Privacy Policy
Privacy policy
Effective: August 10, 2026. Last updated: August 10, 2026.
This policy explains how Luxillum LLC, operator of Jellylink (“we”, “us”) collects, uses, and shares information when you use jellylink.com and the Jellylink application.
1. Who operates Jellylink
Jellylink is operated by Luxillum LLC, based in Seattle, Washington, United States. This policy covers the Jellylink website and product at jellylink.com.
Questions about this policy or your personal information can be sent through our Contact page or by emailing info@jellylink.com.
2. Information you provide
- Account registration: email address, password (handled by our authentication provider), and optional display name.
- Profile preferences: timezone, preferred currency, reminder email preferences, and similar settings you choose.
- Tool and account records: tools you track, account labels, login emails associated with those tools, vendors, websites, and related notes. Jellylink is not a password manager—do not store passwords, API keys, or other secrets.
- Subscription and spend data: plan names, billing models, amounts, currencies, intervals, trial and renewal dates, seats, usage allowances, budgets, and spend entries you record.
- Organization and project context: workspaces, projects, stack dependencies, ownership notes, review decisions, and related operational information.
- Payment references: nicknames, method type, issuer, and optional last-four digits you choose to store as a reference. We do not ask you to store full payment-card numbers in Jellylink records.
- Messages: name, email, topic, company (optional), and message content when you contact us.
3. Information collected automatically
- Authentication and session data needed to keep you signed in and protect account access.
- Device and browser information typically available to any web application (for example, user agent) as part of normal request handling by our hosting and authentication providers.
- IP address and security logs that infrastructure providers may process to operate, secure, and troubleshoot the service.
- Product usage signals inherent to operating the app (for example, which records you create or update). We do not currently use a separate product-analytics or session-recording vendor in the application.
Cookies and local storage used by Jellylink today are limited to essential authentication session storage, workspace selection (`jellylink-workspace-id`), and theme preference (`jellylink-theme`). Because these are essential to run the signed-in product and basic interface preferences—not advertising trackers—we do not show a nonessential cookie consent banner.
4. Information received through integrations
Depending on how you use Jellylink, information may be processed by:
- Supabase for authentication and database hosting of your account and workspace records.
- Vercel for application hosting, routing, and related request infrastructure.
- Resend for transactional email such as renewal reminders, weekly pulse emails, and contact-form delivery.
- Stripe when you purchase or manage a paid Jellylink plan. Stripe processes payment details under its own terms; we store related customer and subscription identifiers needed to manage billing.
Jellylink may also store affiliate URLs that operators configure for certain tools. Those links can send you to third-party sites; those sites have their own privacy practices.
We do not currently operate broad direct sync connectors that pull your vendor account data automatically. Catalog plan and pricing snapshots shown in Jellylink are curated reference data, not live scrapes of your third-party accounts.
5. How we use information
- Provide, maintain, and secure the Jellylink service
- Authenticate you and display the records you create
- Organize tools, accounts, projects, subscriptions, and related context
- Send service communications you request or enable, such as renewal reminders and weekly pulse emails
- Respond to support, privacy, security, and legal inquiries
- Improve reliability and functionality of the product
- Prevent abuse, fraud, and unauthorized access
- Comply with legal obligations and enforce our terms
- Process Jellylink plan billing when you subscribe
7. Sale and advertising sharing
Based on how Jellylink operates today, we do not sell personal information for money, and we do not share personal information for cross-context behavioral advertising. We do not run third-party advertising pixels or session-recording tools in the product.
Where privacy laws such as the CCPA/CPRA or GDPR may apply to you, we will honor applicable rights requests as described below. This policy does not claim that any specific privacy law automatically applies to every user.
8. Retention
We keep account and workspace records for as long as your account remains active and the records are needed to provide Jellylink. You can delete many records yourself inside the product. Contact messages are retained as needed to respond and maintain an operational record of the request. Billing records may be retained as required for accounting, disputes, and legal compliance. We do not publish fixed retention calendars for every data type beyond these operational needs.
9. Security
We use industry-standard providers and access controls to protect information. No method of transmission or storage is completely secure, and we cannot promise absolute security. Please use a strong unique password and avoid storing secrets in Jellylink fields.
10. Your choices and rights
- Access and correction: update profile and workspace records in the app, or request help via contact.
- Export: Settings includes exports for tools, projects, subscriptions, and a renewal calendar.
- Deletion: delete individual records in the product. Full account deletion is handled by request (see below)—there is not currently a fully automated self-serve account wipe.
- Marketing communications: Jellylink transactional reminders can be controlled in Settings. We do not operate a separate advertising email list in the product today. If you receive a message you did not expect, contact us to opt out of nonessential outreach.
- Jurisdiction-specific rights: where applicable, you may have rights to know, access, correct, delete, or limit certain processing. We will respond to valid requests after verifying the requester.
11. How to submit a privacy request
12. International data processing
Jellylink is operated from the United States. If you access the service from another country, your information may be processed in the United States and other locations where our providers operate. Those locations may have different data-protection rules than your home country.
13. Children’s privacy
Jellylink is intended for business and professional use by adults. It is not directed to children under 16, and we do not knowingly collect personal information from children. If you believe a child has provided personal information, contact us and we will take appropriate steps.
14. Policy changes
We may update this policy as Jellylink evolves. The effective and last-updated dates at the top of this page will change when we do. Material changes may also be communicated through the product or by email when appropriate. Continued use after an update means you accept the revised policy.
15. Contact
Luxillum LLC
Operator of Jellylink
Seattle, Washington, United States
Email: info@jellylink.com
Web: jellylink.com/contact