Privacy

Privacy at Journeys

This policy explains what the hosted Journeys service handles when you visit the site, create an account, and monitor customer flows.

Last updated 30 August 2026

Journeys uses your information to provide and protect the monitoring service. We do not sell personal information or use journey data for advertising.

Information we collect

  • Account information: your email address, sign-in records, notification preferences, and account settings.
  • Billing information: plan, credit, invoice, and subscription identifiers. Payment card details are collected and handled by Stripe, not stored by Journeys.
  • Monitoring configuration: the sites, journey names, goals, URLs, schedules, variables, dependencies, and notification recipients you provide.
  • Run information: status, timing, agent activity, visited pages, model usage, screenshots, recordings, reports, diagnostics, and values a journey publishes for another journey.
  • Saved browser sessions and secrets: cookies, browser storage, journey secrets, and an optional model API key when you choose to provide one. These sensitive values are encrypted at rest.
  • Public site usage: the pages you view on the marketing site, the site that referred you, and approximate location and device, collected through Google Analytics.
  • Service communications: messages you send to us and records needed to deliver or suppress service email.

How we use information

We use this information to:

  • authenticate your account and operate the checks you configure;
  • drive and judge browser runs, generate evidence, and notify the recipients you choose;
  • process purchases, enforce plan limits, and maintain billing records;
  • secure, diagnose, maintain, and improve the service; and
  • answer support, privacy, and security requests.

Who processes information

Journeys sends information only where it is needed to provide the service. Stripe processes checkout and subscription payments. Resend delivers sign-in links and service notifications. OpenAI processes the context needed for the browser agent to act and judge a run; when you provide your own OpenAI key, requests use that key. Google Analytics processes public-site visit data, as described under Cookies and analytics. The websites you choose to monitor receive the browser interactions and values required by the journey, just as they would from a person completing the same flow.

We may also disclose information when required by law, or when necessary to protect the service, its customers, or others. We do not sell personal information.

Cookies and analytics

The public landing pages use Google Analytics to count visits and see which pages people read. It sets its own cookies and reports an approximate location, device, and referring site. We use it to understand how people find Journeys. We do not use it for advertising, we do not run advertising cookies, and no journey or account data is sent to it.

The application uses an HTTP-only session cookie to keep you signed in after you use a one-time email link. That cookie is used for authentication, not for tracking across sites.

Retention and deletion

Account and monitoring records are kept while they are needed to provide the service. Detailed run artifacts such as reports, screenshots, and recordings are retained for a limited service period and may be pruned before the smaller history record and verdict. Deleting a saved session removes its stored browser data; deleting a site removes its journeys and associated configuration. Some billing, security, backup, and transaction records may be retained where needed for legitimate operational or legal purposes.

Email hello@journeys.run from your account address to request access, correction, export, or deletion. We may need to verify that the request belongs to you before acting on it.

Session Capture extension

The optional Chrome extension has a narrower job and its own policy, including the browser permissions it requests and what remains on your device. Read the Journeys Session Capture privacy policy.

Security

Journeys limits account access with signed, HTTP-only sessions and encrypts stored model keys, journey secrets, and saved browser sessions. No internet service can guarantee absolute security, so please contact us promptly if you believe your account or data is at risk.

Changes and contact

We will update the date on this page when this policy materially changes. Questions or privacy requests can be sent to hello@journeys.run.