Privacy Policy

Effective September 1, 2026

United States only. JCIL.AI is offered to users and organizations based in the United States. We do not currently process personal data from EU/UK residents under GDPR. If you are located outside the United States, please do not create an account.

Who we are

JCIL.AI is the operator of this platform, based at 130 Bishop Allen Drive, 5th Floor, Cambridge, MA 02139. JCIL stands for "Jesus Christ is Lord." It is a consumer product: a Scripture-aligned AI assistant built for individuals and families who want AI that shares their values. We do not sell institutional or enterprise accounts.

Your data is processed on US infrastructure via the subprocessors listed in our Trust Center. We do not transfer personal information outside the United States.

What we collect

Account information. When you create an account we collect your email address, display name, hashed password (or a Google OAuth identifier), and account preferences. Google sign-in returns your name and email; no additional Google data.

Conversations. Messages you send and AI responses are stored so your conversation history is available when you return. Files you upload (images, PDFs, text files) are stored in encrypted storage and automatically deleted after 14 days.

Long-term memory. We extract a small number of preferences, recurring topics, and explicit feedback from your conversations to make future answers more personal. You can review and clear this memory at any time from your account settings.

Billing. For credit purchases we collect name, email, and payment method via Stripe. Card numbers never touch JCIL.AI servers. Stripe tokenizes everything.

Usage logs. Per-request metadata (which tool ran, token counts, cost in cents) so you can see your spend and we can catch abuse. Not shared with third parties beyond what's required to deliver the service.

Safety events. When the moderation pipeline detects a high-signal crisis pattern (suicide ideation, self-harm, abuse disclosure, child-at-risk), we record the event so it can be reviewed and appropriate follow-up can occur.

Automatic information. IP address, user agent, request timing, and similar request metadata. Used for rate limiting, abuse detection, and debugging. Retained 30 days.

Why we collect it (purposes)

  • Deliver and improve the service you signed up for.
  • Authenticate you, keep your account secure, and prevent abuse.
  • Process payments and apply credits to your balance.
  • Personalize future conversations via the long-term memory system you can control.
  • Detect and respond to crisis situations flagged by the moderation pipeline.
  • Meet legal obligations and respond to valid legal process.

We do not sell your data, rent it, share it for cross-context advertising, or use your conversations to train AI models. Anthropic, whose Claude model generates your answers and runs the built-in web search, commits in its commercial terms not to train on your conversations; it retains API inputs and outputs for a limited period for abuse monitoring, and its privacy documentation has the specifics. See the subprocessors page for the full list of services and what each one receives.

How long we keep it (retention)

  • Active conversations: kept as long as your account is active.
  • File uploads: 14 days, then hard-deleted.
  • Usage logs: 90 days at row-level, aggregated thereafter.
  • Safety events: 180 days, then hard-deleted.
  • Moderation logs: 30 days.
  • Security violations: 24 months, then purged.
  • Support tickets: 24 months, then purged.
  • Shared chat links: expire and are deleted 90 days after they are created.
  • Inactive accounts: we email a warning at 12 months without a sign-in, and delete the account and its data at 18 months.
  • Billing transactions: 24 months (tax / audit requirement), then purged.
  • Deleted accounts: 30-day grace window (recoverable), then permanent.
  • Long-term memory: default 730 days (2 years). You can set it to 30, 90, 180, 365, or 730 days from account settings. There is no "keep forever" option.

Your rights

Regardless of where you live, every US JCIL.AI user has the following rights. California residents are additionally protected by CCPA/CPRA.

  • Right to know. Download a full export of your data (profile, conversations, memory, usage, billing) in JSON from account settings.
  • Right to delete. Delete your account and associated data. Two options: scheduled (30-day window, reversible) or immediate (permanent hard-delete, irreversible).
  • Right to correct. Update or correct any profile field from settings.
  • Right to opt out of "sale" or "sharing." We don't sell or share personal information for cross-context behavioral advertising, so there is nothing to opt out of. A formal opt-out toggle is still available on the privacy settings page for CCPA compliance.
  • Right to non-discrimination. Exercising your rights doesn't change the service you receive.

Do Not Sell or Share My Personal Information. We do not sell personal information, and we do not share it for cross-context behavioral advertising. To record a formal opt-out anyway, use the toggle on your privacy settings page or submit the compliance contact form with topic privacy / data rights.

To exercise any right, use the account settings page or submit the compliance contact form with topic privacy / data rights. We respond within 45 days, typically within one business day.

Children's privacy

JCIL.AI consumer accounts are intended for users age 13 and older. We do not knowingly collect personal information from children under 13 on the consumer product. If you believe a child has created an account, contact us through the compliance formand we'll delete it.

For questions about student privacy under the COPPA school-authorization framework, see our compliance page.

Security

Concrete measures, including TLS 1.3, AES-256 at rest, row-level security on every sensitive table, layered moderation, and vulnerability disclosure, are documented in full on our Security page.

Cookies

We use a handful of first-party cookies for authentication and basic preferences. No cross-site tracking, no advertising pixels. Full details on our cookies page.

AI disclosure

JCIL.AI answers with Claude Haiku 4.5, a model made by Anthropic, an American AI company, accessed through Anthropic's API; specialized work such as generating downloadable documents may run a larger Claude model, still Anthropic's. JCIL builds the product around it: the convictions, continuous quality testing (autonomous checks and human review), the memory, and the privacy design. Live web search runs through Anthropic's built-in search tool. Supporting providers for infrastructure, billing, and delivery are listed in our subprocessor list. Asked whether you are talking to an AI, a bot, or a human, the assistant answers truthfully that it is an AI: JCIL.AI, powered by Claude from Anthropic. It never claims to be human.

AI outputs are generated; they are not professional legal, medical, financial, or pastoral advice. Always verify material decisions with a qualified human.

Changes to this policy

We'll post the updated policy here and change the "Effective" date at the top. For material changes that reduce your rights, we'll notify active account holders by email at least 30 days before the change takes effect.

Contact

Privacy questions, data-rights requests, and legal process: use the compliance contact form.

JCIL.AI
130 Bishop Allen Drive, 5th Floor
Cambridge, MA 02139
United States