privacy.

Privacy policy

Effective date: 23 September 2026 · Version 1.1

Maju is a daily skin progress tracker for iPhone, made by FBMUSSA, LLC (“we”, “us”). This policy explains what the app stores, what leaves your phone, who receives it, and the rights you have. It also covers the maju.cc website. It is written to be read on a phone. Promises first, mechanics second.

Our promises

These are the four commitments shown on the Privacy screen inside the app. They bind us, and nothing else in this policy overrides them.

The short version

1. Who we are

FBMUSSA, LLC
New York, United States. Postal address available on request.
support@maju.cc

We make Maju, listed on the App Store as “Maju: Skin Progress Tracker”. Where data protection law applies, we are the controller of the personal data described in sections 9 to 11. The providers in section 9 process data on our behalf, except Apple, which acts under its own policies.

2. Two ways to use Maju

Local-only. Always available. Everything stays on your phone. We never see your data, because it never reaches us.

With an account. Sign in with Apple to back up your log and follow friends. Signing in is optional, and you can return to local-only mode by deleting your account. Sections 9 and 10 explain what changes when you sign in.

Each section below says which version it applies to.

3. What Maju stores on your iPhone

Applies to both versions.

Photos are saved as files in the app’s private storage on your device. Your logs, routines, products, and settings live in a local database in the same private container. Both are protected by iOS data protection and your passcode.

What is stored:

Backups. If iCloud Backup or a computer backup is turned on, the app’s data, including your photos, is included in that backup like any other app’s. That backup is made by Apple, under your Apple Account and Apple’s terms. It is not a Maju server, and we cannot access it.

4. Face alignment data, and what it is not

Applies to both versions.

Every time you take a photo, Apple’s Vision framework locates your eye positions, on the device, so the new photo lines up with the last one. Maju stores those two points, the distance between them, and the alignment transform, alongside the photo.

That is all it is. Maju does not create a face template or faceprint, does not identify or verify anyone, and never compares faces between people. The data is used only to align photos and to compute the skin signals in section 3. It is generated, stored, and used only on your device. It is never transmitted to us or any provider, with or without an account, so we never possess it. It is deleted when you delete the photo.

5. Photos of skin are sensitive

Applies to both versions.

Photos of your skin, and the skin type and concerns you tell us about, can reveal something about your health. We treat them as sensitive personal information, and as health data where a law defines that term. In local-only mode we never receive any of it. Photos never leave your phone, with or without an account. If you sign in, your self-reported skin type and concerns sync with your explicit consent, given when you sign in, and are visible only to you. Nothing in Maju is a diagnosis, and we do not infer health conditions from your data.

6. Permissions the app asks for

Applies to both versions.

You can change any permission at any time in iOS Settings › Privacy & Security.

7. What Maju does not collect

Applies to the local-only version. Section 9 lists exactly what changes when a service is added.

8. What can leave your phone, and only when you choose

Applies to both versions. Each of these starts with a tap from you and goes through the iOS share sheet, so you pick where it goes. Whoever you send it to holds it under their own terms, not ours.

9. Services we use, and what each one receives

Sentry and PostHog are not switched on yet. We describe them now so this policy is accurate on the day each one is turned on. None of these services ever receives your photos. None receives your notes, the product names you typed, or your username, except Supabase for accounts, as section 10 describes.

Apple

Apple provides the App Store, in-app purchases, Sign in with Apple, iOS notifications, and, if you use it, iCloud Backup. Apple processes payments. We never see your card details. Apple’s privacy policy applies to those services.

RevenueCat, for subscriptions

Purpose: handle Maju Premium and know which devices have it.
Receives: an anonymous app user ID generated by the RevenueCat SDK, your Apple purchase receipt and transaction data, device type and OS version, app version, and the country and currency of your App Store.
Never receives: photos, logs, or anything you typed.
RevenueCat privacy policy.

Sentry, for crash reports

Not switched on in the current version.
Purpose: know when the app crashes so we can fix it.
Receives: the crash stack trace, device model, OS version, app version, free memory and disk, and an installation ID.
Never receives: screenshots or screen recordings. We keep both turned off so a face is never in a crash report.
Sentry privacy policy.

PostHog, for product analytics

Not switched on in the current version.
Purpose: understand which features are used, for example how many people take a photo on day two, so we can improve the app.
Receives: event names such as “screen viewed”, “photo taken”, or “routine completed”, timestamps, an anonymous device identifier, device model, OS and app version, and a coarse region derived from your IP address.
Never receives: photo content, notes, product names you typed, or usernames. We do not record your screen. We do not track you across other apps or websites, so iOS will never show you a tracking prompt for Maju.
Hosted in: the United States.
PostHog privacy policy.

Supabase, for accounts and sync

Purpose: host the optional account described in section 10.
Receives: everything in section 10.
Hosted in: the United States.
Supabase privacy policy.

Push notifications, possibly later

Today every reminder is scheduled on your device. If we add server push for friend activity, we would store a device push token with your account so Apple can deliver the notification. We will update this section before that ships.

Each provider is bound by a data processing agreement and may use the data only to provide its service to us, never for its own purposes.

Other disclosures. Beyond these providers, we disclose personal data only when the law requires it, such as a valid court order; when necessary to protect the safety or rights of you, us, or others; or if Maju is sold or merged, in which case the new owner takes the data under this policy and our promises still apply.

10. Accounts, sync, and friends

Applies only once you create an account. Nobody is forced to. Local-only mode stays available.

Signing in. You sign in with Apple. We receive Apple’s user ID for Maju and, if you allow it, your email address and name. Apple’s Hide My Email relay is supported. We use your email only to identify your account, verify requests, and send service notices.

What syncs. Your profile (skin type, concerns, username, reminder times, and commitment target), your daily logs without the photo (the date, whether a photo was taken, your note, the routine steps you completed, and the two skin-signal numbers), your routines, and your product shelf. Face alignment data and demo content never leave your phone.

Who can see what.

The feed is not switched on yet. When it is:

Friends. You add friends by username or by invite link. Usernames are chosen by you, are unique, and are filtered for profanity and slurs. Friends see your username and what you choose to share, nothing else.

Face alignment data stays on your phone. The two skin-signal numbers sync with your log, are visible only to you, and are deleted with it.

No automated decisions. We make no automated decisions with legal or similarly significant effects on you, and build no advertising profiles.

11. How long we keep data

12. Deleting your data

Step-by-step instructions are on the support page.

13. Your rights

Wherever you live, you can ask us to access, correct, delete, or export the personal data we hold about you, to object to or restrict how we use it, or to withdraw consent. Email support@maju.cc. We will verify your identity, respond within 30 days, and will not treat you differently for exercising your rights. If we refuse a request, we will say why and how to appeal. In local-only mode we hold nothing about you, so the fastest route is the app’s own export and delete controls.

UK, EU, and EEA. Our legal bases are: performing our contract with you, for accounts, sync, and subscriptions (Article 6(1)(b) GDPR); our legitimate interest in keeping the app secure and working, for crash reports and server logs (Article 6(1)(f)); consent for product analytics where the law requires it, and otherwise legitimate interest; and your explicit consent for syncing your self-reported skin type and concerns (Article 9(2)(a)). You can withdraw consent at any time by deleting your account or emailing us. You also have the right to complain to your data protection authority. We have not appointed a representative in the EU or UK, because our processing of data about people there is occasional. If the law comes to require one, we will appoint one and name them here.

California and other US states. In the past twelve months we have collected, directly from you or your device and for the purposes in sections 9 and 10, these categories: identifiers (account and device IDs, and your email address and name if you provide them), purchase records, usage and crash data once those services are on, and, if you create an account and sync, self-reported skin information. We treat that skin information as sensitive personal information and, where state law uses the term, as consumer health data. We disclose these categories only to the service providers in section 9. We do not sell personal information, do not share it for cross-context behavioural advertising, use sensitive information only to provide the service, and offer no financial incentives for data. You have the right to know, correct, delete, opt out, and limit the use of sensitive information, and not to be discriminated against for exercising those rights. You can appoint an authorised agent to make a request for you.

International transfers. Maju is operated from the United States. If you create an account from outside the US, your data is transferred to and processed in the US by us and our providers, under standard contractual clauses or an equivalent safeguard where the law requires one.

14. Children

Maju is for people aged 16 and over. It is not directed to children, and we do not knowingly collect personal information from anyone under 16. If you believe someone under 16 has created an account, email support@maju.cc and we will delete it.

15. Security

Data on your iPhone is protected by iOS data protection and your passcode. The app uses only the standard encryption built into iOS. Data sent to our providers travels over encrypted connections and is stored encrypted at rest. Your photos are never sent to our servers, so there is no cloud copy of them to secure. No system is perfectly secure, so we keep what we hold to the minimum the service needs. If a breach affects your data, we will notify you and the relevant authorities as the law requires.

16. Changes to this policy

If we change this policy in a way that matters, for example when one of the services in section 9 is turned on, we will tell you in the app before the change takes effect and update the date and version at the top. A change that weakens one of our promises, or expands how we use sensitive data, will apply to data already collected only with your fresh consent. Earlier versions are available on request.

17. Contact

FBMUSSA, LLC · New York, United States · Postal address available on request
support@maju.cc