Privacy Notice
Updated 13 September 2026 · pre-launch draft
1. Who is responsible for your information
Jatzo is the service responsible for the personal information described in this notice. Not yet completed, and needed before public launch: the name of the legal person or company that operates Jatzo, its registered address and its contact details.
2. Information we process
When you create an account, Jatzo processes your name, email address, password credential in hashed form, plan and usage information. When you analyse an email, the service processes the uploaded .eml file or pasted source so it can produce the requested security analysis.
The current application does not write raw submitted .eml files, email bodies or attachment contents into persistent case history. It processes them to produce the assessment, then releases them from application processing. History retains the email subject (up to 180 characters) as the case title, check date, risk score, verdict, counts, compact finding labels and limited intelligence summaries. Your subject may contain personal or confidential information: case metadata is not anonymous. Full checked URL lists and source IPs are not stored in the case-history record.
If you or your team use an inbox add-in, Jatzo also keeps a correspondent history: a record that a sender has written to your account before, so that a payment request from a stranger can be told apart from one from a supplier you deal with every week. For each sender it holds a keyed one-way fingerprint of the address (HMAC-SHA256), when that sender was first and last seen, and how many of their messages were checked. No address or domain is stored in any form that can be read back, so it cannot be turned into a list of who you do business with. It is kept on the account that pays, so a business shares one history across its staff, and it is written only from a message an add-in read out of a real mailbox, never from a file uploaded on the website.
If you use the Contact Us form, Jatzo processes the name, email address, company name if supplied, enquiry category and message you provide so the enquiry can be managed and answered. Beta Feedback is stored as an enquiry category; there is no automatic external inbox delivery in this build. Please avoid including passwords, recovery codes or sensitive third-party content in feedback.
3. Why we use the information
We use account information to provide and secure your account, enforce plan limits, maintain case history and operate the service. We process submitted email data to perform the analysis you request, investigate abuse and protect the security of Jatzo.
4. Legal basis
Jatzo relies on these lawful bases under UK data protection law.
- Providing the service you asked for (contract): creating and running your account, analysing the emails you submit, keeping your case history, applying your plan and its allowances, training you take, and answering a message you send through Contact.
- Security and abuse prevention (legitimate interests): security audit events, rate limits and sign-in protection, add-in diagnostics, and the operator's records of support actions and notes. The interest is keeping the service and the accounts on it safe; these records hold nothing from the emails you check and are kept only for the periods in section 6.
- Correspondent history and remembered link reputation answers (legitimate interests): telling a sender who has never written to you apart from one you know, and not paying twice to look up the same link. The interest is detecting fraud aimed at the people Jatzo checks mail for; the history holds fingerprints that cannot be read back as addresses, and a remembered answer holds no link.
- People named in the emails you check (legitimate interests): senders, recipients and anybody in a subject line. The interest is producing the security analysis you asked for; Jatzo keeps only the subject line and the findings, for up to 90 days, and never the message.
- Legal obligations: keeping or disclosing a record where the law requires it, such as financial records once sales begin, and answering a request you make about your information.
Where an organisation gives its staff Jatzo through a business workspace, the organisation decides that its people use it and Jatzo handles the workspace's information on its behalf. The organisation's own privacy notice explains the lawful basis it relies on.
5. Threat intelligence and service providers
On plans that include live threat intelligence, selected URLs extracted from a submitted email may be sent to Google Web Risk for reputation checking. URLs can themselves contain personal information or tokens. DNS and source-IP lookups can also disclose queried domains or IP addresses to the configured lookup services. Approximate source-network geolocation uses ipwho.is. On the same plans, the registration date of up to three linked domains is looked up from that domain's registry through its public RDAP service, which receives the domain name only. A live reputation answer is remembered for up to six hours, or until the provider's own expiry for a known threat, against a keyed fingerprint of the link rather than the link itself, so a link checked again soon, by anybody, is answered without a second lookup. Optional RIPEstat lookups send the selected public IP, and derived network prefix and origin ASN, to RIPE NCC for registry, routing and published abuse-contact information. They do not send the email body or attachments. QR decoding of supported image attachments runs locally in isolation; recovered web URLs can be included in the selected reputation queries. Jatzo does not need to send the complete email to Google Web Risk for this feature. Jatzo's service, its database and its backups are hosted by Hetzner Online GmbH in its Nuremberg data centre in Germany, which runs the server Jatzo uses. Nothing is hosted outside the European Economic Area. Transfers from the United Kingdom to Germany rely on the United Kingdom's adequacy regulations for the EEA, so no standard contractual clauses or international data transfer agreement are needed for hosting. The categories of recipient of personal information are: that hosting provider; Google Web Risk, for link reputation on plans that include it; RIPE NCC, for registry, routing and abuse contact information about a public IP address; ipwho.is, for the approximate location of a public IP address; and domain registries through RDAP, which receive a domain name only. Google processes outside the United Kingdom and the EEA for part of its service, and the safeguard Jatzo relies on for that transfer is not yet stated here; it must be before public launch. Payment and email delivery providers will be listed here before either is switched on.
6. Retention and deletion
Raw submitted email content is processed for analysis and is not saved to case history. Your browser holds the source and current results while the page is in use; downloaded reports are copies under your control. Temporary upload handling and operating-system memory are not a secure-erasure facility.
- Support actions on your account: when Jatzo's operator changes your plan, resets your allowance, signs you out, disables the account or grants training, the action, the reason given and the time are kept for 12 months. Nothing from the emails you check is part of it, and the record stops naming you if you delete your account.
- Changes of team places Jatzo asks an owner to agree: the number of places before and after, whether the owner agreed and when, and who at Jatzo asked, for 12 months. The link in the email is kept only as a one-way fingerprint.
- Notes about your account: Jatzo's operator may note a call with you or something promised to you. Only the operator sees them. They are kept for 12 months, deleted with your account, and given to you if you ask through Contact.
- Add-in diagnostics: which Outlook or Gmail app and version a connection uses, how far the add-in got when it started, and whether its recent requests to Jatzo worked. At most ten entries for each connection, kept for 30 days and deleted with your account. Nothing about any email.
- Cases you send to Jatzo support: only when you press Send to support on a case. Support sees its case reference, the date, the score and grade, your plan, where the check was made and the rules that fired with their points. Never the subject, the message, addresses, links or attachments. It is kept for 30 days unless you withdraw it sooner, and deleting the case or your account withdraws it. Separately, Jatzo counts how often each rule fires across the service each day, with no account or case attached, for 35 days.
- Deletion receipts: when you delete your account you are given a receipt reference. The receipt holds counts of what was removed and what stays, and dates, with nothing that names you, and is kept for 12 months.
- Team activity: if you belong to a business workspace, its owner and administrators see a log of invitations, people joining, leaving and being removed, role changes, handing the workspace over, add-in sign-outs and mailboxes allowed again, security settings, deployment files and the IT email, reports sent to IT, exports of cases and people, changes of team places, cases sent to Jatzo support and taken back, and cases the owner deleted, with the name and email of the person involved, for 12 months. A deleted case is listed by its case reference, never its subject. If you delete your account the log stops naming you.
- Removed inbox mailboxes: when a team owner removes somebody whose mailbox an inbox rollout set up, that mailbox's email address is kept on the team's block list, so the add-in cannot set itself up for it again. It stays until the owner allows the mailbox again or the team is deleted. It has no time limit, and it is not deleted with the person's own account, because it records the team's decision.
- Live link lookup counts: how many paid link reputation lookups an account used in each month, kept for about three months so a question about a recent month can be answered, and deleted with the account.
- Inbox add-in connections: the name you gave a connection, when it was made and last used, and a one-way fingerprint of its code. They do not expire on their own: a connection lasts until you revoke it, a team owner signs it out, or the account is deleted.
- Saved cases, related fingerprints and case feedback: up to 90 days, or less when your plan's history limit is reached. Limits are Free 3, Personal 60, Business 250, Business Pro 500, Enterprise 500 cases. You can delete an individual case, or clear the checks you made, sooner. Deleting history does not refund check allowance.
- Check usage: 62 days, to enforce current monthly allowances.
- Security audit events: 30 days. Abuse-rate counters expire after two days; shared counters are not retained as your account profile.
- Contact messages and Beta Feedback: 90 days from submission, or sooner when the associated account email is deleted. Messages sent using another email address require a separate request.
- Account details, avatar, course access, progress and completion records: until you delete the account or the service closes. Assessment-attempt records expire after 90 days; completion records remain available while the account exists.
- Invitation and recovery tokens: until used or their configured expiry. Expired processing reservations are removed. Unused pending course orders expire after seven days; opaque payment replay records expire after 90 days. Live payments are disabled; legally required financial retention and provider records must be defined before sales begin.
- Temporary intelligence caches: URL exports have a 30-minute access expiry. Geolocation and optional registry observations expire after at most one hour, with shorter caching for failures. The registration date of a linked domain, looked up from its registry through RDAP, is remembered for up to 24 hours. These caches, and a working copy of each remembered link reputation answer below, are in application memory. Expired entries are swept during maintenance as well as on access; expiry does not promise immediate physical memory erasure.
- Remembered link reputation answers: stored in the Jatzo database, not only in memory, so they survive a restart and are included in the managed backups. Each answer is kept against a keyed fingerprint of the link (HMAC-SHA256), never the link itself, and holds only whether the provider listed the link and until when. Answers are shared across customers, so a link anybody checked recently is answered without a second lookup. Each is kept for up to six hours, or less when the provider's own expiry is sooner, and maintenance deletes expired answers.
- Correspondent history: a sender not seen for 13 months is deleted, and the whole history is deleted with the account it belongs to.
Automatic maintenance runs on the first request after startup and then on a request at least an hour after the previous run. The operator must also run scheduled maintenance at least hourly for a live service so expiry is enforced while the site is idle. Expired records are removed on the next maintenance run; closed local installations are cleaned when next used.
Deleting your account
In Account, expand Delete my account, enter your current password and type DELETE. After confirmation, your account details, avatar, personal cases and history, fingerprints, feedback, usage, account-linked audit events, course records and locally held order records are permanently removed from the active Jatzo service. Cases you made in a business workspace are not: they stay with the workspace, no longer linked to you, as Business workspaces below explains. Nor is a mailbox address a team owner removed from their inbox rollout: it stays on that team's block list, as the retention list above explains. Contact messages linked to your account or using your current account email, and invitation/recovery records using that email, are removed too. All sessions cease to provide account access. Your account and its history cannot be recovered through Jatzo.
Restricted managed backups expire after 30 days. We keep a separate keyed deletion marker for up to 35 days so a permitted backup restore cannot reintroduce deleted accounts or cases. This marker contains no readable email address, name, subject or message content; it is still handled as restricted deletion-management data. Backups are held beyond ordinary use during that period, and deletion markers are applied before a restored service is opened.
Deletion cannot remove reports you downloaded, screenshots, emails you separately sent to support, or copies held outside this installation. Production host logs, off-site backups and any external processors must follow the published retention and erasure policy. We do not promise forensic erasure from storage hardware, memory or every third-party system. If a legal duty requires specific records to be retained after paid services launch, the updated notice will identify those records and periods.
7. Your rights
Depending on the circumstances, UK data protection law may give you rights over your personal information, including rights of access, correction, erasure, restriction, objection and data portability. You can download your own data from Account, under Privacy, and use Contact to request help with anything else about your information. We may need to verify your identity before acting. You can also complain to the Information Commissioner’s Office. Not yet completed, and needed before public launch: a direct privacy contact, and the procedure and timescale for answering a request.
Your right to object
Where processing relies on legitimate interests, you can object on grounds relating to your situation. If direct marketing is introduced, you can object to that processing at any time. Contact us to exercise these rights; they are not waived by using the service.
8. Cookies and local storage
Jatzo uses a signed session cookie to keep users signed in and protect requests. The application session lifetime is configured to eight hours; signing out invalidates your Jatzo sessions. Your browser stores your selected colour theme locally. If you connect an inbox add-in with a code, the add-in keeps that connection code in its own browser storage on that device, so you do not have to enter it again, until you disconnect it there or revoke it from your account page. This build does not include advertising or analytics trackers. If optional analytics, advertising or other non-essential cookies are introduced, Jatzo will provide the notices and choices required before using them.
Report exports and email delivery
On PDF-capable plans, a bounded in-memory snapshot may retain extracted URLs, network and header evidence, attachment metadata, QR destinations and provider results for up to 30 minutes. It does not contain the original email body or attachment bytes. Restarts and capacity limits can clear it earlier. Case ownership is rechecked before access; deleting a case or account removes access to its report evidence.
If you request email delivery, the generated PDF, account email address and case reference are sent through the configured Microsoft 365 delivery service. Delivery must be enabled by the operator. In a business team, Report this to IT in an inbox add-in sends a PDF of the check to the IT email address the workspace owner set, not to the person who pressed it. That PDF names the original sender and the subject line, so it concerns two people: the member who reported the email and the person who sent it. We request no sent-item copy, but Microsoft and recipient mail systems may retain transport records or message copies under their own policies. Downloaded or emailed copies are outside Jatzo's case deletion and retention controls. Do not request delivery if your mailbox is not appropriate for the report's contents.
Free-plan ad space currently displays a Jatzo training promotion. No third-party ad requests, profiling or advertising cookies are included. Paid plans are ad-free. Any future advertising provider needs a separate privacy and consent review before activation.
9. Changes
This notice will be reviewed as Jatzo develops. Material changes to how personal information is used will be reflected in an updated notice before the new processing begins.
Threat Memory and Campaign Intelligence
Jatzo may create keyed, privacy-preserving fingerprints from technical email observables such as registered domains and normalised subject patterns. These fingerprints help recognise related reports and confirmed threat infrastructure without retaining the raw email, full URL or source IP in case history. Campaign Intelligence compares those fingerprints only within your own account or, for a business account, within its workspace's shared history. It never compares one customer's messages with another's.
Training and purchases
Training stores account-linked lesson progress, assessment scores and attempt times, completion references and the course version. Individual answers are used to grade the assessment and are not stored. If checkout is enabled, Stripe receives the purchase information needed for hosted payment; Jatzo stores order, session and payment identifiers, amount, currency and access status. Card details are entered with Stripe and are not collected by Jatzo. Learning records follow section 6. Local order records are removed with the account; payment-provider and legally required financial retention must be agreed before live sales are enabled.
Isolation, browser copies and security
Restricted workers process supported uploads, and the website handles transport, validated results and account records. The controls reduce risk but do not guarantee immunity from malicious content, unauthorised access or data loss. Data shown in your browser and any downloaded report remain accessible to you and anyone with access to that device. Do not assume closing a result securely erases every copy.
If you add a profile picture, Jatzo processes the uploaded image in the worker and stores a re-encoded avatar for your account. Security and operational records may include account identifiers, event times, request information and abuse-control fingerprints. Production proxy and host logging must be configured consistently with this notice.
Automated analysis and AI
The current email engine uses programmed checks and scoring; it does not send your email to a generative-AI model for analysis. Its score supports your decision and does not automatically decide whether you should pay, trust a sender or take another action.
Information needed to provide the service
An email address and password are needed for an account. Email source is needed for the requested check. Contact-form fields marked required are needed to manage your enquiry; other information is optional. If you choose not to provide required information, the relevant feature may be unavailable.
Production details still to complete
Still to complete before public operation: the legal person or company operating Jatzo and its registered address (section 1), a direct privacy contact and response procedure (section 7), and the safeguard for the Google Web Risk transfer (section 5). The lawful bases are in section 4, and hosting and the categories of recipient are in section 5. The application retention and account-deletion controls described above are implemented; the deployed schedule, off-site backups, external logs and processor arrangements must be checked before launch. Payment-provider retention and legal obligations must be reconciled before sales begin.
Business workspaces
Business workspace records: cases checked inside a business workspace belong to that workspace. Its owner and administrators can see all of them, and members can open their own. Leaving the team or deleting your account removes your membership and personal details but does not delete business cases: your contributor reference is removed and those cases remain subject to the workspace retention limit. Shared usage charges remain with the subscription owner. Delete your own business cases first if appropriate. An owner must hand over or delete their workspace before deleting their account. Downloaded or emailed copies cannot be recalled.
Business owners and administrators must invite only authorised colleagues, explain this access to staff and use Jatzo in accordance with their organisation's privacy duties. Invitations expire after 48 hours. Workspace history is retained for up to 90 days, subject to the shared plan cap. Removed members lose future workspace access. Previously downloaded reports remain outside Jatzo's control.
Business accounts and personal checks
An account that belongs to a business workspace is a business account. Every check it makes, on the website or in an inbox, is saved to the workspace, and it has no personal history or personal allowance while it is a member. Joining or creating a workspace deletes the checks already saved to that account, and Jatzo says so before you go ahead; to keep them, use a different email address for the team. For personal checks, use a separate account with a personal email address. Leaving or being removed from a workspace does not restore Free checks to that address.
