1. Who we are and what this policy covers
JupiterAI ("JupiterAI", "we", "us" or "our") is based in Western Australia, Australia and provides the Signal Lights macOS application, website, subscription, licensing, recovery and support services (together, the "Services").
This policy describes how we manage personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles where they apply. It does not govern OpenAI, Anthropic, Stripe, Google or websites and services that have their own privacy policies.
2. Our local-first approach
Signal Lights reads limited information on your Mac so it can show whether supported Codex and Claude Code tasks are working, waiting, finished or read, and so it can return you to a task. This may include local task identifiers, titles, timestamps, lifecycle state and bounded local history needed to determine status.
Signal Lights does not automatically upload prompts, conversation bodies, tool inputs, tool results, source files or terminal output to JupiterAI. We do not create a cloud copy of your conversations. Integration choices and display preferences are stored locally.
3. Information we collect
Purchases and subscriptions
When you subscribe, we receive your checkout email address, plan, subscription status, renewal information and identifiers assigned by Stripe. Stripe processes your payment card and billing details. We do not receive or store your full card number.
Licensing and devices
To activate and validate your subscription, we process a randomly generated installation identifier, app version, activation and last-seen dates, subscription status, activation token, and licence information. Licence keys and authentication tokens are encrypted or cryptographically hashed where appropriate. The activation token is stored in your macOS Keychain.
Subscription recovery
If you request a recovery email, we process the email address you submit and a cryptographic hash of that address and your IP address for security and rate limiting. Recovery links and browser sessions use short-lived, one-time tokens. The essential sl_recovery cookie is HttpOnly, lasts for up to 30 minutes and is used only to display and manage the recovered subscription.
Feedback you choose to send
The current app does not collect response-time analytics or upload daily usage totals. If you choose Report an issue, Signal Lights sends the provider, your description, app version, installation identifier and selected screenshot to JupiterAI. The report is stored in our support database and emailed to the support team. The screenshot may contain conversation information, so hide anything private first.
Website, support and technical records
Our hosting and security systems may process standard request information such as IP address, date and time, requested page, browser or app version, device type and error information. If you contact us, we collect the contact details and content you provide so we can respond and keep an appropriate support record. We do not use advertising cookies or behavioural advertising in the Services.
4. How we use information
We use information only where reasonably necessary to:
- process and administer subscriptions, invoices, renewals and cancellations;
- issue, activate, validate, restore and secure licences for up to two Macs;
- operate, maintain, troubleshoot and improve the Services;
- send transactional messages, including recovery and device-removal notices;
- respond to support, privacy and legal enquiries;
- prevent fraud, abuse and security incidents; and
- comply with accounting, tax, consumer, privacy and other legal obligations.
We do not sell or rent personal information, and we do not use your conversation content to train AI models.
5. When we disclose information
We may disclose limited information to service providers that help us operate the Services, including:
- Stripe, for checkout, payment, invoices and subscription management;
- hosting and database providers, for the website, licensing and recovery systems;
- Google, when Gmail infrastructure delivers transactional or support email;
- professional advisers, insurers and contractors who are subject to appropriate confidentiality obligations; and
- regulators, courts, law enforcement or other parties where required or authorised by law, or where reasonably necessary to protect rights, safety and security.
If the business or the Services are reorganised or transferred, relevant records may be disclosed to advisers and a proposed successor subject to appropriate safeguards. We will not permit a successor to use personal information inconsistently with this policy without providing any notice or choice required by law.
6. Overseas processing
Some providers we use are headquartered in, or operate infrastructure from, the United States and other countries. This means purchase, subscription, email, support and technical information may be processed outside Australia, including in the United States. The exact location can depend on a provider's infrastructure and our selected hosting region. We take reasonable steps appropriate to the circumstances to work with reputable providers and protect information disclosed overseas.
7. Retention and deletion
We keep information only for as long as reasonably required for the purposes above. Subscription, transaction and support records may be retained while your subscription is active and afterwards where required for tax, accounting, dispute, fraud-prevention or legal purposes. Device activation records may remain as an audit and security record after a device is deactivated. Expired recovery credentials can no longer be used and are deleted or de-identified when no longer reasonably needed.
Older app versions could optionally share anonymous daily usage totals. Those historical server records are retained only while needed and can be deleted on request. This version removes local response-time history when launched. Feedback emails are kept as support records while needed to investigate and respond. Some residual copies may remain temporarily in secure backups before being overwritten.
8. Security and data breaches
We use safeguards appropriate to the information we handle, including encryption or hashing of sensitive licensing and recovery credentials, short-lived recovery sessions, restricted access and secure transport. No system is completely secure. If an eligible data breach occurs, we will assess and notify affected people and the Office of the Australian Information Commissioner where required by the Notifiable Data Breaches scheme.
9. Access, correction and complaints
You may ask to access or correct personal information we hold about you, request deletion where appropriate, or make a privacy complaint by emailing hello@jupiterai.com.au. We may need to verify your identity before acting. We will respond within a reasonable period and, where the Privacy Act applies, generally within 30 days.
Please include enough detail for us to investigate a complaint. We will acknowledge it, investigate it fairly and explain our response. If you are not satisfied, you may contact the Office of the Australian Information Commissioner.
10. Changes to this policy
We may update this policy to reflect changes to the Services, providers or law. We will publish the updated policy here with a revised date. If a change materially affects how we handle existing personal information, we will provide additional notice or seek consent where required by law.
11. Contact
JupiterAI
Western Australia, Australia
Email: hello@jupiterai.com.au