Privacy Policy
Last updated: September 20, 2026
This policy covers the JevBot by Legety website, the Chrome extension, and the hosted gateway at https://jevbot.legety.com (together, the “Service”), operated by Legety, registered in Georgia(“we”, “us”, “our”). It does not cover the open-source jev_ultrafast Python package run entirely on your own machine with your own API keys — that path never talks to our servers, so we never see anything it does. See “Bring your own key” below for what changes when you use the extension that way instead. For detailed disclosures regarding the Chrome Extension permissions and Chrome Web Store User Data compliance, see our dedicated Chrome Extension Privacy Policy.
1. What we collect
Account data
Sign-in is passwordless: you give us an email address, we email a sign-in link, and we set a session cookie when you use it. We store the email, an optional display name, and the account's role. We do not collect or store a password.
Billing data
Subscriptions and credit packs are sold through Paddle, our payment processor and, for tax and consumer-law purposes, the merchant of record. Paddle collects your card details, billing address, and VAT information directly — we never see or store full card numbers. We keep the Paddle customer ID, subscription ID, plan name, billing interval, and subscription status Paddle sends us, so the account page can show your plan and so a webhook replay cannot double-grant credits.
Usage and metering data
Every decision, text-generation, or transcription call the extension makes through our gateway is logged: which route was used, which model answered, the credits it cost, the run it belonged to, and a timestamp. This is how the credit meter works and how we investigate billing disputes. It is not page content — see the next section for that.
What the agent sends to run your task
When the extension runs against our gateway, doing its job requires sending the model provider what it needs to decide the next action: a structured snapshot of the visible page (control labels, values, and text — not screenshots, in the default loop), your typed goal, and, if you use the microphone shortcut to dictate a goal, the resulting audio clip for transcription. This is forwarded to the upstream inference provider (currently OpenRouter, routing to the underlying model) to generate a response, and is not stored by us beyond the metadata described above. Because the extension can act on any page you have open, avoid pointing it at pages showing information you would not want included in a model prompt — passwords, payment forms, and other people's personal data included.
Extension pairing
Connecting the extension to a plan uses a short-lived pairing code you copy from the account page into the extension, exchanged once for a long-lived bearer token stored in the extension's local storage on your device. We store the token's issuance record, not the page content it is later used to process.
Product analytics
We keep a small, first-party event log (e.g. “checkout completed”, “trial started”) tied to your account, used to understand product usage and debug billing. We do not run third-party analytics, advertising, or tracking scripts on the site or in the extension.
Support email
If you email support@legety.com, we keep that correspondence to answer you and to improve the Service.
2. Bring your own key
The extension and the Python package both work without an account: you supply your own OpenRouter (and, for the package, TypeSafe) API key, and the extension or package talks to that provider directly. In that mode, we do not receive your goal text, page content, audio, or API key — your relationship for that processing is between you and the model provider you chose, under their own privacy terms.
3. Why we process this data
- To create and secure your account, and to keep you signed in (contract necessity).
- To run the plan and pay-as-you-go billing — provisioning credits, charging renewals, and reconciling usage against Paddle's webhooks (contract necessity).
- To execute the browser actions you ask the agent to perform, by forwarding what that requires to the model provider (contract necessity, at your direction).
- To detect abuse of the model allowlist and rate limits, and to keep the gateway solvent (legitimate interest).
- To respond to support requests (legitimate interest / contract necessity).
4. Who we share it with
We do not sell personal data, and we do not share it for advertising. We share only what each of the following needs to do its job:
- Paddle — payment processing, tax/VAT handling, and subscription management. Paddle acts as merchant of record for these transactions.
- OpenRouter (and the underlying model it routes to) — to run the decision, text-generation, and transcription calls the agent makes on our hosted gateway.
- Resend — to deliver sign-in links and billing emails.
- Our hosting and database provider, to run the Service.
We may also disclose data if required by law, to enforce our Terms of Service, or to protect the rights, property, or safety of Legety, our users, or others.
5. Where data is processed
Our infrastructure and the providers above may process data outside the country you are in, including in the United States and the European Union. Where that requires a transfer mechanism under applicable law (such as EU Standard Contractual Clauses), we or our processors put one in place.
6. How long we keep it
- Account records: for as long as the account is open, then deleted or anonymized within 30 days of a deletion request, subject to §7.
- Sign-in links and pairing codes: single-use and short-lived; expired/consumed rows are periodically purged.
- Usage ledger and credit grants: retained for the life of the account and for a reasonable period after, for accounting, tax, and fraud-prevention purposes.
- Support email: kept as long as needed to resolve and reference the request.
7. Your rights
Depending on where you live (for example under the GDPR if you are in the EEA/UK, or the CCPA/CPRA if you are a California resident), you may have the right to access, correct, export, or delete your personal data, to object to or restrict some processing, and to lodge a complaint with your local data protection authority. We do not sell personal data and there is no “sale” or “sharing” to opt out of. To exercise any of these rights, email support@legety.com from the address on your account; we may need to verify you before acting on the request. Closing your account from the account page stops future billing immediately; write to us if you also want the account record itself deleted.
8. Security
Sessions are signed, httpOnly, secure cookies; extension tokens are bearer credentials scoped to your account and revocable by re-pairing; sign-in links and pairing codes expire and can only be used once. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.
9. Children
The Service is not directed to, and we do not knowingly collect personal data from, anyone under 16. If you believe a child has given us personal data, contact us and we will delete it.
10. Changes to this policy
We will update the date at the top of this page when this policy changes, and, for material changes, make reasonable efforts to notify account holders by email.
11. Contact
JevBot by Legety is operated by Legety, Georgia. For privacy-related inquiries, contact us:
- Email: support@legety.com
- Phone: +995555169986