Junto
Sign inSign up
Legal

Privacy Policy

Last updated

Junto ("Junto", "we", "us") operates letsjunto.com and the Junto mobile apps. This policy explains what personal data we handle, why, who else sees it, and what you can require us to do about it.

Junto is a place where people find each other and start ventures together. That means the product is built around being seen: some of what you give us is deliberately public, and this policy is specific about exactly which parts. We are the Data Fiduciary for that data under India's Digital Personal Data Protection Act, 2023.

What we collect

Three kinds of data, kept deliberately separate.

Sign-in identity. You sign in with Google. Google returns your name, email address and profile picture to our authentication provider (Supabase Auth), which holds your account record and issues your session. Our own application database has no email or phone column at all — it stores only the account identifier the auth provider gives it. Practically, this means an ordinary query against Junto's data cannot list your email address.

What you write. Your handle, display name, city, bio, skills, external links, profile photo and cover images, the projects and roles you post, your applications, your messages, and the agreements you sign. This is data you provide knowingly, and most of it is meant to be read by other people.

What the product records as you use it. Your swipes and saves, which projects you applied to and what was decided, your notifications, and — where you allow it — a precise home location (latitude and longitude) used to compute proximity, plus a device push token if you enable notifications on a phone.

What is public, and what is not

This is the section worth reading twice, because the split is not obvious from the interface.

Search engines, and how to say no

Public profiles are indexable by Google and other search engines by default, because being findable is the point of the product — a profile nobody can find does not get you a cofounder.

We also recognise that a real name, photograph, city and biography appearing in Google is a significant thing to do to a person, and that you may not want it. Every account has a discoverability setting. Turn it off and two things happen together: your profile page is served with a `noindex` directive, and it is removed from our sitemap so crawlers stop being pointed at it. The page stays reachable by direct link — turning off indexing is not the same as making the page private — and search engines can take days to weeks to drop a page they have already crawled.

If you want the page gone entirely rather than merely unindexed, delete your account.

Why we process it, and on what basis

Under the DPDP Act we process personal data on the basis of your consent, given when you create an account and when you enable a specific feature, and for the legitimate uses the Act permits — chiefly providing the service you asked for.

Who else processes your data

We do not sell your personal data, and we do not share it with advertisers. We do use service providers, each for one job:

What we do not do

We think the absences are as informative as the inclusions, so they are stated rather than omitted.

Cross-border transfers

Our database is hosted in India (Mumbai). Some providers listed above operate globally and may process data — principally request metadata and delivery infrastructure — outside India. Where that happens we rely on the provider’s contractual protections. The DPDP Act permits transfers except to countries the Government of India restricts, and we will comply with any such restriction.

How long we keep it

Your profile and content stay for as long as your account exists.

Signed agreements are retained after account deletion. An agreement is a record of what two people committed to, and deleting one side of it would destroy the other party’s copy of their own arrangement. We keep the typed legal name, the signature hash, the terms and the timestamp — the minimum that keeps the record meaningful.

Payment records are retained as long as tax and accounting law requires.

Messages in a conversation persist for the other participant. Deleting your account removes your profile and unlinks you, but does not erase your side of someone else’s conversation history.

Backups roll off on their own schedule, so deletion is not instantaneous everywhere at once.

Your rights

Under the DPDP Act you may ask us to:

Children

Junto is not for anyone under 18. We do not knowingly process the data of a child, and we will delete an account we learn belongs to one. If you believe a minor has an account, tell us at grievance@letsjunto.com.

Security

Data is encrypted in transit. Access to production data is restricted. Sessions are cookie-based and scoped to the site. Passwords are not something we hold at all, because sign-in is delegated to Google.

No system is perfectly secure. If a breach occurs that is likely to affect you, we will notify you and the Data Protection Board as the DPDP Act requires.

Grievance Officer

Write to grievance@letsjunto.com and we will acknowledge within 72 hours and respond substantively within 30 days. For anything else about your data — access, correction, erasure, nomination — privacy@letsjunto.com reaches the same team.

Junto, Hyderabad, Telangana, India.

If you are not satisfied with our response, you may complain to the Data Protection Board of India.

Changes

We will update this page when the product changes, and change the date at the top. Material changes will be signalled in the product rather than left to be discovered.