Privacy Policy
This policy explains what personal data YOSUGA K.K. ("YOSUGA", "we") processes when you use our developer APIs (the "Service") and this website, and how we handle the media and text you submit. The Service is sold through the RapidAPI marketplace; RapidAPI's own privacy policy applies to your marketplace account, payment details and key management.
1. Controller and contact
YOSUGA K.K. (YOSUGA株式会社), Yamanoshita 10, Hishida, Seika-cho, Kyoto, Japan. Privacy enquiries: info@yosuga.io.
2. What we process
| Category | Examples | Source |
|---|---|---|
| Subscriber identifiers | RapidAPI username or application identifier, subscription plan | Sent by RapidAPI with each request |
| Request metadata | Job identifiers, timestamps, requested options, status, error codes, usage counts (minutes, requests), IP address and user agent in edge logs | Generated when you call the Service |
| Input content | Media files or URLs you submit, vocabulary hints, timed text you send for formatting, optional metadata and callback_url values | Provided by you |
| Output content | Transcripts, captions, cut lists, rendered video | Generated by the Service |
| Support correspondence | Emails and RapidAPI discussion posts | Provided by you |
Input media may contain personal data of the people recorded in it (voices, names, statements). You are responsible for having a lawful basis to process that content; we process it only on your instructions to deliver the Service.
3. Purposes and legal bases
- Providing the Service you requested, including transcription, formatting and file delivery (performance of a contract).
- Metering usage for billing through RapidAPI and keeping cost and accounting records (contract; legal obligations).
- Preventing abuse, securing the Service and debugging failures (legitimate interests).
- Responding to support requests (contract; legitimate interests).
We do not use your Input or Output to train machine-learning models, and we do not sell personal data.
4. Retention
| Data | Retention |
|---|---|
| Input media | Deleted as soon as the job completes or fails. Files uploaded but never attached to a job are deleted within about 24 hours. |
| Output files and job results | 7 days after completion, then deleted. Jobs return "expired" afterwards. |
| Job metadata, usage and cost records | Kept as long as needed for billing reconciliation, accounting and legal obligations, then deleted or anonymised. |
| Edge and application logs | Up to 30 days, except where needed to investigate abuse or a security incident. |
| Support correspondence | As long as needed to handle the request and for a reasonable period afterwards. |
5. Sub-processors
We rely on the following providers to run the Service. Each processes data under its own terms and security programme.
| Provider | Role | Data involved |
|---|---|---|
| Cloudflare, Inc. | Edge network, API gateway logic, database and object storage | Request metadata, Input (transiently), Output |
| Modal Labs, Inc. | Media processing compute | Input (transiently), Output |
| Google LLC (Gemini API / Gemini Enterprise Agent Platform, formerly Vertex AI) | Speech recognition and audio analysis | Extracted audio and vocabulary hints. Used under Google's paid API terms: Google does not use this data to train or improve its models, and retains prompts and responses only for abuse monitoring for up to 55 days. |
| RapidAPI (part of Nokia) | Marketplace, authentication, billing | Subscriber identifiers, request counts |
| Resend, Inc. | Operational email to our administrators | Job identifiers in alerts (no Input content) |
These providers operate in Japan, the United States and other regions. Where data is transferred internationally we rely on the providers' standard contractual safeguards.
6. Webhooks and callback URLs
If you set a callback_url, we send job status notifications to that address. Payloads contain job identifiers and status, not media content, and are signed so you can verify their origin. You are responsible for the endpoint you nominate.
7. Security
Traffic is encrypted in transit. Output files are delivered through short-lived signed URLs. Input media is stored only for the duration of processing. Access to production systems is limited to YOSUGA personnel who need it to operate the Service.
8. Your rights
Depending on where you are, you may have rights to access, correct, delete or restrict the processing of your personal data, and to object or to data portability. To exercise them, or to request early deletion of a job's Output, email info@yosuga.io with the job identifier. Requests relating to your RapidAPI account or payment details should be addressed to RapidAPI.
9. This website
This website is a static site served by Cloudflare. It sets no cookies and uses no analytics or advertising trackers. Cloudflare may log requests for security and performance purposes.
10. Children
The Service is intended for businesses and developers and is not directed at children under 16.
11. Changes
We may update this policy. The effective date at the top shows the current version; material changes will be noted on the API's RapidAPI listing.