Privacy Policy
Effective August 8, 2026
This policy explains what JaneJack AI collects, why, who we share it with, and what you can ask us to do about it. It covers both our website and the JaneJack service.
1. Two different roles
We handle personal information in two capacities, and your rights differ depending on which applies.
- As a controller. For information about our own customers and website visitors, such as your account details, billing contact, support conversations, and enquiries submitted through our contact form. We decide how that information is used.
- As a processor. For information contained in the calls your assistant handles, such as your callers' phone numbers, names, and whatever they say during a call. That information belongs to you, our customer. We process it on your instructions and to deliver the service.
If you are a caller who spoke to a JaneJack assistant and you want your information removed, contact the business you called. They control that data. If you contact us, we will help them action it.
2. What we collect
Account and company information
- Name, email address, and a hashed password.
- Role within your company account and, if two-factor authentication is enabled, the associated secret.
- Company details supplied during onboarding, including business name, services, hours, policies, and any material you add to your assistant's knowledgebase.
- Invitation records when you add colleagues to your account.
Call information
- Caller phone number, the number called, call direction, start and end times, duration, and how the call ended.
- The transcript of the conversation, and the recording where recording is enabled for your account.
- An automated post-call summary and analysis generated from the transcript.
- Any details the caller provides that your assistant is configured to capture, such as a name, an appointment time, or a reason for calling.
- Per-call cost and usage data used for billing.
Billing information
Billing contact details, subscription status, and invoice history. Card details are entered directly with our payment processor and are never stored on our systems. We hold only a token and the last four digits so you can recognise the card.
Integration credentials
When you connect a third-party tool, we store the access token or API key needed to use it. These are encrypted at rest and used only to serve your own calls. Disconnecting an integration deletes the stored credential.
Technical information
Our servers log IP address, user agent, and request metadata for security, rate limiting, and debugging. We do not run third-party advertising or behavioural analytics trackers on this website. See our Cookie Policy for detail.
3. Why we process it
- To provide the service. Answering calls, booking appointments, producing transcripts and summaries, and showing them to you in the dashboard.
- To authenticate you and keep accounts secure, including two-factor authentication and abuse prevention.
- To bill you and to reconcile usage against your plan.
- To support you, including support tickets and onboarding assistance.
- To improve reliability, by diagnosing failures and measuring quality of service.
Where the GDPR applies, our lawful bases are performance of a contract for the operation of the service, legitimate interests for security and service improvement, and consent where separately requested. We do not use call content to train general-purpose AI models.
4. Who we share it with
We do not sell personal information. We share it with the following sub-processors, each engaged under terms that restrict their use of it to providing their service to us.
| Sub-processor | Purpose | Data involved |
|---|---|---|
| Vapi | Real-time voice pipeline: speech recognition, language model orchestration, and speech synthesis for live calls. | Call audio, transcripts, caller phone number, assistant configuration |
| Telephony carriers (via Vapi) | Provisioning phone numbers and connecting inbound and outbound calls. | Caller and recipient phone numbers, call metadata |
| Stripe | Subscription billing and payment processing. | Billing contact, payment method token, invoice history |
| MongoDB Atlas | Primary application database. | Account records, company records, call logs, transcripts, tickets |
| Redis | Session, cache, and rate-limiting layer. | Short-lived session and request metadata |
| Render | Hosting for the JaneJack API. | All data processed by the API in transit |
| Vercel | Hosting for the JaneJack website and dashboard. | Request metadata such as IP address and user agent |
| Mailchimp Transactional (Mandrill) | Transactional email such as invitations, alerts, and notifications. | Recipient name and email address, message contents |
| Google (Gemini) | Post-call analysis and summarisation of transcripts. | Call transcripts |
In addition, data is shared with a third-party tool only when you choose to connect it: Shopify, Google Calendar, Google Maps Platform, Microsoft Outlook, HubSpot, Zendesk, Slack, WhatsApp Business (Meta). Connecting one of these authorises us to exchange the relevant data with it on your behalf.
We may also disclose information where required by law, to enforce our agreements, or in connection with a merger or acquisition, in which case we will tell you before your information becomes subject to a different policy.
5. Call recording and consent
Recording and transcription laws vary by jurisdiction, and several regions require that all parties consent before a call is recorded. As the business receiving the call, you are responsible for ensuring your assistant is configured to make any disclosure or obtain any consent that applies to you and your callers. We provide the controls to do this, including greeting announcements and the ability to disable recording. We cannot determine your obligations for you.
6. Healthcare data
Calls to a healthcare practice frequently contain protected health information. We support healthcare customers under a business associate agreement. If you handle protected health information, contact us at info@janejack.ai to put a BAA in place before going live.
7. Retention
- Account records are kept for as long as your account is active, then deleted or anonymised within 90 days of closure unless we are required to keep them longer.
- Call logs, transcripts, and recordings are retained for the period configured on your account so you can review call history. You can request deletion of specific calls or shorten the retention period at any time.
- Billing records are kept for the period required by tax and accounting law.
- Server logs are kept for a short operational window and then rotated out.
8. Security
- All traffic to our website and API is encrypted in transit.
- Passwords are stored using a one-way hash. We never see or store them in plain text.
- Integration credentials are encrypted at rest.
- Two-factor authentication is available on every account and we recommend enabling it.
- Access to production data is restricted to the people who need it to operate and support the service.
No system is perfectly secure. If we become aware of a breach affecting your data, we will notify you without undue delay and within the timescales required by applicable law.
9. International transfers
Our infrastructure and sub-processors are based primarily in the United States and the European Union. Where personal information is transferred out of the region it was collected in, we rely on the transfer mechanisms available under applicable law, including standard contractual clauses.
10. Your rights
Depending on where you live, you may have the right to access a copy of your personal information, correct it, delete it, restrict or object to processing, receive it in a portable format, and withdraw consent where processing relies on it. Residents of California may additionally request disclosure of the categories of information collected and may opt out of sale, though we do not sell personal information.
Exercise any of these by writing to info@janejack.ai. We will respond within the period required by applicable law. We will not discriminate against you for making a request. Where we act as a processor on a customer's behalf, we will refer your request to that customer and assist them in responding.
11. Children
The service is intended for businesses and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child's information has reached us, contact us and we will delete it.
12. Changes
We will update this policy as the service changes. The effective date at the top reflects the most recent revision. Material changes will be communicated to account holders by email or through the dashboard before they take effect.
13. Contact
Questions, requests, or complaints about this policy go to info@janejack.ai. If you are in the EEA or the UK and are not satisfied with our response, you may also lodge a complaint with your local supervisory authority.