Last updated: September 28, 2026
About this policy
Updated September 28, 2026. Justinian is operated by Vulcan Technologies, Inc. This policy describes information collected through the commercial Justinian native apps for iOS and Android, web app, and the services they connect to. Contact support@vulcan.ai with privacy questions or requests.
Information we collect and how
We collect the account details supplied when your account is created or you sign in, including your name, email address, user identifier, and authentication events. We collect messages, questions, conversation history, generated responses, files, images, recordings, and transcripts when you submit, record, upload, or use them in Justinian. When you enable connections, we receive the email, calendar, contacts, and file content and metadata those connections make available. Shared workspaces may also supply context available to you. Device, session, usage, performance, and error information is collected as you use the app. If enabled, notifications use a device push token.
AI processing and recipients
Justinian processes your messages and relevant conversation history, documents, images, recordings, transcripts, connected email and calendar content, and task or search context through AI services to answer questions, retrieve relevant information, transcribe audio, generate content, and carry out tasks. Which information is processed depends on your features, connections, and tasks. Anthropic provides Claude processing; Amazon Web Services provides Amazon Bedrock, including Claude models; OpenAI provides language-model and audio-transcription services; Google provides Gemini services for semantic search and embeddings; and Deepgram provides audio transcription. Not every provider processes every request. Vulcan does not train AI models on your content. Our model-provider agreements provide zero data retention: providers use request content only to process your request and do not store it after processing.
App analytics and screen recordings
We run our own analytics and session-recording service on Vulcan's infrastructure to understand product usage, diagnose problems, and provide support; it is not sent to a third-party analytics company. On the web, we collect account and device identifiers, page and feature interactions, performance and error information, and session recordings according to service settings. Web recordings can include visible messages, email bodies, documents, images, copied text, and text entered in the app. Service-side usage and diagnostic events are also recorded by this service. Information may be linked to your account and viewed by authorized Vulcan personnel.
In the native iOS and Android apps, app analytics and screen recordings start only after you accept the Privacy & AI consent screen. While you are signed in, we collect account and device identifiers, feature interactions, diagnostic information, and session recordings. Recordings can include visible messages, email bodies, documents, images, and text entered in the app. Collection stops when you sign out or withdraw consent in Settings > Privacy & AI; there is no separate setting to turn app analytics or recordings off. This does not change analytics collected by the web app or service-side systems.
Other service providers and uses
Amazon Web Services provides hosting and storage. Okta provides authentication. When you enable notifications, Vulcan stores your device push token and notification preferences on its own infrastructure to send notifications. Apple Push Notification service delivers notifications to the iOS app, and Google Firebase Cloud Messaging delivers notifications to the Android app. Connected services, such as Google or Microsoft, exchange data with Justinian to provide the connections you enable; recipients receive emails, invitations, or shared material when you send or share it. We also use information to maintain your account, conversations and files, secure the service, send account-related communications, respond to support requests, and meet legal obligations. We do not sell personal data or share it with advertising networks.
Provider protections and security
We require service providers to use personal information only to deliver their contracted services and to provide protections at least equivalent to those described in this policy. We use encrypted connections and access controls to protect information, and restrict access to production systems to authorized personnel. No method of storage or transmission is completely secure. Your organization's agreement and information-handling rules continue to apply. Consent does not authorize submission of information your organization prohibits or establish a government security authorization.
Government deployment security
Vulcan is FedRAMP Ready and listed on the FedRAMP Marketplace.
Retention and deletion
Vulcan retains the account information and content you choose to submit, upload, or save in Justinian while your account is active to provide and improve your experience. Usage data, recordings, and operational logs are retained according to service settings and applicable security, contractual, and legal requirements. Model providers process request content under our zero-data-retention agreements and do not store it after processing. You can request deletion of your Justinian data at any time by contacting support@vulcan.ai. Some records may need to remain for legal or security obligations.
Consent and your choices
In native iOS versions with Privacy & AI settings and in the Android app, you must agree before AI processing or sign-in. Your acceptance is saved on your device, so ordinary sign-outs and app updates do not require you to agree again. On iOS, acceptance is also linked to the account you sign in to, and a different account must have its own consent. You can review this policy or withdraw consent in Settings > Privacy & AI. Withdrawing signs you out and blocks new AI requests and native analytics from that app on that device until you agree again.
Withdrawal does not undo processing already started, delete existing data, or cancel tasks and connections operating through your account elsewhere. The native consent controls do not change your settings in the web app or other devices. For account-wide withdrawal, deletion, or help stopping existing tasks and connections, contact support@vulcan.ai. You may request access to or correction of your information. Device permissions remain controlled by your device settings: microphone, camera, photo-library, and notification permissions on iOS, and microphone, camera, and notification permissions on Android.
Children and policy changes
Justinian is intended for professional use and is not directed at children under 13. We do not knowingly collect personal information from children. We may update this policy and will communicate material changes through an in-app notice or account communication. In the native iOS and Android apps, we will request consent again if the data, recipients, or purposes covered by your consent materially change; routine sign-ins and app updates do not by themselves change your consent.
Contact
Contact Vulcan Technologies, Inc. at support@vulcan.ai.
