Back

Privacy Policy

Last updated

Your health history is personal. Here is how Juno uses it, protects it and puts you in control.

Your data, in plain language

  • GDPR and UK GDPR: clear legal bases, consent for health data and rights to access, correct, export or delete your information.
  • HIPAA-grade security: encryption, account-scoped access controls and security monitoring.
  • No AI training: your health conversations, symptoms and documents are not used to train AI models.
  • Zero data retention: eligible AI-provider requests use ZDR arrangements. Juno still saves the history you need for ongoing support.
  • No sale of health data: we do not sell it or share it for advertising.
  • Your control: optional connections, access requests, exports and deletion, with the retention periods explained below.

Juno is your 24/7 personal health assistant. This policy explains what happens to the information you share, who processes it, how it is protected and how you can access or delete it.

Data controller: Sharedgenes, Inc., a Delaware corporation in the United States ("Sharedgenes", "we", "us" or "our"), is responsible for the personal data described here. Contact privacy@junocompanion.com for privacy requests or team@juno-chat.com for general support.

This policy sits alongside our Terms of Service, Consumer Health Data Privacy Policy, Cookie Policy and AI Safety & Crisis Protocol.

1. Information we collect

We collect the information needed for the features you use. Optional connections are not a condition of using the rest of Juno.

Account and profile

  • Your name, email address, authentication identifiers and account settings.
  • Age or age range, display name, avatar, language, accessibility preferences, onboarding answers and health goals.
  • Support messages and any referral, invitation, promotion or subscription information associated with your account.

Health information you choose to share

  • Symptoms, conditions, medications, supplements, allergies, mood, sleep, activity, pacing, cycle, hydration, notes and other wellness records.
  • Text conversations, voice transcripts, assistant replies, summaries and the memories or inferences Juno creates from your information.
  • Medical documents, photos, reports and appointment notes you upload.
  • Health data from Apple Health, Health Connect, wearables and other integrations you connect, such as heart rate, heart-rate variability, sleep and steps.
  • Calendar information you choose to connect and symptom history you import from another app.
  • Safety signals that help Juno show relevant crisis or urgent-care resources.

We ask for permission before accessing optional device or integration data. You can disconnect a source or revoke device permissions. Disconnecting stops future access; it does not automatically delete records already imported into your Juno account. You can request deletion of those records separately.

Voice, device and location information

  • Live voice: audio is processed to run the conversation. Juno does not retain raw live-call audio after processing; voice transcripts can be saved to your chat history. An audio file you deliberately upload is an attachment and is covered by the account-data retention rules.
  • Device and operation: device type, operating system, app version, language, timezone, network state, notification permissions, pseudonymous identifiers and technical events.
  • Location context: a country, region, city or timezone you share or permit us to use can help with local resources, reminders and relevant environmental context. We do not require continuous location tracking to use Juno.

Website visits

Our website host, Vercel, processes server logs, including IP addresses, to deliver and secure the website. Supabase processes password-reset tokens on the password-reset page. See our Cookie Policy for website storage and cookies.

2. How we use your information

  • Provide Juno: generate responses, record symptoms, run voice calls, create reminders and prepare summaries or reports you request.
  • Remember context: use your relevant conversation history, preferences, health records and saved memories so you do not have to repeat yourself.
  • Understand changes: help you explore patterns in the records and connected data you choose to share.
  • Operate your account: manage authentication, subscriptions, purchases, integrations, notifications and support.
  • Keep the service reliable: diagnose errors, measure performance, prevent fraud and respond to security issues.
  • Improve the service: use limited product metrics and aggregated or de-identified insights. This is separate from training AI models on your health information.

Juno can surface crisis resources, but it is not an emergency-monitoring service and cannot guarantee it will detect a crisis or contact anyone on your behalf. If you are in crisis in the US, call or text 988; in an emergency, call 911 or your local emergency number.

Health information is sensitive data. We process your health information only with your consent, which we ask for when you create your account and before each optional data source (such as HealthKit, Health Connect, calendar, or document upload) is connected. We will ask again before any materially new purpose. You can withdraw your consent at any time in Settings or by contacting us; after withdrawal we stop the related processing within 15 days.

Reproductive and sexual health information. You may choose to share reproductive or sexual health information with Juno. We collect it only with your consent, we never sell or disclose it for marketing, and you can withdraw consent or delete it at any time.

For users we know are 16–17, we process personal data only as strictly necessary to provide Juno, and we exclude their data from research and product-improvement analytics unless they separately consent. Quebec and Brazil residents: we obtain express consent for the collection and use of sensitive personal information as required by Law 25 and the LGPD.

Sharing is your choice

Health connections, calendar access and uploads are optional. Reports are shared with a clinician or another recipient only when you choose to share them. Information you post to a community, send to another person or export outside Juno is visible to the recipients you select and may be retained under their own rules.

4. GDPR and UK GDPR

We comply with the GDPR and UK GDPR when processing personal data subject to those laws. This means explaining our purposes, using a lawful basis, limiting collection, protecting sensitive health information and enabling your data rights.

We use an Article 6 lawful basis for personal data and an additional Article 9 condition for health data. A contract or legitimate interest alone does not authorise us to process your health information.

  • Consent — Articles 6(1)(a) and 9(2)(a): explicit consent for health and wellness information, and consent for optional processing where required. You can withdraw it at any time; this does not affect processing that was lawful before withdrawal.
  • Contract — Article 6(1)(b): creating your account, managing subscriptions and providing the service you request.
  • Legitimate interests — Article 6(1)(f): proportionate security, fraud prevention and technical diagnostics, after considering your rights and expectations. This is not a substitute for explicit consent to process health data.
  • Legal obligation — Article 6(1)(c): records or disclosures that the law requires.

You can access, correct, export or request deletion of your data, restrict processing, object where applicable, withdraw consent and complain to a regulator. See Your rights for the request process and response times, and International transfers for the safeguards used when data leaves the EEA or UK.

5. Analytics and diagnostics

We use limited operational, product, attribution and subscription information to understand whether features work, diagnose problems and measure use. This is different from using the content of your health conversations for advertising.

What technical events can contain

  • App version, platform, broad locale, screen or feature identifiers and pseudonymous user or session identifiers.
  • Loading times, request status, error categories, whether an action completed and notification or integration outcomes.
  • Subscription, trial, purchase and cancellation events.
  • AI service measurements such as response time, model used, token counts, cost and tool success or failure.

How sensitive content is limited

Our analytics filters exclude free-text health conversations, voice transcripts, symptom notes, medication names, uploaded document content, passwords and authentication tokens from analytics event properties. Pseudonymous identifiers can still relate to your account; pseudonymous data is not the same as anonymous data.

Where session replay is enabled, sensitive screens and fields are excluded or masked. Session replay is not enabled for every build or platform. Diagnostic access is limited to authorised purposes such as reliability, security and support.

Depending on the feature, build and region, app providers can include PostHog, Sentry, AppsFlyer, Appstack, Mixpanel, Superwall and RevenueCat. AI operational diagnostics may use Convoy/Superlog. The website does not set analytics or advertising trackers. See Service providers and the Cookie Policy.

6. HIPAA-grade security

We protect your health information with HIPAA-grade security safeguards. That means concrete protections for stored data, data in transit and access to your account:

  • Encryption in transit: encrypted connections using TLS 1.2 or later protect information travelling between your device, Juno and our service providers.
  • Encryption at rest: AES-256 encryption protects stored data in our core infrastructure.
  • Account and access controls: authentication, authorisation and account-scoped access rules restrict who can read or change your records.
  • Limited operational access: access is restricted to authorised people and services for necessary support, security and service operation.
  • Security monitoring: logging, technical diagnostics, security reviews and incident-response processes help identify and address problems.
  • Data minimisation: we limit what each service receives to what is needed for its role and filter sensitive material from analytics.
  • Deletion and export controls: you can request an export or deletion of the information linked to your account.

Encryption protects data while stored or transmitted. Juno and the providers needed to run a feature must still process the relevant content to respond to you; this is not end-to-end encryption that prevents those services from accessing it.

What “HIPAA-grade” means

“HIPAA-grade” describes our security safeguards. Whether HIPAA legally applies depends on the service and relationship, including whether Juno is acting as a business associate for a covered healthcare provider. The phrase is not a government certification and does not make every consumer account a HIPAA-covered service. Your privacy protections and rights in this policy apply regardless.

Security incidents and notification

If an incident affects your information, we investigate, take steps to contain it and notify you and the relevant authorities as required by applicable law. Under the GDPR, a notifiable personal-data breach must be reported to the supervisory authority without undue delay and, where feasible, within 72 hours of awareness; affected people must be informed without undue delay where the breach is likely to create a high risk to their rights and freedoms.

Where the FTC Health Breach Notification Rule applies, we notify affected people and the FTC without unreasonable delay and no later than 60 days after discovery, as required by 16 CFR Part 318. Applicable HIPAA and state breach-notification rules, including New York requirements, may impose additional obligations. No online service can promise that a security incident will never occur.

7. AI processing and zero data retention

Juno sends relevant information to AI services to produce a response, understand an attachment or run a voice conversation. That can include your current message, relevant previous messages, saved memories, health records and the documents you ask Juno to consider. Live voice requires audio processing; a text transcript and assistant responses can become part of your Juno history.

Your health data is not used to train AI models

We do not use your conversations, symptoms, medical documents or other health information to train AI models. We use provider agreements and service settings that prohibit training foundation models on the identifiable Juno data they process for us. Processing information to answer your question is different from using it to train a model.

Zero Data Retention (ZDR)

Juno uses zero data retention arrangements for eligible AI processing. For requests covered by those arrangements, the AI provider does not retain the request and response content in its routine provider logs after processing. ZDR coverage depends on the provider, the feature and the endpoint used; specific legal or safety exceptions can still apply.

ZDR is a control on the covered AI provider’s retention. It does not mean your information is never processed, and it is not a blanket zero-retention promise for every service in Juno. File storage, saved account history, memory, backups, billing and limited technical diagnostics are separate processing activities.

What Juno still saves

Juno stores the history and health records needed to give you continuity: conversations, voice transcripts, symptoms, attachments, summaries and saved memories associated with your account. A provider’s ZDR setting does not delete those records from Juno. You control them through the export and deletion options described in Retention and deletion.

You can ask privacy@junocompanion.com which providers and features process your data, which are covered by ZDR, and what exceptions or separate retention periods apply to your use of Juno.

8. Retention and deletion

Different records have different retention periods. We keep the data needed to run your account separately from temporary processing by AI providers.

What is kept, and for how long
DataRetention
Account, health records, conversations, voice transcripts, memories and uploadsKept while your account is active. Deleted or de-identified from live systems without undue delay and within 30 days of account deletion, subject to the limited exceptions below.
Raw live-call audioProcessed for the live conversation and not retained by Juno after processing. Saved transcripts are separate account records. Audio attachments you upload follow the account-data rule.
Requests covered by AI-provider ZDRNo routine retention of request or response content by the covered provider after processing, subject to its eligibility rules and applicable exceptions.
Encrypted backupsPurged on a rolling 35-day cycle. A record removed from live systems may remain in a protected backup until that backup expires.
Crash logs90 days.
Billing and accounting recordsOur payment processors may retain required records for up to seven years for tax and accounting obligations.
Aggregated, de-identified informationMay be retained after it no longer identifies you. We do not try to re-identify it.

How to export or delete your data

Use the account privacy controls in the app or email privacy@junocompanion.com. You can request a copy of your records, correct information, delete particular content or delete your account. We verify the request to protect you against someone else accessing or deleting your data.

Account deletion includes Juno’s stored account content, associated files and memory records. Where a processor holds relevant personal data on our behalf, we request deletion or apply its retention process. Uninstalling the app does not delete your account. Disconnecting an integration stops future collection but does not remove copies that the original provider already holds.

Limited exceptions: we may retain specific records where needed for legal obligations, security, fraud prevention, resolving a dispute or billing. Access remains restricted and the records are not reused for unrelated purposes. Records you shared with a clinician, posted publicly or exported to another service are controlled by those recipients after sharing.

9. Sharing and service providers

We never sell your health data, share it for advertising or sell personal data to data brokers. Running Juno does require processing by service providers. They receive information for the role they perform; not every provider receives every conversation.

Providers used by Juno’s features
Provider or categoryRole and relevant information
OpenAI and AnthropicAI responses and, where enabled, real-time AI services. Relevant messages, health context, history and attachments may be processed to perform your request. See the AI and ZDR section of our Privacy Policy.
LiveKit, Deepgram and ElevenLabsWhere used by the voice feature, audio transport, speech recognition or speech generation. This can involve live audio, text to be spoken and technical call metadata.
Supabase, hosted on AWSAuthentication, databases, backend functions and file storage for account information, health records, conversations and uploaded content.
mem0 and ZepWhere used, memory and conversation context that help Juno maintain continuity, including relevant messages, preferences and facts associated with your account.
Connected health and calendar services, including TerraOptional connections to wearables, health platforms and calendars. They process the measurements or records you authorise for the connection.
RevenueCat, Superwall, Apple and GoogleSubscriptions, purchases, entitlement checks, trials and billing events. Apple and Google process payments under their own terms and privacy policies.
PostHog, Sentry, AppsFlyer, Appstack and MixpanelDepending on the build and region, limited analytics, attribution, technical diagnostics and crash reporting. See the content-filtering and masking rules in our Privacy Policy.
Convoy / SuperlogOperational AI diagnostics, such as service timing, failures, request identifiers and limited technical metadata, with controls to minimise sensitive content.
Expo, Apple and Google notification servicesApp delivery, updates and notifications, including device or push identifiers and the information needed to deliver an update or notification.
VercelWebsite hosting and media delivery, including server logs and information needed to deliver the pages or files you request.

The active providers depend on the feature, app build and region. Providers processing personal data on our behalf are restricted to authorised service purposes under the applicable agreements. Contact privacy@junocompanion.com for information about the processors relevant to your account.

Sharing you request

You choose whether to share a report, export information, connect a service or post in a community. Review what is included and who will receive it. A connected service or recipient may also act as an independent controller under its own privacy policy.

Legal and safety disclosures

We may disclose information where the law requires it or permits a necessary and proportionate response to a serious safety or security issue. Juno’s automated safety responses show resources to you; any disclosure to emergency services would happen only after human review or when required by law. You can request human review and contest a decision affecting you. Juno is not an emergency-monitoring service.

California and Texas health information

Because Juno lets you manage health information, Sharedgenes is treated as a provider of health care under California’s Confidentiality of Medical Information Act (CMIA, Civil Code §56.06). We maintain the confidentiality of medical information and do not disclose it without your authorisation except as the CMIA permits.

We handle Texas residents’ health information subject to the Texas Medical Records Privacy Act (HB 300). We do not sell health information or use it for marketing without consent. See the electronic-disclosure notice and additional state rights in our Consumer Health Data Privacy Policy.

10. Your privacy rights

Wherever you live, you can exercise your rights by emailing privacy@junocompanion.com (or team@juno-chat.com) or using Settings > Privacy in the app. We verify requests using your account credentials, respond free of charge (at least twice per year), and never discriminate against you for exercising a right. If we need to verify your identity or ask you to clarify your request, the response period may pause until you reply.

EEA & UK (GDPR / UK GDPR)

  • Access your data (Art. 15) and receive a copy
  • Rectify inaccurate data (Art. 16)
  • Erasure ("right to be forgotten", Art. 17)
  • Restrict processing (Art. 18)
  • Data portability in a machine-readable format (Art. 20)
  • Withdraw consent at any time (Art. 7(3))
  • Not be subject to solely automated decisions with legal or similarly significant effects (Art. 22)

Right to object (Art. 21). You may object at any time to processing based on our legitimate interests. We will stop unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.

We respond within one month. You may lodge a complaint with your supervisory authority (see the EDPB members list). UK users may complain to the Information Commissioner's Office (ico.org.uk/make-a-complaint, 0303 123 1113). You may also complain directly to us (see "Complaints" below).

United States state privacy rights

Residents of California, Colorado, Connecticut, Delaware, Kentucky, Maryland, Minnesota, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Texas, Virginia, and other states with comprehensive privacy laws have the right to:

  • Confirm whether we process your personal data and access it
  • Correct inaccuracies
  • Delete your personal data
  • Obtain a portable copy
  • Opt out of targeted advertising, sale, and profiling in furtherance of decisions with legal or similarly significant effects — we do none of these, and we do not sell personal data
  • Obtain a list of the categories of third parties to which personal data has been disclosed (Delaware, Minnesota, Oregon; see Section 9 — we have sold personal data to no one)
  • Question the result of profiling and learn the reason (Minnesota) — we do not profile you in furtherance of such decisions
  • Withdraw consent for sensitive-data processing at any time

We respond within 45 days (extendable once by 45 days when reasonably necessary; we will tell you if so). Requests are free at least twice in any 12-month period. Appeal: if we decline a request, reply with the subject line "Privacy Appeal" and we will issue a written appeal decision within 60 days. If we deny your appeal, you may contact your state Attorney General (for example Connecticut: portal.ct.gov/ag). Washington and Nevada consumer health data rights and appeals are described in our Consumer Health Data Privacy Policy.

We do not sell personal data, do not process it for targeted advertising, and do not use your personal data to train large language models.

Complaints

You can complain about our data handling by emailing privacy@junocompanion.com with the subject "Complaint" — this is our electronic complaints route, maintained in line with the UK Data (Use and Access) Act 2025. We acknowledge complaints within 30 days of receipt, investigate, and tell you the outcome without undue delay, in plain language. UK users: if you are dissatisfied with our response — or at any time — you can escalate your complaint to the Information Commissioner's Office (ico.org.uk/make-a-complaint, 0303 123 1113).

11. International transfers

Our servers are located in the United States. If you use Juno from outside the US, your personal data is transferred to, stored, and processed in the United States, where it may be accessible to US courts, law enforcement, and national-security authorities under US law.

For EEA users, transfers rely on the EU-U.S. Data Privacy Framework where our subprocessors are certified, and otherwise on Standard Contractual Clauses. For UK users, transfers rely on the UK-US Data Bridge (the UK Extension to the DPF) where available, and otherwise on the UK International Data Transfer Agreement or Addendum. You can request a copy of the relevant safeguards at privacy@junocompanion.com.

Quebec residents: your personal information may be communicated outside Quebec (to the United States); we have assessed these transfers as required by Quebec law (Law 25).

12. Children and teens

Juno is not intended for anyone under 16, and we do not knowingly collect data from anyone under 16. We ask your age at signup. Because our minimum age is 16, users in the EEA and UK meet every applicable age of digital consent. If we discover we have collected data from a child below the applicable age, we delete it promptly.

For users aged 16–17 (where permitted with parental agreement): we apply data minimization, never sell their data or use it for targeted advertising, exclude it from research and product-improvement analytics absent separate consent, and show AI-status and take-a-break reminders. Parents and guardians can contact us to access or delete their teen's data (with identity verification) at privacy@junocompanion.com.

13. Australia

We handle personal information in accordance with the Australian Privacy Principles. Your data is disclosed to service providers in the United States (Section 11). You can request access to or correction of your personal information through our Privacy Officer (Section 14); we respond within 30 days. If you are unhappy with our handling of a complaint, you may contact the Office of the Australian Information Commissioner (oaic.gov.au).

14. Privacy officer and accountability

Sharedgenes has designated a Privacy Officer (Responsable de la protection des renseignements personnels for Quebec) accountable for our handling of personal information. Reach the Privacy Officer at privacy@junocompanion.com. We verify your identity, respond within 30 days, and if you are dissatisfied you may complain to your regulator: OPC (Canada), CAI (Quebec), OAIC (Australia), or ANPD (Brazil).

15. Medical disclaimer

Juno is an AI health assistant designed for general wellness support. It is NOT a medical device or a medical professional, and it does not provide medical advice, diagnosis, or treatment. Always consult qualified healthcare providers for medical advice. If you are in crisis, call or text 988; in an emergency, call 911.

16. Changes to this policy

We may update this Privacy Policy from time to time and will show the date of the latest revision at the top of this page. We will notify you of any significant changes before they take effect.

17. Contact us

For a privacy question, an export, correction or deletion request, contact privacy@junocompanion.com. For general support, email team@juno-chat.com.

Sharedgenes, Inc.
Data controller and operator of Juno
United States

We aim to acknowledge general enquiries within 48 hours. Formal privacy requests and complaints follow the response periods in Your privacy rights.