1. Introduction & Scope
Welcome to JEJ (“JEJ”, “we”, “our”, or “us”), accessible via jej.app, app.jej.app, and our mobile applications distributed via the Apple App Store and Google Play Store (“Services”). JEJ provides next-generation generative artificial intelligence tools for virtual photoshoots, AI models, portrait generation, video synthesis, and creative image generation.
We respect your privacy and are committed to protecting personal information. This Privacy Policy details how we collect, use, process, and safeguard the data you provide when interacting with our platform, including reference imagery, prompts, generation logs, biometric facial vectors, and account telemetry.
2. Information We Collect
We collect information you provide directly, data collected automatically through device interaction, and information from third-party authentication and billing providers:
- Account & Authentication Data: When registering via Google Identity, Apple Sign-In, or email, we receive your name, verified email address, unique account identifier, and secure authorization tokens.
- User Creative Uploads & Inputs: Photographs, portraits, reference images, style examples, composition sketches, and audio/video files uploaded to initiate generations or train custom virtual models.
- Prompts & Generation Parameters: Text prompts, negative prompts, aspect ratios, model checkpoints, seed numbers, and configuration settings used during generation sessions.
- Transaction & Entitlement Information: Subscription tier status, purchase history, order identifiers, and entitlement dates. Payments made through the Apple App Store or Google Play are handled by those platforms; web-based subscriptions are processed by PCI-DSS certified processors (e.g., Stripe). JEJ does not store full credit card numbers or security CVVs.
- Technical, Device & Usage Telemetry: IP address, operating system, browser type, approximate geographic region (country/city level), app version, crash diagnostics, and anonymous session telemetry.
3. Artificial Intelligence Processing & Explicit Consent
Notice on AI Data Transmission
To deliver high-fidelity generative visual results, user-initiated generation requests and reference images may be securely transmitted outside your local device to specialized AI inference infrastructure. We present clear notices, and if you decline AI processing, your content is never transmitted to generative AI endpoints.
When you trigger an AI feature:
- Only the data strictly required to synthesize the requested image or video (prompt text, style parameters, reference image pixels) is transmitted.
- AI models are never provided with sensitive metadata such as payment details, device contacts, precise GPS location, advertising IDs, or authentication passwords.
- You may withdraw your consent for future AI data sharing at any time through your account privacy settings or by contacting our support team. Withdrawal prevents future AI processing but does not affect outputs previously generated at your request.
4. Permissible Inputs & Data Exclusions
AI content processing is strictly automated for image synthesis, quality assurance, abuse prevention, and platform security.
5. Third-Party AI Infrastructure & Zero Foundation Model Training
To run state-of-the-art diffusion, transformer, and neural rendering models at scale, JEJ partners with vetted, enterprise-grade cloud compute and AI infrastructure providers (including Cloudflare Workers, fal.ai, Google Gemini Vision endpoints, AWS, and RunPod):
- Zero Public Model Training: JEJ does NOT use your private uploads, face photos, custom prompts, or generated outputs to train, fine-tune, or improve public foundation models unless you explicitly provide separate, affirmative written consent.
- Contractual Provider Safeguards: Our AI compute providers are bound by strict data protection agreements preventing them from retaining user prompts or using submitted imagery for their own model training.
- Automated Processing vs. Human Review: Processing is completely automated. Human review of user content occurs only under strict exceptions: when you explicitly submit content to customer support for troubleshooting, when investigating substantiated abuse or security incidents, or when required by court order or binding legal statute.
6. Images, Faces, and Biometric Information Guarantee
Strict Non-Sale & Likeness Protection Guarantee
JEJ will NEVER sell, lease, rent, or trade your facial data, uploaded portrait photographs, or biometric vectors to third-party advertisers, data brokers, or commercial marketing firms.
When you use custom face training or likeness consistency tools:
- Facial feature geometry is processed temporarily into private adapter weights (LoRAs) accessible exclusively by your authenticated account.
- You retain complete control over your training datasets and can permanently delete raw uploaded training photos or custom models at any time via your account dashboard.
- Upon account deletion, all associated biometric representations, adapter weights, and original uploads are permanently deleted from active GPU storage.
7. Content Concerning Other People & Minors
If you upload photos, screenshots, or creative references depicting another person, you represent and warrant that you have obtained all necessary legal permissions and consents from that individual.
- You may not upload intimate, private, confidential, or defamatory images of third parties without explicit legal authorization.
- Minor Protection: If an uploaded image contains a minor, you legally affirm that you are the parent or legal guardian with full authority to submit that image for processing. Uploading unauthorized images of minors is strictly prohibited.
8. In-App Purchases, Subscriptions & RevenueCat Integration
When using the JEJ mobile application on iOS or Android, digital subscriptions and in-app credit purchases are managed through third-party purchase management infrastructure (such as RevenueCat) and the respective mobile app stores:
- Purchase infrastructure receives an anonymous app user identifier, product entitlement status, transaction IDs, store environment, country, and currency to fulfill and restore your purchases.
- No payment card details or bank credentials ever pass through or reside on JEJ servers.
- Subscription billing, renewal, and cancellation for mobile purchases are managed exclusively through your Apple App Store or Google Play account settings.
9. Cookies, Local Storage & Analytics
JEJ uses essential session cookies, local storage tokens, and diagnostic telemetry to provide seamless authentication, maintain active generation sessions, remember styling preferences, and safeguard platform security.
- Essential Cookies: Required for secure login, CSRF protection, and account state. Disabling essential cookies in your browser will prevent access to your dashboard.
- Performance & Error Diagnostics: Aggregated, non-personally identifiable telemetry to identify runtime errors, API latency, and GPU queue optimization.
- We do not sell personal browsing history to third-party ad networks.
10. Data Retention & Erasure Schedule
We retain information only as long as necessary to fulfill the purposes outlined in this policy or to comply with statutory legal requirements:
- Account Profile: Retained for the lifetime of your active account and up to 30 days after an account deletion request to allow for backup purge cycles and dispute resolution.
- Generated Imagery: Stored on encrypted cloud volumes while your account remains active. You may delete individual generations at any time.
- Prompt & Audit Logs: Maintained for a limited duration for rate limiting, abuse detection, and service optimization, then anonymized or purged.
- Billing Records: Retained as required by mandatory international tax and accounting laws.
11. Information Security Safeguards
We employ robust technical and organizational safeguards engineered to protect your personal data from unauthorized access, loss, or alteration. These measures include end-to-end TLS 1.3 encryption in transit, AES-256 encryption at rest for cloud storage, continuous DDoS mitigation and web application firewalls via Cloudflare, role-based access control (RBAC), and automated vulnerability monitoring.
12. International Data Transfers
JEJ and its cloud compute partners operate globally across data centers located in the United States and European Union. When data is transferred across international borders, we ensure adequate protection through recognized legal mechanisms, including Standard Contractual Clauses (SCCs) approved by the European Commission, UK International Data Transfer Agreements, and equivalent safeguards.
13. Your Legal Rights (GDPR, CCPA/CPRA, KVKK)
Regardless of your geographical location, JEJ extends the following comprehensive privacy rights:
- Right of Access: Request a copy of the personal information we maintain concerning you.
- Right to Rectification: Request correction of inaccurate or incomplete personal details.
- Right to Erasure (Right to be Forgotten): Request permanent deletion of your account, creative uploads, and generated outputs.
- Right to Data Portability: Obtain your data in a structured, commonly used, machine-readable format.
- Right to Withdraw Consent: Revoke consent for AI data processing at any time without prejudice.
- Non-Discrimination: We will never deny services, charge different prices, or provide a degraded experience for exercising your statutory privacy rights.
To exercise any of these rights, contact us at hi@jej.app. Requests are verified and processed within 30 days.
14. Policy Updates
We may update this Privacy Policy periodically to reflect technological advancements, model capabilities, or evolving legal frameworks. When material revisions occur, we will notify you through an in-app notice, email, or a prominent banner on our website prior to the change taking effect.
15. Contact & Data Protection Inquiries
For privacy inquiries, consent revocations, or data-rights requests, please contact our Data Protection and Privacy team: