Privacy Policy
Last updated: October 8, 2026
1. Introduction
Jery is operated by Jery, Inc., a Delaware corporation ("we," "us," or "our"). We provide a bar-management platform for hospitality teams, covering inventory, recipes, costing, menus, and AI-powered forecasting. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use Jery, whether through our website or the Jery mobile app for iOS and Android. One policy covers both; the mobile app is described in Section 13.
Jery, Inc. is the data controller responsible for your personal data. Jery is currently offered in a private beta. Jery is organized into workspaces, and content you create or upload may be visible to other members of your workspace.
2. Information We Collect
2.1 Information You Provide
- Account Information — Name, email address, and password when you create an account
- Workspace & Profile Information — Workspace details, team membership, and optional profile information you choose to provide
- Billing Information — If and when we introduce paid plans, billing details and payment card data will be collected and processed by our payment provider. We do not charge for the service during the private beta.
- Communications — Messages, support requests, and feedback you send to us
- Form Submissions — When you fill in one of our forms, such as the beta sign-up: your name, email address, role, bar or company, your other answers, and whether you asked to receive updates
- User Content — Content you create or upload, such as recipes, inventory data, menus, supplier invoices, sales data, and uploaded files and images
- Assistant Conversations — Your chats with the Jery assistant: the messages you send, the assistant's replies, the actions it takes for you (tool calls) and their results, and the text and files you share in a chat. Conversations are saved so you can return to them (see Section 3.1).
- Voice — If you use hands-free stock counting or, where offered, voice dictation, the audio the microphone picks up while it is on, which can include other people speaking nearby. For voice counting the audio is streamed live to OpenAI, which transcribes it, works out the counts and speaks the replies; Jery keeps no recording. The counts that save, with the words that produced each one, are saved as part of your workspace content.
- Venue Location — The address of your bar, if you enter it in workspace settings. As you type it, address suggestions come from Google Maps; we then use its coordinates to fetch local weather for forecasting. We do not collect your device's GPS location.
2.2 Information Collected Automatically
- Device Information — Device type, operating system, browser or app version, and, in the mobile app, a push notification token if you enable notifications. We do not collect advertising identifiers and do not track you across other companies' apps or websites.
- Usage Data — Pages visited, features used, actions taken, and time spent on the service
- IP Address — Your Internet Protocol address for security and analytics. The IP address recorded with a sign-in is kept for 90 days (see Section 5).
- Activity Records — A history of changes in your workspace: who created, changed, or deleted a record, when, and through which part of the service (for example the website, the mobile app, the assistant, or voice counting), together with security and team events such as sign-ins, invitations and role changes, support visits, exports, undone imports, and copies of a bar (see Section 3.3)
- Activity Signals — When you were last active, and a daily count of your requests in each area of the product (such as inventory, recipes, or the assistant), kept as one summary row per person, area, and day rather than a log of individual actions (see Section 3.3)
- Cookies — Essential authentication and security cookies, and analytics cookies (see Section 12)
- Error Reports — Technical error information to help us diagnose and improve the service
3. How We Use Your Information
We use the collected information to:
- Provide, maintain, and improve our services
- Process transactions and send related information (if and when paid plans are available)
- Send technical notices, updates, and security alerts
- Send onboarding emails that help you get started, and product updates about Jery; if you signed up through one of our forms, we send updates only if you asked for them. Every one of these emails has an unsubscribe link, and unsubscribing never stops the emails your account needs, such as sign-in codes
- Keep track of our relationships with customers, prospective customers, partners, and investors
- Respond to your comments, questions, and support requests
- Monitor and analyze trends, usage, and activities
- Detect, investigate, and prevent fraudulent or unauthorized activities
- Power AI-powered features using the content you submit to those features
- Deliver push notifications you have opted into on your mobile device
We do not sell your personal information, and we do not use your content to train AI models.
When you scan a bottle's barcode, our servers look the barcode number up in Open Food Facts, a public product database; the request carries only the barcode number, nothing about you or your bar. When you import a scanned product, its product facts (name, size, strength, category, and container) are added to a shared barcode database that helps other bars recognise the same bottle. What is shared never names your bar or anyone on your team, and never includes prices, stock, or anything else from your workspace. Undoing the import, or removing the barcode from the product, withdraws your bar's contribution.
3.1 Assistant Conversations
Authorised Jery staff may review assistant conversations, including the actions the assistant took and the content shared in them, and use what they learn to:
- Investigate and fix problems with the service
- Evaluate the quality and accuracy of the assistant's answers
- Improve the assistant's instructions and tools, and the rest of the product
- Help your bar get more out of Jery (customer success)
Reviewing and evaluating conversations is not the same as training AI models: we do not use your conversations, or any other content, to train AI models, and our AI providers may not use them for that purpose either (see Section 4). We do not copy the content of your conversations into test data; when a conversation reveals a problem, we reproduce it with made-up data. Each time staff read a workspace's conversations through our internal tools, it is recorded in that workspace's Activity Log (see Section 3.2).
3.2 Access by Jery Staff
A limited number of authorised Jery staff (platform administrators) can access workspace data to support customers, operate and improve the service, and help bars succeed:
- Support visits — A staff member can temporarily join a workspace to help, for at most 24 hours at a time. While they are there they appear in the workspace's member list, and the start and end of each visit are recorded in its Activity Log.
- Internal tools — Staff can read customer-success facts about each workspace and its members (see Section 3.3), account details (name, email address, sign-up and last-active times, and workspace memberships), a workspace's activity timeline and AI usage, and a named workspace's assistant conversations. The activity timeline shows what kind of change was made, by whom, and when, but not the names or values of the records changed.
Every read of a workspace's assistant conversations through these tools is recorded in that workspace's Activity Log, where its owners and admins can see it; the entry says what was read, without naming the conversation or who it belongs to. All use of these tools is also logged internally.
3.3 Activity and Audit Records
- Record history — Records such as ingredients, recipes, pre-batches, menus, suppliers, and glassware keep a history of who created, changed, or deleted them and when. Every member of the workspace can see a record's history.
- Activity Log — Workspace owners and admins can see the whole workspace's activity, including changes to the team and the bar's settings, and security events: sign-ins, support visits, exports, undone imports, copies of the bar, and staff reads of assistant conversations. Sign-in events also store the IP address used; it is not shown in the Activity Log and is deleted after 90 days.
- Activity signals — We record when each person was last active in each workspace and a daily summary of how many requests they made in each area of the product. These are used to understand how the service is used and to support customers, and are not shown to other workspace members. Staff support visits are not counted.
- Customer-success snapshots — For Jery staff only, we regularly calculate a summary of facts about each workspace (such as activity, the amount of content, milestones reached, and AI usage) and about each of its members (such as name, email address, role, and recent activity).
4. Third-Party Services & Subprocessors
We rely on the following third-party services (subprocessors) to operate Jery. They process data on our behalf and on our instructions, only to provide the service described, and are bound by their own privacy commitments. We do not sell your data to any of them, and none of them may use your content for their own purposes, including training AI models.
Neon (Database)
Purpose: PostgreSQL database hosting
Data shared: Account information, user and workspace content, application data
Neon Privacy PolicyCloudflare R2 (File & Image Storage / CDN)
Purpose: File and image storage and content delivery
Data shared: Uploaded files, AI-generated images, and associated metadata
Cloudflare Privacy PolicyStripe (Payments)
Purpose: Payment processing (only if and when paid plans launch)
Data shared: Billing details, payment card data, transaction history
Stripe Privacy PolicyResend (Email)
Purpose: Sign-in codes and security email, and receiving supplier invoices emailed to your bar's invoice address
Data shared: Email address, name; invoice emails sent to your bar and their attachments
Resend Privacy PolicyLoops (Email)
Purpose: Product, onboarding, account, and marketing email, and your email preferences
Data shared: Email address, name, role, bar name, and product milestones (such as signing up or publishing a first menu)
Location: United States (Standard Contractual Clauses)
Loops Privacy PolicyAttio (CRM)
Purpose: Managing our relationships with customers, prospective customers, partners, and investors
Data shared: People and companies we work with and our relationship with them, and a summary of each account (role, bar, sign-up date, and whether you want our emails)
Transfers: Standard Contractual Clauses
Attio Privacy PolicyTally (Forms)
Purpose: Our sign-up and survey forms, such as the beta sign-up
Data shared: The answers you give in a form
Location: European Union
Tally Privacy PolicyOpenRouter (AI Gateway)
Purpose: AI model gateway that routes assistant requests to model providers
Data shared: Prompts and content you submit to AI features
OpenRouter Privacy PolicyAI Model Providers (Anthropic, OpenAI, Google)
Purpose: AI models powering chat assistance, document and invoice reading, recipe import, voice transcription, search indexing, and image generation. We reach them through OpenRouter or directly; they may serve requests from their own infrastructure or from cloud platforms that host their models.
Data shared: Prompts, uploaded documents and images, product names, and voice audio you submit to AI features
OpenAI (Voice counting)
Purpose: Real-time speech recognition, understanding and spoken replies for hands-free stock counting
Data shared: Microphone audio while a voice session is on (which can include voices of people nearby), the transcript of what was said, the names, sizes and shelves of the bottles in your workspace used to recognise it, and short notes of the counts you type or scan during that session. Audio and transcripts are processed live and are not used to train OpenAI's models. We ask OpenAI not to store the sessions; like all its API traffic, OpenAI may keep abuse-monitoring logs for up to 30 days under its own policy.
OpenAI Privacy PolicyExpo (Push Notifications)
Purpose: Delivering push notifications to the mobile app via Apple and Google's notification services
Data shared: Push notification token and the content of notifications you have opted into
Expo Privacy PolicyOpen-Meteo (Weather)
Purpose: Local weather data used in sales forecasting
Data shared: The coordinates of your venue's address only. No personal data is sent.
Open-Meteo Terms & PrivacyGoogle Maps Platform and Google Fonts
Purpose: Address suggestions when you set your venue's location, and font delivery for menu designs and shared pages
Data shared: The address text you type, and your IP address when fonts are loaded
Google Privacy PolicyVercel and Railway (Hosting)
Purpose: Hosting the website and application servers that run Jery
Data shared: All data passing through the service, including IP addresses and request logs
Inngest (Background Jobs)
Purpose: Background job processing
Data shared: Event data necessary to run jobs
Inngest Privacy PolicyPostHog (Analytics)
Purpose: Product analytics
Data shared: Usage events, device information, IP address
PostHog Privacy PolicySentry (Error Monitoring)
Purpose: Error monitoring
Data shared: Error reports, stack traces, device information
Sentry Privacy Policy5. Data Retention
We retain your personal information for as long as necessary to:
- Provide our services to you
- Comply with legal obligations
- Resolve disputes and enforce our agreements
When you delete your account, we will delete or anonymize your personal information within 30 days, except where we are required to retain it for legal purposes.
- Record history and Activity Log — Kept for as long as the workspace exists. The IP address recorded with a sign-in is deleted after 90 days. When you delete your account, the IP addresses you signed in with and your name and email address in team entries are removed; entries describing what you did remain in the workspace's history, attributed to a deleted user.
- Activity signals — Deleted when the workspace is deleted or when you delete your account. If you leave a workspace, your daily summaries stay with that workspace until your account is deleted.
- Email and CRM — When you delete your account, we delete your contact in our email service (Loops). In our CRM (Attio) we remove your account ID and role and mark the account deleted; the record of our business relationship with you stays. If you had unsubscribed, bounced, or reported our email as spam, we keep a one-way hash of your email address, which cannot be turned back into the address, so that we never email you again by mistake.
- Customer-success snapshots — A member's snapshot is deleted at the next update after they leave the workspace, and when they delete their account. Daily copies of a workspace's snapshot are kept for 90 days, then one per week for as long as the workspace exists.
6. Your Rights
Depending on your location, you may have the right to:
- Access — Request a copy of your personal data
- Rectification — Request correction of inaccurate data
- Erasure — Request deletion of your personal data
- Portability — Request transfer of your data in a machine-readable format
- Restriction — Request limitation of processing
- Object — Object to processing for marketing or legitimate interests
- Withdraw Consent — Withdraw consent where processing is based on consent
To exercise these rights, contact us at support@jery.ai or use the account settings in the application. You can delete your account yourself at any time from Settings on the website or in the mobile app; we confirm the request by email before deleting.
7. Data Security
We implement appropriate technical and organizational measures to protect your personal data, including:
- Encryption of data in transit (TLS/SSL) and at rest
- Secure authentication mechanisms
- Access controls and audit logging
- Staff access to customer data limited to authorised personnel and recorded (see Section 3.2)
- Secure infrastructure hosted on reputable cloud providers
However, no method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.
8. International Data Transfers
Jery, Inc. is based in the United States, and your information may be processed in the United States and other countries where we or our subprocessors operate. These countries may have different data protection laws than your country of residence. For transfers from the EEA, UK, or Switzerland, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses (SCCs) or applicable adequacy decisions.
9. Children's Privacy
Jery is intended for business and professional use and is not directed to anyone under the age of 16. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us so we can take appropriate action.
10. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have additional rights:
- Right to know what personal information is collected and how it's used
- Right to delete personal information
- Right to opt-out of the sale of personal information (we do not sell your data)
- Right to non-discrimination for exercising your privacy rights
11. European Privacy Rights (GDPR)
If you are in the European Economic Area (EEA), UK, or Switzerland:
- Legal Basis: We process your data based on consent, contract performance, legal obligations, or legitimate interests
- Data Controller: Jery, Inc. is the data controller for your personal data
- Supervisory Authority: You have the right to lodge a complaint with your local data protection authority
12. Cookies and Tracking
We use the following types of cookies:
- Essential Cookies: Required for authentication and security (cannot be disabled)
- Analytics Cookies: Help us understand how you use the service (PostHog)
You can control cookies through your browser settings, though disabling essential cookies may affect service functionality.
13. Mobile App
The Jery mobile app for iOS and Android shows the same product as the website inside the app, with native sign-in, settings, and notifications. Everything in this policy applies to the app. In addition, the app may ask for the following device permissions. Each one is optional and can be changed at any time in your device's settings. Microphone, camera, and photo access are requested only when you first use the related feature; notification permission is requested when you first sign in.
- Microphone — Used for hands-free stock counting, where you say counts out loud while walking your shelves. Audio is captured only while voice counting is on, and it hears whoever is close by, so people near you may be picked up too. It is streamed live to OpenAI for transcription and the spoken replies, and is not stored as a recording by Jery. The microphone goes quiet the moment the app goes to the background, and voice turns itself off a minute later, after a few minutes with no count, or when you leave the count. Nothing is recorded in the background.
- Camera — Used when you open the barcode scanner, which reads barcodes and bottle labels while the scanner screen is open, and when you choose to take a photo to upload, such as a supplier invoice, a document, or an image you attach to a message. Photos of bottle labels are sent to our AI provider to read the printed text. A label photo taken while scanning bottles to add them is kept with that scan and deleted after 30 days; a label photo taken during a stock count is read once and not stored. The app never opens the camera on its own.
- Photos — Used only when you choose a picture from your library to upload, such as your profile photo, an invoice, or an image you attach to a message. We receive only the images you select.
- Notifications — If you allow push notifications, we store a push token for your device so we can send you notifications about your workspace. Turn them off at any time in your device settings; the token is deleted together with your account.
The app does not request your device's location; weather-based forecasting uses the address you enter for your venue. The app does not use advertising identifiers, does not track you across other apps or websites, and contains no third-party advertising. Product analytics and error reporting in the app work as described in Sections 2.2, 4, and 12.
All data sent between the app and our servers is encrypted in transit using TLS. We do not process payments inside the app; if and when paid plans launch, billing is handled by Stripe through our website, and the app never collects payment card data.
Your account and data are the same whether you use the app or the website. You can delete your account from the app's Settings screen, and deleting it removes your data as described in Section 5.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date. Your continued use of the service after changes constitutes acceptance of the updated policy.
15. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us:
- Email: support@jery.ai
- Website: https://jery.ai
See also our Terms of Service for information about your rights and responsibilities when using our service.