Privacy Policy
Last updated: July 30, 2026
This policy explains what JubarteAI collects, why, and how we handle it. JubarteAI is operated by A&A GLOBAL INTERNATIONAL LLC, a Florida limited liability company (“JubarteAI,” “we,” “us”).
We act as the controller for the account-level data we collect about you directly — your email, sign-in metadata, and billing details. For Customer Content — what you and your team write into your workspace (knowledge entries, agent tasks, messages) — we act as a processor on your behalf. The workspace owner is the controller of that content.
For privacy questions, data-subject requests, or a Data Processing Addendum, email hello@jubarte.ai. This policy applies to jubarte.ai, the dashboard, and the MCP API at /api/mcp.
1. Information we collect
Account information
Email, last sign-in timestamp, and — if you sign in via OAuth — the basic profile fields the OAuth provider returns. We collect this to create and secure your account, identify you, and correlate your workspace activity and content to you. Passwords are handled by our authentication provider: we receive a hash, never plaintext.
Workspace information
Workspace name, slug, members, member roles, billing email, and pending invites. We collect this to operate your multi-tenant workspace, enforce membership and roles, and reach the billing contact. Invite tokens are hashed and expire after 14 days.
Knowledge entries (Customer Content)
Whatever your agents write — title, body, tags, branches, repository slugs, refs (ticket IDs, PR URLs), kind, and the authoring agent and seat. We store this content so JubarteAI can make it available to the agents in your workspace — a shared brainyour fleet reads from and writes to. We process it on your behalf solely to store, index, search, and deliver it back to your workspace; we don't use it for our own purposes and we don't train models on it. Be mindful: don't put secrets, API keys, or third-party PII into knowledge entries — they're shared with everyone in your workspace.
Agent activity
Agent name (we generate it), the description you provide identifying the IDE or harness, agent tasks (title, description, branches, repositories, tickets, refs), and inter-agent messages. We collect this so your team and your agents can see who's active and coordinate. Last-seen timestamps are recorded on every MCP call so liveness can be shown accurately. This activity metadata is visible only inside your workspace and is erased with it when your workspace is deleted.
JubarteAI API keys
Per-seat tokens we issue to authenticate your IDE's connection to JubarteAI over MCP — not API keys from your own systems, which we never ask for and never collect. We store a SHA-256 hash and a short prefix for display so we can authenticate requests without holding the plaintext; the plaintext token is shown exactly once, at creation, and is unrecoverable afterward — even to us.
Billing information
Customer ID, subscription ID, plan, status, period end, trial end, billing email, and cancellation flag, mirrored from our billing provider. We collect this to charge the right amount, enforce plan and seat limits, and run the trial and renewal lifecycle. Card data is held by our PCI-compliant payment processor; we never see card numbers.
Version-control integration
If you install our version-control integration, we store the installation ID, the account login (org or user), and metadata for repositories you bind (id, full name, default branch). On a pull-request merge in a bound repository, we receive head and base branch names solely so we can promote knowledge tagged with the head branch onto the base branch, keeping your shared brain organized. We do not read or store your source code.
Operational logs
Standard server-side observability — request logs, error traces, last-seen timestamps. We keep these to operate, secure, and debug the service, and retain them short-term.
2. What we don't collect
Your source code. JubarteAI never reads, ingests, or stores the contents of your repositories. Agents read code locally in your IDE and only write what they choose to share — knowledge entries, tasks, and messages — to JubarteAI. What you see in the dashboard is exactly what the platform stores. Nothing more.
We don't run analytics, advertising, or third-party tracking. We don't sell or rent personal data. We don't train models on your data.
3. How we use information
- Operate the service — authenticate accounts and MCP requests, scope every read and write to your workspace, and serve the dashboard.
- Process billing — sync subscriptions with our billing provider, compute seat counts, and handle trial and renewal lifecycle events.
- Send transactional email — invites, billing reminders, trial-ending notices, payment-failure notices, and similar account-critical messages.
- Run integrations — when a pull request merges in a bound repository, append the base branch onto matching knowledge entries.
- Handle support — respond to questions, debug issues, and act on data-subject requests.
- Improve and develop the service — using de-identified or aggregated usage data, never the contents of your knowledge entries, to debug, analyze usage patterns, and improve features. We don't use this data to train AI models.
4. Legal bases for processing
Where GDPR or UK GDPR applies, we rely on the following legal bases:
- Contract performance — most of what we do: creating your account, operating your workspace, and delivering the service you signed up for.
- Legitimate interests — security and fraud prevention, keeping the service reliable, and improving features using de-identified or aggregated usage data (never Customer Content).
- Legal obligation — tax and accounting records, and responding to lawful requests from authorities.
- Consent — where required, such as optional communications you can opt out of at any time.
For Customer Content, the workspace owner is responsible for having a lawful basis for any personal data its team instructs us to process on its behalf.
5. AI processing
When you run a knowledge search, we send your query and a small slice of candidate entries — title plus roughly the first 400 characters of the body, for the top 50 candidates — to our AI providerfor query expansion and result reranking. The AI provider processes the data only to return the ranking. We don't train any model on your data. Retention by the AI provider is governed by their terms; we'll move to a zero-retention tier where commercially available. If the AI provider isn't configured, search degrades to keyword-only search with no model call.
6. Service providers
We rely on third-party providers to deliver the service. As of the date above, we use providers in the following categories:
- Database, authentication, and realtime hosting — stores workspace data and runs sign-in.
- Billing and card processing — handles subscriptions and payment methods.
- AI provider — query expansion and reranking for knowledge search.
- Transactional email — delivers invites and account-critical notices.
- Version-control integration — receives pull-request events from repositories you connect.
- Application hosting — runs the website, dashboard, and MCP API.
We may change providers from time to time. The current vendor list is available on request from hello@jubarte.ai, and we'll notify paid customers in advance of material changes.
7. How we share information
We don't sell or rent personal data. We disclose data only to the providers above as needed to operate the service, to comply with law or valid legal process, to protect rights, safety, and the integrity of the service, or in connection with a merger, acquisition, or asset sale (with notice and equivalent protections).
8. International data transfers
Data may be processed in the United States and in other regions where our providers operate. We rely on industry-standard safeguards — encryption in transit and at rest (TLS 1.3 / AES-256) plus contractual data-protection terms with providers, including standard contractual clauses where required — to protect data across borders.
9. Tenant isolation
Every read and write is scoped to your workspace and enforced at the data layer — not just in application code that could drift. The MCP API enforces the same boundary on every request, so one workspace can never see or modify another's data.
10. Data retention
Account and workspace data is kept while your account is active. When you cancel or delete your workspace, it enters a 30-day grace period and is then permanently erased. To request an export of your data during that window — knowledge, tasks, messages — email hello@jubarte.ai. Pending invites auto-expire after 14 days. Idempotency ledgers are retained for roughly 90 days for replay protection. Backups roll out within 30 days of deletion.
11. Your rights and choices
You have the right to access, correct, export, and delete your data. For any of these — including objection, restriction of processing, or a request from a member of your workspace — email hello@jubarte.ai. We respond within 30 days.
California residents (CCPA/CPRA): the rights above are how we satisfy access and deletion requests. We do not sell or “share” personal information for cross-context behavioral advertising, and we do not use sensitive personal information for any purpose that requires a separate opt-out.
EU/UK residents: you have rights of access, rectification, erasure, restriction, portability, and objection under GDPR / UK GDPR. You can also lodge a complaint with your local supervisory authority.
12. Cookies
We use only a single strictly-necessary session cookie to keep you signed in. No analytics, no advertising, no third-party tracking cookies. There's no consent banner because there's nothing to consent to beyond that strictly-necessary session cookie.
13. Security
TLS 1.3 in transit, AES-256 at rest on managed infrastructure. API tokens are SHA-256 hashed at rest and only the plaintext is shown — once, at creation. Knowledge writes, agent registrations, and API key use are attributed to a seat and timestamped, so activity in your workspace is traceable. We'll notify affected users without undue delay if we discover a security incident materially affecting their data, as required by applicable law.
14. Children
The service is not directed at children under 13, or under 16 where that minimum applies. We don't knowingly collect personal data from them. If you believe a child has signed up, email us and we'll delete the account.
15. Changes to this policy
We may update this policy. For material changes we'll give notice by email or in-app and update the “Last updated” date above. Continued use after the effective date is acceptance of the updated policy.
16. Contact
A&A GLOBAL INTERNATIONAL LLC, Florida, USA.
Privacy questions, data-subject requests, or DPA requests: hello@jubarte.ai.