Johnni Privacy Policy
Version: 1.0 This version takes effect: October 2, 2026 Last updated: October 2, 2026
Johnni ("Johnni," "we," "us," "our") respects your privacy. This Privacy Policy explains what personal information we collect, why we collect it, how we use and share it, how long we keep it, and what rights you have.
This Policy applies to the Johnni app for homeowners (the "App"), the demonstration home an inspector can try, and the johnni.app website (together, the "Services").
Johnni is offered in two ways. Some people receive Johnni from the home inspector who inspected their home: their inspection report becomes the starting point of their home profile. Others download Johnni on their own and build a home profile themselves, or upload a report from any inspector. An inspector who offers Johnni to you is not the operator of Johnni; Section 7.2 explains exactly what such an inspector can see.
By using the Services you agree to this Policy. Where required by law, we will also ask for your express consent.
1. Who we are and how to reach us
Data controller: Johnni
Privacy contact: hello@johnni.app
We comply with the Personal Information Protection and Electronic Documents Act (Canada) ("PIPEDA") and the Personal Information Protection Act (British Columbia) ("PIPA BC"). Where another provincial or territorial law (for example Quebec's Law 25 or Alberta's PIPA) applies to you, we comply with that law to the extent applicable.
2. Information we collect
We collect only what we need to provide the Services. The categories below describe what we collect, by feature.
2.1 Account and profile information
When you create an account or update your profile we collect:
- First and last name
- Email address
- Password, if you choose to set one (stored in salted-hashed form by our authentication provider)
- Phone number (optional)
- City, province, postal code
- Profile photo (optional)
- Referrer ID (the inspector or person who invited you, if any)
You sign in with your email address and a code we send to it, or with a password if you set one. The App does not offer sign-in through Google, Apple or another provider.
We keep a record of the date you gave or withdrew permission for AI processing, and the version of the notice you saw.
Filled in from your inspection. If your inspector delivered your report through our platform, your name, and where the inspection records them, your phone number and the year and size of the home, are copied into your profile when the report is attached to your account. We fill only fields that are empty; you can change them.
2.2 Photo analysis
When you submit a photo for analysis (for example siding, electrical, plumbing, mechanical or an appliance), we collect:
- The photo itself
- Optional text caption or description you add
- The category you choose, or the one our system infers, and the severity it infers
- Your feedback on the analysis (thumbs up or down)
- Photo metadata, including time of capture
Location data is optional. We do not access your device's precise location unless you grant location permission for a feature that needs it (such as suggesting nearby trades or pre-filling a property address). We do not use location data stored inside a photo. A photo taken with the App's camera is saved without it. A photo you choose from your library is uploaded as it is and may contain location data your phone stored in it; remove it before uploading if you do not want it kept with the photo. You can revoke location permission at any time in your device's settings.
2.3 Repair price estimates
When you generate a repair price estimate, we collect the defect description used as input, the estimate range produced, the property address (where available) and the trade category.
2.4 Trade directory
When you search the directory or contact a trade, we collect the city or region searched, the trade category and filters used, the listings viewed, and, if you contact a trade through the App, the contact details you provide (name, email, phone), your message and the listing contacted.
2.5 Inspection reports
When a home inspection report becomes available to you, because your inspector delivered it through our platform or because you imported it with a one-time access code, we store the report content (sections, findings, severity, recommendations), photos taken on site, the inspector's identity and signature, and property metadata (address, date, services performed).
A report you upload yourself is stored with the findings and home details our system reads from it, and the page images used to show it in the App. It belongs to your account and is deleted with it (Section 9.2).
2.6 Device, usage and diagnostic data
When you use the Services we automatically collect:
- Device type, model, operating system and version
- App version, build number, language, time zone
- IP address. We do not store it in our own databases. The hosting providers that carry our traffic record it in their request logs for a limited time, for security and abuse prevention. It is not used for advertising.
- Crash logs, exception traces, performance metrics
- Feature usage: which screens you visit and which actions you take, with the time. While you are signed in, these events are linked to your account. We use them to see how the App is used and to help you when you contact support. We report on them in aggregate.
- Push notification token (if you allow notifications)
2.7 Johnni chat and voice
When you ask Johnni a question, we process your message, relevant Home Profile or inspection-report context, and the generated response to answer you. Messages and relevant context are sent to our backend and AI providers; they are not necessarily de-identified before processing.
Microphone access begins only after you start a voice feature and grant permission. Depending on the voice mode, a recorded clip is sent through our backend to OpenAI, or live audio is streamed from your device to OpenAI during an active voice session. While a live session is open, the microphone stays on and Johnni listens for your next question; other people's speech in the room may be picked up and answered. We process the transcript, generated text and spoken response, session identifiers, and usage duration and counts to provide the conversation, enforce limits and diagnose failures. Use Mute or End to stop the live microphone, or revoke microphone permission in your device settings. A live session ends on its own after 30 minutes. You can continue using typed chat.
We do not intentionally retain raw microphone recordings in the Johnni application database. This does not mean that audio never leaves your device or that providers have zero retention: their processing and limited operational or abuse-monitoring retention are described in Section 5.3.
Where the chat displays our quality-review notice, a copy of your questions and Johnni's replies, linked to your account and channel, is retained in a restricted quality-review archive for 90 days, with deletion performed by a daily scheduled process. Authorized staff may review it to investigate errors and prepare corrected general guidance. The archive does not include raw audio. Device-local conversation history, temporary live-session context and older saved conversations have separate retention rules in Section 8.
2.8 Communications
If you contact us by email, in-App message or through customer support, we collect the contents of those communications and any attachments.
2.9 Reports about AI answers
If you use "Report this answer", we keep the answer you reported, the question that led to it, the reason you chose, the channel (chat or voice) and your account identifier. Authorized staff review reports to correct errors. Reports are kept while your account exists and are deleted with it.
2.10 What we don't collect
- We do not track you across other apps or websites for advertising purposes.
- We do not access your device's precise location unless you explicitly grant location permission and the feature requires it. Separately, a photo you choose from your library may contain location data your phone stored in it (Section 2.2). We receive that data with the photo and do not use it.
- We do not collect biometric identifiers, your contacts, calendar entries, or health data. Johnni uses the microphone for the voice interaction you start, including streaming while a live session is active, as described in Section 2.7. It does not passively listen outside that interaction.
- We do not knowingly collect personal information from anyone under 19.
2.11 Home Profile and the home's record
Johnni keeps two kinds of information about a home.
Your Home Profile is tied to your account. It holds details taken from your inspection report, such as the home's systems, their makes and models, and their condition at the inspection; details we infer from the home's age and type and from similar homes, shown as estimates; details you add or correct, including answers to questions and appliance plates you photograph; and your tasks and your conversations with Johnni (Section 2.7).
The home's record is tied to the property. It holds the property's systems and components and their ages, your answers about the home, the service events you record, and photo-check results. A service event or photo check includes the note you wrote and the photos you attached. The home's record does not hold your name, your contact details, your tasks or your conversations.
Information about a property can relate to the people who live there even without a name attached, and a note or photo can show a person, a name or an invoice. We protect the home's record under this Policy.
How long the home's record is kept. We keep it while someone holds it in their account. When you delete your account, the home's record is deleted with it, including its notes and photos, unless you handed the home to a new owner, who then holds the record. A record that nobody holds is deleted 7 years after the last activity on it. "Activity" means something a person did: creating the record, recording a service event, running a photo check, or answering a question about the home. Routine system updates do not count.
When you transfer a home to a new owner, using the handoff code in the App, the new owner receives the whole home's record: the property details, the systems and their ages, your answers about the home, and every service event and photo check, including the notes and photos attached to them. There is no way to choose parts of it. Your account name and contact fields are not transferred separately, and your tasks, conversations and account are not transferred. Notes and photos you transfer may contain personal information, such as a name on an invoice or a person in a photo. If there is a note or photo you do not want passed on, ask us to remove it and wait until we confirm it has been removed before you create a handoff code. The code works once and expires after 30 days.
After a transfer, the record belongs to the new owner's account. We keep a copy of your own tasks and answers, without the record, for your account. If you are the former owner and want personal information in a note or photo you added removed, write to hello@johnni.app. We confirm that the request comes from the account that added it, and we remove that note or photo. We do not delete the new owner's record, or entries the new owner added, at a former owner's request.
2.12 Where the information about your home comes from
Your home profile can hold four kinds of information:
- What you entered: answers to Johnni's questions, notes, tasks you completed, corrections you made, and photos you chose to send.
- What was read from an inspection report: the findings, and the systems, makes, models, materials, ages and conditions the inspector recorded. This comes from a report delivered through our platform, or from a report you uploaded. Our automated reading of a report can miss or misread details; the report itself is the record.
- What is inferred or estimated: typical ages and lifespans, repair-cost ranges, and suggestions based on the home's age, type and region and on similar homes. These are estimates produced by our systems and AI providers, shown as such.
- What is shared with the person who invited you, if you chose to share it: see Section 7.2. Nothing in the three groups above is shared with an inviter.
3. How we use your information
We use personal information to:
(a) Provide the Services: generate AI analysis, display inspection reports, run the trade directory, deliver notifications, and answer your questions.
(b) Improve and develop the Services: diagnose bugs, measure performance, design new features, and improve and refine system performance using de-identified and aggregated information (with personal identifiers removed and addresses generalized to neighbourhood or municipal level). We do not use your raw inspection reports or raw home photos to train any AI model unless you give us specific written consent.
(c) Send you service messages. We send messages that are needed to provide the Services: sign-in codes, account and security notices, and notices of changes to the Services or to this Policy. You cannot opt out of these while you have an account, because the Services cannot be provided without them.
(d) Send you promotional messages, where permitted. We send promotional messages, such as news about features, offers from partners and content for homeowners, only where Canada's Anti-Spam Legislation (CASL) allows it: where you have given express consent, or where consent is implied by an existing business relationship with us, and only for the period the law allows. Creating an account, accepting our Terms, or accepting this Policy is not, by itself, consent to promotional messages. Every promotional message identifies us and includes a working unsubscribe. See Section 9.3.
(e) Protect the Services and our users: detect fraud, prevent abuse, enforce our Terms, respond to security incidents, defend legal claims.
(f) Comply with law: respond to legal requests, court orders, regulatory inquiries and audit requirements.
We will not use personal information for materially different purposes than those disclosed here without obtaining further consent or providing notice as required by law.
4. Consent and our authority to handle your information
We collect, use and disclose personal information only for purposes that a reasonable person would consider appropriate in the circumstances, and that we identify at or before the time of collection. We rely on:
- Your express consent, where the information is sensitive or the use is not one you would expect. Examples: the AI permission in the App, granting camera, microphone or location access, sharing your details with the person who invited you, and sending a request to a trade.
- Your implied consent, where the purpose is obvious from what you asked us to do. Example: using the report you uploaded to build your home profile.
- Circumstances in which the law permits or requires collection, use or disclosure without consent, such as complying with a court order or investigating a breach of an agreement or of the law.
We do not treat a contract or our business interests as permission to use your information for purposes you were not told about. If we want to use your information for a materially new purpose, we will tell you and, where the law requires it, ask for your consent first.
You may withdraw consent at any time as described in Section 9, subject to legal and contractual restrictions and reasonable notice. We will tell you what withdrawing means for the Services you use.
5. AI processing, automated decisions and training data
Several Services use AI to analyze your inputs:
- Photo analysis runs your photos through image-similarity and large-language-model systems hosted in Google Cloud and through OpenAI APIs. To describe a photo, the system first finds similar photos in a reference set of inspection photos (Section 5.2) and shows a few of them to the AI model as examples alongside yours.
- Appliance Age Finder reads the data plate you photograph with OpenAI, and looks up the make, model and serial number with Homespy, a third-party appliance-age service, to estimate the appliance's age.
- Report reading runs an inspection report, whether delivered through our platform or uploaded by you, through Anthropic to extract its findings and the home's systems.
- Trade recommendations are produced by matching a finding to a trade category, using keyword rules and AI analysis of the finding.
- Johnni chat and voice use relevant home and report context and messages to provide answers. Voice can use recorded clips or live audio streaming to OpenAI for transcription and spoken responses.
5.1 What we do with your content
We use your photos and documents to provide the Service you asked for, for example producing your photo-analysis result. We retain them for the periods set out in Section 8 so that you can re-access your results.
5.2 System improvement, reference examples and training
We do not train or fine-tune an AI model on your content. No model of ours is trained on inspection reports, photos or conversations today.
Reference examples. The photo-analysis system compares your photo with a reference set of photos from home inspections and shows the closest matches, with their findings, to the AI model as examples. The reference set is built from inspection reports prepared on our platform. It does not include the photos you upload for analysis, and your uploads are not added to it.
Aggregate improvement. For improving our classifiers and estimates we use de-identified and aggregated information, with personal identifiers removed and addresses generalized to neighbourhood or municipal level. Separately, authorized staff may review identifiable submissions and disclosed conversation-review copies for operational quality assurance, debugging and support as described in Sections 2.7 and 5.4. That review is not model training. Corrected general guidance prepared from it must omit personal details. We do not use raw inspection reports, raw home photos or identifiable conversations to train an AI model without your specific written consent.
We do not sell any of your User Content, identifiable or otherwise, to any third party.
5.3 Third-party AI and cloud providers
When you use AI analysis, chat or voice, your submitted content and relevant context is transmitted to and processed by third-party cloud and AI providers acting on our behalf. The providers we use are listed in Section 6 and currently include Google Cloud, Firebase, OpenAI, Anthropic and Homespy. We may add or change providers from time to time; the table in Section 6 is kept current.
We use these providers under their commercial API terms, under which content sent through the API is not used to train their general-purpose models. We rely on those terms; we do not control the providers' systems. Providers may retain content or technical logs for limited service, security, abuse-prevention or legal purposes under those terms. For example, OpenAI API abuse-monitoring logs may be retained for up to 30 days by default; endpoint-specific rules and legal exceptions can differ. We do not promise zero provider retention. Processing may occur outside Canada (see Section 11).
Your permission in the App. The first time you sign in, the App shows you what is shared with our AI providers and asks you to agree. Until you agree, the App does not offer the features that send what you type, say, photograph or upload to an AI provider. Our servers also check for a recorded agreement before answering such a request.
If you choose "Not now", or later withdraw your permission in Menu, Profile, Privacy choices, the parts of the App that need AI (answers, tasks, tools, report upload and photo checks) are not available. You can still open your inspection report, manage your profile and privacy choices, and delete your account.
A withdrawal is recorded on your account and applies on every device. Your other phones apply it when you next open the App on them; a voice conversation already running on another phone continues until you end it there or it ends on its own after 30 minutes, though it no longer receives answers from your home profile. Work already started when you withdraw, such as a report being read, finishes.
Withdrawing does not delete content already processed. To delete it, use account deletion (Section 9.2) or write to hello@johnni.app.
Processing that happens before you use the App. When your inspector delivers a report through our platform, or when you upload one, we use automated tools, including AI providers, to sort the report's findings, estimate repair costs and record details of the home's systems. Later, when you sign in and agree, Johnni uses those recorded details to set up the Home Profile in your account.
5.4 Human review
Submissions and the conversation-review archive described in Section 2.7 may be reviewed by a member of our team for quality assurance, abuse detection, customer-support requests, or to investigate a reported issue. Where a human reviews your submission, the reviewer is bound by confidentiality obligations and accesses only what is necessary for the stated purpose.
5.5 Automated decisions
No Service produces a fully automated decision with legal or similarly significant effect on you. AI output is informational. You decide whether and how to use it.
6. Third-party processors
We use the following processors to operate the Services. Each is bound by a contract or terms requiring confidentiality and limited-purpose processing:
| Processor | Purpose | Region |
|---|---|---|
| Google Firebase (Authentication, Firestore, Cloud Storage, Cloud Functions, Cloud Messaging, Crashlytics) | Account sign-in, app database, notifications, file storage, crash diagnostics | USA |
| Google Cloud Run, Cloud Storage and Cloud Tasks | Hosting our photo-analysis and report-reading services; storing photos and reports | USA |
| Google Cloud Vertex AI | Image similarity for photo analysis (finding reference examples) | USA |
| OpenAI | AI analysis of photos, appliance plates and questions; voice transcription and spoken responses | USA |
| Anthropic | AI-assisted reading of inspection reports, including sorting findings and recording details of a home's systems | USA |
| Homespy | Appliance age lookup from make, model and serial number (Age Finder) | USA |
| Supabase | Database for the photo-analysis service | Canada (Montreal) |
| Sentry (where enabled on backend services) | Server error monitoring and diagnostics | USA |
| Apple (App Store, APNs) | App distribution, iOS push notifications | USA / Canada |
| Google (Play Store) | App distribution, Android push notifications | USA / Canada |
| SendGrid (Twilio) | Email delivery | USA |
| GloboTech Communications | Hosting for our inspection-reporting platform and the johnni.app website | Canada (Montreal) |
Our inspection-reporting platform, through which inspectors deliver reports, is operated by us; it is not a third party.
We may add or change processors. We will update this list when we do.
7. Sharing your information
We do not sell your personal information. We share information only in the following circumstances.
7.1 With service providers
Our processors (Section 6) access information solely to provide services on our behalf.
7.2 With people you choose
- The inspector who invited you to the App. This is optional. If you were invited, the first screen after you sign in asks whether to share, and nothing is shared with them before you answer. If you choose to share, the person who invited you can see: your name, email address and phone number, when you joined, when you last used the App, and which tools you used and when (for example, that you checked a photo or an appliance's age, and for the Age Finder the make, model and serial number you scanned). They cannot see your inspection report, your home profile, your conversations with Johnni, your photos, or the results of any analysis. You can change your answer at any time in Menu, Profile, Privacy choices; when you turn sharing off, we remove your details from their view. Your choice does not change the branding you see or your access to the App. Separately, we are told when someone joins through an invitation, so that we can support the inspector.
- A trade you ask us to contact: when you send a request for a quote, the trade receives what the request screen shows you: the request text (which you can edit), the finding it concerns, up to four photos you attach, your email address, and, if you add them, your phone number and a time to call. The trade also receives your city and, where your home profile has them, the home's type, year built and the make and model of the system concerned. Your street address is not sent. When you tap a phone number or a website, your device places the call or opens the site; we do not send your profile to the trade. Trades listed in the directory are independent third parties, not our employees or agents. What a trade does with your information is governed by its own privacy practices, not by this Policy.
- A partner offer (Savings): opening an offer takes you to the partner's website. We send the partner nothing about you.
- Recipients of a shared report or estimate: the report or estimate contents, to the address you enter. A repair estimate you email is also copied to our support mailbox.
7.3 For business transitions
If we are acquired, merged or reorganized, your information may be transferred to the other party as part of that transaction, as the law permits. Before any information is disclosed for a proposed transaction, the other party must agree to use it only for the transaction and to protect it. After a transaction, your information may be used only for the purposes for which it was collected, under this Policy or one that protects you at least as well. A new owner would need your consent for new purposes, including new marketing.
7.4 For legal reasons
We may disclose personal information when we reasonably believe disclosure is required to comply with a law, court order, subpoena or regulatory request; to protect the safety of any person; to investigate fraud or security incidents; or to enforce our Terms.
7.5 De-identified and aggregate data
We may share de-identified or aggregated information (which cannot reasonably be used to identify any individual) for research, analytics, marketing and industry reporting. We will not attempt to re-identify de-identified data and we will require any recipient to commit not to re-identify it.
8. How long we keep information
We retain personal information only as long as needed for the purposes for which it was collected, plus any period required by law. We may retain longer if needed to comply with law, defend legal claims, or detect and prevent fraud.
| Data type | Retention period |
|---|---|
| Account profile (name, email, phone) | Duration of account. Removed from production systems when the account is deleted (Section 9.2 and "System backups"). |
| Photos uploaded for analysis, and the results | Duration of account; deleted with it. |
| Inspection reports delivered through our platform | Kept by the inspector's platform account under the inspector's own retention rules and the inspection agreement between you and the inspector. Ask your inspector for a copy at any time. |
| Inspection reports you uploaded | Duration of account; deleted with it. |
| Customer-support correspondence | 3 years after resolution. |
| Raw Johnni microphone audio | Processed for the voice interaction; not intentionally retained in our application database. Provider retention is described in Section 5.3. |
| Johnni conversation quality-review copies | 90 days, followed by deletion in the daily cleanup cycle; account-deletion and legal exceptions apply. |
| Reports about AI answers | Duration of account; deleted with it. |
| The home's record (Section 2.11) | Deleted with your account unless a new owner holds it. A record nobody holds is deleted 7 years after the last activity on it, by a weekly cleanup. |
| Temporary live-session transcript and context | Removed when the session ends or expires; a technical session record (times and counts, no content) remains for operational and abuse-prevention purposes until account deletion. |
| Recent Johnni conversation history on your device | Limited recent-chat history until you clear it, it is replaced by newer conversations, or app data is removed; device backups may retain copies. |
| Crash logs and diagnostic data | Firebase Crashlytics keeps crash reports for 90 days. |
| System backups | Our app database is backed up every day (each copy kept 7 days) and every week (each copy kept 12 weeks). A file deleted from our file storage can be restored for 7 days, after which it is erased. |
| Marketing-consent records | 3 years after consent withdrawn (Canada's Anti-Spam Legislation). |
When data falls out of retention, we delete it from production systems. A copy in a backup is erased when that backup reaches the end of its retention period. We keep a record of each account deletion (the account identifier and date, no personal details) so that if we ever restore from a backup, accounts deleted since that backup are deleted again before the restored data is used.
9. Your rights
Under PIPEDA, PIPA BC and other applicable privacy laws you have the right to:
- Access: request a copy of the personal information we hold about you;
- Correct: ask us to correct inaccurate or incomplete information;
- Delete: request deletion of your account and information, subject to the retention exceptions in Section 8;
- Withdraw consent: opt out of marketing, push notifications or specific processing activities, subject to legal and contractual restrictions;
- Port: request your information in a structured, commonly used format where technically feasible;
- Complain: escalate to a privacy regulator if you believe we have not complied with our obligations.
9.1 How to exercise your rights
In the App: go to Menu, Profile to update your profile, manage privacy choices and delete your account. Notifications are managed in your phone's settings.
By email: send a written request to hello@johnni.app with the subject "Privacy Request" and include enough information for us to verify your identity (name, email associated with the account, and the nature of your request).
Response timing: we acknowledge requests within 10 business days and provide a substantive response within 30 calendar days, except where the law permits an extension.
9.2 Account deletion
You can delete your account in two ways:
- In the App: go to Menu, Profile, Delete My Account. We will ask you to confirm.
- By email: write to hello@johnni.app with the subject "Delete My Account" from the email address associated with your account.
What deletion removes. When you confirm in the App, the following is deleted at once from our production systems, before your sign-in is removed; a step that cannot complete is recorded and sent to our support team, who finish it by hand within 30 days:
- Your profile (name, email, phone, avatar) and your sign-in;
- Photos you sent for analysis and the results, including the copies kept by the photo-analysis service, and any copy of an appliance plate you scanned that was kept as a reference example;
- Inspection reports you uploaded yourself, with the findings read from them and their page images, unless you shared one with someone who still holds it;
- Your Home Profile and the home's record, with its notes and photos, unless you handed the home to a new owner (Section 2.11);
- Your conversations with Johnni, the quality-review copies, records of voice sessions, and reports you made about AI answers;
- Your details from the view of the person who invited you, and the invitation records that link you to them;
- Notification registrations and in-App messages.
What we cannot delete this way: records held by the trades, partners or people you chose to share with (Section 7.2), and the items below.
What may be retained, and why:
- An inspection report your inspector delivered through our platform: it stays in the inspector's platform account under their retention rules and the inspection agreement between you and the inspector. Deleting your Johnni account removes it from your account; it does not delete the inspector's copy.
- A home's record you handed to a new owner (Section 2.11), which that owner now holds;
- Records of the analyses the photo service ran (times, categories, which reference examples were shown), kept for reliability review;
- De-identified and aggregated analytical data: indefinitely, with personal identifiers removed;
- System backups: until each backup reaches the end of its retention period (Section 8).
Inactive accounts. If you do not sign in for 24 months, we may treat your account as inactive and, on notice to your last-known email, delete the account in accordance with this Section.
9.3 Promotional messages
You can stop promotional messages at any time. Every promotional email has an unsubscribe link, and most mail apps show their own unsubscribe button; either one takes effect at once and stops all of our promotional email to that address. You can also write to hello@johnni.app; we act on a written request as soon as we can and within 10 business days. We will continue to send the service messages described in Section 3(c).
10. Children
The Services are not intended for, and we do not knowingly collect personal information from, anyone under 19 years of age (the age of majority in British Columbia). If you believe a person under 19 has provided us with personal information, please contact hello@johnni.app and we will delete the account.
11. International transfers
Several of our processors (Section 6) operate outside Canada, including in the United States. When your personal information is processed outside Canada, it is subject to the laws of the country where it is processed, including legal requirements to disclose information to that country's government, courts or law-enforcement authorities. We use contractual and technical safeguards to protect information during international transfer.
By using the Services, you consent to this cross-border transfer.
12. Security
We implement administrative, technical and physical safeguards designed to protect personal information against loss, theft, unauthorized access, disclosure, alteration and destruction, including TLS encryption in transit; at-rest encryption for files in Google Cloud Storage and Firebase; token-based and signed access for sensitive APIs; role-based access controls and the principle of least privilege for staff; and logging and monitoring of access to our systems.
No system is completely secure. We cannot guarantee that information will never be accessed or disclosed in violation of this Policy. Your home profile is available only through your signed-in account and is never published, but it is not kept only on your device: it is stored in our systems and, when you use AI features, sent to the providers in Section 6.
13. Data breach notification
If a breach of security safeguards creates a real risk of significant harm to you, we will notify you and the Office of the Privacy Commissioner of Canada (and, where applicable, the Office of the Information and Privacy Commissioner for BC) as required by PIPEDA and PIPA BC. We will also keep records of all breaches as required by law.
14. Cookies, analytics and tracking technologies
14.1 The johnni.app website
johnni.app sets no cookies and loads no analytics, advertising or tracking tools. Its only form, for inspectors who want to offer Johnni, opens your own email program with the details you typed; nothing is sent to us until you send that email.
14.2 In-App storage
In the App, device-local storage (MMKV, the iOS Keychain and Android SharedPreferences) holds your session token, your cached profile, your AI permission answer and your preferences. It does not transmit anything to third parties.
14.3 Analytics, crash reporting and SDKs
The App uses Firebase Crashlytics to diagnose crashes and application errors. Reports can include stack traces, device, OS and app information, installation identifiers, diagnostic logs and the signed-in account's user ID, so diagnostics may be linked to your account. Firebase normally retains Crashlytics crash information and associated identifiers for 90 days before starting removal from live and backup systems. Our backend services may use Sentry for server error monitoring. These tools are used for reliability and support, not cross-company advertising tracking.
Firebase Cloud Messaging also processes installation and push identifiers and delivery diagnostics to provide notifications. Material changes to collection or purpose will be reflected in this Policy and, where required, a consent notice.
14.4 Cross-app tracking
The App does not track you across other apps or websites for advertising, and does not contain advertising tools. On iOS, we do not request App Tracking Transparency permission.
15. Changes to this Policy
We may update this Policy from time to time. We will tell you about material changes through the App, by email, or by notice on johnni.app at least 14 days before they take effect. Where a change introduces a new purpose for which the law requires consent, we will ask for your consent; continuing to use the Services is not consent to a new purpose.
16. Contact and complaints
Privacy questions, requests or complaints: hello@johnni.app
Johnni
If you are not satisfied with our response, you may contact a privacy regulator:
- Office of the Privacy Commissioner of Canada: priv.gc.ca, 1-800-282-1376
- Office of the Information and Privacy Commissioner for British Columbia: oipc.bc.ca, 1-800-663-7867
- For users elsewhere in Canada, the privacy regulator of your province or territory.
