Legal
Privacy Policy
Last Updated: May 2026
Introduction
At Jalaran, your privacy matters. Jalaran is a cloud-assisted application that uses Supabase for authentication and data storage, and processes AI requests via Jalaran's backend API. This Privacy Policy explains what data we collect, how we use it, and the rights you have over it.
Information We Collect
We collect only the minimum data required to operate your account: your email address for authentication and basic subscription management. Notes you create are stored in Supabase (encrypted at rest and in transit). AI chat prompts and analysis inputs are processed via our backend API on a per-request basis.
How We Use Your Information
Your prompts and files are submitted to Jalaran's backend API to generate responses. They are not permanently retained after processing, and are never used to train third-party AI models without your explicit consent. We use your email strictly for account administration and support. We do not sell your personal data.
Data Security & Retention
Your notes and account data are stored in Supabase, encrypted in transit and at rest. You retain full ownership of your data.
You may delete your account and all associated data at any time, which permanently removes it from our databases.
Your Rights (UU PDP Compliance)
In accordance with the Personal Data Protection Law of Indonesia (UU PDP), you have the right to access, correct, or delete your personal data. You may also withdraw consent for any optional data collection at any time.
This Privacy Policy is governed by and construed in accordance with the laws of the Republic of Indonesia.
Who We Are
Jalaran is operated by [legal entity / operator name], which acts as the data controller responsible for your personal data. You can reach us at [email protected].
Service Providers We Share Data With
We share data only with vetted providers needed to run the service: Supabase (authentication and database hosting), Google (Sign-in with Google), the host that runs our Google Gemma AI model, and — once billing launches — Stripe (payments). Each processes data solely on our instructions.
Legal Basis for Processing
Where the GDPR applies, we process personal data to perform our contract with you, on the basis of your consent for optional features, and for our legitimate interests in securing and improving the service. Where Indonesia's UU PDP applies, we rely on your consent and the other lawful bases it recognises.
How AI Features Use Your Content
When you use AI features, the content you submit — chat prompts, notes, tasks, and uploaded files — is sent to the Google Gemma model hosted for Jalaran to generate a response. It is processed per request and is not used to train third-party AI models without your explicit consent.
International Data Transfers
Your data may be processed on servers outside your country (for example, your Supabase project region and Google's infrastructure). Where required, we rely on appropriate safeguards such as Standard Contractual Clauses. [Confirm Supabase region and transfer mechanism.]
Data Retention
We keep your account and content data while your account is active and delete it when you delete your account; backups are purged on a rolling basis. [Set concrete retention periods.]
Cookies & Local Storage
We use only strictly necessary cookies and local storage — to keep you signed in and to remember preferences such as theme and language. We do not use third-party advertising trackers.
Your Rights Under GDPR and CCPA/CPRA
Depending on where you live, you may have rights to access, correct, delete, export, or object to the processing of your personal data, and to withdraw consent. We do not sell or share your personal information as defined by California law. To exercise any right, email [email protected].
Children's Privacy
Jalaran is not directed to children under 13 (or the minimum age required in your country), and we do not knowingly collect their personal data.
Security Incidents
We use industry-standard safeguards, including encryption in transit and at rest. No system is perfectly secure; if a breach affects your personal data, we will notify you and the relevant authority as required by law.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes in-app or by email and update the "Last Updated" date above.
Contact Us
If you have questions or concerns about this Privacy Policy, contact us at: [email protected]