legal

Privacy policy

Last updated: 18 August 2026

1. Who we are

Jarville (jarville.ai) is a set of self-serve tools for people who make and ship ads, operated by Mycelium Technologies Private Limited ("Jarville", "we", "us"). For the personal data described in this policy, we are the data controller. You can reach us about anything in this policy at privacy@jarville.biz.

2. What we collect

  • Account data. When you sign in we collect your email address and, if you use Google or Microsoft sign-in, the name and profile picture those providers share. We never see or store a password: sign-in is by emailed link or OAuth.
  • Content you give the tools. The ad creatives you upload and the searches you run (for example a brand name in the ad-library tool). On the free, no-signup layer your creative is processed for the result and not stored. When you run a tool from your signed-in account, the creative and its report are saved to your account so you can come back to them.
  • Usage and device data. Your IP address and a device cookie, used to enforce free-tier rate limits and protect the service from abuse; run records (which tool, when, outcome, credits moved); and basic request logs.
  • Analytics data, with your consent or notice where the law allows. If analytics cookies are on, we collect page views, interactions, session recordings, and campaign parameters through PostHog (hosted in the EU). In the EU/EEA, UK and other opt-in jurisdictions they are on only if you accept them in the banner; elsewhere they are on by default and you can turn them off at any time. To decide which applies we read the two-letter country code our hosting provider derives from your IP address at its edge. We do not store either. If you decline, none of that runs: no cookies, no recordings, nothing stored in your browser. See the cookie policy.
  • Anonymous measurement, with or without consent. We count visits, page views and whether the free tools succeeded, even if you decline cookies. For declining visitors this is done without storing anything on your device: our server turns your IP address and browser user-agent into a one-way code using a secret that changes daily, so the code cannot be reversed and is different the next day. It can count a visit; it cannot follow you over time or build a profile. Full description in the cookie policy.
  • Payment data. Credit-pack purchases are processed by Stripe. We receive a record of the purchase (pack, amount, time). Your card details go to Stripe, never to us.
  • Support messages. What you type into the support chat, used to answer you.

3. How we use it, and on what legal basis

  • Providing the service: running the tools on your inputs, saving your gated work, managing credits and purchases, signing you in. Basis: performance of a contract.
  • Security and abuse prevention: rate limiting by IP and device, protecting sign-in. Basis: legitimate interests.
  • Product analytics: understanding which tools are used and where they fail, in detail and over time, including session recordings. Basis: your consent (the cookie banner) in jurisdictions that require prior opt-in; our legitimate interest, with notice and a one-click opt-out, elsewhere. Either way withdrawable at any time.
  • Anonymous audience measurement: counting visits and free-tool outcomes for visitors who have not accepted cookies, using the daily one-way code described above. Basis: legitimate interests (knowing whether the service works and is being used), balanced against your privacy by the fact that nothing is stored on your device, the code cannot be reversed, and it cannot link you across days. You can object at any time by sending a Global Privacy Control signal from your browser, or by emailing us.
  • Transactional email: sign-in links and account confirmations. Basis: performance of a contract. We do not currently send marketing email.
  • Legal obligations: keeping purchase records for accounting and tax.

4. AI processing of your creatives

The tools work by having AI models analyse what you submit: an uploaded creative is sent to a large-language-model provider (Anthropic, via Vercel's AI Gateway) and, for attention heatmaps, to our own model service. These calls run with zero data retention where the provider supports it, and your content is not used to train anyone's models. The verdicts and scores that come back are automated assessments for your information only. No decision with legal or similarly significant effect on you is made this way.

5. Who we share data with

We do not sell personal data. We do run Google’s advertising tag, but only to count which ads led to a signup: where you were never asked for consent, it runs with ad personalisation switched off and Google’s restricted data processing switched on, so Google may measure a conversion for us and may not use what it sees to build audiences or target you elsewhere. Where you were asked and accepted, it runs in full. Beyond that, data goes only to the service providers (processors) we run the product on:

ProviderPurpose
VercelHosting and AI Gateway routing
PlanetScaleDatabase hosting
Amazon Web Services (S3, EU region)Storage of saved creatives and generated reports
Anthropic (via Vercel AI Gateway)AI analysis of submitted content
ModalAttention-model inference
PostHog (EU)Product analytics (with consent) and anonymous audience measurement (without)
FingerprintBrowser identification for free-tier limits and abuse prevention (on the tool pages only)
Google AdsConversion measurement for our own ads, restricted to measurement only unless you explicitly accepted advertising cookies
StripePayment processing
ResendTransactional email (sign-in links)
Google / MicrosoftOptional sign-in providers
SearchAPI.ioQuerying Meta's public Ad Library (your search terms, not your identity)

We may also disclose data where the law requires it, or as part of a corporate transaction (merger, acquisition), in which case this policy continues to apply to it.

6. International transfers

We process data in the EU and the United States. Where personal data of EEA, UK or Swiss residents leaves those jurisdictions, we rely on the providers' European Commission-approved Standard Contractual Clauses and equivalent safeguards.

7. How long we keep things

DataRetention
Free-layer creativesProcessed for the result, not stored
Free-layer run recordsDeleted after 30 days (result cache: 14 days)
Saved (signed-in) workUntil you delete it or your account
Sign-in and confirmation tokensExpire within 10 to 60 minutes; expired tokens swept daily
Account dataUntil you delete your account
Purchase and credit recordsKept after account deletion, pseudonymised, for statutory accounting periods

8. Your rights

You can exercise the two big ones yourself, right now, from your account page:

  • Export your data: "Download my data" gives you everything we hold about you as a JSON file (access and portability).
  • Delete your account: permanently removes your account, saved work, boards and credits, confirmed by a link to your email (erasure).

You also have the right to correct inaccurate data, restrict or object to processing based on legitimate interests, and withdraw consent at any time (the cookie-preferences link in the footer). If you are in the EEA, UK or Switzerland, you can lodge a complaint with your local data protection authority. For anything not covered by the self-serve controls, email privacy@jarville.biz; we verify the request against the account's email and respond within the timeframe applicable law requires (one month under GDPR, 45 days under CCPA).

9. California privacy rights (CCPA/CPRA)

If you are a California resident: in the preceding 12 months we have collected the categories above. These are identifiers (email, name, IP), commercial information (credit purchases and runs), internet activity (usage of the tools; analytics only with consent), professional information (your email domain), and the content you submit. We collect them for the purposes in section 3, share them only with the service providers in section 5, and we do not sell or share personal information as those terms are defined in the CCPA. No data is exchanged for money, and nothing is passed to a third party for cross-context behavioural advertising. That second half is a configuration, not just a promise: for California visitors our Google advertising tag runs with restricted data processing on and ad personalisation off (section 5), which keeps Google a service provider rather than a recipient of shared data. We honour the Global Privacy Control browser signal by disabling analytics and advertising for that browser, which is also how you exercise an opt-out here. Sending it also registers your objection to the anonymous measurement described in section 3.

You have the rights to know, delete, and correct (all available self-serve or by email, as in section 8). We will never discriminate against you in price, service, or features for exercising them. You may use an authorised agent to submit a request; we will verify the request with the account holder.

10. Cookies

Covered separately in the cookie policy, including the full list of cookies and what "Essential only" means.

11. Children

Jarville is a professional tool and not directed at children. You must be at least 16 to use it, and we do not knowingly collect data from anyone younger. If you believe a child has provided us data, email privacy@jarville.biz and we will delete it.

12. Security

Data in transit is encrypted (TLS everywhere, including database connections). Stored creatives live in a private bucket readable only through short-lived signed URLs. Sign-in is passwordless, so there is no password database to breach. Access to production systems is limited to the people who operate them.

13. Changes to this policy

We will update this page when our practices change and revise the date at the top. For material changes we will notify signed-in users (for example by email or an in-product notice) before the change takes effect.

14. Contact

privacy@jarville.biz for Privacy, Jarville (Mycelium Technologies Private Limited).