Jetty Labs, Inc. ("Jetty Labs," "Aluna," "we," "us," or "our") provides Aluna, an assistant for insurance agency work. This policy covers the Aluna web application, APIs, connected-service features, and Aluna Chrome extension (together, the "Services"). Our website Privacy Policy covers the getaluna.ai marketing site.
Customer workspaces
Most Aluna users access the Services through an insurance agency or other business customer (a "Customer"). The Customer decides what information to place in its Aluna workspace and how its workspace is used. We handle that information to provide Aluna under our agreement with the Customer.
If you use Aluna through an organization, that organization should be your first contact for requests about information in its workspace. We separately use limited account, administration, support, billing, security, and operational information to run our business and protect the Services. A signed customer agreement controls if it conflicts with this policy.
Information we process
Account and administration information
We process names, business email addresses, organization membership, roles, authentication and session information, and related account and security events. We may also receive business contact, support, billing, and contract information from Customers.
Customer workspace data
We process the records a Customer brings into or creates in Aluna, including accounts, policies, submissions, documents, tasks, conversations, communications, and workflow results. Depending on what the Customer provides, this can include names, contact information, dates of birth, government identifiers, driver's license numbers, financial or payment information, policy and claims information, health-related information, and other sensitive personal information.
Connected systems
At a Customer's direction, the Services may connect to insurance carrier websites and business systems such as Microsoft 365 and Outlook, email, calendar, document, and accounting services. Depending on the integration, we may process message content and attachments, sender and recipient information, contacts, calendar information, transaction data, provider identifiers, and encrypted authorization tokens. The Customer chooses which integrations and mailboxes to connect.
Communications, support, and product feedback
We process messages users send to Aluna and information a user or Customer chooses to share in a support or security request. In-product feedback includes the sender and organization identity, feedback text, current page address, and submission time. A user may also attach images and choose whether to include recent browser error details after previewing them.
Attached images and browser error details can contain Customer workspace data or other personal or sensitive information. Aluna redacts common credential-shaped values from browser error details but cannot guarantee every sensitive value will be recognized. Users should review the message, images, and error preview before sending. The browser can remember a user's error-sharing choice for the relevant Aluna user and organization in local storage.
Operational, security, and audit information
We process information needed to operate and protect the Services, such as IP address, browser and device information, request metadata, identifiers, timestamps, counts, durations, feature and workflow status, and error codes. Application logs are designed to exclude customer values and page content. Separate activity and audit records may contain the changes, actions, and workflow evidence needed to show what occurred in a Customer workspace. Browser error details that a user chooses to include with product feedback are treated as submitted feedback rather than application logs.
The Services do not use advertising trackers or third-party analytics cookies. They may use first-party cookies and local storage for authentication, security, preferences, and other product functions.
The Aluna Chrome extension
The extension's single purpose is to assist insurance agency work. It lets a user chat with Aluna, attach the page they are working on, prepare and apply approved form fills from the Aluna workspace, and run user-initiated carrier workflows on websites where the user is already signed in.
Current-tab information
The extension reads the current tab's address and title locally so it can offer the page as an attachment and display the correct run or task context. It sends a page's address, title, or content to Aluna only when the user attaches that page, starts an authorized workflow, or authorizes a portal-authoring test on that tab. It does not build or transmit a general history of the user's browsing.
Pages a user attaches
When a user attaches the current page to a message, the extension sends the page address and title, rendered page text, visible form controls and their current values and options, and one or more screenshots to Aluna. Screenshots may include content throughout the scrollable page, including content outside the current viewport, and can include personal, financial, health-related, authentication, or other sensitive information rendered on the page.
The extension excludes recognized password, passcode, token, API-key, and one-time-code fields from structured page text and form data and redacts common credential patterns from extracted text. Screenshots are images of the page as rendered and are not pixel-redacted. A user should not attach a page with a secret visibly rendered unless that information is intended to be included in the request.
Form filling
To prepare a fill, the extension reads the page's form structure and current non-credential values. It applies values the user approves from the Aluna workspace and checks the targeted controls to confirm the page accepted them and to help avoid overwriting existing entries. It does not fill recognized credential or one-time-code fields.
Carrier workflow runs
When a user starts a carrier workflow, the extension opens or uses a dedicated tab and can navigate, fill fields, click controls, make in-page requests using the user's existing carrier session, extract results, capture screenshots, and collect result files such as quote documents. Aluna receives the carrier site address, the page states and values required by the workflow, workflow status and errors, extracted results such as quote numbers and premiums, screenshots, and resulting files.
Chrome displays a debugging banner while the extension is attached to an automation tab. The extension pauses and detaches for declared human steps, including credential entry and consequential final actions, and the user can stop a run. The extension uses the signed-in session to perform authorized requests but does not read or copy carrier cookies into Aluna.
Portal-authoring tests
Authorized users may attach a carrier page to create or test an Aluna workflow. After a separate consent prompt, the extension can capture page structure, headings, control metadata and visible field state; optionally capture screenshots; and perform specifically enabled non-credential form inputs and safe navigation. The consent screen identifies the enabled capabilities, and consequential actions remain human-only.
Chrome permissions and user control
- Current page and scripting. Temporary current-tab access lets the user attach or fill the page they chose. The user may separately grant and revoke persistent access for one site or for HTTP and HTTPS sites generally in the extension's Page attachment access settings or Chrome's extension settings.
- Tabs. Tab access lets the extension read the current tab's address and title and create, focus, monitor, or close a tab used for a workflow.
- Debugger. Debugger access performs the finite set of browser actions and screenshots needed for a user-authorized workflow or portal-authoring operation.
- Storage. Browser storage keeps the authenticated Aluna session, profile and preferences, temporary chat and run state, recent Aluna items, and permission or consent choices.
- Side panel and alarms. These permissions provide the Aluna interface and allow an in-progress run to resume after Chrome suspends the extension's background worker.
Information kept in Chrome
The extension keeps the Aluna session token and temporary chat, page, recent-item, and run state in Chrome session storage. Chrome clears session storage when the browser restarts, and Aluna clears it on sign-out. The extension keeps profile and display preferences, connection state, and remembered page-attachment, portal-authoring, and portal-run approvals in local storage. These approval records are associated with the relevant Aluna user and organization and, where applicable, the approved site, access scope, and review preference. They remain until the user removes them, signs out where applicable, or uninstalls the extension. Chrome separately stores optional site-access permissions, which the user can revoke. Page screenshots and page content are not kept as a local archive by the extension; content sent to Aluna follows the server-side retention terms below.
What the extension does not do
- It does not log keystrokes or read the clipboard.
- It does not collect page content in the background from unrelated tabs or pages the user has not attached or authorized.
- It does not use extension data for advertising, retargeting, creditworthiness, or lending decisions.
- It does not include advertising trackers or third-party analytics.
How we use information
We use information described above to:
- provide the Services and the features a user or Customer requests;
- authenticate users, administer organizations, and enforce access controls;
- operate connected systems and complete user-authorized workflows;
- maintain, secure, support, troubleshoot, and improve the Services in accordance with customer agreements;
- prevent fraud, abuse, and other harmful activity; and
- comply with law and protect rights, safety, and security.
Customer content may be processed by the AI providers listed on our Subprocessors page. We use paid or business API offerings under terms that do not permit those providers to use Customer prompts, documents, or generated responses to train shared foundation models.
We do not sell personal information or share it for cross-context behavioral advertising.
Chrome Web Store Limited Use
Aluna's use of information received through Chrome APIs complies with the Chrome Web Store User Data Policy, including its Limited Use requirements. We collect, use, and transmit extension data only when strictly necessary to provide or improve the extension's disclosed single purpose and related security, maintenance, and reliability.
We do not transfer extension data except as necessary to provide or improve that purpose through the service providers disclosed below, to comply with law, or to protect against fraud, abuse, or security threats. We do not allow a person to read extension data unless the user explicitly consents to review of specific data for support, the data is aggregated and anonymized for permitted internal operations, access is necessary for security, or access is required by law. We do not use or transfer extension data for personalized advertising, data brokerage, creditworthiness, or lending.
How we disclose information
- Service providers. The companies listed at getaluna.ai/legal/subprocessors provide cloud infrastructure, storage, authentication, AI processing, and operational support. They may process Customer data only as needed to provide those services under the applicable contractual terms.
- Carrier websites and connected systems. At a Customer's or user's direction, Aluna sends the information needed to complete a requested operation to the carrier or connected system. Those third parties process the information under their own terms and privacy notices.
- The Customer. Activity in a Customer workspace is available to the Customer and its authorized users according to its configuration and access controls.
- Professional advisers. We may disclose information to lawyers, auditors, insurers, and other advisers where reasonably necessary and subject to confidentiality obligations.
- Legal and security matters. We may disclose information when required by law or reasonably necessary to protect rights, safety, security, and the integrity of the Services. We will notify affected Customers where legally permitted and contractually required.
Retention and deletion
We retain Customer data only as long as reasonably necessary to provide the Services, fulfill our contractual obligations, maintain security and audit records, resolve disputes, and comply with law. The criteria we use include whether the customer agreement and relevant feature are active, whether the information is needed for support or security, and whether a legal or contractual obligation requires us to keep it.
- Customer workspace data — including accounts, communications, chats, tasks, documents, page captures, workflow screenshots, and artifacts — is ordinarily kept while the customer agreement is active and as needed to provide the requested features.
- Product feedback — including feedback messages, attached images, and browser error details a user chooses to include — may be kept in dedicated object storage for up to 30 days. Copies delivered to our internal Slack workspace follow that workspace's configured retention policy.
- When a Customer terminates the Services or requests a supported deletion, we remove affected data from active systems through our standard deletion process, subject to the Customer's agreement and applicable legal obligations.
- Copies may remain temporarily in backups until overwritten through our ordinary backup rotation. Backup copies are isolated from normal product use and are retained for recovery and security purposes.
- Operational logs and audit, billing, contract, security, and legal records are kept only as long as reasonably necessary for the purpose for which they were created.
These are retention criteria, not fixed deletion deadlines. A customer agreement may establish a specific retention or deletion schedule. If a Customer must preserve records — for example, under insurance record-retention rules — it should export them before termination or contact us about available export options. Individual users should route workspace-data requests through the Customer that controls the workspace.
Security
Traffic between users and Aluna's hosted Services uses HTTPS. Customer data is encrypted at rest in our cloud infrastructure, and authorization controls limit access by organization and role. Access to operational systems is limited to authorized personnel. No security measure is perfect, and we cannot guarantee absolute security. Report a concern to security@getaluna.ai.
Your privacy rights and choices
Users and Customers choose which systems to connect, pages to attach, permissions to grant, and workflows to start. A user can stop a run, revoke site access in Chrome, forget remembered portal-authoring access, disconnect the extension from Aluna, or uninstall it.
Depending on where you live and applicable law, you may have rights to request confirmation, access, a copy, correction, or deletion of personal information, or to appeal our response. Submit a request to privacy@getaluna.ai. We may need to verify your identity. When a Customer controls the relevant workspace data, we will coordinate with that Customer and may direct the request to it. We will not discriminate against you for exercising an applicable privacy right.
Data location
The Services are directed to users in the United States. Aluna's primary application infrastructure and core structured-data storage are configured in United States cloud regions. Some storage and other providers use global networks or may process limited data in other locations under their service terms. The Subprocessors page provides more detail.
Children
The Services are business products intended for users who are at least 18 years old. We do not knowingly offer the Services to children.
Changes to this policy
We may update this policy as our Services, practices, or legal obligations change. We will post the updated policy and revise its effective date. If the Chrome extension introduces different data practices after installation, we will also prominently disclose the change to extension users and obtain consent before the new collection or use where required.
Contact us
Jetty Labs, Inc.
2351 E. Briarwood Drive
Holladay, Utah 84124
privacy@getaluna.ai