Home
Last updated · 2026-05-11

Privacy Policy

1. Overview

Jingles is an emotionally-intelligent relationship platform. We collect personal information so that you can match with other users, communicate with them, work through patterns with our AI Coach and Mediator, and feel safer in your conversations. This policy explains what we collect, why, and what rights you have.

2. Information We Collect

2.1 Information you give us directly

  • Account & profile: name, email, date of birth, gender, photos, bio, location, MBTI type, communication preferences.
  • Assessments: attachment style, behavioral patterns, trauma history, mediator preferences. These responses are sensitive personal data under EU/UK GDPR and equivalent regimes.
  • Conversations: messages exchanged with matches, messages exchanged with your private Coach, voice and video session metadata.
  • Interests & matches: who you express interest in, who expresses interest in you, mutual match decisions.

2.2 Information collected automatically

  • Device & usage: IP address (for security and rate limiting), browser type, push notification subscription metadata, anonymized error reports (via Sentry), and aggregate page counts (via Vercel Web Analytics, which is cookieless: it stores nothing on your device, assigns you no identifier, and cannot follow you to other sites).
  • Local storage: theme preference, dismissed notices, session tokens. We do not use third-party analytics cookies.

2.3 Information we derive

  • Trust & Shield scores: aggregate counters updated when Jingle Shield flags messages.
  • Conversation pattern metrics (only if you opt in to Pattern Insight): message counts, average length, response timing, flag history per conversation. We never analyze message content for Pattern Insight — only metadata.

3. How We Use Your Information

  • To operate the matching, chat, and session features.
  • To run the Jingle Shield AI safety analyzer on messages you send (real-time pattern detection).
  • To power your personal AI Coach's responses (private to you).
  • To power the shared Mediator's responses in chats.
  • To generate AI-written Match Explanations using aggregate compatibility data only.
  • To detect abuse, prevent fraud, and enforce these Terms.
  • To communicate service updates and respond to support requests.

4. AI Processing & Third-Party Providers

To deliver the Service, we share specific data with the following processors. We have data-processing agreements in place with each provider, and they are bound to use the data only for the purpose of delivering services to us.

  • Anthropic (Claude): processes individual messages for Shield analysis and Coach/Mediator responses. Message content transits to Anthropic but is not used to train their models (zero-data-retention policy in effect).
  • Supabase: our primary database, authentication, and file storage provider. Hosts profile data, conversations, and session metadata.
  • Agora: WebRTC infrastructure for voice and video sessions. Audio/video streams transit through Agora but are not recorded by Jingles (subject to Section 8 below if recording is ever enabled).
  • Hume AI: optional emotion sensing during voice sessions. Audio is analyzed in-flight; we do not store raw audio.
  • ElevenLabs: voice synthesis for mediator personas in voice sessions.
  • Sentry: error tracking. We do not send Personally Identifiable Information by default (no IP, no user-agent). Stack traces and breadcrumbs are sent for debugging.
  • Upstash Redis: rate-limit counters keyed by user ID. No content; only counts.
  • Vercel: our hosting provider. Standard web access logs apply.
  • Web Push services:when you opt in to push notifications, your browser's push endpoint (Apple Push, Google FCM, Mozilla Push) receives encrypted notification payloads.

5. Sensitive Data

Some of the data you provide — attachment style, trauma history, behavioral patterns, communication preferences — is highly sensitive. We treat it accordingly:

  • Stored encrypted at rest within our Supabase database.
  • Visible only to you and the AI features you have explicitly enabled.
  • Never shared with other users without your action (e.g., you expressing interest in someone shares relevant profile signals with that person, but not the underlying assessment answers).
  • Excluded from training data sent to AI providers (zero-retention agreement in effect with Anthropic).

6. Your Rights

Depending on your jurisdiction (EU/UK GDPR, California CCPA, etc.), you have the following rights:

  • Access & export: Download a copy of your data from Settings → Data → Download My Data.
  • Deletion: Delete your account in the app under Profile → Settings → Account → Delete account. Full steps, and how to delete specific data without closing your account, are on Delete your account or data.
  • Correction: Update profile fields directly in the app.
  • Opt-out: Disable Pattern Insight, push notifications, or AI features in Settings.
  • Object & restrict: Contact us at hello@jhicarus.com to object to specific processing or restrict certain uses.
  • Complain: You may lodge a complaint with your local data protection authority.

7. Data Retention

We retain your data for as long as your account is active. When you delete your account, your profile, matches, messages, and coach history are permanently removed within 30 days. Aggregate, de-identified statistics may be retained for product analytics. Backup copies are purged within 90 days. Where required for legal, tax, or regulatory reasons, we may retain certain records longer.

8. Voice & Video Sessions

Voice and video sessions between matched users are routed through Agora WebRTC. Jingles does not record session audio or video. The shared Mediator may produce text interjections that are saved to the conversation thread. If we ever introduce optional call recording, we will require explicit consent from all participants before recording begins.

8.1 Optional in-call live transcription

As of June 2026 you can opt in to live transcription so the AI Mediator can reference what was actually said when it steps in. This is off by default and opt-in only — you control it in Settings→ Notifications → In-call audio + video.

  • Where it runs: in your browser, using the Web Speech API. Raw audio is not uploaded by us for transcription.
  • What is sent off-device: when the Mediator decides to intervene, the most recent ~30 seconds of finalized transcript text are sent inline with that single AI request to Anthropic so Claude can reference the conversation. Nothing is sent on a continuous stream — only at the moment of an intervention.
  • What is NOT stored:transcript text is never written to our database, our logs, or any cache. It exists only in your browser's memory and for the lifetime of the AI request. The Anthropic zero-data-retention agreement applies to this text too.
  • How to disable: flip the toggle off in Settings at any time. While off, the Mediator still receives the trigger signal (raised voice, face emotion) but no transcript.
  • Browser support:requires Chrome or Safari. Firefox and some mobile browsers don't support the Web Speech API; in those browsers the feature degrades silently even if the toggle is on.

9. Cookies & Local Storage

  • Strictly necessary: authentication session cookies (Supabase), CSRF protection.
  • Functional: theme preference, dismissed in-app notices.
  • Not used: third-party advertising trackers, social media pixels.

If you are in the EU or UK, you may need to provide explicit consent for non-essential cookies. You can change your choice below at any time, without signing in. You can also manage cookies directly in your browser — though disabling strictly-necessary cookies will prevent you from logging in or maintaining a session.

10. International Data Transfers

Our processors (notably Supabase, Anthropic, and Agora) operate servers in the United States. If you are located outside the US, your data will be transferred to and processed in the US under appropriate safeguards (Standard Contractual Clauses, adequacy decisions where applicable).

11. Children

Jingles is not directed to children under 18. We do not knowingly collect data from anyone under 18. If you believe a child has provided us with personal information, contact hello@jhicarus.com.

12. Security

We use industry-standard security practices: TLS encryption in transit, encryption at rest, row-level security policies on the database, server-side input validation, rate limiting, and short-lived authentication tokens. No system is perfectly secure; you assume the residual risk of using internet services.

If you discover a vulnerability, please report it responsibly to security@jhicarus.com (or hello@jhicarus.com if security@ is not yet provisioned). We commit to acknowledging reports within 5 business days.

13. Changes to This Policy

We will surface material changes in the app and via email. Continued use of the Service after the effective date constitutes acceptance.

14. Contact

Privacy questions or data requests: hello@jhicarus.com.