This Privacy Policy applies to Jackdaw, which is operated by Sentinel Development Group, Inc. (“Sentinel Dev,” “we,” or “us”).
1. The short version
- We collect only what Jackdaw needs to provide the features you use.
- We never sell your data. To anyone. Ever.
- We never use your personal data to train AI models — ours, theirs, or anyone else's.
- Our business model is paid subscriptions. You are the customer, not the inventory.
- You can export your data and delete your account at any time.
2. Who we are
Sentinel Development Group, Inc. is a Delaware corporation and the operator of Jackdaw.
For privacy questions, or to request data access, deletion, or portability, write to hello@sntnl.dev.
3. What Jackdaw collects
Jackdaw connects to the data sources you authorize so it can maintain current, source-backed context for your work.
- Account and profile data: name, email, and family or team structure you choose to declare.
- Communications and schedules: email, messages, contacts, calendars, events, reminders, and tasks from services such as Google, Microsoft, Apple, Slack, Discord, and Todoist.
- Work content: files, notes, pages, repositories, issues, pull or merge requests, projects, and related activity from services such as Microsoft OneDrive, Notion, GitHub, GitLab, and Linear.
- Health and activity: workouts, activity, sleep, readiness, and recovery information from services such as Apple Health, Strava, and Oura when you enable those connections.
- Extracted memories: typed records (facts, preferences, constraints, rejections, corrections) derived from your connected sources. These belong to you, retain their source provenance, and are protected by the storage and access controls described below.
- Provenance metadata: for each extracted record we store its source (e.g., “Slack message in #engineering, Apr 2”) so you can trace any fact back to its origin.
- Service logs: request metadata, retained for 30 days.
4. Connected services
Every connection is optional. Jackdaw accesses a service only after you choose to connect it and approve the permissions shown by that service or your device. We request access intended to support the visible features associated with the connection.
Jackdaw uses connected data to sync and display the information you select, power search and source-backed context, generate summaries and assistant responses, identify relevant people and relationships, and perform actions you request. An action that changes an external service, such as sending email or creating a calendar event, is taken only through a feature presented to you.
OAuth access and refresh tokens are encrypted at the application layer before storage. Imported data and the records derived from it are encrypted at rest, transmitted over HTTPS, and isolated by user and workspace. We retain connected data while the connection and account remain active so Jackdaw can provide those features.
We do not sell connected-service data, use it for advertising, or share it with data brokers. Jackdaw may send only the relevant portion to contracted infrastructure and AI service providers acting as our processors when needed to provide a feature you request. Connected-service data is not used to create, train, or improve generalized or shared AI models.
We do not permit employees, contractors, or other humans to read connected-service data except with your explicit consent for specific data, when necessary for security or abuse investigation, when required by law, or when the data has been aggregated and anonymized for permitted internal operations.
You can disconnect a service in Settings → Connections. Disconnecting removes Jackdaw's stored credentials for that connection and deletes its indexed content within 24 hours; deleted data ages out of disaster-recovery backups within 30 days. You can also revoke access directly with the provider. To delete all Jackdaw data, use Settings → Danger Zone → Wipe all data + disconnect sources or email hello@sntnl.dev.
The Integration Data Guide describes the data associated with each currently supported connection.
5. Provider-specific terms
When you connect Google, Jackdaw may access Gmail message and thread content, headers, metadata, labels, and attachments; your subscribed calendar list and event details; and saved and “Other contacts” details. Jackdaw uses this information for the connected-service purposes described above and for actions you direct, including changing Gmail labels, sending email, and creating calendar events. The storage, sharing, human-access, retention, and deletion rules in Section 4 apply fully to Google user data.
Jackdaw's use and transfer of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Microsoft
When you connect Microsoft, Jackdaw may access the Outlook email, calendars, contacts, tasks, and OneDrive files covered by the permissions you approve. The connected-service rules in Section 4 apply to Microsoft data, and Jackdaw's use of that data is also subject to the applicable Microsoft API terms.
Apple and other providers
Apple connections use device permissions for the contacts, calendars, reminders, or health categories you enable. Other integrations access only the account or workspace data covered by the permissions, token, or API key you provide. The same connected-service rules in Section 4 apply regardless of provider.
6. How we use your data
We use the data you provide for one purpose only: to operate the product you signed up for. Specifically:
- To authenticate you and keep you signed in.
- To run the features you use (sync, extraction, retrieval, assistant responses).
- To prevent abuse and enforce our Terms.
- To send transactional emails (sign-in, billing, security alerts) and product announcements you can opt out of.
We do not use your data to train AI models — ours or any third party's. We do not sell, rent, or trade your data. We do not use your data to target ads, because we don't serve ads.
7. AI providers and model calls
Jackdaw uses AI models from third parties (currently OpenAI, Anthropic, and Google) to generate replies and synthesize context. When we send your data to these providers:
- We send only the slice of context relevant to your current request (e.g., the “brief” for a single prompt), not your entire model.
- We use providers' zero-retention API endpoints where available, meaning the provider does not store the request after responding.
- We have signed Data Processing Agreements with each provider explicitly prohibiting use of your data for training.
- You can review which providers are active for your account in your settings, and disable any of them.
8. Encryption and security
- In transit: all data is sent over TLS 1.2+.
- At rest: application data is encrypted at the database and storage layer. OAuth tokens are additionally encrypted at the application layer before storage.
- Access controls: employee access to user data is role-gated, logged, and audited. Production access requires multi-factor authentication and is granted only for break-glass debugging with explicit justification.
- Tenant isolation: service authentication and user- and workspace-scoping controls restrict access at each storage layer.
9. Your rights
Regardless of where you live, you have the following rights over your data:
- Access: request a complete export of your data at any time. We provide it in a structured, machine-readable format (typically JSON) within 30 days.
- Correction: edit or correct any data we hold about you, directly in the product or by request.
- Deletion: delete your account at any time. We delete all your personal data within 30 days, retaining only what we're legally required to keep (typically billing records for 7 years).
- Portability: your model is yours. Export it and walk away — no lock-in.
- Disconnect: revoke access to any connected source at any time. Indexed content from that source is deleted within 24 hours.
- Object / restrict: object to or restrict specific processing activities by writing to hello@sntnl.dev.
Residents of the EU, UK, and Switzerland have additional rights under GDPR. Residents of California have rights under CCPA/CPRA. Residents of other US states may have rights under their respective state privacy laws. We honor all of them, regardless of where you live, because they're the right defaults.
10. Data retention
- Account data: kept for the life of your account, deleted within 30 days of account closure.
- Service logs: 30 days, then automatically deleted.
- Extracted memories (Jackdaw): kept for the life of your account or until you delete them.
- Billing records: 7 years, as required by US tax law.
- Backups: rolling 30-day backups for disaster recovery. Deleted data is purged from backups within 30 days.
11. Sub-processors
We use a small set of vendors to operate the service. Each is bound by contract to handle your data with the same standards we hold ourselves to:
- Cloud infrastructure: DigitalOcean (US region).
- AI model providers: OpenAI, Anthropic, Google (zero-retention endpoints, no training use).
- Email delivery: Resend (transactional).
- Payments: Stripe.
- Error monitoring: Sentry (PII-scrubbed).
A current list with addresses is available at hello@sntnl.dev. We notify users of material changes to sub-processors at least 30 days before they take effect.
12. International transfers
We operate primarily out of the United States. If you access our products from outside the US, your data is transferred to the US. For users in the EU, UK, and Switzerland, we rely on Standard Contractual Clauses (SCCs) and additional safeguards as required.
13. Children
Jackdaw is not directed at children under 13 (or under 16 in the EU). We do not knowingly collect data from children. If you believe we have, write to hello@sntnl.dev and we will delete it.
14. Changes to this policy
We may update this policy from time to time. Material changes will be announced by email and on the product, at least 30 days before they take effect. The “Effective” date at the top of this page reflects the current version.
15. Contact
For privacy questions: hello@sntnl.dev
For data access, correction, deletion, or portability: hello@sntnl.dev
For security disclosures: hello@sntnl.dev