Legal
Privacy Policy
Last updated: [DATE]
Draft pending legal review. This text is not final.
Contents
Journey helps you understand and manage your compensation, benefits, and equity. Most people use Journey through their employer, which pays for the service under a separate agreement. This policy explains what information Journey collects, how we use it, who receives it, and the choices you have. It covers our websites and our products, including JIVA, our AI agent.
If your employer provides Journey to you, we handle some information on your employer’s behalf under our agreement with them — generally, the information your employer provides. Information you add personally is Journey’s responsibility, handled as described in this policy.
Information we collect
From your employer and its systems. When your employer connects Journey to its HR, payroll, benefits, or equity systems, we receive information such as your employment details, salary and bonus, equity grants and vesting, benefits eligibility and elections, and retirement plan data.
From you. Your account details, the questions you ask JIVA, documents you upload, household or dependent information you choose to add, your goals, and financial accounts you choose to connect.
Connected financial accounts. If you connect a bank, investment, or loan account, we use data aggregation providers — [currently Plaid Inc.; add MX and Finicity or Yodlee as each actually ships, with a link to each named provider’s end-user privacy policy] — to link it. You can also connect your own equity accounts [e.g., Carta — name and link when the employee-side connection is live]. Journey receives read-only account, transaction, investment, liability, and equity data. We never receive your account credentials, and Journey cannot move money or transact through these connections. Anything you connect personally — including equity from previous employers — is personal-side information under “What your employer can and cannot see” below.
Automatically. Device information, log data, and usage information, including through cookies and similar technologies on our sites.
How we use information
We use your information to operate Journey: to answer your questions, generate explanations and comparisons, surface deadlines, personalize what you see, provide support, secure the service, improve it, and comply with law.
AI processing. Journey uses third-party AI model providers to generate outputs. These providers process your data to deliver the service and are contractually restricted from using it for other purposes. We do not permit our AI providers to train their models on your data. [CONFIRM: verify current provider API terms and any zero-retention configuration before publishing this sentence.]
We do not sell your personal information. [CONFIRM against CRM/analytics setup and applicable state-law definitions of “sell” and “share.”]
Who receives information
Service providers. Companies that help us run Journey — hosting, authentication, data integrations, AI model providers, email delivery, analytics, and support tooling — under contracts limiting their use of your data. [Full subprocessor roster to live at /legal/subprocessors when published; do not enumerate vendors here.]
Your employer. Only as described in the next section.
Professionals. If you engage an expert through Journey, we share what is needed for them to help you, and their handling of your information is subject to their professional obligations.
Legal and corporate. When required by law or legal process, to protect rights and safety, or in connection with a corporate transaction, subject to this policy.
What your employer can and cannot see
This is the most important promise in this policy, so we want it to be precise.
Your employer can see what it already has: the information it provides to Journey — your compensation, your equity from that employer, your benefits — and anything you choose to send it through Journey, like reporting a qualifying life event to change your health plan. Nothing you report is transmitted to your employer unless you explicitly submit it.
Information you add personally — connected financial accounts, your questions to JIVA, personal goals, household details — is not shared with your employer. Your employer cannot access, view, or recover your account: it belongs to you, and it is anchored to your personal email when you use Journey’s personal features. We may disclose information where required by law.
[REMAINING DECISION — Raffaello + Tiago: (a) whether employers ever receive aggregated, de-identified insights, and if so, minimum thresholds and a disclosure sentence here; (b) Journey staff support-access scope and logging; (c) engaged-expert access scope. Complete the visibility matrix for counsel, with rows grouped by the three data-source classes — (1) employer-provided, (2) employee-connected (Plaid/MX/Finicity, personal Carta), (3) employee-provided (goals, household, questions, documents) — across columns employer / staff / expert / aggregate. The class also drives the controller vs. service-provider analysis: service provider for class 1, controller for classes 2–3. Include the dual-provenance test case: the same grant arriving via employer Carta issuer sync AND the employee’s personal Carta connection must reconcile without leaking across the boundary, and the personal provenance is what keeps the record alive post-separation. Locked invariants: employer pipe one-directional; life events private by default, transmitted only on explicit employee submission; account never employer-recoverable; employer never sees that a household link exists; employer never sees personally connected equity, including prior-employer grants.]
When you leave your employer
Your Journey account belongs to you, not your employer, and your employer can never access or recover it. If your employer’s sponsorship ends, you can keep using Journey with a personal account: your personal data and your own records stay with you.
[REMAINING MECHANICS — Raffaello + Tiago: which employer-sourced records remain visible to you after separation (intended: your own grants, elections, and history — requires the MSA clause in counsel notes); which employer-paid features end; what happens to employer-connected integrations; account conversion flow for users who signed up with a work email only; retention periods per category.]
Retention
We keep information for as long as needed to provide the service, meet legal and tax obligations, and resolve disputes, then delete or de-identify it. [DECISION: retention schedule per data category from Tiago; state concrete periods where practical.]
Your rights and choices
You can access and correct your information, disconnect a linked financial account at any time, request deletion of your account and personal data, and opt out of marketing email. For information your employer provides, we may need to act on your employer’s instructions or direct your request to your employer. Depending on where you live, you may have additional rights under applicable privacy laws; contact us to exercise them. [COUNSEL: align this section with Journey’s controller/service-provider roles per data category; state-law applicability and any required state-specific disclosures; whether a rights-request mechanism beyond email is needed.]
Security
We use encryption, access controls, and monitoring to protect your information. More detail is on our Security page. No system is perfectly secure; notify us immediately at security@usejourneywealth.com if you suspect a problem.
Children
Journey is a workplace service and is not intended for use by children. Adults may provide information about dependents, including children, when relevant to benefits or other Journey features. [COUNSEL: age threshold language and COPPA analysis for adult-provided dependent data.]
Changes to this policy
We may update this policy as our services and the law change. If changes are material, we will notify you. The date above reflects the latest revision.
Contact
legal@usejourneywealth.com Journey Technologies, Inc., [address]