Privacy Policy
Last updated: September 2026
1. Who We Are
Juliapp is operated by DBEK, a company registered in France at 75 rue de Lourmel, 75015 Paris, France. Juliapp provides a community-powered safety mapping and navigation platform (“the Service”). For questions about this policy, contact us at legal@juliapp.io.
2. Data We Collect
We collect only the data necessary to provide and improve the Service:
- Account data: Email address, display name, authentication provider (Google, Apple, or email).
- Location data: GPS coordinates when you use the map, create reports, trigger SOS alerts, or use trip navigation. Location is only accessed with your explicit permission.
- User-generated content: Safety reports (pins), photos, chat messages, saved routes.
- Device information: Push notification tokens, browser type, and language preference.
- Identity verification data, including biometric data: opening an account requires identity verification carried out by our provider Didit. During a session hosted by Didit and opened in your device’s browser, Didit reads an official identity document, captures a selfie, checks that the selfie comes from a live person (passive liveness detection) and compares the face on the selfie with the photo on the document (facial comparison). Liveness detection and facial comparison constitute processing of biometric data; they are performed by Didit, not by the Juliapp application, and only for the duration of the verification. What Juliapp receives and retains from this verification: the sex recorded on the document, the date of birth, a technical fingerprint (hash) of the document preventing the same document from being used for several accounts, the verification status, the identifier of the Didit session, and a minimised technical log of the verification events (statuses, refusal codes, document type and issuing country, liveness and facial-match scores). What Juliapp never receives and never retains: the image of your face, the selfie or video, the image of the document, any biometric template, your name, your address, or your document number in clear text. No image is ever transmitted to Juliapp. All face data is described in section 5.
- Julia assistant data: the messages you write to Julia, Julia’s replies, and the memories Julia saves at your request, stored in your Juliapp account. What is sent to our AI provider is described in section 4.
3. How We Use Your Data
- To provide the Service: display safety reports, route navigation, SOS alerts, push notifications.
- To improve safety: aggregate anonymised data to compute neighborhood safety scores and trend analysis.
- To communicate with you: service emails, safety alerts, magic link sign-in.
- To ensure security: detect abuse, enforce community guidelines, moderate content.
4. Julia assistant and third-party AI processing (Anthropic)
Julia is the in-app assistant of Juliapp. Julia’s replies are generated by a third-party AI service: Claude, provided by Anthropic, PBC (United States), through its commercial API. Julia runs on our servers, which call Anthropic: there is no AI model on your device, and Julia has no voice or audio feature — it works with text only.
- Your permission first: before any data is sent to Anthropic, the app asks for your explicit permission on a dedicated screen that names Anthropic and lists the data below. If you decline, Julia stays off, nothing is sent to Anthropic, and the rest of the app works normally. You can withdraw this permission at any time in Settings → Julia; from that moment, nothing more is sent to Anthropic.
- What is sent to Anthropic, and how: each time you write to Julia, our server sends Anthropic, over an encrypted connection: the text of your message; the recent history of your Julia conversation (up to the last 30 messages), so that Julia can follow the conversation; and, so that Julia can answer about your situation, the following context: your display name; your current location (coordinates); the current time; the type and severity of the safety reports near you and a safety score computed from them; the destination and transport mode of your ongoing trip, if any; whether an SOS alert is in progress; the display names of your Lifelines and whether they are online; your favourite places and your home address as saved in the app, with their coordinates; your recent destinations; your safe-arrival streak; and the memories Julia saved at your request. When Julia uses an app function for you (for example finding safe places nearby or estimating a route), the result of that function is also sent so that Julia can answer. Nothing else is sent: no identity document, no face data, no phone address book, no payment data.
- All uses: this data is used only to generate Julia’s reply to your message and to let Julia carry out the actions you ask for in the app (for example starting a trip, finding safe places, saving a favourite place or a memory). It is not used for advertising or profiling, not sold, and not used to train AI models.
- Equal protection by Anthropic: Anthropic processes this data as our processor, under its commercial terms and data processing addendum. Under those terms, Anthropic does not use data sent through its API to train its models, retains it only for a limited period for abuse monitoring, and then deletes it. We confirm that Anthropic provides the same or equal protection of your data as stated in this policy.
- Transfer outside the EU: Anthropic processes this data in the United States. This transfer is covered by the European Commission’s Standard Contractual Clauses, incorporated in Anthropic’s data processing addendum.
- Storage and deletion on our side: your Julia conversations and memories, and technical logs of Julia’s operation, are stored in your Juliapp account on our EU-hosted database (Supabase). They are deleted when you delete your account (Settings → Delete my account). You can also ask us at any time to delete your Julia history and memories by writing to legal@juliapp.io.
- No other AI provider: Anthropic is the only AI service to which Julia data is sent. We will update this policy, and ask for your permission again in the app, before sending any data to another AI provider.
5. Face data (facial images and biometric processing)
This section describes all the face data involved in Juliapp. Face data is used only for identity verification, carried out by our provider Didit.
- What is collected, and how: during identity verification, in a session hosted by Didit and opened in your device’s browser, Didit captures a selfie (a photo and a short video of your face) and an image of your official identity document, which carries your photo. The Juliapp application itself does not capture or access these images. Face data is collected only after you have given your explicit consent on a dedicated screen in the app.
- All uses: these images are used for two purposes only: to check that the selfie comes from a live person in front of the camera (liveness detection), and to compare the face on the selfie with the photo on the document (facial comparison), in order to verify your identity. Face data is used for nothing else: no advertising, no profiling, no recognition of other people, no training of AI models, and no estimate of your sex or gender from your face.
- Disclosure and sharing: face data is shared with a single third party, Didit, which processes it as our processor under Article 28 GDPR and a data processing agreement, solely on our instructions. Face data is never transmitted to Juliapp, never sold, and never shared with anyone else — including Anthropic and the other providers listed in section 7. Juliapp receives only the outcome of the verification: the verification status and numeric liveness and face-match scores, never an image or a biometric template.
- Equal protection by the third party: we confirm that Didit, the only third party with which face data is shared, provides the same or equal protection of face data as stated in this policy: it is bound by contract to process face data only for the verification, to store it in the European Union (AWS, EU regions), to delete it within the periods below, and never to use it for its own purposes. Didit is certified ISO/IEC 27001 and SOC 2 Type 2.
- Storage and retention: the images (selfie, video and document) are stored by Didit only, in the European Union, for a maximum of 30 days from the verification session, then deleted. No biometric template is kept after the verification session, neither by Didit nor by Juliapp. The verification status and scores kept by Juliapp are retained while your account exists and are deleted with it.
- How to refuse or revoke your consent: before verification, you can refuse on the consent screen: no face data is then collected or processed. After verification, you can revoke your consent at any time by writing to legal@juliapp.io from the email address of your account, or by deleting your account. When you revoke your consent, no further processing of your face data takes place and we ask Didit to delete it without waiting for the end of the 30-day period. Because identity verification is what makes an account verified, your account can then no longer remain a verified account, and the features reserved for verified members are no longer available to you.
- How to delete your face data: (1) in the app, Settings → Delete my account: Juliapp deletes its verification data (status, scores, verification log) and asks Didit, through its deletion service, to delete the verification session — including the images — and the identity linked to your account; or (2) without deleting your account, write to legal@juliapp.io to ask for your face data to be deleted at Didit before the end of the 30-day period. We handle such requests within 30 days at most and confirm the deletion to you.
6. Legal Basis (GDPR Article 6)
- Consent: location access, push notifications.
- Contract: account creation, identity verification, provision of the Service.
- Legitimate interest: safety, abuse prevention, anonymised analytics.
- Explicit consent (Article 9 GDPR): liveness detection and the comparison of your selfie with your identity document are processing of biometric data. They take place only with your explicit consent, which is collected in the application on a dedicated screen before the Didit verification flow is opened, and only for the duration of the verification. If you do not give this consent, no biometric processing takes place and the account is not opened. Juliapp retains no biometric template, and Didit retains none beyond the verification session. See section 5.
- Consent: sending your Julia messages and the context described in section 4 to Anthropic. You can withdraw this consent at any time in Settings → Julia.
7. Data Sharing
We do not sell your data. We share data only with:
- Supabase (database, authentication, file storage and server functions) — stores all account and app data; hosted in the European Union (Ireland).
- Mapbox (maps, address search, geocoding and route calculation) — receives the address or place you search for and the coordinates needed to display the map or compute a route; United States; transfer covered by the Standard Contractual Clauses.
- Didit (identity verification) — Didit acts as our processor within the meaning of Article 28 GDPR, under a data processing agreement, and processes the document and selfie images solely on our instructions and for the sole purpose of verifying your identity. Didit does not sell this data and does not use it for its own purposes. The data is processed and stored in the European Union (AWS, EU regions). Didit is certified ISO/IEC 27001 and SOC 2 Type 2, and its liveness detection is certified iBeta PAD Level 1. Didit provides the same or equal protection of face data as stated in this policy (see sections 2, 5, 6 and 8).
- Vercel (hosting) — serves the website and runs our servers, including the Julia server, so requests from the app pass through it; United States; transfer covered by the Standard Contractual Clauses.
- Anthropic, PBC (AI processing for the Julia assistant, United States) — only if you have accepted it in the app: receives the text of your Julia messages, your recent Julia conversation and the context listed in section 4 (including your location, your saved places and the display names of your Lifelines). Anthropic acts as our processor under its data processing addendum, does not use this data to train its models, and retains it only for a limited period for abuse monitoring before deleting it. The transfer to the United States is covered by the European Commission’s Standard Contractual Clauses. Anthropic provides the same or equal protection of your data as stated in this policy.
- Twilio (SOS text messages) — when an SOS alert cannot reach one of your Lifelines by notification, receives that person’s phone number and the text of the SMS (your display name and the link to follow the alert); United States; transfer covered by the Standard Contractual Clauses.
- Expo (push notification delivery) — receives your device’s notification token and the content of the notification (title and text), and hands it to Apple or Google for delivery; United States; transfer covered by the Standard Contractual Clauses.
- Apple (Apple Push Notification service, and the map shown in the iOS app) — receives your device’s notification token and notification content, and the area of the map you view; transfer covered by the Standard Contractual Clauses.
- Google (Firebase Cloud Messaging, Google Maps Platform, Tenor) — delivers notifications on Android and receives your device’s notification token and notification content; displays the map in the Android app; receives the coordinates of the area in which our server searches for safe places; and receives the search words when you look for a GIF in a private message; transfer covered by the Standard Contractual Clauses.
- Transitous (public transport routes, transitous.org) — receives only the start and end coordinates of the journey you plan by public transport, without your name or any account identifier.
- Sentry (crash and error reports) — receives technical data about the error and the device (app version, operating system, error trace), without your name or email address; hosted in the European Union (Germany).
- PostHog (usage statistics) — on the website, only after you accept analytics cookies; in the iOS app, events describing how the app is used, linked to a pseudonymous identifier of your account. Never used for advertising; hosted in the European Union (Germany).
- Resend (transactional email) — receives your email address and the content of the service emails we send you; United States; transfer covered by the Standard Contractual Clauses.
Each of these providers processes your data only for the purpose stated above, under a data processing agreement or equivalent contractual terms, and provides the same or equal protection of your data as stated in this policy. Where data is processed outside the European Union, the transfer is covered by the European Commission’s Standard Contractual Clauses or another safeguard recognised by the GDPR.
8. Data Retention
- Account data: retained while your account is active, deleted within 30 days of account deletion.
- Safety reports: retained indefinitely to maintain the community safety map. Reports are anonymised after 12 months.
- Location history: retained for 60 days, then automatically deleted.
- Chat messages: retained for 12 months.
- GPS trail from an SOS alert: retained for 30 days after the session ends as evidence, then the coordinates are permanently deleted. The incident record itself is kept without location data.
- Identity verification data retained by Juliapp (sex recorded on the document, date of birth, document fingerprint, verification status, Didit session identifier, minimised technical log of the verification events): retained for as long as the account exists. When you delete your account, Juliapp deletes this data and asks Didit to delete the verification session and the identity associated with it.
- Account refused at verification: data necessary to examine an appeal and to prevent a further attempt is retained for thirty days from notification of the refusal, then deleted.
- Images captured during verification (document and selfie): stored by Didit only, in the European Union, for a maximum of 30 days from the verification session — a retention period set by Juliapp in Didit’s console — then deleted, or earlier on request (see section 5). Didit retains no biometric template beyond the verification session. These images are never transmitted to Juliapp.
- Julia conversations and memories: retained while your account exists, deleted with your account or on request (see section 4). Data sent to Anthropic for Julia: retained by Anthropic only for a limited period for abuse monitoring, then deleted.
9. Your Rights (GDPR Articles 15–22)
As an EU resident, you have the right to:
- Access: Request a copy of your personal data.
- Rectification: Correct inaccurate data.
- Erasure: Delete your account and all associated data (Settings → Delete my account).
- Portability: Export your data in machine-readable format.
- Restriction: Limit processing under certain conditions.
- Object: Object to processing based on legitimate interest.
- Withdraw consent: At any time, without affecting prior processing — for Julia, in Settings → Julia; for face data, see section 5.
To exercise these rights, email legal@juliapp.io. We respond within 30 days.
10. Security
We use industry-standard security measures including encrypted connections (TLS 1.3), row-level security on our database, HMAC-signed webhooks, and secure authentication via Supabase Auth. All data is stored in EU data centres.
11. Children
Juliapp is not directed to children under 18. We do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it promptly.
12. Changes to This Policy
We may update this policy from time to time. Material changes will be notified via the app or email. Continued use after changes constitutes acceptance.
13. Contact & Supervisory Authority
Data controller: DBEK, 75 rue de Lourmel, 75015 Paris, France.
Email: legal@juliapp.io
You may also lodge a complaint with the French data protection authority: CNIL, 3 Place de Fontenoy, 75007 Paris (www.cnil.fr).
14. Mobile Applications
The Juliapp mobile applications (iOS and Android) request the following native permissions:
- Location (always): required for SOS alerts and real-time escort tracking
- Contacts: import to your Lifelines trusted circle
- Notifications: SOS, escort, and community alerts
- Camera: identity verification (photo of the document and selfie) is carried out by our provider Didit in your device’s browser, in a flow hosted by Didit; the Juliapp application itself does not access the camera for that purpose. The application uses the camera only for your profile photo and for the media you choose to attach to a report.
Secure storage: authentication tokens are stored in the Keychain (iOS) and EncryptedSharedPreferences (Android), not in standard storage.
Push notifications: we use Firebase Cloud Messaging (Android) and Apple Push Notification service (iOS) to deliver alerts.
This document is available in several languages. The English version is the authoritative text: in the event of any discrepancy, the English version prevails.