsers automatically accept cookies, but you can modify your browser settings to decline cookies if you prefer. Please note that if you choose to decline cookies, some interactive features of the site may not work as intended.

​

Children's Privacy

We do not knowingly collect or solicit any information from anyone under the age of 13 or knowingly allow such persons to register for the Services. The Services and their content are not directed at children under the age of 13. In the event we learn that we have collected Personal Information from a child under age 13 without parental consent, we will delete that information as quickly as possible. If you believe that we might have any information from a child under 13, please contact us immediately.

​

Third Party Links

Our websites contain links to other websites. We encourage you to review the privacy statements of websites you choose to link to from us so that you can understand how those websites collect, use, and share your information. We are not responsible for the privacy statements or other content on websites outside of our Services.

​

Privacy Rights of United States Residents

Depending on where in the U.S. you reside, you may have additional data rights with respect to Personal Information (but not PHI):

Right to Know and to Access

You have the right to request that we disclose certain information to you about our collection and use of your Personal Information over the past 12 months. This information is disclosed in our Privacy Policy.

You also have the right to request access to Personal Information collected about you and information regarding the source of that information, the purposes for which we collect it, and the third parties and service providers with whom we share it. You may submit such a request as described below. To protect our customers' Personal Information, we are required to verify your identify before we can act on your request.

Right to Portability

You have the right to request that we provide a copy of the Personal Information we have collected about you, in a portable and, to the extent technically feasible, readily usable format that allows you to transmit the data to another entity without hindrance. Once we receive your request and confirm your identity, we will provide to you a copy of your data as required under the applicable data protection laws. We may provide this data to you through your user account with us, or via email to the email address you have provided with your request.

Right to Delete

Subject to certain exceptions, you have the right to request that we delete any of your Personal Information. Once we receive your request and confirm your identity, we will review your request to see if an exception allowing us to retain the information applies. We will delete or de-identify Personal Information not subject to one of these exceptions from our records and will direct our service providers to take similar action.

Right to Correct

Subject to certain exceptions, you have the right to request that we correct inaccurate Personal Information that we have collected about you. Once we receive your request and confirm your identity, we will review your request, taking into account the nature of the personal information and the purposes of the processing of the personal information to see if we can correct the data. We may also request additional information showing that the information you want to correct is inaccurate.

Right to Opt-out

You have the right to opt-out of processing of your Personal Information for the purpose of (i) targeted advertising, (ii) sale of Personal Information, or (iii) profiling to provide you with tailored content, including suggested advertising.

Non-Discrimination

We will not discriminate against you for exercising any of your data privacy rights.

Verification Procedures

In order to process your request to exercise your rights, we must first verify it. We do this by asking you to:

  • Provide personal identifiers we can match against information we may have collected from you previously; and

  • Confirm your request using the email account stated in the request.

We will not collect additional Personal Information from you for the sole purpose of your exercising your rights under the data protection laws. Similarly, we will not require you to create an account with us, solely for the purpose of exercising your rights under the data protection laws.

Authorized Agent

You may authorize another individual or a business, called an authorized agent, to make requests on your behalf. We may require that you and the individual complete notarized affidavits in order to verify the identity of the authorized agent and confirm that you have authorized them to act on your behalf. Parents of minor children may submit a birth certificate of the child in lieu of an affidavit, in order to make requests on the child's behalf.

Additional Rights for California Residents

As a resident of California, you may be eligible for additional protections and options under the California Privacy Rights Act (“CPRA”). Yellow XR does not collect or share personal information beyond what is necessary to provide our Services, such as the therapist’s email. We do not sell or share any of your personal information with third parties.

If you are a California resident, you have the right to request access to the personal information we collect about you. Since Yellow XR only collects the therapist's email and does not store other personal data, you can request that we provide information regarding the email we hold. If you wish to exercise your rights under the CPRA, please contact us directly.

Please note, Yellow XR does not act as a service provider for clients of therapists. If you are a California resident and a client or patient of a therapist using Yellow XR, you may need to reach out directly to that therapist for any inquiries about the personal information they may have collected about you.

California Shine the Light

Residents of the State of California have the right to request information about other companies to whom Yellow XR has disclosed certain categories of personal information during the preceding year for those companies' direct marketing purposes. However, Yellow XR does not share personal information for direct marketing purposes. We only collect and store the therapist's email address and do not disclose or share personal information with third parties for marketing purposes.

If you are a California resident and have any questions or requests regarding your data, please contact us.

​
Changes to Our Privacy Policy

We reserve the right to change this Privacy Policy at any time. The last date this Privacy Policy was updated is listed on the top under “Last Updated.” You should periodically check the Site and this privacy page for updates.

bottom of page