Privacy Policy
This Privacy Policy explains what data Jandex (the "Service") collects, how it is used, and the rights you have over it. By using the Service, you agree to the collection and use of information in accordance with this policy.
We collect the data you give us (account info), the data your ESP (such as Klaviyo or Omnisend) returns to us when you connect it (campaign and flow metrics, the content of your campaigns and flows, audience data, revenue data), and standard technical data (logs, IP, browser). If you connect a Gmail or Google Workspace inbox, we read only the messages needed for the feature you turned on (for example, subscriber replies to your own emails for Reply Tracking). We use that data only to operate the Service. We do not sell it. We share it only with the limited service providers required to run Jandex, and with an AI app such as Claude or ChatGPT only if you connect it to Jandex yourself.
01 Who we are
Jandex is operated by JHM Email Marketing Services, a sole proprietorship registered in the Philippines and based in Mexico, Pampanga, Philippines. References to "Jandex," "we," "us," and "our" refer to this operator, which acts as the data controller for the personal information described in this policy. For privacy questions, contact hello@jandex.io.
02 What we collect
| Category | What it includes |
|---|---|
| Account data | Name, email address, agency or company name, password (hashed), and authentication tokens. |
| ESP data | Access tokens to the email service provider you connect (e.g., Klaviyo or Omnisend). Most of Jandex is read-only, but some tools you explicitly enable, such as list cleaning, can take actions in your ESP on your behalf (for example, suppressing unengaged profiles). Through this connection we retrieve campaign and flow performance; the content of your own campaigns and flows, including subject lines and email and SMS message bodies; segment and audience metrics; revenue figures; and subscriber-level engagement and order events that we use to compute analytics such as lifetime value, email frequency, and time-to-first-purchase. To power AI features that analyze creative, we may also generate and store screenshots of your campaign and flow emails. We do not access your subscribers' personal email accounts or inboxes, we do not use your subscribers' data to contact them, and we keep the personal identifiers we store to what is needed to compute these metrics. |
| Google account data | Only if you choose to connect a Gmail or Google Workspace inbox. We request read-only access and use it solely for the Gmail features you turn on, described in Section 05. Permission to send is requested only if you turn on automatic replies in Reply Tracking. Depending on the feature, we store the inbox address, the access tokens, and the specific messages that feature needs. We never change or delete email in your inbox. |
| Usage data | How you interact with the Service: pages visited, features used, queries asked of the AI assistants, and timestamps. Used to improve product quality. |
| Technical data | IP address, browser type, device type, operating system, referrer URL, and standard server logs. |
| Billing data | If and when you become a paying customer, billing is handled by Lemon Squeezy (lemonsqueezy.com), which acts as our Merchant of Record. We receive only the limited information Lemon Squeezy returns to us (subscription status, plan, transaction IDs). Payment-card details are never seen or stored by Jandex. |
| Communications | Any emails or messages you send us, including support requests and feedback. |
03 How we use it
We use the data we collect for the following purposes:
- To provide, operate, and maintain the Service.
- To process the data your ESP returns and present analytics and AI-generated insights based on it.
- To pass relevant subsets of your data to AI model providers in order to generate insights, summaries, and recommendations within the Service.
- To communicate with you about your account, support requests, security notices, and material updates to the Service.
- To diagnose technical issues, prevent fraud, and ensure security.
- To improve the Service through aggregated and anonymized analysis of usage patterns.
04 AI processing
The Service uses third-party AI models (including models provided by Anthropic and other providers) to power its AI assistants and to generate analyses, summaries, and recommendations. When you interact with the AI assistants or run an AI-powered feature, relevant subsets of your account data, and, where you use features that analyze creative, screenshots of your campaign or flow emails, are transmitted to these providers together with your query in order to generate a response. We use AI providers that offer business-grade APIs with no-training-on-customer-data commitments wherever possible. We do not transmit your raw subscriber lists or your subscribers' email addresses to AI providers.
AI apps you connect (the Jandex connector)
You can choose to connect Jandex to an AI app you use, such as Claude or ChatGPT, through the Jandex connector at https://mcp.jandex.io. This is always optional and always started by you: you add the connector in your AI app, sign in with your Jandex login, and approve the connection on a Jandex page that names the app asking for access.
- What the AI app can see. When you ask the AI app a question, it can request reporting data from Jandex for the brands your Jandex account can access, and nothing else. That data is your reporting: account name, currency and time zone; email revenue by period; campaign and flow names with their performance metrics; link click shares for a campaign; repeat purchase, lifetime value and next purchase figures, including product names; and when customers buy. It does not include your subscribers' email addresses, names or individual profiles, and it does not include your inbox data.
- Read-only. The connector cannot send email, change lists or segments, edit campaigns or flows, change consent or make any change in Jandex or in your email service provider.
- How the AI app handles it. Data the AI app receives is processed by that app's provider under your own agreement with them and their privacy policy. Jandex does not control how that provider stores or uses it, so review their terms before connecting.
- What Jandex keeps. We store the approval you gave (which app, which Jandex user, and when) and the sign-in tokens needed to keep the connection working. For reliability and security we log each request's tool name, duration and outcome for a short period. We do not keep a copy of the answers sent to the AI app.
- Disconnecting. Remove the Jandex connector in your AI app at any time. Access tokens expire within an hour. To have the approval revoked on our side straight away, email hello@jandex.io.
05 Gmail and Google user data
Some Jandex features work by reading an inbox you connect with Google sign-in. Connecting an inbox is always optional, and you choose which inbox to connect. Reply Tracking uses its own connection, separate from the inbox you connect for Competitor Research, so connecting one never gives the other access to that inbox. We ask for read-only access to Gmail (the gmail.readonly permission). Jandex never changes or deletes any email. Jandex only sends email if you turn on automatic replies in Reply Tracking (described below); only then do we also ask for permission to send (the gmail.send permission), and Google shows you that request before you agree.
What we read and why
- Reply Tracking. You connect the inbox your emails' reply-to address goes to. Jandex checks it every few minutes for replies. A message is only kept if it is a reply from one of your own email marketing subscribers (a profile in your connected ESP) to an email you sent them through that ESP. For those replies we store the sender's name and email address, the subject, the date, and the text of the reply with the quoted original removed. We use them to show your reply rate and replies in Jandex, and to send a reply event (and, if the reply matches a reward keyword you set, a keyword event) to your own ESP account so your flows can respond. Every other message in the inbox is ignored: we read only its message headers to rule it out, and we keep no sender, subject or content from it. To avoid checking the same message twice we keep only its Gmail message ID, for up to 7 days.
- Automatic replies (Reply Tracking, optional). If you write a reply for a reward keyword and turn it on, Jandex sends that reply from the connected inbox to a subscriber who replied with that keyword, inside the same email conversation. It is sent once per person per keyword, a few minutes after their reply, and never to auto-replies or to anyone who asked to stop. The message is the text you wrote, with only the subscriber's first name and the code you set filled in. We store the reply we sent, when it was sent and its Gmail message ID, and we tell your own ESP account that it was sent. Jandex does not send any other email from your inbox, and you can turn automatic replies off at any time.
- Competitor Research. You choose the sender domains you want to follow. We store the emails from those senders (sender, subject, preheader and email content) so you can browse and analyze them in Jandex. Messages from other senders are not stored.
- Automated imports. You set up a rule that matches a sender and subject, such as a report your systems email to you. We read only the messages that match your rule and turn them into the data or events you configured. Other messages are not stored.
How Google user data is handled
- We use Google user data only to provide and improve the user-facing features described above, and only for the account you connected it to.
- We do not sell Google user data, and we do not use it for advertising, retargeting, credit checks or lending decisions.
- We do not use Google user data to develop, improve or train generalized AI or machine learning models. If you run an AI feature on content Jandex has stored for you (for example, analyzing a competitor email), that content is sent to our AI provider only to generate the result you asked for, under terms that do not allow it to be used for training.
- We transfer Google user data only to provide the feature you turned on (for example, sending reply events to your own ESP account, or sending an automatic reply you set up to the subscriber it is meant for), to our hosting provider to store it securely, when required by law, or as part of a merger or acquisition with your notice.
- No person at Jandex reads your email unless you ask us to (for example, in a support request), it is needed for security reasons such as investigating abuse, or it is required by law. Our systems process it automatically.
- Access tokens and stored messages are encrypted in transit and at rest.
Jandex's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Disconnecting and deletion
You can remove Jandex's access at any time from your Google Account at myaccount.google.com/permissions. For Reply Tracking you can also click Disconnect in Jandex, which removes the access at Google for you. Once access is removed, Jandex can no longer read or send from the inbox. To have the stored data from your inbox deleted (replies, competitor emails and access tokens), email hello@jandex.io and we will delete it within 30 days. It is also deleted when you delete your Jandex account.
06 Who we share with
We do not sell your data. We do not rent or trade your data. We share data only with the following limited categories of service providers, and only to the extent necessary to operate the Service:
- Hosting & infrastructure (Supabase): to host the application, database, and authentication, and to store your data securely.
- AI model providers (including Anthropic): to process queries and generate insights, as described in Section 04.
- AI apps you connect: if you connect an AI app such as Claude or ChatGPT through the Jandex connector, the reporting data it requests for your accounts is sent to that app, at your direction, as described in Section 04.
- Your own ESP account: when you turn on a feature that sends data back to your ESP (for example, reply events from Reply Tracking), we send it to the ESP account you connected, at your direction.
- Payment processor (Lemon Squeezy): our Merchant of Record, to handle billing if and when you become a paying customer.
- Analytics & error monitoring: to diagnose performance issues and bugs.
- Email service: to send transactional emails (account confirmations, password resets, billing notices).
- Legal & regulatory authorities: when required by law, court order, or to protect our rights or the safety of others.
07 Data retention
We retain your data for as long as your account is active. If you delete your account, we delete your account data, disconnect your ESP integration, and delete any Gmail access tokens and stored inbox data within 30 days, except where retention is required for legal, accounting, or fraud-prevention purposes. Aggregated and anonymized data may be retained indefinitely.
08 Legal bases for processing (GDPR)
If you are located in the European Economic Area, the United Kingdom, or another jurisdiction with similar requirements, we rely on the following legal bases under Article 6(1) of the GDPR for each processing activity described in Section 03:
| Processing activity | Legal basis |
|---|---|
| Account creation, authentication, and billing | Contract (Art. 6(1)(b)): necessary to provide the Service you signed up for. |
| Reading and processing the ESP data you connect (campaigns, flows, metrics, audience and revenue data) | Contract (Art. 6(1)(b)): necessary to provide the reporting and analytics you connected your account for. |
| Reading a Gmail inbox you connect, for the features you turn on (Section 05) | Contract (Art. 6(1)(b)). A feature you actively enabled. For the replies of your own subscribers that we process on your behalf, you are the controller and we act as your processor. |
| Actions you explicitly trigger in your ESP (e.g. list cleaning, pushing a segment) | Contract (Art. 6(1)(b)): a feature you actively initiated. |
| Answering requests from an AI app you connect through the Jandex connector (Section 04) | Contract (Art. 6(1)(b)): a feature you actively connect and approve. |
| AI-generated insights, summaries, and recommendations (Section 04) | Contract (Art. 6(1)(b)) for delivering the feature; legitimate interests (Art. 6(1)(f)) for related product improvement. |
| Service-related communications (account, support, security notices, material updates) | Contract (Art. 6(1)(b)). |
| Optional product or marketing communications | Consent (Art. 6(1)(a)): you may withdraw this at any time. |
| Diagnosing technical issues, fraud prevention, and security monitoring | Legitimate interests (Art. 6(1)(f)): keeping the Service secure and reliable. |
| Aggregated, anonymized analysis to improve the Service | Legitimate interests (Art. 6(1)(f)). |
| Responding to legal requests, tax, accounting, and fraud-prevention record-keeping | Legal obligation (Art. 6(1)(c)). |
09 Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Delete your data ("right to be forgotten").
- Export your data in a portable format.
- Object to or restrict certain types of processing.
- Withdraw consent where processing is based on consent.
To exercise any of these rights, email hello@jandex.io. We will respond within 30 days.
10 California privacy rights (CCPA)
This section applies to personal information we collect about you as a user of the Service (for example, your account, billing, and usage data). It does not apply to the data of your subscribers or contacts that we process on your behalf when you connect an ESP. For that data, we act as your service provider, and your own privacy practices toward your subscribers govern.
Categories of personal information we collect about you, as defined under the CCPA:
- Identifiers: name, email address, agency or company name.
- Commercial information: subscription plan and billing/transaction status.
- Internet or other electronic network activity: pages visited, features used, IP address, browser and device type, server logs.
We do not sell or share personal information (including for cross-context behavioral advertising) as those terms are defined under the CCPA, and we have not done so in the preceding 12 months.
If you are a California resident, you have the right to: know what personal information we collect and how we use it; delete your personal information; correct inaccurate personal information; and non-discrimination for exercising any of these rights. Because we do not sell or share personal information, there is no opt-out to exercise. To submit a request, email hello@jandex.io; we will verify and respond within the timeframe required by law.
11 Security
Keeping your data safe is a priority. We follow industry-standard security practices, including encryption in transit (HTTPS) and at rest, strict access controls, hardened infrastructure from our hosting provider, and regular security review. Your ESP connection and any Gmail connection use access tokens you can revoke at any time, and your payment-card details are handled entirely by our payment provider, and Jandex never sees or stores them.
No online service can promise perfect security, but we treat your data with care and work continually to protect it. In the unlikely event of a security incident affecting your information, we will notify you promptly and take the steps required by law.
12 International data transfers
Jandex is operated from the Philippines, but our service providers (hosting, AI, email, etc.) may be located in the United States, the European Union, or other jurisdictions. By using the Service, you consent to your data being transferred to and processed in countries other than your own. Where required, we use standard contractual clauses or equivalent safeguards.
13 Children
The Service is not intended for individuals under the age of 18. We do not knowingly collect personal data from children. If you become aware that a child has provided personal data to us, please contact us and we will take steps to delete it.
14 Cookies and tracking
The Service uses essential cookies and similar browser local storage to keep you logged in and to remember your preferences. We may also use limited analytics to understand usage patterns. We do not use third-party advertising cookies. You can control cookies through your browser settings.
15 Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will post the updated policy at this URL and update the "Last updated" date at the top. Material changes will be communicated by email to active users.
16 Contact
Privacy questions? Email hello@jandex.io.