‹ Legal myJRNY

Privacy Policy

Last updated: 19 August 2026

1. Introduction

Welcome to myJRNY. We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how JRNY, Inc. ("myJRNY," "we," "us," or "our") collects, uses, discloses, and safeguards your information when you use our mobile applications, our website at myjrny.app, and the public post-sharing pages we host (collectively, the "Services").

Please read this policy carefully. If you disagree with its terms, please discontinue use of our Services. By accessing or using the Services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.

2. Information We Collect

2.1 Information You Provide Directly

We collect information you provide when you create an account, use our Services, or communicate with us, including:

  • Account registration details: first and last name, username, email address, password, and date of birth. Passwords are handled by our authentication provider and are never stored by us in readable form. A child account does not need a personal email address — we issue an internal address in the form username@kids.myjrny.app.
  • Profile information: profile photo, bio, city, state and country, gender, and the sports and activities you add to your profile.
  • Content you create: posts, including their title, notes, photos and videos; comments, reactions and saved posts; tags you create; and direct and group chat messages and their attachments.
  • Communications with us: support requests you submit through in-app Help, including any files you attach, and other correspondence.
  • We do not collect payment or billing information. The Services are free and contain no purchases.

2.2 Information Collected Automatically

When you use our Services, we automatically collect certain technical and usage data, including:

  • Device information: platform (iOS or Android), app version, and a randomly generated installation identifier stored on your device. Where you enable push notifications we also store a notification token for each installation.
  • Log and diagnostic data: our infrastructure provider records standard server logs, including IP address and access times, when the app or our web pages contact our servers. We also collect crash and error reports, which include device state and the sequence of screens that led to the failure.
  • We do not collect GPS or precise location data, and we do not derive your location from your IP address. The only location associated with your account is the city you enter yourself, or the city shown on the identity document used for verification.
  • Activity within the Services: your connections, the posts you react to, comment on and save, and your responses to notifications. We use these to build your feed and your search suggestions.
  • Analytics: we use Google Analytics for Firebase to understand how the app is used — which features are opened, where people run into errors, and how the app performs — so that we can improve it. This is recorded against a randomly generated app-instance identifier rather than your name or email address, and advertising features and advertising identifiers are switched off.
  • We do not use cookies, pixels, web beacons or similar advertising or tracking technologies, and our mobile apps use no cookies at all. The only browser storage we rely on is the sign-in session created when you open a share link that requires you to sign in, which is strictly necessary to show you that page.

2.3 Information From Third Parties

We may also receive information about you from third parties, such as:

  • Google or Apple, if you choose to sign in with one of those accounts. We receive your name and email address, and from Google your profile photo. If you use Sign in with Apple and choose to hide your email address, we receive only the private relay address Apple generates for you.
  • Our identity verification provider, which returns the results described in Section 2.4.
  • Other users who tag you, mention you, or share content involving you

2.4 Identity and Age Verification

Every account is verified before it can be used. Verification is carried out inside the app by our provider, Didit.

Adults photograph a government-issued identity document and take a selfie. Where your document supports it, the app can also read the document’s NFC chip. We receive back your first and last name, date of birth, gender, and the city, region and country shown on the document. These values populate your profile and cannot be edited by you afterwards. If the verification also confirms your email address, that confirmed address replaces the one you signed up with.

A child account is verified by estimating age from a selfie. Where the estimate is inconclusive, the app asks for an identity document instead. An account assessed as at or above our child age limit cannot continue as a child account.

Facial images used for verification and age estimation are biometric data. They are captured and processed by Didit, not by us. We receive only the outcome of the check, the identity fields listed above, a session reference, the status of the check and the number of attempts made. Where consent is required for biometric processing we rely on the consent given before verification begins; for a child account, a parent or guardian gives that consent.

3. How We Use Your Information

We use the information we collect to provide, improve, and personalize our Services. Specifically, we use your information to:

  • Create and manage your account and authenticate your identity
  • Build your feed and suggest people and posts to you. Ranking uses a fixed, rule-based formula based on your connections, the activities on your profile, your country, how recent a post is, and how many reactions and comments it has. We do not use artificial intelligence, and we do not make automated decisions about you that produce legal or similarly significant effects.
  • Enable social features such as connections, reactions, comments, saved posts, chat and sharing
  • Send you service notifications, and account emails, such as help-request receipts, share-link invitations and password resets. We do not send marketing emails.
  • Diagnose crashes and errors, and analyse how the Services are used, so that we can fix problems and improve them
  • Detect, investigate and act on reports of abuse, unsafe behaviour, spam and content that breaks our Community Standards
  • Comply with applicable legal obligations and enforce our Terms and Conditions
  • Respond to your support requests and resolve disputes
  • Operate parental controls, including sending approval requests to a linked parent or guardian and recording their decision

Where UK or EU data protection law applies, our legal bases are: performance of our contract with you, to operate your account and provide the Services; our legitimate interests in keeping the Services safe, secure and working; compliance with our legal obligations; and your consent, which we rely on for identity and age verification (including the biometric processing it involves) and for push notifications. You can withdraw consent at any time, though withdrawing consent to verification means the account can no longer be used.

4. How We Share Your Information

4.1 With Other Users

What other users can see depends on your privacy settings. A new adult account is public by default: your name, username, profile photo, city, linked accounts, connections and posts are visible to other adult users, and your posts can appear in Explore and in search. You can change each of these in Settings at any time. A child account is private at registration, and making any part of it public requires a linked parent or guardian to approve the change. Child accounts and adult accounts are also kept in entirely separate pools: a child’s profile and posts never appear in an adult account’s feed, Explore, trending or search results, and connections can only be formed between accounts of the same type.

4.2 With Service Providers

We share information with the vendors that run the Services on our behalf: Google (Firebase) for authentication, database, file storage, push notifications, crash reporting and hosting; Didit for identity and age verification; and Brevo for sending transactional email. These providers are contractually obligated to use your data solely to perform services on our behalf. We do not use advertising networks, analytics vendors or payment processors.

4.3 For Legal Reasons

We may disclose your information if we believe in good faith that doing so is necessary to: (a) comply with a legal obligation or valid legal process; (b) protect the rights, property, or safety of JRNY, Inc., our users, or the public; or (c) detect or prevent fraud or security issues.

4.4 Business Transfers

If JRNY, Inc. is involved in a merger, acquisition, asset sale, or bankruptcy proceeding, your information may be transferred as part of that transaction. We will provide notice before your personal information is transferred and becomes subject to a different privacy policy.

4.5 With Your Consent

We may share your information with third parties when you explicitly direct us to do so or have given your consent.

5. No Advertising and No Sale of Personal Information

myJRNY does not show advertising. We do not run ads on the Services, we do not use advertising networks or advertising identifiers, and we do not build advertising profiles. We do not sell your personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under United States state privacy laws.

If this ever changes we will update this policy and give notice in the app before any advertising is introduced.

6. Data Retention

We keep your personal information for as long as your account exists. You can delete your account at any time from Settings. Deletion takes effect immediately and is not reversible: your account record, your posts and their photos and videos, your comments, reactions and saved posts, your notifications, your device and push-notification records, and your verification records are erased. Where your name or photo appears inside another person’s content — in a comment thread, for example — it is replaced with an anonymous placeholder rather than removed, so that the other person’s content still makes sense. We may keep a limited record where we are required to for legal or compliance purposes, to prevent fraud, or to resolve a dispute.

This section is our data retention policy, and it applies to children’s personal information as well as adults’. We do not retain personal information indefinitely: we keep each category only for as long as it is needed for the purpose it was collected for, and delete it on the schedules set out here.

Some records are deleted automatically on a fixed timer: a sign-up that is never verified is deleted after 24 hours; a revoked share link is deleted 7 days after it is revoked; a parental approval request that is never answered expires after 14 days; and a password reset link expires after 60 minutes.

Server and crash logs held by our infrastructure providers are retained on those providers’ standard schedules. They are not used to build any profile of you.

7. Your Rights and Choices

Depending on your location, you may have the following rights with respect to your personal information:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate or incomplete data
  • Deletion: Request deletion of your personal data, subject to certain exceptions
  • Portability: Receive your data in a structured, machine-readable format
  • Objection: Object to processing based on legitimate interests or for direct marketing
  • Restriction: Request that we limit how we process your data in certain circumstances
  • Withdrawal of Consent: Where processing is based on consent, withdraw it at any time
  • Non-discrimination: we will not deny you the Services, or give you a lesser experience, because you exercised any of these rights

To exercise any of these rights, contact us at privacy@myjrny.app, or in the app through Settings → Help → Contact Support. We will respond within the period the applicable law allows — one month under UK and EU law, and 45 days under United States state privacy laws. We may need to verify your identity before fulfilling your request. A parent or guardian may exercise these rights on behalf of a linked child.

8. Cookies and Tracking Technologies

We do not use cookies, pixels, web beacons or similar technologies for advertising, analytics or tracking, on our website or in our apps. There is no cookie consent banner because there is nothing to consent to. The only browser storage we rely on is the sign-in session created when you open a share link that requires you to sign in, which is strictly necessary to show you that page. Our Cookie Policy sets this out in full.

9. Children's Privacy

myJRNY is designed to be used by children, with a parent or guardian involved. This section applies in addition to the rest of this policy.

A child account cannot be used until it is linked to a verified adult. The adult completes identity verification with a government-issued document before the link can be made, and must expressly approve the child’s account. We treat that approval as verifiable parental consent under the Children’s Online Privacy Protection Act (COPPA), and as the consent of the holder of parental responsibility under Article 8 of the UK and EU GDPR.

We collect from a child only what the Services need: their name, username, profile photo, city, gender, date of birth, the activities they choose, the content they post, and the technical records described in Section 2.2. A child account does not need a personal email address. We do not require a child to provide more information than is reasonably necessary in order to take part.

A child’s age is verified before their account becomes active. Section 2.4 explains how that verification works and who performs it.

A linked parent or guardian may at any time review the personal information we hold about their child, correct it, require us to delete it, refuse to permit any further collection or use of it, and control what the child can do in the app through parental controls — including whether the child’s account is public, whether they can post publicly, and whether they can connect with other users. These controls are in Settings; requests can also be sent to privacy@myjrny.app.

Facial images used for age estimation, and the details read from an identity document, are biometric identifiers and government-issued identifiers. We treat them as personal information subject to this policy and to the protections described in Section 2.4.

On a child account we collect technical information only to the extent needed to operate and protect the Services — what COPPA calls support for the internal operations of the service. Specifically, we use it to authenticate the account, deliver the notifications the account has enabled, keep the Services working and diagnose faults, understand how the Services are used so that we can improve them, and detect and investigate fraud, abuse and behaviour that puts a child at risk. This is the minimum required to keep children safe on the Services and is not optional. We do not use that information to contact a child individually, to build an advertising or marketing profile, or for any purpose beyond those operations, and advertising features and advertising identifiers are switched off in the analytics we use.

We do not show advertising to children, we do not use a child’s personal information for marketing, and we do not disclose it to any third party for targeted advertising or for training artificial intelligence models. We do not sell it. It is disclosed only to the service providers listed in Section 4.2.

10. International Data Transfers

JRNY, Inc. is a Delaware corporation headquartered in New Jersey, United States, and your information is processed in the United States. If you use the Services from outside the United States your information will be transferred there, and United States data protection law may differ from the law where you live. For transfers from the United Kingdom, the European Economic Area or Switzerland we rely on the European Commission’s Standard Contractual Clauses and the UK Addendum, together with the equivalent terms in our providers’ data processing agreements.

11. Security

We protect your personal information with technical and organisational measures appropriate to its sensitivity. Data is encrypted in transit and at rest by our infrastructure provider, and access to production data is restricted. Photos and videos are stored privately: they are never given a permanent public address, and are served only through links that expire — after 12 hours in the app, and after 6 hours on a share page.

We maintain a written information security program overseen by a member of our team which covers children’s personal information. The program covers the risks to children’s data, the safeguards we put in place against those risks, and a review of how well those safeguards are working, each revisited at least once a year.

While we strive to protect your information, no method of transmission over the internet or electronic storage is 100% secure. We encourage you to use a strong, unique password and to keep your device locked.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other reasons. When we make material changes we will notify you by posting the updated policy at myjrny.app/privacy and in the app, updating the "Last updated" date, and — where required by law — seeking your consent or the consent of a linked parent or guardian. We encourage you to review this policy periodically.

13. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact our Privacy Team:

JRNY, Inc.
Attn: Privacy Team
20 River Court, Apt 403
Jersey City, NJ 07310, United States
Email: privacy@myjrny.app
Policy online: myjrny.app/privacy

JRNY, Inc. is the data controller for personal information processed through the Services. If you are in the United Kingdom or the European Economic Area, you may also lodge a complaint with your local data protection authority.