Back

Privacy

What we collect, what we never do with it, and how your projects stay separated from everyone else's.

What we hold

Your account details, the projects you create, and everything you put inside them: files you upload, notes in the Project Brain, the workers you configure, and the record of what those workers did.

We also hold the credentials you connect, but not in a form we can casually read. Every credential and every secret is encrypted with AES-256-GCM before it reaches the database, and the encryption is bound to the project that owns it, a copy of the row decrypts to nothing anywhere else.

What we do not do

We do not sell your data. We do not use your projects, files or conversations to train models, ours or anyone else's.

We do not show advertising, and we do not let anyone pay to influence what a worker tells you.

Where your data goes when a worker runs

To answer a question, Jelly Task sends the relevant context, the task, the project information a worker is allowed to see, and the results of any tool it called, to an AI provider. Which provider depends on what the task needs; we route across several.

Two things never travel with it: your credentials and your secrets. Workers call named functions on our side and receive structured results back, so a key is used but never included in a prompt. A secret stored in Environment is visible to a worker as a name only.

Separation between projects

Projects are isolated from each other and from other customers at the data layer, not by convention. Every project-scoped read passes through a single check that proves your membership before it returns anything, and searches over stored memory are filtered by project before they run.

The practical effect: a worker in one project cannot see, retrieve or quote another, including your own.

Third parties we rely on

Hosting and database providers, an email sender for account mail, a payment processor for subscriptions, and the AI providers described above. Each receives only what it needs to do its job. The payment processor handles card details directly; we never see a card number.

The services you connect yourself, your repository host, your database, your social accounts, are yours. We act on them with the access you granted and nothing more.

Keeping and deleting

Your data stays while your account is open. You can export a complete archive of any project at any time from its Export page, and you can disconnect any integration in one click, which revokes our stored copy of that credential immediately.

Delete a project and its contents go with it, including its files, memory and stored credentials. Delete your account and the same applies to everything in it. Backups age out on their own schedule.

Your choices

You can see, export, correct or delete what we hold about you. If you would like something done that the app does not expose a button for, write to support@jellytask.app and we will handle it.

Changes

If this policy changes in a way that affects you, we will tell you in the app before it takes effect rather than quietly editing the page.

Plain English on purpose. If something here is unclear, that is a problem with the page and we would like to know.