Effective August 13, 2026
Privacy Policy
This policy explains how Juno AI Labs handles personal information when people visit our sites, use Avalon, connect other services, or contact us.
1. Scope and our role
This Privacy Policy applies to Avalon’s websites, desktop application, workspace services, automations, support, and related interactions. It does not govern third-party services you choose to connect.
Juno AI Labs is a controller for account, website, support, security, and service-administration information. When an organization uses Avalon to process personal information in workspace content, Juno generally acts as its processor or service provider and follows that organization’s documented instructions. In that case, direct requests about workspace content should first go to the organization that controls the workspace, and our Data Processing Addendum applies.
2. Information we collect
| Category | Examples | Source |
|---|---|---|
| Account and workspace | Name, email, avatar, organization, role, membership, region, invitations, authentication metadata | You, your administrator, identity provider |
| Customer Content | Prompts, messages, files, work streams, task history, artifacts, automation definitions and results, feedback | You, workspace members, automations |
| Connected-service data | Authorization metadata and bounded content requested from Google services, GitHub, Linear, Notion, Slack, web pages, webhooks, or email | Services you authorize |
| Product and device | Feature interactions, application version, operating system, device preferences, timestamps, diagnostics, request IDs | Your device and use |
| Security and audit | Sign-in and session events, member changes, connector authorization and revocation, external writes, automation activity, IP address, user agent | Your use, our systems |
| Communications | Support messages, privacy requests, survey responses, and related correspondence | You |
Connector credentials are encrypted and are not included in model prompts. We do not intentionally collect payment-card details directly; a payment provider may handle them if paid plans are offered.
3. Slack data
Avalon’s workspace bot joins public Slack channels so members can mention it consistently and may receive bounded Slack activity for Agent conversations and configured automations. Avalon does not scrape, mirror, or recreate Slack as a parallel inbox, channel browser, history store, or generally searchable index. Slack-derived trigger evidence and content may remain inside an Avalon task, automation, summary, artifact, provenance record, or tool receipt when needed to perform or explain requested work. Personal Slack tools act with the authorizing user’s Slack permissions.
Disconnecting a workspace Slack installation revokes the installation credentials Avalon holds and disables routing. A Slack administrator must separately remove Avalon in Slack App Management to uninstall the app. Disconnecting a personal connection revokes that user credential. These actions stop new access but do not delete existing Avalon resources containing Slack information.
4. How and why we use information
- Provide the Services: create accounts and workspaces; carry out prompts and automations; retrieve user-directed context; generate output; perform tool actions; synchronize state; and provide support.
- Secure the Services: authenticate users, enforce permissions, prevent abuse and fraud, debug incidents, protect connected credentials, and maintain audit records.
- Operate and improve: understand reliability and feature performance, repair errors, and improve workflows. We do not use Customer Content to train our own general-purpose model.
- Communicate: send transactional notices, invitations, service updates, and responses to requests.
- Comply and protect: meet legal obligations and establish, exercise, or defend legal claims.
Where law requires a legal basis, we rely on performance of a contract, our legitimate interests in operating and securing Avalon, consent where requested, and compliance with law. You may withdraw consent at any time, without affecting earlier processing.
5. AI and model providers
To perform requested work, Avalon sends bounded task context to model providers through configured inference services. Context can include prompts, relevant Customer Content, tool results, and instructions. We minimize the context to what the authorized task needs and do not put connector tokens into prompts. Current providers are identified on our Sub-processors page.
Model providers process data to return results and secure their services under contracts with us. Provider-specific retention and deployment can vary. Workspace administrators should avoid placing unnecessary sensitive information in prompts and should configure connections according to their organization’s policies.
6. How we disclose information
We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We disclose information only:
- to infrastructure, model, email, and web-retrieval providers needed to deliver Avalon, listed as Sub-processors;
- to connected services and recipients when a user directs Avalon to read, create, update, send, or publish something;
- to workspace owners, administrators, and members according to workspace permissions;
- to professional advisers and transaction counterparties under confidentiality obligations; or
- when reasonably necessary to comply with law, protect rights and safety, or investigate abuse.
7. Region and international transfers
A workspace is created in a selected Global or EU region, and Avalon stores its workspace data in that architecture. Some providers, support operations, network services, and user-directed connected services may process information outside the selected region. Where required, we use recognized transfer safeguards such as the European Commission’s Standard Contractual Clauses and supplementary measures. Contact privacy@with-avalon.com for transfer documentation applicable to your deployment.
8. Retention and deletion
By default, task and automation content—including connected-service information used in those resources—has no automatic expiration and remains until an authorized user deletes the resource or the workspace is deleted. Workspace audit records are retained for the life of the workspace. Single-use Slack account-link challenges expire after 15 minutes.
Avalon-internal accepted product-event and delivery records expire within 90 days; minimized regional product-analytics contributions may be retained for up to 13 months. Global events delivered to PostHog are governed by our configured provider lifecycle. Local desktop telemetry is eligible for delivery for at most 14 days. See our Cookie & Tracking Notice for the public site's anonymous storage and regional behavior.
We retain account, billing, security, fraud-prevention, dispute, and legal records only as long as reasonably needed for those purposes. Deletion from active systems may not immediately remove information from encrypted backups; backup copies are isolated and expire through our normal rotation. We may retain de-identified information that cannot reasonably identify a person.
9. Your choices and rights
Depending on where you live, you may have rights to know, access, correct, delete, export, restrict, or object to processing; withdraw consent; and appeal a denied request. You may also complain to your local data-protection authority. We will not discriminate against you for exercising a privacy right.
Email privacy@with-avalon.com to make a request. We verify your identity and, for workspace content, your authority in the relevant workspace. Authorized agents may submit requests where law allows, subject to verification. We may retain information where an exemption applies.
Avalon does not sell or share personal information for cross-context behavioral advertising, so there is no sale or advertising-sharing opt-out needed. Our Cookie & Tracking Notice explains site signals and device storage.
10. Security
We use technical and organizational measures designed to protect information, including encrypted connector credentials, scoped workspace authorization, application hardening, request validation, audit events, and secret redaction. No system is completely secure. See our Security Policy for details and reporting instructions.
11. Children
Avalon is not directed to children under 18, and we do not knowingly collect their personal information. If you believe a child has provided information, contact us so we can investigate and delete it where appropriate.
12. Changes and contact
We may update this policy as Avalon and privacy law evolve. We will post the revised policy, change the effective date, and provide additional notice when required. Questions or requests can be sent to privacy@with-avalon.com. Support requests can be sent to support@with-avalon.com.