ajar.

Privacy Policy

Draft · Updated 27 September 2026

Pending review of retention, service providers, and legal terms. This draft is not yet in effect.

About this policy

This policy describes personal information handled through ajar’s website, workspace, APIs, and support. Bennett Blackham operates ajar and is responsible for this information. Contact us at contact@useajar.com.

Information handled by the service

Account information includes your email address and, when supplied by a sign-in provider, your name and profile information. Workspace information includes membership, roles, API key settings, and account preferences. The service also handles authentication records, request metadata, audit events, and messages you send to support. Connector requests may contain information you choose to submit to a third-party service.

Why information is used

Account and workspace information is used to provide the service you request. Authentication and audit records support access control, troubleshooting, and abuse prevention. Billing information supports subscriptions where enabled. Marketing preferences support subscription and unsubscribe choices. The operator must confirm the applicable lawful basis for each purpose before publication.

Service providers and connected services

Sign-in, email delivery, hosting, and billing may involve service providers. A connector sends the information needed for your requested operation to the relevant service, whose own privacy policy also applies. The current providers, processing locations, and any international transfer safeguards must be documented before this policy takes effect.

Cookies and browser storage

The workspace uses cookies for authentication and browser storage for interface preferences. The public preview is delivered through Cloudflare’s tunnel infrastructure. Any analytics or advertising technologies introduced later must be disclosed with the required choices before use.

Retention and deletion

Account records, request logs, authentication records, email records, and backups require separate retention rules. The operator must confirm those periods, deletion procedures, and any legal retention requirements before publication. Closing an account should not be described as immediate deletion of all records unless the implementation supports it.

Your choices and rights

Depending on applicable law, you may request access, correction, deletion, restriction, or portability of personal information, and object to certain processing. You may withdraw consent where processing depends on it. Send requests to contact@useajar.com. We may need to verify your identity before responding. You may also complain to the relevant data protection authority, including the UK Information Commissioner’s Office at ico.org.uk.

Changes

The published policy will identify its effective date. Material changes to data use will be communicated before they take effect where required.