Privacy policy
How Jiddu handles account data, submitted content, payments, analytics, and service usage across the website, API, MCP, and Live.
Last updated: August 5, 2026
1. Scope and controller
This policy applies to jiddu.app, Jiddu accounts, the public API, hosted MCP tools, and Live. The Chrome extension has a separate extension privacy policy that explains its browser permissions and local storage.
Jiddu is operated by Rafael de Menezes Ehlers in Brazil. For privacy questions or requests, use the Jiddu contact form or email support@emails.jiddu.app.
2. Information Jiddu handles
Account and contact data can include the user id, name, email address, session information received from WorkOS AuthKit, API-key labels and hashes, support messages, feedback, and invitation details.
Submitted content can include pasted text, public URLs, filenames, extracted PDF or image text, selected rendered PDF pages, Live transcripts, analysis settings, generated results, and the language you choose. Uploaded PDF and screenshot files are processed in memory rather than retained as original files; extracted content and results are stored with the analysis.
Usage and security data can include request IP addresses, timestamps, feature and model choices, token and credit usage, error and reliability data, and feedback about a result. Google Analytics receives ordinary page-traffic and device/browser information.
Purchase records can include your WorkOS user id, email, Stripe customer, Checkout Session and Payment Intent identifiers, package, amount, currency, and purchase status. Stripe processes payment-card details; Jiddu does not store full card numbers or security codes.
3. Why the information is used
Jiddu uses information to authenticate users and API clients, provide requested analyses, maintain account history and share links, meter credits, complete purchases, deliver emails, answer support requests, prevent abuse, secure and troubleshoot the service, and comply with legal obligations.
Depending on the context, processing is necessary to provide the service you requested, to comply with law, for Jiddu's legitimate interests in security and reliable operation, or based on consent where the law requires it.
4. Submitted content and AI providers
Submitted content is sent through OpenRouter to the upstream provider serving the chosen model. Fact verification and finalized Live Context reports can use Perplexity Sonar through OpenRouter to search public sources. Venue autocomplete sends only the typed venue query, not the manuscript, to DBLP.
In Live, raw audio streams directly from the browser to OpenAI's Realtime API over WebRTC. Jiddu does not receive or retain the raw audio. A temporary replay copy remains only in the current browser tab until a new session starts or the tab closes; Jiddu stores the transcript and selected analysis results.
Paper Explainer and adversarial review can send selected rendered PDF page images when figures or tables require visual inspection. Do not submit confidential, proprietary, embargoed, or personal data unless you are authorized to have it processed by these providers.
5. Storage, visibility, and retention
Completed analyses are stored on Hostinger infrastructure in Boston, Massachusetts, United States, and receive an unlisted share URL. They are not placed in the public sitemap, but anyone who has the URL can view the final result. Signing in associates eligible analyses with your account history; it does not make an existing share URL private.
Analysis history is retained while the account remains active unless earlier deletion is requested. Purchase, credit-ledger, security, and operational records can be kept for as long as reasonably necessary for accounting, fraud prevention, dispute handling, legal compliance, and service integrity. Expired caches and temporary processing data are removed or overwritten as part of normal operation.
6. Service providers, sharing, and international transfers
Jiddu shares only the information needed for a function with providers such as Hostinger for hosting, WorkOS for authentication, Stripe for payments, OpenRouter and upstream model providers for analysis, OpenAI for Live transcription, Resend for email delivery, and Google Analytics for traffic measurement.
Some providers process data outside Brazil. Jiddu can also disclose information when required by law, to investigate abuse or protect rights and safety, or as part of a protected merger, financing, acquisition, or transfer of the service. Jiddu does not sell personal information or use submitted content for personalized advertising.
7. Cookies, local storage, and analytics
Jiddu and WorkOS use cookies needed for sign-in and account security. Jiddu also stores language and theme preferences, invitation state, and short-lived one-time API-key display state. Browser local storage supports preferences and interface features such as dismissed notices and Live glossary state.
Google Analytics measures page traffic. Browser settings or privacy tools can block or remove cookies and local storage, although disabling required storage can prevent sign-in or other features from working correctly.
8. Security
Jiddu uses HTTPS, access controls, server-side provider credentials, hashed REST API secrets, and operational safeguards intended to protect information. No internet service can guarantee absolute security. Revoke a REST key immediately if you believe it has been exposed and contact Jiddu about suspected account or data misuse.
9. Your choices and rights
Depending on applicable law, including Brazil's LGPD, you can request confirmation of processing, access, correction, information about sharing, portability where available, revocation of consent, or anonymization, blocking, or deletion of eligible data. Some information can be retained where the law permits or requires it, including records needed for legal obligations and transaction disputes.
Submit a request through the Jiddu contact form. Jiddu may ask for information needed to verify that the requester is the account holder or otherwise authorized. Material changes to this policy will be reflected on this page with a new update date.