Skip to content
juru

How Juru handles your money

Last updated 3 October 2026

Juru reads your money so it can be useful to you, and that’s the whole relationship. You pay for Juru, so you’re the customer, not the product. Here is what that means in practice, including the parts that aren’t perfect yet.

What Juru will never do

Where your data lives

Your data is stored in Sydney, and the app runs there too. A few services handle specific jobs, and some of them are overseas. This is all of them:

WhatWhoWhere
Your accounts, transactions, goals and messagesSupabase (database and sign-in)Sydney, Australia
The app itselfVercel (hosting and server functions)Sydney, Australia
Questions you ask, PDFs you upload, check-in wordingAnthropic (language model)United States
Quick judgments: a likely category, a possible transfer, what a question needsTypeSafe[confirm region]
Payments and card detailsStripeGlobal (card details never reach Juru)
WhatsApp check-ins, if you turn them onMeta (WhatsApp Business Platform)Global
Exchange ratesEuropean Central Bank reference rates, via FrankfurterNo personal data is sent

Pages may be delivered through Vercel’s worldwide network so they load quickly, but the work on your data happens in Sydney. The full list, with what each service receives, is in the privacy policy.

The honest caveat: language models

Some features use a language model made by Anthropic, and it runs outside Australia, mostly in the United States. When you use one of these features, the transactions it needs are sent there to do the job:

Anthropic’s commercial terms say it doesn’t train its models on this data, and it deletes it after a limited period [confirm current retention period before publishing].

Juru also uses TypeSafe for small, quick judgments: which of your own categories an unfiled transaction probably belongs in, whether an unclear transaction looks like a transfer between your own accounts, and which figures a chat question needs. For these it receives transaction descriptions, merchants, an amount range (never the exact amount), your category and account names, and the text of a chat question. These judgments only ever suggest: anything Juru isn’t sure about, it asks you.

If you’d rather none of this left Australia, you can still use most of Juru: upload CSVs rather than PDFs, and skip chat. Your glance, goals and transactions are calculated in Sydney by code.

Bank feeds are read-only, and their keys are sealed

Where Juru connects to a bank feed (Up in Australia, Akahu in New Zealand), you give it a read-only token. Juru checks it once with the bank, then encrypts it (AES-256-GCM, with a separate key for each token) before storing it. It’s never shown again, not to you and not to Juru’s chat, and only the code that syncs your transactions can open it. Disconnect a feed and its token is destroyed. Transactions already imported stay unless you delete them.

It’s yours: export or delete everything

In Settings you can download everything Juru holds about you as one file: accounts, transactions, goals, rules, messages and settings. Bank tokens appear only as “[sealed]”.

You can also delete everything. It happens straight away, cancels any membership first so nothing more is charged, and removes every row Juru holds about you. Database backups roll off within [backup retention period — confirm in Supabase]. Two things to know: Stripe keeps the payment records the law requires it to, and your sign-in record (your email address) is removed when you ask us at hello@askjuru.com.

What Juru measures about how it’s used

To know whether Juru is working, it records a short, fixed list of events in its own database. Nothing goes to an outside analytics company, there’s no session recording, and no event can carry an amount, a merchant or a description. This is the whole list:

EventWhat it records
loginyou signed in, and how (link or code)
csv_stageda statement was read: row and duplicate counts, CSV or PDF
import_committedrows were added: counts only
first_glance_viewedyou saw your first glance, and whether it had data
goal_createda goal was set: its shape and check-in cadence, never its words or amount
chat_message_senta message was sent, and from where (web or WhatsApp)
export_clickedyou downloaded your data

Juru also counts how much each language model call costs to run (tokens and price), never what was said.

Keeping it safe

Found a security problem? Please write to hello@askjuru.com. We’ll reply within two working days, and we won’t take action against good-faith research.

Why we’re telling you this

Anyone can say they take privacy seriously. What matters is whether the product is built so the promises hold. If we can’t back a sentence on this page, we take the sentence down. Questions: hello@askjuru.com.