Privacy Policy
Last updated: 20 July 2026
This policy explains what data Juratify ("we", "us") processes, why, and how it is protected. Juratify is built around client-side, zero-knowledge encryption, so for most of the content you send us we hold only ciphertext we cannot read.
1. Our role
We are the controller for the data we need to run the business: your account details, billing records, and support correspondence. We are a processor for the evidence your agents record, which we hold and return on your instructions. You remain its controller, so where the events you record contain personal data about your own users, having a lawful basis for that is your responsibility, not ours.
2. Data we process
- Account data: your email address and authentication data, handled through Supabase Auth, plus workspace membership.
- Client-sealed event payloads: stored as ciphertext only. They are encrypted in your environment with a data key we never receive, so we cannot read them.
- Server-sealed event payloads: for events ingested through the OTLP door, we process the payload transiently at ingestion and store it encrypted at rest with a per-workspace key.
- Integrity metadata: timestamps, event types, hash chains, signatures, and checkpoints, which make records tamper-evident.
- API keys: stored only as a hash.
3. Why we process it, and our legal basis
- To provide the Service: accounts, workspaces, and the recording and return of your evidence. Performance of our contract with you, Article 6(1)(b).
- To keep the Service secure and working: abuse prevention, integrity checkpoints, and diagnostics. Our legitimate interests in running a reliable service, Article 6(1)(f).
- To take payment and keep accounting records: performance of our contract and our legal obligations under tax and company law, Article 6(1)(b) and Article 6(1)(c).
- To send service email: confirmation and trial notices. Performance of our contract, Article 6(1)(b). We do not send marketing email.
4. What we cannot see
For client-sealed events, the plaintext never reaches us and the data key is never transmitted. This is a structural property of the Service, not a policy promise: we cannot decrypt what we do not hold the key for.
5. Hosting and location
Data is hosted on Supabase infrastructure in the European Union, region eu-central-1 (Frankfurt, Germany). Storage is append-only.
6. Sub-processors
- Supabase: database, authentication, and hosting of customer data in the EU.
- Vercel: hosting of the application, served from the EU (Frankfurt) region.
- Paddle: payment processing and merchant of record for purchases.
- Resend: delivery of service email, such as sign-up confirmation and trial notices. It processes the recipient address and the message itself.
We update this list before adding or replacing a sub-processor, so you have the chance to review the change and object to it.
7. Retention
Records are retained for at least six months, reflecting the Article 26(6) minimum, and longer depending on your plan or configuration. Because the store is append-only and retention is a floor, records become deletable only after their retention period expires.
8. Your rights
Subject to applicable law, you have the right to access your personal data, to have it corrected, to have it erased, to restrict how we process it, to object to that processing, and to receive your data in a portable form. Where we rely on your consent for anything, you can withdraw it at any time.
Erasure of evidence records is constrained by the append-only design and the retention floor above: records become deletable once their retention period expires. You can export your evidence at any time through the evidence pack, which is also how portability is served.
To exercise any of these, write to the contact address below. We answer within one month, as Article 12(3) requires. If our answer does not satisfy you, you are entitled to complain to the data protection supervisory authority where you live or work.
9. International transfers
Customer evidence is stored in the EU (Frankfurt) and is not moved out of it. Some sub-processors above are established outside the EU or may support us from outside it. Where that involves a transfer, we rely on the European Commission's Standard Contractual Clauses, or on an adequacy decision where one covers the destination country, alongside the terms in each sub-processor's own data processing agreement.
10. Automated decision-making
We do not make decisions about you by automated means, and we do not profile you.
11. Security
Content is encrypted, records are hash-chained and signed, and checkpoints anchor the chain so tampering is detectable. Access to customer data through the dashboard is scoped to workspace members.
12. Cookies and local storage
We set only the cookies needed to keep you signed in, and we use local storage to remember your selected workspace and to hold your encrypted data key so you do not re-enter your passphrase on every visit. Both are strictly necessary to provide the Service, so neither requires a consent banner. We run no advertising, analytics, or tracking cookies, and we embed no third-party trackers.
13. Contact
Privacy questions and data requests can be sent to support@juratify.com.