Privacy Policy
Last updated: September 5, 2026
At Julia AI, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI assistant service (“Service”). Please read this policy carefully.
Table of Contents
1. Who We Are
Julia AI (“Julia”) is operated by LBCMF, which is the data controller for the personal data described in this policy.
LBCMF
104 Boulevard Blanqui, 83300 Draguignan, France
SIREN 842941049 · SIRET 842941049 00020
VAT number FR82842941049
Data protection contact: legal@hellojulia.eu
We are established in France and have no establishment outside the European Union. Our lead supervisory authority is the Commission Nationale de l'Informatique et des Libertés (CNIL). You have the right to lodge a complaint with the CNIL, or with the supervisory authority in your own country of residence.
We are not required to appoint a Data Protection Officer under Article 37 GDPR: we are not a public authority, and neither large-scale systematic monitoring nor large-scale processing of special category data forms our core activity. Data protection questions go to the address above and are handled by us directly.
2. Information We Collect
We collect information you provide directly to us, information generated through your use of the Service, and information from third-party services you connect.
2.1 Account Information
When you create an account, we collect:
- Email address
- Name (optional)
- Language preference (locale)
- Timezone
- Marketing communication preferences
2.2 Messaging Platform Data
When you use Julia through WhatsApp or Telegram, we collect:
- Your messaging platform user identifier
- Display name on the platform
- Messages you send to and receive from Julia
- Media files you share (images, documents)
2.3 Task and Contact Data
To provide assistant functionality, we store:
- Tasks and to-do items you create
- Contact information for people you interact with (names, emails, phone numbers, companies)
- Relationship context and notes you provide
2.4 Memory and Context
Julia remembers information to provide personalized assistance:
- Your preferences and facts you share (stored as profile data)
- Important events and conversations (episodic memory)
- Vector embeddings of memories for semantic search
2.5 Connected Account Data
When you connect external services (Google, Microsoft), we access:
- Calendar events (to read your schedule and create or update appointments)
- Email sending (to send emails you have drafted and approved — we do not read, search, or access your inbox)
- Contacts (to look up recipients and sync your address book)
- Access tokens, so Julia can keep using the connection without asking you again. You can revoke them at any time from your Integrations page
2.6 Payment Information
For paid subscriptions, we process payments through Stripe. We store:
- Stripe customer identifier
- Subscription status and plan details
- Payment history
Note: We do not store credit card numbers or full payment details. This information is handled directly by Stripe.
3. How We Use Your Information
We use the information we collect to:
- Provide the Service: Process your requests, manage your calendar, send emails, track tasks, and provide personalized AI assistance.
- Improve AI Responses: Use conversation context and memory to provide relevant, personalized responses to your queries.
- Maintain Security: Authenticate your identity, prevent fraud, and ensure the security of your account.
- Process Payments: Manage your subscription and process payments through our payment provider.
- Communicate with You: Send service-related notifications, including magic link emails, subscription confirmations, and important updates.
- Send Marketing Communications: Only if you have opted in, send information about new features and services.
4. Legal Basis for Processing
Under the GDPR we must have a lawful basis for each purpose for which we process your personal data. These are ours:
| Purpose | Legal basis |
|---|---|
| Running the assistant — processing your messages, tasks, calendar, contacts and memory | Performance of our contract with you (Art. 6(1)(b)) |
| Accessing calendar, contacts and email sending on accounts you connect | Performance of our contract (Art. 6(1)(b)), authorised by the access you grant and revocable at any time |
| Billing and managing your subscription | Performance of our contract (Art. 6(1)(b)); invoice retention is a legal obligation (Art. 6(1)(c)) |
| Security, preventing abuse, and keeping service logs | Our legitimate interest in operating a secure service (Art. 6(1)(f)) |
| Improving the Service and acting on feedback | Our legitimate interest in improving what we offer (Art. 6(1)(f)) |
| Product update emails | Our legitimate interest in telling existing users what changed (Art. 6(1)(f)). You are told at sign-up that this is on by default and can switch it off at any time |
| Storing details of people you interact with, so Julia can act on your instructions about them | Our legitimate interest, and yours, in a working assistant (Art. 6(1)(f)) |
Where we rely on legitimate interests, you have the right to object — see Your Rights.
We do not train AI models on your data
Your messages, documents, contacts and memories are never used to train or fine-tune any AI model, ours or anyone else's. They are sent to our AI providers only to produce the response to the request you made, and for no other purpose.
5. Third-Party Services
We integrate with and share data with the following third-party services to provide our Service:
| Service | Purpose | Data Shared |
|---|---|---|
| Anthropic | Understanding your requests, transcribing voice notes, generating voice replies, and semantic search over your memories | Message content and context (pseudonymized — see below), voice note audio, response text |
| OpenAI | Understanding your requests, transcribing voice notes, generating voice replies, and semantic search over your memories | Message content and context (pseudonymized — see below), voice note audio, response text |
| Google Cloud | Hosting the service and database (region europe-west9, Paris) | All stored data |
| Vercel | Hosting the website | IP address and request logs when you visit |
| Meta (WhatsApp Business) | Messaging platform | Messages, user identifiers |
| Telegram | Messaging platform | Messages, user identifiers |
| Calendar, Gmail (send only), Contacts | OAuth tokens, API requests | |
| Microsoft | Outlook Calendar, Mail (send only), Contacts | OAuth tokens, API requests |
| Apple (iCloud CalDAV) | Calendar, if you connect an iCloud account | App-specific password, calendar requests |
| Stripe | Payment processing | Customer ID, subscription data |
| MailerSend | Transactional emails | Email address, name |
| Brave Search | Web search | Search queries |
| Semantic Scholar, arXiv, Crossref | Academic and scholarly search | Search queries |
| Jina Reader | Page retrieval. Not currently in use — listed because we may enable it, and we will update the date on this page when we do | URLs of pages you ask Julia to read |
This list is accurate as of the date at the top of this page. If we add a provider in one of these categories we will update this page before doing so.
Pseudonymization before AI processing
Your messages and the conversation context around them are pseudonymized before they reach our AI provider. Real names, email addresses and phone numbers are replaced with consistent tokens, and the real values are restored in the reply you see. The model reasons about PERSON_A and EMAIL_A rather than about your contacts.
Voice notes are the exception. Turning speech into text requires sending the recording itself, so a voice note is transcribed by OpenAI exactly as you spoke it, and a spoken reply is generated from the finished text with real names in it. Pseudonymization works on text, and for voice there is no text until after the recording has been sent. If something is sensitive, send it as text.
5.1 Google API Services User Data Policy
Julia's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We only access your Google data (Calendar, Contacts, and Gmail sending) to provide and improve the user-facing features you request through Julia.
- We do not use Google user data for advertising, and we do not sell it.
- We do not transfer Google user data to third parties except as necessary to provide the Service, to comply with applicable law, or as part of a merger or acquisition.
- We do not allow humans to read your Google data unless we have your explicit consent, it is necessary for security purposes (such as investigating abuse), to comply with applicable law, or the data is aggregated and anonymized.
- Julia requests send-only Gmail access and cannot read, search, or list your inbox.
- You can revoke Julia's access to your Google data at any time from your account's Integrations page or at myaccount.google.com/permissions.
6. Data Storage and Security
6.1 Storage Infrastructure
Your data is stored in:
- PostgreSQL Database: Primary storage for all user data, with pgvector extension for memory embeddings.
- Redis: Temporary storage for authentication tokens, rate limiting, and caching (data expires automatically).
6.2 Security Measures
We implement the following security measures:
- All data transmitted over HTTPS
- Secure, httpOnly cookies for authentication tokens
- Magic link authentication, so there are no passwords to leak
- Cryptographic verification of every incoming message from WhatsApp and Telegram, so only the real platform can deliver messages to your account
- Database queries scoped to your user ID, so one account's data is not reachable from another
- Code that Julia runs on your behalf executes in an isolated container with no network access to our internal systems
No system is perfectly secure, and we would rather describe ours accurately than impressively. If you find a security problem, write to legal@hellojulia.eu and we will respond.
8. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
8.1 Access and Portability
You can view and manage much of your data directly in the Julia user portal — your tasks, contacts and memories. For a complete copy of everything we hold about you, in a machine-readable format, email legal@hellojulia.eu and we will send it within one month.
8.2 Correction
You can update your profile information, edit contacts, and modify memory data at any time through the user portal or by messaging Julia directly.
8.3 Deletion
You can close your account at any time from your account settings. Doing so immediately deactivates it, stops all processing, ends any billing, cancels your scheduled jobs and destroys your sandbox.
To have your stored data erased as well, email legal@hellojulia.eu. We will erase it and confirm to you once it is done, within one month of your request. We are being precise about this because the two steps are currently separate: closing your account is automatic, erasing the stored data is something we do on request.
8.4 Withdraw Consent
You can disconnect third-party integrations (Google, Microsoft) at any time through the account settings. You can also opt out of marketing communications.
8.5 Objection and Restriction
Where we rely on legitimate interests (see section 4), you can object to that processing at any time, and you can ask us to restrict processing while a dispute about accuracy or lawfulness is resolved. Email legal@hellojulia.eu.
8.6 Complaints
If you think we have handled your data wrongly, tell us first — we would rather fix it. You also have the right to complain to a supervisory authority: ours is the French CNIL, and you may equally complain to the authority in your own country of residence.
8.7 Exercising your rights
Every right in this section is exercised the same way: email legal@hellojulia.eu from the address on your account. We will respond within one month, free of charge. We may ask you to confirm your identity if the request comes from somewhere unexpected, which is a protection for you rather than an obstacle.
9. Data Retention
We retain your data according to the following schedule:
| Data Type | Retention Period |
|---|---|
| User profile and preferences | Until account deletion |
| Messages and conversations | Until account deletion |
| Tasks and contacts | Until account deletion |
| Memory data | Until account deletion |
| OAuth tokens | Until you disconnect the integration |
| Research reports | 2 days, then automatically deleted. Save anything you want to keep |
| Authentication tokens | 1 hour (magic links), 7 days (refresh tokens) |
10. International Data Transfers
Your data is stored in France. The service and its database run on Google Cloud in the europe-west9 region (Paris). It is not copied to another region.
Some of the providers listed in section 5 are established in the United States, and data reaches them when you use the features they power — sending a message to be understood by OpenAI, paying through Stripe, receiving an email through MailerSend, visiting the website hosted by Vercel. Those transfers rely on the European Commission's EU–US Data Privacy Framework where the provider is certified under it, and otherwise on Standard Contractual Clauses in our agreement with them.
11. Children's Privacy
The Service is for people aged 16 and over. It is not directed at children, is not marketed to them, and offers nothing designed to appeal to them.
We do not verify age, and we want to be straightforward about why. Julia is reached through WhatsApp and Telegram, both of which set their own minimum ages and verify identity at the account level before a message can ever reach us. Collecting identity documents or running an age-estimation check on every new user would mean gathering substantially more personal data from everyone — including a large majority of adults — than the risk warrants, which is the opposite of the data minimisation the GDPR asks of us. We have judged that the platforms' own controls, combined with a service that holds no appeal for children, are proportionate here.
If you believe someone under 16 is using Julia, write to legal@hellojulia.eu. We will close the account and delete the data, and we will not ask for proof before acting on a credible report.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by:
- Posting the new Privacy Policy on this page
- Updating the “Last updated” date at the top of this policy
- Sending you an email notification for significant changes
Your continued use of the Service after changes become effective constitutes your acceptance of the updated policy.
13. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us:
Email: legal@hellojulia.eu
Post: LBCMF, 104 Boulevard Blanqui, 83300 Draguignan, France
Data deletion: close your account in your account settings, then email us to have the stored data erased.
Privacy Summary
- ✓We collect only what's necessary to provide the service
- ✓We don't sell your data or use it for advertising
- ✓Your data is stored in France, and is never used to train AI models
- ✓Text messages are pseudonymized before reaching our AI provider (voice notes cannot be — see section 5)
- ✓You can close your account at any time, and ask us to erase what we hold
- ✓We use minimal cookies (authentication only)