Privacy Policy

Last updated: July 8, 2026

This document describes the policies about the different types of information that are collected, recorded, and processed by Jsmon. At Jsmon, one of our main priorities is the privacy of our users and visitors. This Privacy Policy document outlines the types of information that are collected and recorded by Jsmon and how we use it. If you have additional questions or require more information about our Privacy Policy, do not hesitate to contact us. This Privacy Policy applies only to our online activities and is valid for visitors and users of our website and platform (jsmon.sh and *.jsmon.sh) with regard to the information that they share and/or that we collect. This policy is not applicable to any information collected offline or via channels other than this website and platform.

Consent

By using our website and platform, you hereby consent to our Privacy Policy and agree to its terms.

Information We Collect

The personal information that you are asked to provide, and the reasons why you are asked to provide it, will be made clear to you at the point we ask you to provide your personal information.

If you contact us directly, we may receive additional information about you such as your name, email address, phone number, the contents of the message and/or attachments you may send us, and any other information you may choose to provide.

When you register for an Account, we may ask for your contact information, including items such as:

- Name
- Company name
- Role
- Number of Employees
- Address
- Email address
- Telephone number

We also collect operational data generated through your use of the platform, including:
- Target domains, subdomains, and assets you configure for scanning and monitoring
- Scan configurations, recurring scan schedules, and scan outputs
- Audit logs and activity records within your account

How We Use Your Information

We use the information we collect in various ways, including to:
- Provide, operate, and maintain our website and platform
- Improve, personalize, and expand our platform capabilities
- Understand and analyze how you use our platform to enhance reliability and performance
- Develop new products, services, features, and functionality
- Communicate with you, either directly or through one of our partners, including for customer service, to provide you with updates and other information relating to the platform and for marketing and promotional purposes
- Send you product updates, security alerts, and account notifications
- Detect, investigate, and prevent fraudulent activity and security incidents

How We Process Scan Data

To improve performance and reduce redundant processing:
- Jsmon may deduplicate the processing of scan results at the content level.
- When a scanned input returns content that is identical to content already processed from a prior scan - whether by you or by another customer.
- Jsmon may reuse the previously computed findings (output) rather than reprocessing the content from scratch. This applies only to content obtained without customer-supplied authentication, credentials, or session context, that is, content that is publicly and identically accessible to any party requesting it.
- This deduplication is based on a fingerprint of the response content itself, not on your identity, account, or workspace. Your account's association with any scan - including the input you provided, when, and the results returned to you - remains logically isolated to your account and workspace, and is access-controlled independently of how the underlying content is stored internally. - Other customers cannot see that you scanned a given input, and you cannot see that another customer did, regardless of whether the underlying content was newly processed or reused.

Data Retention

We retain account data and scan artifacts (outputs) so you can resume, review, and act on results at any time. You may request deletion of your data by contacting us at support@jsmon.sh. Upon a valid deletion request, we will remove your personal data from our records within 30 days, subject to any legal or regulatory obligations.

Where scan results are derived from publicly accessible content that may be shared across customer accounts as described in "How We Process Scan Data," deleting your data removes your account's association with that content - including your scan history, identifiers, and workspace links to it - from our active records. The underlying content itself may be retained if it is still referenced by another customer's active account, and will be permanently deleted once no customer account references it. Data that is not shared in this way, including your account information, configuration, and any content obtained using your credentials or authentication, is deleted in full as described above.

Log Files

Jsmon follows a standard procedure of using log files. These files log visitors and users when they access our website and platform. The information collected by log files includes internet protocol (IP) addresses, browser type, Internet Service Provider (ISP), date and time stamp, referring/exit pages, and the number of page interactions. These are not linked to any information that is personally identifiable.

The purpose of collecting this information is to analyze trends, administer the platform, monitor system performance, and gather aggregate usage metrics.

Cookies and Web Beacons

Like any other website, Jsmon uses cookies. These cookies are used to store information including session state, user preferences, and the pages on the website that the visitor accessed or visited. The information is used to optimize the user experience by customizing our web page content based on the visitor's browser type and/or other information.

For more general information on cookies, please refer to
https://en.wikipedia.org/wiki/HTTP_cookie.

You can choose to disable cookies through your individual browser settings. For more detailed information about cookie management in specific web browsers, please refer to the browsers' respective documentation.

Third-Party Processing

Jsmon uses trusted third-party infrastructure providers, APIs, and services to operate and deliver the platform. These include cloud compute providers, email delivery services, payment processors (Stripe), analytics platforms, and large language model (LLM) providers used to power AI-driven features. We only share information with third parties to the extent necessary to provide the Services.

Jsmon's Privacy Policy does not apply to third-party websites or services. We advise you to consult the respective privacy policies of these third parties for more detailed information about their data handling practices.

Visit https://jsmon.sh/subprocessors for more details.

Security

Jsmon is an AI-powered External Attack Surface Management (EASM) platform, and we take the security of your data seriously. We implement industry-standard technical and organizational measures to protect your personal information and operational data against unauthorized access, alteration, disclosure, or destruction. However, no method of transmission over the Internet or method of electronic storage is 100% secure, and we cannot guarantee absolute security.

GDPR Data Subject Rights

If you are a resident of the European Economic Area (EEA), you have certain data protection rights. Jsmon aims to take reasonable steps to allow you to correct, amend, delete, or limit the use of your personal data. You have the following rights:

- The right to access, update, or delete the personal information we hold about you
- The right to rectification — to have inaccurate personal information corrected
- The right to object to our processing of your personal data - The right to data portability — to receive a copy of your data in a structured, machine-readable format
- The right to withdraw consent at any time where we rely on consent to process your data

To exercise any of these rights, please contact us at support@jsmon.sh. We will respond to your request within one month.

CCPA Privacy Rights (Do Not Sell My Personal Information)

Under the CCPA, among other rights, California consumers have the right to:

- Request that a business that collects a consumer's personal data disclose the categories and specific pieces of personal data that a business has collected about them
- Request that a business delete any personal data about the consumer that a business has collected
- Request that a business that sells a consumer's personal data not sell the consumer's personal data If you make a request, we have one month to respond to you.

If you would like to exercise any of these rights, please contact us at support@jsmon.sh.

Children's Information

Another part of our priority is adding protection for children while using the internet. We encourage parents and guardians to observe, participate in, and/or monitor and guide their children's online activity.

Jsmon does not knowingly collect any personally identifiable information from children under the age of 13. If you believe that your child provided this kind of information on our website, we strongly encourage you to contact us immediately at support@jsmon.sh, and we will make our best efforts to promptly remove such information from our records.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. We will notify you of any significant changes by updating the "Last updated" date at the top of this page and, where appropriate, by sending you a notification via email. We encourage you to review this Privacy Policy periodically.

Contact Us

For questions, concerns, or notices regarding this Privacy policy, please contact us:

Jsmon Inc.
Email: support@jsmon.sh
Website: https://jsmon.sh

Thank you for choosing Jsmon. We are committed to helping you discover, monitor, and secure your external attack surface.

© JSMON 2026 All Rights Reserved.

© JSMON 2026 All Rights Reserved.

© JSMON 2026 All Rights Reserved.