Privacy Policy
This policy explains what personal data withJZ LLC collects when you use the services it runs under mybigexperiment.com, why, who it is shared with, how long it is kept, and what rights you have.
1. In short
- withJZ LLC runs the Services. They are invite-only and not offered to the general public.
- Messages you send to an assistant are processed on servers we rent in the European Union (Germany). They are sent to an AI model provider to generate a reply.
- We do not sell your personal data. We do not use it for advertising. We do not use your content to train AI models.
- Your content is kept until you or your Workspace Operator deletes it. When a workspace is closed, or we verify a request to erase your data, we delete it within 30 days, and from backups within a further 30 days.
- You can ask to see, correct, or delete your data by emailing privacy@mybigexperiment.com.
2. Who we are
The Services are run by withJZ LLC, a Wyoming (USA) limited liability company (“withJZ”, “we”, “us”, “our”).
For anything about privacy, email privacy@mybigexperiment.com.
3. What this policy covers
This policy covers all services and experiments that withJZ LLC operates under mybigexperiment.com (“the Services”). This includes:
- the AI assistants called the “withJZ Crew”, which you can talk to in Slack and Microsoft Teams;
- the private web app for those assistants; and
- this website.
An individual experiment may come with a short extra notice if it works differently. That notice explains the difference. This policy covers everything else.
The Services are invite-only. They are not offered to the general public.
4. Our role: controller or processor
The Services are organized into workspaces. Who decides how your data is used depends on whose workspace you are in.
- Workspaces we run. For workspaces withJZ LLC runs for itself and the people it invites, withJZ LLC is the controller. We decide why and how your personal data is used, as this policy describes.
- Workspaces run by a Workspace Operator. An invited organization or person may operate its own workspace. We call them a “Workspace Operator”. The Workspace Operator decides which chat platforms and AI providers its workspace connects to. For that workspace’s data, the Workspace Operator is the controller. withJZ LLC is a processor: we process the data only on the Workspace Operator’s instructions. The Workspace Operator’s own privacy notice also applies.
- Providers a Workspace Operator connects. A Workspace Operator may connect an AI provider or another service using its own account. That provider is governed by the Workspace Operator’s agreement with it.
5. How the Services work
Here is what happens when you use a withJZ Crew assistant:
- You send a message or file to an assistant. You do this in a Slack or Microsoft Teams direct message, or in the private web app.
- The chat platform delivers it to us. We process it on servers we rent in the European Union (Germany).
- We send it to an AI model provider, together with the context the assistant needs. That context can include earlier messages in the conversation and the assistant’s saved notes. The provider generates a reply.
- The assistant sends the reply back to you in the same chat app or web app.
Assistants can also use tools, such as browsing the web, reading files, and running code. These tools run inside isolated sandbox environments. When an assistant browses the web for you, the websites it visits receive the requests it makes. Those requests may include words from your message.
6. The personal data we process
- Account data. If you use the private web app: your name, your email address, and a hash of your password. We store a one-way hash, not the password itself.
- Chat-platform identifiers. Your Slack or Microsoft Teams user ID, workspace or tenant ID, conversation IDs, and display name.
- Content. The messages, files, images, and links you send to an assistant, and the assistant’s replies. Your content may include personal data about other people.
- Assistant memory. Notes an assistant saves so it can be more helpful to you later, such as your preferences or ongoing tasks.
- Usage and cost metadata. Timestamps, token counts (a measure of how much text an AI model processed), and which AI model was used.
- Technical and security logs. IP addresses and request metadata, such as the time of a request and what was requested. These are recorded at our network edge and on our servers.
Where the data comes from
- From you, when you send messages or files, or set up an account.
- From the chat platform (Slack or Microsoft), which gives us your identifiers and display name when you message an assistant.
- From the person or organization that invited you or runs your workspace, for example your name and email address so you can be invited.
- From the assistants, which create replies and memory notes.
7. What you should not send
Please do not send an assistant:
- Special categories of personal data. This means data about health, genetic or biometric data, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, sex life, or sexual orientation. This applies to data about you and about other people. The only exception is a workspace whose Workspace Operator has told you it permits this. Workspaces run by withJZ LLC do not permit it.
- Confidential information you are not authorized to share. This includes confidential information belonging to your employer, your clients, or anyone else.
8. Why we use your data, and our legal bases
Where the EU or UK GDPR applies, we must have a legal basis under Article 6 for each use of your personal data. These are ours:
| Purpose | Examples | Legal basis |
|---|---|---|
| Providing the Services to you | Receiving your messages, generating and delivering replies, running tools, saving assistant memory, keeping your account working. | Contract (Art. 6(1)(b)) when you use the Services for yourself. Legitimate interests (Art. 6(1)(f)) when you use them for an organization: our interest, and the organization’s, in providing the Services you were invited to use. |
| Security, abuse prevention, troubleshooting, and cost control | Security logs, rate limits, investigating errors, tracking token usage and spending. | Legitimate interests (Art. 6(1)(f)): keeping the Services safe, working, and affordable. |
| Complying with the law | Responding to lawful requests from authorities. Keeping records the law requires. | Legal obligation (Art. 6(1)(c)). |
| Anything we ask your consent for | We explain the purpose when we ask. | Consent (Art. 6(1)(a)). You can withdraw consent at any time. This does not affect processing that happened before you withdrew it. |
You can object to processing based on legitimate interests. See Your rights.
In a workspace run by a Workspace Operator, the Workspace Operator decides the purposes and is responsible for the legal basis.
9. What we do not do
- We do not sell your personal data.
- We do not use your personal data for advertising.
- We do not use your content to train AI models.
- We use AI model providers under business terms that do not allow them to use your content to train their models. Workspace Operators who connect other providers are responsible for those providers’ terms.
- We do not make decisions about you based solely on automated processing that have legal or similarly significant effects on you (GDPR Article 22).
10. Who we share data with
We share personal data only with the service providers we need to run the Services. Today they are:
| What they do | Provider | Location | Why |
|---|---|---|---|
| Hosting | Contabo GmbH | Germany (EU) | Runs the servers that process and store data for the Services. |
| Network and security edge | Cloudflare, Inc. | United States, with a global network | Delivers and protects traffic to the Services and this website. Processes IP addresses and request metadata. |
| Chat platforms you choose to use | Slack Technologies, LLC (Slack); Microsoft Corporation (Microsoft Teams) | United States and other locations | Carry messages between you and the assistants, under your or your organization’s account with them. |
| AI model providers configured for a workspace | Currently Anthropic, PBC and OpenRouter, Inc., plus any provider a Workspace Operator configures | United States and other locations | Generate the assistants’ replies. OpenRouter passes each request to the provider that serves the chosen model. |
| Private admin networking | Tailscale Inc. | Outside the EEA | Private network access for our administrators only. |
| Microsoft Corporation | United States and other locations | Handles email sent to and from privacy@mybigexperiment.com. |
We may also share personal data:
- with authorities, courts, or others when the law requires it; and
- with a successor organization, if withJZ LLC is involved in a merger, acquisition, or sale of all or part of its business.
11. International transfers
We process your messages on our servers in Germany. Some of the recipients above are in the United States or elsewhere outside the European Economic Area (EEA).
When personal data is transferred outside the EEA, we rely on:
- the EU–U.S. Data Privacy Framework, where the recipient is certified under it; and/or
- the European Commission’s Standard Contractual Clauses.
To get a copy of these safeguards, email privacy@mybigexperiment.com.
12. How long we keep data
- Content and assistant memory are kept while the workspace is active, until you or the Workspace Operator deletes them. Workspace Operators may set a shorter retention period where the Services support it.
- Usage and cost metadata is kept while the workspace is active, and deleted with the workspace on the timeline below.
- Account data is kept while your account exists. When your account is closed, it is deleted on the timeline below.
- Security and technical logs are kept for up to 30 days, unless we need them longer to investigate a specific incident.
When a workspace is closed, or you ask us to erase your data
- We delete the data from our active systems within 30 days of the workspace closing, or of verifying your erasure request.
- We delete it from backups within a further 30 days. Our backups rotate within 30 days.
Copies held by others
- Slack and Microsoft keep their own copies of messages in your chat app. Those copies are controlled by your account, or your organization’s account, with them. To delete them, delete them in Slack or Microsoft Teams, or ask your workspace administrator.
- AI model providers may keep inputs and outputs for a limited time under their own terms, for example to monitor for abuse.
13. Your rights
Depending on where you live, data protection laws give you rights over your personal data. These laws include the EU GDPR, the UK GDPR, Kosovo’s Law No. 06/L-082 on Protection of Personal Data, and US state privacy laws where they apply. Your rights may include the right to:
- Access your personal data and get a copy of it.
- Rectification: have inaccurate data corrected, or incomplete data completed.
- Erasure: have your data deleted.
- Restriction: ask us to limit how we use your data.
- Portability: get data you gave us in a structured, machine-readable format, or have it sent to someone else.
- Object to processing, including processing based on legitimate interests.
- Withdraw consent at any time, where we rely on consent.
- Not be subject to solely automated decisions that have legal or similarly significant effects on you.
- Complain to a data protection supervisory authority in the country where you live, where you work, or where the issue occurred.
Some rights have limits under the law. If we cannot fully meet your request, we will tell you why.
14. How to use your rights
- Email privacy@mybigexperiment.com. Tell us what you are asking for, and which chat app or workspace it concerns.
- We may need to verify your identity before we act. For example, we may ask you to confirm the request from the email address or chat account linked to your data.
- We reply within one month. If a request is complex, or you send many requests, we may extend this by up to two more months. If we do, we will tell you within the first month and explain why.
- If your data is in a workspace run by a Workspace Operator, that operator decides how it is used. We will forward your request to the operator or help them respond. You can also contact the operator directly.
15. How we protect your data
- Encryption in transit. We encrypt data in transit.
- Limited access. Administrative access to our systems is limited to withJZ LLC and the administrators it authorizes. They must use multi-factor authentication and private networking.
- Secrets encrypted at rest. Credentials and keys used by the Services are stored encrypted.
- Isolated tools. The assistants’ tools run in isolated sandboxes with restricted network access.
- Breach response. If there is a personal data breach, we notify affected users and the relevant authorities as the law requires. Where the GDPR applies, we notify the supervisory authority within 72 hours of becoming aware of a reportable breach.
To report a security issue, email security@mybigexperiment.com.
16. Children
The Services are not for anyone under 16. We do not knowingly collect personal data from anyone under 16. If you think a child has given us personal data, email privacy@mybigexperiment.com and we will delete it.
17. Cookies
- This website does not set cookies. It uses no analytics, no tracking, no scripts, and no external fonts.
- Cloudflare, our network and security provider, may set a strictly necessary security cookie, for example when it checks that a visitor is not a bot.
- The private web app may use cookies or similar browser storage that are strictly necessary to sign you in and keep your session secure.
- We do not use advertising or analytics cookies.
18. Changes to this policy
We may update this policy. When we do, we change the “Last updated” date at the top and add a note under What changed. For material changes, we also notify active users in the chat apps or by email.
19. Contact us
- withJZ LLC
- Privacy: privacy@mybigexperiment.com
- Security: security@mybigexperiment.com
20. What changed
- First version.