← Trust hub

Privacy Policy

What personal data we collect, why we collect it, and the rights you have over it.

Version 1.0Effective 4 August 2026Last updated 1 September 2026

1. Who we are

Jupiter Day is operated by Jupiter Day Limited, registered in Wales (company number 17306753), registered office Brynmine, Llanfair Clydogau, Llanbedr Pont Steffan, Wales, SA48 8LJ. We are registered with the UK Information Commissioner's Office (ICO) as a data controller. Registration reference ZC212959, registered to Jupiter Day Limited, registered 4 August 2026 and due to expire 3 August 2027. Our data protection contact is the Data Protection Officer, privacy@jupiter-day.com.

2. Controller and processor

For your own account data we are the controller. For personal data you put into your workspace about other people — your team, your contacts, your customers — you are the controller and we are your processor under our Data Processing Agreement.

3. Data we collect

Account and identity data: your name, email address, a hashed password and your workspace name. Team data: roles, assignments and invitations. Content you create: tasks, notes, comments, tags and attachments. Support and enquiries: messages you send us, including through the contact form. Anything you type to Aida, our built-in AI assistant. Collected automatically: your IP address, device and browser information, log data, and essential cookies. We do not collect payment card data.

4. How we use it, and our legal bases

Running your account and providing the service — performance of our contract with you. Managing your team, roles and invitations — contract and our legitimate interests. Sending service emails such as invitations, notifications and account notices — contract and legitimate interests. When we send you an email, our delivery provider records whether it was delivered, and whether it bounced or was reported as spam, so that we can stop sending to addresses that are not working. Security, abuse prevention and audit logging — legitimate interests and legal obligation. Providing support — legitimate interests. AI features — performance of our contract with you. Legal, accounting and tax compliance — legal obligation.

5. AI features (Aida)

AI requests are routed through the Lovable AI Gateway to Google's Gemini models. Lovable acts as our processor and Google acts as a sub-processor for AI inference. Content sent for processing can include the messages you type to Aida and the related content needed to answer them: task titles, notes, dates, team member names and email addresses, knowledge-base content and support-chat text. Aida acts only when prompted and proposes actions for your approval. We do not use your content to train our own models, and we have opted out of our AI provider using your content to train AI models.

6. Sub-processors

Lovable — application hosting, content delivery, the AI gateway, and backup delivery of sign-in emails (US/EU). Supabase, running on AWS — database, authentication and file storage (EU — Ireland). Google — Gemini AI inference (US). Mailgun — delivery of our service emails (EU). Cloudflare, via Lovable — preview images and static asset delivery (Global; no personal data). Zoho Mail — our own business mailboxes (EU). The current list is kept at jupiter-day.com/subprocessors. We do not sell your data and we do not share it for advertising.

7. International transfers

Your core account data and content are stored in the European Union (Ireland), and our email delivery provider processes in the European Union. Some providers (Lovable and Google) process data in the United States, and some of our providers are US-headquartered companies even where processing takes place in the EU. Where data leaves the UK/EEA, or where a provider is subject to US jurisdiction, we rely on the UK International Data Transfer Addendum and the EU Standard Contractual Clauses, together with the safeguards our providers have in place.

8. How long we keep it

Account data: deleted 90 days after account closure. Your content: deleted when your account is deleted. Audit and system logs: 12 months. Support conversations and contact-form messages: 24 months after last contact. Email delivery logs: 12 months. Unsubscribe and suppression records: kept for as long as needed to honour opt-outs. Billing and financial records: kept for 6 years to meet our tax and accounting obligations. Deleted data is removed from our live systems within these windows. Backups are taken daily and kept for up to 14 days before they expire, so data may remain in a backup until then. Backups are stored in the EU (Ireland), the same region as our database. We cannot restore to an arbitrary point in time — only to a daily backup point.

9. Cookies

We use essential cookies only, to keep you signed in and to keep your session secure. We do not use analytics, advertising or tracking cookies. If that changes we will update this policy and ask for your consent first.

10. Your rights

You have the right to access, correct, erase, restrict and object to the processing of your personal data, the right to data portability, and the right to withdraw consent where we rely on it. Email privacy@jupiter-day.com and we will respond within one month. Where your data sits in a workspace controlled by your employer, we may direct your request to them as the controller. You can also complain to the ICO.

11. Security

We use multi-factor authentication, database row-level security, encryption in transit and at rest, audit logging, EU hosting, and restricted access to production systems.

12. Children

Jupiter Day is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 18.

13. Changes to this policy

We may update this policy. We will notify you of material changes before they take effect.

14. Contact

Data Protection Officer, Jupiter Day Limited, privacy@jupiter-day.com, Brynmine, Llanfair Clydogau, Llanbedr Pont Steffan, Wales, SA48 8LJ. ICO registration reference ZC212959.