Back to HeyJess.art

HeyJess.art Launch Information

An open account of where the product actually stands. This is a transparency page, not a certification of any kind.

Draft policy for legal review before public launch

What is connected today

  • Cloud sync for saved campaignsIn place

    Saved campaigns and brand memory start in this browser. When you are signed in you can choose to save them to your account; nothing is uploaded without you asking for it, and the device copy is kept.

  • Accounts and sign-inIn place

    You can sign in with an email link or with Google. An email address is held for the account.

  • External AI processingIn place

    Your prompt, brief and any picture you bring in are sent to an external AI service to make the design you asked for. Each provider's own terms apply, and those providers must be named on this page before public launch.

  • PaymentsIn place

    A paid plan can be bought through an external payment processor. Card details are handled by that processor, never by us. Full billing, cancellation and refund terms are pending legal/business review.

  • Analytics and trackingNot active

    No analytics or advertising tracking is in use, so there is nothing to consent to for that purpose.

  • Email sending from the productNot active

    Apart from the sign-in link sent by the sign-in service, the product cannot send email. Requests made in the product are stored for a person to read, not emailed.

  • Error monitoringNot active

    Errors are written to server logs only. There is no alerting product, so problems are found by looking rather than being told.

  • UploadsIn place

    You can bring in reference images and brand assets. Only bring in material you have the rights to.

Product & user data

  • Browser-local saved work disclosureIn place

    Shown on the saved campaigns page and in the privacy notice.

  • Data collection inventoryPlanned

    A first list is on the privacy notice; it must be checked line by line before launch.

  • Retention policy finalizationPending legal/business review

    Retention periods for anything held outside the device are undecided.

  • User data rights processPlanned

    The request guide is published; handling is manual and the contact route is unconfirmed.

  • Third-party processor inventoryPending legal/business review

    Hosting, AI and payment providers must be named publicly before launch.

Security & reliability

  • Secure deployment reviewPlanned

    Security headers and route checks exist in the test suite; a full review is outstanding.

  • Secret and API key reviewIn place

    Keys are held server-side and covered by an automated check.

  • Dependency reviewPlanned

    Run and record before launch.

  • Backup and recovery planPlanned

    Work saved to an account is held on our side, but no restore has been tested, so recovery is not verified.

  • Incident response contact and processPending legal/business review

    No named contact or process yet.

  • Storage quota and data-loss behaviour reviewPlanned

    Browser storage can fill up; behaviour at the limit needs a documented result.

Accessibility & inclusion

  • Keyboard and mobile testingPlanned

    New trust pages were built keyboard-first; the whole product still needs a pass.

  • Contrast and focus testingPlanned

    Focus styles and contrast tokens are used; a measured audit is outstanding.

  • Screen reader checks on the core flowsPlanned

    Not yet run end to end.

  • Feedback channel for accessibility barriersPlanned

    Published on the accessibility page; the contact needs confirming.

AI and content integrity

  • AI provider data-use disclosurePending legal/business review

    External AI is in use, so the providers and their data terms must be named publicly.

  • Review of output limitationsIn place

    Stated in the terms and in the product's own disclosure.

  • User responsibility noticesIn place

    Stated in the terms and the acceptable use rules.

  • Reporting and moderation processPlanned

    Reporting page exists; the process behind it is not documented.

Reliability & recovery

  • Backup and recovery planPlanned

    Targets are written down below; no restore has been tested, so nothing is verified.

  • Incident response runbookPlanned

    A draft runbook exists below. It has no named owner and has never been rehearsed.

  • Error monitoring and alertingNot active

    Errors are written to server logs; nothing alerts anyone.

  • Account-data migration readinessIn place

    Saving device work to an account is opt-in, owner-scoped and keeps the device copy.

What we could restore

Being honest about this matters more than sounding safe: work you have not saved to your account cannot be recovered by us at all, and for work saved to an account we will not claim recovery until a restore has actually been tested and the result recorded.

  • Held on our sideIn place

    Account records, designs and version history, credits and usage records, saved photos, brand memory and campaigns you chose to save to your account, uploaded files, and privacy requests.

  • Still only in your browserIn place

    Saved campaigns and brand memory you have not chosen to save to your account, plus workflow preferences and the saved look. These cannot be restored by us.

  • Backup frequency targetPlanned

    Daily, provider-managed. Not verified by a restore test.

  • Retention targetPlanned

    Pending business decision.

  • Encryption and accessPlanned

    Traffic is encrypted in transit. Backup storage handling is the hosting provider's, and has not been independently verified here.

  • Restore testing cadencePlanned

    Planned / never run.

  • Recovery time objectivePlanned

    Pending business decision.

  • Recovery point objectivePlanned

    Pending business decision.

  • OwnerPlanned

    Pending legal/business review before launch

  • Launch blockerIn place

    Yes for anything saved to an account: a restore must be tested once before people are told their work is safe with us.

Accessibility reviews

Review cadence: Routine review every 12 months, plus an extra review after a major interface redesign, a major feature launch, or a report of a material accessibility problem.

  • Last review: Pending legal/business review before launch
  • Next planned review: Pending legal/business review before launch
  • Review owner: Pending legal/business review before launch
  • Outstanding access problems: Pending legal/business review before launch
  • Current status: Initial accessibility review pending before launch.

No accessibility certification or standards conformance is claimed, because no independent audit has been carried out.

If something goes wrong

  • 1. Confirm

    Reproduce it, note the time it started and write down what is known.

  • 2. Contain

    Turn off the affected route or feature, rotate any key that may be exposed, and stop further writes if data may be wrong.

  • 3. Assess exposure

    Decide which accounts and which categories of data were affected, using database access rules and server logs.

  • 4. Escalate to providers

    Open a ticket with the hosting, payment or AI provider involved. Escalation channels are pending.

  • 5. Preserve evidence

    Keep logs and copies of affected records before repairing.

  • 6. Tell people

    Write to affected accounts in plain language: what happened, what it means for them, what to do. Wording is pending legal review.

Whether a regulator or individuals must be told, and by when, is pending legal review. This page does not promise a notification deadline.