Privacy policy
What we collect, why, who processes it and how long it stays. Written in plain language, because you should not need a lawyer to read it.
Last updated 19 September 2026
Who we are
Journima is operated by Journima, Prague, Czech Republic. We are the controller for the personal data described on this page, except where a section says that your organisation is. For anything about your data, write to hello@journima.com.
This policy covers the website at journima.com and the product at app.journima.com, including its API at api.journima.com.
The short version
- On this website we use Google Analytics, and only if you accept it in the cookie banner. No advertising, and no analytics or tracking in the product.
- Apart from the analytics cookies you can accept or decline, the only cookies we set are two essential ones on the API domain: one keeps you signed in, one protects Google sign-in for a few minutes.
- What you put into a workspace is yours. For that content your organisation is the controller and we are the processor.
- Everything runs on servers in the European Union, except a small number of named providers in the United States, listed below with what they receive.
- We do not sell data, share it for marketing or send newsletters.
This website
Server logs
journima.com is served by Netlify. Like every web server, it records the IP address, the page requested, the time and the browser identification string in a server log, and keeps it for a short period. We use these logs only to keep the site available and secure. Legal basis: our legitimate interest in running a website.
Analytics
To see which pages are read and where visitors come from, this website uses Google Analytics 4. It runs only after you accept analytics cookies in the banner; if you decline, nothing is loaded and nothing is sent. When it runs, Google receives the pages you visit, the site that referred you, your browser and device type, a rough location derived from your IP address, and a random identifier stored in a cookie so that repeat visits can be counted. Google does not store the IP address itself. We do not use advertising features or Google Signals, and analytics never runs in the product. You can withdraw your consent at any time through the cookie settings in the footer of this site. Legal basis: your consent.
Access requests and contact
When you use the form on this site you give us your name, work email, organisation, team size, what you would like and a short message. Netlify Forms receives the submission and forwards it to our mailbox. We use it to reply and, if you asked for one, to set up your workspace. We keep it until your request is dealt with, and afterwards only as part of your customer record if you become a customer. Email sent to us is handled the same way. Legal basis: the steps needed before entering into a contract with you, and our legitimate interest in answering people who write to us.
Preferences
Your choice of light or dark theme is stored in your browser's local storage under the key jm.theme. It never leaves your browser, and so does your choice in the cookie banner, so we do not ask again. Apart from the analytics cookies described above, this website sets no cookies.
The product
Account data
To give you an account we store your email address, your display name, a hash of your password or the identifier of your Google account, whether your email is verified, when you last signed in, whether you have seen the editor tour and whether you have used a trial. Legal basis: the contract between us, meaning the terms of service.
Workspace content
Maps, stages, lanes, cards, comments, tags, personas, images, metrics, sheet bindings, and the transcripts and documents you bring into the research hub are workspace content. Your organisation decides what goes in and is the controller for any personal data it contains, for example the names of people you interviewed. We process it only to provide the service, on your organisation's instructions, under our data processing agreement, which is part of the terms. Keep transcripts pseudonymised where you can; the research hub works just as well without names.
Audit log
Each workspace keeps a log of significant actions: who did what, and when. It exists so that admins can account for changes. It stays for as long as the workspace exists. Legal basis: the contract, and our customers' legitimate interest in accountability.
Billing
For paid plans we store the plan, the subscription status and a Stripe customer identifier. Card details go directly to Stripe; we never see or store a card number. Invoices are kept for as long as tax law requires. Legal basis: the contract, and our legal obligations as a business.
Google sign-in and Google Sheets
If you sign in with Google we receive your Google account identifier and email address, nothing else. If an admin connects Google Sheets, we store an encrypted token that lets us read the ranges you point metrics at, once a day. An admin can revoke the connection at any time. Both happen only when you choose them. Legal basis: the contract.
Jira
If an admin connects a Jira Cloud site, we store encrypted tokens that let us read the issues your workspace links to portfolio items, and search your issues when a member looks one up. For each linked issue we keep a copy of its key, summary, status and assignee name, refreshed once a day and whenever someone asks for a refresh. When someone creates a Jira issue from a portfolio item, we send that item's title and description to your Jira site. We write nothing else to Jira. An admin can disconnect at any time, which deletes the tokens and the links; the grant itself stays in your Atlassian account until you remove it there. Legal basis: the contract.
AI features
When someone in your workspace asks for a map draft or runs a transcript through the research hub, the text they submit is sent to Anthropic's API and the result comes back. Anthropic does not use it to train models. Nothing is sent unless a person triggers a generation, and an admin can switch AI features off for the whole workspace. Legal basis: the contract.
Email we send
We send transactional email only: invitations, verification links, password resets, trial and billing notices and receipts. It goes through Resend. We do not send marketing email.
Errors and abuse prevention
When something breaks, an error report with the message, the stack trace and the request path goes to Sentry so we can fix it, from our servers or from your browser. Cookies are stripped from these reports and no user identifier is attached. The API also uses your IP address to limit repeated requests and prevent abuse; it is not stored beyond short-lived server logs. Legal basis: our legitimate interest in a service that works and is not abused.
Support
Email you send to support stays in our mailbox for as long as it takes to resolve the matter and for our records afterwards. Our staff have no day-to-day access to customer workspaces. A platform administrator can grant access to resolve a support issue, and every such grant is written to the audit log.
Cookies and local storage
- jm_refresh on api.journima.com. Essential. Keeps you signed in for up to 30 days and is removed when you sign out.
- A short-lived cookie during Google sign-in on api.journima.com. Essential. Protects the sign-in handshake and expires within minutes.
- _ga and _ga_… on journima.com. Analytics, set by Google Analytics only after you accept them in the banner. They hold a random visitor identifier and last up to two years, or until you clear them or withdraw consent.
- Local storage in the product holds your theme, your last workspace, your list view, the zoom level of each map and whether the navigation rail is collapsed. On this website it holds your theme and your cookie choice. It stays in your browser.
The analytics cookies are the only ones that need your consent, which is why this website has a cookie banner and the product does not. Everything else is essential to signing in.
Who processes data for us
We use these providers. Each one is bound by a contract that limits what it may do with the data.
| Provider | Where | What for |
|---|---|---|
| Hetzner Online GmbH | Germany and Finland | Servers, database, object storage for images and exports, backups |
| Netlify, Inc. | United States | Serves journima.com and the product's front end; receives contact-form submissions. Holds no workspace content |
| Resend, Inc. | United States | Transactional email: your address, name and the message |
| Anthropic, PBC | United States | AI features: only the text submitted for a generation, not used for training |
| Stripe Payments Europe, Ltd. | Ireland | Payments, card handling and invoices |
| Google Ireland Limited | Ireland | Google sign-in and Google Sheets, only when you connect them |
| Atlassian Pty Ltd | Wherever your Jira Cloud site is hosted | Jira sync, only when an admin connects it |
| Google Ireland Limited and Google LLC | Ireland and United States | Google Analytics on this website, only after you accept analytics cookies |
| Cloudflare, Inc. | United States | Turnstile bot check on the signup form, only while open registration is on; receives your IP address for the check |
| Functional Software, Inc. (Sentry) | United States | Error reports, with cookies stripped |
Where a provider processes data in the United States, the transfer relies on the European Commission's standard contractual clauses, and on the EU-U.S. Data Privacy Framework where the provider is certified under it. Workspace content leaves the European Union only through two features. An AI feature sends the text someone in your workspace submits to Anthropic. Jira sync sends the searches a member types, the identifiers of the issues you link and, when someone creates an issue from a portfolio item, that item's title and description to your own Jira site, wherever Atlassian hosts it.
How long we keep data
- Account data stays while your account exists. Ask us to delete the account and it is gone within 30 days, apart from invoices we must keep.
- Workspace content stays while the workspace exists. When an owner deletes a workspace, its records are deleted immediately and its stored files, such as images and rendered exports, are cleared afterwards. It then ages out of backups: daily dumps are kept for a week, weekly dumps for a month and monthly dumps for six months, so it is gone from every backup within six months at the latest.
- Contact-form submissions are deleted once dealt with, unless you become a customer.
- Analytics data is kept by Google for two months at visitor level; aggregated reports without identifiers stay longer.
- Server logs are kept by the hosting providers for a short period. Error reports stay in Sentry for a limited period, 90 days by default.
- Invoices and billing records are kept for as long as tax law requires.
Your rights
Under the GDPR you can ask us for a copy of your personal data, have it corrected or deleted, restrict or object to how we process it, and receive it in a portable format. You can withdraw your consent to analytics cookies at any time in the cookie settings. Maps can be exported as PDF or PNG and the portfolio as CSV directly from the product at any time; a full workspace export is available on request. Write to hello@journima.com and we will answer within a month. If your data sits inside a customer's workspace, we may need to pass your request to that organisation, because it decides what happens to its content.
You can also complain to a supervisory authority. Ours is the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů); you may also use the authority where you live or work.
Security
All traffic is encrypted in transit. Database volumes and backups are encrypted at rest. Access to a workspace is by invitation only, with four roles. The trust center describes hosting, encryption, backups and access control in detail. Security reports go to security@journima.com.
Who Journima is for
Journima is a tool for organisations and is not directed at children. You must be at least 18 to create an account.
Changes to this policy
When we change this policy we update the date at the top. If a change matters to how we handle your data, we email account holders before it takes effect.
Contact
Journima, Prague, Czech Republic. hello@journima.com. See also the imprint.