Privacy Policy
Effective September 15, 2026
In short
Your photos are for your people — not for us, and not for anyone else.
What we collect. Only what Juno needs to run: your email, your name and profile, and whatever you choose to share. Nothing more.
How it's stored. Your posts are encrypted end-to-end — photos, videos, captions and comments alike. We store ciphertext to make the app work; Juno can't read what you share, and only the people you've shared it with can.
What we never do. No ads. No selling your data. No data brokers. No profiles built about you. Your activity isn't analyzed for anyone's benefit but yours.
Who sees what. Only the people you've accepted as connections can see what you share. Juno has no public surface and no discovery feed.
Deleting your data. Delete your account in Settings and your content goes with it within a day. Backup copies expire within 30 days. We keep only what the law requires, for as long as it requires.
This summary is here to help you read the policy, not to replace it. The full policy below is what applies.
About this policy
Juno is a mobile app for sharing photos and videos privately with people you know. It is operated by Big Vision Ventures LLC ("Juno", "we", "us" or "our"), 151 Calle de San Francisco, Ste 200, San Juan, Puerto Rico 00901.
This Privacy Policy describes how we handle personal information when you use the Juno app, the juno.so website, and the emails and notifications we send (together, the "Service"). It also explains the choices you have. Using the Service means this policy applies to you. If you do not agree with it, please do not use the Service.
1. What Juno is built not to see
Juno is designed so that the content you share can be read only by you and the people you share it with.
- Encrypted on your device. Photos, videos, captions, comments, your profile photo and your profile cover image are encrypted on your device before they are uploaded, using keys that are created and kept on your devices. Each post has its own key, which your device seals individually to each person you share the post with.
- We hold only ciphertext. Our servers store and deliver the encrypted data and the sealed keys. We do not hold a key that can open them. We cannot read your content, cannot recover it if you lose your keys, and cannot hand it over to anyone in readable form.
- Between your devices. Your identity key is protected by a PIN, and where you turn it on, by your device's biometrics. We never receive your PIN. When you add a device, the key moves between your devices, not through us in readable form.
- What is not encrypted end-to-end. To run the Service we do need to see some information in the clear, such as who you are connected with, who a post is shared with, and the emoji reactions on a post. Section 2 lists all of it. That information is encrypted in transit and at rest, but we can see it.
2. Information we collect
Account and profile. Your email address, your name, an optional short bio, and the public half of your encryption identity key. If you sign in with Apple or Google, we receive the identifier and email that provider gives us for you, which for Apple may be a private relay address. Passwords are stored only as hashes.
Connections and social activity. Who you have invited, requested, accepted, removed or blocked, and who has done the same to you, including who placed a block. The names and membership of any friend lists you create. For each post, who it is shared with and when. Emoji reactions to posts and comments, and the kind and position of any sticker placed on a post. Which posts you have viewed, so a friend's feed can show what is new to them. Your notification inbox and which notifications you have read. Posts you have saved to collections.
Your content, encrypted. The encrypted bytes of your photos, videos, captions, comments, profile photo and cover image, and the sealed per-post keys. Alongside them we store the information needed to deliver them: file sizes, image dimensions, video duration, storage paths and timestamps.
Invites. When you invite someone by text or email, your device sends us a one-way hash of their phone number or email address, salted with a secret we hold, so that the invite can be matched when they redeem it without our storing the address itself. For an email invite we also hold the email address itself so we can send the invitation; it is removed 30 days after the invite is redeemed or expires. We record when an invite is opened and redeemed. The name you label an invite with in the app stays on your device only. An invite shared as a QR code carries no destination at all.
Your contacts. If you allow it, the app reads your device's address book on your device so you can pick who to invite. Your address book is not uploaded to us. Only the phone number or email address of the person you choose leaves your device, in the form described above. A text invite is sent from your own messaging app and your own number.
Devices and notifications. For each device you sign in on: a push-notification token, the platform, and a device label, so we can deliver notifications and let you see and remove your devices. Encrypted copies of your identity key that only your PIN can unwrap. Short-lived pairing codes when you add a device.
Membership. Whether your membership is active, the annual amount you chose, your renewal date, and the transaction identifier the app store assigns to your purchase. Apple or Google processes your payment; we never receive your card details.
Diagnostics. Crash reports and performance data from the app, tagged with the area of the app involved, with personal details scrubbed before they leave your device. These reports are not tied to your account. Launch and render timing, such as how long the app takes to become interactive, is collected separately and tied to an anonymous install identifier rather than to your account.
Messages to us. Anything you include when you email support, privacy or moderation.
What we do not collect. Precise location. Health data. Your browsing history. Advertising identifiers. Your address book. The content of your posts, captions or comments in readable form.
3. How we use information
We use the information above to:
- run the Service: create your account, sign you in, deliver encrypted content and keys to the people you chose, keep your devices in sync, and show each member the connections, reactions, comments and notifications they are entitled to see;
- deliver invites and apply invite rewards, such as a free month;
- manage your membership and billing through the app stores;
- send push notifications and emails about activity on your account, such as a friend request or a new post from a connection. A push notification names the friend who acted but never contains the content of a post, caption or comment;
- keep the Service secure: prevent abuse and spam, enforce rate limits, verify that a device holds your keys before it can sync, and investigate reports;
- respond to your support, privacy and moderation requests;
- diagnose crashes and performance problems and improve the app;
- comply with the law, respond to lawful requests, and establish or defend legal claims; and
- enforce our Terms of Use.
We do not use your information for advertising, sell it, share it with data brokers, build profiles of you, make automated decisions that have legal or similarly significant effects on you, or use it to train artificial-intelligence models.
4. Who we share information with
The people you choose. Your connections see your name, profile photo, bio and the content you share with them, along with the reactions and comments from other connections who are also connected with them. Members you have not connected with see nothing about you.
Service providers. Companies that process information on our behalf, under contracts that restrict them to providing their service to us:
- Supabase hosts our database, authentication, encrypted file storage and server functions, in the United States.
- Apple provides Sign in with Apple, App Store purchases, TestFlight and push-notification delivery to iOS devices.
- Google provides Google Sign-In and, when the Android app is available, Google Play purchases and push delivery to Android devices.
- RevenueCat manages memberships and links app-store purchases to your account.
- Expo builds and updates the app, relays push notifications to Apple and Google, and collects the launch and render timing described above.
- Sentry receives crash reports and performance diagnostics.
- Postmark sends the emails we send, such as invitations and sign-in codes.
- Detour resolves invite links opened on a device that does not yet have Juno installed, so the invite still works after the app is installed.
When the law requires it. We may disclose information to law enforcement, government authorities or other parties where we believe in good faith that it is necessary to comply with the law or a lawful request, to enforce our Terms, or to protect the rights, safety or property of Juno, our members or others. Because your content is encrypted end-to-end, we cannot provide it in readable form.
If Juno changes hands. If the Service is sold, merged or transferred, or in the event of insolvency, information may be transferred to the successor, who will be bound by this policy.
We do not share information with advertising partners, data brokers, affiliates or marketing partners.
5. How long we keep information, and how to delete it
While your account is active, we keep the information above so that the Service works.
Deleting content. You can delete a post or a comment at any time in the app. It is removed from our servers and, the next time their app syncs, from your connections' devices.
Deleting your account. You can delete your account from Settings in the app, or by following the steps at juno.so/delete-account. When you do:
- your account, profile, connections, encrypted content, sealed keys, notifications, device records and membership record are deleted from our systems within 24 hours;
- the email addresses on invites you sent are removed at the same time;
- copies in our database backups and in our service providers' logs expire within 30 days;
- crash and performance diagnostics expire within 90 days; and
- content already delivered to your connections is removed from their devices the next time their app syncs. We cannot remove copies that someone captured outside Juno, such as a screenshot.
Deleting your account does not cancel an app-store subscription. Cancel it in your Apple or Google subscription settings to stop being charged. Apple and Google keep their own records of your purchases under their policies.
After deletion, we keep nothing that identifies you, except where we must keep a record to comply with a legal obligation, resolve a dispute or enforce our Terms, in which case we keep only what that requires, for as long as it requires. Invite email addresses are removed 30 days after the invite is redeemed or expires even if you keep your account.
6. Your choices
- Your profile. You can update your name, bio and photos in the app at any time.
- Notifications. You can turn categories of notifications on or off in the app, and turn off push notifications entirely in your device settings.
- Contacts. You can grant or revoke the app's access to your address book in your device settings. Without it, you can still invite people by entering their details or by QR code.
- Connections. You can remove or block a connection at any time.
- Your information. You can ask us for a copy of the information we hold about you, ask us to correct it, or ask us to delete it, by emailing privacy@juno.so from the address on your account.
- Sign-in providers. If you signed in with Apple or Google, you can manage what that provider shares with us in your settings with them.
7. Children
The Service is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child under 13 has created an account, contact us at privacy@juno.so and we will delete the account and its information. Members aged 13 to 17 may use the Service only with a parent or guardian's permission.
8. Security
We protect your information with end-to-end encryption of your content, encryption in transit and at rest for everything else, hashed passwords, a device PIN that never leaves your device, rate limits on sign-in and invite attempts, and access controls on our systems. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If you discover a security problem, please tell us at support@juno.so.
9. Where information is stored
Our servers are in the United States, and our service providers operate there. If you use the Service from outside the United States, your information will be transferred to and stored in the United States, where privacy laws may differ from those where you live.
10. Your state privacy rights
This section applies to residents of U.S. states whose privacy laws apply to us and give their residents the rights below (the "State Privacy Laws"). Not every right is available in every state, and we may decline a request where the law allows.
- Information and access. You can ask what categories of personal information we collect, where we get it, why, and who we share it with, and you can request a copy of your information.
- Correction and deletion. You can ask us to correct inaccurate information or to delete your information.
- Appeal. If we decline a request, you can appeal by replying to our decision.
- Opt-out rights. We do not sell your personal information, share it for targeted advertising, or use it for profiling that produces legal or similarly significant effects, so there is nothing to opt out of. We do not process sensitive personal information to infer characteristics about you. We do not have actual knowledge that we sell or share the personal information of anyone under 16.
- How to exercise these rights. Email privacy@juno.so from the address on your account. We verify requests by confirming that you control that address; we may ask for more information where the law permits. An authorized agent may submit a request on your behalf if they provide proof of your permission and we can verify your identity.
- No discrimination. We will not treat you differently for exercising these rights.
- California. Under California's "Shine the Light" law, California residents may ask for a list of third parties to whom we disclosed personal information for their own direct marketing purposes in the previous year. We do not disclose personal information for that purpose. Requests can be sent to privacy@juno.so with the subject "Shine the Light Request".
- Nevada. Nevada residents may direct us not to sell their personal information. We do not sell it, but you may record your preference by emailing privacy@juno.so.
11. Changes to this policy
We may update this policy from time to time. Continuing to use the Service after a change takes effect means the updated policy applies.
12. How to contact us
- Privacy requests and questions: privacy@juno.so
- Support: support@juno.so
- Reports of harmful content or behaviour: moderation@juno.so
- Mail: Big Vision Ventures LLC, 151 Calle de San Francisco, Ste 200, San Juan, Puerto Rico 00901
This policy is adapted from a template prepared and made publicly available by General Legal, PC (general.legal). General Legal has not reviewed the adaptations made here and takes no position on them, and nothing in this document is legal advice from General Legal.