JAWZPrivacy

Privacy Policy

Last updated: 2026-10-02

There are two pieces to the Jawz ecosystem, and they handle data differently — so this page covers each one separately. Jawz is a hosted service your AI connects to for the Loop framework and the live market read. Rumo is an optional, local-first companion that keeps your investment memory in plain files on your own machine; it is not available to download at the moment, and this policy still describes it because it keeps running on the machines of everyone who already installed it. Jump to Jawz or Rumo.

Jawz — the hosted service

Jawz is a hosted Model Context Protocol (MCP) server you connect to from your AI assistant (such as Claude or ChatGPT). It serves the Jawz Loop framework and market-data tools. You stay in your own AI app throughout. Jawz is a connector your assistant calls; it is never the AI model itself.

Jawz does not store your portfolio. Symbols and quantities you ask about are used to answer that one request and are then discarded.

1. What personal data we collect

  • Account details — if you sign in (OAuth): a user identifier and the email address supplied by that sign-in.
  • Usage records — which tool, chapter, or mode you ran, when, whether it succeeded, how long it took, and which AI client you used. These records contain no portfolio content.
  • A one-way hash of any context you send — when a loop is run with context (which may describe a portfolio), only an irreversible cryptographic hash of that text is kept, so repeat runs can be recognised. The text itself is never written down.
  • Feedback you or your AI submit about a run — a rating and any comment you choose to include.
  • A daily anonymous identifier — if you connect without signing in, Jawz derives a short irreversible fingerprint from your IP address, browser/agent string, and the current date. Your IP address itself is never stored, the fingerprint cannot be reversed, and it changes every day, so activity cannot be linked across days. It exists to apply fair-use limits and to count how many agents use the service.
  • Anonymous page views of this website — the page requested, the browser or agent string, the origin you arrived from (never the full address), and the same daily anonymous identifier described above. We keep it to answer one question: how much of our traffic is people reading, and how much is AI agents fetching. No cookie is set and nothing is shared with an analytics provider.
  • Your email address, if you subscribe to the Monday brief — from the form on this site, from the Rumo app when you tick its box, or because you asked us to add you. We keep the address, where the subscription came from, and the date. Every brief carries a one-click link to stop it, and replying “stop” works too; the address is then marked unsubscribed and receives nothing further.
  • Your email address, if you connect the Rumo app — Rumo asks for an email before it shows the live Jawz reading. We keep the address, the app version, when it first connected and when it was last seen. Connecting does not subscribe you to anything; the brief is a separate box you choose to tick. Rumo never sends your holdings, values or anything in your vault.
  • Anonymous download events when Rumo was downloaded from this site — version, referrer, and browser, with no identity attached. The download is currently unavailable; events already recorded are kept under the same terms.

2. Why we collect it

  • Account details — to recognise you across sessions and manage access.
  • Usage records — to keep the service running correctly and to see which parts of the framework earn their place.
  • Context hash — to recognise a repeated run without holding the underlying text.
  • Feedback — to revise the published framework.
  • Daily anonymous identifier — to enforce fair-use limits and count adoption.
  • Download events — to see which releases are being installed.
  • Brief subscriptions — to send the brief you asked for, and nothing else.
  • App connections — to know who uses Jawz through Rumo, and to reach them if the service changes. An app connection receives no marketing unless it also subscribed to the brief.

We do not sell personal data, use it for advertising, or use it to build profiles of you.

3. What we never collect or store

  • Your holdings, quantities, positions, or written thesis. These are held in memory only long enough to answer the request you made, and are not written to any database.
  • Brokerage credentials, passwords, or payment details.
  • Advertising identifiers or third-party tracking pixels.

4. Who your data is shared with

  • Market-data providers (Finnhub, CoinGecko, Yahoo Finance) — when you ask for a price, they receive the ticker symbol only. They do not receive your identity, your quantities, or anything else about you.
  • Public data sources (the U.S. Federal Reserve’s FRED, the University of Michigan, fund providers) — these are read on a schedule for everyone. No data about you is sent to them.
  • Infrastructure providers acting on our instructions — Vercel (hosting), Supabase (database), Upstash (short-lived cache), Namecheap Private Email (the hello@jawz.ai mailbox that sends the brief). They process data to run the service and for no purpose of their own.
  • Your own AI provider (Anthropic, OpenAI, or whoever runs your assistant) — what you type into that assistant is governed by that provider’s policy, not this one.
  • We do not share personal data with anyone else, and we do not sell it. We may disclose data if required by law.

5. How long we keep it

  • Account details — for as long as the account exists, then deleted within 30 days of a deletion request.
  • Usage records and context hashes — 24 months, then deleted.
  • Feedback — for as long as the loop it refers to is published.
  • Daily anonymous identifier — the fingerprint expires within 24 hours. Only aggregate counts, which identify nobody, are kept after that.
  • Download events — 24 months.
  • Brief subscriptions and app connections — until you unsubscribe or ask us to delete them. An unsubscribed address is kept only as “do not send”.
  • Cached market data — hours to days; it contains nothing about you.

6. Your choices and controls

  • Use it without an account. Every read tool — market data, the macro read, and the Loop chapters — works with no sign-in at all. Signing in is only needed to save preferences and submit feedback.
  • Ask what we hold. Email hello@jawz.ai and we will tell you what is stored against your account.
  • Ask us to delete it. Email the same address; we action deletion requests within 30 days.
  • Correct it. If something we hold about you is wrong, tell us and we will fix it.
  • Send no context. Nothing requires you to describe your portfolio. The framework chapters and market data work without it.
  • Depending on where you live, you may have additional rights over your data. Ask at the address above and we will honour them.

Rumo — the local companion

Not currently distributed from this site. Nothing below changes for existing installations: Rumo runs on your machine, so removing the download neither reaches your vault nor alters how your data is handled.

Your vault never leaves your device. Rumo talks to one service of ours, Jawz, and only for the things listed below.

Rumo is a local MCP server you install into Claude Desktop as an extension. It reads and writes a vault — a folder of plain Markdown and JSON files — in a location you choose on your own computer (or your own iCloud/Dropbox folder).

  • What Rumo sends to Jawz. While the app is open it fetches the public Jawz reading every few minutes, identifying itself only as “Rumo” and its version — the same request any visitor’s browser makes. If you choose to connect, it sends the email address you type, and, only if you tick the box, a request to subscribe that address to the Monday brief. When you ask it to value your book, it sends the symbols to price, as described in the Jawz section. Nothing else: no holdings, quantities, values, notes or files from your vault.
  • Your data lives only in your vault folder, on your device. If you place it inside iCloud Drive or Dropbox, it syncs across your own devices through your own account with that provider, under that provider’s policy — Rumo still never sees or transmits it. Uninstalling Rumo does not delete your vault.
  • Permissions: Rumo’s only access is the vault folder you select at install. It does not read other files, your browser, your accounts, or your network beyond talking to your local Claude app and the Jawz requests described above.
  • Third parties: your own Claude application (governed by Anthropic’s policy), and Jawz — for the live reading, the optional connection and brief subscription, and the symbols to price when you ask to value or refresh your book, as described above. Rumo makes no other third-party calls.

Both products

Children. These are tools for managing one’s own investments and are not directed at children.

Changes. If this policy changes, the updated version is posted here with a new “Last updated” date.

Contact. Questions about this policy or either product: hello@jawz.ai.