Medallion Console // PRIVACY SUMMARY

Last updated July 19, 2026

Product privacy summary

Jim Technologies operates Medallion Console and its identity administration services. This summary explains the product's current data handling and the controls available to you.

Before public or customer onboarding, the applicable approved Privacy Notice, customer agreement, and any jurisdiction-specific disclosures must also be provided. Contact us for those documents and for the controller or processor details applicable to your use.

What the service handles

  • Account identity: your stable Google account identifier, verified email, display name, and sign-in status.
  • Organization data: organizations, memberships, invitations, roles, sign-in policy, and verified Workspace domains.
  • Security data: sessions, service-account and credential metadata, access grants, administrative events, and limited request security information such as IP address and user agent.
  • Product data: usage counters and the content, metadata, prompts, connector configuration, or ontology data that an organization chooses to process.
  • Billing data only when billing is enabled. Payment-card details are handled by the payment provider rather than stored in Medallion.

Why it is handled

We use this data to authenticate you, enforce tenant boundaries, provide the requested products, protect accounts, investigate failures or abuse, administer billing when enabled, satisfy valid legal obligations, and respond to support or privacy requests.

Visibility and tenant boundaries

Organization owners and data administrators can see their organization's members and administer its machine identities, credentials, and data access. The platform-operations view contains fleet-wide aggregate counts only. A platform role does not grant tenant membership or standing access to bucket names, object names, or object bytes.

Storage-auditor permissions, when granted, are separate tenant/resource permissions. Exceptional support access is also separate from the platform role and must be purpose-bound, exact-scope, time-limited, approved, and audited.

Cookies and analytics

The Console uses only host-scoped cookies needed for sign-in, session security, and requested account functions. Optional advertising and analytics tags are not loaded. Google may use its own cookies when you choose Google sign-in.

Service providers and international processing

Cloudflare hosts the Console application and its product-local state, Google supplies the selected identity service, and Stripe is contacted only if billing is configured and you request a billing action. Medallion product services process customer-selected storage, connector, and ontology data. Processing locations, recipients, contractual roles, and transfer safeguards depend on the deployment and customer agreement; request the applicable register before onboarding.

Retention and deletion

Console sessions and short-lived verification records are removed after expiry by a daily cleanup. Daily Console usage counters are removed after 35 days. Unused Google bearer/ID tokens and profile images are not retained. Other identity, tenant, audit, billing, customer-content, backup, and rights-case periods depend on their purpose, customer controls, applicable agreement, and documented legal obligations. Ask for the applicable schedule before onboarding.

Account deletion is a reviewed workflow. It safely identifies sole organization ownership, active machine identities, legal holds, downstream processors, and backup-restoration requirements. Removing an account does not silently delete customer-managed bucket contents; the organization controls that separate lifecycle.

Your controls

The identity privacy area exports identity-administration records and tracks account-deletion requests, including blockers that require action. Organization-controlled product content and product-local data are handled separately; contact us to include those systems in a rights request. Profile name and email corrections are refreshed from the verified Google identity source when you sign in again.

You may contact us to request access, correction, deletion, portability, restriction, objection, an appeal, or information about a regulator or supervisory authority where applicable. We will verify the request and apply the rules and exceptions that govern the actual processing.

Children and sensitive data

Medallion is not directed to children. Do not submit regulated health, financial, biometric, education, government, or other specially protected data unless a written agreement expressly covers that use.

Contact and changes

Privacy questions and rights requests can be sent to jjkoh@jimtech.xyz. Material changes to this summary will be published here with a revised date. Customer-specific terms, data-processing agreements, approved Privacy Notices, and required local notices remain applicable.