Privacy Notice
Jr. Studio is a local desktop creation tool ("Jr.," "we," or "us"). This notice explains what Jr. handles, what stays on your computer, and what leaves it when you choose to use an AI provider, check for updates, or contact us.
The short version
- Jr. has no Jr. account system and does not operate project storage or sync.
- Your projects, images, prompts, activity, versions, and settings are stored on your computer.
- When you ask Claude Code or Codex to work on a project, the official provider CLI can send your request and project context to that provider under your provider account.
- Jr. does not include background analytics, advertising, or automatic crash reporting, and it does not upload your projects to Jr.
- Jr. can prepare a beta report locally. Nothing is sent unless you review and deliberately copy or email that report.
- Jr. keeps a small rotating technical log on your computer for up to seven days. It is never uploaded automatically; you can review and edit a support report before choosing to copy or email it.
- Software and starter-catalog checks make ordinary HTTPS requests. The hosting providers may receive standard request data such as IP address, time, app version, platform, and user agent, but Jr. does not add an account, project, prompt, or installation identifier.
- If you request a private-beta invitation on getjr.app, Jr. Cloud stores the email address and limited invitation activity described below. This signup is separate from the local Studio app and does not upload app or project data.
Who this beta is for
The Beta is a general-audience evaluation product for an adult account holder. You must be at least 18 to accept the Beta Terms. Household use by another person, including a minor, must be supervised by the adult account holder.
Jr. does not ask children to create an account or submit personal information to Jr. If you supervise household use, review prompts and project content before they are sent to an AI provider.
Information stored locally
Depending on the features you use, Jr. stores the following in its application data directory on your computer:
- project text files and project-local PNG or JPEG images;
- prompts, activity messages, provider results, preview health, and file-change summaries;
- project versions, snapshots, transaction recovery journals, and exported files you choose to save;
- language, preview, provider, daily-run-limit, onboarding, and legal-acceptance settings;
- provider readiness and usage summaries reported by locally installed CLIs;
- verified starter-catalog files and update-check timestamps;
- if you enable a Workspace Rules PIN, a one-way verifier rather than the PIN itself; and
- a rotating local diagnostics log containing app, update, provider-readiness, and sanitized error events, limited to five one-megabyte files and seven days.
This information is available to people and software that can access your macOS or Windows account or backups. Jr.'s PIN is a shared-screen control; it is not encryption and does not protect data from the owner of the logged-in account.
AI providers
AI use is optional. Demo and non-AI creation features work without connecting an AI provider.
When you explicitly run Claude Code or Codex, Jr. starts the provider's official CLI in a staged copy of your project. The provider can receive your prompt, relevant project and starter context, and the project files that its CLI reads while completing the request. The provider processes that information under your account, its terms, and its privacy choices. Jr. does not control the provider's retention, training, or account administration.
The official CLI holds its own credentials. Jr. checks local login/readiness information and may pass an API key already present in your process environment to that same provider CLI, but Jr. does not extract, copy, upload, or store your provider OAuth token. API-key use may create pay-as-you-go charges directly with the provider.
Provider references:
Software and starter updates
Packaged versions of Jr. may check the public release origin for software updates and the public catalog origin for signed starter updates. Those checks do not include Jr. account data, project files, prompts, an installation ID, or analytics events. They necessarily disclose ordinary network information to the hosting providers, including your IP address and request metadata. The request may also identify the installed app version and platform so the correct update can be returned.
Jr. may use GitHub and GitHub Pages to host these public files. Their handling of request logs is governed by their own terms and privacy notice. Jr. does not use those requests to build individual usage profiles. Server operators may retain short-lived security and operational logs supplied by the hosting service.
Support messages
If you email us, we receive the address and content you choose to send. Please do not send provider credentials or project content that you do not want included in a support conversation. We use support messages to respond, troubleshoot, protect the Beta, and keep necessary records of the conversation.
Private-beta invitation requests
If you request an invitation on getjr.app, we collect the email address you enter, your selected reply channel and page language, the referral label in the link you followed (for example, an X post or direct message), request times, and a random personal invitation token. When you open the personal invitation or click a Mac or Windows download button, we record that event, its time, and the selected platform. A download click does not prove that the file finished downloading, was installed, or was used.
We use this information only to send and operate the invitation, understand which outreach brought beta requests, prevent abuse, provide support, and follow up for beta feedback. It is not added to a newsletter or used for advertising or background product analytics. The signup service does not receive projects, prompts, app activity, an installation identifier, or AI provider account information.
Invitation records and email-delivery jobs are stored in Google Cloud and Firebase. The signup endpoint also receives ordinary network information such as IP address and request metadata. It converts the address into a short-lived, salted rate-limit value rather than storing the raw address in the beta participant record. Email delivery uses our configured mail provider.
If you choose WhatsApp, the site first records the invitation request and then opens a prepared WhatsApp message containing the email address and personal invitation link. Nothing is sent to us in WhatsApp until you choose to send that message. Meta and WhatsApp process the message and ordinary connection data under their own terms and privacy notice.
Optional beta reports
Workspace Rules can prepare a beta report from information already stored on your computer. It contains the Jr. version, platform and language, starter and project counts, aggregate AI-run results, aggregate project-change counts, and the number of days with recorded project activity during the previous 14 days. It does not contain prompts, project names, filenames, content, paths, account details, error messages, exact activity times, or a device or installation ID.
The complete report is shown before sharing. Jr. does not upload it. You may copy it or ask Jr. to open your mail app with a message addressed to support@getjr.app. The report and your email address reach us only if you send that message.
Optional diagnostic reports
After a failed or no-change AI run, Jr. can prepare a diagnostic report for that specific outcome. It contains the exact builder prompt and recorded provider error or result, the run mode, failure type, time and duration, starter type, Jr. and starter-catalog versions, platform and language, and the selected provider's CLI version, authentication method, and readiness state. Outside the exact prompt and provider result, Jr. does not add the project name or ID, project files or filenames, account details, credentials, absolute paths, provider conversation IDs, or a device or installation ID. The prompt, error, or provider result may itself contain information you entered or the provider returned.
The complete diagnostic report is shown in an editable field so you can review the prompt and provider result and remove anything you do not want to share. Jr. does not upload it. You may copy it or open a prepared message in your mail app. The report and your email address reach us only if you send that message.
Local support diagnostics
Jr. records a small rotating diagnostics log on your computer so a launch, update, provider, or interface problem can be investigated after it happens. The log contains times, the Jr. version, broad system and language information, update state, provider name/readiness and CLI version, aggregate project/version counts, and sanitized error categories. It does not intentionally record prompts, project names, project files or content, credentials, email addresses, provider conversation IDs, stable device or installation IDs, or the name in your home-folder path. Error details are shortened and common secrets and identifiers are removed before writing.
The log stays in Jr.'s application data, is limited to five one-megabyte files, and entries older than seven days are omitted from reports. Choose Copy Support Diagnostics from the app menu or preview the editable report in Workspace Rules. Jr. never uploads the log or report automatically. It reaches us only if you deliberately paste or send it.
No background analytics
Jr. does not include background product analytics, behavioral telemetry, advertising tracking, automatic crash reporting, cloud sync, or Jr.-hosted project upload. We may learn from feedback, beta reports, and diagnostic reports you deliberately send. GitHub may expose aggregate download counts for release files; those counts are not users or unique installations. Jr. does not add a tracking identifier to update or catalog requests or build individual usage profiles.
Retention and deletion
Local information remains until you delete projects, versions, exported files, or Jr.'s application data. Diagnostics rotate automatically as described above. Removing the application alone may not remove its application data or your exports. macOS or Windows backups may retain copies according to your backup settings.
Provider data and support email are retained under the relevant provider's policy or as reasonably needed to answer and document the support request, protect the Beta, and comply with legal obligations. You may ask about a support message by contacting us.
Private-beta invitation records are kept while the private beta is active and for a reasonable period afterward to operate invitations, understand feedback, prevent abuse, and keep necessary program records. You may ask us to delete your invitation record or stop contacting you by writing to the addresses below.
Security and international processing
Jr. uses local request authentication, staged project mutations, project-file rules, preview network restrictions, and signed release mechanisms described on the Safety page. No security control is perfect. Provider and hosting requests may be processed outside Israel under those services' policies.
Changes
We may update this notice as the Beta changes. The effective date and Terms version on the generated page identify the published edition. A material change to the Beta Terms requires renewed acceptance in the app.
Contact
Privacy and legal questions: legal@getjr.app
Product support: support@getjr.app