Privacy notice
The privacy notice for the DSAIL hosted service, supplementing Jaxon's Privacy Policy. What the service collects, what it never receives, how long it keeps what it holds, who can see it, and which parts of the general policy do not apply here.
Version 2026-09-14. Draft pending review by outside counsel. Issued by Jaxon, Inc. ("Jaxon"). This notice supplements Jaxon's Privacy Policy for one Service: the DSAIL hosted service at agents.jaxon.ai and this documentation site. The Privacy Policy applies to them except where this notice says otherwise; where the two differ about this service, this notice controls. It is versioned with the hosted-service terms and changes on the same notice.
The short version
We hold your rules text and DSAIL source. We do not read them. The only thing we derive is a category label from a published vocabulary, your own model produces it, no term enters that vocabulary until several customers independently land on it, and you can decline the whole thing. We know which organization you belong to and how many checks it has run this month. We do not store your e-mail address, your name or your card.
What in the Privacy Policy does not happen here
The Privacy Policy is written for all of Jaxon's Services. Three of its statements describe things this service does not do:
- Customer Content is not used to train or enhance models (Privacy Policy §3, last paragraph). At this version Jaxon runs no model on this service and uses your content solely to provide the service, as the terms license.
- Customer Content is not shared with Third-Party AI Partners (Privacy Policy §4(c)). There are none on this service. The only third party that holds your content is the hosting subprocessor, Amazon Web Services. The identity and payment providers named below hold no content: neither receives a ruleset, a claim value, a ruleset name or a label.
- No cookies, analytics scripts or advertising technologies (Privacy Policy §5, §11(b)) are set by the service or by this documentation site. The site's one script is the vocabulary page's live render, served from this origin, which sets nothing and reports nothing.
What the service receives
- Ruleset source — the DSAIL text your model drafted and you asked us to compile, save or approve. Stored normalised, at its content hash.
- Claim values — the schema-bounded dictionary you submit to a check. Held in memory for the duration of the call and never written anywhere: a check is pure over its inputs and leaves no record of the values judged.
- Names, notes and approvals — the name you save a ruleset under, and an approver's name and note. These are text you type; an approver's name is personal data where data-protection law applies, and it is stored beside the hash it refers to and used for nothing else. Do not put personal data in these fields beyond what an approval record needs.
- Unit converters — a factor, an attribution you typed, two unit names.
- A category label — optional, produced by your model, stored as ids only (see the published vocabulary).
- Credentials and authorizations — an evaluation credential and a production API key are each stored as a hash of the token, never as the token. A connector authorization is stored as an opaque subject.
- Sign-in identity — when you connect a chat client, you sign in at Jaxon's identity provider (Auth0). What reaches this service and is stored is your provider subject identifier and your organization name, where the organization is one your provider names or, failing that, the domain of your verified e-mail address. Your e-mail address itself is not stored. It is used once, in the moment you sign in, to work out which organization you belong to, and is then discarded; if your address is at a public mailbox provider, the organization recorded is an irreversible digest of the address rather than the address or its domain. No name, no picture and no client address is stored — the service does not even ask your provider for a name or a picture. Sharing a mail domain with somebody does not place you in an organization with them: where your provider names no organization, each address gets a project of its own unless Jaxon has recorded that domain as one organization at that customer's request. Auth0 holds your sign-in credentials under its own notice; Jaxon is the controller of the subject identifier and organization name described here.
- Billing identity — if you subscribe, Jaxon stores a payment-provider customer reference, a subscription reference, a status and your organization name. No card number, no billing address and no cardholder name ever reaches Jaxon: payment happens on a page Stripe hosts and Stripe is the controller of what it collects there, under its own notice.
- Usage counts — how many Jaxon Verified Units your organization has consumed in total, so an allowance can be reported and enforced.
What the service never receives
Your documents. The extraction that turns a document into claim values runs on your model, in your client; the service is not built to receive, store or process document text, and its wire contract has no field for it.
What is logged and metered
Every request writes one structured log line and one usage event. Both are metadata only: door, operation, route, outcome, duration, grammar features, counts of claims by type, source size, revision depth, a pseudonymous account key, a hashed credential id, a ruleset content hash, and — when you labeled — the label's vocabulary ids. This is the "Usage Data" of §4.2 of the General Terms, and it is all of it: the code that writes the usage event takes named parameters and has none that could carry policy text, a claim value, a claim name or a free-text label proposal, so those cannot reach the stream by mistake. Which rules a check concluded FALSE is deliberately not recorded either: that would describe your compliance position, and the stream is bookkeeping about usage.
Usage events are kept for 400 days in Jaxon's AWS account and are visible to a small number of Jaxon staff through a read-only dashboard role. Aggregate figures built from them never leave Jaxon below a minimum cell size; see data handling.
This documentation site
The CDN in front of these pages keeps ordinary access logs — path, referrer, user agent and status — for 400 days, so we can see which pages agents read. Client addresses are not recorded. The vocabulary page fetches the live vocabulary document from agents.jaxon.ai in your browser; that request is logged like any other request to the service and carries no identity.
Where it lives, and who processes it
Everything the service stores is on one encrypted volume in Amazon Web Services, region us-east-1, backed up daily with a cross-region copy in us-west-2 that expires on the same schedule as the usage events. Jaxon staff reach the host through AWS Systems Manager with multi-factor authentication; there is no SSH and no shared password. The Privacy Policy's §16 (international transfers) applies: the data is processed in the United States.
Three service providers are involved, and only the first holds any of your content:
| Provider | What it holds | Why |
|---|---|---|
| Amazon Web Services | everything the service stores: your ruleset source, names, approvals, unit library, usage events | it is the infrastructure the service runs on |
| Auth0 (Okta) | your sign-in credentials and the profile you hold with it | it authenticates you so the service does not have to hold a password |
| Stripe | your payment details, if you subscribe | it takes the payment so Jaxon never handles a card |
Neither Auth0 nor Stripe receives any ruleset, any claim value, any ruleset name or any label. The only thing this service sends either of them is your organization name, as a reference so that a payment can be matched to an account. Jaxon will announce on this page, with notice, before adding another provider.
Your rights
Ask us at privacy@jaxon.ai to export or delete what you stored. Export returns your rulesets, revisions, approvals and unit libraries; deletion removes them and their metadata rows from the live store at once, and backup copies age out on the stated schedule (at most 400 days) without selective restore. Usage events already recorded are not deleted, because they carry no content and because the past cannot be metered retroactively. The Privacy Policy's §17 (rights of non-U.S. residents) and its Contact Us section apply to the personal data in approver names and notes, and to the subject identifier your identity provider issues you.
Deleting your sign-in identity is a request to Auth0 as well as to us, because we hold only the subject identifier and it holds the account. Deleting a payment relationship is a request to Stripe for the same reason. Ask us and we will tell you exactly which of the three holds what, and delete our part.
Security incidents
If Jaxon confirms an incident affecting your stored content, Jaxon will notify you without undue delay and no later than 72 hours after confirming it. What an incident can expose is bounded by what is stored: rules text, names, notes and approvals in the store; metadata in the usage stream; never claim values, documents or any assertion's result.
Changes
The version string at the top changes when this text changes in a way that matters to you, with the notice the terms state. dsail_get_account_status reports the terms version that governs your tier; this notice is versioned with it.
Contact
privacy@jaxon.ai, or Jaxon, Inc., 68 Harrison Avenue, Suite 605, Boston, MA 02111, USA.
Related: Terms of service, Data handling, Published vocabulary; Jaxon's Privacy Policy.