Privacy policy
Privacy at a glance.
Effective August 15, 2026.
What WhyYes is for
WhyYes is decision support for live collectible auctions. It does not place bids, purchase items, operate auction controls, or access marketplace credentials.
Information we handle
When you start watching, WhyYes may process the visible auction-page context, including item imagery, seller, room, listing title, and bid or sale information. It may process a short audio sample only for a low-confidence, user-initiated fallback. We also handle account and device identifiers, extension version, settings and opt-ins, usage and diagnostic events, collection/watchlist entries and notes, identity corrections, and the resulting card identity, valuation, recommendation, and auction-history records.
Some information stays on your device: the extension keeps its device credential, optional marketplace username, outcome state, and any bring-your-own-key (BYOK) AI key in encrypted extension storage. BYOK keys are provider-scoped and are not put in Chrome sync storage, telemetry, exports, learning data, or our usage receipts. We do not collect marketplace passwords or other marketplace credentials.
Why we use it
We use this information to provide decision support, maintain your account and device session, calculate and display valuations, keep your collection and watchlist, secure and troubleshoot the service, enforce limits, provide support, and produce the export or deletion functions you request. WhyYes does not place bids, purchase items, operate auction controls, or use information for advertising or sale of personal data.
Service providers and other recipients
WhyYes uses Cloudflare to host and operate the application backend and its storage, cache, and queue services. When enabled for a request, visible item evidence may be sent to CardSight for recognition. If you select a BYOK AI provider, the relevant request data and your key are sent only to the provider you selected: xAI or OpenAI. Ollama is a user-configured self-hosted or local endpoint; WhyYes does not provide or transmit a vendor key for it. If the service needs additional completed-sale evidence for a resolved card, it may send only canonical card facts to Apify's configured market-data connector; it does not send frames, audio, transcripts, page or chat text, account or device identifiers, credentials, or raw provider payloads to that connector.
These providers process information under their own terms and retention policies. BYOK retention is controlled by your provider account. We do not add advertising, analytics, or third-party scripts to this site.
Retention, deletion, and shared evidence
WhyYes is designed not to retain raw frames, audio, transcripts, chat text, BYOK keys, raw provider responses, raw connector payloads, or raw recordings in its service records. Account-associated settings, activity, valuation, collection, and usage records are retained until you delete your account or they are no longer needed for the disclosed service and security purposes. You can request an account export or deletion from the extension; account deletion removes account-linked records and local account cleanup removes the local vault values described above.
Where product terms permit shared learning, WhyYes reduces auction outcomes to bounded normalized market evidence, such as canonical card identity, confidence/exactness, sale price, source boundary, and expiry. It excludes raw media, transcripts, page/chat text, credentials, and direct account/device identifiers. Account deletion removes your contributions and recomputes affected learning domains; reusable normalized market evidence is expiry-bound. Training eligibility is disabled by default and any future learned influence requires a separate reviewed, versioned product contract.
Chrome Web Store Limited Use
WhyYes affirms that its use of Chrome user data complies with the Chrome Web Store User Data Policy, including its Limited Use requirements. We use that data only to provide and improve the disclosed, user-facing decision-support feature and for security and support; we do not sell it, use it for advertising, or transfer it for unrelated purposes.
Your choices
You can stop using WhyYes at any time. For privacy questions or requests, contact privacy@whyyes.dev. For product or account help, contact support@whyyes.dev. To report a security issue, contact security@whyyes.dev.
Changes
We may update this policy as the product develops. The effective date above will change when we do.
