Jolli Edu and Jolli Code Privacy Statement
Effective Date: October 2, 2026
Last Updated: October 2, 2026
1. About This Privacy Statement
Jolli, Inc. ("Jolli," "we," "us," or "our") is committed to protecting your privacy. This Privacy Statement describes how we collect, use, share, and protect information in connection with:
- Jolli Edu: the Jolli Edu website and web application, including institution sites at addresses such as yourschool.jolli.ai, course chat, course materials, and the Jolli sign-in service at auth.jolli.ai; and
- Jolli Code: the Jolli Code desktop application, command-line interface, and terminal interface, and the Jolli Code web application at app.jolli.ai, which connect to Jolli Edu.
Together these are the "Services." Our general Privacy Statement at https://jollidev.com/privacy covers the Jolli enterprise platform and Jolli Memory and applies when you use those products.
Jolli Edu is an education platform where instructors create and run courses and learners join and study them. Jolli Code is an AI coding agent for learning. You create your own Jolli account to use either product. Section 3 explains what joining an institution workspace or a course means for your data.
By using the Services, to the fullest extent permitted by law, you acknowledge that you have read and agreed to the terms of this Privacy Statement. We reserve the right to change our policies and practices at any time, but you can always find the latest version of this Privacy Statement on this page.
Questions or concerns? Contact us at privacy@jolli.ai.
2. Information We Collect
Personal information is any information that identifies, relates to, or can be linked to a natural person ("Personal Information"). We collect the following categories of information when you use the Services.
Information you provide
- Account Information: Your email address, your password (we store only a cryptographic hash of it), your name, and an optional profile image, provided when you create your Jolli account or sign in with Google or GitHub. You may also set a language and time zone.
- Workspace Profile: Within an institution workspace, your role (owner, administrator, member, instructor, or student) and any profile details recorded for you there, such as a job title, phone number, location, and a student or faculty ID number. These may be entered by you or by the administrator or instructor who added you.
- Conversation Content: In Jolli Code, the prompts and instructions you type, the responses the AI generates, the model's intermediate reasoning, and the context the coding agent gathers while it works, including the contents of files it reads or edits, command output, and the results of tools it runs. Jolli Code sends this content to Jolli's model gateway as part of each request to an AI model, and the gateway keeps a record of the conversation associated with your account and, where applicable, your course. The system prompt is not stored. In Jolli Edu course chat, your messages to course assistants, the assistants' responses, and any files you attach.
- Course Materials and Attachments: Files that instructors upload as course materials, and files that you attach to a chat.
- Session Titles: A short title for each conversation, generated by an AI model from your first message or built from your course code and the text you typed, and stored with the conversation record.
- Course Membership and Sharing Choices: The courses you join, including any passcode or join link you use and any request to join that is awaiting approval, and, when you share a conversation with classmates, the course members you select and the access you grant.
- Other Voluntary Information: Any other Personal Information you choose to share with us, for example through support requests or feedback.
All Personal Information you provide must be true, complete, and accurate. Please notify us of any changes.
Information others provide about you
Workspace administrators and instructors can add people to a workspace or a course by sending an invitation, by entering their details, or by uploading a list of names, email addresses, roles, and student ID numbers. If someone adds you this way, we receive that information from them and use it to create your membership and send you an invitation. The person who adds you is responsible for having the right to share your information with us.
Information collected automatically
- Request Metadata: Each request Jolli Code sends to the model gateway carries identifiers for the conversation, turn, and request; the identifiers of the course and course assistant in use; the name of the slash command that started the turn, if any; the names of any connected tool servers; the names of any tools that failed; and the Jolli Code version. For every AI request from either product, we also log your user identifier, the model used, token counts and cost, the conversation identifier, and your IP address.
- Course and Roster Data: The list of courses you belong to, the assistants and AI models each course makes available to you, and, when you open the sharing panel, the names, email addresses, and roles of the other members of that course so you can choose whom to share with.
- Sign-in and Session Data: Your IP address, browser or client type, sign-in method, and timestamps for each sign-in session, and a security audit log that records who performed account and administrative actions, from which IP address, and when.
- Visit Data: On the Jolli Edu website, a visitor identifier cookie and, when you are signed in, your user identifier are recorded each time you load the application so that we can count visits. We do not record which pages you view or the site you came from.
- Identity Provider Data: If you sign in with Google or GitHub, we receive your name, email address, and profile image from that provider, and we store the tokens the provider issues so that your sign-in keeps working. With GitHub, we read your verified email addresses so that you can choose which one to use. Please review your identity provider's privacy policy for details on how they handle your data.
- Crash Reports (Jolli Code only): The Jolli Code desktop and web applications may send an error report to Sentry, our crash-reporting provider, but only if the build you are using was compiled with crash reporting enabled and the application encounters an unexpected error. If a report is sent, it may contain the error message, a stack trace, the application version, and basic operating system or browser information. Reports are not designed to contain your prompts or code, but an error message may incidentally include a file path from your device.
- Technical and Log Data: IP addresses, user agent, timestamps, and request logs recorded by our servers for security and operational purposes. We may derive approximate location from your IP address. We do not collect precise (GPS-level) geolocation data.
- Telemetry Events: Jolli's command-line and editor tools may send anonymous usage events to our telemetry endpoint, which are scrubbed of content and identity before storage. Jolli Code and the Jolli Edu web application do not currently send telemetry events. Our Telemetry page describes this in detail.
Information stored on your device
Jolli Code keeps the following on your device, in its application data directory, and does not send it to Jolli except as described above:
- Your sign-in credentials (an access token and a refresh token, together with your user identifier, email address, and the address of the Jolli service your account uses). These are stored in Jolli Code's local application database rather than in your operating system's keychain, so you should protect access to your device account.
- Your local sessions, messages, and transcripts, including the course each session is bound to.
- A short-lived cache of your course catalogue (course codes, assistant names, and the models available to you), which is cleared when you sign out.
The Jolli Edu web application keeps your display preferences, panel layout, current workspace, and sign-in preferences in your browser's cookies and local storage.
What we do not collect. Neither product includes third-party analytics or advertising software, records keystrokes or screen contents, or collects precise location. We do not collect payment information. Our Telemetry page describes every network connection the Services make and how to control it.
3. Workspaces, Courses, Instructors, and Course Members
This section describes who can see your data when you join an institution workspace or a course.
- Institution workspaces. When you sign up, you either create a new workspace, becoming its owner, or join an existing one through an invitation, a join link, a course passcode, or a request to join. The owners and administrators of a workspace can see its people directory, including your name, email address, role, and workspace profile details; can manage your membership and role; can set workspace policies; and can remove you. They cannot read your conversations.
- Instructors and course staff. The instructors and staff of a course can see who is enrolled. They cannot read your Jolli Code conversations or your course chat unless you share them. Instructors and workspace administrators can see aggregate activity statistics for their courses, such as counts of sessions by day, hour, and weekday and which tools, assistants, models, and materials were used, without a breakdown by person.
- Course members you choose. You may share a conversation with named members of your course or with everyone in the course. The people you share with can view that conversation. You can revoke a share at any time from the sharing panel, and a share with a person ends when that person leaves the course. Sharing is limited to members of the same course, conversations that are not part of a course cannot be shared, and the Services do not publish conversations to public links.
- Shared answers in course chat. In course chat on the Jolli Edu website, when you ask a question that other members of your course are likely to ask too, the assistant's answer may be stored for about seven days and shown to classmates who ask the same thing. Questions that appear to be personal are excluded. This does not apply to Jolli Code conversations.
- Schools and organizations. Workspaces are often created by instructors or staff acting for a school, university, or other organization. Jolli provides the Services to you directly, and you do not need a school or organization to create your account. If your school uses Jolli Edu, its own policies may also apply to your coursework, and we will work with schools that need a data agreement covering their students. Ask your instructor or school about their policies.
4. How We Use Your Information
We process your information to:
- Provide and operate the Services, including routing your requests to AI models and returning their responses.
- Create and authenticate your account through Jolli's sign-in service or a third-party identity provider you choose.
- Keep a record of your conversations so they can be displayed to you and shared with the course members you choose.
- Answer questions in course chat using the course's materials and, where a course enables it, web search.
- Generate session titles using AI models.
- Attribute usage to courses and produce aggregate usage statistics for instructors and workspace administrators.
- Send transactional and service-related communications, such as email verification, password resets, invitations, join requests, and notifications about your courses.
- Detect and prevent abuse, security threats, or violations of this Privacy Statement or our Terms of Service, including by applying rate limits and sign-in protections.
- Diagnose and fix crashes, errors, and problems with AI requests.
- Generate anonymized, aggregated analytics about Services usage.
- Respond to support requests or inquiries.
- Comply with applicable legal obligations.
Note: We do not use (or allow use of) your Personal Information, prompts, code, or conversations to train third-party foundational AI models. We do not sell your Personal Information, and we do not use it for targeted advertising.
5. Third-Party AI Services and Sub-Processors
Every AI request from Jolli Code and from course chat travels through Jolli's model gateway. The gateway forwards your Conversation Content to the AI model provider configured for your workspace, course, and chosen model. The providers we support are currently Anthropic, OpenAI, Google, and DeepSeek, and a workspace administrator may also configure another provider that is compatible with the OpenAI API. Requests go directly to the provider's own service. These providers process your content under their own security and data handling controls. In our production environment we configure providers that commit not to use customer data for general model training. Jolli Code does not allow Conversation Content to be sent directly to a model provider with a personal API key; all requests go through the gateway.
Course assistants may use a web search service, Tavily, to answer questions. When they do, the search query derived from your question is sent to Tavily, but your identity is not.
Several components of the Services run inside our own cloud environment rather than at a third party, including retrieval over course materials, optional masking of personal data in AI requests, and tracing of AI requests for troubleshooting.
Jolli also uses third-party service providers who provide sub-processing services for the Services, currently including Amazon Web Services (cloud infrastructure, database, and file storage), SendGrid (email delivery), Cloudflare (the Turnstile verification on our sign-up page, which receives your IP address and browser information), and Sentry (crash reports from the Jolli Code desktop and web applications).
Jolli Code also contacts the following services in order to operate. They receive your IP address and standard request information, but no account information and no Conversation Content: GitHub (to check for and download Jolli Code releases and desktop updates), the npm registry (to install plugins you add), and models.opencode.ai (to download a catalogue of AI model capabilities). The Jolli Edu web application loads a code-editing component from cdn.jsdelivr.net when you open a feature that needs it; that host sees your IP address and nothing else.
For a current list of our third-party service providers and sub-processors that handle your Personal Information for us, contact us at support@jolli.ai.
6. Cookies and Browser Storage
The Jolli Edu website and the Jolli sign-in service set only first-party cookies, used to keep you signed in and to remember your preferences:
| Cookie | Purpose | Lifetime |
|---|---|---|
JSID.session_token, JSID.session_data, authToken, gateway_auth | Keep you signed in and authenticate your requests | Your sign-in session |
remember_me_token | Keep you signed in across browser restarts when you choose "remember me" | Until you sign out or it expires |
visitorId | Count visits (see Visit Data above) | 1 year |
jolli_signup_intent | Remember where you started sign-up while you complete it | 5 minutes |
jolli_theme, jolli_rememberMe_pref, email_selection | Your display and sign-in preferences | Up to 10 years |
The sign-up page loads Cloudflare's Turnstile script to verify that you are not a bot. We do not use third-party analytics cookies, advertising cookies, web beacons, or tracking pixels. The Jolli Code desktop application, command-line interface, and terminal interface do not use cookies. You can configure your browser to refuse or remove cookies, though doing so may prevent you from signing in.
7. Data Retention
We retain personal data only as long as necessary for the purposes outlined in this Privacy Statement, or as required by law. When data is no longer needed, we will delete or anonymize it. If deletion is not immediately possible (for example, data stored in backup archives), we will securely isolate it until deletion is feasible.
| Data | Retained |
|---|---|
| Account, profile, and workspace memberships | For as long as your account remains active |
| Conversations, session titles, sharing grants, and chat attachments | Until you delete them or your account is deleted |
| Course materials | Until the instructor removes them or the course is deleted |
| AI request usage logs (model, tokens, cost, IP address) | 90 days |
| Diagnostic traces of AI requests | 90 days in active systems, then moved to an archive |
| Security audit log | 365 days |
| Server logs | 1 month |
| Cached course-chat answers | About 7 days |
| Telemetry events from Jolli's command-line and editor tools | 3 years |
| Crash reports (Jolli Code) | A limited period set by our crash-reporting provider |
| Backup archives | Up to 90 days after deletion from active systems |
| Data on your device | Until you remove it |
Data Storage Location: Data is stored and processed in the United States, in Amazon Web Services' Oregon region. Sub-processors may process data in their own infrastructure.
8. Data Security
We implement reasonable technical and organizational measures to protect your personal information, including:
- Encrypted connections (HTTPS, TLS 1.2 or later) for all traffic between your browser or Jolli Code and Jolli.
- Encryption at rest for our databases and file storage.
- Passwords stored only as Argon2id hashes, password reset tokens and API keys stored as hashes, and sensitive fields such as audit-log details and provider credentials encrypted with AES-256-GCM.
- Each institution workspace's data kept in its own database schema, isolated from other workspaces.
- Role-based access controls (RBAC) and an audit log of account and administrative actions.
- Sign-in protections, including rate limits, lockout after repeated failed attempts, and bot verification on sign-up.
- Jolli Code sends your sign-in token only to Jolli-operated hosts over HTTPS and refuses to send it anywhere else. Sign-in uses a short-lived local callback server bound to a random port on your device; the one-time sign-in code is exchanged for tokens once, and the server then closes.
- Cloud-native security infrastructure, with secrets held in a managed secrets store.
- Multi-factor authentication (MFA) required for all internal employee access to production systems.
Important: No electronic transmission over the internet or information storage technology can be guaranteed to be 100% secure. While we do our best to protect your data, transmission to and from the Services is at your own risk.
9. Data Sharing
We do not sell your personal data. We may share data with:
- Workspace owners and administrators, instructors and course staff, and the course members you choose, as described in Section 3.
- Service Providers: Authorized third-party providers operating on our behalf under data processing agreements, including the AI model providers and sub-processors described in Section 5.
- Third-Party Tools You Connect: Jolli Edu lets you authorize third-party AI tools and agents to access your workspace data through our connector. Any data such a tool receives is governed by its own privacy policy. You control these authorizations.
- Our Personnel: Jolli staff may access data as needed to operate, secure, and support the Services, including reviewing records of AI requests to diagnose problems. Such access is role-restricted and logged.
- Legal Disclosures: We may disclose Personal Information if we have a good faith belief that disclosure is helpful or reasonably necessary to: (a) comply with any applicable law, regulation, legal process, or governmental request; (b) enforce our policies, including investigations of potential violations; (c) investigate, detect, prevent, or take action regarding illegal activities, suspected fraud, or security issues; (d) establish or exercise our rights to defend against legal claims; or (e) prevent harm to the rights, property, or safety of us, our Services, you, or any third party.
- Disputes: In the event of any dispute involving you, we may share Personal Information with our legal counsel, professional advisors, service providers, and relevant courts or tribunals as needed to resolve the dispute, defend against claims, or enforce our rights.
- External Links: The Services may contain links to other websites or services. We are not responsible for the privacy practices of those third-party sites. We encourage you to review the privacy policy of every website or service you visit. This Privacy Statement applies only to Jolli's Services.
- Business Transfers: In connection with a merger, acquisition, financing, or sale of company assets, your data may be transferred as part of that transaction.
10. Minors
The Services are intended for users who are 17 years of age or older. You must be at least 17 to create an account, and we do not knowingly collect Personal Information from anyone under 17. If you are under 18, your parent or guardian should review this Privacy Statement and our Terms of Service with you. We do not sell the Personal Information of users under 18, use it for targeted advertising, or use it to profile them. If you believe we have inadvertently collected data from a child under 17, please contact us at privacy@jolli.ai and we will promptly delete it.
11. Do-Not-Track Signals
Some browsers allow you to send Do-Not-Track ("DNT") signals. Because no uniform standard for DNT has been finalized, we do not currently respond to DNT signals. If an industry standard is adopted in the future, we will update this Privacy Statement accordingly.
12. Your Privacy Rights
Depending on your location, you may have the right to:
- Know what personal data we collect and how it is used.
- Access the personal data we hold about you.
- Correct inaccurate or outdated information.
- Delete your personal data (subject to certain legal exceptions).
- Restrict or object to processing in certain circumstances.
- Data portability: receive a copy of your data in a structured format.
- Withdraw consent at any time, without affecting the lawfulness of prior processing.
- Opt out of profiling or marketing communications via the unsubscribe link in any email we send.
To exercise any of the above rights, contact us at support@jolli.ai.
13. Account Termination & Deletion
You can delete any of your conversations from the Jolli Edu web application at any time. Deleting a conversation permanently removes it, its messages, and its tool records from our active systems.
To request deletion of your account and associated data, contact support@jolli.ai. We will deactivate and delete your information from active systems within 30 days, though we may retain certain data in backup archives or as required by law for fraud prevention, legal compliance, or security purposes. A workspace administrator can also remove you from their workspace, which ends your membership and your access to its courses.
To remove Jolli Code data from your device, sign out of Jolli Code and then delete its application data directory. The locations for each operating system are listed on our Telemetry page.
14. Early Access Notice
Jolli Edu and Jolli Code are early access products. Features and data practices may evolve as the products develop. We will notify users of any material changes to this Privacy Statement.
15. Updates to This Privacy Statement
We may update this Privacy Statement from time to time. The "Last Updated" date at the top will reflect the most recent revision. We will provide notice of material changes either by posting prominently within the Services or by direct notification. Any changes to this Privacy Statement will be effective immediately upon posting and/or notification and shall apply to all information we maintain, use, and disclose. Continued use of the Services after such notice constitutes acceptance of the updated Privacy Statement. For material changes that significantly alter our data collection, use, or sharing practices, we will seek your affirmative re-consent where required by applicable law.
This revision introduces a separate Privacy Statement for Jolli Edu and Jolli Code, describing the data the Jolli Edu web application and the Jolli Code applications process, the role of workspaces, courses, instructors, and course members, and the minimum age of 17.
16. Unsolicited Feedback
This Privacy Statement does not apply to any unsolicited feedback you provide to us through the Services or through any other means, including ideas for new products or modifications to existing products, and other unsolicited submissions (collectively, "Feedback"). All Feedback shall be deemed non-confidential, and we shall be free to reproduce, use, disclose, and distribute such Feedback to others without limitation or attribution.
17. Anonymous Information
We may use information that cannot be connected to any particular person, or that has been de-identified or aggregated such that it can no longer be used to identify any individual, even if it was originally linked to Personal Information. We may use such aggregated information internally for a variety of purposes, including improving our Services, and may share it with third parties or publish it, without restriction.
18. Contact
Jolli, Inc.
- Privacy inquiries: privacy@jolli.ai
- Data subject requests and privacy rights inquiries: support@jolli.ai
We will acknowledge receipt of privacy requests and respond within 30 days, or as otherwise consistent with applicable legal requirements. Identity verification will be performed before fulfilling data access or deletion requests.