Privacy Policy
Effective date: September 15, 2026
1. Introduction
At JESS AI LLC (hereinafter “Jess AI,” “we,” “us,” or “our”), we are committed to protecting your privacy. This Privacy Policy (the “Policy”) explains what personal data we collect, how we use and share it, how long we keep it, and the choices and rights available to you. The Policy applies to our website, our product and Chrome extension, and any other service that links to this Policy (the “Services”).
Please be advised, by using our Services, you consent to the personal information collection and processing practices described in this Policy.
2. Who This Policy Covers
Jess AI is used by businesses (“Customers”) to do work that may involve information about the Customer's own contacts. This Policy describes personal data we collect in three broad situations:
- Website visitors. People who visit our website without creating an account.
- Customers and their teams. People who sign up, and colleagues a customer invites, connects, or otherwise identifies to us (for example, teammates added to a Slack workspace).
- Customer content. Content that flows through while work is being performed, which may include personal data about the customer's own clients, prospects, or contacts, depending on what the customer connects.
3. If Your Data Reaches Us Through a Customer
Where we process that information solely on Customer’s instructions, we act as a service provider or “processor,” and the Customer is the party responsible for that data (the “controller” or “business”). If you are such an individual and have a question about that data, we recommend contacting the Customer directly; we will refer you to them if you contact us.
4. Information We Collect
4.1 Website Visitors
When you visit the website, request a demo, or join a waitlist, we may collect the following types of information:
- Contact and form information: name, email address, company, and any free-text message you submit through a demo request or waitlist form.
- Technical information: your browser's user agent string, IP address, and similar device information, some of which is captured in our security audit logs.
- Attribution information: UTM parameters, referrer URL, and landing page, used to understand how visitors find us.
- Behavioral analytics: pages viewed, features used, and similar interaction data, collected through an analytics provider.
- Advertising identifiers and conversion events, collected through an advertising pixel, for all visitors, including paid campaigns and outbound email links.
- Affiliate referral identifiers, collected through our affiliate tracking provider when you arrive via an affiliate link.
4.2 Customers and Account Holders
When you or your organization sign up, we collect:
- Workspace information: your Slack workspace ID and name, or Microsoft Teams tenant ID, and the OAuth access tokens that authorize us to operate in that workspace.
- Channel identities: depending on how you reach us, this may include your Telegram chat ID, phone number, Slack user ID, display name, and/or email address.
- Profile information you provide, such as your role, how you found us, the type of work you do, and your marketing communications preference.
- Team roster information: the names, email addresses, and Slack user IDs of colleagues you invite or connect to your account.
- Billing information: a customer and subscription identifier from our payment processor, and usage/token counts by AI model, used to calculate charges. We do not receive or store your card number — our payment processor handles payment details directly.
- Signup attribution: the marketing source associated with your account.
4.3 Customer Content
Because we work inside your tools and conversations, the largest category of personal data we process is content you and your organization generate or connect, including:
- Your full conversation history, across every connected channel, stored as structured message data.
- Long-term memory we derive about your business over time, including confidence scores for facts we have inferred.
- Knowledge base documents, files, and threads you upload or share with us.
- Artifacts we generate on your behalf, such as documents, images, and code.
- Credentials for connected third-party tools, encrypted at rest.
- Data returned by any third-party tool you connect us to. When you connect us with a CRM, email account, Google Drive, or any of the roughly 1,000 supported integrations, we can access and process whatever personal data that system holds, which may include information about your own customers, prospects, or contacts. We do not control and generally cannot predict what that data includes; you control which tools are connected and what we are instructed to do with them.
5. How We Use Personal Data
We may use personal data in the following ways:
- Provide the service, such as carrying out tasks you ask us to perform, and maintain memory across conversations so our assistance improves over time.
- Bill and meter usage, including per-task cost accounting and enforcing budget or spend caps.
- Send transactional communications, such as onboarding messages, usage and budget alerts, and account notices.
- Send marketing communications, only to individuals who have opted in, and honoring opt-outs at any time.
- Operate product analytics and measure the effectiveness of our marketing, including advertising conversions.
- Maintain security, prevent abuse, and keep audit logs of security-relevant actions.
- Administer our affiliate program and attribute referrals.
We do not sell personal data, and we do not use the content of your conversations, memory, or files to train our own or any third party's underlying Artificial Intelligence (“AI”) models.
4a. Google user data (Limited Use)
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: the use of raw or derived user data received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements. We do not use, transfer or sell Google user data, whether raw, aggregated or derived, to create, train or improve any generalized or foundational machine learning or artificial intelligence model. Google user data is used only to provide and improve the user-facing features you ask us to perform, and is never used for advertising. Google user data is never sent to third-party image or video generation services: image and video generation is turned off in any conversation that includes Google user data.
6. How We Share Personal Data
We share personal data with various service providers, including the providers listed below. Each service provider processes data on our behalf and only as needed to provide their function to us.
| Vendor | Purpose | What they receive |
|---|---|---|
| An AI model provider | The AI model behind our service | Conversation content, memory, and connected-tool data included in prompts |
| An Integration platform | Integration broker for ~1,000 connected tools | OAuth tokens and the data passed to and from connected tools |
| Our hosting provider | Application hosting and managed database | All data we store |
| Our primary chat channel | Where we talk with most customers | Messages and workspace identifiers |
| A secondary chat channel | An alternate way to reach us | Messages and chat identifiers |
| A third chat channel | An additional workspace platform we operate in | Messages and chat identifiers |
| Our payment processor | Payment processing | Billing identity; payment details are handled entirely by our payment processor |
| An email delivery provider | Transactional and marketing email | Names and email addresses |
| A messaging provider | SMS and WhatsApp messaging | Phone numbers and message content |
| A cloud sandbox provider | Cloud sandbox for code execution | Code and data processed during code tasks |
| An analytics provider | Product analytics (U.S.-hosted) | Usage events and device/browser data |
| Google Fonts | Fonts loaded from Google on each website page | Visitor IP address |
| An advertising platform | Advertising pixel | Visitor and conversion events, advertising identifiers, IP address, user agent, and hashed (SHA-256) email addresses for signups and leads, sent via both the browser pixel and the server-side Conversions API |
| An affiliate tracking provider | Affiliate tracking | Referral identifiers |
| An error monitoring provider | Error monitoring | Error context, which may incidentally include request data |
| An image and video generation provider | Optional image and video generation | Generation prompts |
| Optional customer-enabled integrations | Direct integrations some customers connect | Whatever data those integrations access |
We may also disclose personal data:
- to comply with law, legal process, or governmental request;
- to enforce our Terms of Service;
- to protect the rights, property, or safety of Jess AI, our customers, or others; and
- in connection with a merger, acquisition, financing, or sale of assets, subject to standard confidentiality protections.
7. Cookies, Pixels, and Similar Technologies
Our website uses cookies and similar technologies, including an advertising pixel and analytics tools, which load for visitors regardless of location and collect behavioral, device, and advertising data as described in Section 4.1. We do not currently display a cookie consent banner.
If you are located in the United Kingdom, the European Economic Area, or another jurisdiction that requires consent before non-essential cookies are set, please be aware that these technologies may load before you have an opportunity to opt out, and you should adjust your browser or device settings if you wish to limit this.
You can control cookies through your browser settings, and you can opt out of Meta's advertising use of your data through Meta's ad preferences, and of PostHog analytics by using available browser opt-out tools. Doing so may affect how the site functions.
8. Data Retention
We do not currently apply a uniform, automated retention schedule to most categories of data. In practice, our data retention practices include the following:
- Pending written approvals (actions awaiting your confirmation) are deleted after 2 days.
- Queued Chrome extension notifications are deleted 1 day after delivery.
- Conversation history, derived memory, uploaded documents, generated artifacts, and usage records are retained indefinitely, until you delete your account or request deletion, or as described below.
We may retain data for longer where reasonably necessary for security, fraud prevention, legal, tax, or accounting purposes.
When you delete your account, we reserve the right to revoke connected third-party authorizations first, then remove the personal data associated with your account from our production systems. Our deletion protocols are subject to the following limited exceptions:
- Security audit logs are retained after account deletion with your IP address and user agent removed. The tenant identifier remains so the security trail stays intact.
- We retain a workspace identifier after account deletion for a limited period to administer trial eligibility and prevent trial abuse.
Please be advised that demo and waitlist form submissions are matched to your account by email address and are deleted along with it. If you submitted a form using a different email address than the one on your account, contact us and we will remove it.
9. Your Choices and Rights
Whatever your location, we offer the following controls to every account holder:
- Export your data: request a complete export of your account data in JSON format through your account settings.
- Delete your account: request account deletion through your account settings, which revokes connected integrations and removes your account data as described in Section 8.
- Opt out of marketing: unsubscribe from marketing email at any time using the link in those emails, or by updating your marketing preference in your account. Transactional and account-related messages are not affected by this choice.
Depending on where you live, applicable law may give you additional rights over your personal data, such as the right to know what data we hold about you, to correct it, to delete it, to receive a portable copy, to opt out of certain uses (including targeted advertising or automated profiling), or to limit use of sensitive data, and the right not to be discriminated against for exercising these rights.
We aim to honor these requests for all individuals who contact us, even where not strictly required by law, subject to identity verification and reasonable limits.
We do not currently meet the revenue or data-volume thresholds that trigger certain state privacy laws such as the California Consumer Privacy Act, and, as of the date of this Policy, we do not have paying customers based in the United Kingdom or the European Economic Area. Because our marketing has reached individuals in the UK and traffic from anywhere in the world may reach our website, we address international considerations in Section 10.
To exercise any right described in this section, contact us using the details in Section 15. We may need to verify your identity before acting on a request.
10. International Visitors and Users
Jess AI is based in the United States, and we process and store personal data primarily in the United States through our hosting provider. If you access our website or product from outside the United States, your information will be transferred to, stored, and processed in the United States, where privacy laws may differ from those of your home jurisdiction.
We do not currently have paying customers based in the United Kingdom or European Economic Area, and we have not implemented a UK/EU-specific legal basis framework, a cookie consent mechanism, or the safeguards ordinarily used for international transfers of personal data (such as Standard Contractual Clauses). If you are located in the UK or EEA — including because you received marketing from us or visited our site — and you have questions about how your data is handled, please contact us using the details in Section 15. We are reviewing our practices in this area and this Policy will be updated as that review progresses.
11. Data Security
We maintain technical and organizational measures designed to protect personal data, including:
- Encryption at rest for third-party integration credentials.
- Tenant-scoped, HMAC-signed access tokens with distinct scopes for the dashboard and Chrome extension.
- Signature verification on inbound Slack and Telegram traffic.
- Rate limiting on public endpoints.
- Per-tenant spend caps enforced on every turn.
- Periodic internal security reviews.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal data, we will notify you and any applicable regulator as required by law.
12. Healthcare Data and HIPAA
We are not designed or configured to satisfy the requirements of the Health Insurance Portability and Accountability Act (HIPAA), and we do not currently offer a Business Associate Agreement. Please do not use our Service to process protected health information unless and until we notify you that a HIPAA-compliant offering is available.
13. Children's Privacy
We offer a business product intended for use by working professionals and their organizations. It is not directed to children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, please contact us and we will delete it.
14. Changes to This Policy
We may update this Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. If we make material changes, we will update the “Effective date” above and, where appropriate, provide additional notice such as an email or in-product notification. Your continued use after a change takes effect constitutes acceptance of the updated Policy.
15. Contact Us
If you have questions, concerns, or requests regarding this Policy or our data practices, please contact us at:
JESS AI LLC3434 Kildaire Farm Rd, Suite 135 PMB 506
Cary, NC 27518, United States
josh@tryjess.com