Summary: Junto collects minimal data needed to provide our relationship management service. We use your email and name for authentication, store contact information you add, and never sell your data to third parties.
1. Introduction
Welcome to Junto ("we," "our," or "us"). We are committed to protecting your privacy and being transparent about how we collect, use, and share your personal information.
This Privacy Policy explains our practices regarding your data when you use our relationship management platform at heyjunto.com (the "Service"). By using Junto, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
2.1 Information You Provide
- Account information: Email address, name, and profile picture when you sign up via Google OAuth
- Contact data: Names, email addresses, notes, and relationship details you add about your contacts
- Activity information: Events, meetings, and interactions you record with your contacts
- Preferences: Your timezone, notification settings, and customization choices
2.2 Information Collected Automatically
- Session data: Authentication tokens and session identifiers to keep you logged in
- Usage data: Pages visited, features used, and general interaction patterns
- Device information: Browser type, operating system, and device identifiers
2.3 Information from Third Parties
When you authenticate with Google OAuth, we receive your basic profile information (email, name, profile picture). We only request the minimum scopes needed: openid, email, and profile.
3. How We Use Your Information
We use your information for the following purposes:
- Provide and maintain the Service: Create your account, store your contacts, and enable relationship management features
- Communicate with you: Send notifications about your activities, followups, and account updates
- Improve our Service: Analyze usage patterns to enhance features and user experience
- Ensure security: Detect and prevent fraud, abuse, and unauthorized access
- Comply with legal obligations: Respond to legal requests and enforce our terms
4. How We Share Your Information
We do not sell your personal information. We only share data in these limited circumstances:
4.1 Service Providers
We use trusted third-party services to operate Junto:
- Google OAuth: Authentication services
- ZeptoMail: Email delivery for notifications
- Railway: Cloud hosting and database services
- OpenRouter: AI services for suggestions (data processed but not stored)
4.2 Legal Requirements
We may disclose your information if required by law, court order, or government request, or to protect our rights, safety, or property.
4.3 With Your Consent
We may share information with third parties when you explicitly consent to such sharing.
5. Data Retention
We retain your data for as long as necessary to provide the Service:
| Data Type | Retention Period |
|---|---|
| Account data | Until account deletion + 90 days |
| Contact & activity data | While account is active |
| Session data | 30 days |
| Email delivery logs | 1 year |
| Usage analytics | 2 years (aggregated) |
6. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
6.1 Access & Portability
You can request a copy of your personal data in a machine-readable format (JSON/CSV). We will respond within 30 days.
6.2 Correction
You can update your profile information directly in the app or request corrections to inaccurate data.
6.3 Deletion
You can request deletion of your account and associated data. We will complete deletion within 30 days, except where we need to retain data for legal obligations.
6.4 Opt-Out
You can opt out of marketing communications and certain data processing. We honor Global Privacy Control (GPC) signals automatically.
To exercise your rights: Email us at [email protected] with your request. We may need to verify your identity before processing.
7. Data Security
We implement appropriate security measures to protect your data:
- Encryption in transit (HTTPS/TLS) and at rest
- Secure authentication via OAuth 2.0
- Access controls and least-privilege principles
- Regular security reviews and updates
While we strive to protect your data, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.
9. International Data Transfers
Your data may be processed in the United States where our servers are located. By using Junto, you consent to this transfer. We ensure appropriate safeguards are in place for any international data transfers.
10. Children's Privacy
Junto is not intended for users under 16 years of age. We do not knowingly collect personal information from children. If we learn we have collected data from a child, we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the Service. Your continued use after changes constitutes acceptance of the updated policy.
12. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us: