Privacy notice

Privacy without mystery.

This notice describes the Jern Cloud service as it exists today. It is specific on purpose and is revised whenever processing materially changes. The security page describes the same flows from the engineering side.

Who we are

Jern Cloud is operated by Jern. Questions about this notice go to privacy@jern.ai.

What we collect

Why we process it

To sign you in, scope repository access, run the sessions you ask for, enforce policy and budgets, show evidence to people authorized to see it, meter usage for billing, diagnose failures, protect the service and other customers, and understand where people get stuck on the way to a first pull request.

Who processes it

ProcessorPurpose
GitHubSign-in, repository access, and the pull requests Jern opens
Fly.ioHosting for the control plane, the database, and the per-attempt machines
Amazon Web Services (KMS)Custody of the keys that encrypt evidence and credentials
Anthropic, OpenAI, Google (Gemini, Vertex AI), FireworksModel inference. Prompts and completions for an attempt are forwarded by the Jern gateway to the provider of the model the session chose, under your workspace's own API key for that provider, so that provider's terms for your account apply to that traffic. Only the providers you hold a key for ever receive anything

We do not sell personal information, and we do not use your code, messages, or evidence to train models. Each model provider's handling of API traffic is governed by its own commercial terms.

How long we keep it

Your choices

Changes

Material changes are dated here and sent to workspace owners before they take effect.

Effective: September 2, 2026. Replaces the pilot notice of August 26, 2026.