Legal

Privacy Policy

We believe privacy is not a feature—it is the foundation. This policy explains how Juggernaut Labs collects, uses, stores, and protects your information when you use our platform and services.

Last updated: April 28, 2026
01

Information We Collect

We collect information that you provide directly to us, information generated through your use of the platform, and information from third-party integrations you choose to connect.

Account and Profile Information

When you register for Juggernaut, we collect your name, email address, organization name, job title, and billing information. If you use single sign-on (SSO), we receive authentication details from your identity provider.

Platform Usage Data

We log how you interact with the platform—workflows created, models invoked, API calls made, and feature usage. This helps us improve performance, diagnose issues, and understand which capabilities deliver the most value.

Workflow Content and AI Interactions

When you build workflows, the prompts, configurations, and logic you create are stored to enable execution and replay. If your workflows process data from connected systems (databases, APIs, documents), that data passes through the platform only as necessary to execute your instructions. We do not permanently store your proprietary business data unless you explicitly configure retention policies.

02

How We Use Your Information

We use the information we collect to operate, maintain, and improve the Juggernaut platform. Specifically:

  • Service Provision: To authenticate you, execute your workflows, process your API requests, and deliver the platform capabilities you have subscribed to.
  • Platform Improvement: To identify bugs, optimize performance, prioritize feature development, and enhance user experience based on aggregated usage patterns.
  • Security and Compliance: To detect unauthorized access, enforce usage policies, prevent abuse, and maintain audit trails required for enterprise governance.
  • Communication: To send service updates, security alerts, billing notifications, and occasional product announcements. You can opt out of non-essential communications at any time.
03

AI and Machine Learning

Juggernaut is an AI-native orchestration platform. This section specifically addresses how we handle data in the context of artificial intelligence and large language models.

Model Provider Data Handling

When your workflows invoke third-party AI models (OpenAI, Anthropic, Google, etc.), data is transmitted to those providers under their respective terms. Juggernaut provides granular controls allowing administrators to restrict which models can be used, route sensitive workflows to self-hosted models only, and automatically strip PII before external transmission using built-in guardrails.

We do not use your proprietary workflow data or business inputs to train our own models without explicit written consent. Aggregated, anonymized usage metrics may be used to improve platform performance, but never in a way that could reconstruct your private data or workflows.

For enterprise deployments, we offer zero-data-retention agreements with supported model providers, ensuring that no prompt or response is stored by the underlying AI vendor beyond the immediate inference request.

04

Data Sovereignty & Infrastructure

Your data belongs to you. Juggernaut is architected to keep it that way.

Self-Hosted Deployments

Run Juggernaut entirely on your own infrastructure, behind your firewall, under your own cloud accounts. Your data never touches our servers.

Regional Data Residency

Cloud deployments can be pinned to specific geographic regions (US, EU, Canada, Asia-Pacific) to satisfy local data residency requirements.

For cloud-hosted accounts, we utilize SOC 2 Type II certified infrastructure with encryption at rest (AES-256) and in transit (TLS 1.3). Access to production systems is restricted to senior engineering staff on a need-to-know basis, protected by multi-factor authentication and hardware security keys.

05

Cookies and Tracking Technologies

We use cookies and similar technologies to maintain your session, remember preferences, and analyze platform usage.

  • Essential Cookies: Required for authentication, security, and core platform functionality. Cannot be disabled.
  • Preference Cookies: Remember your settings, theme choices, and dashboard configurations.
  • Analytics Cookies: Help us understand how users navigate the platform so we can improve usability. These are anonymized and aggregated.

You can manage cookie preferences through your browser settings or via the cookie banner presented on first visit. We do not use tracking cookies for advertising purposes and do not sell cookie data to third parties.

06

Third-Party Services and Integrations

Juggernaut integrates with third-party services that you choose to connect—databases, APIs, cloud providers, communication tools, and AI model endpoints. When you authorize these connections, data is shared with those services under their respective privacy policies and terms of service.

We do not sell your personal information to data brokers, advertisers, or unrelated third parties. We only share data with service providers who are essential to delivering the platform (hosting, payment processing, customer support) and who are bound by strict confidentiality and data protection obligations.

In the event of a merger, acquisition, or asset sale, your information would be transferred subject to the same privacy commitments outlined in this policy. You would be notified before any such transfer occurs.

07

Data Security

We implement enterprise-grade security measures to protect your data from unauthorized access, alteration, disclosure, or destruction.

Encryption

AES-256 at rest, TLS 1.3 in transit, end-to-end encryption for sensitive workflows.

Access Control

Role-based permissions, MFA enforcement, hardware key support, principle of least privilege.

Monitoring

24/7 automated threat detection, intrusion monitoring, and anomaly alerting.

Compliance

SOC 2 Type II, GDPR-ready architecture, regular third-party penetration testing.

Despite our efforts, no system is completely impenetrable. In the unlikely event of a data breach affecting your personal information, we will notify you within 72 hours and take immediate remedial action in accordance with applicable law.

08

Data Retention

We retain your information for as long as your account is active or as needed to provide you with services, comply with legal obligations, resolve disputes, and enforce our agreements.

Workflow execution logs are retained based on your plan and governance settings—ranging from 30 days for Starter plans to indefinite for Enterprise accounts with custom archival policies. You can configure automatic deletion schedules for transient workflow data.

When you delete your account, we begin a secure deletion process that permanently removes your personal data from active systems within 30 days. Backup copies may persist in encrypted, isolated storage for up to 90 days before automatic purging.

09

Your Rights and Choices

Depending on your location, you may have specific rights regarding your personal data. Juggernaut supports these rights regardless of jurisdiction:

Access

Request a copy of the personal data we hold about you.

Correction

Update inaccurate or incomplete information in your profile.

Deletion

Request deletion of your account and associated personal data.

Portability

Export your workflow configurations and account data in machine-readable format.

Restriction

Limit how we process your data in specific circumstances.

Objection

Opt out of certain data uses, including non-essential analytics.

To exercise any of these rights, contact us at privacy@juggernautlabs.ai. We will respond within 30 days. For Enterprise accounts, your organization's administrator may also manage user data on your behalf through the admin dashboard.

10

Children's Privacy

Juggernaut is not intended for use by individuals under the age of 16, or under the age of 13 in jurisdictions with stricter regulations. We do not knowingly collect personal information from children. If you believe we have inadvertently collected data from a minor, contact us immediately and we will delete it.

11

Changes to This Policy

We may update this Privacy Policy periodically to reflect changes in our practices, platform capabilities, or legal requirements. When we make material changes, we will notify you via email or through a prominent notice on the platform at least 30 days before the changes take effect.

Your continued use of Juggernaut after the effective date constitutes acceptance of the revised policy. We encourage you to review this page regularly.

12

Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please reach out:

privacy@juggernautlabs.ai
Juggernaut Labs Inc., Toronto, Ontario, Canada
Data Protection Officer: dpo@juggernautlabs.ai

For Enterprise customers, your designated Customer Success Manager can also escalate privacy matters directly to our compliance team.

Questions About Data Sovereignty?

Talk to our team about self-hosted deployments, zero-data-retention agreements, and custom compliance configurations.

Contact Enterprise Team