Privacy Policy

Last updated June 5, 2026

This policy describes how James handles account data, monitoring configuration, public asset snapshots, AI summaries, notifications, integrations, and privacy requests.

1. Scope

This Privacy Policy explains how James collects, uses, discloses, and protects personal information when you visit our website, create an account, configure monitoring, receive notifications, use integrations, or contact us.

For account, website, security, billing, support, and service administration data, James acts as the business or controller. For monitoring content that a customer configures James to process on its behalf, James may act as a processor or service provider under a separate data processing addendum.

2. Personal information we collect

  • Account information: email address, password hash, account identifiers, and account creation timestamps.
  • Session and security information: session tokens stored in an HTTP-only cookie, token hashes, expiration timestamps, IP-derived request metadata, audit events, logs, errors, and abuse-prevention signals.
  • Monitoring configuration: product names, company names, domains, homepage URLs, asset URLs, scan intervals, asset types, product status, and setup instructions you provide.
  • Monitored content: publicly accessible asset content fetched from configured sources, content hashes, byte length, status codes, content type, snapshots, raw diffs, change events, titles, summaries, severity, and scan run status.
  • Notification and integration data: email recipients, Slack incoming webhook URLs, generic webhook URLs, delivery settings, delivery status, delivery timestamps, and delivery errors.
  • Communications: messages, requests, feedback, and support information you send to us.
  • Billing information: plan, subscription, invoice, tax, and payment metadata. Payment card details, if collected, are processed by our payment processor and not stored directly by James.
  • Device and usage information: browser type, device type, pages viewed, feature usage, timestamps, referring pages, and diagnostic information.

3. Information from public sources and integrations

James can fetch content from public websites and product assets that you configure for monitoring. That content may occasionally contain personal information if it is present in the monitored source. You are responsible for configuring only lawful and appropriate sources.

If you connect Slack, email, webhook, payment, hosting, analytics, or other providers, we receive the information needed to operate those integrations and may receive delivery, billing, or usage metadata from those providers.

4. How we use personal information

  • Provide, operate, maintain, and secure James.
  • Create accounts, authenticate users, maintain sessions, and manage dashboard access.
  • Fetch configured assets, run scans, store snapshots, detect changes, generate diffs, and create change events.
  • Generate AI-assisted summaries and severity labels for detected changes.
  • Send email, Slack, webhook, and other configured notifications.
  • Process subscriptions, payments, invoices, taxes, and plan limits.
  • Provide support, respond to requests, debug errors, and improve product reliability.
  • Detect, prevent, investigate, and respond to fraud, abuse, security incidents, unlawful activity, and violations of our Terms of Use.
  • Comply with legal obligations and enforce our rights.

5. AI processing

James may send product names, domains, asset URLs, and diffs from configured monitored assets to AI providers, including OpenAI, to generate product-intelligence summaries. We instruct AI systems not to reproduce source code and to focus on concise business summaries, but outputs may be incomplete or inaccurate.

Do not configure James to process secrets, credentials, sensitive personal information, regulated health information, payment card data, private account data, or content you are not authorized to process.

6. How we disclose personal information

  • Service providers and subprocessors: hosting, database, AI, email, Slack, webhook delivery, payment, analytics, customer support, security, and infrastructure providers that help us operate James.
  • Customer-configured destinations: notification content sent to the email addresses, Slack webhooks, and webhook URLs you configure.
  • Professional advisors: lawyers, auditors, accountants, insurers, and advisors where reasonably necessary.
  • Legal, safety, and compliance: authorities, courts, counterparties, or others when we believe disclosure is required by law or needed to protect rights, safety, security, or the integrity of the service.
  • Business transfers: parties involved in a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets.
  • With your direction or consent: anyone else you authorize us to share information with.

7. Legal bases for processing

Where European privacy law applies, we process personal information as necessary to perform a contract with you, based on our legitimate interests in operating, improving, securing, and marketing James, with your consent where required, and as necessary to comply with legal obligations.

8. Cookies and local storage

James uses an HTTP-only session cookie named james_session to keep you signed in. The session is designed to expire after 30 days unless you sign out earlier.

We may use additional cookies or similar technologies for security, analytics, product diagnostics, and payment workflows as the service evolves. We do not use cookies to sell personal information or share it for cross-context behavioral advertising.

9. Retention

We keep personal information for as long as reasonably necessary to provide James, comply with legal obligations, resolve disputes, enforce agreements, maintain security, and support legitimate business needs. Account records are generally kept while your account is active. Monitoring configuration, snapshots, diffs, change events, scan runs, and delivery logs are retained according to your plan, account settings, deletion requests, and backup schedules.

10. Security

We use reasonable administrative, technical, and organizational safeguards designed to protect personal information, including hashed session tokens, HTTP-only cookies, access controls, operational logging, and provider security controls. No system is perfectly secure, so we cannot guarantee that personal information will always remain secure.

11. International transfers

James may process personal information in the United States and other countries where we or our service providers operate. Those countries may have privacy laws that differ from your location. Where required, we use appropriate transfer mechanisms for international transfers.

12. Your privacy rights

Depending on your location, you may have rights to request access, correction, deletion, portability, restriction, objection, withdrawal of consent, and information about how we process personal information. You may also have the right to appeal a decision or lodge a complaint with a regulator.

California residents may have rights to know, access, correct, delete, limit the use and disclosure of sensitive personal information, opt out of sale or sharing, and be free from discrimination for exercising privacy rights. James does not sell personal information or share it for cross-context behavioral advertising.

To exercise rights, contact privacy@james.watch. We may need to verify your identity and account authority before fulfilling a request. Authorized agents may submit requests where permitted by law.

13. Customer responsibilities

If you configure James to monitor third-party sources, send notifications, or process personal information on behalf of your organization, you are responsible for having the necessary rights, notices, legal bases, and permissions for that use. You are also responsible for configuring notification destinations so that alerts are sent only to appropriate recipients.

14. Children

James is not directed to children under 16, and we do not knowingly collect personal information from children under 16. If you believe a child provided personal information to James, contact privacy@james.watch.

15. Changes and contact

We may update this Privacy Policy from time to time. If changes are material, we will provide notice through the service, by email, or by another reasonable method.

Questions or requests can be sent to privacy@james.watch. Security issues can be sent to security@james.watch. Legal notices can be sent to legal@james.watch.