Privacy Policy
Effective Date: July 15, 2026
Version: 2.0 (replaces Version 1.0, effective December 16, 2025)
Yura is a volunteer management platform operated by Volunteeritude LLC, a North Carolina limited liability company ("Volunteeritude," "Yura," "we," "our," or "us"). This Privacy Policy explains how we collect, use, store, share, and protect information about users of our websites (including useyura.com and volunteeritude.com), our web application, our mobile application, and related services (collectively, the "Services").
This Policy applies to volunteers, organization administrators, school and university personnel, students, and visitors to our public pages. If you use the Services through a school, university, or other organization, that organization's agreement with us (including any data processing agreement) may provide additional protections; where a signed agreement with a customer conflicts with this Policy, the agreement controls to the extent it is more protective of your information.
Summary of key points (the full sections below control):
- We collect the information you give us (profile, volunteer hours, reflections), information organizations record about you, and limited technical data collected automatically.
- We do not sell, rent, or trade personal information, and we do not use it for targeted advertising. We never sell student data or use it for advertising of any kind.
- Organizations and schools you join can see the volunteer information relevant to their program — we explain exactly what they see in Section 6.
- We use a small set of service providers (hosting, payments, email, analytics, AI) listed in Section 7. We do not allow personal information to be used to train AI models.
- You can delete your account and data, and we honor privacy rights available under applicable state laws (Section 10).
- The Services are for users in the United States, age 13 and older.
1. Who We Are and Scope
Volunteeritude LLC operates the platform under two names: "Volunteeritude" and "Yura." Both names refer to the same company, the same platform, and the same data practices. References to "Yura" in the product, our marketing, or this Policy mean Volunteeritude LLC.
This Policy does not apply to:
- Information practices of the organizations, schools, and universities that use Yura. They are independent entities. When an organization collects information from you through Yura (for example, through an application form, custom fields, or a document request), the organization determines what is collected and why. Contact the organization directly with questions about its practices.
- Third-party websites and services we link to (Section 12).
2. Information We Collect
2.1 Information you provide directly
Account registration. Name, email address, username, and a password (which we store only as a cryptographic hash — see Section 11). Registration through Google Sign-In provides us your name, email address, and profile picture from Google instead of a password. At self-serve signup we also ask your date of birth to confirm you're old enough to have an account — we don't store it; we keep only a record that your age was verified.
Volunteer profile (optional fields). Bio, skills and interests, city, state, ZIP code, phone number, date of birth, and a profile photo. Except where noted, profile fields are optional. High-school student accounts provisioned through a school are "restricted" accounts: we do not collect phone number, date of birth, or city/state/ZIP for those accounts, and our systems reject attempts to add them (Section 8).
Volunteer activity data. Service logs (activity description, date, hours, the organization or verifier involved); a 1–5 mood rating (recorded as neutral unless you change it) and an optional free-text reflection on each log; journal entries; goals; awards and recognitions; event registrations and attendance status (including check-in and no-show records); program shift assignments and availability.
A note on reflections and journals: these can contain personal thoughts. We encrypt reflection and journal text at rest in our database, and we do not use this content for analytics, advertising, or AI model training. Journal entries are private to you unless you choose to make one public.
Information organizations collect about you through Yura. Organizations you join may, at their discretion:
- ask you custom questions (text, number, date, select, or checkbox fields) — for example, a school may record a student ID or grade level, and a hospital program may record training status;
- have you complete an application form with questions the organization defines;
- request documents from you (for example, a signed liability waiver, training certificate, or other file), which are stored in a private document vault with access logging; and
- record notes about scheduling, substitutions, and program participation.
The organization defines the content of these fields, forms, and requests; we store the responses on the organization's behalf. Organizations are contractually required to collect only what they reasonably need and to obtain any consents required by law (see our Terms of Use).
Organization information. For organization accounts: organization name, type, and category; EIN; address, phone, website, and social links; logo and branding; and the names, emails, and contact details of organization administrators.
Payment information. For paid organization subscriptions, payments are processed by Stripe. We receive and store billing contact details, subscription status, and invoice metadata. We never receive or store full payment card numbers. Schools and other institutions are typically billed by invoice rather than through Stripe.
Communications. Support requests, contact-form submissions, in-app feedback and bug reports, feature-poll votes, and feedback you give on AI features.
Agreement records. When you accept our Terms of Use or Privacy Policy (or accepted our historical Beta Agreement), we record the agreement type, version, timestamp, and the IP address and browser user-agent from which you agreed. We keep these records to document consent.
2.2 Information we collect automatically
- Device and usage data: IP address, browser and device type, operating system, pages viewed, features used, and timestamps. Server logs (including security audit logs of sign-in and permission events) include user ID, IP address, and user-agent.
- Product analytics: we use PostHog (Section 7) to understand how the Services are used — page views, feature usage, performance metrics ("web vitals"), and application errors. Analytics events for signed-in users are associated with your user ID, name, email, role, and organization — except for restricted student accounts, whose analytics stay pseudonymous (Section 8).
- Cookies and similar technologies: we use cookies that are strictly necessary for the Services (session/authentication cookies and short-lived cookies that carry signup consent), plus PostHog's analytics cookies/storage in production. We also use browser localStorage for convenience features such as saving form drafts on your device and remembering interface preferences. We do not use advertising cookies or third-party ad trackers. See Section 5 for choices.
- Approximate location: we may infer general location from your IP address for security (for example, rate limiting) and aggregate analytics. We do not collect precise geolocation from your device. Event and program locations (addresses and map coordinates) describe where volunteer activities take place — they are locations of events, not tracking of you. Our mobile app does not request location, camera, contacts, or microphone permissions.
2.3 Information from third parties and about non-users
- Google Sign-In: name, email address, and profile picture; for school-affiliated accounts, the email domain is used to associate the account with the correct school (Section 8).
- Organization imports: organizations may upload volunteer rosters or historical service-hour records (for example, by CSV), which can include names, emails, and hours of people who do not yet have Yura accounts. We store this information on the organization's behalf and use it only to operate the organization's program (for example, to match records to an account you later create).
- People you or an organization identify: if you ask a person outside Yura to verify your hours, we collect that person's email address to send the verification request, and we record the verifier's name and email on the verified log. Invitations to join an organization similarly involve the invitee's email address.
- Waitlist and contact submissions: email addresses submitted through our waitlist or contact forms.
If you receive an email from Yura because someone identified you (as a verifier or invitee), we use your email address only for that purpose and you may disregard the request.
3. How We Use Information
We use personal information to:
- Provide the Services: operate accounts; log, verify, and report volunteer hours; run events, programs, shifts, and applications; produce dashboards, reports, and exports for you and your organizations.
- Operate school and institutional programs: associate student accounts with the correct school, enforce restricted-account protections, and generate the reports the school requires (Section 8).
- Communicate with you: transactional and service emails (verification requests, event confirmations and reminders, milestone notifications, security notices), in-app notifications, and browser push notifications you enable. Optional product-update emails are sent only consistent with your email preferences, and every non-essential email includes an unsubscribe link.
- Provide AI-assisted features to organization administrators (Section 4).
- Improve the Services: analytics, debugging, performance measurement, and product research (feature polls, feedback).
- Protect the Services and our users: authentication, rate limiting, fraud and abuse prevention, security auditing, and enforcing our Terms of Use.
- Process payments for paid organization subscriptions.
- Comply with law: respond to lawful requests and meet our legal obligations.
We do not use personal information for third-party advertising, and we do not build advertising profiles. We do not make automated decisions about you that have legal or similarly significant effects.
4. AI Features
Some Yura features for organization administrators use large-language-model technology provided by Anthropic (the Claude API):
- AI search and filtering: an administrator can ask a natural-language question about their own organization's data (for example, "who hasn't logged hours this month?"). To answer, we may send Anthropic relevant organization data — which can include volunteer names and email addresses within that organization, along with events, programs, and custom-field definitions.
- AI report drafting: administrators can generate report documents from their organization's data. To draft a report, the AI may query the organization's aggregated statistics and, where the administrator's request calls for it, individual service-log records within that organization (volunteer name, activity, date, hours, verification status) and responses to that organization's custom fields. Outputs are instructed to avoid including personal information beyond what the report requires.
Commitments that apply to all AI features:
- No AI training on your data. We use Anthropic's commercial API, which under Anthropic's commercial terms is not used to train Anthropic's models, and we do not permit any AI provider to use personal information from Yura to train or improve AI models. Student data is never used to train AI models.
- AI processing happens only to fulfill the administrator's specific request; we do not send reflections, journals, mood data, documents, or passwords to AI providers.
- AI outputs can be inaccurate and are a drafting/search aid only. Organizations are responsible for reviewing AI outputs before relying on them, and must not use AI outputs as the sole basis for decisions about a volunteer or student (see Terms of Use).
- If an administrator submits feedback on an AI response, we store that feedback together with the related prompt so we can improve the feature's design (not to train models). AI prompts are not otherwise retained.
5. Cookies, Analytics, and Your Tracking Choices
- Strictly necessary cookies (authentication/session, security, signup consent) are required for the Services to function and cannot be disabled while using the Services.
- Analytics (PostHog): used to understand product usage and errors. You can limit analytics by using browser tracking protections or blocking requests to our
/ingestanalytics endpoint; core Services continue to work. - Do Not Track / Global Privacy Control: we do not sell or "share" personal information for cross-context behavioral advertising, so there is no sale/sharing to opt out of. We do not currently respond to Do Not Track signals.
- No advertising trackers: we do not run third-party advertising pixels or ad networks on the Services.
6. How We Share Information
We do not sell, rent, or trade personal information. We have never sold personal information. We do not share personal information for cross-context behavioral advertising.
We share information only as follows:
6.1 With organizations and schools you are connected to
When you join an organization (or your school provisions your account), that organization's administrators can see, for their program: your name and email; your service logs with that organization (activity, date, hours, verification status, and any custom fields attached to those logs); your event registrations and attendance; program shift assignments and availability; your responses to that organization's custom fields, applications, and document requests; your total hours; and awards granted by that organization.
If you are connected to a school or other institution: to support graduation, honor-society, and recognition tracking, administrators at your school can see your individual service logs across all organizations — including the activity, date, hours, organization name, and verification status of hours you log with other organizations — as well as your total hours.
Administrators of organizations you belong to can view your profile even if your profile is set to private. Organizations may export the data described above (for example, to CSV, Excel, or PDF reports) for their volunteer-management, compliance, and reporting purposes; once exported, that copy is under the organization's control and its policies.
Your reflections and journal entries are not shared with organizations, and organization data views and exports exclude them. Your individual mood ratings are for your own reflection tools and are not shown to organizations; organization dashboards may show aggregate, non-identifying mood trends (computed only across five or more volunteers, on a delayed basis).
6.2 With people you involve
If you request hour verification from someone outside Yura, that person receives your name and the details of the log you asked them to verify.
6.3 With service providers (subprocessors)
We use a small number of vendors to run Yura. Each may process personal information only to provide services to us, under contracts that require confidentiality and security. As of the Effective Date:
| Provider | Purpose | Personal information involved |
|---|---|---|
| Vercel | Application hosting, content delivery, server logs, performance monitoring | All Service traffic; server/audit logs (user ID, IP, user-agent) |
| Managed PostgreSQL provider — Neon | Primary database | All application data |
| Cloudflare (R2) | Storage of uploaded images and documents | Profile photos, organization media, documents you upload |
| Postmark (ActiveCampaign) | Transactional and notification email delivery | Name, email address, message content |
| Stripe | Payment processing for organization subscriptions | Billing contact and payment details (card data goes to Stripe, not us) |
| Anthropic | AI features (Section 4) | Volunteer names/emails and org data within an admin's AI request |
| PostHog | Product analytics and error tracking | User ID, name, email, role, organization, usage events, device data |
| Pusher | Real-time in-app notifications and dashboard updates | User IDs and notification payloads |
| Upstash | Rate limiting | Rate-limit keys, including IP addresses and user identifiers |
| Sign-in (OAuth) | Google account name, email, profile picture | |
| Browser push services (Apple, Google, Mozilla) | Web push notifications you enable | Push subscription tokens, notification content |
| Linear | Internal tracking of user-submitted feedback and bug reports | Your name, email, and the content of your feedback |
We will update this list when providers change; material changes are announced under Section 14. School customers receive subprocessor commitments in their data processing agreements.
6.4 Legal, safety, and corporate
- Legal compliance: to comply with law, regulation, subpoena, court order, or other legal process, or to respond to lawful government requests.
- Protection: to enforce our Terms of Use; to protect the rights, property, safety, or security of Volunteeritude, our users (including minors), or the public; and to detect and prevent fraud, abuse, or security incidents.
- Business transfers: in a merger, acquisition, financing, reorganization, or sale of assets, personal information may be transferred to the successor, subject to this Policy; we will notify you (and school customers as their agreements require) of any such transfer.
- With your consent: for anything else, we ask first.
6.5 Aggregated and de-identified data
We may create and use aggregated or de-identified data (data that can no longer reasonably identify you) for statistics, research, and product improvement, and we commit to not attempting to re-identify it. We do not use student data to create de-identified data for commercial purposes unrelated to the Services.
7. Public Information
- Organization pages and events: organizations may publish public profile pages and public event listings. These show organization information and event details — public pages never display volunteer rosters, and our public data layer excludes personal contact details.
- Volunteer profiles: volunteer profiles are private by default.
- Photo galleries: organizations may publish photos approved by their administrators. Contact the organization (or us) if a photo of you should be removed.
8. Students and Schools (FERPA and State Student-Privacy Laws)
This section applies when a school, district, university, or other educational institution ("School") uses Yura for its students.
- Role. We act as a service provider to the School. Where the School discloses education records to us, we operate as a "school official" with a "legitimate educational interest" under FERPA (20 U.S.C. § 1232g; 34 C.F.R. § 99.31(a)(1)), performing services the School would otherwise perform itself, under the School's direct control with respect to those records.
- Ownership and control. As between us and the School, student education records belong to the School (and to students and their parents as provided by law). We collect, use, and share student data only to provide the Services to the School, as directed by the School and our agreement with it, and as permitted by law.
- What we don't do with student data. We do not: sell student data; use it for targeted advertising of any kind; build profiles of students for any purpose other than providing the Services to the School; use it to train AI models; or disclose it except to subprocessors bound to equivalent commitments, as directed by the School, or as required by law.
- How student accounts work. Schools may arrange domain-based sign-in, where a student signing in with a school Google account is automatically connected to the school with a restricted account. Restricted accounts block collection of phone number, date of birth, and city/state/ZIP location fields, stay pseudonymous in product analytics, and are excluded from data sent to AI providers. Schools decide which optional data (for example, student ID or grade level via custom fields) they collect through Yura, and are responsible for limiting it to what is reasonably needed.
- Parents and eligible students. Requests to access, correct, or delete a student's education records should be directed to the School; we support the School in fulfilling them. Where required, the School is responsible for providing notices to, and obtaining consents from, parents and guardians.
- Deletion and return. When a School relationship ends, or upon a School's request, we will delete or return the School's student data within the timeframe stated in our agreement with the School (and no later than any deadline applicable law imposes — for example, North Carolina law requires deletion within 45 days of a school's request), except where law requires retention.
- Data processing agreements. We sign data processing/privacy agreements with School customers (including state or consortium standard forms where applicable). Where a signed School agreement conflicts with this Policy, the agreement controls for that School's student data.
- Breach notice. We will notify affected Schools without unreasonable delay of any breach involving their student data, consistent with our agreements and applicable law.
9. Children's Privacy
Yura is not directed to children under 13, and users under 13 are not permitted. We do not knowingly collect personal information from children under 13. School-provisioned accounts are intended for high-school students (13+). If we learn that we have collected personal information from a child under 13 without required consent, we will delete it promptly. If you believe a child under 13 has an account, contact us at admin@volunteeritude.com and we will investigate and delete as required, and we will honor a parent or guardian's request to review or delete their child's information as required by law.
For users aged 13–17, our Terms of Use require parental or guardian consent to use the Services, and where a School provisions accounts the School is responsible for any parental notice or consent its policies and applicable law require.
We apply additional protections to minors' data regardless of age: no targeted advertising, no sale of data, no AI training, and restricted-account data minimization for school-provisioned accounts (Section 8).
10. Your Rights and Choices
Available to everyone, regardless of state:
- Access and correction: view and update your profile and account information in settings at any time.
- Export: export your service-log history from the app (volunteers can self-export their logs); you may also request a copy of your personal information by email.
- Deletion: delete your account in Settings (on the web: Settings → Danger Zone; in the mobile app: Settings → Delete account) or by emailing us at admin@volunteeritude.com. Account deletion is permanent and immediate — your profile, service logs, journals, goals, awards, and document records are deleted and cannot be recovered. Copies that organizations exported before your deletion remain under their control. Uploaded files are removed from our storage systems following deletion; residual copies in encrypted database backups are purged on the backup provider's rolling schedule (approximately 30 days); and we may retain limited records where the law requires (for example, payment and tax records, and records of legal agreements).
- Email choices: unsubscribe from non-essential email via the link in any such email or in settings. Service and security emails (verification requests, password resets) are sent as needed while you have an account.
- Push notifications: enable/disable in your browser or device settings, and per-category in notification preferences.
- Profile visibility: volunteer profiles are private by default; note that administrators of organizations you belong to can view your profile information relevant to their program.
- Google account: you may disconnect Google Sign-In via your Google account permissions (ensure you have a password set first).
State privacy rights. Depending on where you live (for example, California, Virginia, Colorado, Connecticut, Texas, Oregon, Montana, and a growing number of other states), you may have rights to: know/access the personal information we hold about you; obtain a portable copy; correct inaccuracies; delete your personal information; opt out of sale, sharing for targeted advertising, and certain profiling (we do not do these); limit use of sensitive personal information (we use none for secondary purposes); and not be discriminated against for exercising rights. Some states also grant a right to appeal a refusal: if we decline your request, you may appeal by replying to our decision, and we will respond within the timeframe your state's law requires; if your appeal is denied, you may contact your state Attorney General.
To exercise any right, use the in-product tools above or email admin@volunteeritude.com with the subject "Privacy Rights Request." We will verify your identity (usually via your account email) and respond within the time required by your state's law (typically 45 days). An authorized agent may submit a request on your behalf with proof of authorization. For student education records held for a School, we will refer the request to the School as described in Section 8.
California notice at collection. In the last 12 months we have collected these categories of personal information (as defined by the CCPA/CPRA): identifiers (name, email, username, IP address); customer-records information (phone, billing information); characteristics of protected classifications only if you or your organization choose to provide them (for example, date of birth; note that volunteer activity can imply affiliations such as religious or cause-based interests); commercial information (subscription records); internet/network activity (usage data, device data); general (not precise) geolocation inferred from IP; audio/visual (photos you upload); professional/educational information (school affiliation, volunteer history, organization-defined fields such as student ID or grade); and inferences only as needed to operate the Services (for example, hour totals against goals). Sources, purposes, and recipients are described in Sections 2, 3, and 6. We do not sell or share personal information as defined by the CPRA, and we do not collect or use sensitive personal information for purposes requiring a right to limit. Retention is described in Section 13.
11. Security
We take security seriously and apply measures appropriate to the sensitivity of the data, including:
- encryption of data in transit (TLS/HTTPS enforced, including for our mobile app);
- passwords stored only as Argon2id cryptographic hashes (never in plain text);
- application-level encryption at rest for reflection and journal text, plus storage-provider encryption at rest for our database and file storage;
- role-based access controls (25-permission model) limiting what organization administrators can see and do; restricted-account protections for student accounts;
- rate limiting, login-attempt lockouts, and security audit logging of authentication and permission events;
- signed webhooks, scoped API credentials, and access-logged document storage with file-type (MIME/content) and size validation on uploads;
- vendor agreements requiring confidentiality and security for all subprocessors.
No system is completely secure. Please use a strong, unique password and contact us immediately at admin@volunteeritude.com if you suspect unauthorized access. If a security breach affects your unencrypted personal information, we will notify you and any affected customer organizations without unreasonable delay, consistent with applicable law (including S.C. Code § 39-1-90 and N.C. Gen. Stat. § 75-65) and our contractual commitments, and will notify regulators where required.
12. Third-Party Links and Services
The Services contain links to third-party sites (organization websites, social media, video-conference links for virtual events, maps). Their privacy practices are their own; review their policies before providing information. Public marketing pages on our site may embed third-party content (for example, a hosted demo video), which can receive standard technical data (like IP address) from your browser when it loads.
13. Data Retention
We keep personal information only as long as needed for the purposes described in this Policy:
| Data | Retention |
|---|---|
| Account and profile data | While your account is active; deleted immediately upon account deletion |
| Service logs, journals, goals, awards, documents | While your account is active; deleted with your account. Copies previously exported by organizations remain under those organizations' control |
| Organization-held records about non-users (imports, invites, verifier emails) | While the organization maintains them; organizations can delete them; deleted when the organization's account is deleted |
| Agreement/consent records (including IP and user-agent at acceptance) | Retained as evidence of consent while your account is active, then for 2 years after account deletion |
| Security/audit logs | Server audit logs per hosting-provider log retention; document-access audit trails for the life of the related organization account, then up to 2 years |
| Payment and tax records | Up to 7 years, as required for tax and accounting |
| Analytics data | Per PostHog retention settings |
| Encrypted backups | Purged on rolling backup cycles (approximately 30 days) |
| Student data held for a School | Per the School's agreement and instructions; deleted or returned at contract end or upon request (Section 8) |
Where this table and a signed customer agreement differ, the agreement controls for that customer's data.
14. Changes to This Policy
We may update this Policy as our practices, the law, or the Services change. For material changes we will: post the updated Policy with a new Effective Date and version; email the address on your account at least 30 days before the changes take effect (or such longer notice as our School agreements require); and display an in-product notice. For School customers, we will not make material changes to student-data practices without providing the notice required by our agreements and applicable student-privacy laws. If a change materially expands how we use previously collected personal information, we will obtain any consent the law requires. Prior versions are available on request.
15. Geographic Scope
The Services are operated from the United States, are intended for users located in the United States, and store data in the United States. If you access the Services from outside the United States, you do so on your own initiative, and your information will be processed in the United States. The Services are not directed to residents of the European Economic Area or the United Kingdom.
16. Contact Us
Volunteeritude LLC
4030 Wake Forest Road, Ste 349, Raleigh, NC 27609
Email: legal@volunteeritude.com (subject line "Privacy Inquiry" or "Privacy Rights Request")
We respond to privacy inquiries within 30 days, and to verified rights requests within the time applicable law requires.