Privacy policy
1. Data controller
The controller of personal data is:
JIMBLE LABS, SAS — RCS Aix-en-Provence 108 108 804
Registered office: 1 Mail de la Bastide, 13590 Meyreuil
Email: contact@jimble.dev
2. Data Protection Officer (DPO)
You can contact our Data Protection Officer at the following address:
contact@jimble.dev
3. Data collected and purposes
We collect and process the following personal data:
- Registration data: last name, first name, email address, password. Purpose: creating and managing your user account. Legal basis: performance of the contract.
- Connection data: IP address, connection logs, user agent. Purpose: security, fraud detection, technical support. Legal basis: legitimate interest.
- Payment data: billing information transmitted to our payment provider Stripe. We do not store your bank details. Purpose: payment processing. Legal basis: performance of the contract.
- Usage data: workflows created, executions, token consumption. Purpose: provision of the service, billing, product improvement. Legal basis: performance of the contract and legitimate interest.
4. Google user data
Jimble accesses certain data from your Google Account only if you explicitly authorise it to do so on Google's consent screen.
- Sign in with Google: name, email address and profile picture of your Google Account. Purpose: creating your Jimble account and signing you in to it. Legal basis: performance of the contract.
- Google Calendar integration (calendar.events scope), when you connect your calendar to a project:
- the email address of the connected Google Account and the identifier of the calendar used (your primary calendar);
- a refresh token allowing actions to be taken on your calendar when you are not present;
- the events in your primary calendar (title, dates, description, location, attendees), which the AI agents of the workflows you configure can view and create, and which they can modify or delete when they created them themselves.
Use. This data is used exclusively to provide the features you have configured; it is excluded from any other purpose, in particular from the product improvement mentioned in section 3. Jimble only modifies and deletes events that it has created itself: your other events are never modified or deleted. By default, no email is sent to the attendees of an event.
Sharing. Google data is not sold, not used for advertising purposes and not transferred to third parties, except in the following cases:
- the AI model provider you have chosen for a workflow's agent, which receives the calendar information necessary to perform the task you have entrusted to it;
- our hosting and infrastructure subprocessors, solely for the provision of the service;
- the competent authorities, where required by law.
Artificial intelligence. Jimble does not use Google data, and does not transfer it, to develop, improve or train generalised artificial intelligence or machine learning models.
Human access. JIMBLE LABS staff do not view your Google data, except with your explicit consent (for example for a support request), where necessary for the security of the service (abuse detection) or to comply with a legal obligation.
Storage and security. The refresh token is encrypted at rest in our database (AES-256). Short-lived access tokens are never stored. Jimble does not keep a copy of your calendar: only the information that an agent includes in its results or execution logs is retained, together with the execution history of your workflows.
Revocation and deletion. You can withdraw access at any time by removing the Google Calendar integration from your project: Jimble then deletes its credentials and asks Google to revoke the authorisation (where the same Google Account is connected to several projects, the authorisation is revoked when the last integration is removed). You can also revoke access from the permissions page of your Google Account. Deleting your Jimble account immediately deletes your Google Calendar integrations and asks Google to revoke the corresponding authorisation (unless that Google Account remains connected to another Jimble account), without waiting for the end of your account's retention period.
Limited Use. Jimble's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
5. Retention periods
- Account data: for the entire lifetime of your active account and for one year after closure.
- Billing data: 10 years, for accounting obligations.
- Security logs: 24 months.
6. Recipients of the data
Your personal data may be transmitted to the following categories of recipients:
- Authorised JIMBLE LABS staff
- Technical subprocessors (hosting, infrastructure, payment) — see the full list of subprocessors
- Competent authorities upon judicial request
7. Transfers outside the European Union
Your data is hosted in the EU and is not transferred outside the EU.
8. Your GDPR rights
In accordance with Regulation (EU) 2016/679, you have the following rights:
- Right of access: obtain a copy of your personal data.
- Right to rectification: correct inaccurate or incomplete data.
- Right to erasure: delete your data under certain conditions.
- Right to restriction of processing: freeze the processing of your data in certain cases.
- Right to object: object to the processing of your data on legitimate grounds.
- Right to data portability: receive your data in a structured, commonly used format.
- Right to lodge a complaint with the CNIL (French data protection authority): www.cnil.fr
To exercise your rights, contact us at: contact@jimble.dev
9. Cookies
To find out more about the cookies used on our website, please see our Cookie policy.
10. Changes to this policy
We reserve the right to modify this privacy policy at any time. The current version is always available on this page.
Last updated: 1 October 2026