Here is what Jandex accesses, why, and where your data lives.
Jandex requests the data it needs to report on your account, and nothing more. It reads campaigns, flows, metrics, profiles, events, lists, and segments. The only thing it ever writes to your Klaviyo account is a List, and only when you explicitly push a Jandex-built RFM segment. For the exact permission granted on each object and what Jandex does with it, see the data reference.
Jandex never sends email on your behalf, never sees your Klaviyo password, and never stores your customers' plaintext email addresses.
Your connection uses OAuth, so Jandex holds a secure token rather than an API key. Tokens are stored encrypted and can be revoked by you at any time from inside Klaviyo. Account data is stored in a managed Postgres database hosted in the Asia Pacific (Tokyo) region, with access controls so that each customer can only reach their own data.
For the complete details, read the Jandex Privacy Policy.