Privacy policy
Effective date: [PLACEHOLDER: effective date] · Version 1.0
Maju is a daily skin progress tracker for iPhone, made by FBMUSSA, LLC (“we”, “us”). This policy explains what the app stores, what leaves your phone, and what we will never do with your data. It is written to be read on a phone. Promises first, mechanics second.
Our promises
These are the same four commitments shown on the Privacy screen inside the app. Nothing in this policy overrides them.
- Photos stay private by default. Nothing is shared unless you choose to share it, and you are asked again every time.
- Never sold. Your photos and data are not sold to advertisers, data brokers, or anyone else.
- Never used to train AI without your explicit opt-in. Silence means no.
- Never paywalled. Your past photos are always yours to see and export for free. Progress you already made never sits behind a subscription.
The short version
- Today, Maju runs entirely on your iPhone. There is no account, no sign-in, and no Maju server. The app makes no network requests and contains no third-party code. Nothing is uploaded.
- Your photos, routines, notes, and settings are stored in the app’s private space on your device, protected by iOS encryption.
- To line up each photo with the last one, the app stores the position of your eyes in each photo. This is used only for alignment, never to identify you, and is deleted with the photo.
- We plan to add subscriptions, crash reporting, product analytics, and optional accounts. Section 9 already describes each one, what it receives, and what it never receives. Local-only mode will stay available.
- You can export every photo or delete everything at any time, from Settings.
1. Who we are
FBMUSSA, LLC
[PLACEHOLDER: mailing address]
support@maju.cc
We make Maju, listed on the App Store as “Maju: Skin Progress Tracker”. Where data protection law applies, we are the data controller for the information described in sections 9 and 10.
2. Two ways to use Maju
Local-only. This is the version in the App Store today, and it will always be available. Everything stays on your phone. We never see your data, because it never reaches us.
With an account. When accounts ship, you will be able to sign in so your data syncs across devices and friends can see what you choose to share. Signing in is optional. Sections 9 and 10 explain what changes when you do.
Each section below says which version it applies to.
3. What Maju stores on your iPhone
Applies to both versions.
Photos are saved as files in the app’s private storage on your device. Your logs, routines, products, and settings live in a local database in the same private container. Both are protected by iOS device encryption and your passcode.
What is stored:
- Profile. Skin type, skin concerns, goals, an optional username, reminder times, a commitment target in days, and whether feed posts include the day’s photo by default.
- Daily logs. The photo, the date, an optional note, which routine steps you completed and how many times (for example sunscreen reapplied twice), and any routine swaps for that day.
- Face alignment data. For each photo, the coordinates of your left and right eyes, the distance between them, and the transform used to line the photo up with the previous one. See section 4.
- Skin signals. Two numbers computed from each photo: an average brightness value, and a tone evenness score from 0 to 100. These are observations from an image, not a measure of skin health.
- Routines, steps, and your product shelf. Product name, brand, category, opened and finished dates, expiry months, optional SPF value, sunscreen type, and ingredients. Product details may be filled in from a built-in catalog of common skincare products.
- Demo content. Sample photos, routines, and friends, so every screen has something to show. The faces are synthetic and the friends are fictional. You can remove the demo in Settings. It never mixes with your own logs.
Backups. If iCloud Backup or a computer backup is turned on, the app’s data, including your photos, is included in that backup like any other app’s. That is Apple’s backup, under your Apple Account and Apple’s terms. It is not a Maju server, and we cannot access it.
4. Face alignment data, and what it is not
Applies to both versions.
Every time you take a photo, Apple’s Vision framework finds your eye positions, on the device, so the new photo lines up with the last one. Maju stores those two points, the distance between them, and the alignment transform, alongside the photo.
That is all it is. Maju does not build a face template, does not identify or verify anyone, and never compares faces between people. The data is used only to align photos and to compute the skin signals in section 3. It never leaves your device in local-only mode, and it is deleted when you delete the photo.
5. Photos of skin are sensitive
Applies to both versions.
Photos of your skin, and the skin type and concerns you tell us about, can say something about your health. We treat them as sensitive personal information. In local-only mode we never receive them. If you later create an account and choose to sync, they are stored in the cloud only with your explicit consent, given when you sign in, and only so we can show your data back to you and to the friends you choose. Skin type and concerns are self-reported. Nothing in Maju is a diagnosis.
6. Permissions the app asks for
Applies to both versions.
- Camera. For your daily aligned photo. Without it you can still log your routine, but not take the photo.
- Notifications. At most two reminders a day, one morning and one evening, at times you pick. They are scheduled on your device by iOS. Turn them off or change the times in Settings, or in iOS Settings.
- Photo library. Only through Apple’s photo picker, when you choose to import an older photo. The app never scans or reads your library on its own.
You can change any permission at any time in iOS Settings › Privacy & Security.
7. What Maju does not collect
Applies to the local-only version. Section 9 lists exactly what changes when a service is added.
- No name, email address, phone number, or contact list.
- No location.
- No advertising identifier, and no tracking across other apps or websites.
- No HealthKit data.
- No analytics and no crash reports.
- No network requests at all.
8. What can leave your phone, and only when you choose
Applies to both versions. Each of these starts with a tap from you and goes through the iOS share sheet, so you pick where it goes.
- Export my photos. All of your original photo files, untouched.
- Share a card, a before-and-after image, or a timelapse video. Where it goes after the share sheet is up to you.
- Share to feed. A preview only in the local-only version. Once accounts ship, section 10 applies.
9. Services we use, and what each one receives
Some of these are not in the app yet. We describe them now so this policy is accurate on the day each one is turned on. None of them ever receives your photos, your notes, the product names you typed, or your username, except where section 10 says so for accounts.
Apple
Apple provides the App Store, in-app purchases, iOS notifications, and, if you use it, iCloud Backup. Apple processes payments. We never see your card details. Apple’s privacy policy applies to those services.
RevenueCat, for subscriptions
Purpose: handle Maju Premium and know which devices have it.
Receives: an anonymous app user ID generated by the RevenueCat SDK, your Apple purchase receipt and transaction data, device type and OS version, app version, and the country and currency of your App Store.
Never receives: photos, logs, or anything you typed.
RevenueCat privacy policy.
Sentry, for crash reports
Purpose: know when the app crashes so we can fix it.
Receives: the crash stack trace, device model, OS version, app version, free memory and disk, and an installation ID.
Never receives: screenshots or screen recordings. We keep both turned off so a face is never in a crash report.
Sentry privacy policy.
PostHog, for product analytics
Purpose: understand which features are used, for example how many people take a photo on day two, so we can improve the app.
Receives: event names such as “screen viewed”, “photo taken”, or “routine completed”, timestamps, an anonymous device identifier, device model, OS and app version, and a coarse region derived from your IP address.
Never receives: photo content, notes, product names you typed, or usernames. We do not record your screen. We do not track you across other apps or websites, so iOS will never show you a tracking prompt for Maju.
PostHog privacy policy.
Supabase, for accounts and sync
Purpose: host the optional account described in section 10.
Receives: everything in section 10.
Hosted in: [PLACEHOLDER: hosting region, e.g. the United States, or an EU region for EU users].
Supabase privacy policy.
Push notifications, possibly later
Today every reminder is scheduled on your device. If we add server push for friend activity, we would store a device push token with your account so Apple can deliver the notification. We will update this section before that ships.
Each provider is bound by a data processing agreement and may use the data only to provide its service to us.
10. Accounts, sync, and friends
Applies only once you create an account. Nobody is forced to. Local-only mode stays available.
Signing in. You can sign in with Apple, with Google, or with an email magic link. We receive the provider’s user ID and, if you allow it, your email address and name. Apple’s Hide My Email relay is supported.
What syncs. Everything in section 3 is mirrored to a database and a private photo storage bucket, so it follows you across devices and survives a lost phone. Photos are served through short-lived signed links.
Who can see what.
- Your photos, notes, and logs: only you.
- A feed post: your friends. A post carries the day number and rhythm stats. Including the photo is opt-in per post and off by default. You can change the default in Settings.
- Comments, likes, and reactions: the friends who can see the post they are on. There is no public profile and no public feed.
- Routine changes: shared only if you tap “share this?” on each one. Nothing is ever auto-posted.
Friends. You add friends by username or by invite link. Usernames are chosen by you, are unique, and are filtered for profanity and slurs.
Face alignment data and skin signals sync with your photos, are visible only to you, and are deleted with them.
11. How long we keep data
- On your device. Until you delete it in the app, or delete the app.
- Account data. For as long as your account exists, then deleted within [PLACEHOLDER: retention after deletion, e.g. 30 days] of your deletion request, except where we must keep a record for tax or legal reasons.
- Purchase records. Kept by Apple under Apple’s policies, and by RevenueCat for as long as we use their service.
- Crash reports and analytics events. [PLACEHOLDER: retention window, e.g. 90 days].
- Support emails. [PLACEHOLDER: support email retention period, e.g. two years].
12. Deleting your data
- Local-only. In the app, Settings › Delete everything removes every photo, log, routine, product, and setting on the device. There is no undo. Deleting the app does the same.
- With an account. [PLACEHOLDER: in-app path to delete account]. This deletes your account and every copy of your data on our servers, including photos, within the period in section 11.
- Cannot open the app? Email support@maju.cc from the address on your account and we will delete it.
- Subscriptions are managed by Apple. Deleting your data or your account does not cancel a subscription. Cancel in Settings › Apple Account › Subscriptions.
Step-by-step instructions are on the support page.
13. Your rights
Wherever you live, you can ask us to access, correct, delete, or export the personal data we hold about you, or object to or restrict how we use it. Email support@maju.cc. We will respond within 30 days and will not treat you differently for exercising your rights. In local-only mode we hold nothing about you, so the fastest route is the app’s own export and delete controls.
UK, EU, and EEA. Our legal bases are: performing our contract with you, for accounts, sync, and subscriptions (Article 6(1)(b) GDPR); our legitimate interest in keeping the app working, for crash reports (Article 6(1)(f)); consent for product analytics where the law requires it, and otherwise legitimate interest; and your explicit consent for syncing skin photos and concerns (Article 9(2)(a)). You can withdraw consent at any time in the app. You also have the right to complain to your data protection authority. [PLACEHOLDER: EU representative, if appointed, or delete the sentence]
California and other US states. In the past twelve months we have collected, for the purposes in sections 9 and 10, these categories: identifiers (account and device IDs, and your email address if you provide it), purchase information, usage data, and, if you create an account and sync, photos and self-reported skin information, which we treat as sensitive personal information. We do not sell personal information, do not share it for cross-context behavioural advertising, and do not use sensitive personal information for anything other than providing the service. You have the right to know, correct, delete, and opt out, and not to be discriminated against for exercising those rights. You can appoint an authorised agent to make a request for you.
International transfers. Maju is operated from the United States. If you create an account from outside the US, your data may be transferred to and processed in the US by us and our providers, under standard contractual clauses or an equivalent safeguard where the law requires one.
14. Children
Maju is for people aged 16 and over. It is not directed to children, and we do not knowingly collect personal information from anyone under 16. If you believe someone under 16 has created an account, email support@maju.cc and we will delete it.
15. Security
Data on your iPhone is protected by iOS data protection and your passcode. The app uses only the standard encryption built into iOS. Data sent to our providers travels over encrypted connections, and photos in the cloud sit in a private bucket readable only through short-lived signed links. No system is perfectly secure, so we keep what we hold to the minimum the service needs.
16. Changes to this policy
If we change this policy in a way that matters, for example when one of the services in section 9 is turned on, we will tell you in the app before the change takes effect and update the date and version at the top. Earlier versions are available on request.
17. Contact
FBMUSSA, LLC · [PLACEHOLDER: mailing address]
support@maju.cc