Privacy
Last updated August 2026
This page explains what JUTSU does with personal data — both on this website and inside a customer deployment. It is written to be read, not to be survived.
This website
The marketing site sets no advertising or cross-site tracking cookies. A single entry in your browser’s local storage records whether you dismissed the announcement bar and which colour theme you chose. Both stay on your device and are never transmitted.
If you email us from a link on this site, we receive whatever you send — typically your name, address and the contents of your message — and use it only to reply.
Inside a deployment
JUTSU runs inside your own cloud or VPC. We do not host your corpus and we do not receive a copy of it. Within a deployment:
- Connectors are read-only. Nothing is written back to a source system.
- Permissions are inherited from each source at ingestion and enforced again at query time, so a result only surfaces for someone who could already open the underlying document.
- Personal identifiers are masked during ingestion.
- Data is encrypted in transit and at rest.
- Every query and every answer is written to an audit trail.
Knowledge-risk scoring
Bus-factor scores are reported in aggregate by default. Individual-level scoring is off unless a customer explicitly enables it, and enabling it is a decision for that customer to make with notice to the people affected. A data protection impact assessment is completed before any live pilot.
Your rights
Where the DPDP Act 2023 or the GDPR applies, you may request access to, correction of, or deletion of your personal data. For data held inside a customer deployment, that customer is the controller and we act on their instructions — contact them first, and we will support the request.
Contact
Questions about this policy: hello@jutsu.dev.
