Privacy Policy

Privacy policy

Effective: August 10, 2026. Last updated: August 20, 2026.

Jellylink is operated by Peachity LLC.

In this policy, “Jellylink,” “we,” “us,” and “our” refer to the Jellylink service operated by Peachity LLC.

This policy explains how we collect, use, and share information when you use jellylink.com and the Jellylink application.

1. Who operates Jellylink

This policy covers the Jellylink website and product at jellylink.com, operated from Seattle, Washington, United States.

Questions about this policy or your personal information can be sent through our Contact page or by emailing info@jellylink.com.

2. Information you provide

Ordinary workspace records. You may enter tools, login-account references, subscription details, renewals, spend, budgets, notes, projects, and related context. Jellylink is not a password manager — do not place passwords, recovery codes, or raw API secrets into ordinary tool, account, or note fields.

  • Account registration: email address, password (handled by our authentication provider), and optional display name.
  • Profile preferences: timezone, preferred currency, reminder email preferences, and similar settings.
  • Workspace records: tools, accounts, subscriptions, projects, stack dependencies, ownership notes, and spend you record.
  • Payment references: nicknames, method type, issuer, and optional last-four digits you choose to store as a reference. We do not ask you to store full payment-card numbers in Jellylink records.
  • Imports and uploads: CSV, receipts, PDFs, or pasted invoice text you submit for Smart Import review.
  • Messages: name, email, topic, company (optional), and message content when you contact us.

Dedicated connection credentials. When you intentionally connect a provider, Jellylink may securely receive and store OAuth access or refresh tokens, API or admin keys, and related provider identifiers needed to operate that connection. These credentials are separate from ordinary workspace fields and are handled as described in Security and Retention below.

3. Information collected automatically

  • Authentication and session data needed to keep you signed in and protect account access.
  • Device and browser information typically available to web applications (for example, user agent) as part of normal request handling.
  • IP address and security logs that infrastructure providers may process to operate, secure, and troubleshoot the service.
  • Product usage signals inherent to operating the app (for example, which records you create or update, and privacy-safe Discover events such as public goal or catalog tool selections). Discover analytics do not include email addresses, private project names, or subscription details.
  • Public website analytics: Jellylink uses Google Analytics to understand how visitors find and use our public website, such as pages viewed, referral source, device and browser information, and interactions with public product and Discover pages. We do not send private workspace records, account credentials, API keys, AI prompts, or other sensitive workspace content to Google Analytics. Advertising personalization is not enabled.

Cookies and local storage used by Jellylink include essential authentication session storage, workspace selection, theme preference, the last selected Discover project, a short-lived Discover signup handoff containing only validated public catalog identifiers, and analytics cookies or storage that Google Analytics may set on public pages. Essential product cookies support signed-in operation and basic interface preferences. We do not currently use a session-recording vendor.

4. Connected services you authorize

Jellylink connects a third-party provider only when you explicitly authorize or supply the required credential. Depending on provider and your permissions, Jellylink may receive:

  • Repository, project, workspace, or resource names and identifiers
  • Organization or team metadata
  • Usage metrics, request counts, token counts, and model identifiers
  • Provider-reported costs and billing-related metadata
  • Dates, time buckets, and mapping metadata needed for reporting

Jellylink limits its provider calls to the supported connection and reporting purposes implemented for each provider. Not every provider supplies every field.

Provider-specific boundaries:

  • GitHub: repository metadata (names, visibility, archived state). Jellylink does not read repository source code or file contents.
  • Supabase: project and organization metadata and supported reporting endpoints — not database row or table contents through the connection.
  • Vercel: project and deployment metadata and supported usage or billing metadata where enabled. A separate Vercel AI Gateway connection reports usage for traffic routed through the Gateway.
  • OpenAI API: organization projects, usage metrics, models, tokens, requests, and provider-reported API costs. This does not give Jellylink access to ChatGPT conversation history or consumer subscription billing.
  • Anthropic API: supported organization or workspace usage, costs, and optional aggregate analytics where your account supports them — not prompt or response content through usage reporting.
  • Vercel AI Gateway: usage, model, provider, and cost metadata for Gateway-routed requests — not prompt or response storage through the reporting connector.
  • Cursor Teams: supported team usage metadata at the granularity exposed by the Admin API — not source code or prompt retrieval.

Affiliate URLs configured for certain catalog tools may send you to third-party sites with their own privacy practices. See our Affiliate Disclosure.

5. Service providers Jellylink uses

These companies process information on Jellylink’s behalf to operate the product. They are distinct from providers you choose to connect:

  • Supabase — authentication, database hosting, and storage for account and workspace records.
  • Vercel — application hosting, routing, and related request infrastructure.
  • Stripe — payment processing when you purchase or manage a paid Jellylink plan. Stripe processes payment details under its own terms; we store related customer and subscription identifiers.
  • Resend — transactional email such as renewal reminders, weekly pulse emails, and contact-form delivery.
  • OpenAI — model processing for Ask Jelly, Smart Import, and optional weekly brief wording when you use those features.
  • Google Analytics — aggregate measurement of public website traffic and interactions on jellylink.com. Google processes this data under its own terms as our analytics provider.

6. How Jellylink uses information

  • Provide, maintain, and secure the Jellylink service
  • Authenticate you and display the records you create
  • Organize tools, accounts, projects, subscriptions, and connected resources
  • Sync and display supported Connected Stack and AI usage data you authorize
  • Send service communications you request or enable, such as renewal reminders and weekly pulse emails
  • Power Ask Jelly, Smart Import, and optional automated summaries from your workspace records (with confirmation before writes where applicable)
  • Respond to support, privacy, security, and legal inquiries
  • Improve reliability and functionality of the product
  • Prevent abuse, fraud, and unauthorized access
  • Comply with legal obligations and enforce our terms
  • Process Jellylink plan billing when you subscribe

7. How information is shared

  • Infrastructure providers listed above, as needed to operate Jellylink.
  • Connected providers only when you authorize a connection and Jellylink calls their APIs on your behalf.
  • Workspace members you invite, according to the roles and access you grant.
  • Legal and safety disclosures when required by law, valid legal process, or to protect rights, security, and integrity.
  • Business transfers if we are involved in a merger, acquisition, financing, or sale of assets, subject to appropriate confidentiality and notice where required.
  • Affiliate partners only in the limited sense that clicking a paid or affiliate link may communicate referral information to the partner or platform as part of ordinary referral tracking. Jellylink does not sell your workspace data to affiliate partners. See our Affiliate Disclosure.

8. Sale and advertising sharing

Based on how Jellylink operates today, we do not sell personal information for money, and we do not use personal information for cross-context behavioral advertising. We do not run third-party advertising pixels or session-recording tools in the product.

Depending on where you live, applicable law may give you rights to access, correct, delete, or restrict certain uses of personal information. This policy does not claim that any specific privacy law automatically applies to every user.

9. AI processing

Connected AI usage. Provider connections retrieve usage and cost metadata reported by the provider. This does not require Jellylink to store your prompt or response content from those providers.

Ask Jelly. When you ask a question, Jellylink may send your question, relevant Help excerpts, and relevant workspace facts to the configured model provider to generate an answer. Ask Jelly requests use OpenAI’s API with training opt-out controls where available (store: false). OpenAI’s own retention terms may still apply to abuse monitoring or similar processing — Jellylink does not control third-party retention policies.

Smart Import. When you upload or paste import content, Jellylink may send that content to a model provider to propose vendor, plan, and amount fields for your review. Nothing is written to your stack until you confirm a proposal.

10. Retention and disconnection

We keep account and workspace records for as long as your account remains active and the records are needed to provide Jellylink. You can delete many records yourself inside the product.

Disconnecting a provider: stored connection credentials are deleted and future syncs stop. By default, the connection row may remain marked disconnected and historical snapshots, discovered resources, and usage history may be retained. A full history delete option may be available in some flows.

Contact messages are retained as needed to respond and maintain an operational record. Billing records may be retained as required for accounting, disputes, and legal compliance.

11. Security

Jellylink uses technical and organizational safeguards, including encrypted provider credentials, workspace access controls, and server-side provider requests. No method of transmission or storage is completely secure, and we cannot promise absolute security. Please use a strong unique password and avoid placing secrets in ordinary Jellylink fields.

12. Your choices and rights

  • Access and correction: update profile and workspace records in the app.
  • Export: Settings includes CSV exports for tools, projects, and subscriptions, plus a renewal calendar (ICS). Exports cover supported workspace records — not necessarily every personal-data field Jellylink holds.
  • Deletion: delete individual records in the product, or permanently delete your account under Settings → Account & security → Delete account.
  • Marketing communications: Jellylink transactional reminders can be controlled in Settings. We do not operate a separate advertising email list in the product today.

13. Account deletion and access requests

If you cannot access your account or need help beyond available exports, use Contact with topic “General question” (note that it is a privacy or access request) or email info@jellylink.com. We may verify that you control the account before fulfilling a formal request.

14. International data processing

Jellylink is operated from the United States. If you access the service from another country, your information may be processed in the United States and other locations where our providers operate. Those locations may have different data-protection rules than your home country.

15. Children’s privacy

Jellylink is intended for business and professional use by adults. It is not directed to children under 16, and we do not knowingly collect personal information from children. If you believe a child has provided personal information, contact us and we will take appropriate steps.

16. Policy changes

We may update this policy as Jellylink evolves. The effective and last-updated dates at the top of this page will change when we do. Material changes may also be communicated through the product or by email when appropriate. Continued use after an update means you accept the revised policy.

17. Contact

Peachity LLC
Jellylink
Seattle, Washington, United States
Email: info@jellylink.com
Web: jellylink.com/contact