Privacy notice
Privacy without mystery.
This notice describes the Jern Cloud service as it exists today. It is specific on purpose and is revised whenever processing materially changes. The security page describes the same flows from the engineering side.
Who we are
Jern Cloud is operated by Jern. Questions about this notice go to privacy@jern.ai.
What we collect
- Account identity. Your GitHub user id, login, display name, and avatar, received when you sign in with GitHub. We do not receive your GitHub password, and we do not keep your GitHub access token.
- Repository and workspace metadata. The installations and repositories you grant to the Jern Cloud GitHub App, organization membership and invitations, roles, and workspace settings.
- Session content. The messages you send, the agent's final replies, and task prompts, stored in plaintext so the dashboard can show your conversation.
- Evidence. The full trace of each attempt, which can include prompts, model responses, tool inputs and outputs, policy decisions, and file content the agent observed. Workspace snapshots and dependency caches when an environment uses them. All of these are encrypted before storage.
- Usage and audit records. Token counts metered by the gateway, attempt outcomes, approvals, retention and settings changes, and similar workspace events.
- Product measurement. A small set of step events, such as "installation selected" or "session started", tied to a workspace or a user id. They name the step only. They never contain message text, code, or credentials, and this website loads no third-party analytics.
- Website page views. Each page of jern.ai sends one count to Jern's own API with the page path and, if you arrived through a campaign link, its short label. No cookies, no identifiers, no IP address is stored, and nothing is shared with a third party.
- Service logs. One line per request with a request id, method, path, status, timing, and the client address. Logs never contain prompts, traces, or credentials.
- Provider credential. Your workspace's model provider API key (Anthropic, OpenAI, Google Gemini or Vertex AI, or Fireworks), required to run sessions, is validated once with that provider, encrypted before storage, and used only to serve your workspace's attempts.
Why we process it
To sign you in, scope repository access, run the sessions you ask for, enforce policy and budgets, show evidence to people authorized to see it, meter usage for billing, diagnose failures, protect the service and other customers, and understand where people get stuck on the way to a first pull request.
Who processes it
| Processor | Purpose |
|---|---|
| GitHub | Sign-in, repository access, and the pull requests Jern opens |
| Fly.io | Hosting for the control plane, the database, and the per-attempt machines |
| Amazon Web Services (KMS) | Custody of the keys that encrypt evidence and credentials |
| Anthropic, OpenAI, Google (Gemini, Vertex AI), Fireworks | Model inference. Prompts and completions for an attempt are forwarded by the Jern gateway to the provider of the model the session chose, under your workspace's own API key for that provider, so that provider's terms for your account apply to that traffic. Only the providers you hold a key for ever receive anything |
We do not sell personal information, and we do not use your code, messages, or evidence to train models. Each model provider's handling of API traffic is governed by its own commercial terms.
How long we keep it
- Evidence and conversation text are kept for your workspace's evidence retention window, 90 days by default and adjustable in Settings. After that, evidence is deleted and conversation text is redacted in place. Enforcement is automatic and hourly, and an administrator can run it at any time.
- Session and attempt records without their content, audit events, usage, and billing records are kept while the workspace exists and for as long as needed to operate, bill, and defend the service.
- Per-attempt machines are destroyed at the end of every attempt. Nothing persists on them.
- Browser sessions expire after 24 hours. Only a digest of the session credential is stored.
Your choices
- Change or revoke repository access at any time from the GitHub App installation settings. Access is re-checked on every read.
- Shorten the retention window or purge evidence now from Settings.
- Remove a bring-your-own provider key from Settings.
- Ask us to delete a workspace and its data by writing to privacy@jern.ai from an owner account. We confirm the deletion in writing.
- Report a security concern to security@jern.ai.
Changes
Material changes are dated here and sent to workspace owners before they take effect.
Effective: September 2, 2026. Replaces the pilot notice of August 26, 2026.