1. Who We Are
JellyNet (“we,” “us,” “our”) is an API capacity-sharing marketplace that enables suppliers to monetise idle API capacity and buyers (including AI agents and developers) to access pooled capacity across multiple AI and LLM providers through a single universal key.
This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, and what rights you have regarding your data. This policy applies to all users of the Platform, including visitors, suppliers, and buyers.
Data Fiduciary: JellyNet, operated from Bangalore, Karnataka, India.
Contact: admin@jellynet.net
2. Data We Collect
2.1 Account Data
When you sign in using Google OAuth or email-based authentication, we collect:
- Name and email address — provided by Google or entered directly. Used to identify your account and communicate with you.
- Profile picture — provided by Google (if available). Displayed in your dashboard.
Lawful basis: Consent (you choose to sign in) and performance of contract (we need this to provide the service).
2.2 Usage and Transaction Data
We collect the following when you use the Platform:
- API call metadata: Endpoint ID, protocol name, timestamp, response status code, latency, and token count (where applicable). Used for routing, billing, and platform health monitoring.
- Transaction records: Credit purchases, x402 payment transaction hashes, amounts, sender/receiver wallet addresses, epoch settlement records, and withdrawal history. Used for billing, earnings calculation, and audit.
- Supplier key metadata: Protocol, label, status (active/inactive/rate-limited), calls served count, and key health scores. The key material itself is encrypted at rest.
What we do NOT collect: We do not log, store, inspect, or process the content of API request bodies or response bodies. Your prompts, completions, and any data exchanged with the upstream API pass through our proxy layer in transit and are not retained.
Lawful basis: Performance of contract and legitimate interest (platform health, fraud prevention).
2.3 Wallet Addresses
If you connect a wallet or provide a Solana or Base address for x402 payments or USDC withdrawals, we store that wallet address. Wallet addresses are public blockchain identifiers and are also visible on-chain.
We do not generate wallets on your behalf, and we do not store private keys or mnemonic phrases.
Lawful basis: Performance of contract (processing payments and withdrawals).
2.4 Technical and Device Data
When you access the Platform, we automatically collect:
- IP address — used for security, abuse prevention, and approximate geolocation (country level) for analytics.
- Browser type, operating system, device type — used for troubleshooting and Platform optimisation.
- Referral source and pages visited — used for analytics.
Lawful basis: Legitimate interest (security, platform improvement).
2.5 Communication Data
If you contact us via email or in-app support, we retain the content of those communications and any associated metadata for the purpose of responding to your inquiry and maintaining support records.
Lawful basis: Legitimate interest (customer support).
3. How We Use Your Data
We use the data we collect to:
- Authenticate your account and maintain sessions.
- Route API calls through the proxy and verify payments.
- Calculate earnings, credit balances, and process withdrawals.
- Display your transaction history, earnings dashboard, and key health.
- Monitor Platform health, detect abuse, and prevent fraud.
- Communicate with you about service updates, policy changes, and (with your consent) product announcements.
- Comply with applicable legal obligations.
We do not sell your personal data to third parties. We do not use your data for advertising or behavioural profiling.
4. Data Sharing
4.1 Infrastructure Providers
We use third-party infrastructure providers to host and operate the Platform. These providers process data on our behalf under appropriate contractual safeguards:
- Fly.io — backend API hosting
- Vercel — frontend hosting
- DigitalOcean — PostgreSQL database
- Stripe — fiat payment processing
- Google — OAuth authentication
4.2 Blockchain Networks
When you make or receive x402 payments, transaction data (wallet addresses, amounts, timestamps) is broadcast to public blockchain networks (Solana, Base). This data is permanently recorded on-chain and visible to anyone. This is inherent to blockchain technology and is outside our control once a transaction is submitted.
4.3 Upstream API Providers
When the Platform routes a call through a supplier’s key, the upstream API provider receives the request as if it came from the supplier’s account. The upstream provider’s own privacy policy and data practices apply to that interaction. JellyNet does not control what upstream providers log or retain.
4.4 Legal Requirements
We may disclose personal data if required by law, regulation, legal process, or enforceable governmental request. We will notify you of such disclosure where permitted by law.
4.5 Business Transfers
In the event of a merger, acquisition, or asset sale, your personal data may be transferred to the acquiring entity. We will notify you before your data is transferred and becomes subject to a different privacy policy.
5. Data Retention
- Account data: Retained for as long as your account is active. Upon account deletion, personal data is deleted within 30 days, except where retention is required by law.
- Transaction and payment records: Retained indefinitely for audit, compliance, and dispute-resolution purposes. On-chain transaction data cannot be deleted.
- API call metadata: Retained for 12 months for operational purposes, then aggregated/anonymised.
- Technical logs (IP, browser): Retained for up to 90 days, then deleted or anonymised.
6. Data Security
We implement the following security measures:
- Encryption at rest: Supplier API keys are encrypted using AES-256 symmetric encryption before storage. Database connections use TLS.
- Encryption in transit: All data transmitted between your device and the Platform uses HTTPS (TLS 1.2+).
- Access controls: Production database access is restricted to authorised personnel and services.
- No plaintext secrets: API keys, tokens, and other sensitive credentials are never stored in plaintext.
Despite these measures, no system is perfectly secure. We cannot guarantee absolute security of your data and encourage you to use strong, unique credentials and to notify us immediately of any suspected breach.
7. Your Rights
7.1 Rights Under India's DPDPA (2023)
If you are located in India or your data is processed in India, you have the right to:
- Access: Request confirmation of whether we process your personal data and obtain a summary of it.
- Correction: Request correction of inaccurate or incomplete personal data.
- Erasure: Request deletion of your personal data, subject to legal retention requirements.
- Grievance redressal: Lodge a grievance with our Grievance Officer (see Section 11).
- Nomination: Nominate another individual to exercise your rights in case of your death or incapacity.
7.2 Rights Under GDPR (EEA/UK Users)
If you are located in the European Economic Area or United Kingdom, you additionally have the right to:
- Data portability: Receive your personal data in a structured, commonly used, machine-readable format.
- Restriction: Request that we restrict processing of your personal data in certain circumstances.
- Objection: Object to processing based on legitimate interest.
- Withdraw consent: Where processing is based on consent, withdraw that consent at any time.
- Lodge a complaint: File a complaint with your local data protection authority.
7.3 Cross-Border Data Transfers
JellyNet’s infrastructure is distributed across multiple regions. Your data may be transferred to and processed in countries outside your country of residence, including India, the United States, and other jurisdictions where our infrastructure providers operate. We ensure such transfers are subject to appropriate safeguards, including contractual protections with our service providers.
7.4 Exercising Your Rights
To exercise any of the rights described above, contact us at admin@jellynet.net. We will respond within 30 days. We may request verification of your identity before processing your request.
8. Children's Data
The Platform is not intended for individuals under 18 years of age. We do not knowingly collect personal data from minors. If we become aware that we have collected data from a minor, we will take steps to delete that data promptly. If you believe we have inadvertently collected data from a minor, please contact us at admin@jellynet.net.
9. Automated Decision-Making
The Platform uses automated systems for:
- API call routing: Calls are automatically routed to supplier keys based on pool availability, quota, and health scores. This does not involve profiling of individuals.
- Fraud detection: We may use automated rules to flag or suspend accounts exhibiting suspicious patterns. Any automated suspension is subject to human review upon request.
These automated processes do not produce legal effects or similarly significant effects on individuals.
10. Beta Disclaimer
JellyNet is currently in beta. Data collected during the beta period may be migrated, restructured, or (with reasonable notice) reset when the Platform moves to general availability. We will provide at least 14 days’ notice before any data reset that affects user balances or transaction history.
11. Grievance Officer
In accordance with India’s Digital Personal Data Protection Act, 2023, we have designated a Grievance Officer to address data-related concerns:
Grievance Officer: Mukul Israni
Email: admin@jellynet.net
Response time: Within 30 days of receiving your grievance.
If you are not satisfied with our response, you may escalate your grievance to the Data Protection Board of India (once constituted) or, for EEA/UK users, to your local data protection authority.
12. Changes to This Policy
We may update this Privacy Policy as the Platform evolves. We will update the “Last updated” date at the top of this page. For material changes, we will notify you via email or in-app notice at least 14 days before the changes take effect.
13. Contact
For privacy-related questions, data requests, or grievances:
- Email: admin@jellynet.net
- Website: https://www.jellynet.net
- X (Twitter): @jellynet_
Also see our Terms of Service and Cookie Policy.