Skip to content

Privacy Policy

Last updated: 1 September 2026

Who we are

jhint is made by JSoft, a software studio. The legal entity behind it is Ara Israelyan IE, an individual entrepreneur registered in Armenia. In data-protection terms, that entity is the controller of the limited personal data described below.

  • Controller: Ara Israelyan IE, individual entrepreneur (Armenia)
  • State registration: no. 286.1597722, registered 22 July 2026, Register of Legal Entities, Ministry of Justice of the Republic of Armenia
  • Tax identification number (TIN): 20349229
  • Address: Vahram Papazyan St. 27, Yerevan 0012, Armenia
  • Contact for privacy matters: support@jhint.ai

Write to support@jhint.ai about anything in this policy — including requests about your data.

The short version

  • Your audio never leaves your computer. Speech is recognised on-device.
  • The default model runs on your computer too. The app carries its own inference engine; the model weights are downloaded once from Hugging Face and then used locally. Choosing an external provider instead is a deliberate act, and the app tells you what will leave before the first send.
  • The transcript is not stored by default. It lives in the session and goes away with it. If you switch saving on, conversations are kept on your computer, encrypted — they still never reach us.
  • There is no telemetry. No usage events, no crash pings, no analytics inside the app.
  • There are no accounts. The product is unlocked with a licence key, not a login.
  • We never see your card. Payment data belongs to Paddle, our merchant of record.
  • We keep the email address your licence is registered to. It sits in our database next to your Paddle identifiers, so the app can show you which address your key belongs to — no other personal detail is added.

What stays on your computer

jhint captures system audio, recognises speech locally and shows the text in an overlay. None of that is uploaded — not to us, not to anyone else.

On macOS, capturing system audio is covered by the Screen Recording permission, which you grant yourself in System Settings; recognition runs with WhisperKit on the Apple Neural Engine.

On Windows, jhint captures system output audio using Windows loopback audio capture. Windows does not show a separate permission prompt for this type of capture. While listening is active, jhint can receive any audio your computer is playing, not only audio from the call or meeting you intended to transcribe. Audio is processed locally as described below and is discarded after recognition.

  • Audio is held in memory only until it has been recognised, then discarded. It is never written to disk.
  • The transcript stays in the current session unless you deliberately turn on saving — see Saved conversations below for what is kept then, and how.
  • Screenshots are only taken when you ask for one, and you see a preview before anything is sent to an external model. A screenshot travels inside the request itself and is never written to disk.
  • Provider API keys and jhint’s local encryption key are stored in protected credential storage provided by your operating system — Apple Keychain on macOS and Windows Credential Manager on Windows — rather than in jhint configuration files.
  • Your licence token is stored in the same protected operating-system credential storage. Since it carries the email address your licence is registered to (see below), that address lives there too, on your computer.
  • Diagnostic logs record events, never the content of a conversation.
  • The built-in model runs as a separate process on your computer that listens only on a loopback address, with a fresh key generated at each start. Questions you send it, and its answers, do not go through the network.

Settings include Delete All Local Data, which removes sessions, temporary files, logs and stored credentials from your machine.

Saved conversations

Storing a conversation is off until you turn it on — the switch is Settings → Privacy & data → Store transcript. While it is off, or while Keep data for is set to Do not keep, nothing about a conversation is written to disk at all: not the text, not even a record that the conversation happened.

When you do turn it on, each conversation is saved as one file on your computer and contains:

  • the recognised speech from the conversation — which includes what other people said;
  • the questions you asked and the answers the model gave;
  • the date, how long it ran, how many questions there were, and which provider and model answered.

How it is protected. Saved conversations are encrypted with AES-GCM using a 256-bit key stored in protected credential storage provided by your operating system. The key remains on your computer. A file copied to another machine cannot be read at all. Encryption is there because the app’s folder is not otherwise protected from other programs running under your own account.

On macOS specifically, the keychain releases the key after the first unlock following a restart, so a saved conversation cannot be read on a Mac that has not been unlocked. That property belongs to the Keychain and is not claimed for Windows Credential Manager.

How long it is kept. You choose under Keep data for: one day, seven days (the default), or no limit. Conversations past their time are deleted when the app starts and when a conversation ends. You can also open the History tab to read a conversation, export it to Markdown, or delete it — and Delete All Local Data removes everything at once.

What this means for the other people in the conversation. A saved conversation holds their words, and they have not agreed to that. Deciding to keep it is your decision, not ours: we cannot see these files, cannot reach them and hold no copy. Where you are, keeping a record of what someone said may require telling them or asking their permission — see Recording other people in the Terms of Use and the Acceptable Use Policy.

What leaves your computer, and when

The app makes only the outbound requests described below. Most of them depend on a choice of yours — a provider you picked, a model you asked to download, an update you accepted. When a later version adds a new kind of request, it is described here before that version ships.

Licence checks

To confirm your subscription, jhint sends your licence key, a random installation identifier, a device check value, the version of the app and the platform it runs on — one word, either macos or windows — to our licence service on Cloudflare.

The device check value is created on your computer by applying a one-way keyed cryptographic function to a device or operating-system installation identifier together with your licence key. On macOS, the source identifier is provided for the Mac; on Windows, it is the MachineGuid created by Windows for that installation. The source identifier itself is never sent to us. Because your licence key is used in deriving the value, the same computer produces different device check values under different licence keys. We use the value only to recognise a computer already activated under the same licence and to enforce the device limit of your plan.

It also lets us avoid treating a reinstall on the same computer as a new device.

The version of the app tells the service which build is asking, so that a plan whose rules a build does not yet know is not issued to it. The platform is that single word and nothing else — not your operating system version, not your hardware. We record it against the activation to see how many installations come from each platform; it is stored in the activation record and deleted with it. No conversation content is included in licence checks.

Recovering a lost key

If you use Lost your key? in Settings → License, the app sends the email address you paid with to our licence service. We ask Paddle whether that address belongs to a customer and, if so, email your key or keys to it through Resend. That lookup doesn’t change what’s on file for your licence — the stored address comes from your purchase, not from this form.

The model that answers

Nothing is sent to a model until you press Answer. By default jhint answers with the built-in model running on your own computer: the app ships with the inference engine inside it and talks to it over a loopback address on your machine, so that request never reaches the network. If you choose an external provider, the request goes directly from your computer to that provider, under your own account and API key — it does not pass through us, and we never see it. What that provider does with the request is governed by their terms, which the app shows you before the first external send.

By default only the current question is included. Recent conversation context and your profile are two separate switches, each off until you turn it on, each set per session.

Downloading the speech-recognition model

The first time you use a speech-recognition model, the app downloads it from Hugging Face. That request contains no personal data beyond what any file download involves.

Downloading the built-in language model

The engine that runs the built-in model is part of the app, but the model weights are not: they are several gigabytes and you choose which one you want. When you do, the app downloads the file from Hugging Face, from a fixed repository revision, and checks it against a checksum held in the app before using it. Like any file download, the request carries nothing about you beyond your IP address. Next to the downloaded files the app writes the model’s licence and a note saying which repository and revision it came from.

The list of built-in models

To know which models it can offer — their sizes, memory requirements and licences — the app fetches a small list from updates.jhint.ai. It is a plain file download: nothing about you, your licence or your conversations is part of the request.

Searching the web, if you turn it on

The built-in model can be allowed to look something up. This is off until you turn it on, and turning it on asks you to accept a separate notice explaining what follows.

When it is on and the model decides it needs a fact:

  • the app opens a search page from your computer, over your own internet connection and from your own IP address. The request does not pass through us, and we never see it;
  • the query is written by the model out of what it was given, which can include what other people said in your conversation. The app shows you every query it makes, so you can see what left;
  • the app then reads what the search returned. It can open only pages that appeared in that search, only over https, and only where the site’s own machine-readable rules allow it. If a site refuses, or its rules cannot be read, the page is not opened;
  • what it reads is treated as untrusted text. Instructions inside a page cannot change what the model is allowed to do, and cannot send it anywhere else;
  • no logins and no cookies from your browsers are used, and nothing is done to work around a block or a CAPTCHA. Cookies the search engine sets do not survive the session.

The search engine is a third party and sees what any visitor’s browser would show it: your query, your IP address and the ordinary details of a web request. What it does with that is governed by its own privacy policy, not ours.

We do not keep your queries. They are not sent to us, not logged by us, and not stored anywhere outside your computer.

Checking for a new version

Once a day the app asks updates.jhint.ai whether a newer version exists, and downloads it from there if you accept the update. You can also ask at any moment from the menu bar — Check for Updates…. The request carries nothing about you or your use of the app: the version you are running and your IP address, as any download does.

Refreshing what models can do

To know which models accept images and how much text they take, the app keeps a small reference table from models.dev and refreshes it in the background. It is a plain file download: nothing about you, your licence or your conversations is part of the request.

What we store about a licence

Our licence service runs on Cloudflare Workers and uses Cloudflare D1. Cloudflare may process service data internationally subject to the safeguards described in its Data Processing Addendum. The database holds identifiers and subscription status — nothing about you as a person, and nothing about your conversations.

What we holdWhy
Licence keyTo unlock the product
Installation identifierTo honour the device limit your plan carries and issue access tokens
Device check valueTo recognise a computer already activated under the same licence, enforce the device limit of the plan, and avoid treating a reinstall on the same computer as a new device
Paddle customer and subscription identifiersTo match a payment to a licence
Subscription status, period end, scheduled changesTo decide whether the licence is active and to tell you when the trial ends
Identifiers of processed payment eventsSo a repeated delivery is not applied twice
A flag that the key was emailedSo you receive that email once, not monthly
The email address your licence is registered toSo the app can show you which address your key belongs to, on the Settings → License tab
Where the licence came from, and — for licences that run for a fixed term — its start and end datesSo we know whether the licence is still active, and can tell you when it ends
For a campaign purchase: the Paddle transaction, which reward you bought, its status, and the version of the campaign offer you bought underTo issue your licence, to add time if you buy a second reward, and to keep a record of the terms that applied to your purchase

Not stored: your name, postal address, card details, audio, transcripts, prompts, model answers, or anything about how you use the app.

We store the email address your licence was bought under. It’s saved next to your Paddle identifiers when your licence key is emailed after purchase, so the Settings → License tab can show it to you and so later renewals don’t need to ask Paddle again. Resending a lost key, or the pricing page checking whether your trial is still available, uses the address you type in at that moment only — it goes to Paddle and, for key emails, to Resend, and doesn’t change what’s on file. It’s never written to our logs.

If you bought a campaign reward, nothing extra is collected: the purchase reaches us as a Paddle webhook, and the address it carries is the same one Paddle already holds for you. The campaign page itself asks you for nothing beyond the checkout, and we are not connected to any outside crowdfunding platform. The address is held on the same terms as any other: not in our logs, not shared beyond the providers named here, and deleted on request.

Payments

Purchases are handled by Paddle.com Market Ltd, which acts as merchant of record. Legally, Paddle is the seller: it takes the payment, charges the tax, issues the invoice, and is the controller of the payment data you enter — card details and billing address. We do not receive them, and we cannot see them; your email address is the one exception, handled as described above.

From Paddle we receive only identifiers and status: that a subscription exists, what it costs, whether it is active, when the period ends. Paddle’s own privacy policy is at paddle.com/legal/privacy.

Paddle also sends you its own emails — the payment receipt and subscription notices. Those are required of it as merchant of record and are sent under its policies, not ours.

Email

We send you your licence key by email, right after purchase. The key is generated by us and never given to Paddle, so it cannot appear in their receipt — which is exactly why this email exists. To send it, our service asks Paddle for your address and passes it to Resend, our delivery provider — and saves it next to your Paddle identifiers, so the Settings → License tab can show you which address your key belongs to.

If you use Lost your key? in Settings → License, we send it again the same way, using the address you type into that form. That request doesn’t change what’s stored — the address on file still comes from your purchase, not from a recovery request. Resend keeps its own delivery log under its policy; our own record of either email is limited to the fact that it was sent, plus the address stored as above.

Mail you send to support@jhint.ai is forwarded to our inbox by Cloudflare Email Routing. We keep support correspondence for as long as reasonably necessary to handle the request, maintain appropriate records of the support provided, resolve disputes, and meet legal obligations. We periodically delete correspondence that is no longer needed.

Enterprise inquiries

If you contact us about jhint Enterprise, we collect the information you provide through the Enterprise inquiry form, such as your email address, organization, estimated number of seats, and the contents of your message. We use this information to respond to your inquiry, understand your organization’s requirements, and communicate with you about a potential business relationship. Depending on the circumstances, we process this information as necessary to take steps at your request before entering into a contract or on the basis of our legitimate interests in responding to business inquiries and developing customer relationships.

We normally retain Enterprise inquiry information for up to 24 months after our last substantive communication with you, unless the information becomes part of an ongoing contractual or business relationship or a longer retention period is required by applicable law. You may request deletion of your inquiry information, subject to any legal obligation or other lawful basis requiring us to retain it.

This website

The site is static, hosted on Cloudflare Pages, which keeps technical request logs for security and operations.

Fonts are served from this site itself, not from a font CDN, so loading a page does not tell a third party that you visited us.

Paddle’s script is loaded on the pricing and checkout pages only. It works out which country you are in from your IP address so prices are shown in the right currency, and it may set cookies during checkout. That processing is Paddle’s.

We count page views with Cloudflare Web Analytics: no cookies, no fingerprinting, no tracking across other sites, and nothing that identifies you. It tells us how many people opened a page and which site sent them — page counts, not profiles. There is no analytics of any kind inside the app itself.

Your rights

If you are in the EEA or the UK, the GDPR gives you the right to access your data, correct it, have it deleted, restrict or object to its processing, and receive a copy of it. You can also complain to your national supervisory authority.

Because we have no accounts, the way to identify yourself to us is your licence key — quote it when you write to support@jhint.ai. Bear in mind what we actually hold: for anything about your payments, your name or your invoices, Paddle is the controller and the request has to go to them.

The legal basis depends on what the processing is for:

  • Performance of our contract with you, and steps at your request before a contract — issuing your licence key, checking that it is valid, honouring the device limit your plan carries — including recognising a computer already activated under your licence, so that reinstalling jhint does not use up a second device slot — and sending you the key by email; and responding to an Enterprise inquiry you send us. None of it can be done without a key, an installation identifier, a device check value and the version of the app that is asking.
  • Our legitimate interests — responding to business inquiries and developing customer relationships, and keeping the licence service safe and working: limiting how fast new installations can be added to one key, rate-limiting the routes that accept an email address, and operational logs that record events without conversation content. The interest is preventing abuse of a product sold per person; we keep the data needed for it to a minimum. The platform recorded with an activation rests on the same ground: we run the product on two platforms and need to know how the installations divide between them, which one word answers without telling us anything about you or your computer.

The companies behind the service, and what they are to us. Paddle is not our processor: as merchant of record it is the seller, and it decides for itself how payment, tax, fraud checks and invoicing are handled — an independent controller for those purposes. We are the controller of the Paddle identifiers, the email address and the licence data we receive and use for licensing and support. Cloudflare processes licence and customer data on our instructions as our processor, and acts independently for the limited account, service and security data covered by its own terms. Resend processes the address and content of the key email as our processor, and is a controller for its own account and usage data as described in its DPA. All three operate internationally, so this limited data may be processed outside your country under the safeguards those providers publish.

How long we keep things

  • Licence records — while the subscription exists and for up to 24 months after it ends, so that a returning customer keeps the same key.
  • Installation records — a device slot is freed automatically after 30 days without contact; the record itself is kept up to 90 days to limit how fast new installations can be added to one key. The device check value and the platform are stored as part of that activation record and are deleted when the record is deleted; they have no separate retention period, and we keep no other list of devices.
  • Your email address — no automatic expiry: we don’t run a process that clears it after a fixed period. Write to support@jhint.ai and we’ll remove it from your customer record by hand. While your licence stays active, note that the next time the app needs it we may fetch it from Paddle again — Paddle keeps it regardless, as merchant of record.
  • Waitlist addresses — until early access opens and the announcement is sent, or until you ask us to delete yours.
  • Enterprise inquiries — up to 24 months, as described above. Deletion runs automatically on a daily schedule, not by hand.
  • Support correspondence — as long as reasonably necessary, as described above. We review it at least once a year and delete what is no longer needed; our working target is 24 months after a request is closed, subject to any legal, tax or security hold.
  • Cloudflare logs — under Cloudflare’s retention periods.
  • Saved conversations on your computer — for the period you chose under Keep data for: one day, seven days, or until you delete them. This happens on your machine; we hold no copy and cannot reach it.
  • Anything else on your computer — until you delete it. We cannot reach it.

Changes

If this policy changes in a way that affects what we collect or why, we will update the date at the top and, where the change is significant, say so on the site. You must be at least 18 years old to purchase or use jhint.

Questions about this document? Write to support@jhint.ai .