Privacy Policy
Last updated: July 9, 2026
This Privacy Policy explains how Jess (“Jess”, “we”, “us”), operated by Ghostify, collects, uses, shares, and protects information when you install or use the Jess application — available in Slack, Microsoft Teams, and messaging channels (Telegram, WhatsApp, and SMS) — together with our related websites and dashboards (the “Service”). By using the Service you agree to this Policy.
1. Who we are
Jess is an AI assistant (“AI employee”) that operates inside Slack, Microsoft Teams, and messaging channels (Telegram, WhatsApp, SMS), and acts across third‑party tools you connect. The data controller is Ghostify. Contact: josh@tryjess.com.
2. Information we collect
You / your workspace provide
- Slack / Teams workspace & account data: workspace name and ID, channel and user IDs, display names, and email addresses (via the platform’s API, with the scopes you grant at install).
- Messaging‑channel account data: for personal channels (Telegram, WhatsApp, SMS), the chat or user ID, phone number, and display name provided by that channel — the identifiers needed to receive your messages and reply to you.
- Messages and content: the content of messages, threads, files, and documents you send to Jess or in the channels and direct messages where Jess is present or is mentioned, used to understand and complete your requests.
- Knowledge base: text you add to Jess’s knowledge base.
- Integration credentials: OAuth tokens or API keys for third‑party tools you connect (e.g. Gmail, Google Workspace, HubSpot, GoHighLevel, Stripe, Meta Ads, Whop). These are encrypted at rest (AES‑256‑GCM) and are never exposed to the browser or to the AI model as readable text.
- Billing data: if you subscribe, payment is processed by Stripe; we store your plan status and a Stripe customer/subscription identifier, we do not store card numbers.
- Lead/contact data: if you submit a demo or waitlist form, the email and details you provide.
Collected automatically
- Usage & operational data: AI token counts, timestamps, request metadata, IP address, and user agent, used for rate limiting, abuse prevention, billing, and reliability.
- Audit logs: records of sensitive actions (installs, integration connects, policy changes) for security. Logs do not store secrets.
3. How we use information
- To provide the Service, respond to requests, run research, and take actions in the tools you connect.
- To send AI prompts and relevant context to our AI provider (Anthropic) to generate responses.
- To enforce usage limits, prevent abuse, and protect against runaway cost.
- To process billing and manage subscriptions (via Stripe).
- To secure, debug, and improve the Service, and to comply with law.
- Our team may review limited usage information — including a sample of the requests people make of Jess — to understand how the Service is used and make it better. Access is restricted to authorized staff and is never used to train third‑party AI models.
We do not sell your personal information. We do not use your private workspace content to train third‑party AI models.
4. AI processing
Jess uses large language models provided by Anthropic to generate responses and decide actions. Your request and the context needed to fulfill it (which may include message content and connected‑tool data) are sent to Anthropic for processing. Actions that modify data in sensitive integrations are gated by access controls and, where configured, require confirmation. AI output can be imperfect, see our Terms.
4a. Google user data (Limited Use)
Jess's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: the use of raw or derived user data received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements. We do not use, transfer or sell Google user data, whether raw, aggregated or derived, to create, train or improve any generalized or foundational machine learning or artificial intelligence model. Google user data is used only to provide and improve the user-facing features you ask Jess to perform, and is never used for advertising.
5. Sub‑processors & sharing
We share data with service providers only as needed to run the Service:
| Provider | Purpose |
|---|---|
| Anthropic | AI model processing |
| Slack / Microsoft Teams | Workspace platforms Jess runs in |
| Telegram | Messaging platform for the Telegram channel |
| Twilio | SMS & WhatsApp message delivery |
| Composio | Integration/OAuth connectivity to third‑party apps |
| Render | Application hosting & managed Postgres database |
| Stripe | Payments & subscriptions (if you subscribe) |
| The tools you connect | To perform the actions you request in them |
We may also disclose information to comply with law, enforce our Terms, or protect rights and safety.
6. Data retention
We retain workspace/account data, conversation history, knowledge‑base content, and connected credentials for as long as your workspace has Jess installed or your account is active, and delete or anonymize them within a reasonable period after you uninstall, stop using the Service, or request deletion. Audit and billing records may be retained longer where required for security or legal/accounting purposes.
7. Your rights & choices
- Access / export: a workspace admin can export their workspace’s stored data, email josh@tryjess.com or use the in‑product export where available.
- Deletion: uninstall Jess from Slack or Teams, stop messaging the bot, and/or email us to request deletion of your workspace’s or account’s data. We will delete it (subject to limited legal/security retention).
- Disconnect integrations: remove any connected tool at any time from the Jess dashboard; this deletes the stored credential for that tool.
- Depending on your location (e.g. EEA/UK under GDPR, California under CCPA/CPRA), you may have rights to access, correct, delete, port, or restrict processing of your personal data. Contact us to exercise them.
8. Security
We protect data with encryption in transit (HTTPS/HSTS) and at rest for credentials (AES‑256‑GCM), strict access controls, per‑tenant isolation, rate limiting, audit logging, and least‑privilege secrets. No method of transmission or storage is 100% secure, but we work to protect your information.
9. International transfers
We and our sub‑processors may process data in the United States and other countries. Where required, we rely on appropriate safeguards for international transfers.
10. Children
The Service is for business use and is not directed to children under 16. We do not knowingly collect their data.
11. Changes
We may update this Policy; we will revise the “Last updated” date and, for material changes, provide notice. Continued use after changes constitutes acceptance.
12. Contact
Questions or requests: josh@tryjess.com (Ghostify).