# Privacy notice

The privacy notice for the DSAIL hosted service, supplementing Jaxon's Privacy Policy. What the service collects, what it never receives, how long it keeps what it holds, who can see it, and which parts of the general policy do not apply here.

**Version 2026-09-14.** Draft pending review by outside counsel. Issued by **Jaxon, Inc.**
("Jaxon"). This notice supplements Jaxon's [Privacy Policy](https://jaxon.ai/privacy/) for one
Service: the DSAIL hosted service at `agents.jaxon.ai` and this documentation site. The Privacy
Policy applies to them except where this notice says otherwise; where the two differ about this
service, this notice controls. It is versioned with the hosted-service [terms](terms.md) and
changes on the same notice.

## The short version

We hold your rules text and DSAIL source. We do not read them. The only thing we derive is a
category label from a published vocabulary, your own model produces it, no term enters that
vocabulary until several customers independently land on it, and you can decline the whole thing.
We know which organization you belong to and how many checks it has run this month. We do not
store your e-mail address, your name or your card.

## What in the Privacy Policy does not happen here

The Privacy Policy is written for all of Jaxon's Services. Three of its statements describe
things this service does not do:

- **Customer Content is not used to train or enhance models** (Privacy Policy §3, last
  paragraph). At this version Jaxon runs no model on this service and uses your content solely to
  provide the service, as the [terms](terms.md) license.
- **Customer Content is not shared with Third-Party AI Partners** (Privacy Policy §4(c)). There
  are none on this service. The only third party that holds your content is the hosting
  subprocessor, Amazon Web Services. The identity and payment providers named below hold no
  content: neither receives a ruleset, a claim value, a ruleset name or a label.
- **No cookies, analytics scripts or advertising technologies** (Privacy Policy §5, §11(b)) are
  set by the service or by this documentation site. The site's one script is the vocabulary
  page's live render, served from this origin, which sets nothing and reports nothing.

## What the service receives

- **Ruleset source** — the DSAIL text your model drafted and you asked us to compile, save or
  approve. Stored normalised, at its content hash.
- **Claim values** — the schema-bounded dictionary you submit to a check. Held in memory for the
  duration of the call and never written anywhere: a check is pure over its inputs and leaves no
  record of the values judged.
- **Names, notes and approvals** — the name you save a ruleset under, and an approver's name and
  note. These are text you type; an approver's name is personal data where data-protection law
  applies, and it is stored beside the hash it refers to and used for nothing else. Do not put
  personal data in these fields beyond what an approval record needs.
- **Unit converters** — a factor, an attribution you typed, two unit names.
- **A category label** — optional, produced by your model, stored as ids only (see
  [the published vocabulary](vocabulary.md)).
- **Credentials and authorizations** — an evaluation credential and a production API key are each
  stored as a hash of the token, never as the token. A connector authorization is stored as an
  opaque subject.
- **Sign-in identity** — when you connect a chat client, you sign in at Jaxon's identity provider
  (Auth0). What reaches this service and is stored is **your provider subject identifier and your
  organization name**, where the organization is one your provider names or, failing that, the
  domain of your verified e-mail address. **Your e-mail address itself is not stored.** It is used
  once, in the moment you sign in, to work out which organization you belong to, and is then
  discarded; if your address is at a public mailbox provider, the organization recorded is an
  irreversible digest of the address rather than the address or its domain. No name, no picture and
  no client address is stored — the service does not even ask your provider for a name or a
  picture. Sharing a mail domain with somebody does not place you in an organization with them:
  where your provider names no organization, each address gets a project of its own unless Jaxon
  has recorded that domain as one organization at that customer's request. Auth0 holds your
  sign-in credentials under its own notice; Jaxon is the controller of the subject identifier and
  organization name described here.
- **Billing identity** — if you subscribe, Jaxon stores a payment-provider customer reference, a
  subscription reference, a status and your organization name. **No card number, no billing
  address and no cardholder name ever reaches Jaxon**: payment happens on a page Stripe hosts and
  Stripe is the controller of what it collects there, under its own notice.
- **Usage counts** — how many Jaxon Verified Units your organization has consumed in total, so
  an allowance can be reported and enforced.

## What the service never receives

Your documents. The extraction that turns a document into claim values runs on your model, in
your client; the service is not built to receive, store or process document text, and its wire
contract has no field for it.

## What is logged and metered

Every request writes one structured log line and one usage event. Both are **metadata only**:
door, operation, route, outcome, duration, grammar features, counts of claims by type, source
size, revision depth, a pseudonymous account key, a hashed credential id, a ruleset content hash,
and — when you labeled — the label's vocabulary ids. This is the "Usage Data" of §4.2 of the
General Terms, and it is all of it: the code that writes the usage event takes named parameters
and has none that could carry policy text, a claim value, a claim name or a free-text label
proposal, so those cannot reach the stream by mistake. Which rules a check concluded FALSE is
deliberately not recorded either: that would describe your compliance position, and the stream is
bookkeeping about usage.

Usage events are kept for 400 days in Jaxon's AWS account and are visible to a small number of
Jaxon staff through a read-only dashboard role. Aggregate figures built from them never leave
Jaxon below a minimum cell size; see [data handling](data-handling.md).

## This documentation site

The CDN in front of these pages keeps ordinary access logs — path, referrer, user agent and
status — for 400 days, so we can see which pages agents read. Client addresses are not recorded.
The vocabulary page fetches the live vocabulary document from `agents.jaxon.ai` in your browser;
that request is logged like any other request to the service and carries no identity.

## Where it lives, and who processes it

Everything the service stores is on one encrypted volume in Amazon Web Services, region
`us-east-1`, backed up daily with a cross-region copy in `us-west-2` that expires on the same
schedule as the usage events. Jaxon staff reach the host through AWS Systems Manager with
multi-factor authentication; there is no SSH and no shared password. The Privacy Policy's §16
(international transfers) applies: the data is processed in the United States.

Three service providers are involved, and only the first holds any of your content:

| Provider | What it holds | Why |
| --- | --- | --- |
| Amazon Web Services | everything the service stores: your ruleset source, names, approvals, unit library, usage events | it is the infrastructure the service runs on |
| Auth0 (Okta) | your sign-in credentials and the profile you hold with it | it authenticates you so the service does not have to hold a password |
| Stripe | your payment details, if you subscribe | it takes the payment so Jaxon never handles a card |

**Neither Auth0 nor Stripe receives any ruleset, any claim value, any ruleset name or any label.**
The only thing this service sends either of them is your organization name, as a reference so that
a payment can be matched to an account. Jaxon will announce on this page, with notice, before
adding another provider.

## Your rights

Ask us at privacy@jaxon.ai to export or delete what you stored. Export returns your rulesets,
revisions, approvals and unit libraries; deletion removes them and their metadata rows from the
live store at once, and backup copies age out on the stated schedule (at most 400 days) without
selective restore. Usage events already recorded are not deleted, because they carry no content
and because the past cannot be metered retroactively. The Privacy Policy's §17 (rights of non-U.S.
residents) and its Contact Us section apply to the personal data in approver names and notes, and
to the subject identifier your identity provider issues you.

Deleting your sign-in identity is a request to Auth0 as well as to us, because we hold only the
subject identifier and it holds the account. Deleting a payment relationship is a request to
Stripe for the same reason. Ask us and we will tell you exactly which of the three holds what, and
delete our part.

## Security incidents

If Jaxon confirms an incident affecting your stored content, Jaxon will notify you without undue
delay and no later than 72 hours after confirming it. What an incident can expose is bounded by
what is stored: rules text, names, notes and approvals in the store; metadata in the usage
stream; never claim values, documents or any assertion's result.

## Changes

The version string at the top changes when this text changes in a way that matters to you, with
the notice the terms state. `dsail_get_account_status` reports the terms version that governs your
tier; this notice is versioned with it.

## Contact

privacy@jaxon.ai, or Jaxon, Inc., 68 Harrison Avenue, Suite 605, Boston, MA 02111, USA.

Related: [Terms of service](terms.md), [Data handling](data-handling.md),
[Published vocabulary](vocabulary.md); Jaxon's [Privacy Policy](https://jaxon.ai/privacy/).
