Privacy Policy

Effective Sep 22, 2026

This policy explains what personal information JOLIVE Labs Inc. ("JOLIVE Labs", "we", "us") collects through VigiLens (vigilensfinance.com and the VigiLens app), why, who we share it with, and the choices and rights you have.

VigiLens is used by financial advisors ("advisors") to communicate with their own clients. We handle two kinds of personal information differently:

1. Our two roles

  • Advisor account information: the details advisors give us to use VigiLens. We decide how this is used, and this policy governs it.
  • Client information: the details advisors store about their own clients, and what those clients do on the pages advisors send them. The advisor decides how this is used; we process it only on the advisor's behalf and on their instructions, under our Terms of Service. If you are an advisor's client, the advisor's own privacy notice applies, and questions or requests about your information are best sent to them. We'll help them respond.

2. What we collect and why

From advisors:

  • Account and profile: name, firm name, email address, phone number, firm mailing address, logo, firm colour and typeface, and password (stored by our authentication provider, never by us in readable form). Used to run your account and to brand the messages you send.
  • Content you create: model portfolios, incidents, drafts, surveys, saved comparisons, videos, and any recordings you make of yourself on camera or voice. Used to provide the Services.
  • Voice: if you choose a cloned voice, voice samples used to create it and the resulting voice model, held by our voice provider. Used only to narrate your own videos, with your express consent.
  • Settings and activity: your preferences, monitoring settings, when you accepted our Terms, and a log of actions such as sending a message. Used to operate features, keep a record you can export, and secure the Services.
  • Support messages you send us. Used to answer you.
  • Billing: your subscription plan, its status and renewal date, and how many videos you have generated. Payment itself is handled by Stripe on their own pages. We never see or store your card number; we keep only the identifiers Stripe gives us so we can show your plan and open your billing portal.

About advisors' clients (entered or imported by the advisor):

  • Name, email address, phone number, notes, tags, the model portfolio they're assigned to, and answers to surveys the advisor sends, which can include goals, timelines and life events.
  • Optionally, a date of birth and the date the person became a client, used to remind the advisor when a birthday or an anniversary is coming up and to personalise that greeting. Both are optional and the advisor can remove them at any time. The dates themselves are never sent to our AI or voice providers; for an anniversary we send only the number of years.
  • Engagement with the pages advisors send: whether and when a message was opened, whether a video was played, replies, unsubscribe choices, and the IP address and time of those visits.

Automatically, from anyone using the site: technical information such as IP address, browser and device type, and pages requested, used for security, abuse prevention (including rate limiting and Google reCAPTCHA checks in the app), and fixing errors.

We don't sell personal information, and we don't use it for advertising.

4. AI processing

To draft messages and scripts, we send the relevant context to our AI provider (OpenAI): for example the size of a market move, your firm name, and a client's first name, notes and survey answers. To narrate videos, we send the script to a voice provider: Fish Audio for a voice you or your team recorded, and ElevenLabs for the stock voices we provide. A recording made to create a cloned voice is sent to Fish Audio, and stays there until the voice is deleted.

OpenAI does not use data sent through its API to train its models by default, and keeps it for up to 30 days for abuse monitoring. We don't use client information to train any AI model.

5. Service providers and where data is stored

We use these providers to run VigiLens. Each processes personal information only to provide its service to us:

  • Google Cloud / Firebase: hosting, database, file storage, sign-in, and reCAPTCHA (United States)
  • Resend: sending email (United States)
  • OpenAI: AI drafting (United States)
  • Fish Audio (Hanabi AI Inc.): voice cloning and narration for voices you record (United States)
  • ElevenLabs: narration in the voices VigiLens provides (United States)
  • Amazon Web Services: video rendering and storage of finished videos (United States)
  • Upstash: rate limiting (United States)
  • Sentry: error monitoring, configured without session recordings (United States)
  • Stripe: subscription billing and payment processing (United States, Ireland and Canada)
  • Cloudflare: domain name services
  • Google Workspace: our support mailbox

We also use a commercial market-data provider; we send it ticker symbols and dates, not personal information.

As this list shows, personal information is stored and processed outside Canada, mainly in the United States, and may be accessible to courts, law enforcement and national security authorities there. We choose providers with strong security and contractual commitments, and we remain responsible for information we transfer to them.

6. When we access or disclose information

Our staff access account or client information only when needed: to help with a support request (with your permission), to investigate a problem or security issue, or when the law requires it.

We disclose personal information only to the providers above, to comply with a valid legal requirement, to protect the rights, safety or security of people or the Services, or as part of a merger or sale of our business (in which case this policy's protections continue to apply).

7. How long we keep it

We keep information while your account is open. If you delete your account, it enters a 30-day grace period; after that, your account, client information, files, cloned voices and rendered videos are deleted from our active systems. Residual copies in our providers' systems expire on those providers' schedules. We keep a minimal record that the account existed and when it was deleted, without personal details.

Advisors can edit or archive client records at any time and should remove client information they no longer need. To have a specific client's information erased, the advisor can contact us and we will delete it.

8. How we protect it

Data is encrypted in transit and at rest by our hosting provider. Each advisor's data is isolated by access rules enforced on our servers, public client pages are reached only through hard-to-guess links, and actions are logged in a record that can't be edited. We limit staff access and review our security regularly.

No system is perfectly secure. If a breach of security safeguards involving personal information creates a real risk of significant harm, we will notify affected advisors without undue delay (and within 72 hours of confirming it where a customer's regulations require), notify regulators such as the Office of the Privacy Commissioner of Canada as the law requires, and keep a record of incidents.

9. Your rights

You can ask to see the personal information we hold about you, correct it, or have it deleted, and ask how it has been used and disclosed. Advisors can do much of this themselves in Settings, including downloading everything and deleting their account. Residents of Quebec also have the right to data portability and to be informed of automated processing, and California residents may have rights under the CCPA.

We'll respond within 30 days. We may need to verify your identity first. If you're an advisor's client, we'll pass your request to your advisor, who controls your information, and help them respond.

If you're not satisfied with our response, you can complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca) or, in Quebec, the Commission d'accès à l'information.

10. Cookies and similar technologies

We use a secure session cookie to keep you signed in, store a few display preferences in your browser, and use Google reCAPTCHA in the app to tell real visitors from automated traffic. We don't use advertising or cross-site tracking cookies. Client emails don't contain tracking pixels; opens are recorded when the client visits their message page.

11. Privacy Officer and contact

Our Privacy Officer is responsible for how we handle personal information. You can reach them at support@vigilensfinance.com (subject line: "Privacy").

We may update this policy. When we make a significant change we'll update the effective date and ask advisors to review it in the app.

The structure of this policy is adapted from the 37signals open-source policies (github.com/basecamp/policies), used under the Creative Commons Attribution 4.0 International licence (creativecommons.org/licenses/by/4.0). Changes were made.