Legal

Privacy Policy

JARO exposes a browser-visible privacy surface for account, AI-processing, billing, and operational data handling.

Version

1.0

Effective

2026-03-21

Updated

2026-03-21

External legal review pending.

This public trust surface is active for operational transparency, but attorney review, trademark validation, and company-formation hardening remain tracked as external owner blockers before broader public launch claims.

Who processes your data

JARO AI operates JARO as an AI-assisted planning service. Privacy questions and data-rights requests can be sent to [email protected].

What data JARO processes

  • Account identifiers and authentication/session material needed to sign you in.
  • Conversation content and planning inputs required to generate AI-assisted outputs.
  • Usage, quota, and security telemetry used to operate the service and prevent abuse.
  • Billing metadata and subscription state when commercial billing is activated.

How data is used and shared

JARO uses your data to authenticate your account, generate planning responses, maintain conversation continuity, detect abuse, meter usage, and satisfy operational and legal obligations.

Data is shared only with the processors required to run the service, including hosted infrastructure, payment processing, and LLM inference providers. The active Sprint 4 evidence pack tracks Google, OpenAI, Anthropic, Stripe, and Railway as core sub-processors.

Cookies and session data

JARO uses strictly necessary authentication cookies and server-side session material to keep the workspace signed in and defend the session boundary.

Analytics, advertising, and other non-essential tracking cookies are not assumed by default on the public browser shell.

Retention, rights, and deletion

Data is retained according to operational, billing, security, and compliance requirements. Users may request access, correction, deletion, restriction, objection, or portability through the privacy contact.

Self-serve deletion remains a later product hardening item, so Phase 9 beta requests are fulfilled through the support and privacy mailbox workflow.

Security and breach response

JARO applies transport security, session controls, abuse defenses, and encrypted storage patterns appropriate to the current runtime. If a personal-data breach is confirmed, the service follows the Sprint 4 breach-notification procedure, including the GDPR Art. 33 72-hour notification lane where applicable.

Contact