Privacy Policy
Version 2026-09-30 · Effective 2026-09-30
This policy explains what personal data jitprompt collects, why, who it is shared with, how long it is kept, and your rights. jitprompt is operated by Mirko Pace, an individual doing business as jitprompt, [MAILING ADDRESS] (“we”, “us”). Contact: privacy@jitprompt.com.
1. Two roles
- Controller — for the data about you as a user of the Service: your account, your sign-ins, billing, and our communications with you.
- Processor — for the documents organizations upload and the queries their agents send (“Customer Content”). The organization decides what goes in and is the controller; we process it on its instructions under our Data Processing Addendum. If you have a question about personal data inside an organization’s documents, contact that organization first; we will help it respond.
2. What we collect
| Data | Examples | Source |
|---|---|---|
| Account | email address, password (stored only as a salted scrypt hash), whether your email is verified, staff flag | you |
| Organization | organization name, members and their roles, invitations (the invited email address) | you, your colleagues |
| Sessions and security | session identifiers (stored hashed), IP addresses used for rate limiting and lockout, failed sign-in counts | your browser |
| Activity | an audit log of changes (who added a member, created or revoked an API key, changed a plan) | the Service |
| Usage | API keys (stored hashed) and when they were last used, counts of uploads and searches, model tokens used | the Service |
| Customer Content | uploaded files, their text, sections, summaries and embeddings; the “plan” text agents send to search | your organization and its agents |
| Billing (paid plans) | plan, subscription status, payment processor customer ID — card details go to the processor, never to us | you, the payment processor |
| Support | what you write to us | you |
| Early-access requests | your name, email address and what you’re building, from the form on jitprompt.com | you |
The app sets only strictly necessary cookies: a session cookie after you sign in, and a short-lived form-protection cookie before. It uses no analytics or advertising cookies. The website (jitprompt.com) sets no cookies and uses no analytics.
3. Why we use it (and the legal basis under the GDPR)
| Purpose | Legal basis |
|---|---|
| Create and run your account and organization, serve your documents to your agents | contract (Art. 6(1)(b)) |
| Send verification, password-reset, invitation and billing emails | contract |
| Security: rate limits, lockout, abuse prevention, audit log | legitimate interests in keeping the Service and its customers safe (Art. 6(1)(f)) |
| Plan limits, usage metering and cost tracking | contract; legitimate interests in pricing the Service sustainably |
| Billing, tax and accounting records | contract; legal obligation (Art. 6(1)(c)) |
| Answering support requests | contract; legitimate interests |
| Answering early-access requests and inviting you when signup opens | steps you asked for before a contract (Art. 6(1)(b)); legitimate interests |
We do not sell personal data, do not use it for advertising, and do not use Customer Content to train AI models. We send no marketing email without your consent.
4. Who we share it with
We use the service providers (“subprocessors”) listed at jitprompt.com/subprocessors, only to run the Service:
- ImprovMX — forwards email you send to our @jitprompt.com addresses, and early-access requests from the website, to our mailbox.
- Google (Gmail) — the mailbox where those messages are kept.
- Amazon Web Services — hosting, database, file storage, email delivery (United States, us-west-2).
- Anthropic — language models that split uploaded documents into sections and write their summaries. Receives document text.
- Voyage AI — embeddings for search. Receives document text and the plan text of searches.
- A payment processor, when paid plans launch — subscriptions and payments. It will be named here before it receives any data.
We may also disclose data if the law requires it, to protect the rights and safety of users or the public, or to a successor if the Service is transferred (you will be told, and this policy will keep applying).
5. International transfers
The Service runs in the United States. If you are in the European Economic Area, the United Kingdom or Switzerland, your data is transferred to the US. We rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum) with our subprocessors, and on the EU–US Data Privacy Framework where a subprocessor is certified. You can ask us for a copy of the relevant safeguards.
6. How long we keep it
| Data | Kept |
|---|---|
| Account data | until you delete your account (Account page, immediate) or ask us to (within 30 days); your address is also removed from organizations’ audit logs |
| Organization data | until an owner deletes the organization: purged 7 days after the request (cancellable until then) |
| Customer Content | while it exists in the Service; earlier versions of a document’s file as many as the plan keeps (e.g. the last 5), until newer versions replace them; a deleted document’s stored file remains in versioned storage for up to 90 days, and in database backups for up to 7 days |
| Agent call log (including search plan text) | 30 days |
| Application logs | 30 days |
| Rate-limit records (IP addresses) | at most 1 day |
| Sessions | 14 days, or until you sign out |
| Audit log and usage records | while the organization exists |
| Billing records | as long as tax law requires (typically 7 years) |
| Early-access requests | until you’ve signed up or told us you’re not interested, and at most 24 months |
7. Security
Data is encrypted in transit (TLS) and at rest (AWS-managed encryption for the database and file storage). Passwords, session tokens and API keys are stored only as hashes. Each organization’s data is isolated from every other’s, and access to production systems is limited to the operator.
8. Your rights
Depending on where you live, you have the right to access your personal data, correct it, delete it, receive it in a portable format, object to or restrict processing based on legitimate interests, and withdraw consent where we rely on it. EU/UK residents may complain to their data protection authority. California residents have the rights to know, delete and correct, and not to be discriminated against for exercising them; we do not sell or share personal information as those terms are defined in the CCPA.
You can download your account data and delete your account yourself from the Account page; an organization’s owners can export and delete its data from its Settings. For anything else, email privacy@jitprompt.com from your account’s address. We answer within 30 days (45 days for California requests). For Customer Content, we act on the instructions of the organization that controls it.
9. Children
The Service is not directed to children and is not for anyone under 16.
10. Changes
We will post changes here with a new version date and, for material changes, tell you by email or in the app before they take effect.
Contact: privacy@jitprompt.com