Privacy Policy
Effective date: April 4, 2026
1. Introduction
Endpaper Corporation ("Juni," "we," "us," or "our") operates the Juni AI assistant service and the website at meetjuni.com. This Privacy Policy describes how we collect, use, disclose, and protect information when you use our website, create an account, or use the Juni service (collectively, the "Service").
Juni is a cloud-based AI assistant designed for real estate professionals. Juni connects to your team's business tools — such as Slack, Google Workspace, and CRM systems — to automate workflows and assist with day-to-day operations. This Privacy Policy covers both visitors to our website and users of the Service.
2. Information We Collect
We collect only the information necessary to provide, maintain, and secure the Service.
Account Information
When you create an account or sign in via Google OAuth, we collect:
- Profile information. Your name, email address, and profile photo URL as provided by Google.
- Team information. Team name, timezone, and team role (admin or member).
- Session data. Session tokens and last sign-in timestamps for authentication and security.
We do not collect or store passwords. Authentication is handled entirely through Google OAuth 2.0.
Conversation and Agent Data
When you use the Service, we store:
- Chat messages. The full content of conversations between you and the AI assistant, including your messages, assistant responses, and system messages.
- File attachments. Images, PDFs, and other files you upload to conversations (up to 20 MB per file).
- Playbooks and triggers. Workflow descriptions, schedules, and execution history that you create to automate tasks.
- Activity logs. Timestamped summaries of actions the AI agent performs on your behalf.
- Tool call records. Records of tools the AI agent invoked during conversations, including tool names and parameters.
Configuration and Metadata
We store configuration and operational metadata necessary to run the Service, including:
- Team configuration. Custom agent instructions ("agent context") that your team provides to guide the AI assistant's behavior.
- Invitation records. Email addresses, invitation tokens, and expiration times for team invitations.
- Integration mappings. Internal records that link Slack channels and users to their corresponding Juni conversations and accounts.
- AI processing metadata. Token usage counts, model identifiers, and AI reasoning traces generated during conversations.
- Selected drives. Which Google Drive locations (My Drive and/or Shared Drives) you have selected for the Google integration.
Team Visibility
Juni is organized around teams. Some data is visible to other members of your team:
- Team-visible conversations. Chats may be marked as "team-visible," in which case other members of your team can view the conversation. Chats marked "private" are visible only to the owner.
- Shared playbooks. All team members can view playbooks created by any team member. Only the owner can modify their own playbooks.
- Shared integrations. When a team administrator connects Slack or Follow Up Boss, those integrations are available to all team members through Juni. Google integrations are private to the individual user who connects them.
- Team administrators may have visibility into team-level usage and configuration data.
If your personal information appears in data processed by Juni on behalf of a team (for example, your contact record in a connected CRM), please direct privacy requests to the team administrator who controls that data. We process such data as a service provider on behalf of the team.
Connected Platform Data
When you connect third-party platforms to Juni, we access and process data from those platforms as needed to provide the Service:
- Slack. When your team connects Slack, Juni requests the following access: messages in public channels where Juni is invited, messages in private channels where Juni is invited, direct messages sent to the Juni bot, thread replies, message reactions, the ability to join public channels, and user profile information including display names and email addresses. Juni also posts messages and responses in channels where it is active. We access Slack data only after your team grants permission through Slack's OAuth consent screen.
- Google (Drive, Docs, Sheets, Slides). Files, documents, spreadsheets, and presentations in your selected Google Drive locations (My Drive and/or Shared Drives). Juni can search, read, create, and update files within the scopes you authorize. We access Google data only after you individually grant permission through Google's OAuth consent screen.
- Follow Up Boss. Contact records, lead information, call logs, text messages, email events, and campaign data from your CRM. We access Follow Up Boss data using an API key provided by your team administrator.
Connection Credentials
We store the credentials necessary to maintain your integrations, including OAuth tokens for Slack and Google, and API keys for Follow Up Boss. All credentials are encrypted at rest.
Slack and Follow Up Boss integrations are team-scoped (available to all team members). Google integrations are user-scoped (private to the individual user who connects them).
Payment Information
If you subscribe to a paid plan, payment processing is handled by Stripe. We do not store credit card numbers, bank account details, or other sensitive financial information on our servers. Stripe may collect billing contact information and transaction metadata. Stripe's handling of your payment data is governed by Stripe's privacy policy.
Website Usage Data
When you visit meetjuni.com, we may collect:
- Log data. IP address, browser type, operating system, referring URL, pages visited, and timestamps.
- Device information. Device type and screen resolution to ensure the website displays correctly.
Communications
If you contact us (for example, via email or a support request), we collect the information you provide in those communications.
3. How We Use Information
To Provide and Operate the Service
- Authenticate users and maintain sessions
- Execute tasks, respond to requests, and generate outputs through the AI assistant
- Maintain integrations with connected platforms
- Run scheduled playbooks and triggers
- Deliver activity logs and conversation history
AI Processing
Relevant portions of your data (such as conversation content, playbook instructions, and data retrieved from connected platforms) are processed by AI systems to generate responses, reports, and other outputs at your direction. See Section 5 for details.
To Maintain Security and Integrity
- Detect and prevent fraud, abuse, and unauthorized access
- Investigate security incidents and maintain audit trails
- Rate-limit requests and block suspicious activity
Service Improvement
We may use aggregated or de-identified data (that cannot reasonably identify you) to understand usage patterns and improve reliability and product experience. We do not use your data for advertising.
Communications
- Send service-related communications (product updates, security notices, billing messages)
- Respond to support requests
- Send team invitations on behalf of administrators
Compliance
Comply with legal obligations, enforce our Terms of Use, and protect the rights, safety, and property of our users and Endpaper Corporation.
4. Legal Basis for Processing
If you are located in the European Economic Area (EEA), United Kingdom, or another jurisdiction that requires a legal basis for processing personal data, we rely on the following:
- Contract performance. Processing data as necessary to provide the Service you have requested.
- Legitimate interests. Improving the Service, ensuring security, and preventing fraud, where these interests are not overridden by your rights.
- Legal obligation. Complying with applicable laws and regulations.
- Consent. Where you have given specific consent for a particular use (for example, connecting a third-party integration via OAuth), which you may withdraw at any time.
5. Artificial Intelligence and Data Processing
We use AI models from third-party providers to power the Juni assistant. Here is how this works:
- AI providers. We currently use AI models from Google (Gemini), Anthropic (Claude), and OpenAI (GPT). The active provider may change over time. We will update this list if our providers change.
- What is sent. When you interact with the assistant, conversation content, playbook instructions, tool definitions, and data retrieved from connected platforms may be sent to AI providers for processing.
- No model training. We do not use your data to train AI models. Our AI providers are contractually prohibited from using data submitted through their commercial APIs to train or improve their models.
- Data processing agreements. We maintain data processing agreements with our AI providers that govern their handling of data.
- Provider changes. If we intend to use a new AI provider whose commercial terms do not include a prohibition on using customer data for model training, we will notify affected users in advance and obtain consent before transmitting data to that provider.
- Autonomous operations. Juni may execute tasks autonomously through scheduled playbooks and triggers. Depending on your configuration, some actions may execute without per-action human review. See Section 6 of the Terms of Use for details.
6. Google API Services User Data Policy
Juni's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- Juni limits its use of Google user data to providing or improving user-facing features that are prominent in Juni's user interface.
- Juni does not transfer Google user data to third parties unless (a) it is necessary to provide or improve user-facing features that are prominent in Juni's user interface and only with the user's affirmative consent (for example, when you direct Juni to process a Google document using AI, the document content is sent to our AI providers), (b) it is necessary for security purposes (such as investigating abuse), (c) it is necessary to comply with applicable laws or regulations, or (d) the data is aggregated and anonymized and used for internal operations in a manner that does not identify any individual user.
- Juni does not use Google user data for serving advertisements, including retargeting, personalized, or interest-based advertising.
- Juni does not allow humans to read Google user data unless the user has provided affirmative consent, it is necessary for security purposes, it is necessary to comply with applicable law, or the data has been aggregated and anonymized for internal operations.
- Juni does not use Google user data to train or improve AI models.
6a. Slack Data Use and Compliance
Juni accesses Slack data only after your team administrator grants permission through Slack's OAuth consent screen. Our commitments regarding Slack data:
- We use Slack data only to provide and operate the Service.
- We do not sell Slack data.
- We do not use Slack data for advertising.
- We affirm that Slack APIs are not used to develop, improve, or train generalized AI and/or ML models.
- We do not use Slack data to train our own or third-party foundation models.
You can uninstall Juni or revoke access at any time in Slack's App Management settings. After revocation, we stop collecting new Slack data immediately. Uninstalling or revoking access does not by itself delete previously stored data. To request deletion of previously stored Slack data, contact us at support@meetjuni.com or see Section 8 (Data Retention).
7. Information Sharing and Disclosure
We do not sell, rent, or trade personal information. We have not sold personal information in the preceding 12 months.
We share information only as necessary to provide and support the Service:
- AI providers. Google (Gemini), Anthropic (Claude), and OpenAI (GPT) for AI processing. Data is sent only as needed to generate responses at your direction.
- Cloud hosting. Railway for application hosting and infrastructure.
- Database and caching. PostgreSQL for data storage, Redis for caching and job queues.
- Email delivery. Postmark for transactional emails (invitations, notifications).
- Error tracking. Sentry for error monitoring and audit logging. Sensitive fields are automatically filtered before transmission.
- Payment processing. Stripe for billing and subscription management.
Each service provider is bound by agreements that require them to protect data and restrict their use of it to providing services to us.
We may also disclose information when required by law, subpoena, or court order, or when we reasonably believe disclosure is necessary to protect our rights, your safety, or the safety of others.
In the event of a merger, acquisition, restructuring, or sale of assets, information may be disclosed to advisors and successor entities subject to appropriate confidentiality protections.
8. Data Retention
- Account and conversation data. Retained for the duration of your active account. When an account is closed or we receive a verified deletion request, we delete data from production systems within 90 days.
- Backups. Encrypted backups are used only for business continuity. Backup copies are removed as they age out on their normal rotation schedule.
- Website log data. Retained for up to 90 days for operational and security purposes.
- Payment records. Retained as required for tax, accounting, and legal compliance obligations.
You can request deletion of your data at any time by contacting us at support@meetjuni.com. For team-level data, we may require the request to come from a team administrator.
9. Data Security
We use industry-standard security measures to protect information, including:
- Encryption in transit. All data transmitted between Juni, users, and third-party providers is encrypted using TLS. HTTP Strict Transport Security (HSTS) is enabled across all production systems.
- Encryption at rest. OAuth tokens, API keys, and other sensitive credentials are encrypted at rest using application-level encryption.
- Access control. Access to customer data is limited to authorized personnel on a need-to-know basis. All personnel with access are subject to confidentiality obligations.
- Application security. We use automated static security analysis, dependency vulnerability scanning, code review, rate limiting, Content Security Policy headers, and sensitive data filtering in logs.
- Authentication security. Google OAuth 2.0 with session token rotation, secure/httponly/same-site cookies, and protection against CSRF and session fixation.
While we take reasonable steps to protect information, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security. You are responsible for maintaining the security of your Google account and connected third-party accounts.
10. Your Rights
Depending on your location, you may have the following rights regarding your personal information:
- Access. Request a copy of the personal information we hold about you.
- Correction. Request that we correct inaccurate or incomplete information.
- Deletion. Request that we delete your personal information.
- Portability. Request your data in a structured, machine-readable format.
- Restriction. Request that we limit how we process your data.
- Objection. Object to processing based on legitimate interests.
- Withdrawal of consent. Where processing is based on consent, withdraw consent at any time.
To exercise any of these rights, contact us at support@meetjuni.com. We will respond to verified requests within 30 days (or 45 days if we need an extension, with notice to you).
You can also disconnect integrations at any time: revoke Juni's access to Slack via Slack's App Management settings, revoke Google access via your Google Account permissions, or remove your Follow Up Boss API key from Juni's settings. Disconnecting an integration stops new data collection from that source but does not by itself delete previously stored data. Contact us to request deletion of previously stored data.
11. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):
- Right to know. You may request the categories and specific pieces of personal information we have collected about you in the past 12 months.
- Right to delete. You may request deletion of your personal information, subject to certain exceptions.
- Right to correct. You may request correction of inaccurate personal information.
- Right to non-discrimination. We will not discriminate against you for exercising your privacy rights.
- Right to opt out of sale. We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising.
We honor Global Privacy Control (GPC) signals as a valid opt-out request. To submit a rights request, email support@meetjuni.com.
12. International Data Transfers
The Service is hosted in the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States. Where required for cross-border transfers, we use appropriate safeguards such as Standard Contractual Clauses.
13. Cookies and Tracking
The Service uses essential cookies required to maintain your session and authenticate your account. These cookies are strictly necessary for the Service to function. We do not currently use advertising cookies, analytics cookies, or third-party tracking cookies.
If we add analytics or other non-essential cookies in the future, we will update this section and provide appropriate notice and controls.
14. Children's Privacy
The Service is not intended for children under the age of 18. We do not knowingly collect personal information from children. If we learn that we have collected personal information from a child under 18, we will delete that information promptly. Contact support@meetjuni.com if you believe a child has provided personal information.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by posting a notice on the Service at least 30 days before the changes take effect. The "Effective date" at the top of this page indicates when this policy was last updated.
16. Contact Us
If you have questions about this Privacy Policy or wish to exercise your privacy rights, contact us at:
Endpaper Corporation720 Seneca Street Ste 107 #759
Seattle, WA 98101
Email: support@meetjuni.com
Please also review our Terms of Use.