LAST UPDATED 10 AUGUST 2026
Privacy policy
Jagi is an app for two people. What you put in it belongs to the two of you, and this page explains exactly what we hold, why we hold it, and how you get rid of it.
THE SHORT VERSION
- We never sell your personal data, and we never share it with advertisers or data brokers.
- Your messages, photos and voice notes are for your partner. We do not read them, we do not mine them, and we do not train any AI on them.
- Location is optional. Even when it is on, your partner only ever sees your city and the distance between you.
- You can delete your account from inside the app, and it takes your data with it.
- Anything unclear, write to [email protected] and ask.
01Who we are
Jagi is made by Erwan ROMBO, an independent developer registered in France under SIREN 821 343 068 and based in Dole, France. For the purposes of the General Data Protection Regulation, Erwan ROMBO is the data controller for the personal data described on this page.
This policy covers the Jagi mobile app on iOS and Android, its home screen widgets, and this website. Jagi was previously called Joy, and accounts created under that name are covered by the same policy.
You can reach us at any time at [email protected].
02What we collect
Your account
- How you signed in. Jagi supports Sign in with Apple, Sign in with Google, and email with a password. With Apple or Google we receive an account identifier and an email address. We never see your Apple or Google password.
- Your profile. Your name, your email address, an avatar image if you upload one, and an invite code so your partner can find you.
- Optional details. Gender, birth date and a favourite colour. These are used to word the app correctly, to remind your partner of your birthday, and to colour your companion. Every one of them can be left empty.
- Language and time zone. So notifications arrive in your language and at a reasonable hour where you are.
What the two of you create
Everything you and your partner put into your bond is stored so that it can be shown to both of you: touches and custom actions, moods, messages, photos and their captions, voice notes, answers to questions, moves and scores in games, important dates, shared lists, your companion and its name, your streak and experience points, and morning and night greetings.
Location, only if you turn it on
- We store your city, your country and approximate coordinates. Location is off until you switch it on, and you can switch it off again in the app or in your phone settings.
- Coordinates are used for two things: the distance between you and your partner, and the weather where each of you is. To fetch the weather, coordinates are sent to Apple WeatherKit through our own server, and the answers are cached in coarse buckets of roughly eleven kilometres.
- Your partner is shown your city and the distance. Your exact coordinates are never shown, to them or to anyone else.
Device and technical data
- A push notification token from Firebase, so we can deliver the notifications you have turned on.
- Device model, operating system version, app version, and the IP address your requests arrive from.
- Device and installation identifiers used by our analytics and attribution providers, described below.
Purchases
Payment is handled entirely by Apple and Google. We never see your card number or your billing address. RevenueCat records what you bought and whether it is still active, linked to an app specific identifier, so the app knows to unlock Jagi Forever for both of you and so you can restore a purchase on a new phone.
Diagnostics and analytics
- Crash reports (Sentry). When the app crashes we receive the error, the device state and a short trail of the actions that led to it. Sentry is configured to attach a screenshot of the screen and the view hierarchy at the moment of the crash, which means a crash report can capture what was on screen at that instant. These reports are used only to find and fix the crash.
- Product analytics (Amplitude and PostHog). Which screens are opened and which features are used, so we can see what works and what does not. This never includes the content of your messages, photos or voice notes. PostHog runs on its European host.
- Install attribution (AppsFlyer). Which link or campaign brought you to Jagi. On iOS this only uses the advertising identifier if you allow it in the App Tracking Transparency prompt, and declining it does not change anything about the app.
There is no advertising network inside Jagi. You will not see ads, and your data is not used to target ads at you anywhere else.
03What your partner can see
Jagi is built for two people, so the honest answer is: nearly everything you put into it. Once you are bonded, your partner can see the touches you send, your mood, your morning and night greetings, whether you are currently in the app, your messages, photos, voice notes, question answers, game moves, the dates and lists you add, your name, your avatar, your birth date if you set one, and your city and the distance between you if location is on.
Your partner does not see your email address, your password, your exact coordinates, or anything you keep outside the app.
Choose your partner accordingly. If a bond ends, ask us and we will help you clear what is yours.
04Why we use it
| Purpose | Data | Legal basis |
|---|---|---|
| Run your account and your bond | Account details and everything the two of you create | Performance of our contract with you |
| Send the notifications you turned on | Push token, time zone, language, notification preferences | Performance of our contract, plus your device permission |
| Show distance and weather | City, country, approximate coordinates | Your consent, withdrawn by turning location off |
| Unlock and restore purchases | Purchase status from Apple, Google and RevenueCat | Performance of our contract |
| Keep the app working and fix crashes | Crash reports, device and app version | Our legitimate interest in a working app |
| Understand which features are used | Product analytics events | Our legitimate interest in improving Jagi, or your consent where the law requires it |
| Measure which campaign brought you | Install attribution and advertising identifier | Your consent, given in the tracking prompt |
| Email you about the app itself | Your email address and your name | Our legitimate interest in telling our own users about the app they signed up for. Every message carries a one click unsubscribe, and unsubscribing never affects your account |
| Prevent abuse and answer legal requests | Whatever is strictly needed for the case at hand | Our legitimate interest, or a legal obligation |
05Who we share it with
We use a small number of providers to run Jagi. They process data on our instructions and are not allowed to use it for their own purposes.
| Provider | What it does | Where |
|---|---|---|
| Supabase | Database, sign in, file storage, realtime, server functions | United States |
| Google Firebase | Push notifications | United States and European Union |
| Apple and Google | Sign in, payments, app distribution | Global |
| RevenueCat | Purchase and subscription status | United States |
| Apple WeatherKit | Weather for a set of coordinates | Global |
| Sentry | Crash reports | United States |
| Amplitude | Product analytics | United States |
| PostHog | Product analytics | European Union |
| AppsFlyer | Install attribution | United States and European Union |
| Kit | Email about the app | United States |
Beyond these, we share personal data only when the law requires it, or to defend a legal claim. If Jagi is ever sold or transferred, we will say so here and in the app before your data moves.
06Where your data is stored
Jagi's database, files and server functions run on Supabase, hosted on Amazon Web Services in North Virginia, in the United States. Sentry, Amplitude and RevenueCat also process data in the United States. PostHog runs on its European host.
If you are in the European Union, the European Economic Area, the United Kingdom or Switzerland, this means your data is transferred outside your country. Those transfers rely on the European Commission's standard contractual clauses, and, where the provider is certified, on the EU to US Data Privacy Framework.
07How long we keep it
- Your account and everything in your bond: for as long as your account exists.
- Notification records: thirty days.
- Notification scheduling state: one hundred and eighty days.
- Daily activity counters: sixty days.
- Crash reports and analytics: kept by those providers under their own retention windows, typically up to ninety days for crash data and up to a year for product analytics.
When you delete a photo, a voice note, a date or a list item, it disappears from the app immediately and is flagged for removal, then cleared from storage during routine cleanup.
08Deleting your account
In the app, open Settings, then your profile, then delete your account. There is a confirmation step, and then it is done. Deletion removes your sign in account and the personal data attached to it, including your profile, your moods, your messages, your photos and voice notes, your answers, your game history, your dates and lists, and your stored location.
Two honest caveats. Your partner keeps their own account and the items they created. Shared things the two of you built together, such as a list you both added to, may remain in their side of the bond. And analytics or crash events already sent are held by those providers until their retention window ends, though we can ask them to delete yours if you write to us.
Deleting your account cannot be undone. If you only want a break, sign out instead.
09Your rights
If you are in the European Union, the European Economic Area or the United Kingdom, you have the right to access your data, to correct it, to have it erased, to restrict or object to how we use it, to receive a copy in a portable format, and to withdraw a consent you gave, at any time, without it affecting what came before.
Write to [email protected] and we will answer within one month. It is one person answering, so if a request needs longer, we will tell you why.
If you think we have handled your data badly, you can complain to your national data protection authority. In France that is the CNIL, at www.cnil.fr.
10Permissions the app asks for
Every permission below is optional. Jagi keeps working if you decline, it simply does less.
| Permission | What it is for |
|---|---|
| Notifications | Telling you when your partner reaches out |
| Photos | Choosing an avatar or a picture to share |
| Microphone | Recording a voice note |
| Location | Distance between you, and the weather where you are |
| Tracking (iOS) | Attributing your install to the campaign that brought you. Decline it and nothing in the app changes |
11Children
Jagi is not for children. You must be at least 16 years old to create an account. We do not knowingly collect data from anyone younger, and if we learn that an account belongs to someone under 16, we delete it. If you are a parent or guardian and believe your child has an account, write to [email protected] and we will remove it.
12Security
Everything travels over encrypted connections and is encrypted at rest by our hosting provider. Every database table is protected by row level security, which means the database itself refuses to hand your bond's data to anyone outside it, rather than trusting the app to ask nicely. Access to the production systems is limited to one person.
No system is perfectly secure. If you ever find a hole in ours, please tell us at [email protected] before you tell anyone else, and we will fix it and thank you properly.
13Changes to this policy
When this policy changes, the date at the top of the page changes with it. If a change matters to you, for instance a new provider or a new kind of data, we will tell you in the app before it takes effect.
14Contact
Erwan ROMBO, Dole, France
SIREN 821 343 068
[email protected]
Our terms of use sit alongside this page.
자기 · jagi ·