Skip to content
Jelly

Privacy Policy

Effective 7 October 2026 · Last updated 7 October 2026

This Privacy Policy explains how ON JELLY LLC, a Florida limited liability company doing business as Jelly (“Jelly”, “we”, “us”), collects, uses, shares and protects personal information when you use Jelly: the Jelly iPhone app, the website at onjelly.com (including app.onjelly.com and help.onjelly.com), and the emails, texts and notifications we send (together, the “Services”).

It is written to describe what our systems actually do. Where we say we do not do something, we mean the system does not do it.

The short version

  • We collect what it takes to run a clothing rental marketplace: your account, your addresses, your rentals and listings, your messages, and the videos and photos that record a piece’s condition when it changes hands.
  • Other members see your first name and your handle. They never see your full name, email address or phone number, and they see a street address only on a shipped order, where the shipping label carries it (section 5).
  • We do not sell your personal information, we do not share it for targeted advertising, and there is no advertising technology in the app or on the website.
  • Your card goes to Stripe, not to us. If you are asked to verify your identity, Stripe checks your photo ID and a selfie; we receive the result, not the images (section 2.8).
  • Mona, our in-app stylist, Jelly Support’s AI assistant and our photo features use outside AI services (xAI and Google) only after you say yes, and you can turn that off at any time (section 6).
  • You can download your data, correct it, and delete your account yourself (sections 9 and 10).

1. Who we are and what this covers

Jelly is operated by ON JELLY LLC, a Florida limited liability company doing business as Jelly, at 2155 Washington Ct, Miami Beach, FL 33139. For anything in this policy, email info@onjelly.com with the subject “Privacy request”.

Jelly is a marketplace where members rent and buy clothing from one another. It is for adults aged 18 and over in the United States. The Terms of Service set out the agreement between you and Jelly; this policy explains how we handle personal information under it.

This policy does not cover other companies’ websites and services, even when Jelly links to them or uses them to provide part of the Services, for example a shop that sells a piece you are tracking, the payment and verification pages Stripe runs, or Sign in with Apple. Their own privacy policies apply to what they do. Section 4 says what we send them.


2. What we collect

We collect information you give us, information created when you use the Services, and information we receive from the companies that help us run Jelly. Section 10.4 lists it again by the categories California law uses.

2.1 When you create an account

  • Mobile phone number. Required. Your account is tied to a verified phone number: a code texted to it is how you sign up, and one of the ways you can sign in. The code is generated, sent and checked by our SMS provider, Twilio; Jelly never sees or stores it. We also use your number to reach you about a rental in progress, and we give it to a courier or a carrier when they need to reach you (section 4.2). We never use your phone number for marketing.
  • Email address. Required, for receipts, notices about your account and account recovery. If you sign in with Apple, this may be the private relay address Apple gives us.
  • Your name. Your first name, and your last name if you give it. Other members only ever see your first name (section 5). Your last initial appears on a shipping label (section 4.2).
  • Date of birth, where we ask for it, to confirm that you are 18 or over. It is never shown to anyone.
  • ZIP code, so that we can show you what can reach you.
  • Handle. Your handle is public.
  • Password, only if you set one. It is stored as a scrypt hash with a salt unique to your account; we never store the password itself and cannot read it. Accounts created with a phone code or with Apple usually have no password at all.
  • Sign in with Apple. If you use it, we store the identifier Apple gives Jelly for your Apple account, the email address Apple shares, and your name if Apple sends it. We also keep, encrypted, the token Apple issues to Jelly for your account. It is used for one thing: to tell Apple to withdraw Jelly’s access when you delete your Jelly account (section 9).
  • Who invited you. If you joined through a friend’s invitation link, we record which member invited you, so that their referral credit can be granted. Your own invitation code is made from your first name.
  • Your agreement to our Terms: which version you accepted, and when.

2.2 Your profile and settings

  • Sizes and fit: your sizes, your height, your shoe and waist sizes if you add them, and a fit note if you write one.
  • Profile photo, bio and social handles (Instagram, TikTok or Pinterest), if you add them. Location and camera data are removed from a profile photo when it is uploaded.
  • Your style: the colors and brands you love or avoid, occasions and their dates, budgets, neighborhoods, style words and your own notes. Mona uses these (section 6).
  • Closet settings, if you lend: your fit refund policy, whether you take offers and the lowest offer you will accept automatically (which stays private), rental lengths, away dates, delivery options, and whether to show your sizes on your closet.
  • Your choices: notification settings, the two history switches described in section 5, and your answer about the outside AI services in section 6.
  • Your location, only if you tap “Use my location”. Your device sends its coordinates to our servers once, to work out your ZIP code and neighborhood. The coordinates are not stored. Your phone or browser asks your permission first.

2.3 Addresses and delivery details

  • Delivery addresses: street, unit, city, state, ZIP code, neighborhood, building type and a label you choose; and, if you add them, a contact name and phone number for that address, pickup instructions, an access code, and whether there is a doorman.

Your addresses, and the phone numbers saved with them, are used only to deliver and collect pieces (by courier, by carrier, or through a pickup you schedule) and to check an address with the US Postal Service when you save it (section 4.2). They never appear in any listing, order page, message or public page, and they are never shown to another member, with one exception: on a shipped order, the shipping label carries the address (section 5).

2.4 What you do on Jelly

  • Rentals and purchases: the pieces, dates, delivery method, prices, fees, credits applied, refunds, late fees, extensions, cancellations, and the timeline and tracking of each order.
  • Offers you make and receive, and how and when they were answered.
  • Listings: photos, descriptions, brand, size, prices, replacement value, any receipt you upload, and your closet settings.
  • Reviews and ratings you give and receive, and fit feedback.
  • Saves, follows, Looks, alerts, Requests (with replies and votes), and pieces you share.
  • Money records: your credits, payouts, any amount you owe and payments towards it, and referral rewards.
  • Problems: issues you report, damage and loss claims, the photos, receipts and descriptions attached to them, and how they were resolved; and reports and blocks you make.
  • Sale Tracker: the products you track and how you want to hear about them (section 6).

2.5 Messages and support

  • Messages with other members.
  • Your conversations with Mona (section 6).
  • Conversations with Jelly Support, and the notes our team keeps about the work on them. Where Jelly Support’s AI assistant answers first, the conversation also holds its replies, any answer it wrote that our checks stopped, any flag you put on one of its replies, and the short summary it writes for our team (section 6.7).
  • Help requests sent without signing in: the email address and phone number you give us, the topic and your message, the IP address and device description the request came from, and any Jelly account that matches the details you gave.

Messages you send through Jelly are stored by Jelly. We may review them when a message is reported, when it is part of an order or a dispute we are resolving, when it bears on a support request, or when we need to in order to keep members safe, enforce our Terms or comply with the law. They are not scanned automatically. When a message arrives, its first few words appear in the notification sent to the recipient.

2.6 Payment information

  • Cards. You enter your card into a form provided by our payment processor, Stripe. Jelly never receives or stores your card number or security code. We keep the reference Stripe gives us for your customer record. Your card’s brand, last four digits and expiry date are fetched from Stripe when we show them to you; we do not store them.
  • Payouts. If you lend, Stripe collects the identity, bank and tax details it needs to pay you, on its own pages. We keep a reference to your Stripe payout account, its status and any restriction Stripe reports, and your bank’s name and the last four digits of the account, so that we can show you where your payouts go.
  • Payment records: charges, holds, refunds, disputes and chargebacks, and the fraud signals Stripe sends us about a payment (sections 2.8 and 4.1).

2.7 Device, log and security information

  • Request logs. Our servers log each request’s route, result, timing and reference number and, if you are signed in, your Jelly account number. Our hosting provider keeps its server logs for a limited period under its own settings.
  • An activity record of things that happen on your account (signing in, changing your email or password, booking, cancelling, reporting a problem), each with the IP address and the device description (the browser or app’s user-agent string) it came from. It is how we answer “was this really me?” and what we look at when a payment is disputed.
  • A security record of failed sign-ins, lockouts, blocked requests and forged requests, each with the IP address and device description, and the email address or phone number being tried in masked form. It is how we notice someone attacking accounts.
  • A record of every email we send you: the address, the subject line, what kind of message it was, when it was sent, and whether your mail provider reported it delivered, bounced or marked as spam. We never store the contents of the email.
  • A record of failed calls to our suppliers (for example a payment or delivery request that errored), so that we can fix what broke.
  • A diagnostic trail, only if you send one. The app keeps a short technical record on your phone of requests that failed. Nothing is sent unless you tap “Send to Jelly”. It carries the route, result, timing and error, with your account number, handle, IP address and device description, and no request contents, no searches, no address, no price and nothing about a piece.
  • Session tokens that keep you signed in, and single-use secrets (a password-reset link, an email-verification code, a sign-up receipt), which are stored hashed, never in the clear.
  • A push token, if you allow notifications: the token your phone gives us so that we can send them.
  • Crash reports and product analytics, when we switch them on. Our app and servers are built to send crash reports to Sentry and a fixed, published list of product events to PostHog. When switched on, a crash report carries the error, the screen, the app version and your account number, and a security alert from our servers can carry an IP address; a product event carries its name, your account number and identifiers such as a piece or order number. Neither is sent a screenshot, the contents of any field you typed, a search, a message, your address or your card. Neither is used for advertising.
  • Cookies and browser storage on the website (section 7).

2.8 Identity verification

We ask every member to verify who she is once: a renter before she books (a rental or a purchase, whatever the piece is worth) and a lender before her first piece goes live. You can do it when you sign up or later; browsing, saving and asking Mona never need it. Once you are verified you are not asked again. Stripe also verifies a lender’s identity when she sets up the payout account her earnings are paid to (section 4.1). When Stripe scores a payment as risky, or a card issuer reports a charge as possibly fraudulent, we record it as described below.

The check is run by Stripe Identity, on Stripe’s own screens.

  • What Stripe collects from you: photographs of a government-issued photo ID (a driver’s license or a passport), a selfie, and the details Stripe reads from the document.
  • What Jelly receives and keeps: the outcome only: the status (verified, needs another try, or failed), a reference to the verification, the number of attempts, the date you were verified, and Stripe’s short reason when a check has to be redone. Jelly’s systems never receive or store the ID images, the selfie, the document number or the other details on your document.
  • What Jelly can see at Stripe. Stripe makes the verification, including the images, available to Jelly inside our Stripe account. We do not download or copy them. A person at Jelly looks at them there only when a check needs a person to review it.
  • How many tries you get. A check can be tried up to five times. After that, a person at Jelly has to look at it. A person at Jelly can record a verification by hand (for example where a document is genuine and the check keeps failing on it) and must give a written reason, which is kept in our internal audit log with their name and the time.
  • What a flagged payment means for your data. When Stripe scores a payment as risky, or an issuer reports a charge, Jelly records which signal it was, when, and on which order, so that we can ask you to verify and a person can review the order. Nothing is cancelled or refunded automatically because of it, and the other member on the rental is not told.

Biometric information notice. Comparing your selfie with the photo on your ID uses facial recognition technology. To make the comparison, Stripe creates measurements of the geometry of your face from the selfie and from the photo on your ID. Some state laws, including those of Illinois, Texas, Washington and Colorado, call these measurements biometric identifiers or biometric data.

  • Who collects it. Stripe collects and processes it, as our service provider and, for its own fraud-prevention purposes, on its own account. Jelly never receives, stores or has access to your biometric identifiers.
  • Why. Only to confirm that the ID belongs to the person presenting it, and so to prevent fraud on Jelly. It is not used for anything else.
  • Consent. Stripe asks for your consent on its own screens before it captures your ID and selfie, and our Terms of Service record that, by starting a check, you consent to Stripe collecting and processing your ID and images for this purpose and telling us the result. You do not have to give it, but a booking that requires verification cannot go ahead without a completed check.
  • How long it is kept. Stripe’s published policy is that the biometric identifiers created for a verification are permanently deleted from its systems within one year, which is within the periods state laws allow. Stripe keeps the ID images, the selfie and the details read from your document under its own retention schedule, which can run for several years. If you would like Stripe to delete them sooner, write to us and we will ask Stripe to, unless we need them for a fraud investigation or a legal claim. You can also write to Stripe at privacy@stripe.com.
  • Never sold. Jelly does not sell, lease, trade or otherwise profit from your biometric identifiers, and never discloses them to anyone, because it never has them. Stripe’s use of them is governed by its own notice, at stripe.com/privacy.

Biometric data is treated as health-related information in some states. Apart from the check described here, Jelly does not collect any health information.

2.9 Condition videos and photos

Every rental is recorded at each handover, so that both sides can show what condition a piece was in when it changed hands.

  • What is recorded: a short video, between 10 and 60 seconds, filmed live with the camera in the Jelly app (never chosen from your photo library) and only once the booking has been paid for. If video is not possible on your phone, a photo is accepted instead, taken the same way, and everything in this section applies to it in the same way. A video records whatever sound the phone picks up. The lender films the piece before it goes out, the renter films it within 12 hours of it arriving and again before it goes back, and the lender may keep an optional record of the piece as it came back.
  • What we keep with it: the recording, which stage it belongs to, how long it runs, when it was filmed and uploaded, which member filmed it, and any note that member added: a choice from a fixed list (“as described”, “needs cleaning”, “marks or damage”, “missing piece”) and, if they wrote one, a short note in their own words, which the other member can read. Nothing is read out of a recording automatically: it is not analysed, not scanned, and never used to train anything.
  • Who can see it: the two members on that rental and Jelly’s support team, through a link that expires after ten minutes. A condition video or photo is never public, never appears on a listing, and is never shown to anyone who is not on the rental it belongs to. It may show the inside of your home, which is why it is treated this way. Please avoid filming other people.
  • If you do not film the piece when it arrives, within 12 hours, you lose the right to report a problem or ask for a fit refund on that rental. We tell you at delivery, and again two hours before the deadline.
  • How long we keep it: section 9.

The parcel photo (shipped orders only, optional). Whoever ships a leg may photograph the packed, labelled parcel before the carrier collects it: up to three photos, taken live with the camera in the Jelly app. We keep the photo, when it was taken, which member took it and which label it shows. Because the label carries both members’ names and addresses, only the member who took it and Jelly’s support team can see it, never the other member. We use it as evidence if the carrier changes its charge for the parcel and the charge is questioned. It is kept on the same schedule as condition videos and photos (section 9).

2.10 The waitlist

If you join the waitlist on our website without an account, we keep your email address, the page you joined from, and when, and our activity record notes the IP address and device description it came from. We use your address only to tell you about Jelly, and we keep it until you leave the list or ask us to remove it.

2.11 What we do not collect

Some of this is worth saying plainly, because a marketplace could reasonably be assumed to do it, and Jelly does not.

  • We do not buy information about you from anybody. No background checks, no criminal or court records, no public-records or identity data beyond the outcome Stripe returns (section 2.8), no credit data, and nothing from a data broker.
  • That includes when something goes wrong. If a piece is not returned, a payment is disputed or an account is flagged for review, we work from what is already on your Jelly account (the rental, the payments, the messages, the condition recordings, and the activity and security records) and from what our payment processor tells us about those payments, and nothing else.
  • We do not keep a history of what you search for or look at. The app remembers your recent searches on your phone (section 7); they are not stored on our servers.
  • We do not read your contacts or your photo library. The app sees only the photos you choose or take for a particular purpose.
  • We do not check the pieces themselves. We do not photograph, inspect or authenticate anything, and we hold no record of a piece beyond what its members filmed and wrote.

2.12 Where it comes from

  • From you: what you enter, upload, film, write and choose.
  • From your device: IP address, device description, push token and, only if you ask us to use it, your location (section 2.2).
  • From other members: reviews and ratings of you, messages to you, reports about you, a lender’s condition recording of a piece you rented, and the details of a claim involving you.
  • From the companies that help us run Jelly: Stripe (payment status, payout account status, fraud signals and verification outcomes), Twilio (whether your phone code was approved), Apple (your Apple sign-in identifier and email), couriers and carriers (delivery status and tracking), the US Postal Service through EasyPost (corrections to an address you save), and our email provider (whether an email was delivered).

3. How we use it

  • To run your account, keep you signed in and keep your account secure.
  • To show you pieces in your size, that can reach you, and that are free on your dates.
  • To take payment, itemise it, hold and release amounts, apply credits and pay lenders.
  • To book couriers, buy shipping labels, schedule carrier pickups and get a piece from one door to another.
  • To show listings, reviews, Looks, Requests and closets to other members, within the limits in section 5.
  • To send you what you need about your account and your rentals, and the alerts you ask for.
  • To answer support requests, and to mediate issues and claims between members.
  • To detect and stop fraud, counterfeits, abuse and security threats, and to enforce our Terms.
  • To run Mona and the other features in section 6.
  • To keep the Services working, to understand how they are used, and to fix and improve them.
  • To meet our legal obligations and to establish, exercise or defend legal claims.

We do not use your information to build advertising profiles, and we do not run behavioural advertising.

3.1 Texts, emails and notifications

  • Texts. We text you a code when you sign up or sign in, and when you add or change a phone number. If you lend, we may also text you about an offer on one of your pieces that is waiting for your answer. We never send marketing texts. Message frequency varies, and your carrier’s message and data rates may apply. Reply STOP to any text from Jelly to stop receiving texts, or HELP for help. You can also stop offer texts by turning off money notifications in your settings. Sign-in codes are part of how your account works, so you cannot turn those off and keep signing in with your phone.
  • We do not share your mobile number, or your agreement to receive texts, with anyone for their own marketing. The only companies that receive your number are the service providers in section 4 that deliver texts, deliveries and pickups for us.
  • Emails. We send receipts, notices about your rentals, offers, payouts and account, and the alerts you set up. We do not send marketing email to members. You can turn email off, entirely or by kind, in your notification settings; emails you need in order to use your account (sign-in and verification codes, password resets and security notices) are sent regardless.
  • Push notifications are sent only if you allow them on your device. You can turn them off, entirely or by kind, in your notification settings or in your phone’s settings.

3.2 Things that happen automatically

Some steps on an order happen automatically, based on what has happened on it: a late fee starts when a return is late, a booking that needs an identity check asks for one, and the steps the Terms describe for a piece that is not returned begin on schedule. Jelly does not use profiling to make decisions that have legal or similarly significant effects about you. If you disagree with anything that happened automatically on your account, write to us and a person will review it.


4. Who we share it with

We share personal information only as this section and section 5 describe.

4.1 Stripe: payments

Card payments and lender payouts are processed by Stripe. Your card details go to Stripe directly. When we create your Stripe customer record we send Stripe your name, email address and Jelly account number. Lender payouts run through Stripe Connect, and Stripe collects the identity and bank details it needs to pay you. Stripe scores each card payment for fraud risk and tells Jelly the score, and passes on an issuer’s report that a charge may be fraudulent; Jelly uses these only to decide whether to ask a renter to verify her identity (section 2.8) and to flag the order for a person to review. Stripe also runs identity verification (section 2.8). Stripe handles this information under its own privacy policy as well as on our behalf.

4.2 Couriers, carriers and shipping platforms: delivery

When a courier delivers, we send the courier company (Uber Direct or DoorDash Drive) the pickup and drop-off addresses, a contact name made of “Jelly” and the first name of the member at each end, the phone number of the member at each end (the phone saved on that address, or your account phone), and a description of the parcel as a garment. DoorDash also receives a reference that contains Jelly’s own number for the piece and for the renter’s account. A courier needs an address to drive to and a number to call. No other detail about you is sent.

When a piece is shipped, we buy the label through Priority Shippers, a shipping platform operated by ShipBoss Ltd., for a UPS label, or through EasyPost (Simpler Postage, Inc.) for a USPS label. For each end of the leg we send the platform a first name and last initial, the street address, whether it is residential, and the parcel’s size and weight, with the order’s reference. Where a piece is insured in transit, its declared value is sent too. The label names “Jelly Shop” as the sending company, above the sending member’s first name and last initial. No member’s email address is ever sent to a shipping platform, and no member’s phone number is sent with a label or printed on one; where a phone number appears on a label, it is Jelly’s own. The carrier reports the parcel’s progress back to us, which we show on the order as a city and state, never a street.

When you schedule a carrier pickup, we send the carrier (UPS through Priority Shippers, or USPS through EasyPost) your own address, your first name and last initial, the day and time window, and your own phone number, so that the driver can reach you. For a USPS pickup, any instructions you add are sent too. This is the one time a member’s phone number is sent to a carrier, and it is never shown to the other member.

When you save a street address, we may send it (the street, unit, city, state and ZIP code, and nothing else) to EasyPost, which checks it against the US Postal Service’s address records. If the Postal Service corrects the ZIP code, city or state, we save the corrected version and tell you; if it cannot confirm the address, we save it as you typed it and say so.

Couriers, shipping platforms and carriers use what we send them to complete the delivery or pickup, and they handle it under their own privacy policies as well as their agreements with us.

4.3 Service providers

We use the companies below to run the Services. They process personal information to provide their service to us.

ProviderWhat it does for JellyWhat reaches it
RailwayHosts our servers, database, uploaded files and backupsEverything the Services store
CloudflareDomain, network and security in front of our websites; hosts app.onjelly.comWebsite traffic, including IP addresses, in transit
StripeCard payments, holds, refunds and lender payouts (section 4.1)Card details (entered directly with Stripe); your name, email and account number; payout, bank and tax details
Stripe IdentityThe ID and selfie check (section 2.8)Your photo ID, your selfie and what Stripe reads from the document. Jelly receives only the outcome
TwilioSends and checks sign-in codes; sends texts (section 3.1)Your mobile number, and the words of any text we send you
AppleSign in with Apple; delivers push notifications to iPhonesYour Apple sign-in; a push token and the notification’s words
ExpoSends push notifications to your deviceA push token, and the notification’s title and words
ResendSends our emailYour email address and the contents of that email
xAIMona’s replies, Jelly Support’s AI assistant, and reading photographs (section 6)What section 6 describes, and nothing else
Google Cloud (Vertex AI)Turns a photograph into the numbers that let “find this piece” search by picture (section 6)The image of a listing’s cover photo, or of a photo you search with. Nothing else
SearchApi, SerpApi or DataForSEOFinds shops that sell a product you ask us to track (section 6). One is chosen for our deployment; the others are not calledThe product words or link you give us, the words of a request you make to Mona to find a product, or a temporary link to a photo you track with
Uber Direct / DoorDash DriveCourier delivery (section 4.2)Addresses, first names and phone numbers of both ends
Priority Shippers (ShipBoss Ltd.)UPS labels, rates, tracking and pickups (section 4.2)For each end: first name and last initial, street address, residential or not; the parcel’s details and the order’s reference. For a pickup you book: your phone number
EasyPost (Simpler Postage, Inc.)USPS labels, rates, tracking, parcel insurance and pickups; checking a saved address with the US Postal Service (section 4.2)For a label: the same as Priority Shippers. For a pickup you book: your phone number and instructions. For an address check: the street, unit, city, state and ZIP code only
UPS and USPSCarry shipped parcelsWhat is printed on the label, and for a pickup, your phone number
SentryCrash and error reports, when switched on (section 2.7)Error details, the screen and app version, your account number, and for server security alerts an IP address
PostHogProduct analytics, when switched on (section 2.7)A fixed list of event names, with your account number and identifiers such as a piece or order number

4.4 Other members

What other members can see is set out in section 5.

4.5 Legal requirements, safety and our rights

We may disclose information where the law requires it, such as in response to a valid subpoena or court order; where we believe in good faith it is needed to protect the safety of a member or the public; to investigate or prevent fraud or a breach of our Terms; or to establish, exercise or defend a legal claim. Where the law allows and it is practical, we will tell you about a legal demand for your information before we disclose it.

4.6 If Jelly’s business changes hands

If Jelly is involved in a merger, acquisition, financing, reorganisation or sale of all or part of its business, personal information may be transferred as part of that transaction. It will remain subject to the promises in this policy, and if the new owner wants to use it in a materially different way, you will be told first.

4.7 At your direction

We share information when you ask us to, for example when you share a Look, a piece or your closet by link, or make a Look public.

4.8 We do not sell your personal information

We do not sell your personal information, and we do not share it for cross-context behavioural advertising (targeted advertising). We have not done either in the past twelve months. There is no advertising software in the Jelly app, no advertising network connected to our servers, and no advertising or analytics tag on the website. We do not disclose personal information to anyone for their own marketing.


5. What other members see

Your public profile shows:

  • your first name and your handle
  • your profile photo and bio, if you added them
  • your neighborhood (the area of your default address, never the address itself)
  • your height and your fit note, if you added them, and your sizes if you choose to show them on your closet
  • your social handles, if you added them
  • your ratings (as a lender and as a renter) and the reviews written about your pieces and your closet
  • your labels, such as the Verified seal, and the month you joined
  • your closet (the pieces you have listed) and its figures: how many followers it has, how many pieces you have lent, sold, rented and bought, how quickly and how often you answer offers, how many offers have lapsed, and whether you have been active today
  • your public Looks, if you make a Look public, and the Requests and replies you post

The Verified seal shows that you have completed the identity check in section 2.8, or that a person at Jelly has recorded your verification by hand. The other labels, and what earns each one, are explained in the app.

Your rental and lending history. Unless you turn it off, anyone, including people who are not signed in, can open the pieces you have rented or bought, and the pieces you have lent or sold, from your closet, as a list of the pieces only: no dates, no prices and no other member. You can turn either list off in Account → Privacy. The counts stay on your profile either way.

What a lender writes about you as a renter is not shown on your profile or to other members. Your renter rating, the number, is public.

Other members never see your full name, email address, phone number or date of birth, and they do not see your street address except in the one case below. This is enforced in our code: everything that can reach another member passes through a single layer that removes those details, and an automated test checks it.

The one exception is a shipped order (section 4.2). A shipping label shows the recipient’s first name, last initial and address, and names “Jelly Shop” as the sender; under that name it also carries the sending member’s first name, last initial and address, as the return address. So on a shipped order, each of you sees the other’s first name, last initial and address: on the label you print, and on the parcel that arrives. The label file is available only to the member who ships that leg (and to Jelly’s support team), and the address appears nowhere else in Jelly. We tell a renter this at checkout before a shipped order is booked, and a lender when she allows shipping.

Where the lender offers a handoff, the two of you meet in person and see each other. Jelly arranges no part of a handoff and records no place for one: where you meet is whatever the two of you agree, and a handoff reveals no address unless you choose to meet at one. Meeting somewhere public is safest. Where a piece travels by courier, you never meet and neither of you sees the other’s address.

Blocking. If you block a member, neither of you can message the other. The member you block is not told.


6. Mona and the other AI features

Mona is the stylist in the app and on the website. Jelly also uses AI to read photographs (to search by picture, to find a piece you have seen elsewhere, and to help fill in a listing) and to answer first in a Jelly Support chat, and the Sale Tracker uses shopping-search services to find shops that sell a product. This section says exactly what each of these sends, and to whom.

6.1 We ask first

Nothing of yours described in this section (your messages to Mona, what Mona remembers, your messages to Jelly Support, or a photograph you take or choose) is sent to xAI or to Google until you have said yes, on a screen in the app or on onjelly.com that names both companies and says what each receives. The same answer covers a photograph you use to track a product (section 6.6). We keep a record of your answer and when you gave it. You can change it at any time in Account → Privacy; from then on, nothing further is sent. If what we send, or who we send it to, changes, we ask you again.

If you have not said yes, or you turn it off, Mona still answers you, from Jelly’s own software; a Jelly Support chat is answered by Jelly’s own software or by a person on our team; a link you paste is read from the page’s own words; and searching with a photo, tracking with a photo and filling in a listing from its photos are unavailable.

Three things in this section do not depend on your answer. The cover photo of every published listing, which is already public on Jelly, is processed for picture search (section 6.5). When a product is looked up from a shop’s link, the shop’s own public product image may be read by xAI or used to find the product elsewhere (section 6.6). And looking a product up by its name or its link sends those words to a shopping-search provider, which is not an AI service (section 6.6).

6.2 Mona

Mona’s replies are written with the help of an AI model from xAI (the maker of Grok), acting as our service provider. Which pieces Mona shows you is decided by Jelly’s own software on Jelly’s servers, not by the model: the model can only choose among pieces our system has already checked are real, in your size, free on your dates and inside your price range.

To answer you, we send xAI:

  • your message and the last several messages in the same conversation, yours and Mona’s. Before anything is sent, our software removes email addresses, phone numbers, card numbers and street addresses that it recognises. It cannot catch every way of writing them, so please do not give Mona contact or payment details;
  • your size, height and neighborhood (the area of your default address). If you tell Mona you are shopping for someone else, your size and height are left out;
  • your style preferences, a short summary of the brands and colors you save, rent and set alerts for, and what Mona remembers (section 6.3);
  • what you are looking for in the conversation (the occasion, dates, size, budget, pieces you passed on and why) and the names of your alerts and Looks;
  • the public details of the pieces Mona is considering: title, brand, size, category, colors, tags, neighborhood, the price for the rental period and for your dates, any sale price, the lender’s fit refund policy, the lender’s fit note or an extract of the description, and up to three renters’ reviews of the piece, without their names;
  • the results of what Mona looks up for you: a price for your dates, whether the pieces in a Look are free, or the shops and prices for a product.

We do not send xAI your name, handle, email address, phone number, street address, payment details, order history, or any lender’s identity.

6.3 Your style preferences, and what Mona remembers

Your style preferences are your sizes, the brands and colors you like and avoid, how you dress, your neighborhood and what you would spend. They are yours to edit or empty at any time, on Your style and Your sizes and fit.

  • When you tell Mona a preference about yourself, she changes it for you. If you say “I love Farm Rio”, “I don’t wear yellow” or “I’m a 6 now”, Mona updates that preference on your account, tells you she has, and shows a card with an Undo. She does this only for something you say about yourself, never for what you ask her to find for one occasion, never from what you tap, and never for someone else you are shopping for. Each change she makes is listed on Your style for 30 days with an Undo, and our record of it is deleted after 90 days.
  • Your preferences only change the order in which pieces are shown to you. They never hide anything.

What Mona remembers is a list of things you have told her that are useful in a later conversation and that your preferences have no place for: for example that you work in finance, that you would rather rent than buy, or that your sister’s wedding is in June.

  • What she does not keep. She does not keep what you are looking for in the current conversation, such as this Friday’s dinner. She does not note your health, religion, sexuality, politics, ethnicity or finances unless you ask her to remember them. She never notes comments about your body, identity or account numbers, immigration or criminal status, money amounts, contact details or addresses, even if you ask. Our software refuses those notes whoever proposes them, and Mona is instructed never to note other people’s names.
  • How long notes are kept. She keeps at most thirty notes. A note about a plan is deleted once its date has passed. Any other note stays until you delete it or turn remembering off, or until the list is full and it is the one she has used least recently.
  • When notes are made. Most notes are made during the conversation, and a “Memory updated” note appears under her reply when one is. Jelly’s own software reads your message for them, and the AI model that already reads your message may suggest one. After a conversation has been quiet for a while, we send it to xAI once more to check for anything worth keeping that was missed. This second send uses the same words with the same details removed, and nothing new about you. Messages about shopping for someone else are left out. Anything this check adds is shown on the conversation, and if the model is unavailable, Jelly’s own software decides instead and nothing is sent.
  • Your controls. Everything she remembers is shown to you in full, under Account → Mona remembers. You can delete any note or all of them. You can also turn remembering off, which deletes every note. A note you delete is not made again from anything you said before you deleted it. Your notes and the changes she made are included in your data download.

6.4 Photos: search, “Source this” and filling in a listing

  • Searching with a photo. If you search with a photograph (from the camera, your photo library or a link you paste), the picture is sent to xAI to be described: what kind of piece it is, its colors, and the brand if a label is visible. Location and camera data are removed from the picture before it is sent or stored. Only the picture goes; nothing identifying you goes with it. A photo you search with is not kept unless you choose to attach it to a Request. A photo you send Mona in a conversation is uploaded first and deleted by a daily clean-up once nothing uses it, at least a day later.
  • Pasting a link. When you paste a link, Jelly’s servers fetch that public web page to read its title and main image; the page’s owner sees a request from Jelly, not from you. For a link you search with, we record only the site’s name. A link you paste to Mona stays in your conversation as you wrote it.
  • Filling in a listing (“Autofill with AI”). When you tap it, up to four of that listing’s photographs are sent to xAI in the same way, together with what you have already typed into that listing (its name, and a brand, category or colors you have picked) to suggest a name, a short description, a category and colors, and the brand when a label shows it or you have named it. The suggestions are put into the form for you to check and change, and nothing is saved until you save it. Anything about size, fit, condition, price, value or authenticity, anything describing a person, and any brand that is not on a label and that you did not name is removed before you see it.

What comes back from the model is used only as search words or as suggestions, and is checked against Jelly’s own lists of brands, categories and colors before anything is shown to you.

6.5 Searching by picture

Reading words off a photograph finds a hundred similar dresses; it does not find the dress. So a photograph is also turned into a string of numbers (a description of the picture that a computer can compare, and that no person can read or turn back into an image) and compared with the same kind of numbers held for pieces currently listed.

  • The numbers are made by Google, using its Vertex AI service, which is sent the image and nothing else: no name, no handle, no account number, no words.
  • The cover photo of each published listing goes through this once, in the background after the piece is published. What is kept beside the listing is the numbers, not a copy of the photograph, and they are deleted when the listing is removed with its owner’s account.
  • A photograph you search with is not kept. It is turned into numbers, compared, and dropped.

6.6 Sale Tracker

If you ask Jelly to track a product at retail (by sharing or pasting a shop’s link, typing its name, taking a photograph, or asking Mona), we look for the shops that sell it and check them again over time.

  • What goes to the shopping-search provider (section 4.3): the brand and the name, the link you pasted, or the words a photograph was read as. When you ask Mona to find a product, the words of your request are used. Never your name, handle, account number, size, location or conversation.
  • If you track with your own photograph (which needs your yes in section 6.1), the photograph, with location and camera data removed, is placed at a temporary, unguessable web address on our servers for the length of one search, so that the provider can ask Google Lens to look at it, and it is deleted as soon as the search ends. When you track from a shop’s link, the shop’s own public product image may be used the same way.
  • How we read shops’ pages. We fetch the shops’ own public product pages from Jelly’s servers, signed out, as a crawler that identifies itself as Jelly (JellyBot/1.0), obeying each site’s robots.txt. Our regular checks send one request to a shop at a time, at least three seconds apart, or slower if the site asks. We do not get around a site’s bot protection. The shop sees a request from Jelly, and it carries nothing about you. If a shop declines our requests, we stop asking it for a week and read that shop’s price from the search provider’s data instead.
  • Checking two listings are the same product. Where this is switched on, we may ask xAI whether two shops are selling the same product; only the product names and the shops are sent.
  • Price history belongs to the product, not to you. We keep one price reading a day for each shop that lists a tracked product, for ninety days, on a shared record of that product. It says nothing about who is watching.
  • Your tracks are yours. Which products you track, what you asked to hear about, and which shops you left out are private: no lender, no other member and no shop is told that you are watching a piece. They are deleted with your account.
  • Links to shops carry nothing of ours. When you open a shop from Jelly, the link has no Jelly tracking tag and does not pass through us.

6.7 Jelly Support’s AI assistant

When you start a chat with Jelly Support, an AI assistant may answer first, while a person on our team can join and take over at any time. Its messages are always labelled Jelly Support · AI. It is not Mona, and it is not a person.

  • What it does. It explains the state of your own rentals, the charges and payouts on them and how Jelly works, from your orders, Jelly’s published policies and our help centre. It cannot change anything: it does not refund, cancel, charge, rebook or edit anything, and it does not decide whether anyone is owed money.
  • It hands you to a person whenever the matter is one only a person settles (a refund, a cancellation, a payment or payout, a courier that has not come, damage, a piece that has not come back, or your safety), when it is not sure of the answer, when you are unhappy with it, or when you ask for a person a second time. There is no button to press: say so in your own words. The first time, it answers what you asked and tells you that asking again brings someone in. Anyone on our team can also join your chat at any time. Once a person has your chat, the assistant stops answering in it.
  • What we send xAI to answer you: your messages in that chat and the earlier messages in it, yours and Jelly Support’s, with email addresses, phone numbers, card numbers and street addresses removed first; and your own orders only (for each, its order reference, the piece’s title and brand, whether you are renting or lending it, its dates and where it is up to, and for the order the chat is about, how each leg is travelling, what you paid or will be paid, and any fee, hold, refund, credit or extension on it), with your credit balance, any amount you owe and whether your payout account is set up. It can read these; it cannot change them.
  • What we never send: your name, handle, email address, phone number or street address, your payment details, anything about the other member on a rental, or anything about any other member.
  • What we keep: the conversation stays in your Jelly Support conversation (section 2.5), with a short summary the assistant writes for the person who picks it up. If our checks stop an answer it wrote, we keep that unsent answer with the conversation, for our team only, so we can see what went wrong; email addresses, phone numbers, card numbers and street addresses are removed from it first. If you flag one of its replies, your flag and anything you write with it stay with the conversation too. We also keep a record of each answer it gives (whether it answered or handed over, why, how long it took, and which help-centre sections and published policies it drew on) that holds none of the words.

6.8 What the AI and search companies do with it

  • xAI processes what we send only to produce the reply or description we asked for. Its published terms say it does not train its models on what we send without our explicit permission, and that it keeps requests for up to 30 days to watch for abuse, and then deletes them.
  • Google processes the photographs it receives as our service provider under its Google Cloud terms, which do not allow it to use them to train its models without our permission.
  • The shopping-search provider uses what we send to run the search and return shop listings.

If an AI service is unavailable, Mona answers from Jelly’s own software alone and nothing is sent; a Jelly Support chat is answered by Jelly’s own software or goes to a person; photo search falls back to Jelly’s own software, and no picture leaves our servers.


7. Cookies and similar technologies

The website sets no advertising cookies and carries no advertising or analytics tag, no conversion pixel and no social-media pixel. It uses a few cookies and a little browser storage of its own, to keep you signed in and to remember your choices:

NameWhat it is forHow long it lasts
jelly_sessionKeeps you signed in. It cannot be read by scripts on the page30 days
jelly_stay_webRemembers that you chose to stay on the website rather than open the app30 minutes
jelly_zipThe ZIP code you asked us to show delivery for1 year
jelly_refThe invitation link you arrived through, so the friend who invited you is credited30 days
Browser storageYour delivery ZIP code, and a message to Mona that has not been sent yetThe ZIP code until you clear it; the message until you close the tab

On the payment and payout steps, Stripe loads its own script, which sets Stripe’s own cookies to process the payment and prevent fraud. They are governed by Stripe’s privacy policy.

If we ever add analytics to the website, we will update this policy before it goes live.

In the app. The iPhone app keeps your sign-in in the iOS Keychain, and remembers your recent searches and some display choices on your phone. The version of the app at app.onjelly.com keeps the same things in your browser’s storage. The app contains no advertising software, no advertising identifier and no conversion pixel, and it never asks to track you across other companies’ apps or websites. It includes the Sentry and PostHog software described in section 2.7, which sends nothing unless we switch it on.

Your choices. You can block or delete cookies and browser storage in your browser’s settings. If you block jelly_session, you will not be able to stay signed in on the website.

Do Not Track and Global Privacy Control. Some browsers send a “Do Not Track” or “Global Privacy Control” signal. Our website does not change its behaviour in response to Do Not Track. A Global Privacy Control signal asks a business not to sell or share your personal information for advertising. Jelly does neither, for anyone, so what the signal asks for is already how Jelly works whether or not your browser sends it. If that ever changes, we will honour the signal as a valid request to opt out.


8. How we protect it

We use reasonable administrative, technical and physical safeguards designed to protect personal information, appropriate to its sensitivity. They include:

  • Information travels between your device and Jelly encrypted.
  • Passwords are stored as scrypt hashes with a unique salt and compared in constant time; sign-in and verification codes and links are stored hashed; the Apple sign-in token is encrypted.
  • Sessions use random tokens that expire 30 days after last use and end when you sign out; on the website, the session cookie cannot be read by scripts on the page.
  • Sign-in attempts and other sensitive actions are rate-limited, and we keep the security record described in section 2.7.
  • Addresses, phone numbers and email addresses are removed from everything that reaches another member (section 5).
  • Condition recordings and shipping labels are never publicly reachable: a recording is shown through a short-lived link to the members on its rental, and a label only to the member who ships that leg.
  • Listing and profile photos are re-encoded when they are uploaded, which removes their hidden data, such as location.
  • Only Jelly staff with an @onjelly.com account, a password and a code emailed to them at each sign-in can reach our internal tools. Our support desk hides your address and phone number until a person reveals them, which needs a reason and is recorded. Opening your conversation with Mona, other than from a reported reply or a support case, needs a reason and is recorded. Staff actions such as suspending an account, recording an identity check by hand or revealing contact details are recorded in an internal audit log.
  • We ask our service providers to protect the information we send them.

No system is perfectly secure, and we cannot guarantee the security of information. If a breach of security affects your personal information, we will notify you, and the authorities, as the law requires.


9. How long we keep it, and deleting your account

We keep personal information for as long as we need it for the purposes in section 3, and then delete it or remove what identifies you. Where a fixed period suits the information, we set one, and our systems apply it automatically every day. Where it does not (because a record belongs to two members, or because the law requires us to keep it), we say what decides how long it is kept.

WhatHow long
Your account, profile, listings, saved pieces, Looks, alerts, tracks and addressesWhile your account is open
Sessions (signed-in devices)30 days after last use
Sign-in and verification codes, links and receipts1 day after they are used or expire, stored hashed throughout
Security record (includes IP address and device)30 days
Activity record (includes IP address and device)365 days
Record of emails we sent you (never the contents)365 days
Failed supplier calls, and receipts of our suppliers’ status updates30 days
Notifications90 days after you read them; unread ones while your account is open
A diagnostic trail you sent us30 days
Condition videos and photos, and parcel photos90 days after the rental closes. If an issue or claim refers to that rental, while it is open and for one year after it is resolved. A recording on a rental that was cancelled is kept with the order until you ask us to delete it
What Mona remembersAt most 30 notes. A note about a plan is deleted once its date has passed; any other note stays until you delete it, turn remembering off, or the list is full and it is the one used least recently (section 6.3)
Changes Mona made to your style preferences90 days, so you can see and undo them (section 6.3)
Your conversations with MonaWhile your account is open; deleted with it
Messages between you and another memberWhile either member’s account is open, because a conversation belongs to both people in it
Support conversations, cases and help requestsFor as long as they may be needed to resolve a dispute, handle a claim or meet a legal obligation, as our record of what we were asked and what we did
Shipping label filesWith the order, until the label is cancelled or you delete your account
Your identity verification outcomeWhile your account is open
Rental, payment, credit, payout, claim and review recordsFor as long as tax, accounting and other laws require and any dispute or claim about them can arise
Our internal audit log of staff actionsKept as a lasting record of what our staff did
Records of your consent to our Terms and to the outside AI servicesKept as proof of what you agreed to, including after your account is deleted
The waitlistUntil you leave the list or ask us to remove you
Backups of our databaseReplaced as they rotate, normally within about a week

Our service providers keep what we send them for the periods set out in their own terms and policies. Stripe, for example, keeps payment and verification records for as long as the law requires it to (section 2.8).

Deleting your account

You can delete your account yourself, in the app under Account → Delete account, or on the website under Account → Privacy. You can also write to info@onjelly.com and we will do it for you.

When you delete your account:

  • Your name, email address, password, phone number, date of birth, ZIP code, saved addresses, fit profile, style preferences, social handles, profile photograph (the file itself, not only the link to it), Apple sign-in identifier and identity verification outcome are erased, and your handle is released.
  • If you signed in with Apple, we ask Apple to withdraw Jelly’s access to your Apple account, and erase the token we held for it. If Apple cannot be reached at that moment, your account is deleted anyway.
  • Your saved pieces, Looks, follows, alerts, tracks, notifications, push tokens and Mona’s notes and conversations are deleted, and we delete your customer record at Stripe, with your saved cards.
  • Your listings come off Jelly and stop being bookable. Their photos and descriptions stay in our records alongside the orders they belong to, and their picture-search numbers are deleted.
  • Your activity and security records are kept as a record that something happened, with the IP address and device description removed. The record of emails we sent you is kept with your email address removed.
  • Shipping label files for your orders are deleted, and your name and street address are removed from the shipment records.
  • Help requests you sent without signing in keep your message, with your email address, phone number, IP address and device description removed.
  • What we keep on purpose: your rental, payment, credit, payout, claim and outstanding-balance records; reviews you wrote and reviews written about you; Requests you posted that other members replied to; reports and safety records involving you; messages you sent, which stay in the other member’s inbox; support conversations; our staff audit log; and your consent records. These are kept without your name or contact details attached (the account behind them becomes “Deleted member”) because they are other members’ records too, and because tax, accounting and fraud-prevention rules, and the need to resolve disputes, require us to keep them.
  • Condition videos and photos follow the schedule in the table above rather than being deleted at once: where one is the other member’s evidence, it is kept until the rental or claim it belongs to is settled.
  • Copies in our backups are replaced as the backups rotate, normally within about a week.
  • What our providers hold. Deleting your Jelly account does not delete what our service providers keep under their own legal obligations, for example Stripe’s payment and payout records, or a courier’s or carrier’s delivery records. If you lend, your Stripe payout account is not closed automatically; you can close it with Stripe, or ask us for help. If you want Stripe to delete your identity verification images, see section 2.8.

We cannot delete an account in the middle of a rental. If a rental is still on its way, out, due back or on its way back, or a claim is open, the app will say so and ask you to finish or cancel it first. Someone else is holding your piece, or you are holding theirs.

We cannot delete an account with money outstanding on it. If a late fee, a replacement value or another charge is still unpaid, the app will say the amount and point you to Account → Balance. Settle it and the account can be deleted.

Deletion is immediate and cannot be undone. You can sign up again afterwards; it will be a new account with nothing carried over.


10. Your choices and your rights

We give every member the rights below, wherever in the United States she lives. Some state laws give these rights by law, and section 10.4 and 10.5 describe them; some of those laws apply only to businesses above a certain size, but we honour the requests they describe for everyone.

10.1 What you can do yourself, today

  • Get a copy of your data. Account → Download my data (in the app, or Account → Privacy on the website) gives you a machine-readable file of most of what we hold about you: your profile, addresses, consents, listings, orders, offers, credits, payouts, messages you sent, your messages to Mona, what Mona remembers and the changes she made to your style preferences, reviews, notifications, alerts, saves, Looks, follows, Requests, reports, blocks, sessions and your most recent 200 activity records. Some records are not in the file yet: your condition recordings, support conversations, shipment records, payout account details, your full activity history, and your security and email records. Ask us for any of them and we will provide them. The download can be made twice a day.
  • Correct it. Your name, handle, email address, phone number, addresses, sizes, fit note, bio, photo and style preferences can all be changed in the app.
  • Delete your account (section 9).
  • See and delete what Mona remembers, or turn remembering off, and undo a change Mona made to your style preferences (section 6.3).
  • Turn off the outside AI services in Account → Privacy (section 6.1).
  • Hide your rental and lending history in Account → Privacy (section 5).
  • Choose what we send you in your notification settings (section 3.1).

10.2 What you can ask us for

You can ask us to:

  • confirm whether we hold personal information about you, and tell you what we hold, where it came from, why we use it and who we disclose it to;
  • give you a copy of it, in a portable format;
  • correct information that is inaccurate;
  • delete it, subject to the exceptions below;
  • opt out of the sale of personal information, of targeted advertising and of profiling that has legal or similarly significant effects, none of which Jelly does (sections 3.2 and 4.8);
  • limit our use of sensitive personal information to what is needed to provide the Services, which is already all we use it for (section 10.4);
  • where we rely on your consent, withdraw it.

When we may say no to deleting something. We may keep information where the law allows it, for example where we need it to complete a rental or purchase you are part of, to detect and prevent fraud or security incidents, to meet a legal obligation such as tax and accounting rules, to establish or defend a legal claim, or because it is also another member’s record. If we keep something, we will tell you what and why.

10.3 How to make a request

Email info@onjelly.com from the email address on your account, with the subject “Privacy request”, and say what you are asking for. If you are signed in, the tools in section 10.1 are the quickest route.

  • Verification. To protect you, we confirm that a request comes from the account holder before we act on it. We match the details in your request against those on your account and may send a code to the phone number or email address on your account. We will not ask for more information than we need, and we use it only to verify your request.
  • Someone acting for you. You may use an authorised agent. We will ask the agent for your signed permission, and may ask you to confirm your identity with us directly, unless the agent holds a power of attorney.
  • Timing. We respond within the time the law that applies to you requires, and we will tell you if we need longer and why.
  • Appeals. If we decline your request, you can appeal by replying to our answer or by writing to info@onjelly.com with “Privacy appeal” in the subject. We will review the decision again and tell you the outcome and the reasons. If we deny your appeal, you may contact the attorney general of your state.
  • No discrimination. We will not deny you the Services, charge you a different price or give you a different level of service because you exercised a privacy right. We do not offer any financial incentive or price difference in exchange for personal information; referral credits under our Terms are for introducing a friend who rents, not for giving us information.
  • Requests are free. If requests from one person are clearly unfounded or excessive, the law may allow us to charge a reasonable fee or decline; we will tell you if so.

10.4 California residents

If you live in California, the California Consumer Privacy Act (as amended by the California Privacy Rights Act) gives you the rights to know, access, correct and delete personal information, to opt out of its sale or sharing, to limit the use of sensitive personal information, and not to be discriminated against for exercising these rights. Sections 10.1 to 10.3 describe how to use them.

In the past twelve months we have collected the categories below, from the sources in section 2.12, for the purposes in section 3, and kept them for the periods in section 9. We have disclosed each category for a business purpose only to the recipients shown. We have not sold or shared any of them.

CategoryExamples at JellyDisclosed to
IdentifiersName, handle, email address, phone number, postal address, account number, IP address, push token, Apple sign-in identifierService providers (section 4.3); couriers and carriers (section 4.2); other members, as first name and handle, and on a shipped order the name and address on the label (section 5)
Personal information in customer recordsName, address, phone number, and payment and bank details held by StripeService providers; couriers and carriers
Protected characteristicsAge, through date of birthOur hosting provider only; never other members
Commercial informationRentals, purchases, listings, offers, credits, payouts, claimsService providers; other members, as described in section 5
Biometric informationFace geometry created by Stripe during an identity check (section 2.8)Collected by Stripe as our service provider; Jelly never receives it
Internet or network activityActivity and security records, request logs, diagnostic trails, cookies, and product events when switched onService providers
GeolocationYour ZIP code and neighborhood; your device’s location once, if you ask us to use it, which is not storedService providers
Audio, visual and similarCondition videos (with sound) and photos, profile and listing photos, photos you search withService providers (section 6); the other member on a rental, for condition recordings
InferencesYour style preferences and Mona’s notes; your labels and ratingsxAI, for Mona and Jelly Support’s AI assistant (section 6); other members, for labels and ratings
Sensitive personal informationYour account sign-in details; the contents of messages between members; the government ID and selfie collected by Stripe (Jelly receives only the outcome); your device’s location, if you ask us to use itService providers, only to provide the Services

We use sensitive personal information only to provide the Services, to keep them secure and to prevent fraud (the uses the law permits without offering a right to limit), so we do not offer a separate “Limit the use of my sensitive personal information” link.

We do not sell or share personal information, and we have no actual knowledge of selling or sharing the personal information of anyone under 16. We do not disclose personal information to third parties for their own direct marketing, so California’s “Shine the Light” law gives nothing further to request.

10.5 Residents of other states

If you live in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Florida (where its law applies) or another state with a comprehensive privacy law (including Montana, Iowa, Delaware, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky and Rhode Island), you may have the rights to confirm and access your personal data, to correct it, to delete it, to get a portable copy, and to opt out of targeted advertising, the sale of personal data and certain profiling, as well as the right to appeal a decision about your request. Jelly does not sell personal data, does not use it for targeted advertising and does not profile you in ways those laws cover. Where those laws require consent before sensitive data is processed, including biometric data, that consent is collected by Stripe before the identity check begins (section 2.8). Use sections 10.1 to 10.3 to exercise any of these rights.

If you live in Nevada, you have the right to opt out of the sale of certain personal information. Jelly does not sell it.

10.6 Why there is no “Do Not Sell or Share” link

A “Do Not Sell or Share My Personal Information” link exists to switch off a sale or an advertising use. Jelly has neither, so there is nothing for such a link to switch off. If that ever stops being true, the link will be in place before the first sale or sharing, not after it.


11. Children

Jelly is for people 18 and over. It is not directed to children, and we do not knowingly collect personal information from anyone under 18. If we learn that we have collected personal information from someone under 18, we will delete it. If you are the parent or guardian of a child who has given us personal information, write to info@onjelly.com and we will delete it.


12. Where your information is held

Jelly operates in the United States and its Services are intended for people in the United States.

Our main servers (including our database, the photos and videos you upload, and our backups) are hosted by Railway in its data centre in Virginia, in the United States. Most of our other service providers process information in the United States. Some of them, including xAI, may process it in other countries where they or their providers operate. Wherever it is processed, it remains subject to this policy.

If we move where your information is held, we will update this section.


13. Changes to this policy

When we change this policy, we will post the new version here and update the date at the top.

If a change is material (for example a new kind of information, a new use, or a new kind of recipient), we will tell you in the app or by email before it takes effect. Where the change would use information we already hold in a way you have not agreed to, or where the law requires it, we will ask for your consent first. The app already asks you to accept updated Terms before you can book, list or make an offer, and asks again about the outside AI services whenever what they receive changes.

What changed on 7 October 2026: section 2.8 now says who is asked to verify their identity: every member, once (a renter before she books and a lender before her first piece goes live) rather than only for some bookings. What Stripe collects during a check, and what Jelly receives from it, have not changed. Section 5: the Verified seal now means the identity check, or a verification a person at Jelly recorded by hand, no longer a payout account. Section 2.9: condition videos and photos are taken live, only after the booking is paid for, and the optional photo of a shipped parcel is described, with who can see it; section 9 says how long it is kept. Nothing more is sent to the AI services, so the app does not ask you about them again. Punctuation has also been tidied throughout, with no change of meaning.

What changed on 1 October 2026: section 6.3. When you tell Mona a preference about yourself, she now changes it on your account, with an Undo. What she remembers now holds longer-lived facts you tell her: at most thirty notes, and only a note about a plan expires on a date. What she never keeps is spelled out. What we send to xAI has not changed: your style preferences and what Mona remembers were already sent (section 6.2). Also section 6.7 and section 2.5: Jelly Support’s AI assistant no longer shows a “Talk to a person” button (it brings in a person when the matter needs one or when you ask a second time, and anyone on our team can join a chat), and we now keep, for our team only, an answer it wrote that our checks stopped, and any flag you put on one of its replies. Nothing more is sent to xAI. For these reasons, the app does not ask you again.

What changed on 29 September 2026: section 6 now describes Jelly Support’s AI assistant (section 6.7), and “Autofill with AI” now sends what you have typed into a listing along with its photos (section 6.4). Both change what xAI receives, so the app asks you again before anything more is sent.


14. Contact

ON JELLY LLC (doing business as Jelly), 2155 Washington Ct, Miami Beach, FL 33139.

Privacy questions and requests: info@onjelly.com, with the subject “Privacy request”.