Publication review required
How repair data is handled
YourTech limits collection, copying, storage, and transfer to the agreed service purpose and keeps customer credentials outside diagnostic packages and public forms.
- Effective date
- August 24, 2026
- Last updated
- August 23, 2026
- Applies to
- YourTech intake, diagnostic, backup, restore, report, and support workflows
Public intake
Public intake collects general contact, location, device, and problem information through Zoho Forms only when that feature is enabled. It has no attachment or file-upload field. Do not enter passwords, PINs, Social Security numbers, banking or card details, or other unnecessary sensitive information. Submitting intake does not authorize remote access.
Job and consent records
The private owner system uses a non-identifying customer or device alias, a service category, job status, consent version, provider, timestamps, and limited authorization facts. An attended-session record must link the customer acknowledgment to a job, device, consent version, provider, timestamp, technician, and source reference. Continuing access is a separate private record with purpose, scope, expiration, revocation, provider permissions, and agent-removal status.
Backup and transfer
The technician toolkit selects approved local user-data categories and is designed to detect and exclude supported cloud-synchronized roots, mapped or UNC network locations, and junction traversal. It also excludes credentials, authentication tokens, browser passwords, unsupported mail caches, and protected system paths from the authorized backup scope. Downloads remain excluded unless deliberately selected for each user. A manifest and SHA-256 checks support verification; they do not guarantee that every environment is detected or that a source device or destination will remain available.
Private reports
Diagnostic reports may contain exact local paths, device identifiers, scan evidence, configuration facts, and errors needed for service. A separate redacted copy replaces configured personal identifiers with stable tokens where practical. Reports contain no active scripts and, when upload is enabled, use a short-lived, one-use, job- and report-scoped upload authorization with private storage, type and size limits, integrity verification, and audit events.
Retention and deletion status
Reports remain private while the related job is open and become eligible for owner-controlled deletion 90 days after the job closes. The current maintenance action is manual and audited; the site does not claim automatic deletion. Audit events are retained at least 12 months. Continuing-access authorization records remain for 24 months after expiration, revocation, agent removal, or job closure—whichever is latest—without extending active access. The owner portal exposes report eligibility, authorization expiry, revocation, removal, and record-retention status.
Credentials and sensitive secrets
Customers should enter private credentials themselves when possible. The toolkit does not copy passwords, browser credential databases, saved sessions, authentication tokens or cookies, product keys, recovery keys, or saved Wi-Fi secrets. Remote session codes, upload-token values, payment tokens, and provider secrets are not intended for reports or audit metadata.
Optional AI-assisted analysis
No report is sent to ChatGPT or another AI provider automatically. A technician must deliberately select a redacted copy, review it, and submit only the minimum material needed. The full private report is not automatically transmitted, and customer files and malware samples are not uploaded through this workflow. Redaction is designed to reduce unnecessary personal information by removing or replacing configured identifiers, but it does not guarantee anonymity and may retain device facts or stable replacement tokens needed to interpret findings. AI recommendations are advisory. The technician remains responsible for reviewing them, and the toolkit never automatically executes AI-generated commands or modifies the customer device from AI output.
Customer choices and questions
A customer can ask what categories are being copied, decline an optional transfer or AI-assisted review, end an attended remote session, or request deletion of eligible YourTech-held information. Some records may remain when needed for an active job, invoice, dispute, security investigation, provider requirement, or lawful obligation. Contact support@yourtechit.com with questions.
