Privacy Policy
Effective Date: April 22, 2026
Last Updated: April 22, 2026
RWX-TEK INC ("we," "us," "our") operates Jettson.ai ("Service"). This Privacy Policy explains how we collect, use, store, share, and protect your personal information, and describes your rights under applicable privacy laws worldwide.
By using Jettson, you acknowledge this Privacy Policy and our data practices described herein.
1. Who We Are and How to Contact Us
RWX-TEK INC
8605 Santa Monica Blvd #664055
West Hollywood, CA 90069
United States
Privacy contact: privacy@jettson.ai (or customertek@rwxtek.com)
For EU/EEA users, RWX-TEK INC is the data controller for personal data processed through Jettson.
2. Information We Collect
2.1 Information You Provide Directly
- Account Information: Name, email address, password (hashed — never stored in plaintext)
- Profile Information: Optional details including company name, role, and preferences
- Payment Information: Billing name, address, and payment method (card details processed and stored by Stripe; we do not store full card numbers or CVV)
- Content: Chat messages, uploaded files, AI prompts, CRM contacts, and other content you submit
- Communications: Support inquiries, feedback, and email correspondence
2.2 Information We Collect Automatically
- Usage Data: Features used, pages visited, clicks, session duration, and interaction patterns
- Device and Technical Data: IP address, browser type and version, operating system, device type, screen resolution, and language settings
- Log Data: Server logs including timestamps, API endpoints accessed, response codes, and error logs (retained for 90 days)
- Authentication Events: Login timestamps, logout events, failed authentication attempts
2.3 Information from Third Parties
- OAuth Providers: If you connect Google, Microsoft, or Apple accounts, we receive your name, email, and access tokens (encrypted at rest using AES-256-GCM)
- Stripe: Transaction status and payment metadata
- Apollo.io: Lead and company enrichment data for Studio CRM features
- Telegram: User ID and message content for Telegram integration users
- Sentry: Crash reports and error data
3. How We Use Your Information
We use your personal information to:
| Purpose | Legal Basis (GDPR) |
|---|---|
| Provide and operate the Service | Contract performance |
| Process payments and subscriptions | Contract performance |
| Authenticate and secure accounts | Legitimate interests / Contract |
| Enforce AI token limits and quotas | Contract performance |
| Monitor for abuse and security threats | Legitimate interests |
| Send transactional communications (receipts, security alerts) | Contract performance |
| Send marketing communications (with opt-out) | Consent |
| Improve and develop the Service | Legitimate interests |
| Comply with legal obligations | Legal obligation |
| Resolve disputes and enforce Terms | Legitimate interests / Legal obligation |
We do not use your personal data to train AI models without your explicit consent.
4. AI-Specific Data Processing
4.1 Chat and Prompt Data
When you use Jettson's AI features:
- Your messages are transmitted to third-party AI providers (Anthropic, OpenAI) for inference
- These providers process your prompts under their own terms; see Anthropic's Privacy Policy and OpenAI's Privacy Policy
- We do not sell your prompt data to third parties
- Chat history is stored in Firebase and retained for 90 days unless you delete it earlier
4.2 AI Provider Data Practices
Third-party AI providers may retain prompts subject to their own data retention and zero-data-retention policies. We recommend reviewing their policies before submitting sensitive information.
4.3 Automated Decision-Making
Jettson uses automated systems to enforce usage limits, detect abuse, and process subscription changes. These decisions are based on objective criteria (usage counts, fraud signals) and are not based on profiling for discriminatory purposes. You may contact us to request human review of an automated decision that materially affects you.
4.4 No Sensitive Data in AI Prompts
You should not submit sensitive personal data — including government IDs, financial account numbers, medical records, biometric data, or children's data — into AI chat features. We are not responsible for sensitive data you voluntarily submit to AI models.
5. Data Sharing and Disclosure
5.1 Service Providers (Data Processors)
We share data with trusted service providers who process data on our behalf. The complete list is published at jettson.ai/subprocessors.
| Provider | Purpose | Location |
|---|---|---|
| Vercel | Web hosting, edge runtime, CDN | USA / Global |
| Firebase (Google Cloud) | Authentication, database, file storage | USA |
| Cloudflare | DDoS protection, WAF, bot mitigation | USA / Global |
| Railway | Gateway runtime hosting | USA |
| Anthropic | Claude AI model inference | USA |
| OpenAI | GPT and embeddings inference | USA |
| Google (Gemini) | Gemini AI model inference | USA |
| Apple | Sign in with Apple authentication | USA |
| Stripe | Payment processing | USA |
| Resend | Transactional email delivery | USA |
| Telegram | Telegram bot integration (opt-in) | Global |
| Sentry | Error monitoring | USA |
| Apollo.io | Lead and company data enrichment | USA |
All service providers are bound by data processing agreements requiring them to protect your data and use it only for the purposes we specify.
5.2 Business Transfers
If RWX-TEK INC is involved in a merger, acquisition, asset sale, or bankruptcy, your data may be transferred to the successor entity. We will provide notice before your data becomes subject to a different privacy policy.
5.3 Legal Requirements
We may disclose personal data when required by law, court order, subpoena, regulatory authority, or to:
- Comply with applicable legal obligations
- Protect the rights, property, or safety of RWX-TEK INC, our users, or the public
- Detect, investigate, or prevent fraud, abuse, or security threats
- Enforce our Terms of Service
We will notify you of legal demands for your data where legally permitted to do so.
5.4 No Sale of Personal Data
We do not sell, rent, or trade your personal information to third parties for their marketing purposes. This applies to California residents under CCPA/CPRA and broadly to all users.
6. Data Retention
| Data Category | Retention Period |
|---|---|
| Account and profile data | While account is active + 30 days after deletion |
| Chat messages and AI prompts | 90 days (or until you delete) |
| OAuth tokens (Google, Microsoft) | Until you disconnect the integration or delete your account |
| Payment records | 7 years (tax and legal compliance) |
| Security and audit logs | 90 days |
| Backup data | Up to 30 days after deletion |
| Legal hold data | Duration of legal proceeding |
You may delete your account at any time via account settings or by contacting us. Upon deletion, we will remove your personal data within 30 days, except where retention is required by law.
7. Data Security
7.1 Security Measures
We implement industry-standard security measures including:
- Encryption in transit: TLS 1.2+ for all data transmission
- Encryption at rest: AES-256-GCM for stored OAuth tokens and sensitive credentials
- Authentication: Firebase Admin SDK with cryptographically verified tokens
- Access controls: Role-based access, principle of least privilege
- Rate limiting: Protection against brute force and automated attacks
- Security monitoring: Real-time error tracking and anomaly detection via Sentry
7.2 No Absolute Guarantee
No security system is impenetrable. We cannot guarantee absolute security of your data. You use the Service at your own risk. You are responsible for keeping your login credentials secure.
7.3 Security Incidents
In the event of a data breach affecting your personal data, we will:
- Notify affected users within 72 hours of becoming aware of the breach (to the extent required by applicable law)
- Notify relevant authorities as required by GDPR (Article 33), CCPA, and other applicable law
- Provide information about the nature of the breach, data affected, and steps taken
Report security vulnerabilities to: customertek@rwxtek.com
8. Cookies and Tracking
We use cookies and similar technologies as described in our Cookie Policy at jettson.ai/cookies. Essential cookies are required for the Service to function. Non-essential analytics and marketing cookies require your consent.
9. Your Rights — All Users
All users have the following rights regarding their personal data:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate or incomplete data
- Deletion: Request deletion of your personal data (subject to legal retention obligations)
- Data Portability: Receive your data in a machine-readable format
- Opt-Out of Marketing: Unsubscribe from marketing communications at any time via the unsubscribe link in emails or by contacting us
To exercise these rights, contact customertek@rwxtek.com. We will respond within 30 days. We may verify your identity before processing requests.
10. California Residents — CCPA/CPRA Rights
If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) grant you additional rights:
10.1 Categories of Personal Information Collected
We collect the following categories of personal information as defined by CCPA:
- Identifiers (name, email, IP address)
- Commercial information (subscription and payment records)
- Internet/electronic activity (usage logs, click data)
- Geolocation data (derived from IP address, coarse)
- Inferences drawn from the above (feature preferences)
We do not collect biometric information, precise geolocation, or sensitive personal information beyond what is necessary to provide the Service.
10.2 Sources
Information is collected directly from you, automatically through your use of the Service, and from third-party service providers listed in Section 5.1.
10.3 Purposes
See Section 3. We do not use personal information for purposes incompatible with those disclosed.
10.4 Right to Know
You may request disclosure of: categories of personal information collected; sources; purposes; categories of third parties with whom we share data; and specific pieces of information collected about you.
10.5 Right to Delete
You may request deletion of your personal information, subject to exceptions (legal obligations, fraud prevention, security).
10.6 Right to Correct
You may request correction of inaccurate personal information.
10.7 Right to Opt-Out of Sale / Sharing
We do not sell or share personal information for cross-context behavioral advertising. If this changes, we will provide a "Do Not Sell or Share My Personal Information" link.
10.8 Right to Limit Use of Sensitive Personal Information
We do not use sensitive personal information beyond what is necessary to provide the Service.
10.9 Right to Non-Discrimination
We will not discriminate against you for exercising CCPA/CPRA rights.
10.10 Shine the Light
California Civil Code § 1798.83 allows California residents to request information about data shared with third parties for their direct marketing. We do not share data for third-party direct marketing.
To exercise CCPA/CPRA rights: Email customertek@rwxtek.com with subject "California Privacy Rights." We will respond within 45 days, with a 45-day extension where necessary.
11. European Union and EEA Residents — GDPR Rights
If you are in the EU or EEA, the General Data Protection Regulation (GDPR) grants you the following rights:
- Right of access (Article 15): Obtain confirmation of processing and a copy of your data
- Right to rectification (Article 16): Correct inaccurate data
- Right to erasure / "right to be forgotten" (Article 17): Request deletion where no legitimate basis for retention exists
- Right to restrict processing (Article 18): Pause processing in certain circumstances
- Right to data portability (Article 20): Receive data in a structured, machine-readable format
- Right to object (Article 21): Object to processing based on legitimate interests or direct marketing
- Rights related to automated decisions (Article 22): Opt out of solely automated decisions that significantly affect you
To exercise GDPR rights: Contact privacy@jettson.ai. We will respond within 30 days (extendable by 2 months for complex requests). If unsatisfied with our response, you may lodge a complaint with your national supervisory authority.
11.1 International Data Transfers
Data is processed in the United States. We rely on the following mechanisms for international transfers from the EU/EEA:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Data Processing Agreements with all sub-processors
11.2 Supervisory Authorities
You may lodge a complaint with your national supervisory authority. Find your authority at: edpb.europa.eu/about-edpb/board/members
12. Other International Users
If you reside outside the United States, EU, or EEA — including the United Kingdom, Canada, Brazil, Australia, or Latin America — your local data protection law may grant you rights similar to those described above (access, correction, deletion, complaint to a supervisory authority). Email privacy@jettson.ai with any privacy request and we will respond in accordance with the law applicable to you.
13. Children's Privacy
Jettson is not directed at children under 18. We do not knowingly collect personal information from children. If we discover we have inadvertently collected data from a child under 18, we will delete it within 72 hours. Parents or guardians who believe their child has provided us with personal information should contact customertek@rwxtek.com immediately.
14. Do Not Track
We respect Do Not Track (DNT) signals by defaulting non-essential cookies and analytics to disabled until you explicitly opt in via our cookie consent mechanism.
15. Changes to This Policy
We may update this Privacy Policy at any time. For material changes, we will notify you by email to your registered address and via notice on the Service at least 14 days before changes take effect. The "Last Updated" date at the top reflects the most recent revision. Your continued use of Jettson after the effective date constitutes acceptance of the updated policy.
16. Data Processing Agreement (DPA)
Business customers subject to GDPR, UK GDPR, CCPA, or other data protection laws requiring a Data Processing Agreement may request a DPA by contacting customertek@rwxtek.com. We will execute a DPA reflecting applicable legal requirements.
17. Contact and Complaints
Privacy inquiries: privacy@jettson.ai (or customertek@rwxtek.com)
Mailing address:
RWX-TEK INC
8605 Santa Monica Blvd #664055
West Hollywood, CA 90069
United States
If you believe we have not adequately addressed your privacy concerns, you have the right to contact your local data protection authority or lodge a complaint with the relevant supervisory body for your jurisdiction.
RWX-TEK INC — Last Updated: April 22, 2026