Data Protection Audit
Last updated 13 September 2026. This is a self-published technical disclosure, not a third-party certification — it describes, specifically, what our own code actually does with your data. Where we fall short of what you might expect, we say so rather than leave it out. See also our Privacy Policy and Terms for the legal terms this sits alongside.
We do not sell your data
There is no code path, feature, or business arrangement anywhere in Jenny that sells, licenses, or trades your data to anyone. Nothing is monetized off the back of your conversation content. The only revenue Jenny generates is your Jenny Pro subscription (via Stripe) and ads served to free-tier accounts (via Google AdSense, which does not receive your conversation content — see below).
Your chat is not sent to a third-party AI company
Jenny's model runtime is self-hosted — responses are generated by a model we run ourselves, not by sending your messages to OpenAI, Anthropic, Google, or any other external AI provider. The only third party that ever sees part of a message is Tavily, and only for the specific text of a search query, and only on the (relatively rare) messages where Jenny actually needs to look something up — see "Third parties" below.
What's actually stored
- Your email address, and your password as a bcrypt salted hash — never in plain text, never reversible
- The text of your conversations — this is unavoidable: it's how "continue this chat later" works at all
- Account metadata: tier, feedback you give on replies, timestamps, which mode you used
- For Jenny Pro accounts only: a rolling, auto-summarized memory of durable facts about you (under ~400 words), used to give Jenny context across separate conversations. This is not yet exposable or clearable by you directly through the product — see "Where we fall short" below
What's deliberately never stored
- Files you attach to a chat message (PDF, Word, text, etc.) are read entirely in memory for that one request, then discarded — only the extracted text that gets folded into your message is kept, same as anything else you type
- Photos or images you send (iOS camera/vision features) are processed for that one request and never written back into your stored message — only Jenny's text reply is kept
- Your card details — Stripe handles payment directly; we only ever store a Stripe customer/subscription ID, never a card number
- Your plaintext password, at any point, ever
Automated safety review, and what we log about it
Every reply passes through an automated safety filter before it reaches you. A small number of hard-blocked categories (e.g. content facilitating serious harm) can never be bypassed, for any account. For a narrower set of soft categories, an admin account can choose to see content that would otherwise be blocked — and every time that happens, it's written to a permanent, un-editable audit log. That log records which category was bypassed, by whom, on which conversation, and when — it does not duplicate a copy of the actual message content. Ordinary accounts are never logged this way; only bypasses on admin accounts are.
Internal access — what staff (i.e. Will) can see
The admin panel exposes account-level metadata — email, tier, admin flag, marketing preference, join date — and the safety audit log described above. It does not expose a way to browse or search anyone's conversation content. The only way conversation content is ever seen internally is the same safety-bypass mechanism described above, which is itself logged.
Third parties
- Railway — hosts our servers and database. Necessary infrastructure, not a data buyer.
- Tavily — receives the text of a search query (not your full conversation) only on messages where Jenny determines it needs to search the web for current information.
- Stripe — processes payment for Jenny Pro. We never see or store your card details.
- Google AdSense — serves ads on free-tier accounts only. It does not receive your conversation content, though it may set its own cookies and use device information to select/measure ads under Google's own policies.
Deleting your data
You can delete individual conversations yourself, at any time, from the chat sidebar — this removes the conversation and its messages immediately. Full account deletion is handled manually today rather than as a self-service button: email legal@willgraves.co.uk and we'll action it within one month, per UK GDPR.
Encryption
Traffic to Jenny is served over HTTPS at the platform (Railway) level. Our application code doesn't independently enforce TLS — we rely on Railway's edge for that, the same way most hosted web services do. Whether the underlying database is encrypted at rest is a property of Railway's managed Postgres infrastructure rather than something our own code configures; we haven't independently verified the specifics beyond Railway's own platform documentation, and say so here rather than assert a standard we can't personally attest to.
Marketing emails
Opted in by default, with a one-click unsubscribe link in every email — unsubscribing flips a per-account setting immediately and permanently excludes you from future sends, no confirmation dance required.
Where we fall short today
An honest audit names its gaps. As of this writing:
- The Jenny Pro memory summary (above) has no in-product UI yet to view or clear it directly — contact us if you want it cleared in the meantime
- Account deletion is a manual, email-initiated process rather than a self-service button
- We haven't independently audited Railway's at-rest database encryption ourselves — we rely on their platform-level guarantees
We'd rather list these plainly than have this page read as more reassuring than it is. This page will be updated as these are addressed.
Questions
If anything here doesn't match what you observe, or you want more detail on a specific claim, contact legal@willgraves.co.uk. We'd genuinely like to know.