Privacy Policy
Last updated: February 8, 2026
JSON Copilot is a browser-based JSON formatter, validator, and AI-powered editor provided by Cardamon Inc ("we", "us", "our"). This Privacy Policy explains how we collect, use, store, and protect your data when you use our website and services (the "Service").
1. How we process your data
Core features (formatting, validation, minification, schema checking) run entirely in your browser. Your JSON data is not sent to any server for these operations.
AI-powered features (such as Explain, Fix & Validate, Test Data, and JSON Schema generation) require server-side processing. When you use these features, your JSON content is sent to our servers and forwarded to AI providers (such as OpenAI) to generate results.
2. Data we collect
2.1 Account information
When you create an account (via Google OAuth or email magic link), we collect:
- Email address
- Display name (from your authentication provider)
- Profile picture URL (from your authentication provider)
2.2 Usage data
For authenticated users, we store:
- Project data including JSON content, output, and schemas you save to projects
- AI Copilot history including the JSON input and AI-generated output for each request
- Credit consumption and transaction history
- Subscription status and plan information
2.3 Payment information
Payment processing is handled by Paddle.com Market Limited ("Paddle"), our Merchant of Record. We do not collect or store your credit card numbers, bank account details, or other payment credentials. Paddle collects and processes payment information in accordance with their own Privacy Policy. We receive from Paddle: transaction IDs, subscription status, and billing country for our records.
2.4 Automatically collected data
We may collect basic technical information such as browser type, device type, and pages visited through privacy-friendly analytics. We do not collect the contents of your JSON through analytics.
3. How we use your data
We use the data we collect to:
- Provide and operate the Service
- Process AI requests and return results
- Manage your account, subscriptions, and credit balance
- Send transactional emails (account verification, password resets)
- Improve the Service and fix bugs
- Prevent abuse, fraud, and security threats
We do not:
- Use your JSON content for training AI models
- Sell your personal data or JSON content to third parties
- Send marketing emails without your explicit consent
4. Sub-processors and third-party services
We use the following third-party services to operate the Service:
| Provider | Purpose | Data shared |
|---|---|---|
| Paddle | Payment processing (Merchant of Record) | Billing info, email, transaction data |
| Supabase | Authentication and database hosting | Account data, projects, AI history |
| OpenAI | AI processing for Copilot features | JSON content submitted to AI features |
| Vercel | Hosting, analytics, and AI gateway | Basic usage analytics, request routing |
| Google (OAuth) | Authentication | Email, name, profile picture |
5. Cookies and local storage
We use essential cookies and browser local storage to:
- Maintain your authentication session
- Remember your preferences (theme, layout, editor settings)
- Store unsaved JSON content locally in your browser
We may also use privacy-friendly analytics (Vercel Analytics) that do not use cookies for tracking individual users. If third-party advertisements are displayed (such as Google AdSense), those services may set their own cookies in accordance with their own privacy policies.
6. Data retention
- Account data: Retained for as long as your account is active. After account deletion, we will remove your personal data within 30 days, except where retention is required by law (e.g., billing records).
- Project data and AI history: Retained for as long as your account is active, subject to plan-based history retention limits. You may delete individual projects or AI history entries at any time.
- Billing records: Transaction records may be retained for up to 7 years as required for tax and legal compliance.
- Server logs: Automatically deleted after 30 days.
7. Your rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate personal data
- Deletion: Request deletion of your account and personal data
- Portability: Request your data in a structured, machine-readable format
- Objection: Object to certain processing of your personal data
- Restriction: Request restriction of processing in certain circumstances
To exercise any of these rights, contact us at support@cardamon.org. We will respond to your request within 30 days.
For EU/EEA residents (GDPR): Our legal basis for processing personal data includes: performance of a contract (providing the Service), legitimate interests (improving the Service, preventing fraud), and consent (where applicable). You have the right to lodge a complaint with your local data protection authority.
For California residents (CCPA): We do not sell your personal information. You have the right to know what personal information we collect and to request its deletion.
8. Data security
We implement reasonable technical and organizational measures to protect your data, including encryption in transit (TLS/HTTPS), secure authentication, and access controls. However, no method of transmission over the Internet or electronic storage is 100% secure, and we cannot guarantee absolute security.
9. International data transfers
Your data may be processed in the United States and other countries where our service providers operate. By using the Service, you consent to the transfer of your data to these countries. We ensure that appropriate safeguards are in place for international transfers.
10. Children's privacy
JSON Copilot is intended for use by individuals who are at least 13 years old. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us so we can delete it.
11. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page and, where practicable, provide notice through the Service. Your continued use of JSON Copilot after any changes means you accept the revised policy.
12. Contact
If you have any questions about this Privacy Policy or wish to exercise your data rights, you can contact us at:
- Email: support@cardamon.org
- Address: Cardamon Inc, Boca Raton, Florida, United States
© Cardamon Inc. All rights reserved. JSON Copilot is an independent project and is not affiliated with, endorsed by, or sponsored by GitHub, Microsoft, or GitHub Copilot.