DeskCouncil ← Home

Privacy Policy

Jumping Ahead Inc., a Florida corporation ("Company," "we," "us") Product: DeskCouncil Version 2.1 Effective date: July 15, 2026
4281 Express Lane, Suite L7283, Sarasota, FL 34238, USA Privacy: privacy@JumpingAhead.com Legal: legal@JumpingAhead.com

The short version

DeskCouncil is local-first: your documents live and are worked on on your computer. When you ask the AI something, DeskCouncil acts as a gateway that routes your request to a third-party AI service (DigitalOcean's serverless inference). We are not the AI provider, and the zero-data-retention ("ZDR") guarantee is DigitalOcean's, not ours. When the Software shows the ZDR indicator, it routes the request only through a currently approved ZDR-eligible configuration; certain models, endpoints, and features are not ZDR-eligible and are blocked or separately disclosed (see Section 3). We do not intentionally persist your document, prompt, or AI-output content on our systems, we do not sell your personal information, and we do not use your content to train models. The information that reaches our account systems is billing and account metadata. Do not submit protected health information (PHI) (Section 9).

1. Who we are, and our role

This Privacy Policy explains how Jumping Ahead Inc., a Florida corporation ("Company," "we," "us"), handles personal information in connection with the DeskCouncil desktop software (the "Software") and website (together, the "Service").

Our role depends on the data and the mode (Section 4). In short: for account, billing, website, and consent information we are a controller; for the document/prompt content you route in Service-Fee Mode we act as a processor on your behalf, with DigitalOcean and the model vendors as sub-processors; in BYO-Key Mode the content goes directly from your device to your own provider and we provide local software. Where we act as a processor, an Article 28 Data Processing Addendum (DPA) governs that processing and is made available for execution during organizational onboarding — not merely "on request."

2. Scope

This policy covers personal information processed through the Software and website. It does not cover services you separately contract for (e.g., your own AI Provider account in BYO-Key Mode, or an external legal-research service you connect with your own credentials), which are governed by those providers' terms.

3. How the Software handles content (core design)

3.1 Local-first. Your documents are stored and worked on on your device in an encrypted local database, and sensitive credentials (such as an AI Provider key) are held in your operating system's credential facility. This on-device data is not synced to us.

3.2 What crosses the wire, by mode. To answer a request, DeskCouncil sends the content a task needs to DigitalOcean for inference.

3.3 ZDR-Eligible Processing (allowlist). When the Software displays the ZDR indicator, it routes the request only through a currently approved ZDR-eligible configuration — meaning an approved provider, model, endpoint, and region, with storage disabled, and without invoking any non-eligible feature. We maintain an allowlist (not merely a blocklist). The following are not ZDR-eligible and are blocked from ZDR Mode or separately disclosed and separately chosen: models subject to mandatory retention (for example, certain models require ~30-day retention of prompts/completions), the Files API (persistent file storage), Batch mode (Section 8), prompt caching, persistent agent memory, and provider-side traces/conversation logs. Provider legal, security, and abuse-prevention exceptions may also apply under the Provider Policies.

3.4 Fail-closed. If a ZDR-eligible route is unavailable, DeskCouncil stops the request and tells you ZDR processing is unavailable; it does not silently switch to a different model, endpoint, region, provider, or to Batch/Files/cached inference. Using any non-ZDR alternative requires your separate, affirmative choice.

3.5 The ZDR guarantee is DigitalOcean's. Zero retention is DigitalOcean's practice for eligible interactive inference, described in its data-privacy documentation (docs.digitalocean.com/products/inference/details/data-privacy); direct questions about it to DigitalOcean. We monitor material changes to that documentation and adjust the allowlist accordingly.

4. Controller / processor roles by mode

DataModeOur roleOthers
Account, authentication, billing/usage metadata, website logs, consent recordsallControllerSub-processors in Section 7
Document/prompt/AI-output contentService-FeeProcessor (on your documented instructions)You = controller; DigitalOcean + model vendors = sub-processors
Document/prompt/AI-output contentBYO-KeyLocal software only (we do not receive it)You contract directly with your AI Provider

Where we act as a processor, the DPA governs that processing, defines your and our responsibilities for data-subject requests (Section 19), and is offered for execution at organizational onboarding.

5. Personal information we process

We practice data minimization. This section describes the categories we process (it is not an exhaustive, immutable list; we update it as the Service changes). We do not process your document, prompt, or AI-output content as stored data — it is intentionally absent.

CategoryWhat it is / sourcePurposeGDPR legal basisRetention (see §15)
AccountEmail, account identifiers you provide.Create/administer your account.Contract (6(1)(b)).Life of account + 30 days, then anonymized.
Authentication & securityPassword hash, auth tokens, MFA settings, login/failed-login history, org membership, role/permissions, device/session identifiers, recovery records.Secure the account; prevent unauthorized access.Legitimate interests (6(1)(f)) in security.90 days for security logs; settings for account life.
Billing & usage metadataModel, unit/token counts, cost, service fee, timestamps, and a matter label if you assign one.Meter, bill, receipts, abuse-prevention.Contract (6(1)(b)); legal obligation for tax (6(1)(c)).7 years (tax/accounting).
Payment metadataHandled by Stripe; we receive limited data (e.g., last4, status), not full card numbers.Process top-ups.Contract; legal obligation.Per Stripe + accounting.
Consent recordsIdentifier, typed name, timestamp, IP, user-agent, document version/hash.Evidence your assent to the Terms.Legitimate interests + establishment/defense of legal claims (6(1)(f)).Legal-claims retention (§15).
Application / telemetry / licensingSoftware version, OS, update checks, license/entitlement status, feature/provider configuration, ZDR-mode status, installer/download activity.Deliver updates, licensing, support, security.Legitimate interests (6(1)(f)).Life of account; update/installer logs within 90 days.
Security & fraudIP-derived coarse location, rate-limit/abuse indicators, blocked requests, provider response status, API-request identifiers, anomalies.Prevent fraud/abuse; protect the Service.Legitimate interests (6(1)(f)).12 months.
SupportMessages you send us. Do not send client/patient/matter content through support unless we provide an expressly approved secure channel — see below.Respond to you.Legitimate interests (6(1)(f)).24 months.
Email deliveryConsent-receipt and billing emails and their delivery metadata (which reveal account existence, usage, firm affiliation).Send required transactional messages.Contract; legitimate interests.Per provider (§7).
Website logsIP, user-agent, timestamps.Operate/secure the site.Legitimate interests (6(1)(f)).90 days.

Support-channel caveat. If you nonetheless send client, patient, or matter content through an ordinary support channel, it may be processed to answer you and retained per our support retention; we ask you not to, and we do not treat ordinary support as an approved channel for confidential content.

Matter labels. A "matter label" is a free-text field and could contain sensitive information (a client or patient name, case number, condition). We recommend using a non-identifying label or code, and we are moving toward local-only matter names with a pseudonymous server billing id so that identifying labels need not reach us.

Local data created on your device (not collected by us). The Software creates local data on your device — the encrypted database, the local audit log, temporary extraction/OCR files, indexes, caches, exported reports, and encryption keys held in OS credential storage. This stays under your control; you can remove it via the Software or your operating system (Section 20).

CCPA/CPRA categories. For California residents, the above map to Identifiers, customer records / commercial information, internet/network activity, and professional information. We do not collect Social Security numbers, precise geolocation, biometric data, or your document content.

6. What we do not do

7. Sub-processors

We maintain a complete, published sub-processor list (this section) and notify of material changes before they take effect (Section 24). For each we record its role, data categories, and safeguards.

Sub-processorService it provides usData it handlesInternational-transfer safeguard
DigitalOceanAI inference gateway (routes to hosted + third-party models such as Anthropic and OpenAI, which act as DigitalOcean's downstream sub-processors)Request content in transit for inference; no persistence for ZDR-eligible routesEU SCCs (UK IDTA / Swiss addendum as applicable); no BAA — no PHI
SupabaseCloud hosting of the account database, authentication, and serverless functionsAccount, authentication, wallet, usage metadata, consent records, evidence ledger — no document contentSupabase DPA + EU SCCs (UK IDTA / Swiss addendum as applicable)
StripePayment processing for prepaid top-upsPayment metadata (Stripe handles card data)Stripe DPA + EU SCCs
Bunny.netWebsite + installer download hosting/CDNStandard web/CDN server logs (IP, user-agent)DPA + EU SCCs (UK IDTA / Swiss addendum as applicable)
ResendSends the consent-acceptance receipt emailRecipient email address + receipt content (account/consent metadata — no document content)Resend DPA + EU SCCs (UK IDTA / Swiss addendum as applicable)

Payment receipts are sent by Stripe (already listed). Authentication emails, if enabled, are sent through Supabase (already listed). We do not use third-party analytics, advertising, error-monitoring, or crash-reporting services. A current version of this list is maintained here and material changes are notified per Section 24.

8. Optional Batch mode — a non-ZDR feature (disclosure)

Any optional Batch feature is not zero-retention. The AI infrastructure provider retains batch output/error files for approximately 29–30 days and offers no early-delete, so the window cannot be shortened. Batch is off by default, decoupled from matter folders, intended for research / non-confidential data only, labeled non-ZDR, and used only after you accept a non-ZDR acknowledgment. Batch is one of several non-ZDR features (Section 3.3) — it is not "the only exception."

9. Healthcare and PHI

Do not submit PHI. The Service is not configured for HIPAA, we do not offer a Business Associate Agreement, and PHI must not be submitted through the Software. The Medical vertical and healthcare-related features are for non-PHI purposes only (e.g., de-identified research, education, general drafting) until the Company offers an approved Healthcare Mode under a signed BAA chain (customer↔us and us↔DigitalOcean and each model vendor), HIPAA-eligible models/endpoints, no Batch/Files/unapproved caching/persistent agent state, a risk analysis, and incident/breach procedures. Zero retention is not the same as HIPAA compliance. Depending on the product's data handling, the FTC Health Breach Notification Rule may also apply and is assessed separately.

10. Legal bases and how we use information (EEA/UK)

We use the data in Section 5 to provide, secure, and support the Service; meter and bill; keep consent records; prevent fraud/abuse; and comply with law. Legal bases are per the Section 5 table: contract (6(1)(b)) for processing necessary to deliver/bill the Service; legal obligation (6(1)(c)) for tax and accounting; and legitimate interests (6(1)(f)) for security, fraud-prevention, support, and limited service improvement (we maintain internal legitimate-interest assessments and honor objections). We rely on legitimate interests / establishment and defense of legal claims for consent records (not a general "legal obligation"). Where we rely on consent, you may withdraw it at any time.

11. Automated decision-making and profiling

DeskCouncil is not designed to make solely automated decisions that produce legal or similarly significant effects, and we make no such decisions about you as an account holder. Where you use the Software to help evaluate another person (a client, patient, litigant, employee, or claimant), you must provide meaningful human review and remain responsible for the notices, lawful basis, assessments, and rights owed to that individual; we assist as a processor where the DPA requires.

12. Cookies, analytics, and fonts

The DeskCouncil website uses no advertising or cross-site tracking cookies and no third-party behavioral analytics; we keep only short-lived server logs needed to operate and secure the site. "No tracking cookies" is not the same as "no tracking" — we also do not use server-to-server behavioral analytics or fingerprinting on visitors. We are moving to self-hosted web fonts so that no font request goes to a third party.

13. How we share information

We share personal information only with the sub-processors in Section 7 (under contractual confidentiality and data-protection obligations); as required by law or valid legal process, or to protect rights and safety; and in a corporate transaction (subject to this policy). We do not sell or "share" personal information for cross-context behavioral advertising.

14. International data transfers

We operate from the United States and accept users worldwide, including in the EEA, UK, and Switzerland. For transfers of personal information from those regions to a country without an adequacy decision, we rely on the EU Standard Contractual Clauses, and the UK International Data Transfer Addendum and Swiss addendum as applicable, together with supplementary measures where needed. You may request a copy of the relevant safeguards at privacy@JumpingAhead.com.

15. Data retention

We keep each category only as long as needed for the purposes in Section 5, then delete or anonymize it. Schedule:

Anonymization means we remove or irreversibly obscure identifiers (account email, firm name, free-text matter labels) so remaining records are not reasonably linkable to you; where a stable pseudonymous identifier must persist for integrity, we treat that data as pseudonymous (not anonymous) and continue to protect it. Our account-closure tooling anonymizes personal fields on closure and hard-purges after the retention window (Section 20).

16. Security

We encrypt supported local application data at rest on your device and use your operating system's credential facility for sensitive credentials; server-side systems use access controls and encryption in transit, and we do not write request/response content to logs. No system is perfectly secure. Detailed implementation (encryption specifics, key management, temporary-file and log handling, update signing) is maintained in a separate, versioned security document available for enterprise due diligence.

17. Data-breach notification

If we become aware of a personal-data breach affecting information we process, or cause our sub-processors to process, we will act without undue delay under applicable law. Specifically: as a controller under the GDPR/UK GDPR, we notify the competent supervisory authority within 72 hours where the breach is likely to result in a risk, and affected individuals without undue delay where the risk is high; as a processor, we notify the relevant controller without undue delay. Under Florida law (§ 501.171) and other US state laws, we provide notice within the required timeframes (Florida: generally within 30 days of determining a covered breach, subject to statutory qualifications; a third-party agent may have a shorter duty to notify the covered entity). HIPAA and FTC Health Breach Rule tracks apply where relevant.

18. Your privacy rights

To exercise any right, email privacy@JumpingAhead.com. We verify your request (control of the account email, plus reasonable additional verification for sensitive requests), allow an authorized agent (with proof of authority), respond within the time applicable law requires, and do not discriminate against you for exercising rights.

EEA / UK / Switzerland (GDPR / UK GDPR). Access, rectification, erasure, restriction, objection, portability, withdrawal of consent, and the right to lodge a complaint with your supervisory authority.

California (CCPA/CPRA). Where the CCPA applies to us (or where we voluntarily extend these rights): the rights to know/access, delete, correct, and to opt out of "sale"/"sharing" and to limit sensitive personal information. We do not sell or share personal information and do not use sensitive personal information in a way that triggers the right to limit. We provide a Notice at Collection at the points we collect personal information (account registration, payment, activation, support, installer download, and any optional telemetry/Batch/Healthcare activation). In the prior 12 months we collected the Section 5 categories for the Section 10 purposes and disclosed them only to the Section 7 sub-processors; we disclosed no categories for money or other valuable consideration. Shine the Light (Civ. Code § 1798.83): we do not disclose personal information to third parties for their direct marketing.

Other US states. Residents of US states with applicable comprehensive privacy laws may exercise the rights their state's law provides (typically access, correction, deletion, portability, and opt-outs of targeted advertising, sale, and certain profiling), including any appeal right — email privacy@JumpingAhead.com with "Privacy Appeal." We do not sell personal data, use it for targeted advertising, or profile you for decisions producing legal/significant effects.

Nevada. We do not sell covered information; you may still submit a request.

19. Requests about client or patient data in professional files

If you are an individual whose information appears inside a customer's document (for example, a lawyer's client or a doctor's patient), we generally process that content on the professional's behalf; the professional/practice is the controller (or covered entity), and you should direct your request to them. We cannot search or produce content we do not possess. Where the DPA/BAA requires, we assist the customer in responding. This does not deny any right you may have — it directs it to the party that holds the data.

20. Account closure and data deletion

You can close your account at any time (in-app or by emailing privacy@JumpingAhead.com). On closure we anonymize your personal data — we scrub your account email, firm name, and any free-text matter labels, and disable your login — while retaining the content-free financial, consent, and evidence metadata for the retention window in Section 15 (for tax and legal-claims purposes), after which it is hard-purged. A legal hold may suspend deletion for data relevant to a live matter. Your local, on-device data is under your control and can be removed via the Software or your operating system.

21. Your choices

You control the folders you connect, what you send to the AI, your local audit log, and (in BYO-Key Mode) your own AI Provider relationship. You can opt out of non-essential emails; transactional messages (consent receipts, billing notices) are necessary to the Service.

22. Children

Account users must be adults (18+). DeskCouncil is not directed to children and we do not knowingly create accounts for anyone under 18. Separately, individuals described in Customer Content may include minors (for example, a juvenile record or a pediatric file) where the professional is legally permitted to process that information; that content stays on the professional's device and is processed on their behalf, and we do not knowingly collect it as our own data.

23. Consent records

When you affirm the Terms and Key Acknowledgments, we record each affirmation in an append-only, tamper-evident ledger (identifier, typed name, timestamp/UTC, IP, user-agent, document version/hash), retained per Section 15. See the Terms of Service, Section 17.

24. Changes to this policy

We handle changes by type: non-material clarifications — updated effective date and ordinary notice; material prospective changes — advance email or in-app notice; new optional processing — affirmative opt-in; a materially new or incompatible use of previously collected information — a new consent or another valid legal basis; changes to contractual commitments — separate acceptance through the Terms process. We will not retroactively reduce a zero-retention or confidentiality commitment for information already processed. Continued use reflects acceptance of non-material updates only.

25. Contact

Questions or privacy requests: privacy@JumpingAhead.com · Jumping Ahead Inc., 4281 Express Lane, Suite L7283, Sarasota, FL 34238, USA · (+1) 941-531-9897. EEA/UK residents may also contact our Art. 27 representative (Section 1) and their supervisory authority.

See also our Terms of Service.