Privacy Policy
Effective July 25, 2026 · Contact: hello@junie.app
Read this first if HIPAA applies to you
Junie does not currently offer a Business Associate Agreement (BAA). If you are a HIPAA covered entity or business associate, do not use Junie to create, receive, maintain, or transmit protected health information on your behalf. The U.S. Department of Health and Human Services explains when HIPAA requires a business associate contract. Ask a qualified advisor if you are unsure whether HIPAA applies to your practice.
Who we are and who this policy covers
Verios LLC, a Delaware limited liability company doing business as Junie ("Junie," "we," or "us"), operates https://junie.app, https://my.junie.app, and related email and support services. This policy covers:
- people who visit our website;
- people who join a waitlist, download a resource, or receive Junie email;
- doulas, birth workers, and other people who create or use a Junie account; and
- people whose information an account holder puts in Junie, including their clients.
In this policy, Client Records means information about or provided by an account holder's client. Client Records may include personal information that belongs to or concerns that client. Junie does not claim that an account holder owns a client's personal information.
Our role
Junie decides how to use website, waitlist, account, billing, and support information for the purposes described here. Account holders decide which Client Records to enter and how to use them in their practices. We process those records to operate Junie, follow the account holder's instructions, protect the service, and meet legal obligations. An account holder is responsible for the notices, permissions, and lawful basis required for the Client Records they put in Junie.
Information we collect
| Context | Information |
|---|---|
| Website visits | IP address, browser and device details, page URL, referring page, campaign parameters, approximate location derived from IP, and analytics or advertising identifiers stored in cookies or local storage |
| Waitlists and resources | Email address, the page or source connected to the signup, email delivery and interaction records, and unsubscribe status |
| Junie accounts | Name, email, sign-in information, business profile, settings, subscription and Stripe customer identifiers, session IP address and user agent, product activity, support messages, and error or diagnostic data |
| Client Records | Contact details, inquiries and messages, estimated due date, service interests, birth date, appointments, private notes, contracts and signatures, payment schedules and status, superbills, and information entered in free-text fields |
| Payments | Amount, status, installments, refunds, Stripe account and transaction identifiers, and limited payment-method details such as card versus bank payment. Stripe, not Junie, collects full card and bank-account numbers. |
| AI features | The content sent to the feature, generated drafts, review decisions, model name, and usage information |
How we use information
- operate accounts, client workflows, documents, schedules, email, and payments;
- authenticate users and protect accounts, Client Records, and the service;
- provide support and communicate about service or policy changes;
- bill for Junie subscriptions and maintain transaction records;
- measure website and product use, including advertising attribution;
- generate and review AI-assisted drafts when an account holder uses an AI feature;
- debug failures, prevent fraud or abuse, and respond to security incidents; and
- comply with law and enforce our agreements.
Website analytics, cookies, and advertising measurement
The Junie app uses essential cookies for sign-in and security. The marketing website also uses the following optional tools when they are configured and the visitor chooses the relevant use. Neither optional tool loads before that choice:
- PostHog records page views, referring and campaign information, and events such as a waitlist signup. Autocapture is off. PostHog stores an identifier in local storage and a cookie.
- OpenAI Ads measures whether a visit, waitlist signup, or account signup followed an OpenAI ad. Its browser pixel can read OpenAI ad-attribution information. For an account signup, Junie also sends OpenAI a SHA-256 hash of the normalized email address so OpenAI can match and deduplicate the conversion. When the server-side conversion is configured, the current signup code sends that event without reading the marketing site's advertising choice.
These tools are not configured to send Client Records. Activity on a marketing page may still reveal an interest in pregnancy, doula services, Medicaid, reimbursement, or other health-related topics when it is linked to a browser or advertising identifier. Our Consumer Health Data Privacy Policy explains that data flow. Analytics collection and advertising measurement on the marketing site have separate opt-in controls. A visitor can withdraw either choice through “Privacy choices” in the footer. That choice is not currently shared with the Junie app or its server-side account-signup conversion. Until Junie adds one consent flow across both sites, the server-side conversion should not be enabled where prior opt-in is required. Browser settings and privacy extensions can also block nonessential storage or scripts, though essential app cookies are required to sign in. We do not sell Client Records or consumer health data.
AI features
Junie's AI integrations support the Anthropic and OpenAI commercial APIs for assisted setup, drafting, import mapping, tone adjustment, and safety checks. The configured provider receives the instructions and context for the requested task. For an inquiry reply, that context can include the family's inquiry text, which may contain whatever the writer chose to share. Do not use an AI workflow for content you are not authorized to send to the configured provider.
Junie does not use account or Client Records to train its own models. Anthropic and OpenAI each state that commercial API inputs and outputs are not used for model training by default. Under standard settings, either provider may retain inputs and outputs for up to 30 days, subject to stated exceptions. See Anthropic's commercial retention explanation and OpenAI's current API data controls. Junie does not represent that either integration has Zero Data Retention or a HIPAA BAA.
Service providers and other disclosures
These providers receive information for the purposes shown:
| Provider | Purpose and information |
|---|---|
| Cloud hosting, database, backups, operational telemetry, business email, and optional Google sign-in. Depending on the service, Google may process account information, Client Records, support email, and technical data. | |
| Stripe | Junie subscriptions, connected-account onboarding, client payments, refunds, and disputes. Stripe receives account, contact, transaction, and payment-method data under Stripe's Privacy Policy. |
| Postmark | Account, transactional, marketing, and inbound email. Postmark receives email addresses, message content, and delivery records. |
| PostHog | Website and product analytics. PostHog receives website visit data, identifiers, and account-level product events. Junie does not intentionally send Client Records to PostHog. |
| Anthropic and OpenAI | AI processing through the configured commercial API, as described above. Anthropic or OpenAI may receive prompt and output content. OpenAI may separately receive ad-attribution data and a hashed account-signup email when OpenAI Ads measurement is configured. The current server-side signup conversion does not read the marketing-site advertising choice. |
| Sentry | Error monitoring when configured. Sentry may receive error, request, browser, device, and diagnostic information. Junie does not intentionally send Client Records to Sentry. |
We may also disclose information to professional advisors under confidentiality obligations; when required by law or legal process; to investigate fraud, abuse, or a security incident; or in a merger, financing, acquisition, bankruptcy, or sale of assets. A successor would take on the obligations in this policy for transferred personal information.
Security
Junie uses HTTPS for browser connections, database-level tenant isolation, restricted production access, field encryption for private client notes and optional birth notes, and hashed, expiring client-access links. Daily database backups retain the 14 most recent copies. No security measure eliminates all risk. Our Security & privacy page separates implemented controls from work that is still planned.
Cancellation, export, account deletion, and backups
- Canceling a paid subscription does not delete the account. It stops the subscription renewal according to the billing settings shown in Stripe. Account and Client Records remain until the account holder deletes them or asks us to do so.
- Export is available while the account exists. The in-app export is a ZIP containing CSV files for clients, leads, engagements, payments, installments, hour entries, messages, agent activity, and calendar events, plus HTML copies of executed contracts and generated receipts. It does not currently include private notes, birth-event details, packages, templates, setup artifacts, or imported source files. Download and check it before deleting the account.
- Do not rely on the in-app deletion control yet. The control exists, but Junie has not verified that it works with the permissions used in production. Until that work is complete, cancel any paid subscription and email hello@junie.app with an account-deletion request. We will verify and process the request, subject to records that may be kept separately for security, email suppression, payment, dispute, tax, or legal purposes.
- Backups are separate from production. Junie keeps 14 daily database backup copies for disaster recovery. Deleted production records can remain in a fixed backup until the copy ages out. We handle verified consumer-health-data deletion requests from backups within the deadlines required by applicable law.
Waitlist and marketing records remain until you unsubscribe, ask us to delete them, or we no longer need them for the stated purpose. We may retain a suppression record so we do not email an address that opted out. Provider, security, transaction, and legal records follow the provider's retention rules and any legal requirements that apply.
Your choices and privacy requests
Account holders can correct account information and export the listed account data in the app. Anyone can request access, correction, deletion, or a copy of personal information by emailing hello@junie.app. We may ask for information needed to verify the request and protect the person whose information is involved.
If you are an account holder's client, you can ask that account holder because they know the context of the record. You may also contact Junie directly; you do not need to create an account. We will coordinate with the account holder where appropriate and respond within the time required by applicable law. To appeal a denied request, reply to the decision or email hello@junie.app with "Privacy appeal" in the subject. We will not discriminate against you for making a privacy request.
Children's information
Junie accounts are for adults age 18 or older. Client Records may include information about a newborn or another child when an adult account holder or client provides it for the account holder's services. We process that information for the same limited purposes described in this policy.
Changes and contact
We will update the effective date when this policy changes. If a material change affects how we use account or Client Records, we will also notify account holders through the service or by email when required. Privacy questions and requests can be sent to hello@junie.app.