Privacy Policy
Last updated: 9 October 2026
What personal data Jralo collects, why, who else processes it, how long it is kept, and how to use your rights wherever you live.
1. Who is responsible
Misimi Corp, GNB Road, Guwahati, Assam 781007, India, operates Jralo and decides how the personal data described here is used. That makes it the "controller" under the EU, UK and Swiss data protection laws and Brazil's LGPD, the "Data Fiduciary" under India's Digital Personal Data Protection Act, 2023, and the responsible organisation under the laws of Canada, Australia and Japan. For personal data inside a customer's own website or code, which we handle only to provide the Service, we act on the customer's behalf under the Data Processing Addendum. Contact for anything in this policy: support@jralo.com.
2. Data we collect
| Category | What it is | Where it comes from |
|---|---|---|
| Account data | Your name and email address, and a user id | You, through our sign-in provider, Clerk |
| Billing data | Your plan, subscription status, purchases of fix cycles and the country of purchase. We never receive your card details. | Creem, our Merchant of Record |
| Site and check data | The addresses of sites you add, the results of each check (problems found, the page elements involved, short code snippets), and the dated record of those checks | The public web pages you ask us to check |
| GitHub data | Which repository you chose for a site and the GitHub App installation that lets us open pull requests. During a fix, the code of that repository. | You and GitHub |
| Shopify shop data | If you install the Jralo app in Shopify: your shop's myshopify.com address and primary domain, an access token for the app's own use (stored encrypted), and the ids and status of the app charges you approved. The app asks Shopify for no access to your products, orders or customers, and we hold no data about your shop's customers. | Shopify, when you install the app |
| Early-access list | The email address you gave to join it | You |
| Technical data | IP address, browser type and request logs, used to run and protect the Service | Your use of the Service |
| Messages | Emails you send us | You |
Public pages we check may happen to contain personal data about other people. We process it only to produce your results.
3. Why we use it, and our legal bases
- To provide the Service you asked for (performance of a contract): your account, checks, the evidence record, Website Mechanic, billing status.
- To keep the Service secure, prevent misuse and enforce our policies (our legitimate interests): request logs, limits on use.
- To meet legal, tax and accounting duties (legal obligation).
- To email you about the product (your consent, which you can withdraw at any time).
Where a law works on consent rather than these bases, such as India's DPDP Act, we process your data for the purposes stated here on your consent, given when you sign up, or for the legitimate uses that law allows.
4. What we never do
We do not sell personal data. We do not use your data or your results for advertising. We never share check results with law firms or anyone else, other than the providers in section 6 acting on our instructions.
5. Artificial intelligence
Website Mechanic sends the code of the repository you chose, and the problems your latest check found, to Anthropic so that it can write the fixes. We do not keep your code after the job finishes.
6. Who else processes your data
| Provider | What it does for us |
|---|---|
| Cloudflare | Hosting, the database, page checks and security |
| Clerk | Sign-up and sign-in |
| Creem | Payments, invoices and tax, as Merchant of Record |
| Shopify | For shops that install the Jralo app: installation, sign-in through Shopify admin, and billing on the shop's Shopify bill |
| Anthropic | The AI that writes Website Mechanic fixes |
| GitHub | Reading the repository you chose and opening pull requests |
We will update this list before adding or replacing a provider. We also disclose data where the law requires it.
7. Transfers between countries
We are based in India and our providers process data in the United States and other countries. When personal data leaves the country it was collected in, we rely on:
- EU and EEA: the European Commission's Standard Contractual Clauses, and adequacy decisions where one applies.
- United Kingdom: the UK International Data Transfer Addendum to those clauses.
- Switzerland: the same clauses, with the changes required by the Swiss Federal Act on Data Protection.
- Brazil: the transfer mechanisms in Article 33 of the LGPD, including standard contractual clauses.
- Canada, Australia and Japan: contracts that require each provider to protect the data to the standard those countries' laws expect, and, where the law asks for it, your consent.
- India: transfers allowed under the DPDP Act, which permits them except to countries the Government of India restricts.
8. How long we keep it
- Checks run without an account: deleted after 7 days.
- Account data, sites, checks and the evidence record: kept until you delete them. Deleting a site removes its checks and its record. Deleting your account from the dashboard removes your sites, every check saved for you and any unused fix cycles.
- Shops that installed the Jralo app in Shopify: when you uninstall, your plan ends and your public record is taken down at once. Shopify asks us to erase the shop's data 48 hours later, and we then erase all of it: the shop record, its site, its checks and its evidence record. Requests about a shop's customers are answered too, although we hold no customer data.
- Code read by Website Mechanic: not kept by us after the job finishes.
- Billing records: kept by Creem for as long as tax law requires.
9. Your rights
Wherever you live, you can ask us for a copy of your personal data, ask us to correct or delete it, and withdraw any consent you gave. You can delete your account and everything in it yourself from the dashboard. For anything else, email support@jralo.com from your account address; we answer within 30 days and do not charge for it. You also have these rights under your local law:
| Where you live | Your rights | Where you can complain |
|---|---|---|
| EU and EEA (GDPR) | Access, correction, deletion, restriction, objection, portability, withdrawing consent | Your national data protection authority |
| United Kingdom (UK GDPR) | The same rights as in the EU | The Information Commissioner's Office |
| Switzerland (FADP) | Access, correction, deletion, objection, portability | The Federal Data Protection and Information Commissioner |
| Canada (PIPEDA) | Access, correction, withdrawing consent, challenging how we comply | The Office of the Privacy Commissioner of Canada |
| Brazil (LGPD) | Confirmation, access, correction, anonymisation, deletion, portability, information about sharing, withdrawing consent | The Autoridade Nacional de Proteção de Dados |
| India (DPDP Act) | Access to a summary, correction, erasure, grievance redressal, nominating another person to act for you | First to us at the address above, then the Data Protection Board of India |
| Australia (Privacy Act) | Access and correction | The Office of the Australian Information Commissioner |
| Japan (APPI) | Disclosure, correction, stopping use, deletion | The Personal Information Protection Commission |
If you live somewhere not listed, the first paragraph of this section still applies to you.
10. Security
Data is encrypted in transit. GitHub credentials are encrypted with a key held separately from the database. Access to the systems that hold data is limited to the people who need it. If a personal data breach affects you, we will tell you and the relevant authorities as the law requires.
11. Cookies
We use only the cookies needed to sign you in and keep the Service secure. We use no advertising or analytics cookies. The badge and the public record pages set no cookies.
12. Children
The Service is for businesses and is not directed to anyone under 18.
13. Changes
We will post updates here and email you about material changes.