Jelby Mascot - Blue Raspberry
JelbyAutonomous Coding Agent

Privacy Policy

Last updated: September 9, 2026

Jelby is published by Wilburn Pacific Company. This policy covers two separate things: the Jelby app that runs on your computer, and this website (jelby.ai). They handle data differently, so we describe each on its own below.

One distinction runs through everything, and it is worth stating plainly. We do not receive your code. Jelby works on your repositories on your own machine. Your code, prompts, transcripts, and Jelby's memory of your work are never sent to us, and nothing on this page qualifies that. When the app talks to an AI model you configured, that traffic goes from your machine to that model provider — not through us.

The Jelby app

Jelby is local-first. It watches your repositories, reproduces failures, drafts fixes, and opens pull requests, all from your own computer. The following are properties of the software itself, verified in how it is built:

  • Local-first. The background service listens only on 127.0.0.1 (loopback) behind an access token. It is not reachable from the web.
  • Encrypted at rest.Your work history — patches, plans, transcripts, memory — lives in encrypted local databases. The keys are held in your operating system's keychain, never on disk.
  • Credentials stay in the OS keychain.Sign-in tokens, API keys you provide, and the dashboard's own token live only in the OS keychain (Windows Credential Manager, macOS Keychain), never in plaintext files.
  • Nothing acts without you. Actions that send, write, spend, or change things pause for your explicit approval, and the app keeps a local audit log of what it did — for you, on your machine.
  • No product telemetry. No analytics, no tracking, no usage pings.

What leaves your machine, and where it goes

The app connects out only for the following, all of which you configure and control:

  • The AI model providers you choose. This is the most important line on this page. When Jelby asks a model to plan, write, or review code, the relevant code and context are sent to the provider you configured — for example Anthropic, OpenAI or GitHub Copilot, or Google — under your account and their privacy terms. If you run a local model (for example via Ollama), that work stays on your machine entirely, and Jelby is fully functional that way. We are not in this path: your code and prompts do not pass through our servers.
  • Your code host. Jelby talks to GitHub (or the host you connect) to read repositories and open pull requests, using credentials scoped to the repositories you chose.
  • Sign-in and licensing. Jelby requires a Jelby account, and the app exchanges sign-in and license records with jelby.ai. When you connect GitHub through your account, our connection service issues short-lived access tokens to your machine. It is authentication only: it mints tokens; your code and your work never pass through it.
  • Downloads you trigger, such as fetching a local model or an update you asked for.

This website

This website is a normal website, separate from the local-first app. It is where you read about Jelby, download it, and manage your account. It uses the following:

  • First-party analytics. We use Microsoft Application Insights to understand how the site performs and is used, as aggregate operational data.
  • Consent-gated analytics cookies. Google analytics tags load only if you accept them in the consent banner; until then, ad and analytics cookie storage is denied by default. Declining does not change what the site can do for you.
  • Accounts. Using Jelby requires a Jelby account. Our authentication provider, Clerk, processes your email address and sign-in details on our behalf so we can sign you in, and your account holds your plan and your GitHub connection.
  • Payments. When paid plans are offered, payments are processed by Stripe. We do not see or store your full card details.
  • Ordinary server records, including IP addresses and request times, which any service on the internet receives. We use them to run and protect the service.

What we do not do

  • We do not sell your personal information.
  • The Jelby app does not phone home about your code or your work. There is no product telemetry.
  • We do not use your code or your work to train anything. It does not reach us, which is the point of the design. (What a model provider does with traffic you send them is governed by their terms and your settings with them — choose providers, or local models, accordingly.)
  • We do not track you across other websites.

Your choices

Jelby requires an account to sign in, but what your account can see never includes your work: run Jelby with only local models and your code, prompts, and memory never leave your machine at all. You can ask us to delete your account. You can decline analytics cookies in the banner and the site works identically.

Changes

If this policy changes, we will post the updated version here and revise the date above.

Contact

Questions about privacy? Reach us at our contact page, or see the license agreement for the software terms.