privacy policy
Privacy Policy
Effective 7 September 2026
the short version
Yugma keeps two people's video players in sync. To do that, our server passes small messages between you and the person you're watching with.
- No account. No sign-up. No profile. We never ask who you are, and we have no way to find out.
- We never touch the video. The film or show streams from Netflix, Prime Video or YouTube straight to you, exactly as it would without us. It does not pass through our server.
- What we do pass along: where you are in the video, when you play, pause, seek or change speed, your chat messages, your reactions, and a reference to what you're watching so we can take you both to the same episode. These are relayed to the other person; the server keeps only the room's current state, and only for as long as the room exists.
- We store nothing about your session. A room exists only while someone is in it, and is deleted roughly thirty seconds after the last person leaves.
- Chat is not end-to-end encrypted yet. Messages are protected in transit, but our server can technically see them as they pass through. We never store or log them. End-to-end encryption is planned.
- We count, but we don't identify. We keep totals — how many rooms were created this hour, how many joins failed — with nothing attached that could point back to a person.
That's the whole thing. The rest of this page says the same in more detail.
1. Who runs Yugma
Yugma is built and operated by Yash Vijay Patil, an individual based in India. There is no company behind it.
For anything on this page, including questions, requests or complaints: hello@yugma.app. That address is also the grievance contact under India's Digital Personal Data Protection Act, 2023.
2. What the extension sends to our server
When you start or join a watch party, the extension opens a connection to our relay server and sends only what's needed to keep two players together:
- A six-character room codeSo the right two people are connected
- Your position in the video, in secondsTo detect and correct drift between you
- Play, pause, seek and playback-rate eventsSo an action on one side happens on the other
- Ad-break start and end signalsSo the person not in an ad waits rather than running ahead
- Chat messages and reactions you sendTo deliver them to the other person
- A reference to what you're watching — which platform, its catalogue id and the title's name — and episode changesTo take you both to the same title and episode
- The extension's version number, once, when it connectsSo an outdated build can be told to update instead of half-working
Two things worth being direct about.
The reference travels through us. To take you both to the same episode, the platform, catalogue id and name of what you're watching pass through our server. They are relayed to the other person and held only as the room's current state while the room exists — never written to a database, never written to a log file.
Chat is not end-to-end encrypted today. Your connection to us is encrypted (HTTPS/WSS), so nobody on your network or ours in between can read your messages. But they pass through our server in readable form before being handed on. We do not store them, log them, or look at them, and the server keeps no copy once delivered. End-to-end encryption — where the message is unreadable even to us — is planned for a future release, and this page will be updated when it ships.
What we never receive: your name, email, phone number, streaming account details, viewing history, payment information, or anything you type outside of Yugma's chat box. We assign no identifier to you or your device. Two sessions by the same person are, to us, indistinguishable from two sessions by strangers.
3. What stays on your device
Some things are saved locally by the extension, in your browser's own storage. These never leave your computer and we cannot read them:
- Your chat transcript, so it survives a page refresh or a short absence. Each device keeps only its own copy, capped in size and stamped with the room's code. It is removed when you join a different room, when you come back and the room no longer exists, or after six hours without returning. We keep no copy at all.
- The last room code you used, so you can rejoin after a reload.
- A flag noting you've seen the first-run tour, so it doesn't show again.
- Diagnostic recordings, in developer builds only. The version on the Chrome Web Store contains no recorder. In a developer build a recording is kept in the page's memory and written only to your own computer when you export it. Nothing is uploaded. If you want to send one to us to help fix a bug, you export it as a file and send it yourself — that is the only way one ever reaches us.
Uninstalling the extension removes all of it.
4. What we store, and for how long
Rooms. A room lives in our server's memory while it's in use. It is deleted roughly thirty seconds after the last person disconnects (a little longer if their connection dropped rather than left, to let them come back). It is never written to a disk or a database.
Server logs. Our server writes technical logs — connection and disconnection events, error conditions, the hourly totals described in section 5 — to help us keep it running. They are kept on a short rolling window: each log is capped in size and cleared every week, so nothing in them outlives about a week. They do not contain your chat messages, the references to what you watch, or the codes of rooms that exist. We do not record your IP address in them; it is held in memory only while you are connected, to limit how fast one connection can create rooms.
Nothing else. We operate no user database, because we have no users to put in one.
5. Analytics
We need to know whether Yugma is actually working — whether people can create rooms, whether joins are failing, whether people are pairing up. We do this without identifying anyone.
Our server keeps running totals, written to its own log once an hour and then reset. For example: forty rooms created; thirty-one joins succeeded; six failed because the code didn't match a room; two rooms paired; how many watch suggestions were made on each platform.
The important part: these are counts, not records. There is no row for you. Every value is a number from a small fixed list — never free text, never a link, never a message, never an identifier. They go nowhere else: no analytics service receives them.
Failed joins. When a join fails because the code doesn't match any room, the server notes that code in its log so we can find out whether people are mistyping codes, using expired ones, or hitting a bug. A code that matches no room is not a secret — it identifies nothing and nobody. The code of a room that exists is never written to the log.
We do not use any of this for advertising and do not send any user identifier anywhere.
6. The website
yugma.app is the page you're reading. It is separate from the extension.
The waitlist form. If you join the waitlist, we receive the email address you type. It goes to a private Google Sheet that only the operator can open. We use it to tell you when we ship something — nothing else. We never sell it, never send marketing you didn't ask for, and never pass it to anyone. Ask us at hello@yugma.app and we'll delete your entry.
Site analytics. The website currently loads no analytics and sets no cookies of its own. If we add visit counting later, we will update this page first and, for visitors in the EU or UK, ask for your consent before anything is set.
Fonts. The typefaces on this site are served by Google Fonts, which receives your IP address when your browser fetches them.
7. Who else is involved
We keep this list as short as we can. In full, it is:
- Google Cloud — hosts our server, in Mumbai, India.
- Google Sheets — holds waitlist sign-ups, readable only by the operator.
- Google Fonts — serves the typefaces on yugma.app (see section 6).
- Cloudflare — provides DNS for yugma.app.
- The Chrome Web Store — distributes the extension and reports installation counts to us, in aggregate. Google's own privacy policy governs the store.
Netflix, Amazon Prime Video and YouTube are not our partners and receive nothing from us. Your relationship with them is entirely your own, governed by their terms and their privacy policies. Yugma does not log you in, does not touch your account, and does not change what they can see about your viewing.
8. Your rights
Because we hold almost nothing, most rights are simple to satisfy — often because there is nothing to act on.
If you are in India, under the Digital Personal Data Protection Act, 2023, you may ask what personal data we hold about you, ask us to correct or erase it, nominate someone to act for you, and raise a grievance. Write to hello@yugma.app and we will reply within a reasonable period. In practice, unless you have joined the waitlist, our honest answer will be that we hold no personal data about you at all. If you are not satisfied with our response, you may complain to the Data Protection Board of India.
If you are in the EU, the UK or the EEA, under the GDPR you have rights of access, rectification, erasure, restriction, portability and objection, and you may complain to your national supervisory authority. Our lawful basis for relaying your session data is the performance of the service you asked for; for our aggregate counts it is our legitimate interest in keeping the service working, which involves no personal data. An email you give us for the waitlist is processed with your consent, withdrawable at any time. Data held by Google on our behalf is transferred outside the EEA under Google's standard contractual clauses.
Everyone, wherever you are, can stop everything at once by leaving the room or uninstalling the extension. There is no account to close.
9. Children
Yugma is not intended for children under 13, and we do not knowingly collect anything from them. The streaming services Yugma works with require their own accounts with their own age requirements.
10. Security
Connections between your browser and our server are encrypted with TLS. The server holds no database of users and no stored session content, which means there is very little for a breach to expose. Our infrastructure is restricted to the ports needed to serve the site and the relay, with administrative access limited to the operator.
We are one person, not a security team. We have designed Yugma so that the worst case is small: there is no archive of who watched what with whom, because we never built one.
11. Changes to this policy
If we change how Yugma handles data, we will update this page and change the effective date at the top. Significant changes — particularly anything that widens what we receive — will also be announced in the extension itself. Continuing to use Yugma after a change means you accept the updated policy.
12. Contact
hello@yugma.app — for questions, requests, complaints, or anything on this page. The extension is on the Chrome Web Store; the rest of Yugma is on the home page.