Privacy Policy
Last updated 13 August 2026. Valet is operated by Jumpstart Lab. Questions: jeff@jumpstartlab.com.
Valet holds credentials for external accounts you choose to connect — Google, Calendly, Zoom, Notion, Granola — and uses them to make requests on your behalf when a tool you have authorised asks. This policy describes exactly what it stores, why, and how to get rid of it.
What Valet stores
Who you are
When you sign in, Valet records the stable identifier and email address supplied by Jumpstart Lab's identity provider. The identifier — not the email — is what every connection is filed under, so changing your email address never detaches you from your own connections.
The connections you make
- The credential itself — an OAuth access and refresh token, or an API key you paste. Encrypted at rest, and never shown back to you or to anyone else after it is stored.
- Which account it is — the address or name the provider reports, so you can tell several connections of the same kind apart.
- What it may reach — the permissions the provider granted at consent, and, for some providers, an account identifier their API requires on every call.
- Whether it still works — the time of the last successful check and, if it failed, the provider's reason so the page can tell you what to do.
What was done with it
Valet keeps a record of custody actions — connecting, pausing, deleting, revoking, and health checks — including failures. These records never contain credentials.
What Valet does with it
One thing: makes the request a tool asked for, using the credential for the account that tool was granted, and returns the provider's answer. Access is granted per tool, per account, and per capability, and checked on every request. A tool granted your calendar cannot reach your mail, cannot make changes it was not granted, and cannot reach another person's account.
Credentials are never handed out. Tools receive results. Nothing that asks Valet for data receives the token behind it.
Google user data
Valet's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Concretely, for a connected Google account Valet requests access to your calendar so that tools you authorise can read your schedule and, where you have granted it, create or change events. Calendar data is fetched at the moment a request is made and returned to that tool; Valet does not build a copy of your calendar, does not use it to train models, does not use it for advertising, and does not sell it or transfer it to anyone but the tool you granted.
Who else sees it
Only the tools you have been granted access for, and only within their grant. Valet's infrastructure providers necessarily process data in the course of running the service: it is hosted on Jumpstart Lab's own servers, and requests go to the account providers you connected. There are no advertisers, analytics brokers, or data sales.
How long it is kept, and how to remove it
A connection is kept until you remove it. On the connections page you can:
- Withdraw one tool's access to a connection — that tool stops being able to use the account immediately, and the connection itself is untouched, so everything else you have granted keeps working.
- Delete a connection — Valet asks the provider to revoke the access first, then erases the stored credential. If the provider refuses the revocation, Valet keeps the connection and tells you, rather than quietly forgetting a grant that is still live at the provider.
Some providers offer no way to revoke a key from outside; for those, delete erases what Valet holds and tells you to rotate the key at the provider to fully withdraw access. You can also revoke Valet's access at any time from your Google account's security settings, independently of anything here.
The record of custody actions is retained as an audit trail. It never contains credentials.
Security
Credentials are encrypted at rest with per-record keys held outside the database. Reaching them requires signing in as you; every request a tool makes is checked against what that tool was granted. Error messages from providers are stripped of credential material before they are stored or shown.
Changes
If this policy changes materially, the date above changes with it.