Skip to main content
Back to home

Privacy

Last updated August 2026

This page explains what JUTSU does with personal data — both on this website and inside a customer deployment. It is written to be read, not to be survived.

This website

The marketing site sets no advertising or cross-site tracking cookies. A single entry in your browser’s local storage records whether you dismissed the announcement bar and which colour theme you chose. Both stay on your device and are never transmitted.

If you email us from a link on this site, we receive whatever you send — typically your name, address and the contents of your message — and use it only to reply.

Inside a deployment

JUTSU runs inside your own cloud or VPC. We do not host your corpus and we do not receive a copy of it. Within a deployment:

  • Connectors are read-only. Nothing is written back to a source system.
  • Permissions are inherited from each source at ingestion and enforced again at query time, so a result only surfaces for someone who could already open the underlying document.
  • Personal identifiers are masked during ingestion.
  • Data is encrypted in transit and at rest.
  • Every query and every answer is written to an audit trail.

Knowledge-risk scoring

Bus-factor scores are reported in aggregate by default. Individual-level scoring is off unless a customer explicitly enables it, and enabling it is a decision for that customer to make with notice to the people affected. A data protection impact assessment is completed before any live pilot.

Your rights

Where the DPDP Act 2023 or the GDPR applies, you may request access to, correction of, or deletion of your personal data. For data held inside a customer deployment, that customer is the controller and we act on their instructions — contact them first, and we will support the request.

Contact

Questions about this policy: hello@jutsu.dev.