Privacy policy
Last updated 6 October 2026
Jigsaw is run by Jigsaw ("we"). Jigsaw hosts small apps and lets their owners share them by email. This policy explains what we collect, why, and what you can do about it.
What we collect
| What | Why |
|---|---|
| Your email address and a sign-in identifier | To sign you in and to decide which apps you can open. |
| Apps you publish: their files, name and version | To host and serve them. |
| The email addresses and roles of people you share an app with | To let those people in, with the role you chose. |
| Records an app stores through Jigsaw's data API, and who added each one | To give the app a place to keep its data. |
| Keys you paste for an app | To hand them to that app's server, or to add them to outside calls the app's page asks Jigsaw to make. Keys are stored encrypted and Jigsaw never shows them again. People you share an app with can make calls that use its key, so only paste keys you are willing to let them use. |
| Publish tokens (stored only as a one-way hash) and when each was last used | To let your agent publish for you. |
| The teams you belong to and your role in them | To decide which team apps you can manage. Other members of a team can see your email address. |
| Rules a team's admins set: the email domains its people must have, guidance for agents, and keys for the team's apps | To let a team run its apps its own way. The guidance is given to the agents of the team's members. Team keys are stored encrypted, like an app's own keys. |
| Feedback you send us, with your email address if you gave one | To improve Jigsaw and to reply to you. |
| The folders you make and which apps you put in them | To show your apps the way you arranged them. Only you see your folders. |
| A daily count of outside calls each app makes through Jigsaw | To enforce the limit an app's owner sets. |
| Reports you send about an app, with your email if you were signed in | To review apps that may break our rules. |
| A record of how you use Jigsaw: the days you were signed in, which apps you opened and on which days, and when you published or shared an app | To understand how Jigsaw is used and to improve it. We see it. If an app belongs to a team, that team's admins can also see who published, opened and shared it. |
| Technical logs: address requested, time, IP address, errors | To keep the service running and to investigate abuse. |
We do not sell personal information. We do not use advertising trackers or outside analytics services, and there are no advertising cookies.
Cookies
Jigsaw uses only the cookies it needs to work: one that keeps you signed in to Jigsaw, one per app that keeps you signed in to that app for up to 24 hours, and short-lived cookies that protect the sign-in step. Because these are strictly necessary, there is no cookie banner.
What an app and its owner can see
Apps on Jigsaw are built and published by their owners, not by us, and we do not review them. When you open an app, Jigsaw tells that app your email address and your role. An app's owner can see the email addresses of the people they shared it with. The app, and so the other people using it, can see the email address of whoever added each record.
An app with its own server can keep its own data, which is outside Jigsaw's control. Only open apps from people you trust, and ask the app's owner how they use your information.
If you choose to list an app for your team, people signed in with an address at your email domain can see the app's name and your email address as its owner. They cannot open the app unless you share it with them. Nothing is listed unless you choose it.
Who helps us run Jigsaw
We use a small number of service providers who process information on our behalf:
- WorkOS handles sign-in: it checks the code or password you enter and, if you set a password, stores it in protected form. We never see your password. If you sign in with Google, GitHub or Apple, that company confirms who you are and passes on your email address and, where you have given one, your name. We never see your password with them. If your team uses company sign-in, WorkOS passes you to your company's own sign-in system, which confirms who you are.
- Resend delivers the emails Jigsaw sends: sign-in codes, password resets and invitations. It handles the address each email goes to and what the email says.
- Stripe takes payment if you buy a plan. Your card details go to Stripe; we never see or store them. We keep which plan you are on and your Stripe customer reference.
- Fly.io runs Jigsaw's servers and the servers of apps that have their own, in London, United Kingdom.
- Supabase hosts the database, in London, United Kingdom.
When an app's page asks Jigsaw to call an outside service using a key its owner pasted, the request goes to that service.
How long we keep it
We keep your information for as long as your account exists. When you delete an app, its files, records and keys are deleted. When you delete your account, your account, your apps and everything in them, your publish tokens, your folders, your place on teams and your place on other people's apps are deleted. A team's apps belong to the team and stay with it; a team that has no other members is deleted with you. Records you added to someone else's app stay with that app, no longer linked to you, and reports and feedback you sent are kept without your email address. Backups and logs are removed on a rolling basis, within 30 days.
Your choices
- See and export your data. Settings has an export of your account, and each app's settings has an export of its data.
- Delete your account. You can delete your account at any time from Settings.
- Leave an app. You can remove yourself from an app someone shared with you.
- Ask us. Depending on where you live, you may have further rights, such as correcting your information or objecting to how it is used. Write to team@jigsawapps.com.
Security
Connections are encrypted in transit. Pasted keys are encrypted at rest. Every app runs at its own address, separate from your Jigsaw account, and apps are prevented from framing each other or loading each other's files. No system is perfectly secure; if you think you have found a problem, write to team@jigsawapps.com.
Children
Jigsaw is not meant for children under 16, and we do not knowingly collect their information.
Where information is processed
Jigsaw's servers and database are in the United Kingdom. WorkOS, Stripe, Resend, Fly.io and Supabase are companies based in the United States, and they may process information there. When information leaves the United Kingdom, we rely on the safeguards in those providers' data processing terms, such as standard contractual clauses.
Changes
If we change this policy in a way that matters, we will update the date above and tell you before the change takes effect.
Contact
Jigsaw. Email: team@jigsawapps.com.