Privacy Notice
Effective October 6, 2026
Pathion operates Jena4. This notice explains what information Jena4 handles, why it is used, where it may go, and the choices available to you.
Information Jena4 handles
- Account and team information: email address, user identifier, organization and workspace names, team roles, invitations, and sign-in session information. Jena4 uses passwordless email sign-in and does not ask you to create a password.
- Customer content: the conclusions, facts, evidence, rules, requirements, explanations, sources, timestamps, and other text or structured data that you or your organization submit.
- Service and security records: actions taken in the service, audit history, usage totals, error and job status, API-key prefixes and hashes, webhook configuration and delivery results, and information needed to prevent abuse.
- Payment information: if paid billing is enabled, Stripe processes payment and subscription information. Jena4 may retain related customer, subscription, price, and billing-status identifiers, but does not store full payment-card details.
Do not place sensitive personal information in customer content unless your organization has determined that doing so is appropriate and lawful.
How Pathion uses information
Pathion uses this information to authenticate users; operate organizations, workspaces, roles, and invitations; maintain and explain governed conclusions; provide APIs and customer-configured webhooks; secure and troubleshoot the service; enforce service limits; communicate about the service; and operate billing when paid billing is available.
Jena4 does not currently sell personal information or use customer information for targeted advertising.
Cloudflare Turnstile
Jena4 uses Cloudflare Turnstile on forms that request authentication emails. It helps distinguish people from automated traffic. Cloudflare says Turnstile processes security signals such as IP address, TLS fingerprint, browser user-agent, site key, and site origin. Cloudflare also states that Turnstile does not access form entries or other page inputs.
Learn more in Cloudflare’s Turnstile Privacy Addendum.
Service providers and destinations
Pathion uses service providers to operate Jena4:
- Supabase for authentication, sessions, database storage, and related backend services.
- Vercel for application hosting and delivery.
- Resend for authentication and invitation email delivery.
- Cloudflare for Turnstile bot detection.
- Stripe for payment and subscription processing if paid billing is enabled.
If your organization configures a webhook, Jena4 sends the selected event data to that organization-controlled endpoint. Organization owners and administrators can also invite teammates and manage access, which exposes relevant account information within that organization.
Pathion may also disclose information when required by law, to protect the service or people, or as part of a business transaction subject to appropriate safeguards.
Cookies and similar technology
Jena4 uses essential cookies or similar browser storage for authentication, security, one-time sign-in completion, and workspace selection. These controls are necessary for the service to function. Turnstile may process browser and device signals for security as described above.
Retention, access, and deletion
Retention depends on the type of record and the needs of operating, securing, and documenting the service. Product and audit histories may be preserved beyond the history window visible under a particular plan; a plan’s history window limits access and does not mean older records were deleted.
Self-service organization export and deletion are not currently available. To request access, correction, export, or deletion, email hello@jena4.com. Pathion will evaluate the request against applicable law, security needs, the rights of the organization and other users, and records that must be preserved.
Security
Pathion uses organizational and technical safeguards intended to protect information, including tenant access controls, hashed API keys and invitation tokens, encrypted webhook signing secrets, and signed HTTPS webhook delivery. No online service can guarantee absolute security.
Children
Jena4 is a business service and is not directed to children under 13. Contact Pathion if you believe a child has provided personal information through the service.
Changes and contact
Pathion may update this notice as Jena4, its providers, or legal requirements change. The effective date above will be updated when the notice changes.
Questions or privacy requests can be sent to hello@jena4.com.
