Privacy
What JuniFi holds, and what it will never do with it.
JuniFi asks for read access to your money. This page is the plain-language account of what that means — written during the beta, before there is anything to gain by being vague.
Draft — effective date to be determined
JuniFi is in private beta and this document is a plain-language placeholder, not a finished legal agreement. It has not been reviewed by counsel and it carries no effective date. It is published now because you deserve to know how the product behaves before you hand it anything — and it will be replaced by a reviewed version, with a real effective date, before JuniFi is generally available or charges anyone.
JuniFi is a financial tool for people who work for themselves: founders, freelancers, contractors and creators — people whose company and household draw on overlapping accounts. To do that it has to read genuinely sensitive information: balances, transactions, declared obligations and whatever your business system knows about your revenue.
The short version is that JuniFi holds that data to show it back to you and to answer your questions about it, keeps it on its own server in the United States, shares it with a handful of named providers that make the product work, and does not sell, broker or advertise against it. The detail is below, and the technical controls behind it are described on the security page.
1.Who is responsible for your data
Junious Digital Laboratories LLC, trading as Junious Digital Labs, of Spokane, Washington, United States, operates JuniFi and is the party responsible for the personal and financial data it holds. There is no parent company, no investor with access, and no affiliate that your data is shared into.
2.What JuniFi collects
Only what the product needs to do its job. Grouped by why it exists rather than by technical category:
- Account identity — your email address, a hash of your password, and the timestamps of sign-in activity.
- Financial connections — the institutions you link through Plaid and an encrypted access token for each, never a bank username or password.
- Financial records — accounts, balances, transactions, the entity and scope assigned to each, the obligations you declare, budgets, goals and detected recurring charges.
- Business-system records — whatever the connector you configure is scoped to read, such as invoices, bills and revenue from Odoo.
- Things you tell the CFO — the facts it stores in memory, and your conversation history with it.
- Operational logs — errors and request records needed to keep the service working and to investigate problems.
- Early-access requests — if you used the form on this site, your email address and the optional sentence about what you run.
3.What JuniFi does not collect
There is no advertising or analytics tracker on the application, no third-party session recorder, and no cross-site advertising identifier. JuniFi does not ask for a government identification number, a date of birth, or a credit report, because it does none of the things that would require them.
4.Why JuniFi holds it
To show you your own money, hold the business and the owner apart, reconcile the obligations you declared against the ledger, age your receivables, produce forecasts and reports, answer the questions you ask the CFO, keep your account secure, and meet the record-keeping obligations that fall on a United States company.
Your financial data is never used for advertising, never sold, never brokered, and never pooled with another user’s for any purpose.
5.Who it is shared with
A short and nameable list of service providers, each limited to what its function requires:
- Plaid Inc. — bank and card connectivity. Your institution credentials are handled by Plaid, not by JuniFi.
- Anthropic PBC — the Claude model behind the CFO. The figures a given question needs are sent in order to answer it.
- The hosting provider for the United States server JuniFi runs on.
- The business system you choose to connect, which JuniFi reads with the credentials you supply.
- Legal disclosure, if a valid legal process requires it — and you will be told unless the law forbids telling you.
6.Where it is stored, and for how long
Financial records are stored in a PostgreSQL database on a server in the United States, reached only over TLS. Plaid access tokens are encrypted at rest. Passwords are stored only as PBKDF2-HMAC-SHA256 hashes and cannot be recovered or read by anyone, including us.
Data is kept for as long as your account exists, because a cash forecast is only as good as the history behind it. When you delete your account the stored financial data is removed and the Plaid connections behind it are revoked. Routine backups and the minimum records a company must keep may persist for a short, bounded period after that.
7.Your choices
You can export everything JuniFi holds about your money as CSV and JSON at any time. You can disconnect an institution, which removes its stored token. You can correct or delete any fact in the CFO’s memory, including rolling it back to an earlier version. You can ask for your account and its data to be deleted — today that request goes to the email address below and is handled by a person; a self-service control is on the roadmap and is listed as not yet built on the security page.
Depending on where you live you may have additional statutory rights over your data, including rights of access, correction, deletion and portability. JuniFi intends to honour such requests regardless of where you live; the reviewed version of this document will set out the formal process.
8.Cookies
JuniFi sets one cookie that matters: a signed, HttpOnly session cookie that keeps you logged in. It is strictly necessary for the service to function, which is why this site has no cookie consent banner — there is no advertising or analytics cookie to consent to.
9.Children
JuniFi is a business tool for adults and is not directed at anyone under eighteen. Accounts are not knowingly opened for minors, and an account found to belong to one will be closed and its data deleted.
10.Changes to this document
This is a beta-period draft. It will be replaced by a reviewed version carrying a real effective date before JuniFi is generally available or charges anyone. Material changes will be sent to the email address on your account rather than published quietly.
Questions about this document
Anything unclear here is a defect in the writing, not something you should have to guess at. Write to joshj@juniouslabs.digital and a person will answer.