Jai
Last updated 9 September 2026.
Privacy Policy
Jai turns your travel booking emails and receipts into a trip you can see at a glance. This
page explains what we access, what we store, who else can see it, what we never do, and how to
delete your data.
What we access
Your Gmail inbox — only if you connect it. If you turn on automatic
import, we request the gmail.readonly scope — read-only access to your mail.
This is requested as its own, separate permission step, never bundled into signing in with
Google. Before we read a message, a simple filter checks whether it looks like a booking;
messages that don't are skipped and never sent to our extraction step. You can disconnect at any
time from Settings, which revokes our access at Google immediately.
Email you forward to us. If you'd rather not connect your inbox, you can
forward a booking confirmation instead. We only ever process the message you chose to send.
Your camera or photo library — only when you add a receipt or a profile
photo. Jai asks for access at the moment you attach a receipt to an expense or choose a
photo for your profile, and only receives the image you pick. We don't browse your photo library
and we don't read anything else from it.
Jai's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
What we store
- The trip details we extract from a booking confirmation — flight numbers, dates,
confirmation codes, hotel names, and similar — so we can show you your trip.
- The original email, kept so a booking can be re-processed if something goes wrong. It's
held as a file in separate storage, not inside the database that runs Jai — that
database holds the trip details we extracted and a reference to the file, not your mail. The
file is never changed once written.
- Receipt photos you add, and the amounts, dates, and merchant names we read from them.
- Your profile photo, if you set one. It's stored as an image file in the same separate
storage as the rest — the database holds a reference to it, not the picture — and
it's shown to the people you share a trip with, wherever your name appears. Setting one is
optional; without it, Jai draws your initials.
- The expenses you record — amounts, currency, who paid, and how a cost is split
among the people on the trip.
- If you connect Gmail import, an encrypted copy of the access token that lets us check
your inbox on your behalf. It's encrypted (AES-256-GCM) with a key only our server holds,
and it is never visible to us in plain text, never logged, and never shared.
- Your trip's destination, and — only when you pick it from the city list built into
the app rather than typing it freely — that city's approximate centre point. It comes
from a list of cities shipped inside Jai, so it describes the city you chose, not where you
are. Jai does not ask for, receive, or store your device's location. We keep it so the place
suggestions in a plan can be near your trip instead of near our servers.
- Basic account information: your email address and anything you tell us directly (like a
trip name).
- If you ask to be kept posted because Jai is invite-only and you don't have an invite
yet, the email address you typed — and nothing else. It's stored only so we can let
you know when you can join.
- When someone tries to make an account and Jai turns them away, we record that it
happened, the reason, and which sign-in method was used — with a one-way scrambled
version of the email address rather than the address itself, so we can tell one person
trying five times from five different people, and can't email anyone from it.
Who else can see your trip
Trips in Jai are meant to be shared. When you invite someone to a trip, they can see that
trip's plans, expenses, and receipts, and they can see who paid for what. They cannot see your
other trips, your inbox, or anything from a trip they aren't on.
You can also open a trip in a browser at trips.myjai.app. That page requires
signing in and shows exactly what the app would show the same person — it is not a public
link, and it isn't indexed by search engines.
What we never do
- We never sell your data, to anyone, for any reason.
- We never use your emails, receipts, or trip data for advertising, and we don't build
advertising profiles from them.
- We can never send, delete, or change anything in your mailbox. The access we ask for is
read-only, so writing to your inbox isn't something Jai is able to do.
- No one at Jai reads your email content as a matter of course. The only exception is a
genuine security investigation (for example, checking for abuse) or where we're legally
required to — and even then, access is limited to what's necessary.
Retention and deletion
We keep your trip data and connected-inbox access for as long as your account is active, so
Jai keeps working the way you'd expect.
A receipt photo that isn't attached to anything — you started adding one and didn't
finish — is deleted automatically within seven days. A receipt attached to an expense is
kept for as long as that expense exists, so the paper is still there when someone questions the
number.
Your profile photo is kept until you remove or replace it. When you replace it, the previous
picture is deleted; when you remove it, so is that one, and Jai goes back to drawing your
initials.
If you disconnect Gmail import, we stop reading your inbox immediately and delete the stored
access token — trips already created are unaffected.
If you left your email to be kept posted about joining, it is deleted automatically the
moment you're invited to a trip or an account is made with that address — that happens
on its own, not on request. If neither ever happens, we keep it until you ask us to remove it;
email us at the address below and we will. The turned-away-signup records described above are
deleted after 30 days.
To delete your account and everything we've stored about you, email us at the address below
and we'll delete it. (We're building a self-serve "delete my account" option directly into the
app; until it ships, this email request is the path.)
Who else touches your data
A small number of specialist companies process parts of your data so that Jai can work. None
of them are permitted to use it for their own purposes, and none of them are advertisers or
data brokers. We describe them below by the job they do — and if you'd like the current
list by name, email us at the address at the bottom of this page and we'll send it to you.
- Cloud infrastructure — hosts our database, runs our backend, and
stores incoming email, trip attachments, receipt photos, and profile photos. Each of those
sits in its own separate store, so a rule that suits one kind of file is never applied to
another.
- Google (Gemini API) — reads a booking confirmation's text, and a
receipt photo's contents, to pull out the details (dates, flight numbers, totals, and so on).
This is the model we use for every real extraction. We name this one rather than describing
it by role, because it is the step where your mail is actually read by a machine, and you
should know exactly who does that.
- Google (Maps Platform — Places) — when you type a place or an
address into a plan, what you type is sent to Google's Places service to suggest matches, along
with your trip's destination city so the suggestions are nearby. The same happens when you type
a destination while starting a trip — there, nothing about a trip is sent (there isn't one
yet), and picking a suggestion sends nothing further: Jai keeps the name you chose and looks up
its coordinates in its own offline city list. Google doesn't receive your
name, your account, or anything else about your trip. The suggestions are Google Maps content:
using them is subject to the Google Maps
Additional Terms of Service and the Google
Privacy Policy. What you pick is saved to your plan as your own text.
- A second AI provider — used only for internal quality testing and
comparisons. Real bookings are not sent to it.
- Email delivery — sends transactional email, like a trip invite.
- Push notifications — delivers notifications to the Jai app,
including the text shown on the notification. On Android, on the day you travel, Jai may also
show an ongoing notification on your lock screen carrying that flight's status — its
gate, its times, and where it is in the day — delivered through the same provider.
Turning off the “Live day-of” notification category stops it, and swiping the
card away stops it for that flight; unpinning it keeps the card but takes it off the status
bar.
- Travel data — a flight-status service receives a flight number so
we can tell you about a delay or a gate change, and a weather service receives a destination
name and its coordinates so we can suggest what to pack. Neither receives anything that
identifies you.
- Error monitoring — receives crash and error reports from the app so
we can fix problems. These reports never include the contents of your email, and we strip
access tokens and invite links from them before they're sent.
Changes to this policy
When Jai starts doing something new with your data, we update this page at the same time as
we ship the change, and move the date at the top. If a change is significant — a new kind
of data, or a new company touching it — we'll tell you in the app rather than relying on
you to re-read this page.
Contact
Questions, requests, or concerns: hello@myjai.app.
← Back to myjai.app