Juvat
PricingWorkspaceDocs
Sign inCreate account
PricingWorkspaceDocsSign in

Privacy Policy — Juvat

> DRAFT — attorney review required. Must be tailored to the jurisdictions you serve (GDPR, CCPA/CPRA, biometric statutes, etc.) and to your actual data flows and sub-processors before publishing.

Last updated: [DATE] · Controller: [LEGAL ENTITY]

1. Scope

This describes how we collect, use, share, and protect personal data when you use Juvat. For business/API customers where you determine the purposes of processing, we act as your processor, and a Data Processing Addendum governs that processing.

2. Data we collect

  • Account data: name, email, authentication identifiers, billing identifiers (payments handled by our processor; we don't store full card numbers).
  • Usage & metadata: requests, tokens, models/features used, timestamps, device/log data — used for billing, security, and analytics.
  • Content: your prompts, files, and outputs. Content is not logged by default; we process it transiently to deliver the Service. If you opt in to content logging, we store it per your setting.
  • Memory: facts, preferences, decisions, and project data you or the Service save to your memory, which you can view, edit, export, and delete.
  • Biometric data (voice): if you use voice cloning, we process a voiceprint derived from your reference audio. See §7.
  • Connector data: if you connect third-party accounts (e.g. email, code hosts), we access the data you authorize, for the purposes you direct.
  • Walkthrough recordings (Trace): if you use the Trace browser extension, the steps you choose to record — screenshots, page URLs and titles, clicks, and text you typed into non-password fields. See §8.

3. How we use data

To provide, secure, bill, support, and improve the Service; to enforce our terms and comply with law. We do not use your prompt/response content to train AI models.

4. How we share data — sub-processors

To deliver the Service we route data to sub-processors. Representative list (maintained current at [SUBPROCESSOR PAGE URL]):

  • Model inference: [OpenRouter and the model hosts it routes to; and/or direct providers]. Your prompts and outputs are processed by these to generate responses. Some may operate outside your country and may have their own retention; we select for and disclose their terms.
  • Infrastructure/database: [Supabase].
  • Payments: [Stripe].
  • Media generation/storage: [Fal/Replicate; object storage]. If you choose bring-your-own or local storage, your media is stored where you direct.
  • Email/notifications: [provider].

We share data with these only as needed to provide the Service, and with authorities where legally required. We do not sell personal data. [Under CCPA/CPRA, disclose any "sharing" for cross-context advertising — default: none.]

5. International transfers

Data may be processed in countries other than yours, including by non-US model hosts. Where required, we rely on appropriate transfer mechanisms. [Counsel to specify SCCs/mechanisms.]

6. Your rights

Depending on your location, you may have rights to access, correct, delete, port, and restrict processing of your data, and to opt out of certain processing. We provide in-product tools to view, export, and delete memory and stored content, and you can request other rights at [PRIVACY CONTACT]. We won't discriminate against you for exercising rights.

7. Biometric data (voice cloning)

If you create a voice clone, we collect and store a voiceprint (biometric identifier).

  • We obtain your consent before creating it, and you represent you have consent from any other person whose voice is used.
  • Purpose: solely to generate speech in that voice at your direction.
  • We do not sell or disclose biometric data except as needed to provide the feature or as required by law.
  • Retention: we retain voiceprints only as long as your voice model exists; you can delete it anytime, and we destroy it per our schedule (and per applicable law, e.g. within [X] years or on account closure, whichever is first).

[Biometric-specific statutes (BIPA, CUBI, etc.) impose specific consent, notice, and destruction requirements — counsel must finalize this section.]

8. Walkthrough recordings (Trace)

If you install the Juvat Trace browser extension and start a recording, we collect that recording's steps: the pages visited while recording (URL and title), your clicks, text you type into non-password fields, and a screenshot of each step.

  • Recording is explicit. Capture happens only between your Start and Stop, on the tab you chose, with a visible recording indicator the whole time. Nothing is captured in the background.
  • Passwords are never captured. Values entered into password fields are excluded by design; a step only notes that a password was entered.
  • Storage and control. Recordings are saved to your account as walkthroughs. You can edit captions, delete individual steps, or delete a whole walkthrough at any time, and walkthroughs are deleted with your account.
  • Sharing is your action. A walkthrough is private until you create an unlisted share link; anyone holding that link can view it, and you can revoke it at any time. Files you export are under your control.
  • No stored credentials. The extension holds no passwords, tokens, or keys; it saves recordings using your existing signed-in session.

9. Retention

We retain account and billing data for as long as your account is active and as required for legal/tax purposes; usage metadata per our schedule; content per your logging settings; memory until you delete it. On termination, we provide an export window then delete per schedule.

10. Security

We use technical and organizational measures (encryption in transit/at rest, access controls, tenant isolation) to protect data. No system is perfectly secure. We follow an incident-response process and will notify affected users and regulators as required by law (e.g. GDPR 72-hour, applicable US timelines).

11. Children

The Service is not for children under 18 [or 13 with the required protections]. We don't knowingly collect data from children under 13; if we learn we have, we delete it.

12. Cookies/analytics

[Describe any cookies/analytics and controls, or state none beyond essential.]

13. Changes

We'll post updates here and notify you of material changes.

14. Contact

[PRIVACY CONTACT EMAIL / ADDRESS] · [EU/UK representative or DPO if required].

© 2026 JuvatDocsSupportPrivacyTermsAcceptable use