NewYu policy
Privacy
How the current NewYu demo handles the Arena story preview, analytics, invitation access, abuse prevention, and checkout.
Account-free by default
The Arena story community is a preview you can explore without an account. Reading stories, trying reactions, or walking through the share flow does not require signing in.
There is no sign-in screen and no sign-up form. NewYu has no accounts at all: the former pages now redirect to the invitation page, which grants temporary browser access and creates no identity.
Nothing you write is stored or published yet
Arena posting and accounts are not live. The reactions and the share-a-story flow run only in your browser for the current session — nothing you type is uploaded, saved to a server, or published.
The stories and reaction counts shown in Arena are illustrative sample content, not real posts or live user activity.
Invitation access — no email, no account
NewYu is in private preview and does not collect email addresses. The email waitlist has been retired, and the endpoint that received it now refuses every request.
Access is granted by an invitation code handed to you directly. Entering it stores a signed cookie in your browser that records only that a valid code was presented, when it was presented, and which invitation it was — never who you are. There is no account, no profile, no mailing list, and no database.
The invitation is a bearer capability: anyone holding the code can enter, so it identifies an invitation and never a person. The session is temporary, expires on its own, and can be ended at any time with Leave private preview. Your invitation code itself is never stored or logged by NewYu.
The invitation and session values contain no email address, name, raw IP address, or user identity. Abuse prevention is described separately below.
Abuse prevention and request metadata
To slow invitation guessing during the live private preview, NewYu uses a hosting-edge rate limit on the invitation exchange. The hosting provider counts requests by IP address for a ten-minute window before the request reaches NewYu's application code.
NewYu's application also supports a separate rate limiter for public POST endpoints. It reads the IP-related forwarding headers your connection already carries and derives a one-way SHA-256 identifier from them together with the endpoint name. NewYu does not intentionally persist raw IP addresses in its own application storage, and the derived identifier is never joined to your invitation, your session, or anything you do inside the preview.
When the optional Upstash backend is configured, the derived identifier is stored under a temporary counter and expires with its window — ten minutes for the invitation endpoint and one minute for checkout. Without Upstash, the production application-level limiter permits the request and emits no rate-limit headers; the private-preview launch therefore relies on the separately configured hosting-edge rule for invitation protection. Local development uses temporary in-memory counters that discard expired entries.
This identifier is used only to limit request rates. It is never used for profiling, advertising, appearance or attractiveness analysis, rankings, or personalising what you see.
Separately from NewYu, the infrastructure that serves this site — including the hosting-edge firewall, network, and optional rate-limit provider — processes ordinary request metadata such as IP addresses and user agents as part of operating their services. That metadata is outside NewYu's application storage.
Saved guidance stays in your browser
Guidance you choose to save is stored only in your own browser, using local browser storage on this device. NewYu does not need an account or a server to save it.
It is not synced across accounts, devices, browsers, or private windows, and there is no cloud backup. Clearing your browser data, or using a different browser or device, can remove it.
If you would rather not store anything locally, simply do not use Save locally — you can still generate, copy, or export guidance without saving it.
Product analytics
NewYu may record lightweight product-usage events on its public pages — for example, clicking a pricing call-to-action — to understand how the demo is used.
Private-preview surfaces are excluded by construction. The invitation page, Arena, and the dashboard are served from a separate layout that mounts no analytics or performance component, and links entering them load a fresh page so no measurement script carries over from a public page. No usage event is sent from them either, because activity behind the gate would describe someone holding an invitation.
These events are designed to avoid anything you type, your email address, name, photos, payment details, and other free-text you enter.
Payments and checkout
Pricing is not purchasable today, and payments, checkout, and Apple Pay are not live.
NewYu does not collect, store, render, or log card details. When a Stripe test-mode checkout is configured, the payment page itself is hosted by Stripe, and the Stripe integration remains a test-mode foundation rather than live billing.
What NewYu does not do
NewYu does not score faces, rate or rank appearance, or make fixed-trait judgments, and there are no public rankings.
Anything in the Library or community is informational only and is not medical advice. Please avoid posting medical, financial, legal, or highly sensitive personal information, or anyone else's private images or information.
Children and minors
NewYu is not intended for children under 13, and children under 13 should not submit any personal information. NewYu does not knowingly collect personal information from children under 13, and no longer collects email addresses from anyone.
If you believe a child under 13 has submitted personal information, please contact the NewYu team through the channel where you received access so it can be removed. If you are under 18, please use NewYu only with a parent or guardian's awareness.
Keeping and removing information
Because posting and cloud storage are not live, there is no stored or published post history to keep or delete. Anything you type in the Arena preview or share flow stays in your browser for the session only.
There is no early-access mailing list and no stored email address, so there is nothing held about you to request or delete. Your preview session lives only in your own browser cookie: it expires by itself, Leave private preview clears it immediately, and clearing your browser data removes it.
Questions
For questions about this summary, reach the NewYu team through the channel where you received access.