Back to Jugg.ai

Privacy Policy

What we hold, why we hold it, who else touches it, and how to get it back.

Draft — pending legal review. This document has been drafted in-house and has not yet been reviewed by a lawyer. It states our genuine intent and current practice, and we will publish a reviewed version before it is relied on in a dispute. If a clause here matters to your decision, email support@jugg.ai and ask.
Provided by
Dylan Davies, trading as Jugg.ai, Wellington, New Zealand
Contact
support@jugg.ai
Last updated
28 August 2026

1.Who is responsible

Dylan Davies, trading as Jugg.ai, Wellington, New Zealand, is the agency (under the New Zealand Privacy Act 2020) and the data controller (under the UK/EU GDPR) for the personal information described here.

Privacy Officer: Dylan Davies — privacy@jugg.ai.

2.What we store

  • Account. Your name, email address and avatar as your sign-in provider (Google, GitHub or Microsoft) reports them, and the OAuth tokens for that sign-in — encrypted at rest with AES-256-GCM.
  • Organisation. Org name, members and their roles, invitations, plan and subscription state, and your spend caps.
  • Model provider keys. The API key you paste for your model provider, encrypted at rest. It is never returned to the browser and never logged — the product only ever shows a masked hint.
  • Connections. For each tool you connect: its URL, its scopes, and its credentials or OAuth tokens, encrypted at rest.
  • Work. The jobs you submit, the missions and skills you write, the task board, agent activity logs, the reports your agents produce, and estimated token usage per call.
  • The Hive. Your teams’ shared memory — the findings, reports and facts your agents write, plus embeddings computed from them for search.
  • Audit log. Who did what in your organisation, and what your agents did on your behalf.

Whatever you or your agents put into a job, a mission or the Hive is stored as written. If that includes someone else’s personal information, you are responsible for having a lawful basis to put it there.

3.Why we hold it (lawful basis)

  • To perform our contract with you — running your teams, remembering what they learn, enforcing your caps, billing your subscription.
  • Legitimate interests — keeping the Service secure and available, preventing abuse, debugging failures, and understanding aggregate usage.
  • Legal obligation — tax and accounting records for payments.

We do not train models on your data, we do not sell it, and we do not share it with advertisers. There is no ad tracking anywhere in the product.

4.Who else processes it (subprocessors)

We use these providers to run the Service. Each is bound by its own agreement with us and may only process your data on our instructions.

ProviderWhat it doesWhere
VercelApplication hosting and edge delivery. Sees requests and logs.United States / global edge
NeonManaged PostgreSQL — the primary database (accounts, teams, jobs, the Hive, encrypted credentials).Region chosen at provisioning
InngestDurable job execution. Sees job metadata and the events that drive agent sessions.United States
StripeSubscription billing. Holds your billing details; we never see your card number.United States / global
SentryError monitoring. Receives scrubbed stack traces and request context.United States / EU
ResendTransactional email (digests, approval notices, invites).United States
Voyage AIText embeddings for Hive search, on OUR account (not yours). Receives the text of Hive entries whenever we hold a platform embedding key and your organisation is inside its daily quota — this is tried FIRST, whether or not you have supplied your own OpenAI key. Only when the quota is used up, the call fails, or we hold no platform key does embedding fall back to your own OpenAI key; if you have none, search falls back to full-text and no embedding text leaves at all.United States
AnthropicThe Workforce Architect's design call, on OUR account (not yours), for an organisation that has not added a model key yet — that one call is free. It receives the brief you type on the design screen and nothing else. Once you add your own key, every model call runs on YOUR account with the provider you chose, below.United States
Your chosen model providerRuns the model calls your agents make. Prompts, tool results and the content your agents work on are sent there under YOUR account and YOUR agreement with them.Depends on the provider you choose — Settings → Model provider states it per provider

The model provider is the one you choose, and it is the one that sees the substance of your work. Settings → Model provider states, for each provider, which country processes your prompts — read it before you connect customer data. Because these providers are overseas, using the Service involves a cross-border disclosure of personal information under Information Privacy Principle 12.

We will update this list before adding a subprocessor that handles customer data.

5.How long we keep it

  • Account, organisation and work — for as long as your organisation exists. When your organisation is deleted (see §11 of the Terms), every row keyed to it is removed by database cascade.
  • Agent activity logs — 30 days, then removed automatically by a nightly retention sweep.
  • The Hive — kept deliberately: it is the memory that makes a standing team worth having. The Hive is retained for as long as your organisation is active. To have specific entries or the whole Hive deleted, email support@jugg.ai. A nightly sweep re-embeds entries when the search model changes, so their text is sent to the embedding subprocessor above again at that point.
  • Billing records — kept for as long as tax law requires, typically seven years.
  • Credentials — deleted when you remove the connection or the provider key.

6.Your rights

You may ask us to give you a copy of the personal information we hold about you, correct it, or delete it. Under the GDPR you may also object to or restrict processing, and ask for portability. Email support@jugg.ai — we aim to answer within a few business days and, for a formal request under the Privacy Act, within the statutory 20 working days.

If you are not satisfied with how we handle it, you may complain to the New Zealand Office of the Privacy Commissioner or, in the EU/UK, to your local supervisory authority.

7.Security, and telling you when something goes wrong

Every tenant-keyed table is protected by database row-level security, so one organisation’s queries cannot reach another’s rows. Provider keys and connection credentials are encrypted at rest with AES-256-GCM. Custom tools your agents write run in a sandbox with no ambient network or filesystem access. Secrets are scrubbed from logs.

If a breach occurs that is likely to cause you serious harm, we will notify you and the Office of the Privacy Commissioner as required by the Privacy Act 2020, without undue delay.

Found a vulnerability? Please report it to security@jugg.ai rather than disclosing it publicly. We will not pursue researchers acting in good faith. We hold no security certifications — we are not SOC 2 audited, and we will never imply otherwise.

8.Cookies

We set only what the product needs to work: a session cookie so you stay signed in, and a cookie recording which organisation you are currently acting in. There are no advertising cookies, no third-party trackers and no cross-site profiling, which is why you are not being asked to dismiss a banner.

9.Children

The Service is for business use and is not directed at anyone under 16. We do not knowingly collect their personal information.

10.Changes to this policy

We will update this page when our practices change, and change the “Last updated” date above. For a material change affecting how we use your personal information, we will tell you by email.