HeyJess.art Launch Information
An open account of where the product actually stands. This is a transparency page, not a certification of any kind.
Draft policy for legal review before public launch
What is connected today
- Cloud sync for saved campaignsIn place
Saved campaigns and brand memory start in this browser. When you are signed in you can choose to save them to your account; nothing is uploaded without you asking for it, and the device copy is kept.
- Accounts and sign-inIn place
You can sign in with an email link or with Google. An email address is held for the account.
- External AI processingIn place
Your prompt, brief and any picture you bring in are sent to an external AI service to make the design you asked for. Each provider's own terms apply, and those providers must be named on this page before public launch.
- PaymentsIn place
A paid plan can be bought through an external payment processor. Card details are handled by that processor, never by us. Full billing, cancellation and refund terms are pending legal/business review.
- Analytics and trackingNot active
No analytics or advertising tracking is in use, so there is nothing to consent to for that purpose.
- Email sending from the productNot active
Apart from the sign-in link sent by the sign-in service, the product cannot send email. Requests made in the product are stored for a person to read, not emailed.
- Error monitoringNot active
Errors are written to server logs only. There is no alerting product, so problems are found by looking rather than being told.
- UploadsIn place
You can bring in reference images and brand assets. Only bring in material you have the rights to.
Product & user data
- Browser-local saved work disclosureIn place
Shown on the saved campaigns page and in the privacy notice.
- Data collection inventoryPlanned
A first list is on the privacy notice; it must be checked line by line before launch.
- Retention policy finalizationPending legal/business review
Retention periods for anything held outside the device are undecided.
- User data rights processPlanned
The request guide is published; handling is manual and the contact route is unconfirmed.
- Third-party processor inventoryPending legal/business review
Hosting, AI and payment providers must be named publicly before launch.
Legal & consumer information
- Privacy noticeIn place
Published as a draft for legal review.
- Terms of useIn place
Published as a draft for legal review.
- Acceptable use rulesIn place
Published as a draft for legal review.
- Age policyPending legal/business review
A provisional minimum age is set; the final gate differs by market.
- Copyright and trademark complaint routePlanned
The reporting page exists; the named contact is unconfirmed.
- Pricing, cancellation and refund disclosuresPending legal/business review
Required before any paid plan is offered publicly.
Security & reliability
- Secure deployment reviewPlanned
Security headers and route checks exist in the test suite; a full review is outstanding.
- Secret and API key reviewIn place
Keys are held server-side and covered by an automated check.
- Dependency reviewPlanned
Run and record before launch.
- Backup and recovery planPlanned
Work saved to an account is held on our side, but no restore has been tested, so recovery is not verified.
- Incident response contact and processPending legal/business review
No named contact or process yet.
- Storage quota and data-loss behaviour reviewPlanned
Browser storage can fill up; behaviour at the limit needs a documented result.
Accessibility & inclusion
- Keyboard and mobile testingPlanned
New trust pages were built keyboard-first; the whole product still needs a pass.
- Contrast and focus testingPlanned
Focus styles and contrast tokens are used; a measured audit is outstanding.
- Screen reader checks on the core flowsPlanned
Not yet run end to end.
- Feedback channel for accessibility barriersPlanned
Published on the accessibility page; the contact needs confirming.
AI and content integrity
- AI provider data-use disclosurePending legal/business review
External AI is in use, so the providers and their data terms must be named publicly.
- Review of output limitationsIn place
Stated in the terms and in the product's own disclosure.
- User responsibility noticesIn place
Stated in the terms and the acceptable use rules.
- Reporting and moderation processPlanned
Reporting page exists; the process behind it is not documented.
Reliability & recovery
- Backup and recovery planPlanned
Targets are written down below; no restore has been tested, so nothing is verified.
- Incident response runbookPlanned
A draft runbook exists below. It has no named owner and has never been rehearsed.
- Error monitoring and alertingNot active
Errors are written to server logs; nothing alerts anyone.
- Account-data migration readinessIn place
Saving device work to an account is opt-in, owner-scoped and keeps the device copy.
What we could restore
Being honest about this matters more than sounding safe: work you have not saved to your account cannot be recovered by us at all, and for work saved to an account we will not claim recovery until a restore has actually been tested and the result recorded.
- Held on our sideIn place
Account records, designs and version history, credits and usage records, saved photos, brand memory and campaigns you chose to save to your account, uploaded files, and privacy requests.
- Still only in your browserIn place
Saved campaigns and brand memory you have not chosen to save to your account, plus workflow preferences and the saved look. These cannot be restored by us.
- Backup frequency targetPlanned
Daily, provider-managed. Not verified by a restore test.
- Retention targetPlanned
Pending business decision.
- Encryption and accessPlanned
Traffic is encrypted in transit. Backup storage handling is the hosting provider's, and has not been independently verified here.
- Restore testing cadencePlanned
Planned / never run.
- Recovery time objectivePlanned
Pending business decision.
- Recovery point objectivePlanned
Pending business decision.
- OwnerPlanned
Pending legal/business review before launch
- Launch blockerIn place
Yes for anything saved to an account: a restore must be tested once before people are told their work is safe with us.
Accessibility reviews
Review cadence: Routine review every 12 months, plus an extra review after a major interface redesign, a major feature launch, or a report of a material accessibility problem.
- Last review: Pending legal/business review before launch
- Next planned review: Pending legal/business review before launch
- Review owner: Pending legal/business review before launch
- Outstanding access problems: Pending legal/business review before launch
- Current status: Initial accessibility review pending before launch.
No accessibility certification or standards conformance is claimed, because no independent audit has been carried out.
If something goes wrong
- 1. Confirm
Reproduce it, note the time it started and write down what is known.
- 2. Contain
Turn off the affected route or feature, rotate any key that may be exposed, and stop further writes if data may be wrong.
- 3. Assess exposure
Decide which accounts and which categories of data were affected, using database access rules and server logs.
- 4. Escalate to providers
Open a ticket with the hosting, payment or AI provider involved. Escalation channels are pending.
- 5. Preserve evidence
Keep logs and copies of affected records before repairing.
- 6. Tell people
Write to affected accounts in plain language: what happened, what it means for them, what to do. Wording is pending legal review.
Whether a regulator or individuals must be told, and by when, is pending legal review. This page does not promise a notification deadline.