Privacy Policy

JammyJar ("we", "us") is an AI image generation and library product, built and operated from Switzerland. We comply with the EU General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (FADP). This page explains what we collect and why — in plain language, because there is nothing to hide. Questions any time: support@jammyjar.com.

What we collect

  • Account data — your email address and optional name. Sign-in is passwordless: we email you a one-time code, so we never store a password.
  • Your content — the prompts you write, images you upload (for example as style references), images you generate, and the themes, tags and workspaces you create.
  • Billing data — payments are handled by Stripe. We never see or store your card number; we keep records of your purchases and credit balance.
  • Usage data — product analytics via PostHog (EU cloud) and server logs (including IP addresses) to keep the service running and secure.

We do not buy data about you, and we never sell your data to anyone.

How we use it

We use your data to run JammyJar: authenticate you, generate your images, store your library, process payments, send transactional emails (sign-in codes, receipts), understand how the product is used, and prevent abuse. The legal bases are performance of our contract with you, our legitimate interest in operating and improving the service, and legal obligations (e.g. keeping billing records).

AI processing

When you generate an image, your prompt and any reference images are sent to the AI model provider behind the model you picked — currently Google (Gemini), OpenAI, Recraft and Krea — solely to produce your result. We may add new model providers at any time; the same rules apply to them. We never use your content to train AI models, and we use API terms under which providers process your inputs to serve your request, not to train their public models.

Where your data lives

Your images and database live on AWS and Neon in Frankfurt, Germany (eu-central-1). The web app is served by Fly.io from the EU. Some providers (Stripe, the AI model providers) process data in the United States; these transfers are covered by the EU Standard Contractual Clauses and the EU–US / Swiss–US Data Privacy Framework where applicable.

Who we share it with

Only the processors we need to run the service: AWS (hosting, storage, email), Fly.io (web hosting), Neon (database), Stripe (payments), PostHog (analytics, EU), Cloudflare (bot protection), and Google, OpenAI, Recraft and Krea (image generation). Each processes data only on our instructions. We disclose data beyond that only if the law requires it.

Workspaces and public images

Content in a workspace is visible to the members of that workspace. If you publish an image to the public library, that image and its prompt become visible to anyone on the internet. You can unpublish at any time, but copies made by others while it was public may persist.

Retention

We keep your data for as long as your account exists. When you delete your account, your personal data and content are deleted within 30 days (backups roll off shortly after). Billing records are kept for as long as Swiss law requires, then deleted.

Cookies

We use only essential cookies (session/sign-in) and analytics. No advertising trackers, no third-party ad cookies.

Your rights

Under the GDPR and FADP you can access, correct, export or delete your data, object to processing, and withdraw consent at any time. Most of it you can do directly in the app; for everything else email support@jammyjar.com and we'll respond within 30 days. You can also complain to your local data protection authority or the Swiss FDPIC.

Changes

If we make material changes to this policy, we'll update the date above and notify you by email or in the app before the changes take effect.