Terms of Use
Effective 14 September 2026. These Terms govern use of the official Josi CE application and publisher-supplied paid modules from SOCAL RECEPTIONIST LLC. The GNU AGPL v3 separately governs copying, modification and distribution of the open-source code. If you do not agree, do not use the official application or paid modules.
Preview, AI and reliance
Josi CE 0.1 is beta-quality Community Preview software. Features and AI output may be incomplete, unavailable, delayed or wrong. Do not use Josi as the sole system for emergencies, safety, healthcare, legal, financial, employment, compliance, access control or backups. Review output and approve consequential actions yourself.
Operator and user responsibilities
The installation operator controls the server, users, providers, retention and backups. Users must protect credentials and use only accounts and data they are authorized to use. Do not use Josi to violate law or rights, exploit or harm minors, send unlawful or abusive communications, distribute malware, bypass security, misrepresent AI authorship or access another person's data without authority.
Connected services
Features can send necessary data to operator-selected AI, email, Google, Microsoft, messaging, storage, backup, developer, telemetry or support services. Those services have their own terms, privacy, security, availability, retention and pricing. The operator and user are responsible for their configuration, permissions, recipients and use.
Family BETA
Family and Parental Controls must not be relied on to protect a child. They control only Josi and may fail. They are not device controls, web filters, location monitoring, emergency services or actual screen-time measurement. The operator and supervising adult are responsible for consent, child-privacy law, age-appropriate use, disclosure to the child, active supervision and independent device-level controls.
Data, security and backups
Users retain rights in their content. Operators are responsible for lawful collection, notice, access, retention, export and deletion. A compromised host can bypass application controls. A database backup excludes the separate master key; losing it may make credentials unrecoverable. Test restores and keep independent backups.
Paid modules
A signed licence key grants only the named feature, buyer, installation and term. It grants no source ownership, trademark right, support, warranty or SLA. Do not forge, alter, share, resell or use a key outside its issued scope. An expired, revoked, invalid or wrong-installation key may make the module inert.
No warranties and limitation
TO THE MAXIMUM EXTENT PERMITTED BY LAW, JOSI, ITS DOCUMENTATION AND PAID MODULES ARE PROVIDED “AS IS” AND “AS AVAILABLE,” WITHOUT WARRANTIES OF ACCURACY, RELIABILITY, FITNESS, NON-INFRINGEMENT, SECURITY OR AVAILABILITY. TO THE MAXIMUM EXTENT PERMITTED BY LAW, SOCAL RECEPTIONIST LLC WILL NOT BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY OR PUNITIVE DAMAGES, OR LOSS OF DATA, PROFITS, REVENUE, GOODWILL OR USE. Nothing excludes liability that applicable law does not permit excluding.
Community Preview use carries no support entitlement, guaranteed response or SLA. Updated Terms may be published prospectively with a new effective date. Questions and reports follow the repository's public Support and Security policies.
Privacy Notice
Effective 14 September 2026. Josi CE is self-hosted. The person or organization operating an installation is normally the controller of its data. SOCAL RECEPTIONIST LLC does not receive installation data merely because the software is running.
Data categories and purposes
Depending on enabled features, Josi processes account/authentication data; profiles and personalization; conversations, tasks, approvals and memory; contacts, calendars, email and connected-account identifiers; files, extracted text, indexes and citations; encrypted provider credentials; usage/cost records; audit events; backups; channel identifiers and messages; diagnostics/support material; and Voice Box audio. It uses these to authenticate, provide requested functions, enforce policy, connect services, operate and secure the installation, calculate configured limits, and back up or restore data.
Family BETA data
Family BETA processes the parent-child relationship, controls, schedules, distinct minutes in which a child sends a message, parental access events, and child conversations opened by the linked adult. It is not device or screen-time monitoring. Ending a relationship removes schedules, controls and activity-minute records; ordinary conversation retention remains controlled by the installation.
Who receives data
Data stays on the installation unless a user or operator enables or uses a destination. Necessary data may then go to the selected AI provider; Google or Microsoft; configured SMTP/mail services; Telegram, Slack, WhatsApp or Signal; configured storage/backup providers; configured GitHub, Netlify, Vercel, Supabase or other developer services; an operator-selected telemetry or support gateway; recipients and shared users authorized by the user; and public documentation/Groq only when optional help chat is enabled and used. Voice Box is intended to run locally. Disclosures may also occur when required by law, needed for safety/security, or in a lawful business transfer.
SOCAL RECEPTIONIST LLC does not sell installation data, use it for advertising, or use private content to train generalized AI models. External providers operate under their own policies and may process data internationally.
Telemetry, support, retention and rights
Telemetry is off by default and excludes prompts, message content, contacts, calendars, credentials and identifiable business data. Support bundles are made locally for review and are not sent until approved to a configured gateway. Retention and deletion are controlled by the operator and feature settings; third-party and backup copies may follow separate retention. Contact the operator for access, correction, deletion, restriction, objection or portability. Privacy questions follow the repository's public Support and Security policies.
Children and security
The operator and supervising adult must obtain required consent, provide age-appropriate notice and comply with child-privacy law. Josi uses access controls, encrypted stored credentials, audit events, CSRF protection and a restrictive browser policy, but no system is perfectly secure and a host operator can bypass application controls.
Cookie Notice
Effective 14 September 2026. The official application uses only strictly necessary first-party cookies: an HTTP-only authentication session cookie (optionally persistent when “Keep me signed in” is selected) and a CSRF cookie paired with a request header. They are not used for advertising, cross-site tracking or analytics. The Content Security Policy prevents third-party scripts and resources from loading.
The PWA caches versioned application files and an offline page, not private API responses or user content. Connected providers may set their own cookies on their sites during OAuth or sign-in. Signing out ends the server session; browser settings can clear cookies and the PWA cache. Operators are responsible for disclosing cookies introduced by modified builds.
Software and paid-feature licences
The Josi CE source code is licensed under GNU AGPL v3. The Josi name, marks and official product identity are governed separately by the trademark policy. Third-party notices remain applicable. A modified build must not imply publisher approval or support.
A publisher-signed paid-feature key is a separate entitlement, not a software copyright licence. It activates only the feature, buyer, installation and term encoded in the key and is governed by the Terms above. Community Preview carries no support entitlement or SLA.
