GJJ

Closed alpha · closed-alpha-2026-07-16

Closed Alpha Privacy Notice

A plain-language description of the minimum account and community information used during testing.

This working closed-alpha document supports product testing. It is not a substitute for the final legal review required before public launch.

Information used

Supabase Auth processes your email and password credentials. GoJumpingJack stores a public handle and display name, your 18+ and policy acknowledgements, optional city relationships and interests, contributions, interactions, reports, moderation outcomes, and security/audit records needed to operate the closed alpha.

Location safety

The profile asks only about a relationship to a city, such as resident or frequent visitor. It does not ask for a precise home address, work address, or live location, and those details should not be posted publicly about yourself or anyone else.

How information is used

Information is used to authenticate accounts, operate city guides, review contributions, prevent abuse, explain decisions, measure reliability, communicate operational notices, and improve the product. Public email addresses are not part of member profiles.

Service providers and retention

Infrastructure providers process information on GoJumpingJack's behalf. A first-party, HTTP-only browser token and short-lived keyed network cohorts help identify automated or coordinated abuse without storing raw IP addresses in the abuse-event record. Security, moderation, rights, and audit records may need different retention periods from ordinary profile content. During the closed alpha, access, correction, or deletion questions should be sent to support@gojumpingjack.com.

Testing status

This is a working closed-alpha notice, not the final public privacy policy. Provider configuration, retention schedules, export/deletion tools, and final legal language must pass the documented public-launch review.

Feedback, Help, releases, and monitoring

Signed-in feedback stores the member's case text, category, safe status history, optional page and environment context, and private staff notes; verified email remains in Supabase Auth and is not copied into the case. Release acknowledgements, protected-maintenance events, worker receipts, aggregate account counts, and availability monitoring support reliable operations.

Provider metadata and external sharing

When external sharing is enabled, GoJumpingJack may store a canonical provider URL, bounded provider metadata, attribution, content fingerprint, restriction state, and refresh time. It does not execute provider-supplied HTML in ordinary text fields.

Invitations and referral attribution

An invitation visit may set a first-party HTTP-only browser token for up to 30 days so a verified member can be attributed to the first valid inviter. GoJumpingJack records the link channel, optional city, visit time, join milestone, and qualification milestone. It does not receive the recipient’s phone number, email address, contact list, or the external app selected from a device share menu. Self-referrals are rejected, inviter-facing results are aggregate, and invitations do not currently earn money, travel credit, or prizes.

Retention and account control

Closed feedback text is ordinarily retained for up to 24 months and approved attachment metadata for a shorter period unless account deletion, legal preservation, security, or a shorter operator decision applies. Signed-in export and deletion controls describe their current scope; staff notes, third-party data, and security signals are excluded from member export where necessary.

Questions about the closed alpha: support@gojumpingjack.com