Privacy Policy
How JuhJuh collects, uses, and protects your data.
Last updated: February 3, 2026
01 Overview
JuhJuh Ltd ("JuhJuh," "we," "our") operates the JuhJuh development orchestration platform. This Privacy Policy describes how we collect, use, store, and protect your personal data when you use JuhJuh and visit our website.
This policy applies to all users of JuhJuh, including individual developers, team members, and workspace administrators. By using JuhJuh, you agree to the practices described in this document.
02 Data we collect
We collect data in three categories:
Account information
When you create an account, we collect your name, email address, and password (stored using industry-standard one-way hashing). If you join a workspace, we associate your account with that workspace.
Usage data
We collect data about how you use JuhJuh, including: tickets created and modified, prompts generated and executed, execution logs (input/output token counts, duration, cost), audit trail events, and IP addresses used to access the platform.
Code and repository data
When you connect code repositories to JuhJuh, we access repository metadata (branch names, file paths, commit history) as needed to execute development workflows. JuhJuh does not persistently store your source code beyond the active execution context. Repository credentials are stored encrypted in your project resource configuration.
03 How we use your data
We use collected data to:
- Operate and maintain the JuhJuh platform
- Authenticate your identity and enforce access controls
- Execute automated development workflows on your behalf
- Track token usage and compute costs for billing and attribution
- Generate audit trails for compliance and security review
- Improve the platform through aggregated, anonymized usage analytics
- Communicate service updates, security notices, and billing information
04 Data storage and security
JuhJuh data is stored in encrypted databases with encryption at rest. Real-time messaging and task queuing services are configured with authentication and access controls.
Security measures include:
- Industry-standard one-way password hashing
- Session-based authentication with secure, HTTP-only cookies
- IP whitelisting with CIDR-range precision
- Sliding-window rate limiting on authentication endpoints
- Environment variable sanitization for AI execution contexts
- Role-based access control with four permission levels
- TLS encryption for all data in transit
05 Data retention
We retain your data for the following periods:
| Data type | Retention period |
|---|---|
| Account information | Duration of account + 30 days after deletion |
| Execution logs | 12 months from creation |
| Audit trail | 24 months from creation |
| Session data | 14 days from last activity |
| Repository metadata | Duration of project resource connection |
Enterprise customers may negotiate custom retention schedules under a Data Processing Agreement.
06 Your rights
Depending on your jurisdiction, you may have the right to:
- Access your personal data and request a copy
- Rectify inaccurate or incomplete data
- Delete your account and associated data
- Export your data in a machine-readable format
- Restrict processing under certain conditions
- Object to processing based on legitimate interests
- Withdraw consent where processing is consent-based
To exercise any of these rights, contact us at privacy@juhjuh.com. We respond to all requests within 30 days.
07 Cookies
JuhJuh uses the following cookies:
| Cookie | Purpose | Duration |
|---|---|---|
| sessionid | Authentication session | 14 days |
| csrftoken | CSRF protection | 12 months |
| theme | Dark/light mode preference | 12 months |
JuhJuh does not use third-party tracking cookies, advertising cookies, or analytics cookies that identify individual users.
08 Connected accounts and the permissions we ask for
A connection lets JuhJuh act on an account you already own — post a message, read an issue, open a pull request. You decide which accounts to connect and you can remove any of them at any time.
Two things are true of every connection:
- The access is stored encrypted and is used only for the automations you set up in JuhJuh.
- Removing a connection stops JuhJuh from using it straight away. It does not cancel the permission at the provider — use the last column below to do that as well.
Some providers show you a permission screen where JuhJuh asks for a named list of permissions. Others have no permission screen at all: you generate an access key in your own account and paste it in, so the access is whatever you chose to give that key. The table says which is which.
| Provider | What we ask for | What we do with it | How long we keep it | How to take it back |
|---|---|---|---|---|
| Slack | Permission screen, asking for: chat:writecommandsapp_mentions:readim:historyim:readusers:readusers:read.email | Post ticket and pull-request updates into the channels you pick, answer slash commands and mentions, read direct messages sent to the JuhJuh app, and match Slack members to JuhJuh accounts by email address. | While the connection exists | Slack → Settings & administration → Manage apps → remove JuhJuh |
| Google (Calendar, Drive, Sheets) | Sign-in through the Google app you supply. JuhJuh sends no permission list of its own, so the access granted is exactly what that app is set up to allow. | Read and write only the calendar entry, file or sheet that an automation you configured names. | While the connection exists | Google Account → Data & privacy → Third-party apps & services |
| YouTube | Sign-in through the Google app you supply. JuhJuh sends no permission list of its own, so the access granted is exactly what that app is set up to allow. You may instead paste a Data API key. | Read channel and video details for the automations you configure. | While the connection exists | Delete the key in the Google console, or remove JuhJuh under your Google Account’s third-party access |
| Permission screen, asking for: pages_show_listpages_read_engagementpages_manage_posts You may instead paste a long-lived Page access token and the Page ID, generated in your own Facebook app, supplying that app’s ID and secret so a short-lived token can be exchanged for a long-lived one. | Act on that one Page — read and publish the posts and comments your automations describe. Nothing outside that Page. | While the connection exists | Facebook → Settings → Business integrations, and remove the app the token came from | |
| Permission screen, asking for: instagram_business_basicinstagram_business_content_publish You may instead paste a long-lived access token and the Instagram account ID, plus the linked Facebook Page ID if you generated the token through Facebook. | Act on that one Instagram professional account — read and publish the content your automations describe. | While the connection exists | Instagram → Apps and websites, or remove the app on the linked Facebook Page | |
| Threads | Nothing. JuhJuh has no Threads connection today. | Nothing. We hold no Threads data. | Not applicable | Not applicable |
| Permission screen, asking for: openidprofilew_member_social | Read and publish on the account that token belongs to, for the automations you configure. | While the connection exists | Expire or delete the token in your LinkedIn developer app, and check LinkedIn → Settings → Data privacy → Permitted services | |
| GitHub | No permission screen. You paste a personal access token, plus a server address if you self-host. | Read repository contents and history, create branches, and open and update pull requests in the repositories you connect. | While the connection exists | GitHub → Settings → Developer settings → Personal access tokens → delete |
| GitLab | No permission screen. You paste a personal or project access token. | Read repository contents and history, create branches, and open and update merge requests in the repositories you connect. | While the connection exists | GitLab → Preferences → Access tokens → revoke |
| Bitbucket | No permission screen. You supply the workspace name and an API token (or an older app password with the account email). | Read repository contents and history, create branches, and open and update pull requests in the repositories you connect. | While the connection exists | Atlassian account → Security → API tokens (or Bitbucket app passwords) → revoke |
| Jira | Your account email and an Atlassian API token, or a sign-in through the Atlassian app you supply. | Read and write the issues in the projects you connect, and keep them in step with tickets in JuhJuh. | While the connection exists | Atlassian account → Security → API tokens → revoke, or remove the app under connected apps |
| Calendly | Permission screen, asking for: users:readwebhooks:readwebhooks:writescheduled_events:read | Read your Calendly user and your scheduled events, and set up the event subscriptions that start your automations. | While the connection exists | Calendly → Integrations → remove JuhJuh |
| Todoist | Permission screen, asking for: data:read_writedata:delete | Read, create, change and delete the tasks and projects your automations act on. | While the connection exists | Todoist → Settings → Integrations → remove JuhJuh |
| Medium | Permission screen, asking for: basicProfilepublishPostlistPublications | Read your basic profile, list the publications you can write to, and publish the posts your automations create. | While the connection exists | Medium → Settings → Connections → remove JuhJuh |
| QuickBooks | Permission screen, asking for: com.intuit.quickbooks.accounting | Read and write the accounting records your automations act on. | While the connection exists | Intuit account → Apps → disconnect JuhJuh |
Every other provider in our catalogue follows the same shape as the rows above with no permission screen: you create a key or token in your own account, paste it into JuhJuh, and it is used only for the automations you configure. If you want to know exactly what a particular provider holds for you, ask us and we will tell you.
09 Third-party services
JuhJuh integrates with third-party services that you configure. When you connect a resource (Jira, GitHub, GitLab, Bitbucket, Slack, etc.), data flows between JuhJuh and that service according to the permissions you grant. We access only the data necessary to execute the configured workflows.
Our infrastructure providers include:
- Database hosting for data storage
- Messaging infrastructure for real-time updates and task queuing
- AI model providers for code generation execution
- Stripe for payment processing (all paid plans)
Each third-party provider is bound by their own privacy policies and our contractual data protection obligations.
10 Changes to this policy
We may update this Privacy Policy to reflect changes in our practices, technology, or legal requirements. We will notify registered users of material changes via email at least 30 days before the changes take effect. The "Last updated" date at the top of this page indicates the most recent revision.
11 Contact
For privacy-related inquiries:
JuhJuh Ltd — Data Protection Officer