Privacy Policy
This Policy explains how Husena LLC collects, uses, discloses, protects, retains, and provides choices about personal information when you use Jotmor™.
1. Controller and contact
Husena LLC is the operator and controller responsible for Jotmor.
Husena LLC 5900 Balcones Drive, Suite 100 Austin, Texas 78731 United StatesContact privacy@jotmor.com for privacy questions or requests. To appeal a denied request, reply with “Privacy appeal” in the subject line.
2. Scope and eligibility
This Policy applies to Jotmor websites, applications, APIs, account services, notes, file storage, media processing, search, billing integration, support, and security operations. It does not govern third-party services you use independently.
Jotmor is for adults aged 18 and older. We do not knowingly collect personal information from children. Contact us if you believe a minor supplied information so we can investigate and delete it where appropriate.
3. Information we collect
Account and identity
- Email address, account identifiers, display name, plan, settings, storage usage, and account lifecycle dates.
- Amazon Cognito identifiers, email-verification state, and authentication events. We do not receive your Cognito password or authenticator secret.
- Legal-document versions, hashes, acceptance time, IP address, and user agent used to preserve agreement evidence.
Notes, files, and derived content
- Note titles, bodies, revisions, timestamps, organization, feedback, and attachments.
- Original filenames, detected and declared media types, sizes, hashes, dimensions, duration, page counts, thumbnails, and converted playback files.
- OCR text, transcripts, timestamps, descriptions, summaries, chapters, page references, processing states, and errors.
- Embeddings, content hashes, topics, connections, search chunks, ranking inputs and outputs, and related retrieval data.
Search, usage, and operations
- Search queries, filters, candidate identifiers, rankings, fallbacks, cache state, and monthly quota counters.
- Recently opened or edited items and upload, processing, export, cancellation, deletion, retry, and feature activity.
- Browser family, capability tier, IP address, user agent, request time and ID, service errors, rate-limit events, WAF events, and malware-scan status.
Subscriptions and financial records
- Selected plan and interval; Polar customer, product, subscription, order, and refund identifiers; subscription status and period dates.
- Order status, billing reason, currency, total and tax amounts, cumulative refunded amount and tax, and provider timestamps.
- Refund status, reason, amount, tax amount, benefit-revocation indication, and associated customer, subscription, and order references.
- Checkout, portal, webhook, reconciliation, cancellation-attempt, and billing-readiness events.
Polar and its payment processors collect billing addresses, tax information, and payment credentials directly. Jotmor does not receive or store complete card numbers or card security codes.
Support and local storage
We collect messages and attachments sent to support, privacy, legal, or security addresses and our responses. Jotmor uses essential browser storage for authentication, security, settings, and feature state. We do not currently use advertising cookies, cross-site tracking, or behavioral advertising analytics.
4. How and why we use information
- Provide the Service: authenticate users; save, sync, process, organize, search, display, export, and delete content; administer plans and billing access.
- Operate AI features: create OCR, transcripts, descriptions, summaries, embeddings, connections, and rankings for your account.
- Security and reliability: prevent abuse and fraud, scan malware, rate-limit requests, investigate incidents, debug errors, monitor availability, and restore data.
- Transactions: initiate checkout, reconcile provider status, apply entitlements, administer cancellation, and maintain order, refund, tax, and accounting records.
- Legal obligations and rights: respond to valid process, handle privacy requests, maintain required records, defend claims, and provide required notices.
- Communication: send account, verification, security, billing, renewal, policy, support, and service messages.
Where laws such as the GDPR or UK GDPR require a lawful basis, we rely on performance of our contract, legal obligations, our legitimate interests in security and reliable operation, protection of vital interests in exceptional circumstances, or consent for a specifically identified optional use. You may withdraw optional consent without affecting earlier lawful processing.
5. AI services and training
Jotmor uses Amazon Bedrock services for data automation, multimodal embeddings, and language-model processing. We send only content and metadata reasonably needed for the requested operation. We do not sell User Content or use it to train a generalized or publicly available model. Generalized model training would require a separate affirmative opt-in. We may use deidentified operational statistics that are not reasonably linkable to a person.
6. When we disclose information
- Service providers. Vendors process data for hosting, storage, databases, authentication, email, security, malware screening, conversion, AI processing, monitoring, and support under access and contractual restrictions. See the Subprocessor List.
- Payments. Polar acts as merchant of record for checkout, subscriptions, taxes, invoices, renewals, refunds, and chargebacks and may engage Stripe and other processors. Polar returns transaction status and identifiers so we can provide the purchased plan and retain financial records.
- Legal and safety. We may preserve or disclose data where reasonably necessary to comply with law or valid process, protect rights and safety, investigate fraud or security issues, or enforce agreements. We may challenge overbroad requests where appropriate.
- Business transactions. Information may be reviewed or transferred in a financing, merger, acquisition, reorganization, bankruptcy, or asset sale, subject to appropriate confidentiality and required notice.
- At your direction. We disclose information when you request or specifically authorize it.
We do not sell personal information, share it for cross-context behavioral advertising, or use it for targeted advertising. We do not knowingly sell or share personal information of minors.
7. International transfers
Husena is based in the United States, and Jotmor primarily stores and processes information in the United States. If you use Jotmor elsewhere, information is transferred to jurisdictions whose laws may differ from yours. Where required, we use recognized contractual safeguards, adequacy decisions, provider transfer mechanisms, or another lawful basis. Information about applicable safeguards is available on request.
8. Retention
We retain information only as reasonably needed for the purposes above:
- Uncompleted incoming uploads: approximately 24 hours.
- Temporary AI and media-processing outputs: approximately 7 days.
- Ready export packages: approximately 7 days.
- Older note revisions, while retaining the latest revision: approximately 90 days.
- Application logs: approximately 30 days; web and storage access logs: approximately 90 days.
- Deleted notes, files, and accounts: hidden or disabled promptly and normally purged after approximately 30 days.
- Database and disaster-recovery backups: until the configured encrypted backup lifecycle expires.
- Webhook delivery identifiers and event metadata: approximately 90 days.
- Minimal legal-acceptance evidence: up to 7 years after account closure.
- Minimal customer, subscription, order, refund, tax, cancellation, and reconciliation records: generally up to 7 years after the transaction or account closure for accounting, tax, fraud prevention, provider reconciliation, and legal claims.
Deletion may be delayed by legal hold, security investigation, technical recovery, chargeback, tax duty, or mandatory retention. Data in backups is isolated from ordinary use and expires through its lifecycle.
9. Your choices and rights
Depending on where you live, you may have rights to know, access, correct, delete, restrict, object, obtain a portable copy, withdraw consent, opt out of certain processing, or appeal a decision. Jotmor provides access, export, correction, and deletion tools broadly.
- Review or edit notes, files, and settings in the Service.
- Use “Export my data” for a portable archive, including customer-facing subscription, order, and refund summaries.
- Use “Delete account” to disable access and begin deletion. Provider cancellation retries continue independently and never block privacy deletion.
- Email privacy@jotmor.com for requests not available in-product.
We may verify identity and authority, request information reasonably needed to locate records, deny fraudulent or lawfully exempt requests, and retain request evidence. We aim to answer verified requests within 30 days and will explain a lawful extension or denial. Authorized agents must show authority. You may appeal and complain to your local regulator without discriminatory treatment.
10. U.S. state disclosures
Residents of states with comprehensive privacy laws may request access, correction, deletion, portability, and an appeal as applicable. We do not sell personal information or use it for targeted advertising, so no sale or targeted-advertising opt-out is necessary. We do not use sensitive personal information to infer characteristics or beyond the purposes permitted by law. We do not offer financial incentives for data.
Categories collected include identifiers, customer records, commercial and transaction information, internet or network activity, User Content, approximate location derived from IP, and inferences used for search and organization. Sources are you, your devices, our service activity, and providers. Uses and recipients are described in Sections 4 and 6.
11. Security
We use measures designed to protect data, including encryption in transit and at rest, private storage and databases, access controls, multi-factor-capable authentication, malware screening, network controls, rate limits, audit logs, backups, and monitoring. No method is completely secure. Report suspected vulnerabilities to security@jotmor.com and do not access, alter, or retain another person’s data while testing.
12. Policy changes
We may update this Policy for product, provider, legal, security, or operational changes. We post the version and effective date. Material changes receive reasonable advance notice and renewed acknowledgment where appropriate. Prior versions remain available in the legal archive.
13. Contact
Privacy: privacy@jotmor.com
Support: support@jotmor.com
Legal: legal@jotmor.com
Security: security@jotmor.com