1. App Purpose
The app is used for enterprise sign-in and account linking workflows only. It does not sell data, run unauthorized profiling, or process Yahoo API data for unrelated advertising purposes.
2. OAuth Scopes Requested
openidfor identity authenticationprofilefor basic account profile displayemailfor account identification and notices (when granted)
3. Data Fields Processed
- Yahoo UID / subject identifier
- Display name, avatar, email (scope dependent)
- Login timestamp, IP, device metadata, and security logs
Data Use, Retention, and Deletion
Use Limitation
Data is used only for authentication, account management, security controls, and support operations.
Retention
- Yahoo API profile fields: retained for no longer than 24 hours
- Required OAuth tokens: retained only while account linking is active
- Security audit logs: default 90 days
Deletion and Revocation
Users may request deletion or authorization revocation through support@hcytechsoft.com. Tokens are disabled within 24 hours after revocation, and related data is deleted or anonymized per policy workflow.
Policy URLs for Yahoo Review
The links below can be submitted directly in Yahoo Developer review materials.