Privacy Policy
Effective 11 August 2026 · jazzr.in
Jazzr provides AI assistants that businesses add to their websites and share with their customers and staff. This page explains what data we handle, why, for how long, and how to reach us. It is written to satisfy the notice requirements of India's Digital Personal Data Protection Act, 2023 (DPDP) and, where applicable, the GDPR, in plain language.
Two ways you might be here
- You run a business using Jazzr. For your account data, we are the Data Fiduciary (controller). For the documents you upload and the conversations your visitors have with your assistant, you are the Data Fiduciary and we process that data on your behalf and your instructions.
- You chatted with a business's assistant. The business you were talking to decides how that data is used, contact them first for any request about your data. You can also always reach us directly (contact below), and we will help.
What we collect
- Account data: business name, work email, and a password we store only as a salted hash. Used to run your account and send transactional email (e.g. verification).
- Content you provide: documents you upload and website pages you point the assistant at. Used only to answer questions asked of your assistant. Never shared with other businesses, never used to train AI models.
- Conversations: the questions visitors type into an assistant and the answers given, kept so the business can review quality and see what customers ask.
- Feature-interest emails: if you leave your email on our roadmap section, we use it only to tell you when those features are ready. Write to the contact below to be removed at any time.
- Technical data: IP addresses are used transiently, in memory, for rate limiting only; we do not keep them, we do not profile visitors, and we use no advertising trackers. The only cookies are essential ones (admin sign-in session).
AI processing and sub-processors
To generate an answer, the visitor's question, the recent conversation, and the most relevant excerpts from the business's own documents are sent to a large-language-model provider: currently Groq, Inc. (United States). Under our agreement with the provider, this data is not used to train their models. Transactional email is delivered through an SMTP provider. That is the complete list of sub-processors.
Want more control? Businesses can choose their own AI model, including a local, self-hosted LLM so conversation data never leaves their infrastructure, and can host the entire Jazzr stack on their own servers (additional setup effort and pricing apply). Contact us to set either up.
Voice input
The optional microphone button uses your browser's built-in speech service, which may send audio to the browser's vendor (for example Google, in Chrome) for transcription. We therefore recommend, especially for health-related conversations, that you do not speak confidential or personal details aloud; typing is more private. The widget shows this reminder on first microphone use. A server-side speech option that avoids browser vendors is on our roadmap for businesses that need it.
How long we keep data
- Conversations: deleted automatically after 180 days. Businesses can also delete all of their assistant's conversation logs at any time from their dashboard. Aggregate counters (how many questions per day) are kept, they contain no personal data.
- Documents: kept until the business deletes them. Deleting a document removes the file, its search index entries, and takes it out of every future answer immediately.
- Account data: kept while the account is active. Write to us to close an account and we will delete it.
Your rights and how to reach us
You can ask us what data we hold about you, ask for corrections, ask for deletion, withdraw a consent you gave, or raise any complaint. Grievance contact:
We aim to respond within 7 days, and in every case within the timelines required by applicable law. If you are in India and are not satisfied with our response, you may complain to the Data Protection Board of India.
Children
Jazzr does not knowingly collect children's data for its own purposes, does not build profiles of any visitor, and does not track anyone across sites. Businesses whose audiences include children (for example schools and academies) are responsible for the consents their audience requires; we support them with the controls above.
Security
Passwords are hashed (bcrypt), traffic is encrypted in transit (TLS), each business's data is isolated from every other business, staff-only assistants can be passcode-gated, and conversation logs are excluded from server access logs by design. If a breach affecting your personal data ever occurs, we will notify you and the authorities as the law requires.
Changes
If this policy changes materially, we will post the new version here with a new effective date, and notify account holders by email.