Privacy Policy
The short version
DeskCouncil is local-first: your documents live and are worked on on your computer. When you ask the AI something, DeskCouncil acts as a gateway that routes your request to a third-party AI service (DigitalOcean's serverless inference). We are not the AI provider, and the zero-data-retention ("ZDR") guarantee is DigitalOcean's, not ours. When the Software shows the ZDR indicator, it routes the request only through a currently approved ZDR-eligible configuration; certain models, endpoints, and features are not ZDR-eligible and are blocked or separately disclosed (see Section 3). We do not intentionally persist your document, prompt, or AI-output content on our systems, we do not sell your personal information, and we do not use your content to train models. The information that reaches our account systems is billing and account metadata. Do not submit protected health information (PHI) (Section 9).
1. Who we are, and our role
This Privacy Policy explains how Jumping Ahead Inc., a Florida corporation ("Company," "we," "us"), handles personal information in connection with the DeskCouncil desktop software (the "Software") and website (together, the "Service").
Our role depends on the data and the mode (Section 4). In short: for account, billing, website, and consent information we are a controller; for the document/prompt content you route in Service-Fee Mode we act as a processor on your behalf, with DigitalOcean and the model vendors as sub-processors; in BYO-Key Mode the content goes directly from your device to your own provider and we provide local software. Where we act as a processor, an Article 28 Data Processing Addendum (DPA) governs that processing and is made available for execution during organizational onboarding — not merely "on request."
- Privacy requests / questions: privacy@JumpingAhead.com
- Postal: Jumping Ahead Inc., 4281 Express Lane, Suite L7283, Sarasota, FL 34238, USA
- EEA/UK representative (Art. 27): Because we accept users worldwide, including in the EEA and UK, we have appointed an Article 27 representative: David LeVine — contact sales@JumpingAhead.com.
2. Scope
This policy covers personal information processed through the Software and website. It does not cover services you separately contract for (e.g., your own AI Provider account in BYO-Key Mode, or an external legal-research service you connect with your own credentials), which are governed by those providers' terms.
3. How the Software handles content (core design)
3.1 Local-first. Your documents are stored and worked on on your device in an encrypted local database, and sensitive credentials (such as an AI Provider key) are held in your operating system's credential facility. This on-device data is not synced to us.
3.2 What crosses the wire, by mode. To answer a request, DeskCouncil sends the content a task needs to DigitalOcean for inference.
- BYO-Key Mode: the request travels directly from your device to the AI Provider; it does not pass through our systems.
- Service-Fee Mode: the request passes through the Company's gateway/relay in transit (so we can authenticate you, meter usage, and inject the provider credential) on its way to DigitalOcean. We transmit the content to fulfill your request; we do not intentionally persist it, and we do not write request or response content to our logs — our logs hold usage metadata only. It is therefore accurate to say we do not persist your content on our systems — not that we "never receive" it.
3.3 ZDR-Eligible Processing (allowlist). When the Software displays the ZDR indicator, it routes the request only through a currently approved ZDR-eligible configuration — meaning an approved provider, model, endpoint, and region, with storage disabled, and without invoking any non-eligible feature. We maintain an allowlist (not merely a blocklist). The following are not ZDR-eligible and are blocked from ZDR Mode or separately disclosed and separately chosen: models subject to mandatory retention (for example, certain models require ~30-day retention of prompts/completions), the Files API (persistent file storage), Batch mode (Section 8), prompt caching, persistent agent memory, and provider-side traces/conversation logs. Provider legal, security, and abuse-prevention exceptions may also apply under the Provider Policies.
3.4 Fail-closed. If a ZDR-eligible route is unavailable, DeskCouncil stops the request and tells you ZDR processing is unavailable; it does not silently switch to a different model, endpoint, region, provider, or to Batch/Files/cached inference. Using any non-ZDR alternative requires your separate, affirmative choice.
3.5 The ZDR guarantee is DigitalOcean's. Zero retention is DigitalOcean's practice for eligible interactive inference, described in its data-privacy documentation (docs.digitalocean.com/products/inference/details/data-privacy); direct questions about it to DigitalOcean. We monitor material changes to that documentation and adjust the allowlist accordingly.
4. Controller / processor roles by mode
| Data | Mode | Our role | Others |
|---|---|---|---|
| Account, authentication, billing/usage metadata, website logs, consent records | all | Controller | Sub-processors in Section 7 |
| Document/prompt/AI-output content | Service-Fee | Processor (on your documented instructions) | You = controller; DigitalOcean + model vendors = sub-processors |
| Document/prompt/AI-output content | BYO-Key | Local software only (we do not receive it) | You contract directly with your AI Provider |
Where we act as a processor, the DPA governs that processing, defines your and our responsibilities for data-subject requests (Section 19), and is offered for execution at organizational onboarding.
5. Personal information we process
We practice data minimization. This section describes the categories we process (it is not an exhaustive, immutable list; we update it as the Service changes). We do not process your document, prompt, or AI-output content as stored data — it is intentionally absent.
| Category | What it is / source | Purpose | GDPR legal basis | Retention (see §15) |
|---|---|---|---|---|
| Account | Email, account identifiers you provide. | Create/administer your account. | Contract (6(1)(b)). | Life of account + 30 days, then anonymized. |
| Authentication & security | Password hash, auth tokens, MFA settings, login/failed-login history, org membership, role/permissions, device/session identifiers, recovery records. | Secure the account; prevent unauthorized access. | Legitimate interests (6(1)(f)) in security. | 90 days for security logs; settings for account life. |
| Billing & usage metadata | Model, unit/token counts, cost, service fee, timestamps, and a matter label if you assign one. | Meter, bill, receipts, abuse-prevention. | Contract (6(1)(b)); legal obligation for tax (6(1)(c)). | 7 years (tax/accounting). |
| Payment metadata | Handled by Stripe; we receive limited data (e.g., last4, status), not full card numbers. | Process top-ups. | Contract; legal obligation. | Per Stripe + accounting. |
| Consent records | Identifier, typed name, timestamp, IP, user-agent, document version/hash. | Evidence your assent to the Terms. | Legitimate interests + establishment/defense of legal claims (6(1)(f)). | Legal-claims retention (§15). |
| Application / telemetry / licensing | Software version, OS, update checks, license/entitlement status, feature/provider configuration, ZDR-mode status, installer/download activity. | Deliver updates, licensing, support, security. | Legitimate interests (6(1)(f)). | Life of account; update/installer logs within 90 days. |
| Security & fraud | IP-derived coarse location, rate-limit/abuse indicators, blocked requests, provider response status, API-request identifiers, anomalies. | Prevent fraud/abuse; protect the Service. | Legitimate interests (6(1)(f)). | 12 months. |
| Support | Messages you send us. Do not send client/patient/matter content through support unless we provide an expressly approved secure channel — see below. | Respond to you. | Legitimate interests (6(1)(f)). | 24 months. |
| Email delivery | Consent-receipt and billing emails and their delivery metadata (which reveal account existence, usage, firm affiliation). | Send required transactional messages. | Contract; legitimate interests. | Per provider (§7). |
| Website logs | IP, user-agent, timestamps. | Operate/secure the site. | Legitimate interests (6(1)(f)). | 90 days. |
Support-channel caveat. If you nonetheless send client, patient, or matter content through an ordinary support channel, it may be processed to answer you and retained per our support retention; we ask you not to, and we do not treat ordinary support as an approved channel for confidential content.
Matter labels. A "matter label" is a free-text field and could contain sensitive information (a client or patient name, case number, condition). We recommend using a non-identifying label or code, and we are moving toward local-only matter names with a pseudonymous server billing id so that identifying labels need not reach us.
Local data created on your device (not collected by us). The Software creates local data on your device — the encrypted database, the local audit log, temporary extraction/OCR files, indexes, caches, exported reports, and encryption keys held in OS credential storage. This stays under your control; you can remove it via the Software or your operating system (Section 20).
CCPA/CPRA categories. For California residents, the above map to Identifiers, customer records / commercial information, internet/network activity, and professional information. We do not collect Social Security numbers, precise geolocation, biometric data, or your document content.
6. What we do not do
- We do not intentionally persist your document, prompt, or AI-output content on our systems, and we do not write request/response content to our logs.
- We never use your content to train, retrain, or fine-tune models.
- We never sell your personal information, and we never "share" it for cross-context behavioral advertising (CCPA/CPRA).
- We do not run third-party advertising trackers or content analytics over your documents.
7. Sub-processors
We maintain a complete, published sub-processor list (this section) and notify of material changes before they take effect (Section 24). For each we record its role, data categories, and safeguards.
| Sub-processor | Service it provides us | Data it handles | International-transfer safeguard |
|---|---|---|---|
| DigitalOcean | AI inference gateway (routes to hosted + third-party models such as Anthropic and OpenAI, which act as DigitalOcean's downstream sub-processors) | Request content in transit for inference; no persistence for ZDR-eligible routes | EU SCCs (UK IDTA / Swiss addendum as applicable); no BAA — no PHI |
| Supabase | Cloud hosting of the account database, authentication, and serverless functions | Account, authentication, wallet, usage metadata, consent records, evidence ledger — no document content | Supabase DPA + EU SCCs (UK IDTA / Swiss addendum as applicable) |
| Stripe | Payment processing for prepaid top-ups | Payment metadata (Stripe handles card data) | Stripe DPA + EU SCCs |
| Bunny.net | Website + installer download hosting/CDN | Standard web/CDN server logs (IP, user-agent) | DPA + EU SCCs (UK IDTA / Swiss addendum as applicable) |
| Resend | Sends the consent-acceptance receipt email | Recipient email address + receipt content (account/consent metadata — no document content) | Resend DPA + EU SCCs (UK IDTA / Swiss addendum as applicable) |
Payment receipts are sent by Stripe (already listed). Authentication emails, if enabled, are sent through Supabase (already listed). We do not use third-party analytics, advertising, error-monitoring, or crash-reporting services. A current version of this list is maintained here and material changes are notified per Section 24.
8. Optional Batch mode — a non-ZDR feature (disclosure)
Any optional Batch feature is not zero-retention. The AI infrastructure provider retains batch output/error files for approximately 29–30 days and offers no early-delete, so the window cannot be shortened. Batch is off by default, decoupled from matter folders, intended for research / non-confidential data only, labeled non-ZDR, and used only after you accept a non-ZDR acknowledgment. Batch is one of several non-ZDR features (Section 3.3) — it is not "the only exception."
9. Healthcare and PHI
Do not submit PHI. The Service is not configured for HIPAA, we do not offer a Business Associate Agreement, and PHI must not be submitted through the Software. The Medical vertical and healthcare-related features are for non-PHI purposes only (e.g., de-identified research, education, general drafting) until the Company offers an approved Healthcare Mode under a signed BAA chain (customer↔us and us↔DigitalOcean and each model vendor), HIPAA-eligible models/endpoints, no Batch/Files/unapproved caching/persistent agent state, a risk analysis, and incident/breach procedures. Zero retention is not the same as HIPAA compliance. Depending on the product's data handling, the FTC Health Breach Notification Rule may also apply and is assessed separately.
10. Legal bases and how we use information (EEA/UK)
We use the data in Section 5 to provide, secure, and support the Service; meter and bill; keep consent records; prevent fraud/abuse; and comply with law. Legal bases are per the Section 5 table: contract (6(1)(b)) for processing necessary to deliver/bill the Service; legal obligation (6(1)(c)) for tax and accounting; and legitimate interests (6(1)(f)) for security, fraud-prevention, support, and limited service improvement (we maintain internal legitimate-interest assessments and honor objections). We rely on legitimate interests / establishment and defense of legal claims for consent records (not a general "legal obligation"). Where we rely on consent, you may withdraw it at any time.
11. Automated decision-making and profiling
DeskCouncil is not designed to make solely automated decisions that produce legal or similarly significant effects, and we make no such decisions about you as an account holder. Where you use the Software to help evaluate another person (a client, patient, litigant, employee, or claimant), you must provide meaningful human review and remain responsible for the notices, lawful basis, assessments, and rights owed to that individual; we assist as a processor where the DPA requires.
12. Cookies, analytics, and fonts
The DeskCouncil website uses no advertising or cross-site tracking cookies and no third-party behavioral analytics; we keep only short-lived server logs needed to operate and secure the site. "No tracking cookies" is not the same as "no tracking" — we also do not use server-to-server behavioral analytics or fingerprinting on visitors. We are moving to self-hosted web fonts so that no font request goes to a third party.
13. How we share information
We share personal information only with the sub-processors in Section 7 (under contractual confidentiality and data-protection obligations); as required by law or valid legal process, or to protect rights and safety; and in a corporate transaction (subject to this policy). We do not sell or "share" personal information for cross-context behavioral advertising.
14. International data transfers
We operate from the United States and accept users worldwide, including in the EEA, UK, and Switzerland. For transfers of personal information from those regions to a country without an adequacy decision, we rely on the EU Standard Contractual Clauses, and the UK International Data Transfer Addendum and Swiss addendum as applicable, together with supplementary measures where needed. You may request a copy of the relevant safeguards at privacy@JumpingAhead.com.
15. Data retention
We keep each category only as long as needed for the purposes in Section 5, then delete or anonymize it. Schedule:
- Active-account data — life of account; closed-account data — anonymized within 30 days of closure (Section 20), with content-free financial/consent/evidence metadata retained per below.
- Billing / tax / payment metadata — 7 years.
- Consent records — a defined legal-claims retention period (covering the 2-year contractual limitation plus tolling, arbitration, regulatory inquiry, chargeback, and "which version applied" questions); 4 years after the applicable Terms version ceases to apply, subject to legal hold.
- Authentication / security / server logs — 90 days. Fraud/abuse and rate-limit records — 12 months.
- Support tickets — 24 months. Email delivery logs — per provider (§7).
- Request-evidence ledger (content-free) — legal-claims retention (4 years), then purged.
- Backups — rolling 30 days. Legal holds suspend deletion for affected data.
Anonymization means we remove or irreversibly obscure identifiers (account email, firm name, free-text matter labels) so remaining records are not reasonably linkable to you; where a stable pseudonymous identifier must persist for integrity, we treat that data as pseudonymous (not anonymous) and continue to protect it. Our account-closure tooling anonymizes personal fields on closure and hard-purges after the retention window (Section 20).
16. Security
We encrypt supported local application data at rest on your device and use your operating system's credential facility for sensitive credentials; server-side systems use access controls and encryption in transit, and we do not write request/response content to logs. No system is perfectly secure. Detailed implementation (encryption specifics, key management, temporary-file and log handling, update signing) is maintained in a separate, versioned security document available for enterprise due diligence.
17. Data-breach notification
If we become aware of a personal-data breach affecting information we process, or cause our sub-processors to process, we will act without undue delay under applicable law. Specifically: as a controller under the GDPR/UK GDPR, we notify the competent supervisory authority within 72 hours where the breach is likely to result in a risk, and affected individuals without undue delay where the risk is high; as a processor, we notify the relevant controller without undue delay. Under Florida law (§ 501.171) and other US state laws, we provide notice within the required timeframes (Florida: generally within 30 days of determining a covered breach, subject to statutory qualifications; a third-party agent may have a shorter duty to notify the covered entity). HIPAA and FTC Health Breach Rule tracks apply where relevant.
18. Your privacy rights
To exercise any right, email privacy@JumpingAhead.com. We verify your request (control of the account email, plus reasonable additional verification for sensitive requests), allow an authorized agent (with proof of authority), respond within the time applicable law requires, and do not discriminate against you for exercising rights.
EEA / UK / Switzerland (GDPR / UK GDPR). Access, rectification, erasure, restriction, objection, portability, withdrawal of consent, and the right to lodge a complaint with your supervisory authority.
California (CCPA/CPRA). Where the CCPA applies to us (or where we voluntarily extend these rights): the rights to know/access, delete, correct, and to opt out of "sale"/"sharing" and to limit sensitive personal information. We do not sell or share personal information and do not use sensitive personal information in a way that triggers the right to limit. We provide a Notice at Collection at the points we collect personal information (account registration, payment, activation, support, installer download, and any optional telemetry/Batch/Healthcare activation). In the prior 12 months we collected the Section 5 categories for the Section 10 purposes and disclosed them only to the Section 7 sub-processors; we disclosed no categories for money or other valuable consideration. Shine the Light (Civ. Code § 1798.83): we do not disclose personal information to third parties for their direct marketing.
Other US states. Residents of US states with applicable comprehensive privacy laws may exercise the rights their state's law provides (typically access, correction, deletion, portability, and opt-outs of targeted advertising, sale, and certain profiling), including any appeal right — email privacy@JumpingAhead.com with "Privacy Appeal." We do not sell personal data, use it for targeted advertising, or profile you for decisions producing legal/significant effects.
Nevada. We do not sell covered information; you may still submit a request.
19. Requests about client or patient data in professional files
If you are an individual whose information appears inside a customer's document (for example, a lawyer's client or a doctor's patient), we generally process that content on the professional's behalf; the professional/practice is the controller (or covered entity), and you should direct your request to them. We cannot search or produce content we do not possess. Where the DPA/BAA requires, we assist the customer in responding. This does not deny any right you may have — it directs it to the party that holds the data.
20. Account closure and data deletion
You can close your account at any time (in-app or by emailing privacy@JumpingAhead.com). On closure we anonymize your personal data — we scrub your account email, firm name, and any free-text matter labels, and disable your login — while retaining the content-free financial, consent, and evidence metadata for the retention window in Section 15 (for tax and legal-claims purposes), after which it is hard-purged. A legal hold may suspend deletion for data relevant to a live matter. Your local, on-device data is under your control and can be removed via the Software or your operating system.
21. Your choices
You control the folders you connect, what you send to the AI, your local audit log, and (in BYO-Key Mode) your own AI Provider relationship. You can opt out of non-essential emails; transactional messages (consent receipts, billing notices) are necessary to the Service.
22. Children
Account users must be adults (18+). DeskCouncil is not directed to children and we do not knowingly create accounts for anyone under 18. Separately, individuals described in Customer Content may include minors (for example, a juvenile record or a pediatric file) where the professional is legally permitted to process that information; that content stays on the professional's device and is processed on their behalf, and we do not knowingly collect it as our own data.
23. Consent records
When you affirm the Terms and Key Acknowledgments, we record each affirmation in an append-only, tamper-evident ledger (identifier, typed name, timestamp/UTC, IP, user-agent, document version/hash), retained per Section 15. See the Terms of Service, Section 17.
24. Changes to this policy
We handle changes by type: non-material clarifications — updated effective date and ordinary notice; material prospective changes — advance email or in-app notice; new optional processing — affirmative opt-in; a materially new or incompatible use of previously collected information — a new consent or another valid legal basis; changes to contractual commitments — separate acceptance through the Terms process. We will not retroactively reduce a zero-retention or confidentiality commitment for information already processed. Continued use reflects acceptance of non-material updates only.
25. Contact
Questions or privacy requests: privacy@JumpingAhead.com · Jumping Ahead Inc., 4281 Express Lane, Suite L7283, Sarasota, FL 34238, USA · (+1) 941-531-9897. EEA/UK residents may also contact our Art. 27 representative (Section 1) and their supervisory authority.
See also our Terms of Service.