Skip to content

Privacy

A plain-language summary of how Jithox handles your data. It is an honest startup baseline, not a lawyer-reviewed document, and it says so.

Last updated: August 2026.

Jithox for WhatsApp prepares business work — quotes, invoices and customer questions — from the messages you give it. Every real-world action happens only after you approve the exact content, and every action is recorded with a receipt.

Jithox MCP answers read-only EU e-invoicing checks for software and AI agents. It processes the business identifiers a call submits — VAT numbers, Peppol participant ids, invoice documents — to answer that call.

Invoice Status sends the administration id and requested state and page filters, or the invoice number, to Moneybird. Moneybird returns sales-invoice records. Before Jithox returns selected fields to the authenticated MCP caller, it omits free invoice reference text and contact first name, last name, e-mail, phone and address. Returned invoice identifiers, dates, amounts and Moneybird company or administration names may still be personal data. Jithox invokes no AI model for this check; the caller may pass the result to its own model.

  • The messages you paste or forward, and the invoices, drafts and questions prepared from them.
  • Your business details (name, VAT number, address, IBAN) that you enter once for your invoices.
  • Customer details you explicitly save — never saved without your confirmation.
  • Approvals and receipts: who approved what, when, and what the provider confirmed.
  • Sign-in identity via our sign-in provider (e-mail, name). Its own privacy policy applies on top of ours.
  • For MCP: usage counts and signed receipts per accepted call, so a balance and an accounting trail exist.
  • For Invoice Status: the encrypted, account-bound Moneybird permission and fixed invocation and receipt-reference metadata. Jithox does not durably store the invoice query or result. Administration ids and names are cached in process: an entry is reused for 60 seconds and may remain until it is replaced or the process ends.
  • No sending, invoicing, replying or publishing without your explicit approval.
  • No invented invoice facts — only what your message or your input contains.
  • No selling of your data, and no advertising network embedded.
  • No card data stored by us. Card payments run on Stripe's hosted checkout and card details never touch jithox.com.
  • Your data belongs to your workspace only — it is never visible to another customer.

The public pages measure aggregated visits with Vercel Web Analytics, and nothing else. There is no second analytics vendor, no advertising pixel and no session replay.

The funnel events we record carry exactly three properties: which product the page belongs to, its language, and the deploy environment. No e-mail address, no account id, no phone number, no message content, no invoice data and no error text can be attached to an event, because the event shape has no field for any of it.

We also keep a first-party record of the steps between a visit and a purchase — a page viewed, a button clicked, a sign-in completed, a trial started, a key created, a call accepted or refused, a payment confirmed — in our own database, with no third party involved. Each record holds only fixed categories: the page template (never the URL or its query string), which button (a short label), the product, whether the visit came from a search engine, a social network or elsewhere (never the referring address), mobile or desktop (from the screen width, never the browser signature), and a coarse duration bucket. Access keys, tool inputs and outputs, passwords, IP addresses and payment details have no field to land in. Anonymous visitors are not identified: two events from one visit are linked only through a random value the browser sets for itself, hashed with a key that changes daily, so nothing accumulates across days. Raw records are deleted after 30 days, and any figure we publish from them is an aggregate in which counts below five are not shown.

Application data lives in our European-region database. Sign-in data lives with our sign-in provider, e-mail delivery runs through our e-mail provider, and card payments run through Stripe. We keep this list current as the product grows.

Using Jithox for your own customers' data? The data processing agreement names every sub-processor and is signed on request.

Data processing agreement

Jithox is an early-stage product. We do not claim SOC 2, ISO 27001, HIPAA or PCI certifications, and there has been no independent penetration test yet. Secrets stay server-side, workspaces are strictly separated, and every outbound action is approval-gated and receipted.

Deleting a WhatsApp connection, closing an account, removing one customer and erasing an invoice are four different requests with four different answers. The deletion page states each of them, including where the answer is no and why.

Delete your data