ACCESS · JD AI Systems

Privacy Policy

Effective date: June 6, 2026 · Last updated: August 16, 2026

This Privacy Policy describes how JD AI Systems, LLC (“Company,” “we,” “our,” or “us”) collects, uses, protects, and discloses information when you use the ACCESS platform and JYSON (“Service”). Our primary headquarters is in Tampa, Florida; our secondary headquarters is in Atlanta, Georgia (opening 2026).

This policy is written to match the product as built. It is not a claim that we cannot be sued, that we are fully compliant with every AI statute worldwide, or that we are a controller under the Florida Digital Bill of Rights. FDBR controller duties attach to companies that meet a high revenue or specified-platform threshold we do not claim to meet. We still honor access, correction, deletion, and export as product rights, and we follow Florida FIPA and Georgia breach-notification law, which do apply.

Public JYSON at jyson.app also has jyson.app privacy. Signed-in ACCESS use is this page.

1. Who This Policy Applies To

This policy applies to users of ACCESS and signed-in JYSON. You must be at least 18 years old. JYSON is not a children’s product. It may not be suitable for some minors.

2. Information We Collect

Account Information

  • Name, email address, and username (via Clerk authentication)
  • ACCESS handle (e.g. username.access)
  • Profile details you choose to provide

Workspace Data (your world)

  • Projects, registry objects, assets, vault metadata, and systems you create
  • CRM contacts you enter or import (you own this data)
  • Knowledge base content and blueprints
  • JYSON conversations in your ACCESS world so JYSON can help you build — not so we can train Zin
  • Workflow configurations and execution logs

Visitor preview (jyson.app, not signed in)

  • A signed cookie that stores only a random id and a turn count (cap 6)
  • We do not store visitor chat bodies. That cookie is not merged into a later account.

JDAI public / social chat (Base App, Zora, Telegram, web)

JDAI also answers the public on crypto social surfaces (Base App wallet chat and Zora via XMTP), Telegram (@jdaisystemsbot), and a free web chat lane. These are not a signed-in ACCESS account. A wallet address or visitor id is not proof of identity.

  • What we store: inbound and outbound message text, channel and conversation references, hashed or truncated sender claims (for example a wallet address when XMTP provides one), rate-limit and abuse counters, optional short memory facts extracted from what you say, and escalation notes for human review.
  • Why: to reply, prevent loops and spam, enforce spend and free-tier caps, and keep a conversation coherent across turns.
  • What answers are not: not legal, medical, tax, or financial advice. Market data is informational. JDAI cannot send, swap, trade, or move funds in these chats.
  • Retention: kept in operational databases for the service and abuse control until deleted on a valid privacy request or as otherwise required by law.
  • Paid answers: researched answers may use x402 USDC on Base; payment metadata is handled by the payment facilitator and our till records — not as a substitute for this privacy notice.

Deep link for this section: getaccess.world/privacy#jdai-social.

Billing and Payment Information

  • Payments are processed by Stripe, Inc., a PCI-DSS-compliant payment processor. We do not store full card numbers or full bank account numbers. We store only Stripe Customer IDs and subscription metadata.
  • ACH Bank Transfer Authorization: If you choose ACH payment, your bank account information is provided directly to Stripe under their ACH authorization agreement. Stripe stores your bank account and routing details; we store only the Stripe payment method reference. ACH transactions are governed by NACHA rules. You may revoke ACH authorization at any time through the billing portal or by contacting us. Unauthorized ACH debits may be disputed with your bank within 60 days of the statement date in which the unauthorized transaction appeared.
  • Billing address and invoice history (via Stripe Billing)

Usage and Technical Information

  • Platform activity: pages visited, features used, commands executed
  • JYSON message counts and spend on the company ledger for billing and abuse control
  • IP address, browser type, device type, and operating system (including country for geo-availability)
  • Error logs and performance diagnostics for platform reliability

Communications

  • Email preferences and consent records
  • Support correspondence

3. How We Use Your Information

We process your information only for the following purposes:

  • Service delivery: Provide ACCESS, JYSON (the product you talk to), Zin (the model), and workspace tools
  • Billing: Process subscriptions, invoices, ACH authorizations, and refunds through Stripe
  • Security: Detect fraud, unauthorized access, and platform abuse
  • Transactional communication: Send receipts, security alerts, and service notices required by law or contract
  • Marketing (opt-in only): Send product updates and promotional offers you have explicitly consented to receive. We do not send unsolicited marketing.
  • Legal compliance: Meet applicable legal, tax, and regulatory obligations

We do not use your personal data for targeted advertising, profiling for decisions producing legal effects, or the sale of personal data to third parties. There is no “help improve JYSON” toggle. We do not put customer chats into a company improvement or training archive. De-identified “platform improvement” of conversation bodies is not a purpose of this product.

4. JYSON, Zin, and AI Processing

JYSON is AI, not a human. Zin is JYSON’s model. Outputs can be wrong. You review before you rely. JYSON is a workbench for thinking and building, not a companion, friend, or romantic partner. It is not a lawyer, doctor, lender, or hiring engine.

While Zin runs on contracted frontier engines, a turn is sent to the lab on the wire for that turn so the model can answer. We name them because the code actually calls them:

  • Anthropic, PBC — current default Zin engine on the ACCESS gateway (API / enterprise terms: we do not opt in to training on API customer content)
  • OpenAI, L.L.C. and Google LLC — possible routed engines on some signed-in ACCESS paths

JD AI Systems did not train those labs’ weights. Customer chats, vaults, and intent areyour world. JYSON reads them to help you. They are not used to adapt Zin. Company intelligence (our vault, our evals, licensed or open data) is a separate store. Those two stores do not mix.

Operator copies of a turn exist only as needed to run it (abuse, billing, security) and are not kept as a life-of-account improvement warehouse. Durable history lives in your ACCESS world, which you can export or delete with your account.

JYSON is not offered in the European Economic Area or the United Kingdom until we have legal readiness to operate there.

5. Information Sharing and Disclosure

We do not sell your personal information. We do not share your data with advertisers or data brokers. We may share information with:

  • Anthropic, OpenAI, Google — AI subprocessors for Zin turns, as described in Section 4
  • Stripe, Inc. — payment processing (PCI-DSS compliant, US-based)
  • Clerk, Inc. — authentication and identity management
  • Supabase, Inc. — database infrastructure for ACCESS (data stored in the United States)
  • Vercel, Inc. — platform hosting and edge computing
  • Legal and government authorities: When required by Florida law, federal law, court order, or to protect the safety, rights, or property of users or the Company
  • Business transfers: In the event of a merger, acquisition, or asset sale, personal data may be transferred. We will notify you via email before such transfer and your rights under this policy continue to apply.

Frontier labs process prompts under their API terms. We use API / enterprise no-training terms where offered. Their systems may still retain inputs for safety or legal hold under their own policies — that is a reason we treat rented engines as a bridge, not the product.

6. Your Rights (product + Florida / Georgia law that applies)

You may request access, correction, deletion, and a portable copy of your ACCESS world. We do not sell personal data. We do not run targeted advertising on your workspace. We do not use JYSON as an automated hiring, lending, housing, or government-benefits engine.

To exercise these rights, email support@jdwhite.world or use Settings → Account within your ACCESS workspace. We will verify identity before processing a request.

7. Data Breach Notification

In the event of a security breach affecting your personal data, we will notify affected users in accordance with both Florida and Georgia law.

Florida — FIPA (§ 501.171, Fla. Stat.)

  • Investigate and assess the breach promptly upon discovery
  • Notify affected Florida residents within 30 days of discovering the breach (or as soon as reasonably possible given the scope of investigation)
  • Notify the Florida Department of Legal Affairs if the breach affects 500 or more Florida residents, within 30 days of discovery

Georgia — Notification of Data System Breach Act (O.C.G.A. § 10-1-912)

  • Notify affected Georgia residents in the most expedient time possible and without unreasonable delay following discovery of the breach
  • Notify the Georgia Consumer Protection Division of the Office of the Attorney General if the breach affects 10,000 or more Georgia residents

All breach notifications, regardless of state, will include: a description of the incident, the categories of personal information involved, the approximate date of the breach, steps we are taking to address the breach, and recommended steps you can take to protect yourself. Notice will be delivered by email to the address on your account.

8. Data Retention

  • Your ACCESS world (including signed-in JYSON history): retained while the account is active; exportable on request; deleted with the account after the cancellation window below
  • Cancelled/deleted accounts: Workspace data preserved in read-only mode for 90 days, then permanently deleted, except where a legal hold or tax law requires a freeze
  • Operator copies of a turn: only what is required to run the turn (abuse, billing, security) — short-lived, not a company improvement archive
  • Visitor preview: cookie count only; no chat warehouse
  • Billing records: retained for 7 years as required by Florida and federal tax law
  • Security logs: retained for up to 12 months

A deletion policy yields to a preservation order. Architecture choice: we do not keep a second research pile of chats, so there is little extra to produce beyond what ACCESS already stores for you.

9. Security

We implement commercially reasonable security measures including: encryption in transit (TLS 1.2+), encryption at rest, strict access controls, and commercially reasonable practices across our service providers.

ACCESS data lives in Supabase (Postgres) under JD AI Systems. Customer world and company intelligence are separate stores. We do not build a third “JYSON database” that copies everyone’s chats. No security measure is 100% effective. If you discover a potential vulnerability, report it to support@jdwhite.world.

10. Email Communications

  • Transactional emails (billing receipts, security alerts, service notices): Required for account operation. Cannot be disabled.
  • Marketing and product emails: Require your explicit consent (opt-in). You may withdraw consent at any time through Settings → Notifications or the unsubscribe link in any marketing email. Opt-out requests are processed within 10 business days.

We comply with the Florida Electronic Commerce Protection Act, the Georgia Computer Systems Protection Act (O.C.G.A. § 16-9-90 et seq.), and applicable federal CAN-SPAM and TCPA requirements. We do not send unsolicited commercial email. We do not text or iMessage you from JYSON without a separate prior-consent ledger.

11. Deceptive and Unfair Trade Practices

We operate under the Florida Deceptive and Unfair Trade Practices Act (FDUTPA) (§ 501.201, Fla. Stat.) and the Georgia Fair Business Practices Act (GFBPA) (O.C.G.A. § 10-1-390 et seq.). We do not claim JYSON is a human, that outputs cannot be wrong, that Zin is another company’s named model, or that we cannot be sued.

If you believe we have engaged in any deceptive or unfair practice:

  • Florida residents: Contact us at support@jdwhite.world or file a complaint with the Florida Department of Agriculture and Consumer Services.
  • Georgia residents: Contact us at support@jdwhite.world or file a complaint with the Georgia Governor’s Office of Consumer Protection.

12. Children’s Privacy

ACCESS and JYSON are for people 18 and older. We do not knowingly collect personal information from anyone under 18. COPPA additionally protects children under 13; we do not offer a kids product. If you believe a minor has created an account, contact us immediately and we will delete the account and associated data.

13. Changes to This Policy

We may update this policy at any time. For material changes, we will notify you via email to the address on your account at least 14 days before the change takes effect. Your continued use of ACCESS after the effective date constitutes acceptance. You may always view the current policy at getaccess.world/privacy. Counsel may stamp a later long-form version; this page is the floor that matches the code.

14. Contact and Privacy Requests

For privacy requests, questions, or data rights requests:

  • Email: support@jdwhite.world
  • In-app: Settings → Account → Privacy Request

JD AI Systems, LLC
Primary headquarters: Tampa, Florida
Secondary headquarters: Atlanta, Georgia (opening 2026)
Governing law: State of Florida, Hillsborough County

Terms of Service · Privacy Policy · Safety · Acceptable Use · Cookies · Email preferences