Effective Date: July 15, 2026
Version: 2.0 (replaces Version 1.0, effective December 16, 2025)
Yura is a volunteer management platform operated by Volunteeritude LLC, a North Carolina limited liability company ("Volunteeritude," "Yura," "we," "our," or "us"). This Privacy Policy explains how we collect, use, store, share, and protect information about users of our websites (including useyura.com and volunteeritude.com), our web application, our mobile application, and related services (collectively, the "Services").
This Policy applies to volunteers, organization administrators, school and university personnel, students, and visitors to our public pages. If you use the Services through a school, university, or other organization, that organization's agreement with us (including any data processing agreement) may provide additional protections; where a signed agreement with a customer conflicts with this Policy, the agreement controls to the extent it is more protective of your information.
Summary of key points (the full sections below control):
Volunteeritude LLC operates the platform under two names: "Volunteeritude" and "Yura." Both names refer to the same company, the same platform, and the same data practices. References to "Yura" in the product, our marketing, or this Policy mean Volunteeritude LLC.
This Policy does not apply to:
Account registration. Name, email address, username, and a password (which we store only as a cryptographic hash — see Section 11). Registration through Google Sign-In provides us your name, email address, and profile picture from Google instead of a password. At self-serve signup we also ask your date of birth to confirm you're old enough to have an account — we don't store it; we keep only a record that your age was verified.
Volunteer profile (optional fields). Bio, skills and interests, city, state, ZIP code, phone number, date of birth, and a profile photo. Except where noted, profile fields are optional. High-school student accounts provisioned through a school are "restricted" accounts: we do not collect phone number, date of birth, or city/state/ZIP for those accounts, and our systems reject attempts to add them (Section 8).
Volunteer activity data. Service logs (activity description, date, hours, the organization or verifier involved); a 1–5 mood rating (recorded as neutral unless you change it) and an optional free-text reflection on each log; journal entries; goals; awards and recognitions; event registrations and attendance status (including check-in and no-show records); program shift assignments and availability.
A note on reflections and journals: these can contain personal thoughts. We encrypt reflection and journal text at rest in our database, and we do not use this content for analytics, advertising, or AI model training. Journal entries are private to you unless you choose to make one public.
Information organizations collect about you through Yura. Organizations you join may, at their discretion:
The organization defines the content of these fields, forms, and requests; we store the responses on the organization's behalf. Organizations are contractually required to collect only what they reasonably need and to obtain any consents required by law (see our Terms of Use).
Organization information. For organization accounts: organization name, type, and category; EIN; address, phone, website, and social links; logo and branding; and the names, emails, and contact details of organization administrators.
Payment information. For paid organization subscriptions, payments are processed by Stripe. We receive and store billing contact details, subscription status, and invoice metadata. We never receive or store full payment card numbers. Schools and other institutions are typically billed by invoice rather than through Stripe.
Communications. Support requests, contact-form submissions, in-app feedback and bug reports, feature-poll votes, and feedback you give on AI features.
Agreement records. When you accept our Terms of Use or Privacy Policy (or accepted our historical Beta Agreement), we record the agreement type, version, timestamp, and the IP address and browser user-agent from which you agreed. We keep these records to document consent.
If you receive an email from Yura because someone identified you (as a verifier or invitee), we use your email address only for that purpose and you may disregard the request.
We use personal information to:
We do not use personal information for third-party advertising, and we do not build advertising profiles. We do not make automated decisions about you that have legal or similarly significant effects.
Some Yura features for organization administrators use large-language-model technology provided by Anthropic (the Claude API):
Commitments that apply to all AI features:
/ingest analytics endpoint; core Services continue to work.We do not sell, rent, or trade personal information. We have never sold personal information. We do not share personal information for cross-context behavioral advertising.
We share information only as follows:
When you join an organization (or your school provisions your account), that organization's administrators can see, for their program: your name and email; your service logs with that organization (activity, date, hours, verification status, and any custom fields attached to those logs); your event registrations and attendance; program shift assignments and availability; your responses to that organization's custom fields, applications, and document requests; your total hours; and awards granted by that organization.
If you are connected to a school or other institution: to support graduation, honor-society, and recognition tracking, administrators at your school can see your individual service logs across all organizations — including the activity, date, hours, organization name, and verification status of hours you log with other organizations — as well as your total hours.
Administrators of organizations you belong to can view your profile even if your profile is set to private. Organizations may export the data described above (for example, to CSV, Excel, or PDF reports) for their volunteer-management, compliance, and reporting purposes; once exported, that copy is under the organization's control and its policies.
Your reflections and journal entries are not shared with organizations, and organization data views and exports exclude them. Your individual mood ratings are for your own reflection tools and are not shown to organizations; organization dashboards may show aggregate, non-identifying mood trends (computed only across five or more volunteers, on a delayed basis).
If you request hour verification from someone outside Yura, that person receives your name and the details of the log you asked them to verify.
We use a small number of vendors to run Yura. Each may process personal information only to provide services to us, under contracts that require confidentiality and security. As of the Effective Date:
| Provider | Purpose | Personal information involved |
|---|---|---|
| Vercel | Application hosting, content delivery, server logs, performance monitoring | All Service traffic; server/audit logs (user ID, IP, user-agent) |
| Managed PostgreSQL provider — Neon | Primary database | All application data |
| Cloudflare (R2) | Storage of uploaded images and documents | Profile photos, organization media, documents you upload |
| Postmark (ActiveCampaign) | Transactional and notification email delivery | Name, email address, message content |
| Stripe | Payment processing for organization subscriptions | Billing contact and payment details (card data goes to Stripe, not us) |
| Anthropic | AI features (Section 4) | Volunteer names/emails and org data within an admin's AI request |
| PostHog | Product analytics and error tracking | User ID, name, email, role, organization, usage events, device data |
| Pusher | Real-time in-app notifications and dashboard updates | User IDs and notification payloads |
| Upstash | Rate limiting | Rate-limit keys, including IP addresses and user identifiers |
| Sign-in (OAuth) | Google account name, email, profile picture | |
| Browser push services (Apple, Google, Mozilla) | Web push notifications you enable | Push subscription tokens, notification content |
| Linear | Internal tracking of user-submitted feedback and bug reports | Your name, email, and the content of your feedback |
We will update this list when providers change; material changes are announced under Section 14. School customers receive subprocessor commitments in their data processing agreements.
We may create and use aggregated or de-identified data (data that can no longer reasonably identify you) for statistics, research, and product improvement, and we commit to not attempting to re-identify it. We do not use student data to create de-identified data for commercial purposes unrelated to the Services.
This section applies when a school, district, university, or other educational institution ("School") uses Yura for its students.
Yura is not directed to children under 13, and users under 13 are not permitted. We do not knowingly collect personal information from children under 13. School-provisioned accounts are intended for high-school students (13+). If we learn that we have collected personal information from a child under 13 without required consent, we will delete it promptly. If you believe a child under 13 has an account, contact us at admin@volunteeritude.com and we will investigate and delete as required, and we will honor a parent or guardian's request to review or delete their child's information as required by law.
For users aged 13–17, our Terms of Use require parental or guardian consent to use the Services, and where a School provisions accounts the School is responsible for any parental notice or consent its policies and applicable law require.
We apply additional protections to minors' data regardless of age: no targeted advertising, no sale of data, no AI training, and restricted-account data minimization for school-provisioned accounts (Section 8).
Available to everyone, regardless of state:
State privacy rights. Depending on where you live (for example, California, Virginia, Colorado, Connecticut, Texas, Oregon, Montana, and a growing number of other states), you may have rights to: know/access the personal information we hold about you; obtain a portable copy; correct inaccuracies; delete your personal information; opt out of sale, sharing for targeted advertising, and certain profiling (we do not do these); limit use of sensitive personal information (we use none for secondary purposes); and not be discriminated against for exercising rights. Some states also grant a right to appeal a refusal: if we decline your request, you may appeal by replying to our decision, and we will respond within the timeframe your state's law requires; if your appeal is denied, you may contact your state Attorney General.
To exercise any right, use the in-product tools above or email admin@volunteeritude.com with the subject "Privacy Rights Request." We will verify your identity (usually via your account email) and respond within the time required by your state's law (typically 45 days). An authorized agent may submit a request on your behalf with proof of authorization. For student education records held for a School, we will refer the request to the School as described in Section 8.
California notice at collection. In the last 12 months we have collected these categories of personal information (as defined by the CCPA/CPRA): identifiers (name, email, username, IP address); customer-records information (phone, billing information); characteristics of protected classifications only if you or your organization choose to provide them (for example, date of birth; note that volunteer activity can imply affiliations such as religious or cause-based interests); commercial information (subscription records); internet/network activity (usage data, device data); general (not precise) geolocation inferred from IP; audio/visual (photos you upload); professional/educational information (school affiliation, volunteer history, organization-defined fields such as student ID or grade); and inferences only as needed to operate the Services (for example, hour totals against goals). Sources, purposes, and recipients are described in Sections 2, 3, and 6. We do not sell or share personal information as defined by the CPRA, and we do not collect or use sensitive personal information for purposes requiring a right to limit. Retention is described in Section 13.
We take security seriously and apply measures appropriate to the sensitivity of the data, including:
No system is completely secure. Please use a strong, unique password and contact us immediately at admin@volunteeritude.com if you suspect unauthorized access. If a security breach affects your unencrypted personal information, we will notify you and any affected customer organizations without unreasonable delay, consistent with applicable law (including S.C. Code § 39-1-90 and N.C. Gen. Stat. § 75-65) and our contractual commitments, and will notify regulators where required.
The Services contain links to third-party sites (organization websites, social media, video-conference links for virtual events, maps). Their privacy practices are their own; review their policies before providing information. Public marketing pages on our site may embed third-party content (for example, a hosted demo video), which can receive standard technical data (like IP address) from your browser when it loads.
We keep personal information only as long as needed for the purposes described in this Policy:
| Data | Retention |
|---|---|
| Account and profile data | While your account is active; deleted immediately upon account deletion |
| Service logs, journals, goals, awards, documents | While your account is active; deleted with your account. Copies previously exported by organizations remain under those organizations' control |
| Organization-held records about non-users (imports, invites, verifier emails) | While the organization maintains them; organizations can delete them; deleted when the organization's account is deleted |
| Agreement/consent records (including IP and user-agent at acceptance) | Retained as evidence of consent while your account is active, then for 2 years after account deletion |
| Security/audit logs | Server audit logs per hosting-provider log retention; document-access audit trails for the life of the related organization account, then up to 2 years |
| Payment and tax records | Up to 7 years, as required for tax and accounting |
| Analytics data | Per PostHog retention settings |
| Encrypted backups | Purged on rolling backup cycles (approximately 30 days) |
| Student data held for a School | Per the School's agreement and instructions; deleted or returned at contract end or upon request (Section 8) |
Where this table and a signed customer agreement differ, the agreement controls for that customer's data.
We may update this Policy as our practices, the law, or the Services change. For material changes we will: post the updated Policy with a new Effective Date and version; email the address on your account at least 30 days before the changes take effect (or such longer notice as our School agreements require); and display an in-product notice. For School customers, we will not make material changes to student-data practices without providing the notice required by our agreements and applicable student-privacy laws. If a change materially expands how we use previously collected personal information, we will obtain any consent the law requires. Prior versions are available on request.
The Services are operated from the United States, are intended for users located in the United States, and store data in the United States. If you access the Services from outside the United States, you do so on your own initiative, and your information will be processed in the United States. The Services are not directed to residents of the European Economic Area or the United Kingdom.
Volunteeritude LLC
4030 Wake Forest Road, Ste 349, Raleigh, NC 27609
Email: legal@volunteeritude.com (subject line "Privacy Inquiry" or "Privacy Rights Request")
We respond to privacy inquiries within 30 days, and to verified rights requests within the time applicable law requires.