This policy explains how personal information is processed when you use JAERVIS.engineering (the "Service"). It is a privacy notice, not a request for blanket consent to data processing.
1. Who is responsible and how to contact us
Balazs Kerulo operates JAERVIS.engineering and is responsible for personal information processed to administer accounts and operate the Service. For privacy questions or to exercise your rights, email privacy@jaervis.engineering.
If you use the Service through an organisation, that organisation may be responsible for personal information in its workspace, with us processing it on the organisation's behalf. Your organisation determines who can access its workspace and how its content is used. Requests concerning that content may need to be handled with your organisation.
2. Information we process
- Account information: your user identifier, email address, profile details you provide, authentication and session information, and legal-acceptance records. If you use social sign-in, the identity provider supplies information needed for that sign-in.
- Organisation and workspace information: memberships, roles, invitations, projects, documents, document versions, uploaded files, templates, skillsets, and activity records.
- AI interactions: prompts, chat history, selected or retrieved project context, generated responses, asset interpretations, and document summaries.
- Operational information: subscription status, usage counters, and technical information received by the Service and its providers, such as IP addresses, browser details, request timestamps, and error information.
- Communications: information you send when contacting us, including privacy requests and the information necessary to respond to them.
Workspace content may contain personal information about other people. Submit only information you are authorised to share and that is necessary for your work. Avoid including sensitive personal information or secrets that the task does not require.
3. Purposes and legal bases
We use information to authenticate users, manage accounts and permissions, store and display workspace content, support collaboration, provide AI features, enforce usage limits, maintain security, diagnose failures, respond to requests, and meet legal obligations.
Where the GDPR or similar law applies, the relevant legal bases are performance of a contract with you or steps you request before entering one; legitimate interests in operating, securing, and supporting the Service, subject to your rights; and compliance with legal obligations. Where a processing activity requires consent, that consent must be obtained separately and can be withdrawn. Accepting the licence agreement does not provide consent for unrelated processing. For organisation-controlled content, the organisation is responsible for identifying its legal basis.
4. AI processing
AI features send relevant content to external AI providers. Depending on the feature and configuration, these providers include Google and Anthropic. Requests can include your prompts, conversation history, project context, document excerpts, or uploaded content needed to generate a response or interpret an asset.
AI processing is not limited to messages you send in chat. Saving or editing documents can automatically send document excerpts to Google to generate change summaries. Prompts, responses, and generated summaries may also be stored in your workspace.
AI-provider retention and any use for model improvement depend on the applicable provider terms and account configuration. This policy does not promise zero retention or exclusion from model training. Contact us before submitting information that requires particular processing restrictions. AI outputs can contain inaccurate personal information; verify outputs before relying on them and contact us about corrections where needed.
5. Who receives information
Information is processed by service providers supporting authentication (Clerk), database and storage services (Supabase), AI features (Google and Anthropic, as applicable), and the infrastructure used to host and deliver the Service. Each receives information relevant to the functions it performs. Provider handling is also subject to the applicable service terms and data-processing arrangements.
Content and activity may be visible to authorised members and administrators of your organisation or project. Content you publish, share, or export can reach the recipients you choose. We may also disclose information when legally required or necessary to protect rights, investigate abuse, or respond to security incidents, subject to applicable law.
6. Cookies and local storage
The Service and its authentication provider use cookies and similar browser storage to support sign-in, sessions, security, and application preferences. You can manage browser storage in your browser settings, but blocking essential authentication storage may prevent sign-in or disrupt the Service. Acceptance of the licence agreement is not consent to non-essential tracking.
7. Retention and deletion
Retention depends on the purpose of processing, the lifetime of your account and workspace, your organisation's instructions, and applicable legal, security, and dispute-resolution needs. Document versions, activity history, provider logs, and backups may have different retention periods from the current document or account record.
Deleting an account or item does not necessarily erase all associated versions, organisation-owned content, logs, or backup copies immediately. Contact us for a deletion request or information about retention applicable to your data. We assess requests under applicable law and explain any lawful grounds for retaining information.
8. International processing and security
Depending on hosting locations and provider arrangements, your information may be processed outside your country, including outside the EEA or UK. Where applicable law requires transfer safeguards, these must be established, for example through an adequacy decision or approved contractual safeguards. Contact us for details of the locations and safeguards applicable to your data; no particular data-residency region is promised by this policy.
The Service uses authentication and access controls to restrict access to workspace data. No online service or transmission method is completely secure. Protect your account credentials and review who has access to your organisation and projects.
9. Your rights
Depending on your location and applicable law, you may have rights to access, correct, delete, or obtain a portable copy of your personal information, restrict processing, or object to processing based on legitimate interests. Where processing relies on consent, you can withdraw it without affecting the lawfulness of processing before withdrawal. You may also complain to your local data-protection authority.
Send requests to privacy@jaervis.engineering. We may need to verify your identity and coordinate with your organisation before responding. Applicable exceptions and legal obligations may limit particular requests.
10. Changes to this policy
We will update the version and effective date when this policy changes and provide additional notice of material changes where required by law. New processing that requires consent will require separate consent; publishing a revised policy does not itself provide that consent.