Privacy Policy
Last updated: July 20, 2026
Who we are
This policy is issued by Jacard AI, Inc., 360 S Baywood Ave, San Jose, CA 95128 ("Jacard", "we", "us"). We operate from the United States and serve users globally. It covers three products:
- jacard.ai: a free, public generative-UI analysis engine. You submit prompts (with optional file uploads) and we generate interactive analysis pages ("Jacard Views") and, if you choose, standalone published pages ("Jacard Pages").
- Jacard AI Retail (shopping.jacard.ai): a merchant console and embedded Shopify app for generating storefront and collection pages.
- Jacard Olympus: an early-access B2B workspace where AI agents analyze company data inside org workspaces.
For questions about this policy or your data, email privacy@jacard.ai.
What we collect
Account data. Email address and name, via Supabase Auth (email/password or Google sign-in). jacard.ai also works in guest mode without an account.
User content. Your prompts, uploaded files, conversations, and the pages we generate for you. On Retail, this includes merchant business and catalog data ingested from Shopify with the merchant's authorization (product data, from which we generate image captions and embeddings), plus public Meta Ad Library data we index. On Olympus, this includes company data your organization connects via scoped API keys, and agent session history, which is persisted in private GitHub repositories.
Usage data. Rate-limit counters (held in Redis), feature usage, and device/browser information collected through analytics tools: Vercel Analytics always, and Google Analytics 4 and Microsoft Clarity where enabled.
Access and analysis requests. If you request early access or a Jacard Analysis on www.jacard.ai, we collect the name, email address, business type, and website or store URL you submit, along with the request time. We use them to respond to your request, prepare the analysis you asked for, and follow up about the product; we retain them until you ask us to delete them (write to privacy@jacard.ai).
Cookies. We use cookies for authentication sessions and, where analytics tools are enabled, for usage measurement.
We do not ask for, and you should not upload, government IDs, financial account numbers, or other sensitive personal data, because none of our products needs them.
How we use your data
- To provide the service: generating Views and Pages, running merchant page generation, operating Olympus workspaces, authenticating you, and enforcing rate limits.
- AI processing. Your prompts, files, and relevant context are sent to third-party AI model providers (Google, Cerebras, OpenRouter, OpenAI, Anthropic) to generate results, and to search providers (SerpAPI, Tavily) when a query needs web results. These providers process data under their own terms with us. We do not use your content to train foundation models.
- To keep the service safe and working: debugging, abuse prevention, rate limiting, and aggregate usage analysis.
- To communicate with you: transactional email (delivered via SMTP), such as auth and account messages.
Public by design: published pages and share links
Some parts of Jacard are meant to be public, and it is important you understand which:
- Jacard Pages are deployed to public URLs. Anyone with the link can view them, and they may be indexed by search engines.
- Share links for chats and Views make that content publicly accessible to anyone who has the link.
- Retail storefront and collection pages are published by merchants for their public storefronts, after the merchant manually approves them.
Do not include personal, confidential, or sensitive information in content you intend to publish or share. Until you publish or share, your content is private to you (or to your org, on Olympus).
Legal bases and consent
Where the EU/UK GDPR applies, we rely on: contract (providing the services you signed up for), legitimate interests (security, abuse prevention, service analytics), and consent (optional analytics cookies such as Google Analytics 4 and Microsoft Clarity, where a consent choice is presented).
For users in US states with comprehensive privacy laws (including California under the CCPA/CPRA), we process personal data as described in this policy, we do not sell personal information, and we do not share it for cross-context behavioral advertising. You can exercise your state-law rights as described under "Your rights."
Sharing and subprocessors
We do not sell personal data. We share it only with the service providers below, to run the products, and where required by law.
| Provider | Purpose |
|---|---|
| Supabase | Authentication, database, file storage |
| Render | Application hosting |
| Cloudflare | CDN, object storage (R2), edge compute (Workers) |
| GitHub | Git-based persistence (private per-session repos on Olympus) |
| Modal | Sandboxed compute for agent workloads |
| Redis Cloud / Upstash | Rate limiting and caching |
| Google, Cerebras, OpenRouter, OpenAI, Anthropic | AI model inference on user content |
| SerpAPI, Tavily | Web search for grounded analyses |
| Vercel Analytics | Usage analytics |
| Google Analytics 4 | Usage analytics (where enabled) |
| Microsoft Clarity | Usage analytics (where enabled) |
| SMTP email provider | Transactional email delivery |
On Retail, catalog data is received from Shopify under the merchant's authorization of our Shopify app.
Retention
We keep account data and user content while your account is active or, for merchants and orgs, while the commercial relationship lasts. Published pages remain public until you or the publishing merchant/org unpublish or delete them. Rate-limit and cache entries in Redis are short-lived by design. Uploaded files are accessed via short-lived signed URLs. When you delete content or your account, we delete or de-identify the associated data within a reasonable period, except where we must retain it for legal, security, or dispute-resolution reasons.
Your rights
Depending on your location (including under the GDPR and US state privacy laws such as the CCPA/CPRA), you have the right to access your personal data, correct it, delete it, receive a portable copy, and withdraw consent where processing is based on consent. EEA/UK users may also object to or restrict certain processing and complain to their supervisory authority. California and other US state residents may exercise their rights without discrimination for doing so.
To exercise any of these rights, email privacy@jacard.ai from the address associated with your account. We will verify the request and respond within the timelines required by applicable law. Note that deleting a published page removes it from our systems, but copies already made by others or cached by search engines are outside our control.
Children
Our services are not directed at children: under 13 in the United States (consistent with COPPA), and under 16 in the EEA. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact privacy@jacard.ai and we will delete it.
International transfers
We operate from the United States, and our service providers process data primarily in the United States and the EU. Where the GDPR applies to a transfer out of the EEA/UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses with our providers.
Changes to this policy
We may update this policy as our products evolve. We will post the new version at this URL and update the date above; for material changes affecting registered users, we will make reasonable efforts to notify you (for example, by email or an in-product notice).
Contact
Jacard AI, Inc. 360 S Baywood Ave, San Jose, CA 95128
Privacy: privacy@jacard.ai · Security reports: security@jacard.ai (we also accept vulnerability reports via GitHub private vulnerability reporting).