Last updated September 4, 2026
Privacy Policy
Overview
This Privacy Policy explains how Jinu ("Jinu," "we," "us," or "our") collects, uses, discloses, and otherwise processes your information when you use the Jinu website and mobile applications and related services (the "Jinu Service"). Jinu is designed to collect as little personal information as necessary. We do not sell or share your personal information for advertising, we do not use advertising networks or build advertising profiles, and we do not process payments between buyers and sellers. If you choose to share your device location, your device's reading is rounded on your device to roughly a one kilometre area before it reaches us, and we use that rounded figure to work out your city and to sort listings by distance; we do not track your location in the background and we do not build a location history. Section 02 explains exactly what happens to those coordinates. If you are a resident of a United States state with a consumer privacy law, please also see Section 08.
Information we collect
A. Information you provide
- Account information, such as your email address and, if you sign in with Google or Apple, the name and profile picture those providers return. Sign-in is passwordless, and we do not collect or store passwords. If you choose to verify a phone number, we also hold that number; Section 10 explains what we do with it and what we never do with it.
- Profile information you choose to add, such as a display name, username, biography, avatar, default location, and your notification and privacy settings.
- Listing content, such as titles, prices, categories, descriptions, the city you enter, photographs, and, for certain categories, structured details (for example, vehicle or property attributes and, for job posts, an application email and resume).
- Communications and activity, such as messages, offers, reviews, reports, and support requests.
B. Information we collect automatically
- Device and log information, such as your IP address, browser and device type, and access times.
- Approximate location, derived from the city you enter or inferred from your IP address. This is the default, and it is all we have unless you actively choose to share your device location.
- Usage information, collected with first-party analytics and cookies or similar technologies and, where product analytics is allowed, recordings of your own sessions with personal details masked (see Section 05).
D. Precise device location, only if you choose to share it
Some parts of the Jinu Service offer to fill in your location for you, for example the "use my location" control when you set your city, when you pick a location while posting, and when you search near you. These controls are optional and never run on their own. Your browser or phone asks your permission first, and you can refuse, and you can change your mind later in your browser or device settings. Browsing, posting, and messaging all work without ever granting it.
If you do grant it, we want you to know exactly what happens to the coordinates, because it is more than the city label you see afterwards:
- Your device produces a precise latitude and longitude, and we round it in your browser before it is sent, to about two decimal places, which is roughly a one kilometre area. We do not receive the exact reading.
- Those coordinates are sent to our maps and geocoding provider to convert them into a place name, and to draw maps. On the web this request currently goes directly from your browser, which means the provider also receives your IP address. We are changing this so the request is relayed by our servers instead, which removes that disclosure.
- The coordinates may be stored on your device so the Jinu Service remembers where you were browsing and you are not asked again on every page.
- The rounded coordinates may appear in the web address of a search-results page when you filter by distance. Web addresses are recorded in our ordinary server logs, so a rounded coordinate can appear there. Those logs are retained as described in Section 06.
- We do not attach coordinates to your account profile, we do not track you in the background, we do not keep a history of where you have been, and we do not use your location for advertising. A listing you publish shows the city you chose, not your device location.
Our mobile applications request only coarse, approximate location from the operating system rather than fine location. If you would rather share nothing at all, type a city name instead of using the location control.
C. Information from third parties
We receive limited information from sign-in providers when you choose to use them, and from data lookups used to complete a listing (for example, decoding a vehicle identification number or retrieving location context for a property). We do not obtain information from data brokers.
How we use your information
- To provide, maintain, and improve the Jinu Service, including creating your account and displaying and routing listings, messages, and offers;
- To keep the marketplace safe, including detecting and preventing fraud, scams, and abuse, and reviewing content;
- To process fees for publishing certain listings and to send you service and transactional communications;
- To comply with law and enforce our agreements; and
- To provide optional features you choose to use, such as artificial-intelligence drafting tools.
We do not use your information to target advertising to you or to build advertising profiles.
How and when we disclose information
We disclose your information only in these circumstances:
- With other users, when you post a listing or public profile or communicate through the Jinu Service. Your contact email is not displayed publicly.
- With service providers that process information on our behalf. These include providers that help us with website hosting and content delivery, database and file storage, identity and authentication, email delivery, text-message delivery, payment processing (Stripe), error monitoring, product analytics and session recording (PostHog, in the United States), rate limiting and abuse prevention, geocoding and maps, optional artificial-intelligence features, push-notification delivery, and customer support and help-centre hosting. They may use the information only to perform services for us. The categories are listed at Subprocessors, and a current list of the specific providers is available on request at privacy@jinu.app. Three of these deserve to be called out by name rather than by category, because of what is or would be sent to them:
- Photographs you submit to our artificial-intelligence features are sent to Google. When you use Quick Post, the photograph you take or upload is transmitted to Google's Gemini service so it can identify the item and draft a title, category, and description for you. If Google is unavailable the same photograph is sent instead to Groq, an alternative artificial-intelligence provider. Uploaded images are also sent to Hugging Face for automated adult-content scanning, which is a safety measure rather than an optional feature. Photographs can show far more than the item, including the inside of your home and the people in it, so please consider what is in the frame. These providers act as our processors, and each provider's own terms govern what it may do with the content we send it. You can avoid the drafting features entirely by writing your listing yourself; the safety scan runs on every uploaded image.
- Every photograph you upload is sent to Microsoft to be checked against known child sexual abuse material. The image is transmitted to Microsoft's PhotoDNA service, which compares it against pictures already identified as child sexual abuse material by Microsoft and by the child-protection organisations that contribute to its database. Microsoft states that it converts the image into a numerical signature for that comparison and does not retain the image; that is Microsoft's account of its own handling, and not something we can verify from outside. We first built this the other way round, computing the signature on our own servers so that only the signature would ever leave them, and we could not make it run: the component required to compute it will not load on our hosting, and the check sat switched off, examining nothing. We chose a check that runs over a promise that protected nobody. This is a different check from the adult-content scan described above, and it answers a different question: the scan judges a picture nobody has catalogued, while this one recognises material that has already been identified. Where an image matches, we refuse the upload, preserve the material and the surrounding record as evidence, and report it as United States law requires. Law-enforcement requests explains what happens next.
- Location coordinates are sent to our maps and geocoding provider, OpenStreetMap, to turn coordinates into place names and to render maps. See Section 02D.
- For legal and safety reasons, to comply with law, respond to lawful requests, enforce our agreements, or protect the rights, safety, and property of Jinu, our users, or the public. Law-enforcement and government requests go to legal@jinu.app, and Law-enforcement requests explains what legal process we require for which records, what a preservation request does and does not do, and when we tell you: Where legally permitted, Jinu may make reasonable efforts to notify the affected member before disclosure. A court order, a statutory non-disclosure provision or another legal restriction can prohibit that notice, and where one applies we do not give it.
- In a business transfer, such as a merger, financing, acquisition, or sale of assets.
- With your consent or at your direction, and in aggregated or de-identified form.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
Cookies and similar technologies
We use a small number of cookies and browser-storage keys to operate the Jinu Service, remember your preferences, and understand how the Service is used. We do not use advertising cookies or tracking pixels, we do not use any advertising networks or third-party ad or cross-site tracking technologies, and we never sell your personal information. The categories we use are:
- Strictly necessary, such as your Supabase sign-in and session cookies, a cross-site-request-forgery token, and load-related cookies. These keep you signed in and let the Service work, so they are always on and do not require consent.
- Functional storage, such as your language, display, and marketplace preferences and your recently-viewed items. These are stored on your device to remember your choices.
- Product analytics, our measurement of how the Service is used (for example, funnel and usage events) so we can improve it, and, under the same setting, session recordings of your own screens and taps, described below. Some of this runs through a product-analytics provider acting as our processor, PostHog, in the United States, served from our own domain; it is never tied to an ad network and never sold. In the United States and in the Jinu apps it is on by default and you can turn it off at any time. On the web everywhere else it runs only after you accept our cookie banner.
- Error monitoring, a diagnostics service (Sentry) that captures errors, and a separate, limited error-replay recording used only for debugging. Error replay is never on by default anywhere, including in the United States, happens only on the web, and runs only if you accept it. It is not the product-analytics session recording described below.
Session recordings
When product analytics is allowed, we also record your own session: the screens you move through and where you tap or click, in the order you did them, on the website and in the Jinu apps for iPhone and Android alike. We use recordings the way we use usage events, to see where the Service confuses people or breaks, and for nothing else. A recording is a reconstruction of your own session on your device. It is not video, it does not use your camera or microphone, and it captures nothing from other apps or other websites.
- It runs only when product analytics is allowed, and follows that setting everywhere it exists: on by default in the United States and in the Jinu apps; on the web outside the United States only after you accept the cookie banner; off if you have chosen "Essential only" or turned analytics off in Settings; and off whenever your browser sends a Global Privacy Control signal. Turning analytics off turns recording off with it.
- Other people's words and anyone's contact details are masked on your device before anything is sent. Everything you type into any field; every message in a conversation, in both directions, and the conversation list; the names and handles of other members wherever they appear, including a seller's profile, a listing card, your inbox, offers and reviews; addresses, phone numbers and email addresses anywhere; checkout and billing screens; the personal fields of your account and settings screens; and any photo inside a conversation are replaced by blank shapes in the recording. What remains is the Service's own layout and your own path through it.
- Public listing content can appear. The photographs, titles and prices of listings are already public on the Service and are not masked, so a recording of you browsing looks like browsing.
- Retention. Recordings are kept for the period set in our analytics processor's retention policy, currently 30 days, and are then deleted. They are held by PostHog in the United States, are never sold, and are never used for advertising.
- Reviewers are excluded. The test accounts used by app-store reviewers are kept out of product analytics entirely, and so out of recording.
Where product analytics runs by default depends on where you are and how you use Jinu. In the Jinu apps for iPhone and Android it is on by default, and you can turn it off at any time under Settings, then Privacy and data. On the web, for visitors in the United States it is on by default and no banner interrupts you; you can turn it off at any time using the "Cookie settings" link in the site footer. On the web outside the United States, including the European Economic Area, the United Kingdom and Switzerland, it runs only after you accept the cookie banner. Session recording for product analytics follows the analytics setting wherever you are. Error replay for diagnostics happens only on the web, is never on by default anywhere, and runs only if you accept it. If you choose "Essential only," all of these stay off, and we do not later switch analytics back on for anyone who has made that choice. Signed-in users can also turn analytics off at any time in Settings. Most browsers let you remove or reject cookies, although this may affect how the Jinu Service works. For the full list of cookies and storage keys with their purpose and retention, see our Cookie Policy.
Data retention
We retain personal information for as long as necessary to provide the Jinu Service and for the purposes described in this Policy, and then delete or anonymize it. Retention periods depend on the nature of the information, the length of your relationship with Jinu, and any legal, dispute-resolution, or safety obligations that require us to keep it. When you delete your account, we delete or anonymize the associated personal information, except where retention is required by law.
As a specific example, we delete direct messages after about 18 months of inactivity in a conversation. We keep them longer only where needed, such as when a message has been reported to us, relates to an ongoing transaction, or shares a photo or file, and diagnostic logs are kept for a shorter period as described in our Cookie Policy. Session recordings made for product analytics are kept by our analytics processor for the period stated in Section 05, currently 30 days. Whatever the age, you can delete your account at any time to remove your messages and shared files.
Deletion removes your data from the live service straight away. Encrypted operational backups are taken on a rolling schedule and expire within 30 days, so a copy of a deleted record can persist inside a backup for up to that window; backups are never queried to serve the Jinu Service and are only ever used to recover from a disaster. For the full list of what is erased, what is kept with your identity stripped out, and how to start the process, see Delete your account.
Your choices and rights
You may review and update your profile and settings at any time, opt out of non-essential communications, export a copy of your data, and delete your account from within the Jinu Service. Deleting your account is self-serve on the website and in both mobile apps: Delete your account gives the exact steps for each, and explains what is erased and what is kept.
Depending on where you live, you may also have the right to access or know, correct, delete, and obtain a portable copy of your personal information, to opt out of the sale or sharing of personal information and of targeted advertising, and to appeal a denied request. To exercise a right, use the in-app tools or email privacy@jinu.app. We verify requests using the account email associated with the data and respond within the time required by applicable law.
State-specific and regional disclosures
California. In the past twelve months we collected the categories of personal information listed below. We did not sell or share personal information for cross-context behavioral advertising, and we do not use or disclose sensitive personal information for purposes that would require a right to limit. California residents have the rights described in Section 07 and may exercise them as described there.
| Category | Examples | Sold or shared? |
|---|---|---|
| Identifiers | Email, name, avatar, username, account and device identifiers, IP address | No |
| Customer records | Contact and application details you provide | No |
| Commercial information | Listings, offers, favorites, and publishing-fee payments | No |
| Internet or network activity | Views, searches, usage information, and, where product analytics is allowed, recordings of your own sessions with personal details masked (Section 05) | No |
| Geolocation | Approximate, city-level location; a rounded device location (about one kilometre) only if you grant permission (Section 02D) | No |
| Content you create | Messages, reviews, reports, and uploaded files | No |
Notice at collection. This section, together with Sections 02 (what we collect), 03 (how we use it), and 06 (how long we keep it), is our notice at collection: it describes the categories of personal information we collect, the purposes for each, and our retention periods. We do not sell or share your personal information, and we honor Global Privacy Control signals. You can review these choices on our Do Not Sell or Share My Personal Information page.
Other United States states. Residents of states with comprehensive privacy laws (for example, Virginia, Colorado, Connecticut, Utah, Texas, and Oregon) have the rights described in Section 07. Because Jinu does not sell personal data, conduct targeted advertising, or profile users in furtherance of significant decisions, the related opt-outs require no action.
EEA, United Kingdom, and Switzerland. Where these laws apply, the controller of your personal information is Jinu App LLC, 7901 4th Street N, Suite 300, St. Petersburg, FL 33702, and it and relies on the legal bases of performance of a contract, consent, legitimate interests, and legal obligation. You may object to or restrict certain processing, withdraw consent, and lodge a complaint with your supervisory authority. Where we transfer information internationally, we rely on appropriate safeguards such as the Standard Contractual Clauses.
Eligibility and age
The minimum age to use the Jinu Service is eighteen. Jinu is not directed to children, and we do not knowingly collect personal information from anyone under eighteen. If we learn that we have collected information from a person under eighteen, we will delete it and terminate the account. If you believe a person under eighteen has provided us information, contact privacy@jinu.app.
Text messages
Jinu sends exactly one kind of text message: a one-time verification code, and only at the moment you ask for one. We do not send marketing, promotional, or recurring text messages of any kind, and there is no way to subscribe to any. If a text message arrives from Jinu that is not a code you just requested, it did not come from us.
A. What you consent to, and when
- Message type. A single six-digit verification code, used to confirm that a phone number belongs to you.
- Message frequency. One message per request. Messages are sent only when you press the button that asks for a code, so the frequency is entirely yours; there is also a cap on how many codes one account may request, to limit abuse.
- Message and data rates may apply. Your mobile carrier may charge you for receiving a text message. Jinu does not charge you for verification.
- Reply STOP to any message to stop receiving them, and HELP for help. Carriers honour STOP independently of us. Stopping messages means you cannot complete phone verification, which is optional; nothing else about your account changes.
- Consent is not a condition of anything. You do not have to verify a phone number to browse, post, buy, sell, or message on Jinu. It is an optional trust signal, and you may decline it and use the Jinu Service in full.
B. What we do with the number
- We store your phone number on your account so that a number can be verified once and so that the same number cannot be used to run several accounts at the same time.
- We never display it. Your phone number is not shown on your profile, on a listing, or to another member, and there is no setting that reveals it.
- We share it with our text-message delivery provider, because delivering a text message to your carrier requires giving them the number. That is the only recipient, it is for delivery alone, and the categories of providers we use are listed at Subprocessors.
- No mobile information is shared with third parties or affiliates for marketing or promotional purposes. We do not sell it, we do not rent it, we do not use it for advertising, and we do not pass it to anyone for their own use.
- Our abuse and spend records keep a one-way keyed hash of the number, not the number itself, so that we can count how many distinct numbers an account or a network is trying without keeping a readable list of them. Those records are pruned on the retention schedule in Section 06.
If you verify a number and later want it removed, write to privacy@jinu.app. Deleting your account removes it along with the rest of your information, as described in Section 06 and in Deleting your account.
Security, changes, and contact
We use reasonable technical and organizational measures, including encryption in transit and access controls, to help protect your information. No method of transmission or storage is completely secure.
We may update this Privacy Policy from time to time. If we make changes, we will revise the date at the top of this page and, for material changes, provide more prominent notice. Your continued use of the Jinu Service after an update takes effect signifies your acceptance of the revised Policy.
If you have questions or requests regarding this Privacy Policy, contact us at privacy@jinu.app. For general help, contact hello@jinu.app. A postal address is available on request. This Policy should be read together with our Terms of Service.