Skip to main content

YEE Audit Tools

Privacy Policy

This Privacy Policy explains how the Youth Enabling Environments Audit Tool ("YEE Audit Tools," "YEE," "we," or "us") handles information across the YEE web platform and mobile field-audit application.

Effective September 22, 2026Web + mobile

No ads or data sales

YEE does not sell personal information or use audit data for targeted advertising.

Role-scoped access

Auditors, managers, and administrators receive different access based on their responsibilities.

Offline fieldwork

The mobile app can keep assigned work and in-progress audit data on the device so fieldwork can continue offline.

The short version

YEE collects the information needed to create accounts, assign fieldwork, complete audits, synchronize offline work, generate reports, and keep the service reliable. Access is limited by role and organization. We do not sell user data or run advertising in YEE.

1. Information we collect

Depending on your role and how your organization uses YEE, we may process:

  • Account and profile information: name, email address, organization or institution, account role, job title, professional disciplines, optional phone number, account status, and generated user or auditor identifiers.
  • Project and place information: research projects, assigned places, place details, project membership, and assignment records entered by authorized managers.
  • Audit and research information: survey responses, domain weights, comments, section comments, submission status, timestamps, scores, and report/export data.
  • Technical and usage information: app or browser version, operating system, device and network information, IP-derived technical information, page or screen views, taps/clicks, app lifecycle events, errors, diagnostics, and performance data.
  • Local offline data: the mobile app stores assigned places, instrument content, in-progress drafts, pending synchronization records, and related metadata on the device so audits can continue without a network connection.

YEE does not request device GPS, camera, microphone, contacts, or photo-library access as a standard part of the audit workflow. A place being evaluated may have location information entered by an authorized manager, but that is information about the research site, not a continuous record of an auditor's device location.

2. How we use information

We use information to create and maintain accounts; assign auditors; save, synchronize, submit, score, and report audits; support offline fieldwork; generate authorized reports and research exports; maintain security and reliability; and respond to support, privacy, and account requests.

3. When information is shared

We do not sell personal information and do not share YEE data for targeted advertising.

  • Authorized people in your YEE workspace. Managers can access information needed to manage their organization's projects, auditors, audits, and reports. Platform administrators may have broader access for system administration.
  • Service providers. YEE may use providers for application hosting, database hosting, mobile app delivery and updates, maps/place lookup, analytics, and error monitoring.
  • Research or institutional recipients. Authorized exports or reports may be shared by the organization running a project according to its research protocol, consent process, institutional requirements, and applicable law.
  • Legal and safety purposes. We may disclose information when reasonably necessary to comply with law, protect users, investigate misuse, or protect the service.

4. Analytics and diagnostics

When enabled in a YEE deployment, we use PostHog for product analytics and session replay and Sentry for crash, error, and performance monitoring. These tools may receive a YEE user identifier, email address, role, organization or account context, device/app information, navigation events, and diagnostic information.

Session replay can record interaction context such as screens viewed, taps/clicks, and on-screen content to help diagnose usability and reliability problems. YEE does not use session replay for advertising.

The web application may also use Google Maps or Places services for manager-entered place search and map previews when configured. The mobile application uses Expo services for application delivery and updates.

5. Access and research privacy

YEE uses role-based access controls. Auditors are limited to their assigned fieldwork and their own submissions. Managers are scoped to their organization's projects and may review submissions, reports, and authorized raw-data exports. Platform administrators may access system-wide data when needed to operate the service.

Reporting and comparison surfaces are designed to use generated auditor identifiers, such as AUD-001, instead of personal names where a full identity is not needed. Organizations should avoid entering unnecessary personal or sensitive information in free-text audit comments.

6. Security and offline storage

YEE uses administrative and technical safeguards intended to protect information. On the web, authentication tokens are stored in an HttpOnly session cookie with secure production settings. On mobile, authentication sessions and offline-login credentials are stored using the operating system's secure storage when available.

To support offline fieldwork, in-progress audit drafts and synchronization queues are stored locally in account-scoped device storage. Application-level encryption is not currently enabled for those local draft records. Protect access to any device used for YEE fieldwork, and remove app data before transferring a device to another person.

Production network traffic is expected to use HTTPS/TLS. No method of storage or transmission is completely secure, so we cannot guarantee absolute security.

7. Retention and account deletion

We retain account and project information for as long as it is reasonably needed to provide YEE, administer the relevant research workspace, maintain security, and satisfy applicable institutional, legal, or research-record obligations.

Mobile offline drafts may remain on a device until they are submitted, cleared, or the application data is removed. Submitted audit records may be retained by the organization operating the project under its approved research or records-retention requirements.

Request account deletion

Email j.loebach@cornell.edu with the email address used for your YEE account and the name of your organization. The request will be verified before account-linked personal information is removed.

Where a submitted research record must be retained, we may retain or de-identify that record as permitted or required by the applicable research protocol, institutional policy, or law. Deletion may take additional time to propagate through backups and security logs.

8. Youth participants

YEE is designed for youth-engaged environmental assessment and may be used by youth participants as part of an organization-led research, education, or community project. Organizations using YEE are responsible for determining participant eligibility and obtaining any parental permission, participant consent or assent, ethics approval, or other authorization required for their project.

YEE does not use youth audit information for targeted advertising and does not sell that information.

9. International processing

YEE and its service providers may process or store information in the United States or in other countries where the relevant service provider operates. If you access YEE from outside the United States, your information may therefore be transferred across borders.

10. Changes to this policy

We may update this Privacy Policy when YEE features, data practices, or legal requirements change. The effective date at the top of this page will be updated when a revised policy is published.

11. Contact

YEE Audit Tools is developed for the Youth Enabling Environments project in collaboration with the DECA Lab (Design Environments with/for Children & Adolescents) at Cornell University.

Privacy questions or deletion requests

j.loebach@cornell.edu

DECA Lab, Department of Human Centered Design, Cornell University, Ithaca, New York, United States.