DSAIL Quickstarts Guides Compare REST MCP tools Errors Legal Support

Privacy notice

The privacy notice for the DSAIL hosted service, supplementing Jaxon's Privacy Policy. What the service collects, what it never receives, how long it keeps what it holds, who can see it, and which parts of the general policy do not apply here.

Version 2026-09-14. Draft pending review by outside counsel. Issued by Jaxon, Inc. ("Jaxon"). This notice supplements Jaxon's Privacy Policy for one Service: the DSAIL hosted service at agents.jaxon.ai and this documentation site. The Privacy Policy applies to them except where this notice says otherwise; where the two differ about this service, this notice controls. It is versioned with the hosted-service terms and changes on the same notice.

The short version

We hold your rules text and DSAIL source. We do not read them. The only thing we derive is a category label from a published vocabulary, your own model produces it, no term enters that vocabulary until several customers independently land on it, and you can decline the whole thing. We know which organization you belong to and how many checks it has run this month. We do not store your e-mail address, your name or your card.

What in the Privacy Policy does not happen here

The Privacy Policy is written for all of Jaxon's Services. Three of its statements describe things this service does not do:

What the service receives

What the service never receives

Your documents. The extraction that turns a document into claim values runs on your model, in your client; the service is not built to receive, store or process document text, and its wire contract has no field for it.

What is logged and metered

Every request writes one structured log line and one usage event. Both are metadata only: door, operation, route, outcome, duration, grammar features, counts of claims by type, source size, revision depth, a pseudonymous account key, a hashed credential id, a ruleset content hash, and — when you labeled — the label's vocabulary ids. This is the "Usage Data" of §4.2 of the General Terms, and it is all of it: the code that writes the usage event takes named parameters and has none that could carry policy text, a claim value, a claim name or a free-text label proposal, so those cannot reach the stream by mistake. Which rules a check concluded FALSE is deliberately not recorded either: that would describe your compliance position, and the stream is bookkeeping about usage.

Usage events are kept for 400 days in Jaxon's AWS account and are visible to a small number of Jaxon staff through a read-only dashboard role. Aggregate figures built from them never leave Jaxon below a minimum cell size; see data handling.

This documentation site

The CDN in front of these pages keeps ordinary access logs — path, referrer, user agent and status — for 400 days, so we can see which pages agents read. Client addresses are not recorded. The vocabulary page fetches the live vocabulary document from agents.jaxon.ai in your browser; that request is logged like any other request to the service and carries no identity.

Where it lives, and who processes it

Everything the service stores is on one encrypted volume in Amazon Web Services, region us-east-1, backed up daily with a cross-region copy in us-west-2 that expires on the same schedule as the usage events. Jaxon staff reach the host through AWS Systems Manager with multi-factor authentication; there is no SSH and no shared password. The Privacy Policy's §16 (international transfers) applies: the data is processed in the United States.

Three service providers are involved, and only the first holds any of your content:

ProviderWhat it holdsWhy
Amazon Web Serviceseverything the service stores: your ruleset source, names, approvals, unit library, usage eventsit is the infrastructure the service runs on
Auth0 (Okta)your sign-in credentials and the profile you hold with itit authenticates you so the service does not have to hold a password
Stripeyour payment details, if you subscribeit takes the payment so Jaxon never handles a card

Neither Auth0 nor Stripe receives any ruleset, any claim value, any ruleset name or any label. The only thing this service sends either of them is your organization name, as a reference so that a payment can be matched to an account. Jaxon will announce on this page, with notice, before adding another provider.

Your rights

Ask us at privacy@jaxon.ai to export or delete what you stored. Export returns your rulesets, revisions, approvals and unit libraries; deletion removes them and their metadata rows from the live store at once, and backup copies age out on the stated schedule (at most 400 days) without selective restore. Usage events already recorded are not deleted, because they carry no content and because the past cannot be metered retroactively. The Privacy Policy's §17 (rights of non-U.S. residents) and its Contact Us section apply to the personal data in approver names and notes, and to the subject identifier your identity provider issues you.

Deleting your sign-in identity is a request to Auth0 as well as to us, because we hold only the subject identifier and it holds the account. Deleting a payment relationship is a request to Stripe for the same reason. Ask us and we will tell you exactly which of the three holds what, and delete our part.

Security incidents

If Jaxon confirms an incident affecting your stored content, Jaxon will notify you without undue delay and no later than 72 hours after confirming it. What an incident can expose is bounded by what is stored: rules text, names, notes and approvals in the store; metadata in the usage stream; never claim values, documents or any assertion's result.

Changes

The version string at the top changes when this text changes in a way that matters to you, with the notice the terms state. dsail_get_account_status reports the terms version that governs your tier; this notice is versioned with it.

Contact

privacy@jaxon.ai, or Jaxon, Inc., 68 Harrison Avenue, Suite 605, Boston, MA 02111, USA.

Related: Terms of service, Data handling, Published vocabulary; Jaxon's Privacy Policy.