Privacy Policy
Joura is a personal GLP-1 progress tracker. This policy explains what data Joura collects, why, where it is stored and how you can delete it. The short version: Joura only stores what you enter, keeps it in your own private space, never shows ads, never sells data and never uses your data to track you across other apps or websites.
1. Who is responsible
Joura is developed and operated by Faustino Pinto (netpunch), Portugal — the data controller for the purposes of the EU General Data Protection Regulation (GDPR).
Contact: faustino@netpunch.pt
2. What we collect
2.1 What you enter in the app
- Profile: your first name, weight unit (lb or kg) and reminder preferences.
- Medication: the medication name, dose and schedule you set up, and each dose you log (date and time, injection site, optional note).
- Check-ins: how you feel, and optionally appetite, energy, side effects and their severity.
- Weight: the weight entries you log.
- Progress photos: the photos you choose to take or import, with the date, optional weight and note.
Medication, check-in, weight and photo data are health data. Joura processes them only because you ask it to, to show you your own progress (GDPR Art. 9(2)(a), explicit consent, which you can withdraw at any time by deleting your data).
2.2 Account data
When you first open Joura we create an anonymous account: a random user ID with no name or email attached. Everything you log is stored under that ID.
If you choose Secure your progress, we additionally store the email address and sign-in provider you link (Sign in with Apple, Google or email and password). Sign in with Apple lets you hide your real email address. Passwords are handled by Firebase Authentication and are never visible to us.
2.3 Purchases
If you subscribe to Joura Pro, Apple (App Store) or Google (Google Play) processes the payment. We never receive your card details. Our subscription partner RevenueCat receives your Joura user ID and the purchase and subscription status so that Pro features can be unlocked and restored on your devices.
2.4 Technical and diagnostic data
- Crash reports (Firebase Crashlytics): device model, operating system version, app version and the technical trace of a crash. Health values are never included.
- Usage events (Firebase Analytics): which features are used, for example that a dose was logged or a check-in completed. The values you enter (medication, dose, weight, symptoms, notes, photos) are never sent as part of these events.
- Identifiers: your Joura user ID, a Firebase installation ID and Apple's identifier for vendor, used to keep the above consistent per device.
- App integrity (Firebase App Check): an attestation from your device that requests come from a genuine copy of Joura.
Joura does not collect your precise or approximate location, contacts, browsing history or any advertising identifier.
3. How we use your data
- To provide the app: show your journey, trends and comparisons, and keep your data in sync across your devices when you link an account.
- To unlock and restore Joura Pro purchases.
- To send the reminders you turn on. Reminders are scheduled on your device and never contain your medication, dose, weight or symptoms.
- To find and fix crashes and understand which features matter.
- To protect the service against abuse and to comply with the law.
We do not use your data for advertising, profiling, selling, sharing with data brokers or training AI models, and we do not link it with data from other companies to track you.
4. Progress photos
Photos are private by default. They are stored in a storage location that only your account can read, they are never public, never shown to other users and never used for anything other than showing you your own progress. Comparisons happen inside the app. There is no feed and no sharing feature.
5. Where your data is stored and who processes it
Your data is stored on Google Cloud infrastructure (Firebase) in the European Union: the database in the eur3 multi-region and photos in europe-west1 (Belgium). Data is encrypted in transit and at rest by Google's standard mechanisms, and access is restricted to your account by security rules.
| Processor | Purpose | Data |
|---|---|---|
| Google (Firebase Authentication, Cloud Firestore, Cloud Storage, Cloud Functions, App Check, Remote Config) | Accounts, storage, sync, account deletion, app integrity | Everything in sections 2.1, 2.2 and 2.4 |
| Google (Firebase Crashlytics, Firebase Analytics) | Crash reporting, usage statistics | Section 2.4 only |
| RevenueCat | Subscription management and restore | User ID, purchase and subscription status |
| Apple, Google | App distribution, payments, Sign in with Apple / Google | Purchase and sign-in data under their own policies |
Where a processor handles data outside the EU (for example RevenueCat in the United States), transfers rely on the European Commission's Standard Contractual Clauses or an adequacy decision.
6. How long we keep data
- Your logs, photos and account: for as long as you keep your account. Historical logs are immutable snapshots of what you entered; you can delete individual entries in the app at any time.
- Deleting your account (Profile → Privacy & Data → Delete my account) permanently deletes your database records, your photos and your sign-in from our systems right away. This cannot be undone.
- Crash and usage data: kept for a limited period by Google Firebase (crash data up to 90 days) and never linked back to your health data.
- An anonymous account you never linked stays on your device; if you uninstall the app without linking, its data becomes inaccessible and is removed during routine clean-up.
7. Your rights
Under the GDPR and similar laws you can ask us to access, correct, export, restrict or delete your personal data, object to processing, and withdraw consent at any time. Deletion is available directly in the app; for anything else, email faustino@netpunch.pt and we will answer within 30 days. You also have the right to complain to your data protection authority — in Portugal, the CNPD (cnpd.pt).
8. Children
Joura is not intended for anyone under 16 and we do not knowingly collect data from children. If you believe a child has used Joura, contact us and we will delete the data.
9. Not medical advice
Joura records what you enter and performs simple calculations. It does not provide medical advice, diagnose side effects or recommend starting, stopping or changing any medication. Always follow the guidance of your prescriber.
10. Changes
If this policy changes in a meaningful way we will show a notice in the app and update the date at the top of this page. Earlier versions are available on request.
Questions? Write to faustino@netpunch.pt. Also see the Terms of Use and Support.