← Home

Privacy Policy

Last updated 2026-05-12.

In plain English

Javeline captures your conversations with AI tools (ChatGPT, Claude, Gemini, Grok, Perplexity, Notion AI) so you can search and recall what you’ve already done. We store this data on your device and, if you sign in, in a Supabase database under your account (encrypted at rest at the infrastructure level). Secrets and sensitive values you type are scrubbed on your device before storage. Javeline’s own server can read your message text — but only to power features you asked for: your search and your assistant. We do not sell it, show ads, or train models on it — the only outside parties that receive it are the service providers that run Javeline (infrastructure) and the AI providers you send content to, all listed under Subprocessors below. (Client-side, server-blind end-to-end encryption is in development as an option you’ll be able to turn on.)

We do not sell your data. We do not show ads. We do not train AI models on your conversations. The only third parties that receive your data are the service providers required to run Javeline — our infrastructure providers, and the AI providers you deliberately send content to (e.g. Anthropic for AI Assist and the daily digest, OpenAI for search embeddings). They are all listed under Subprocessors below.

Data we collect

From the browser extension

  • Conversation metadata: title, URL, tool name, timestamps. Stored locally and (after sign-in) in your Supabase row.
  • Message content: the text of prompts and responses, with detected secrets scrubbed on your device first. Stored in your Supabase row (encrypted at rest at the infrastructure level) and readable by Javeline’s server to power your search and assistant. When you enable the optional client-side encryption (in development), message bodies are AES-GCM-256 encrypted on your device first, under a key derived from your passphrase via PBKDF2-SHA256 (310,000 iterations) that the server never sees.
  • Vector embeddings: numerical representations of your messages used for semantic search. Stored as plaintext vectors so server-side nearest-neighbor search works. These cannot be reversed to recover original text.
  • Redaction metadata: counts and category labels (e.g., “3 API keys scrubbed”) for content the local PII scrubber removed before storage. We see that you redacted something; we do not see what was redacted.

From web and mobile clients

  • Email address for sign-in (one-time-code verification).
  • Wrapped master key blob (only if you enable client-side encryption, in development) — the encrypted form of that key. Stored in auth.wrapped_keys. Useless without your passphrase.
  • Session tokens issued by Supabase Auth.
  • App-version metadata for debugging.

What we explicitly do NOT collect

  • Your passphrase — ever, in any form (used only if you enable client-side encryption, in development).
  • Browsing history outside the AI tool domains the extension is configured for.
  • Identifiers beyond what Supabase Auth assigns.
  • Location data, contacts, microphone, camera, or any device sensor.

How we use your data

  • To provide search, recall, repeat-detection, and synthesis features.
  • To sync your captures across your devices (extension, web, mobile).
  • To compute aggregate insights and themes from your conversation titles (via Anthropic Claude — see Subprocessors below).
  • To send you product emails you’ve opted into (digest summaries, security alerts).

We do not use your data to train AI models, sell ads, share with data brokers, or for any purpose not directly related to delivering the Javeline product.

Subprocessors

The third-party services we use to operate Javeline:

  • Supabase (database, auth, file storage). Hosts the message store (encrypted at rest) and your user record.
  • Vercel (web hosting). Serves the Javeline web app; processes API requests.
  • Anthropic (AI Assist and synthesis). Receives plaintext context items you choose to ask questions about, plus your conversation titles for daily-digest generation. Per Anthropic’s policy, data sent via API is not used for model training.
  • OpenAI (embeddings). Receives PII-scrubbed message text to generate vector embeddings. Per OpenAI’s API policy, this is not used for training.
  • Resend (transactional email). Sends sign-in codes and notification emails. Receives only your email address and the email body.
  • EAS / Expo (mobile build + push notifications, if enabled).
  • Apple / Google (app distribution and platform push services).

Data retention & deletion

We retain your data as long as your account is active. You can delete your account at any time from /account; this triggers a cascade delete of all your conversations, messages, embeddings, wrapped keys, and notification preferences within 30 days.

You can export your data as a JSON archive at any time from /account.

Email logs sent via Resend are retained per Resend’s policy (typically 30 days). Supabase database backups are retained 7 days on the Pro plan.

Your rights

You have the right to:

  • Access the data we hold about you (export from /account)
  • Correct inaccurate data (delete + recapture)
  • Delete your account and all associated data
  • Object to processing (stop using the product; uninstall)
  • Data portability (JSON export)

GDPR / CCPA: you have the rights granted by these regulations in your jurisdiction. Contact privacy@javeline.ai for any request.

Security

  • On-device scrubbing of detected secrets before message bodies are stored; encryption at rest for the message store.
  • Optional client-side, server-blind end-to-end encryption (in development): AES-GCM-256 for message bodies, keys derived from your passphrase via PBKDF2-SHA256 (310k iterations), never seen by the server.
  • TLS 1.2+ for all network connections.
  • Supabase Row-Level Security (RLS) on every table.
  • Service-role keys held only on the server; never exposed to clients.
  • No third-party trackers or analytics in production.

Security report? Email security@javeline.ai.

Children

Javeline is not directed to children under 13 and we do not knowingly collect data from anyone under 13.

Changes to this policy

We’ll post material changes to this policy and email account holders when they take effect. Version history is in our public GitHub repository.

Last reviewed 2026-05-12. Source-of-truth version lives at github.com/mattdomit/javeline.