Joulary — Privacy Notice
Joulary ("the app") automates home EV charging using your vehicle, electricity tariff and calendar. This notice explains what personal data the app and its backend process, why, who else is involved, and the rights you have. The data controller is Alexey Yudichev, who operates Joulary; contact: support@joulary.com.
What we collect
- Account — your email address and display name. If you set a password, it is handled by Google Firebase Authentication and is never stored by us.
- If you sign in with Google or Apple — instead of a password, that provider confirms your identity to us and we receive your email address, your name, and an identifier the provider uses for you. We never see your Google or Apple password. Apple's "Hide My Email" is supported: choose it and we receive a relay address instead of your real one, which works everywhere in the app. Signing in this way necessarily tells Google or Apple that you use Joulary — signing in with an email address and password instead keeps them out of it.
- Integrations you connect — Tesla account access tokens and your vehicle's state (location, battery level, charging activity); your Octopus Energy API key, account number and tariff / consumption data; your iCloud app-specific password and calendar events (titles, times, locations) when you connect a calendar. Credentials are stored encrypted at rest.
- Home location — the location you set so the app knows when your car is at home.
- Notifications — a push token and a device identifier, so the app can notify you (for example, to plug the car in).
- Derived history — charging, energy and journey history and the savings reports computed from it.
- Technical logs — IP addresses and request metadata, kept for security and troubleshooting.
- Support messages — if you contact us, what you write, and the diagnostics described under "Contacting us" below.
There is no advertising, no marketing, no third-party analytics or tracking SDK in the app, and your data is never sold.
Why we process it
- To provide the service you sign up for (contract, UK/EU GDPR Art. 6(1)(b)) — planning and controlling charging, showing history and savings, and sending the notifications that are part of the service. Notifications are only delivered if you grant the operating-system permission.
- To keep the service secure and working (legitimate interests, Art. 6(1)(f)) — abuse prevention, rate limiting, and operational logs.
- To answer you when you get in touch — handling a support request about the service you hold with us is part of providing it (Art. 6(1)(b)). If you write to us without an account, or cannot sign in to one, we rely instead on our legitimate interest in replying to an enquiry you chose to send (Art. 6(1)(f)).
Emails we send you
We email you when something changes about your account itself: when the account is created, when a deletion is scheduled, if that deletion is cancelled, and once your data has actually been erased. We do this to deliver the service (Art. 6(1)(b)) and so that you can notice a change you did not make (Art. 6(1)(f)). When a deletion is scheduled, the same warning also goes as a notification to any phone where you are signed in to Joulary and have allowed its notifications, so it does not depend on an email reaching you.
These are service messages, not marketing, and we put no unsubscribe link in them. That is deliberate. If somebody else got into your account and asked us to delete it, the warning email is the only thing that would tell you before your data was gone, so it is not something we want you to be able to switch off by accident. In exchange we keep the set small and strictly about your account: we will never send you marketing, newsletters, offers or product announcements, and nothing of that kind will be added to these emails.
Your email app may still show you an "Unsubscribe" button on these messages, and it works. Please read this before you use it. Our email provider adds a standard unsubscribe header to everything it sends, including messages like ours, and it gives us no way to remove it. If you use that button, all four of these emails stop — including the emailed deletion warning. Nothing else about your account changes, you would still be able to sign in, and the warning would still reach a phone where you are signed in to Joulary with its notifications allowed; but you would lose the emailed copy, the one that reaches you if the app is no longer on your phone. We think you should have both, so we would rather you did not turn it off; if you already have and you want it back, email support@joulary.com and we will ask the provider to lift the block.
Our email provider is Brevo (Sendinblue SAS, France), listed below. They receive your email address, your name if you have given us one, and the message itself; they keep a delivery record for a limited period, which is why the final "your account has been deleted" email explains that a record of it outlives the deletion. Brevo stores the messages themselves in the EU, but uses a few providers of its own outside it — to serve its network, for its support desk, for its internal dashboards, and for parts of its own support and maintenance team based in India and the United States — so some of the information around a message can be handled outside the EU under the standard safeguards for such transfers. Brevo also lists several AI providers among the companies it may use, but only for optional features we do not use; we send our emails through its plain sending interface, so nothing we send you is put through any of them.
Brevo adds delivery tracking to these emails, and we cannot switch it off. Every message carries an invisible image that is fetched from Brevo when the message is displayed, and every link in it points at Brevo first and forwards you on. So Brevo can record that a message was opened, roughly when, the network address it was opened from, and which links were followed. We have turned on Brevo's anonymisation setting, which strips the identity from those records, and Brevo offers no way to turn the tracking off altogether for messages of this kind.
We do not use any of it. We do not read these records, build a profile of you, or change what we send based on whether you opened anything — and, as above, we send you no marketing to target. Our basis for it is our legitimate interest in the messages actually arriving (Art. 6(1)(f)), which is the same reason the delivery record exists at all. If you would rather not be counted: most email apps block remote images until you ask for them, which stops the invisible image being fetched, and you can copy a link's address instead of clicking it.
Contacting us
There are two ways to reach a person, and they are handled differently.
From inside the app, while signed in. Your message is stored on our servers as a support ticket, with a reference we show you. We take your email address and name from your account, not from the form, so you do not type them again. Two things may travel with the message:
- Diagnostics — attached by default, and you can turn them off before sending. They are what the app itself could see at that moment: which screen you were on, when it last heard from our server, and your platform, operating-system version, device model, app version, locale and time zone. They deliberately contain no location, no home address, no calendar entries, no journey history and no credentials.
- The recent turns of your conversation with the in-app assistant — attached only if you switch it on, which is off by default. We show you the turns on the screen before you send, so you can see exactly what would go. This is the only time we keep a copy of an assistant conversation.
We keep your message so we can answer it. The diagnostics and any attached conversation are encrypted on our servers and opened only while someone is working on your ticket, and we record who opened them and when. Once a ticket is closed, it and everything attached to it are deleted 30 days later. If you used one of your rights below in a ticket, we keep that ticket for as long as we need to show we dealt with it. If you delete your account we erase all your tickets straight away, open or closed, without waiting for those 30 days. Your own tickets also appear in the copy of your data you can download at any time (Profile → Export my data): the reference, the dates, what you wrote, and whether diagnostics went with it.
By email. Writing to support@joulary.com — which is what the signed-out screens and this website offer, since there is no account to attach a ticket to — sends an ordinary email from your own mail app to our support mailbox. If you use the link in the app, it fills in the same technical details listed above and nothing else — you can read it all, and delete any of it, before you send. The emails in that mailbox, yours and our replies, are deleted automatically 120 days after the last one in the conversation. If you wrote to use one of your rights below, we keep that conversation for as long as we need to show we dealt with it.
Either way, please send only what we need to help. If that means mentioning someone else — whoever else drives the car, say — what you write about them stays part of your message and goes no further. We do not start a record about them, and it is deleted along with your message.
Who processes it for us
| Provider | Purpose | Location |
|---|---|---|
| Google (Firebase) | Sign-in, identity, push message delivery; "Continue with Google" if you choose it | US / EU |
| Brevo (Sendinblue SAS) | Sending the account emails described above, and the delivery tracking that comes with them | EU (France); some of their own providers US |
| Tesla, Inc. | Vehicle data and commands, at your direction | US |
| Octopus Energy | Electricity tariff and consumption data, at your direction | UK |
| Apple | "Sign in with Apple" and iCloud calendar access, both at your direction; push delivery on iOS | US / EU |
| Expo | Push notification relay. Expo also uses device information from delivery (such as IP addresses and crash traces) in aggregate for its own service analytics, as an independent controller under its data processing addendum | US |
| Anthropic | Runs the language model behind the in-app help assistant, only while you have turned the assistant on. It receives your question and, when the question is about your own car, what your own screens in the app are showing: your settings, which kinds of account you have connected, the charging and climate picture on your home screen, your upcoming charge targets and how sure you said you are of each, the trips the plan is charging for with the charge it expects before and after each, and the electricity prices on the Timeline. It never receives your home or car location, the titles or contents of your calendar entries, the names of your charge targets, your email address, or any password or access token. Under Anthropic's terms your questions are not used to train models, and are deleted within 30 days | US |
| Google Maps / platform geocoding | Showing the map and finding an address when you set your home location | US |
| Google Workspace | Runs the mailbox behind our support address, so it holds the messages you send us and the replies we send back | US / EU |
| Our hosting provider | Runs the Joulary backend | EU or UK |
Where a provider is outside the UK/EU, transfers rely on that provider's standard data-protection terms (Standard Contractual Clauses / UK Addendum) or an adequacy decision.
How long we keep it
- Your account and connected-integration data — until you delete your account, or until it has gone unused for about two years. Deletion is available in the app (Profile → Delete account); after a short grace period during which you can cancel, everything is permanently erased, including integration credentials and history.
- Accounts nobody uses are deleted. An account counts as in use while you open the app, and also while Joulary is acting on your car for you — starting a charge it planned, or running preconditioning it committed to. When neither has happened for about 22 months we email you, and notify any phone you are signed in on, saying the account will be erased on a date about two months later — roughly two years after it was last used; signing in before then keeps it, and nothing is erased.
- Journey history — 12 months. These records include the start and end location of each drive, so they are kept for the shortest period the app can work with, and are deleted automatically after that whether or not you delete your account.
- Charging, climate and energy history, and the savings reports derived from it — 5 years, so that year-on-year comparisons remain available. Deleted automatically after that.
- Support tickets raised in the app — 30 days after the ticket is closed, including the diagnostics and any conversation attached to it. A ticket in which you used one of your rights is kept for as long as we need to show we dealt with it. A ticket that is still open is not deleted on a timer; we close it. Deleting your account erases all your tickets straight away, whether open or closed.
- Email you send to the support address, and our replies — 120 days after the last message in the conversation, deleted automatically. A conversation in which you used one of your rights is kept for as long as we need to show we dealt with it.
- Application logs — up to 60 days. Access logs at the network edge — up to 60 days.
- On your device, cached history is erased when you sign out or delete the account.
Your rights
You can export a copy of your data (Profile → Export my data) and delete your account (Profile → Delete account) directly in the app — these implement your rights of access, portability and erasure. You also have the rights to rectification, restriction and objection, and to lodge a complaint with your supervisory authority (in the UK, the Information Commissioner's Office). For anything you cannot do in the app, email support@joulary.com.
Children
Joulary is not directed at children and is not intended for use by anyone under 16.
Changes
Changes to this notice are published on this page with an updated effective date.