Privacy policy
Your trip is personal.
Jurn uses booking evidence to build and maintain your trip. We do not sell your data, use it for advertising, or make private documents public by default.
Updated 9 September 2026
Who is responsible
Jurn is a product operated by JMN Ventures. JMN Ventures is the controller of personal data processed through the Jurn private beta offered in Denmark.
CVR 46561708
Bentzonvej 42, 1. tv
2000 Frederiksberg, Denmark
support@hellojurn.com
What we collect
| Category | Examples | Why |
|---|---|---|
| Account information | Name, email address, user and device identifiers | Sign-in, account security, support, and keeping your data scoped to you. |
| Website visits and contact | Technical connection information; your email address and any message you choose to send us | Delivering and protecting the public website, answering questions, and responding to early-access requests. |
| Booking evidence | Forwarded email text, sender details, PDFs, images, calendar files, and selected attachments | Extracting supported travel facts, preserving provenance, resolving uncertainty, and showing your original proof. |
| Trip information | Routes, dates, times, operators, traveler count, booking references, actions, corrections, and review decisions | Building and maintaining your private trips. |
| Operational information | Request identifiers, bounded performance and error data, aggregate parser outcomes | Keeping the service reliable, secure, and understandable without reading raw content for routine monitoring. |
| Optional device inputs | A photo or file you choose; location used for an on-device travel estimate | Adding a confirmation or estimating a route you explicitly request. Precise location is not uploaded by Jurn. |
How booking evidence is handled
- Tracking markup and executable email content are removed.
- Files are read locally first using native document readers and bounded OCR. Original file pixels are not sent to OpenAI.
- Recognizable payment cards, bank accounts, identity numbers, credentials, access codes, and loyalty numbers are removed before AI processing. Jurn does not need them.
- Identity documents, medical documents, unreadable files, and uncertain file types stay private and are routed to manual review instead of AI processing.
- Only locally filtered text is read by deterministic software and, when needed, the OpenAI API to identify travel facts.
- Evidence-backed facts may be proposed. Ambiguous, conflicting, or unsupported facts are withheld for review.
- Original proof stays private and is linked only to the journeys it supports.
OpenAI states that API data is not used to train its models by default. Under OpenAI's default API controls, abuse-monitoring logs may retain limited request content for up to 30 days. Jurn therefore sends only locally filtered text and does not send original files or image pixels.
Why we process it
| Purpose | Legal basis |
|---|---|
| Account access, booking evidence, trips, review, proof, and user-requested sharing | Necessary to provide the service and perform our agreement with you. |
| Limited companion details contained in a shared booking | Our legitimate interest in organizing the booking requested by the account holder, balanced against the companion's privacy rights. |
| Optional mailbox access or device inputs | Your requested action and, where required, your consent. You can disconnect mailbox access or withdraw consent. |
| Security, abuse prevention, reliability, and support | Our legitimate interests in operating and protecting the service, balanced against your rights. |
| Legal compliance and legal claims | Compliance with legal obligations and our legitimate interest in establishing, exercising, or defending legal claims. |
You are not required by law to provide booking evidence. Without an email address, we cannot create or secure an account. Without booking evidence or manually entered trip facts, Jurn cannot build the corresponding trip.
Data about other travelers
A confirmation may include the name or booking details of a companion because one person booked for several travelers. Use Jurn only for evidence you are entitled to manage. We use companion information only to organize the submitted booking, do not create an account for that person, and do not use it for advertising. A companion may contact us to exercise their data-protection rights. We minimize these details and do not infer traveler identities from ticket count, seat count, room count, or filenames.
Automated extraction
Jurn uses software and, when needed, an AI model to propose facts from booking evidence. The app identifies uncertain evidence for review and lets you correct or dismiss it. It does not make decisions that produce legal or similarly significant effects solely by automated means. The source, accepted facts, withheld facts, and your corrections remain distinguishable.
Service providers
Jurn uses a limited set of processors to operate the beta:
- OpenAI for supported semantic extraction from locally filtered booking text.
- OpenAI Sites for hosting the public website, including these privacy, terms, and support pages. This is separate from booking extraction.
- Cloudflare for public website delivery and security, and for forwarding support emails to our company mailbox.
- Railway for application, database, and private-file hosting.
- Expo and Apple for building and distributing the mobile application and notifications.
- Resend for login emails and inbound email routing.
- Microsoft only if you separately authorize an Outlook connection.
These providers may process information outside your country. We use their contractual and transfer safeguards where required.
Device storage and tracking
Jurn does not use advertising or marketing trackers. The app and website may use technically necessary device storage for sign-in, security, preferences, and offline access to data you have already requested. If we introduce non-essential analytics or another tracking purpose, we will explain it and request any consent required before enabling it.
Retention
- Settled pipeline copies of raw email content are scheduled for deletion after 30 days.
- Original confirmations, attachments, and structured trip data remain until you delete them or delete your account.
- Sessions normally expire after 30 days. One-time login links expire after 15 minutes and cannot be reused.
- Operational logs are minimized and protected by redaction. We do not intentionally log booking content.
- Encrypted backups, when present, age out according to the hosting provider's backup schedule and are used only for recovery.
Sharing
Trips are private by default. If you create a public itinerary link, recipients receive only the included route and schedule facts. Public responses exclude booking references, seats, notes, private places, tasks, documents, raw evidence, and information about which journey holds proof. Deactivating the link stops public access.
Your choices and rights
- Correct trip facts inside the app. Your correction takes priority over weaker later evidence.
- Disconnect a mailbox without deleting your trips.
- Delete documents, trips, or your complete account. Account deletion is available in Profile and removes the data and files owned by the account from the active service.
- Ask for access, correction, a portable copy, restriction, objection, or deletion by emailing us. Automated export is not yet available, so export requests are handled manually during beta.
- Withdraw consent where consent is the basis. Withdrawal does not affect earlier lawful processing.
- We normally respond to a rights request within one month. We may ask for information needed to verify your identity.
- Complain to Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, Denmark, or another competent data-protection authority.
Security and limits
Hosted booking content, tokens, and private files are access-controlled; sensitive source content and provider credentials are encrypted at rest. No system is perfectly secure. If we learn of a material incident, we will investigate, contain it, and notify affected people or authorities when required.
Children
Jurn is available to people of every age and does not impose an age gate. We do not collect a birth date merely to determine access. Children receive the same private-by-default controls, data minimization, review, correction, deletion, and support rights as every other user. We do not use a child's data for advertising or behavioral profiling.
A feature that depends on consent or another authorization under applicable law will be enabled only when that requirement is met. Privacy information and review choices intended for younger users will be written in clear, age-appropriate language.
Changes
On 9 September 2026, we updated the product name, contact address, and website and support-provider information. JMN Ventures remains the data controller.
We will update the effective date and explain material changes here. If a change materially alters how existing data is used, we will provide additional notice before it takes effect.