Yes or Yes
Make a link

Privacy Policy

Last updated 2026-08-02

Yes or Yes lets you send someone a link that asks for permission, with a No button that runs away. There are no accounts here, so we never ask for your name, your email address or your phone number. This page is not a template: it describes what this service actually stores, and every claim on it can be checked against the code that runs the site.

The short version

We never ask you to register. We hold no email address, no phone number and no payment details, because nothing in the service ever collects them.

We never store your IP address. Where we need one to stop abuse we store a salted, one-way hash of it, and in most cases we hold that hash only in memory for a minute and then throw it away.

The question you write, the photo you attach and the design you pick are deleted 7 days after you create the link. The photo is deleted from storage, not just hidden.

We use no tracking pixels and no session recording, and nothing here tries to recognise you as a person. We do count page views, with one tool — Vercel Web Analytics — that sets no cookie and stores nothing in your browser. It loads on exactly the same pages as Google’s advertising script and no others: the home page, the three topic pages and these documents. Neither is loaded on the create page, the dashboard, or either of the two pages the recipient sees.

What a link stores when you create one

When you create a link we store the question, any supporting text, the labels you put on the two buttons, the taunts the running button shows, and the recipient’s name if you typed one. We also store the look you chose — theme, font, confetti and background effect — along with how the No button escapes and how many escapes it takes before No can be pressed, plus the language of the link.

We generate two identifiers for every link. The short public one appears in the address you share. The long secret one opens the dashboard where you watch for an answer. Anyone who has the public address can open the question; anyone who has the secret can see the answer. Neither is tied to you as a person.

If you attach a photo or a GIF, your browser shrinks it and uploads it to our file storage, where it gets a public address with a random suffix. Anyone holding that address can open the image — that is how the recipient’s browser and messaging-app previews load it. If you switch on the option to show the photo in the share preview, the image is also drawn into the preview card that services like WhatsApp, Instagram and KakaoTalk fetch when the link is pasted.

Everything in a link is free text you chose to write. Please treat it as public to anyone the link reaches: we have no way to control who the recipient forwards it to.

What the recipient’s visit stores

When someone opens a link we record that the link was opened, how many times that visitor has opened it, and when they first and last did so. When they answer we record the answer, how many times the No button escaped before they answered, and the time of the answer.

On a link addressed to several people, the person answering can type a name for themselves. That name is stored with their answer and shown on the sender’s dashboard. It is the only name a recipient can ever give us, and it is optional.

We do not store the recipient’s IP address, browser, device, screen size, referrer or location with any of this. The only thing that ties two visits together is the random visitor identifier described below.

Cookies and browser storage

gp_vid is a cookie holding a random identifier that our server creates the first time you open a link. It cannot be read by scripts on the page, it lasts 400 days, and it carries no name and no advertising value. It is strictly necessary for the service to work: it is how a one-to-one link locks after the first answer, and how opening the same link twice counts as one visitor rather than two.

gp_locale is a cookie that remembers the language you picked with the language switcher. It lasts 400 days and is only ever set when you use that switcher. Recipient pages ignore it entirely — a link is always shown in the language its sender chose.

gp_my_links is browser local storage on the device of someone who creates links. It keeps up to 50 entries, each with a link’s public address, its dashboard secret, its question and when it was made, so that the "my links" list on the home page can find your dashboards again. It never leaves your browser and is never sent to us; we cannot read it and we cannot delete it for you. Two consequences follow from that, and they pull in opposite directions: clearing your browsing data makes those dashboards unreachable forever, because the secret was only ever on your device; and anyone else using the same browser profile can open them. Do not create links you would not want seen on a shared or public computer.

Google sets its own advertising cookies on the pages that carry ads. That is covered in its own section below. The page-view counting on those same pages sets no cookie and stores nothing here; it has its own section too.

IP addresses and abuse limits

Anyone can create a link here without an account, so without some limit a single script could fill our database and our file storage in an afternoon. That is the only reason we look at IP addresses at all.

When you create a link we combine your IP address with a secret value that only we hold, hash the result with SHA-256, and store the hash on the link. We use it to count how many links one address made in the past hour and to refuse more than 10. The original address is never written anywhere. The hash cannot be turned back into an address without our secret, and we do not share it.

When someone opens a link, answers one, or asks to upload a photo, we hash the address the same way but keep the hash only in the server’s memory, for the length of the rate-limit window — one minute, or one hour for uploads. It is never written to the database. We made that choice deliberately: those two records are kept for a long time, and we did not want a visitor’s hashed address sitting in them forever.

The hash is deleted when the link expires. The row that held it survives, but the hash on it is blanked by the same scheduled job that deletes your question and your photo, because rate limiting only ever looks an hour back and a 7-day-old hash cannot serve it.

What we read but never store

When you arrive at the bare address of the site, and only then, we look at the language your browser asks for and at the country code our hosting provider attaches to the request, so we can send you to the English, Spanish or Korean version. Neither value is stored, and no other page on the site looks at them.

Our hosting provider keeps ordinary server logs of requests, as any web host does. We do not build anything on top of those logs and we do not join them to anything described above.

How long we keep things

A link expires 7 days after it is created. A scheduled job runs every day; for every expired link it deletes the uploaded photo from file storage and blanks the question, the supporting text, the button labels, the taunts, the recipient’s name, the image address, the whole design, the creator’s hashed IP address, and any name a responder typed for themselves. In practice that means everything a person wrote is gone within a day of expiry, and at most 7 days plus one after the link was created. After that the link shows only a message saying it is no longer available, and even the sender’s dashboard can no longer display the question.

Some things are kept indefinitely, and we would rather say so plainly than let you assume otherwise. We keep the fact that a link existed, its two identifiers, its language, its escape rules, and when it was made and expired. We also keep the shape of every answer and every visit: yes or no, how many escapes it took, when it happened, the view counts, and the random visitor identifier those rows are grouped by. That identifier is what makes one person opening a link five times count as one viewer rather than five, so removing it would collapse the very numbers the sender is left with.

We keep those for two reasons. The sender’s dashboard is the only thing this service gives back to the person who made the link, and it has to keep working after the link expires. And the number of escapes people actually sit through is what tells us whether the difficulty settings are sensible. Nothing in what survives is text a person wrote — everything anybody typed is deleted with the link.

Two things our deletion cannot reach, and you should know both. If you switched the photo into the share preview, messaging apps that fetched the preview card keep their own cached copy on their own servers; deleting ours does not delete theirs. And anything a recipient screenshotted or forwarded is simply out of everyone’s hands. If you want what we do hold gone sooner, or gone entirely, see the section on your rights below.

How we count visits

We use one measurement tool, Vercel Web Analytics, and only on the pages that also carry ads: the home page, the three topic pages and these documents. It tells us which of those pages are actually read and where readers arrived from. It is not loaded on the create page, the dashboard, or either of the two pages a recipient sees — so the address of a link, and the secret that opens a dashboard, are never reported to it.

It sets no cookie, and it writes nothing to your browser: no local storage, no session storage. We verified that by running the production script in a browser and watching what it touched, rather than trusting the description. Both the script and the page-view report are served from this domain, so visiting a page here sends no request to a third-party host on account of it.

Visitors are not counted with anything kept on your device. Vercel derives a hash on its own servers from the incoming request — your IP address together with your browser’s user-agent string — and that hash is what tells one visitor from another. We never receive it. It is valid for a single day and then reset, so it cannot connect you across two days, or to any other website.

Each page view reports the address of the page, the route pattern behind it, the page that referred you, the time, an approximate location Vercel derives from the request (country, region, city), your operating system, browser and device type, and the version of the measurement script. It never reports anything you wrote. Vercel discards the visit session after 24 hours and keeps the aggregate figures for a reporting window of 12 months.

Advertising

Third-party vendors, including Google, use cookies to serve ads based on a user’s prior visits to this website or other websites. Google’s use of advertising cookies enables it and its partners to serve ads to you based on your visit to this site and/or other sites on the Internet.

You can opt out of personalised advertising by visiting Google’s Ads Settings at adssettings.google.com. You can also opt out of a third-party vendor’s use of cookies for personalised advertising at aboutads.info/choices, or, in Europe, at youronlinechoices.eu. Opting out does not remove ads; it stops them being tailored to you.

We place ad slots on the home page and the three topic pages. Google can also place ads of its own on any page that loads its script, so treat that list as where we put them rather than as an exhaustive list of where they can turn up. There are four screens where Google’s advertising script is not loaded at all, so it cannot set a cookie there either: the page with the running button, the result page that shows the answer, the create page and the dashboard. The running-button page has been a deliberate rule of this product from the start: an ad next to a button that moves is an invitation to click it by accident, and Google’s own policy treats that as a violation. The other three lost their ads in August 2026, when Google’s review judged them to be screens without anything to read.

Our advertising account is still under review, so ad slots may be empty while you read this even though the script is loaded. If you are in the European Economic Area, the United Kingdom or Switzerland and want to refuse advertising cookies before a consent tool is available here, use your browser’s cookie controls together with the opt-out links above.

Who else handles the data

The site runs on Vercel, which also stores the photos you upload, keeps the ordinary request logs mentioned above, and runs the visit counting described above. The database is Neon. Advertising is Google. Those three, and nobody else, can reach the data described on this page. We do not sell it and we do not share it for marketing. Counting visits did not add a fourth company: it happens inside the same hosting provider the site already runs on.

These providers may process data outside your own country, including in the United States.

The fonts on this site are downloaded when the site is built and served from our own domain, so your browser makes no request to Google’s font servers when you visit. We mention it because policies often claim the opposite by copying a template.

Why we are allowed to hold this

If the GDPR or the UK GDPR applies to you: we rely on the necessity of providing a service you asked for when we store the content of a link, show it to the recipient and report the answer to the sender. We rely on our legitimate interest in keeping a free, account-free service usable when we count views and when we hash IP addresses to stop abuse. The same legitimate interest covers counting page views, which produces totals rather than a profile of you. Where advertising cookies are used, the lawful basis is consent, and the opt-out routes above are how you exercise a choice today.

Cookies that are strictly necessary to deliver the service you asked for — gp_vid — do not require consent under the ePrivacy rules, because without them a one-to-one link could not lock after the first answer. The visit counting falls outside those rules for the opposite reason: it stores nothing on your device and reads nothing from it, and storing or reading is the act those rules govern. The consent tool mentioned in the advertising section is about advertising cookies; it will not change how visits are counted.

Your rights, and how to use them

You can ask us for a copy of what a given link holds, to correct it, to delete it, to restrict what we do with it, or to object to it. Depending on where you live these rights come from the GDPR, the UK GDPR, Korea’s Personal Information Protection Act or a similar law, and we handle every request the same way regardless.

There is no delete button in the product, and we would rather tell you that than pretend otherwise. Because there are no accounts, the service has no way to prove that a particular link is yours. Requests are handled by hand: message the operator on Instagram at tastekim_ with the full address of the link. The operator can block it straight away, at which point it returns "not found" everywhere on the site, and can then delete its records.

You do not have to be the person who created a link to ask for it to be taken down. If a link is about you, or carries a photo of you, the same route applies and we will act on it.

You can clear the cookies described above at any time in your browser settings. Clearing gp_vid means a one-to-one link you already answered will let you answer again, and a return visit will be counted as a new viewer.

If you think we have handled your data badly, you can complain to your national data protection authority.

Children

This service is not directed at children, and nothing on it is designed for them. Do not use it if you are under 13, or under the age at which you can agree to online services on your own where you live — in parts of the European Economic Area that age is 16.

If you believe a child has sent us something through this service, tell the operator using the contact route above and we will remove it.

Security, and what this service cannot protect

Everything is served over HTTPS. The dashboard secret is long enough that it cannot realistically be guessed, and it is the only key to a dashboard — treat it like a password, and be careful where you paste it.

Two things are worth knowing plainly. Anyone who has a link’s public address can open the question and answer it, because that address is the only thing standing between the link and the world. And an uploaded photo lives at a public address for as long as the link does: it is unguessable, but it is not access-controlled.

The lock on a one-to-one link is a nicety, not a security boundary. It relies on a cookie, and someone who opens the link in a different browser will be treated as a new visitor. The dashboard shows when that has happened rather than hiding it.

Changes, and which language wins

If we change what this policy says, we change the date at the top. Where a change materially affects what we collect or how long we keep it, we will say so in the text rather than quietly editing a sentence.

This policy exists in English, Spanish and Korean. The three are meant to say the same thing; if they ever disagree, the English version is the one we mean.

Questions about any of this go to the operator on Instagram at tastekim_.