Privacy notice
Privacy
This notice describes how Jelly handles personal information. It covers the elements an online privacy notice is expected to include under ISO/IEC 29184, the information GDPR Articles 13 and 14 require when personal data is collected, and the categories used in a California notice at collection. It describes this application as it works today.
Who we are
Jelly is a private tool for tracking a gambling habit and a goal to gamble less or stop, and for inviting someone you care about to use it. The operator of this website is the controller of the personal information described here.
We have not appointed a data protection officer or a representative in the European Union or the United Kingdom. The production site is gamble-responsibly.vercel.app.
Who this notice applies to
- People who create an account or sign in
- People who send an invitation, and people whose email address is entered so an invitation can be sent
- People who use the public pages, including the demo
- People whose goal, habit details, or messages are saved in an account
Information we collect
We collect information you give us, information created when you use Jelly, and a small amount of technical information needed to run the service.
Information you provide
| Category | Examples | When |
|---|---|---|
| Identifiers | Name and email address | Account creation, sign-in, and invitations |
| Credentials | A hash of your password. We do not store the password itself. | Account creation and password sign-in |
| Goal and habit details | Goal, focus areas, types of gambling, frequency, triggers, pause action, a reduce target, and a stop date | When you save onboarding answers |
| Limits and plan progress | Guardrail settings and notices you save, and checklist items you mark done | When you save them while signed in |
| Messages | Chat messages you send, replies, and a safety flag such as crisis or betting advice | After you accept the chat disclosure |
| Invitations | Sender name, sender email, recipient email, and an optional note | When someone requests an invitation |
| Emergency contact | The link between an account and a contact, including the time consent was recorded | When you create an account from an invitation |
Information collected as you use Jelly
| Category | Examples | When |
|---|---|---|
| Session data | Session token, expiry, IP address, and browser user agent | When you sign in |
| Email and sign-in records | Verification records, and magic-link tokens stored in hashed form | When we send those emails |
| On-device demo storage | Demo connection choices and demo guardrail or insight choices in this browser | When you use the demo |
Sensitive information
Goal, habit, limit, and chat content can describe gambling behavior. Chat can also include distress or crisis. We treat that information as sensitive. We use it to provide Jelly to you. We do not use it for advertising, and we do not sell it.
What we do not collect for the demo
Jelly does not connect to a bank, sportsbook, or payment account. Charts and connected activity in the demo use synthetic fixture data, not your financial accounts. We do not use advertising or analytics cookies. We do not sell personal information, and we do not share it for cross-context behavioral advertising.
Why we use it
- Create and protect your account, and keep you signed in
- Save the goal, limits, and plan progress you choose
- Send email the product requires: address verification, a magic-link sign-in, a confirmation to the person who requested an invitation, the invitation after that person confirms, and an emergency-contact request to the person you ask
- Provide chat replies and check messages for crisis language, after you accept the chat disclosure
- Remember an emergency-contact relationship when you create an account from an invitation, or when someone you ask accepts a request to be your emergency contact
- Keep the service reliable and limit misuse of invitations
- Show demo fixtures, and remember demo choices on your device
A name, email address, and password are required to create an account. You choose the habit details you enter. Features that depend on a goal, a limit, or chat need the information those features use. You can browse the public pages without an account. You can use Jelly without naming an emergency contact.
Legal bases
If the GDPR, UK GDPR, or Swiss data protection law applies, we rely on these bases:
- Contract. Providing the account and the features you use.
- Consent. Sending chat content, and a short summary of your goal, focus, triggers, and pause action, to OpenAI. Adding an emergency contact when you create an account from an invitation, or when you request one and they accept. Emailing an invitation at the sender's request. Emailing an emergency-contact request.
- Legitimate interests. Securing accounts and sessions, and limiting misuse of invitations. Those interests are limited to running Jelly. They do not include advertising.
You can withdraw chat consent by stopping use of chat and asking us to delete the thread. You can choose not to create an account from an invitation, and you can ignore an emergency-contact request. Withdrawal does not undo processing that has already happened.
Information from someone else
If someone enters your email address to invite you, we receive that address, the sender’s name and email address, and any note they wrote, from the sender. We email you the invitation directly. The sender's email address has not been confirmed. You can ignore the invitation.
Creating an account from the invitation is your choice. If you do, the sender becomes your emergency contact. They do not receive your habit record, spending, goal, dashboard, or chat.
If someone with a Jelly account asks you to be their emergency contact, we email you their name, their email address, and a link. The link expires in 72 hours. You can ignore that email. If you accept, you do not receive their habit record, spending, goal, dashboard, or chat.
Who receives it
Service providers process personal information for us, for the purposes in this notice.
- Vercel hosts the application.
- Timescale stores account and product data in the application database.
- Resend delivers verification email, sign-in links, invitations, and emergency-contact requests.
- OpenAI generates chat replies and checks message text for crisis language. We send your message and a summary of your goal, focus areas, triggers, and pause action. Chat completion requests are sent with storage disabled. We still keep the conversation in our database for the period below. OpenAI receives this information only after you accept the chat disclosure.
- Google Fonts receives the IP address and browser data your browser sends when it loads the typeface used on these pages.
An emergency contact does not get access to your habit record, spending, goal details, dashboard, or conversations. A notice to an emergency contact, if one is sent, is limited to the fact that you are struggling or asked to be contacted.
We may disclose information if the law requires it, or to protect someone from imminent harm. We do not sell personal information.
How long we keep it
- Account, profile, guardrails, plan progress, and emergency-contact records are kept while the account exists, and removed when a deletion request is completed.
- Sessions end when they expire, normally within 30 days of the last refresh, or when you sign out.
- A magic-link sign-in expires after 10 minutes.
- An invitation expires after 72 hours unless it is accepted first. Confirmation links sent for older invitation requests expire after 24 hours.
- An emergency-contact request link expires after 72 hours unless it is accepted first.
- Chat threads and messages are deleted 90 days after the thread was last updated. You can ask us to delete them sooner.
- Demo data in the browser remains until you clear site data for this site.
Security
The production site uses HTTPS. Passwords are stored as hashes. Invitation tokens, emergency-contact request tokens, and magic-link tokens are stored in hashed form. Reading account data requires a signed-in session. No method of storage or transmission is perfectly secure.
Your choices and rights
Depending on where you live, you can ask to access the personal information we hold, correct it, delete it, receive a portable copy, object to or restrict certain processing, withdraw consent, or appeal a refusal. If you are in the EEA, the United Kingdom, or Switzerland, you can also lodge a complaint with a data protection authority.
California residents can ask for the categories and specific pieces of personal information we collected, the categories of sources, the business or commercial purposes, and the categories of third parties we disclosed it to. You can ask us to delete information and to correct inaccurate information. We do not sell or share personal information as those terms are used in the California Consumer Privacy Act. We do not use sensitive personal information to infer characteristics for advertising. We will not discriminate against you for making a request.
Jelly does not yet offer a self-serve export or delete control in the product. Use the contact method below. We confirm a request with the email address on the account, or with the email address that received a Jelly message if you have no account. We may refuse a request when the law allows it, including when we cannot verify that it is yours.
Children
Jelly is meant for adults. It is not directed to children under 13, and we do not knowingly collect personal information from a child under 13. If you believe a child under 13 has given us personal information, contact us and we will delete it.
International transfers
We and our service providers may process information in the United States, where the host, database, email, and chat providers operate. If you use Jelly from another country, your information is transferred there. Privacy rules in those locations can differ from the rules where you live.
Automated processing
Plan text, activity checks, and chat safety classification describe information you entered or synthetic demo data. They can choose a fixed support reply. They do not block a sportsbook, move money, diagnose a condition, or produce a decision that has a legal or similarly significant effect. You decide what to do next.
Changes
We will post changes on this page and update the effective date. If a change needs new consent, we will ask before using your information in that new way.
How to contact us
To ask for access, correction, or deletion, contact the operator of Jelly from the email address on your account, with the subject “Privacy request,” so we can verify that the request is yours. If you do not have an account, use the email address that received the Jelly message and describe that message.
A dedicated privacy address and a postal address are not published on this page. When a dedicated address is available, it will be listed here.
Jelly