What Juru will never do
- Sell or share your financial data. Not with advertisers, data brokers or “partners”. There are no ads in Juru, and there never will be.
- Move your money. Juru reads statements you upload and, if you connect one, a read-only bank feed. It can’t make a payment or touch a balance. It never asks for your banking password.
- Make up a number. Every figure Juru shows is calculated by code from your transactions, and links to the rows behind it. The language model that writes replies may only quote figures that code has already worked out, and replies are checked for any number that wasn’t.
- Judge you. Juru tracks what you said you wanted. It doesn’t tell you how to spend, rank you against other people, or nag.
Where your data lives
Your data is stored in Sydney, and the app runs there too. A few services handle specific jobs, and some of them are overseas. This is all of them:
| What | Who | Where |
|---|---|---|
| Your accounts, transactions, goals and messages | Supabase (database and sign-in) | Sydney, Australia |
| The app itself | Vercel (hosting and server functions) | Sydney, Australia |
| Questions you ask, PDFs you upload, check-in wording | Anthropic (language model) | United States |
| Quick judgments: a likely category, a possible transfer, what a question needs | TypeSafe | [confirm region] |
| Payments and card details | Stripe | Global (card details never reach Juru) |
| WhatsApp check-ins, if you turn them on | Meta (WhatsApp Business Platform) | Global |
| Exchange rates | European Central Bank reference rates, via Frankfurter | No personal data is sent |
Pages may be delivered through Vercel’s worldwide network so they load quickly, but the work on your data happens in Sydney. The full list, with what each service receives, is in the privacy policy.
The honest caveat: language models
Some features use a language model made by Anthropic, and it runs outside Australia, mostly in the United States. When you use one of these features, the transactions it needs are sent there to do the job:
- Chat, on the web or WhatsApp: your question, recent conversation, and the figures and transactions Juru looks up to answer it.
- Reading a PDF statement: the statement’s text. CSV files and bank feeds are read by code and never sent to a model.
- Wording a check-in: the goal and its figures, already calculated.
Anthropic’s commercial terms say it doesn’t train its models on this data, and it deletes it after a limited period [confirm current retention period before publishing].
Juru also uses TypeSafe for small, quick judgments: which of your own categories an unfiled transaction probably belongs in, whether an unclear transaction looks like a transfer between your own accounts, and which figures a chat question needs. For these it receives transaction descriptions, merchants, an amount range (never the exact amount), your category and account names, and the text of a chat question. These judgments only ever suggest: anything Juru isn’t sure about, it asks you.
If you’d rather none of this left Australia, you can still use most of Juru: upload CSVs rather than PDFs, and skip chat. Your glance, goals and transactions are calculated in Sydney by code.
Bank feeds are read-only, and their keys are sealed
Where Juru connects to a bank feed (Up in Australia, Akahu in New Zealand), you give it a read-only token. Juru checks it once with the bank, then encrypts it (AES-256-GCM, with a separate key for each token) before storing it. It’s never shown again, not to you and not to Juru’s chat, and only the code that syncs your transactions can open it. Disconnect a feed and its token is destroyed. Transactions already imported stay unless you delete them.
It’s yours: export or delete everything
In Settings you can download everything Juru holds about you as one file: accounts, transactions, goals, rules, messages and settings. Bank tokens appear only as “[sealed]”.
You can also delete everything. It happens straight away, cancels any membership first so nothing more is charged, and removes every row Juru holds about you. Database backups roll off within [backup retention period — confirm in Supabase]. Two things to know: Stripe keeps the payment records the law requires it to, and your sign-in record (your email address) is removed when you ask us at hello@askjuru.com.
What Juru measures about how it’s used
To know whether Juru is working, it records a short, fixed list of events in its own database. Nothing goes to an outside analytics company, there’s no session recording, and no event can carry an amount, a merchant or a description. This is the whole list:
| Event | What it records |
|---|---|
login | you signed in, and how (link or code) |
csv_staged | a statement was read: row and duplicate counts, CSV or PDF |
import_committed | rows were added: counts only |
first_glance_viewed | you saw your first glance, and whether it had data |
goal_created | a goal was set: its shape and check-in cadence, never its words or amount |
chat_message_sent | a message was sent, and from where (web or WhatsApp) |
export_clicked | you downloaded your data |
Juru also counts how much each language model call costs to run (tokens and price), never what was said.
Keeping it safe
- Everything travels encrypted (HTTPS), and the database is encrypted at rest.
- Every row of your data is tied to your account, and every read and write checks it. The database’s public interface is locked, so only Juru’s own servers can reach your data.
- The tools Juru’s team uses to run the service show statuses and counts, never your transactions.
- If there’s ever a data breach that could seriously harm you, we’ll tell you, and the Office of the Australian Information Commissioner or New Zealand’s Privacy Commissioner, as the law requires.
Found a security problem? Please write to hello@askjuru.com. We’ll reply within two working days, and we won’t take action against good-faith research.
Why we’re telling you this
Anyone can say they take privacy seriously. What matters is whether the product is built so the promises hold. If we can’t back a sentence on this page, we take the sentence down. Questions: hello@askjuru.com.