Privacy Policy

Last updated: November 30, 2025

Introduction

Jelliflow ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our web application and Chrome browser extension (collectively, the "Service").

By using Jelliflow, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our Service.

Information We Collect

1. Chrome Extension Data Collection

Our Chrome extension only collects data when you explicitly start a recording session. Data collection is opt-in and requires you to click "Start Recording" in the Jelliflow dashboard. A visual indicator is displayed during active recording sessions.

What we collect during recording sessions:

  • User Interaction Events: Clicks, scrolls, navigation, form submissions, focus events
  • Element Selectors: CSS selectors, element IDs, classes, tags, and attributes (data-testid, aria-label, role)
  • Element Metadata: Text content (truncated to 100 characters), tag names, class lists
  • Positional Data: Click coordinates, scroll positions, element rectangles
  • Page Information: Current page URL, navigation paths, page titles
  • Technical Data: Timestamps, viewport dimensions, timezone, browser user agent

Privacy Protections:

  • Passwords: Completely redacted as [REDACTED]
  • Other Input Fields: Only character count is recorded (e.g., [15 chars]), never the actual content
  • No Passive Tracking: The extension does NOT collect any data when recording is not active
  • No Browsing History: We do not track your general browsing activity

2. Web Application Data

  • Account Information: Email address, name, profile picture (if provided)
  • Workspace Data: Workspace name, team member information, product configurations
  • Journey Data: Onboarding flows you create, step configurations, trigger settings
  • Analytics Data: Journey performance metrics, completion rates, user engagement data
  • Usage Information: Feature usage, session duration, interaction patterns within the Jelliflow dashboard

3. Automatically Collected Information

  • Log Data: IP address, browser type, operating system, access times, pages viewed
  • Cookies: Session cookies for authentication, preference cookies for user settings
  • Device Information: Device type, screen resolution, timezone

How We Use Your Information

We use the collected information for the following purposes:

  • Service Delivery: To provide, maintain, and improve the Jelliflow service
  • Journey Creation: To analyze recorded user flows and generate AI-powered onboarding journeys
  • Authentication: To manage your account and authenticate your access
  • Communication: To send you service updates, technical notices, and support messages
  • Analytics: To understand how users interact with our service and improve user experience
  • Security: To detect, prevent, and address technical issues and security threats
  • Compliance: To comply with legal obligations and enforce our terms of service

Chrome Extension Permissions

Our Chrome extension requires certain permissions to function. Here's why we need each permission:

activeTab

Used to identify the current tab's URL when you start a recording session.

storage

Used to store authentication state and connection settings locally in your browser.

tabs

Required to manage recording sessions across browser tabs (create, focus, and monitor tabs during recording).

scripting

Used to inject the recorder script into tabs when you start recording.

Host permissions (<all_urls>)

Required to allow you to record flows on any website. Since users record flows on their own SaaS applications (which can be hosted on any domain), we cannot restrict this to specific URLs.

Data Sharing and Disclosure

We do not sell, trade, or rent your personal information to third parties. We may share your information only in the following circumstances:

  • Service Providers: With trusted third-party service providers who assist us in operating our service (e.g., hosting, analytics, email delivery), under strict confidentiality agreements
  • Legal Requirements: When required by law, subpoena, or other legal process
  • Business Transfers: In connection with a merger, acquisition, or sale of assets (you will be notified via email)
  • Protection: To protect the rights, property, or safety of Jelliflow, our users, or others
  • With Consent: With your explicit consent for any other purpose

We certify:

  • We do NOT sell or transfer user data to third parties, outside of approved use cases
  • We do NOT use or transfer user data for purposes unrelated to our core service
  • We do NOT use or transfer user data to determine creditworthiness or for lending purposes

Data Security

We implement industry-standard security measures to protect your information:

  • Encryption: Data in transit is encrypted using TLS/SSL
  • Authentication: Secure authentication with short-lived tokens (15-minute expiry)
  • Access Controls: Strict access controls and authentication requirements for our systems
  • Regular Audits: Regular security audits and vulnerability assessments

However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee its absolute security.

Data Retention

We retain your information for as long as necessary to provide our services and fulfill the purposes outlined in this Privacy Policy. Specifically:

  • Account Data: Retained until you delete your account
  • Recording Data: Retained until you delete the specific recording or journey
  • Analytics Data: Aggregated and anonymized data may be retained indefinitely
  • Log Data: Retained for 90 days for security and debugging purposes

When you delete data, we will remove it from our active databases and it will no longer be accessible. Deleted data may persist in backups for up to 30 days before permanent deletion.

Your Rights and Choices

Depending on your location, you may have the following rights regarding your personal information:

  • Access: Request a copy of the personal information we hold about you
  • Correction: Request correction of inaccurate or incomplete information
  • Deletion: Request deletion of your personal information
  • Portability: Request a copy of your data in a machine-readable format
  • Objection: Object to our processing of your personal information
  • Restriction: Request restriction of processing of your personal information
  • Withdrawal: Withdraw consent at any time (where processing is based on consent)

To exercise any of these rights, please contact us at privacy@jelliflow.com. We will respond to your request within 30 days.

Cookies and Tracking Technologies

We use cookies and similar tracking technologies to track activity on our Service and store certain information. You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some portions of our Service.

For more information about how we use cookies, please see our Cookie Policy.

Children's Privacy

Our Service is not intended for use by children under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and you are aware that your child has provided us with personal information, please contact us. If we become aware that we have collected personal information from children without verification of parental consent, we will take steps to remove that information from our servers.

International Data Transfers

Your information may be transferred to and maintained on computers located outside of your state, province, country, or other governmental jurisdiction where data protection laws may differ. By using our Service, you consent to your information being transferred to our facilities and to the third parties with whom we share it as described in this Privacy Policy.

Changes to This Privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date at the top of this policy. We will also notify you via email if the changes are significant.

You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.

Contact Us

If you have any questions about this Privacy Policy, please contact us:

This privacy policy complies with GDPR, CCPA, and Chrome Web Store Developer Program Policies.