Jinna.ai | Privacy Policy

PRIVACY POLICY

Last updated: 18 August 2026

Privacy Policy

This Privacy Policy explains how JINNA.AI LTD (“Jinna”, “we”, “us”, or “our”) collects, uses, discloses, and protects personal information when you use Jinna.ai, app.jinna.ai, our applications, AI features, integrations, shared documents, and related services (collectively, the “Services”).

JINNA.AI LTD is a company registered in the United Kingdom.

Contact: hello@jinna.ai

Address: 7 Warrington Crescent, London W9 1ED, United Kingdom

This Privacy Policy applies to account holders, visitors, people who interact with documents or communications created through Jinna, and other individuals whose personal information may be processed through the Services.

1. Our role

Depending on the context, Jinna may process personal information in different capacities.

For information relating to your Jinna account, billing, use of our Services, security, support, analytics, and our relationship with you, Jinna generally acts as a data controller or equivalent responsible business.

When a business user uploads, creates, imports, or otherwise processes personal information relating to its own clients, contacts, suppliers, employees, signatories, or other third parties through Jinna, Jinna may act as a processor or service provider on that user's behalf. In those circumstances, the user is responsible for determining whether it has an appropriate legal basis and providing any notices required by applicable law.

2. Information we collect

The information we process depends on how you use Jinna.

Account and profile information

We may collect information such as:

If you sign in using Google, we may receive basic Google account information authorised by you, such as your name, email address, Google account identifier, and profile information.

Business information

You may provide information about yourself or your business, including:

Contacts and third-party information

Users may store information about clients, leads, suppliers, contractors, signatories, and other contacts. This may include:

If you provide information about another person, you are responsible for having the rights and permissions necessary to do so.

Documents and transactions

Jinna may process information contained in or associated with:

Jinna does not store full payment-card numbers when payments are processed through third-party payment providers such as Stripe.

AI conversations and business memory

When you use Jinna's AI features, we may process:

Jinna may use this context to make future interactions more relevant and to perform tasks you request.

Communications

We may process communications sent to or from Jinna, including email addresses, recipients, message content, attachments, subject lines, and related metadata.

Document viewing and signing information

When a person views, interacts with, or signs a document created through Jinna, we may collect information such as:

Some Jinna emails may use tracking technologies to record whether a document-related email has been opened. These features are used to provide document, delivery, security, and engagement information to the sender.

Information from connected services

If you connect a third-party service such as Google or Xero, Jinna may receive information from and send information to that service according to the permissions you grant and the features you use.

You can choose whether to connect optional integrations.

Information from public sources

Where you ask Jinna to research or understand a business, Jinna may obtain information from publicly available sources such as business websites and other public web content.

Technical and usage information

We may automatically collect information including:

More information is available in our Cookie Policy.

3. How we use information

We use personal information to:

We may also use contact details to communicate about Jinna, including product updates and marketing where permitted by applicable law. You may opt out of marketing communications at any time by contacting us at hello@jinna.ai or by using an unsubscribe mechanism where one is provided.

4. Artificial intelligence

Jinna uses artificial intelligence to provide features such as drafting, analysis, business context retrieval, document generation, research, and task execution.

Information you provide to Jinna may be transmitted to AI infrastructure providers acting on our behalf where necessary to provide the feature you request.

Our current AI infrastructure includes services provided by Google Cloud and Google Vertex AI. AI systems can produce inaccurate or incomplete information. Users should review important AI-generated outputs before relying on them.

Jinna does not use Google Workspace data to train or improve general-purpose artificial intelligence models.

We do not use automated decision-making that produces legal or similarly significant effects about individuals unless we separately explain that processing and it is permitted under applicable law.

5. Google account and Google Workspace data

This section specifically describes Jinna's use of information obtained through Google APIs.

Jinna may allow you to sign in using Google and may offer optional Google Workspace functionality.

Depending on the functionality available to you and the permissions you choose to grant, Jinna may use Google data to:

Jinna only requests access to Google information necessary for the relevant user-facing functionality.

For Calendar features, information processed may include event information you provide or instruct Jinna to use, such as titles, dates, times, descriptions, and attendee details.

If you connect Gmail, information processed may include message and thread identifiers, sender and recipient information, subject lines, dates and timestamps, message snippets, relevant message content, and mailbox state such as whether a conversation is unread or in your inbox.

Jinna accesses Gmail information when necessary to perform features that you request. Jinna does not continuously synchronise or create a separate permanent copy of your Gmail mailbox.

Relevant Gmail content may be retrieved and processed during a request so that Jinna can answer your question, draft a response, send a message, or perform another Gmail action you have requested.

Jinna is designed to minimise persistence of Gmail content. Gmail API tool results retained by Jinna are limited to operational information such as message or thread identifiers, result counts, actions performed, confirmation state, and success or failure information. Information that you ask Jinna to discuss may still appear in your Jinna conversation history or in another Jinna record where you deliberately ask Jinna to use or save that information.

When Jinna prepares an outgoing Gmail message for you, the proposed message may be retained as part of the confirmation process so that the message you approve is the message that is sent.

Gmail content is treated as external content. Instructions or commands contained inside an email are not treated as instructions from you. Gmail content is not automatically added to Jinna's permanent business memory solely because it appeared in an email. Information may become part of your Jinna data where you explicitly ask Jinna to remember it or deliberately use it in another Jinna record or workflow.

Jinna does not currently request Google Drive access through its user OAuth flow. If we introduce additional Google Workspace integrations in the future, we will request additional permissions before accessing that information and update our disclosures where necessary.

Google Workspace information is used only to provide or improve the user-facing functionality for which access was granted.

We do not:

Google Workspace data may be processed by service providers acting on our behalf only where necessary to provide the relevant functionality, maintain security, comply with law, or otherwise as permitted by Google's applicable policies.

Human access to Google Workspace user data is restricted except where the user has authorised access, access is necessary for security or troubleshooting, the information is appropriately aggregated or anonymised, or access is required by law.

Jinna's use of information received from Google Workspace APIs adheres to the Google Workspace User Data and Developer Policy, including the Limited Use requirements.

You can revoke Jinna's Google permissions through your Google Account settings. Where Jinna provides an integration-disconnect control, you may also use that control to stop Jinna from using that integration.

Because Google may treat permissions granted to different Jinna Google integrations as part of the same Google project grant, disconnecting one Google integration in Jinna may not revoke all Google-side permissions where another Google integration remains connected. You can review or revoke Jinna's Google permissions directly through your Google Account settings.

Revoking access prevents Jinna from making new requests using the revoked permission, but information previously created or retained in Jinna may remain where necessary to provide the Services, maintain records, comply with law, or satisfy legitimate security and legal requirements.

Google currently expressly requires Workspace API data to be limited to user-facing functionality and prohibits use for advertising, credit decisions, data resale, and general-purpose AI training.

6. Payments

Jinna uses payment service providers such as Stripe for subscription billing and payment functionality.

Payment providers may collect payment-card and financial information directly from you under their own privacy policies.

Jinna may receive and retain identifiers and transaction information such as:

Jinna does not receive or store full card numbers entered on Stripe-hosted payment pages. Where a Jinna user connects their own Stripe account to receive client payments, payments are processed through that user's connected payment account.

7. How we disclose information

We do not disclose personal information except as described in this Policy or as directed by you.

We may disclose information to service providers that help us operate Jinna, including providers of:

Current providers may include Supabase, Google Cloud, Google Vertex AI, Vercel, Stripe, Resend, Loops, and Temporal Cloud.

If you enable an integration such as Xero or Google Workspace, information may also be exchanged with that provider at your direction.

We may disclose information:

8. Shared documents

Jinna allows users to create links that can be shared with clients and other recipients. Depending on the feature, access may be controlled by a unique link, email verification, expiry settings, signing verification, or other controls.

Users are responsible for deciding who receives a shared link and for ensuring that any information included in a shared document may lawfully be disclosed to its recipients.

9. Cookies and analytics

We use cookies and similar technologies for authentication, security, application functionality, preferences, and, where permitted, analytics.

In jurisdictions where consent is legally required for non-essential cookies or similar technologies, we ask for consent before activating those technologies.

You can find additional information and manage applicable preferences through our Cookie Policy and Cookie Settings.

10. Legal bases for UK and EEA users

Where the UK GDPR or EU GDPR applies, we process personal information under one or more of the following legal bases:

Contract. Processing necessary to provide Jinna, manage an account or subscription, perform requested integrations and workflows, and provide customer support.

Legitimate interests. Processing necessary to secure, maintain, troubleshoot, and improve Jinna; understand service performance; prevent abuse; manage our business; and establish or defend legal claims, where those interests are not overridden by the rights and interests of individuals.

Consent. Where we specifically ask for consent, including for certain cookies, marketing, integrations, or optional processing.

Legal obligation. Where processing is necessary to comply with law, regulation, tax, accounting, court orders, or other legal obligations.

Where Jinna acts only as a processor on behalf of a business customer, the customer is responsible for identifying the relevant legal basis for its processing.

11. Sensitive information

Jinna is not designed to request special-category or highly sensitive personal information as part of ordinary account registration.

However, users can upload documents, communications, notes, files, and other Customer Content that may contain sensitive information. You should not provide sensitive information unless it is necessary for your use of Jinna and you have a lawful basis and appropriate authority to process that information.

12. Data retention

We retain personal information for as long as reasonably necessary for the purposes described in this Policy, including to provide an active account, maintain business and transaction records, meet legal obligations, resolve disputes, prevent abuse, and enforce agreements.

Different categories of information may be retained for different periods. For example, records relating to executed electronic signatures, transactions, security events, financial records, or disputes may need to be retained after an account or document is otherwise deleted.

For Gmail, Jinna does not continuously synchronise or retain a separate permanent copy of your mailbox. Relevant Gmail content may be processed when needed for a request, while limited operational records such as message or thread identifiers, confirmation state, actions performed, and result status may be retained where necessary to operate and secure the integration.

An outgoing email draft may be retained as part of Jinna's confirmation and audit mechanisms where necessary to ensure that an authorised message is sent as intended.

Where information is no longer required, we take reasonable steps to delete or anonymise it, subject to legal, security, backup, fraud-prevention, and technical requirements. Information contained in backups may remain after deletion from active systems and may not be immediately removable from individual backup copies.

13. Security

We use technical and organisational measures designed to protect personal information, including authentication, access controls, tenant-level access restrictions, transport encryption, security monitoring, audit mechanisms, and infrastructure security controls.

No system can guarantee absolute security. You are responsible for safeguarding your account credentials and for using appropriate security practices when sharing documents or configuring integrations.

14. International transfers

Jinna operates internationally and uses service providers located in different countries. As a result, personal information may be processed outside your country of residence.

Where UK or EEA personal information is transferred internationally and applicable law requires safeguards, we use an appropriate legal mechanism, which may include an adequacy decision, approved contractual safeguards, or another mechanism recognised under applicable data-protection law.

Personal information remains subject to the protections required by applicable law regardless of processing location. The GDPR requires appropriate mechanisms for transfers outside the EEA where the destination does not benefit from an adequacy decision.

15. Your privacy rights

Depending on where you live and applicable law, you may have rights to:

To exercise a privacy right, contact:

hello@jinna.ai

We may request information reasonably necessary to verify your identity and protect your account.

Some rights are subject to legal limitations and exceptions. UK and EEA laws provide rights including access, rectification, deletion, restriction, portability, and objection.

16. United States privacy rights

Residents of certain U.S. states may have additional privacy rights where the applicable state law applies to Jinna. Depending on the law, these may include rights to:

We will not discriminate against you for exercising a legally protected privacy right. Jinna does not sell Google Workspace user data or use it for targeted advertising.

Requests may be submitted to hello@jinna.ai. For California residents, the CCPA, where applicable, provides rights including access, deletion, correction, opt-out of sale or sharing, limitations concerning certain sensitive information, and non-discrimination.

17. Children

The Services are intended for users who are at least 18 years old. We do not knowingly offer Jinna directly to children under 18. If you believe a child has provided personal information to Jinna contrary to this Policy, please contact us.

18. Changes to this Privacy Policy

We may update this Privacy Policy as Jinna, our technology, or applicable laws change. We will update the “Last updated” date when changes are made. If a change materially affects how we use personal information, we will provide additional notice where required by law.

19. Contact and complaints

Questions, privacy requests, and concerns can be sent to:

JINNA.AI LTD
7 Warrington Crescent
London W9 1ED
United Kingdom
hello@jinna.ai

If UK data-protection law applies to you, you may also have the right to complain to the UK Information Commissioner's Office. If EU/EEA data-protection law applies, you may have the right to complain to the supervisory authority in the country where you live, work, or believe an infringement occurred.