Jacard AI
Get an Analysis

Privacy Policy

Last updated: July 20, 2026

Who we are

This policy is issued by Jacard AI, Inc., 360 S Baywood Ave, San Jose, CA 95128 ("Jacard", "we", "us"). We operate from the United States and serve users globally. It covers three products:

For questions about this policy or your data, email privacy@jacard.ai.

What we collect

Account data. Email address and name, via Supabase Auth (email/password or Google sign-in). jacard.ai also works in guest mode without an account.

User content. Your prompts, uploaded files, conversations, and the pages we generate for you. On Retail, this includes merchant business and catalog data ingested from Shopify with the merchant's authorization (product data, from which we generate image captions and embeddings), plus public Meta Ad Library data we index. On Olympus, this includes company data your organization connects via scoped API keys, and agent session history, which is persisted in private GitHub repositories.

Usage data. Rate-limit counters (held in Redis), feature usage, and device/browser information collected through analytics tools: Vercel Analytics always, and Google Analytics 4 and Microsoft Clarity where enabled.

Access and analysis requests. If you request early access or a Jacard Analysis on www.jacard.ai, we collect the name, email address, business type, and website or store URL you submit, along with the request time. We use them to respond to your request, prepare the analysis you asked for, and follow up about the product; we retain them until you ask us to delete them (write to privacy@jacard.ai).

Cookies. We use cookies for authentication sessions and, where analytics tools are enabled, for usage measurement.

We do not ask for, and you should not upload, government IDs, financial account numbers, or other sensitive personal data, because none of our products needs them.

How we use your data

Some parts of Jacard are meant to be public, and it is important you understand which:

Do not include personal, confidential, or sensitive information in content you intend to publish or share. Until you publish or share, your content is private to you (or to your org, on Olympus).

Where the EU/UK GDPR applies, we rely on: contract (providing the services you signed up for), legitimate interests (security, abuse prevention, service analytics), and consent (optional analytics cookies such as Google Analytics 4 and Microsoft Clarity, where a consent choice is presented).

For users in US states with comprehensive privacy laws (including California under the CCPA/CPRA), we process personal data as described in this policy, we do not sell personal information, and we do not share it for cross-context behavioral advertising. You can exercise your state-law rights as described under "Your rights."

Sharing and subprocessors

We do not sell personal data. We share it only with the service providers below, to run the products, and where required by law.

ProviderPurpose
SupabaseAuthentication, database, file storage
RenderApplication hosting
CloudflareCDN, object storage (R2), edge compute (Workers)
GitHubGit-based persistence (private per-session repos on Olympus)
ModalSandboxed compute for agent workloads
Redis Cloud / UpstashRate limiting and caching
Google, Cerebras, OpenRouter, OpenAI, AnthropicAI model inference on user content
SerpAPI, TavilyWeb search for grounded analyses
Vercel AnalyticsUsage analytics
Google Analytics 4Usage analytics (where enabled)
Microsoft ClarityUsage analytics (where enabled)
SMTP email providerTransactional email delivery

On Retail, catalog data is received from Shopify under the merchant's authorization of our Shopify app.

Retention

We keep account data and user content while your account is active or, for merchants and orgs, while the commercial relationship lasts. Published pages remain public until you or the publishing merchant/org unpublish or delete them. Rate-limit and cache entries in Redis are short-lived by design. Uploaded files are accessed via short-lived signed URLs. When you delete content or your account, we delete or de-identify the associated data within a reasonable period, except where we must retain it for legal, security, or dispute-resolution reasons.

Your rights

Depending on your location (including under the GDPR and US state privacy laws such as the CCPA/CPRA), you have the right to access your personal data, correct it, delete it, receive a portable copy, and withdraw consent where processing is based on consent. EEA/UK users may also object to or restrict certain processing and complain to their supervisory authority. California and other US state residents may exercise their rights without discrimination for doing so.

To exercise any of these rights, email privacy@jacard.ai from the address associated with your account. We will verify the request and respond within the timelines required by applicable law. Note that deleting a published page removes it from our systems, but copies already made by others or cached by search engines are outside our control.

Children

Our services are not directed at children: under 13 in the United States (consistent with COPPA), and under 16 in the EEA. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact privacy@jacard.ai and we will delete it.

International transfers

We operate from the United States, and our service providers process data primarily in the United States and the EU. Where the GDPR applies to a transfer out of the EEA/UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses with our providers.

Changes to this policy

We may update this policy as our products evolve. We will post the new version at this URL and update the date above; for material changes affecting registered users, we will make reasonable efforts to notify you (for example, by email or an in-product notice).

Contact

Jacard AI, Inc. 360 S Baywood Ave, San Jose, CA 95128

Privacy: privacy@jacard.ai · Security reports: security@jacard.ai (we also accept vulnerability reports via GitHub private vulnerability reporting).