Privacy Policy
Last updated September 2026
JML(“we”, “us”, “our”) is the roster and evidence file for who should have access. This Privacy Policy explains what information we collect, how we use it, and the choices you have.
Information we collect
- Account information — name, email address, and authentication credentials when you sign up or are invited to a workspace.
- Workspace data — organizations, positions, applications, employees, and lifecycle requests you and your teammates create inside JML.
- Usage data — basic technical information such as browser, IP address, and request logs used to operate and secure the service.
How we use information
- To operate, maintain, and improve the JML service.
- To authenticate users and enforce role-based access controls.
- To send transactional emails (invitations, password resets, lifecycle notifications).
- To detect, investigate, and prevent abuse or security incidents.
Sharing
We do not sell personal information. We share data only with the sub-processors required to run JML (for example, our hosting and email providers), and when required by law.
Data retention
Workspace data is retained while your organization is active. You may export or request deletion of your data at any time by contacting us.
Security
JML enforces row-level security at the database layer, encrypted transport (TLS) for all traffic, and least-privilege access for internal operators. See our Security page for details.
Your rights
Depending on your jurisdiction, you may have the right to access, correct, export, or delete personal information we hold about you. To exercise these rights, email privacy@usejml.com.
Changes
We may update this policy from time to time. Material changes will be communicated through the product or by email.
Contact
Questions? Reach us at privacy@usejml.com.