Skip to main content

Jay

Privacy policy.

Last updated: October 6, 2026

Jay stores your conversations, projects, files and recordings on your computer, not in the cloud. Our servers only receive what they need to manage your account, count your usage and bill your plan; what you entrust to the artificial intelligence models is processed on servers located in France.

  • What goes to the models (your messages, the files, pages or emails the agent reads for you, the audio of meetings to transcribe) is kept for 30 days in the gateway logs, then deleted.
  • No training: neither dev-id nor its service providers use your content to train or improve models.
  • No selling, no advertising: your data is never sold or rented, and the app contains no advertising or audience measurement trackers.
  • You stay in control: you can view, export, correct or delete your data, and delete your account from Jay.

1. Who is responsible for your data

dev-id, the publisher of Jay, is the controller of the processing described in this policy.

dev-id, a French simplified joint-stock company (SAS) with share capital of €123,897.91, registered with the Trade and Companies Register (RCS) of Aix-en-Provence under number 828 890 145, with its registered office at 2 chemin de Freyguières, 13240 Septèmes-les-Vallons, France. dev-id's Data Protection Officer (DPO) is Céline Souliers. For any question about your data: contact@dev-id.fr, or by post to the registered office address.

This policy covers the Jay app and the online services that make it work. It does not cover:

  • the dev-id.fr website, which has its own policy;
  • services from other publishers that you connect to Jay (Google, Notion, Figma...), which are governed by their own policies (section 5);
  • third-party data you process with Jay for your business (customers, employees, meeting participants): your business is the controller of that data, and dev-id then acts as a processor, under Annex 2 of the terms of service.

2. What stays on your computer

Most of what you do in Jay is stored on your computer, and dev-id has no access to it.

Stored on your computer:

  • your conversations, their attachments and your settings, in the app's data folder;
  • your projects, with their instructions, memory, knowledge base and the documents, spreadsheets, presentations and mockups of the Atelier, in each project's folder;
  • your meeting recordings and their transcripts, in your Documents folder or in the project folder;
  • your global memory, your skills and your custom agents;
  • the app's technical logs and incident log, which are never sent automatically;
  • cookies from sites opened in the built-in browser, as in any browser.

Jay does not sync your conversations or projects to the cloud. This content only leaves your computer when it is sent to the models to answer a request (section 4) or sent to a service you have connected (section 5).

Secrets (model access key, tokens and keys for connected services) are encrypted with your system's keychain. The rest is not encrypted by Jay: turn on disk encryption (FileVault on Mac, BitLocker on Windows) to protect it.

You can export a backup of your projects and conversations from Settings > Account. Uninstalling Jay does not delete these folders: delete them yourself if you wish.

3. Data processed on our servers

Our servers process your account, usage and billing data, for the purposes and periods below.

WhyWhat dataLegal basisHow long
Create your account and sign you inEmail, password (stored in hashed form), name, profile picture; with Google: identifier, name, email, picture and Google Workspace domainPerformance of the contractLife of the account; deleted after 3 years without sign-in or subscription, preceded by a warning email
Run your accountCurrent plan, special access (testing program, experimental features), onboarding steps, last activity, app version and operating systemPerformance of the contractLife of the account
Give you access to the modelsPersonal access key, linked to your identifier and email, and list of the models in your planPerformance of the contractLife of the account, then revocation
Answer your requests to the modelsContent of requests and responses (section 4)Performance of the contract30 days
Count usage and enforce quotasFor each call: model, tokens, images, estimated cost, conversation or meeting identifier (for a meeting: its date and title), app and version, date; weekly and monthly countersPerformance of the contract; legitimate interest (preventing abuse, sizing the service)Log: 12 months; counters: replaced each period
Manage the subscription and billingWith us: plan, subscription status and dates, customer identifier; with Stripe: name, address, VAT number, payment method, payment historyPerformance of the contract; legal obligation (accounting)Life of the subscription; invoices: 10 years
Write to you about the serviceEmail (sign-up confirmation, forgotten password, subscription, change of terms)Performance of the contractLife of the account
Handle your requests and complaintsEmail, content of your messages and reportsLegitimate interest; legal obligation for exercising your rights3 years after your last request
Secure the serviceTechnical logs from our hosting providers: date, request; no IP address recordedLegitimate interestUp to 30 days
Update JayInstalled version, random installation identifier; no IP address recordedLegitimate interestUp to 30 days

Data processed under the contract is necessary: without it, we can neither create your account nor give you access to the models. Our account servers are hosted in the European Union, in Frankfurt (section 7). We do not sell or rent your data, we do not use it for advertising, and we do not send you marketing messages.

4. What goes to the artificial intelligence models

When you make a request, Jay sends the models what they need to answer it, on servers located in France, and this content is deleted after 30 days.

Depending on the request, the following may be sent:

  • your message and the conversation history;
  • the project's instructions and memory, and your global memory, which Jay adds to the context;
  • the content of the files, web pages, emails, documents or events the agent reads for you, and the screenshots you ask it to take;
  • the images you attach, have generated or edited, and the audio of meetings to transcribe;
  • ancillary calls: a conversation title, a summary of a long exchange, a memory update, automatic mode selection (Auto), a check of generated images.

Where. These requests go through an access gateway, then are processed by Jay's models, running on the servers of Oreus, our processor, in France. They are not sent to any other model provider.

How long. The gateway keeps the content of requests and responses for 30 days, to diagnose incidents and prevent abuse, then deletes it. Only authorized staff at dev-id and Oreus can view it, for service security, abuse prevention or to analyze a problem you report to us. The models keep nothing lasting after answering.

No training. Neither dev-id nor Oreus uses your content to train or improve models. If that were ever to change, it would only be with your explicit consent and after an update to this policy.

Image checks. Before and after generating an image, Jay has the request and the resulting image checked by its own models, to block content prohibited by the terms of service.

Automated decisions. Jay automatically chooses a model and applies your quotas, but makes no decision producing legal effects concerning you based solely on automated processing.

5. Services you connect and the web

When you connect a service to Jay, exchanges take place directly between your computer and that service: dev-id keeps neither your credentials nor your data on its servers.

How it works. You authorize Jay from the service's page (Google, Figma, Notion...) or by entering a key (Pennylane, Eurécia, GitHub, GitLab...). Tokens and keys are encrypted on your computer. For Google and Figma, the initial exchange of the authorization code goes through one of our servers, which holds the app secret and keeps nothing; Jay then queries the service directly. You can revoke access at any time, in Jay or in the service's settings. Each service remains responsible for the data it holds, under its own policy.

Use. Jay only accesses a connected service to carry out a request from you. What it reads there (an email, a file, an event, a page) is sent to the models as described in section 4. Actions visible to others (sending an email, inviting to an event, moving a file) are submitted to you for confirmation, depending on the permission level you chose.

Google. Jay requests access to Gmail (read, organize, draft, send), Google Drive (read, organize, create) and Google Calendar (read, create events). This data is used only for the features you use in Jay: it is not sold, not used for advertising or to train models, and no one reads it except for security, to comply with the law or, with your consent, to analyze a problem you report to us. Jay's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.

Search and browsing. To search the web, the agent opens the Google results page, or DuckDuckGo as a fallback, in Jay's built-in browser, from your computer. These search engines, like the sites the agent visits for you, receive the usual information of a visit (search, IP address, built-in browser cookies) and process it under their own policies.

Other services contacted from your computer, depending on the features used: Google Fonts for brand guideline fonts, GitHub or the address of your choice to install a skill, the MCP servers you add, and Apple speech recognition for dictation (section 6).

6. Meetings and dictation

Meeting recordings stay on your computer; only the audio to be transcribed goes to the models.

Recording. Jay records the sound from your microphone and, if you choose, from your computer (the audio of a call). Audio files and transcripts are stored on your computer.

Transcription. To transcribe, Jay sends the audio in segments to the Ear model, under the conditions of section 4 (servers in France, 30-day logs). An excerpt of the transcript may also be sent to suggest a title. The meeting's date and title appear in your usage count (section 3).

People being recorded. A recorded meeting contains other people's voices and words. Before recording, you must inform them and obtain their consent (article 11 of the terms of service). When you record in a professional context, your business is the controller of this data, and dev-id acts on its behalf as a processor for the transcription.

Dictation. On Mac, voice dictation in the input bar uses Apple speech recognition. It runs on your computer when your language allows; otherwise, the audio is processed by Apple, under its own privacy policy.

7. Recipients and transfers

Four service providers receive data on our behalf; content sent to the models stays in France.

ProviderRoleDataLocationSafeguards
OREUS, a French simplified joint-stock company (SAS), RCS Marseille 942 951 690, registered office: 6 rue Berthelot, 13014 Marseille, FranceAccess gateway and model executionContent of requests and responses; identifier and email linked to your access keyFranceData processing agreement
Supabase, Inc.Account database, authentication, account emails, server functionsAccount, profile, subscription, usageEuropean Union (Frankfurt, Germany)Data processing agreement, standard contractual clauses
Stripe Payments Europe, Ltd.Payment, invoices, VAT, subscription portalEmail, name, address, VAT number, payment method, historyIreland, with transfers to Stripe, Inc. (United States)EU-US Data Privacy Framework, standard contractual clauses
Notion Labs, Inc.Bug report form, if you use itWhat you enter in itUnited StatesEU-US Data Privacy Framework, standard contractual clauses

Stripe also acts as a separate controller for its own obligations (fraud prevention, legal obligations), under its privacy policy. The following also have access to your data, within the limits of their duties: authorized dev-id staff, and administrative or judicial authorities upon lawful request. The services you connect (section 5) act under their own responsibility.

Transfers outside the European Union. Supabase, Stripe and Notion are American companies or belong to American groups. Data they process or access from the United States is covered by the European Commission's adequacy decision on the EU-US Data Privacy Framework where the provider is certified under it, and otherwise by the European Commission's standard contractual clauses. You can obtain a copy by writing to us.

8. Security

dev-id protects your data with technical and organizational measures appropriate to the risks.

  • Exchanges between Jay, our servers and our service providers are encrypted (HTTPS).
  • Each account has its own model access key, which can be revoked at any time and is erased from your computer when you sign out.
  • In our database, each account can only access its own data, and administration is restricted to authorized staff.
  • Card numbers never pass through our servers: they are processed by Stripe, which is PCI DSS certified.
  • On your computer, secrets are encrypted by the system keychain, and the agent's sensitive actions require your confirmation depending on the permission level you chose.

Your part: protect access to your computer (session password, disk encryption), keep your password secret, and sign out of Jay on a shared computer.

In the event of a data breach posing a risk to your rights, we notify the CNIL (the French data protection authority) within 72 hours, and we inform you without delay if the risk is high.

9. Your rights

You can at any time access your data, correct it, have it erased, retrieve it or object to certain processing.

  • Access: find out whether we process data about you, and obtain a copy.
  • Rectification: have inaccurate data corrected; your name and picture can be changed directly in Jay's Settings.
  • Erasure: have your data deleted, in particular by deleting your account (Settings > Account, “Delete my account”).
  • Restriction: have processing frozen, for example while a disputed piece of data is checked.
  • Portability: receive the data you provided to us in a structured, machine-readable format.
  • Objection: object, on grounds relating to your particular situation, to processing based on our legitimate interest.
  • Post-mortem instructions: specify what happens to your data after your death.

Account deletion. Your request signs you out immediately. Within 30 days, we delete your account and your data from our servers, revoke your model access key and cancel your subscription, with no further charge. We keep only what the law requires (invoices: 10 years). Gateway log content disappears no later than 30 days after it was sent. Your files stay on your computer: it is up to you to delete them.

Exercising your rights. Write to contact@dev-id.fr from your account's email address, or by post to 2 chemin de Freyguières, 13240 Septèmes-les-Vallons, France. We reply within one month, which may be extended by two months for a complex request, in which case we let you know. If we have reasonable doubts about your identity, we may ask you to confirm it. Data that is only on your computer is not accessible to us: you view, export and delete it yourself.

Complaint. If you believe your rights are not being respected, you can lodge a complaint with the CNIL (3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France, cnil.fr).

10. Minimum age, trackers and updates to this policy

Jay is for people aged 15 and over, contains no advertising trackers, and you are notified of any significant change to this policy.

Minimum age. You must be 15 to create a Jay account. Between 15 and 18, subscribing to a paid plan requires the consent of a holder of parental authority. If we learn that an account belongs to someone under 15, we delete it.

Trackers. The app contains no audience measurement, advertising or crash reporting tools. It stores on your computer your sign-in session and a random identifier used for updates, which are strictly necessary for the service; sites opened in the built-in browser set their own cookies there. The dev-id.fr website has its own cookie policy.

Updates to this policy. We may change this policy to reflect changes to Jay or to the law. The date of the version in force appears at the top of the document, and we notify you by email or in the app before any significant change.