Privacy policy
Effective date: 23 September 2026 · Version 1.1
Maju is a daily skin progress tracker for iPhone, made by FBMUSSA, LLC (“we”, “us”). This policy explains what the app stores, what leaves your phone, who receives it, and the rights you have. It also covers the maju.cc website. It is written to be read on a phone. Promises first, mechanics second.
Our promises
These are the four commitments shown on the Privacy screen inside the app. They bind us, and nothing else in this policy overrides them.
- Photos stay private by default. Your photos are never uploaded to us. Nothing is shared unless you choose to share it, and you are asked each time.
- Never sold. We do not sell your photos or personal information, and do not share them for cross-context behavioural advertising, as US state privacy laws define those terms.
- Never used to train AI without your explicit opt-in. We will not use your photos or data to train any machine learning model unless you opt in through a clear, separate choice. Silence means no.
- Never paywalled. Your past photos are always yours to see and export for free. Progress you already made never sits behind a subscription.
The short version
- Maju works without an account. Everything stays on your iPhone unless you sign in. If you sign in with Apple, your routines, products, notes, and daily log details sync to your account. Your photos never leave your phone.
- Your photos, routines, notes, and settings are stored in the app’s private space on your device, protected by iOS encryption.
- To line up each photo with the last one, the app records the position of your eyes in each photo. This stays on your device, is used only for alignment, never identifies you, and is deleted with the photo.
- Maju Premium is sold through Apple and managed with RevenueCat. Section 9 lists every service we use, what it receives, and what it never receives. Local-only mode stays available.
- You can export every photo or delete everything at any time, from Settings.
1. Who we are
FBMUSSA, LLC
New York, United States. Postal address available on request.
support@maju.cc
We make Maju, listed on the App Store as “Maju: Skin Progress Tracker”. Where data protection law applies, we are the controller of the personal data described in sections 9 to 11. The providers in section 9 process data on our behalf, except Apple, which acts under its own policies.
2. Two ways to use Maju
Local-only. Always available. Everything stays on your phone. We never see your data, because it never reaches us.
With an account. Sign in with Apple to back up your log and follow friends. Signing in is optional, and you can return to local-only mode by deleting your account. Sections 9 and 10 explain what changes when you sign in.
Each section below says which version it applies to.
3. What Maju stores on your iPhone
Applies to both versions.
Photos are saved as files in the app’s private storage on your device. Your logs, routines, products, and settings live in a local database in the same private container. Both are protected by iOS data protection and your passcode.
What is stored:
- Profile. Skin type, skin concerns, an optional username, reminder times, a commitment target in days, and whether feed posts include the day’s photo by default.
- Daily logs. The photo, the date, an optional note, which routine steps you completed and how many times (for example sunscreen reapplied twice), and any routine swaps for that day.
- Face alignment data. For each photo, the coordinates of your left and right eyes, the distance between them, and the transform used to line the photo up with the previous one. See section 4.
- Skin signals. Two numbers computed on your device from each photo: an average brightness value, and a tone evenness score from 0 to 100. These are observations about an image, not a measure of skin health.
- Routines, steps, and your product shelf. Product name, brand, category, opened and finished dates, expiry months, optional SPF value, sunscreen type, and ingredients. Product details may be filled in from a built-in catalog of common skincare products.
- Demo content. Sample photos, routines, and friends, so every screen has something to show. The faces are synthetic and the friends are fictional. You can remove the demo in Settings. It never mixes with your own logs.
Backups. If iCloud Backup or a computer backup is turned on, the app’s data, including your photos, is included in that backup like any other app’s. That backup is made by Apple, under your Apple Account and Apple’s terms. It is not a Maju server, and we cannot access it.
4. Face alignment data, and what it is not
Applies to both versions.
Every time you take a photo, Apple’s Vision framework locates your eye positions, on the device, so the new photo lines up with the last one. Maju stores those two points, the distance between them, and the alignment transform, alongside the photo.
That is all it is. Maju does not create a face template or faceprint, does not identify or verify anyone, and never compares faces between people. The data is used only to align photos and to compute the skin signals in section 3. It is generated, stored, and used only on your device. It is never transmitted to us or any provider, with or without an account, so we never possess it. It is deleted when you delete the photo.
5. Photos of skin are sensitive
Applies to both versions.
Photos of your skin, and the skin type and concerns you tell us about, can reveal something about your health. We treat them as sensitive personal information, and as health data where a law defines that term. In local-only mode we never receive any of it. Photos never leave your phone, with or without an account. If you sign in, your self-reported skin type and concerns sync with your explicit consent, given when you sign in, and are visible only to you. Nothing in Maju is a diagnosis, and we do not infer health conditions from your data.
6. Permissions the app asks for
Applies to both versions.
- Camera. For your daily aligned photo. Without it you can still log your routine, but not take the photo.
- Notifications. At most two reminders a day, one morning and one evening, at times you pick. They are scheduled on your device by iOS. Turn them off or change the times in Settings, or in iOS Settings.
- Photo library. Only through Apple’s photo picker, when you choose to import an older photo. The app never scans or reads your library on its own.
- Saving to Photos. Only when you export a timelapse video and choose to save it.
You can change any permission at any time in iOS Settings › Privacy & Security.
7. What Maju does not collect
Applies to the local-only version. Section 9 lists exactly what changes when a service is added.
- No name, email address, phone number, or contact list.
- No location.
- No advertising identifier, and no tracking across other apps or websites.
- No HealthKit data.
- No analytics and no crash reports.
- No network requests except the ones listed in section 9.
8. What can leave your phone, and only when you choose
Applies to both versions. Each of these starts with a tap from you and goes through the iOS share sheet, so you pick where it goes. Whoever you send it to holds it under their own terms, not ours.
- Export my photos. All of your original photo files, untouched.
- Share a card, a before-and-after image, or a timelapse video. Where it goes after the share sheet is up to you.
- Share to feed. A preview only until the feed is switched on. Section 10 explains what a post will carry once it is.
9. Services we use, and what each one receives
Sentry and PostHog are not switched on yet. We describe them now so this policy is accurate on the day each one is turned on. None of these services ever receives your photos. None receives your notes, the product names you typed, or your username, except Supabase for accounts, as section 10 describes.
Apple
Apple provides the App Store, in-app purchases, Sign in with Apple, iOS notifications, and, if you use it, iCloud Backup. Apple processes payments. We never see your card details. Apple’s privacy policy applies to those services.
RevenueCat, for subscriptions
Purpose: handle Maju Premium and know which devices have it.
Receives: an anonymous app user ID generated by the RevenueCat SDK, your Apple purchase receipt and transaction data, device type and OS version, app version, and the country and currency of your App Store.
Never receives: photos, logs, or anything you typed.
RevenueCat privacy policy.
Sentry, for crash reports
Not switched on in the current version.
Purpose: know when the app crashes so we can fix it.
Receives: the crash stack trace, device model, OS version, app version, free memory and disk, and an installation ID.
Never receives: screenshots or screen recordings. We keep both turned off so a face is never in a crash report.
Sentry privacy policy.
PostHog, for product analytics
Not switched on in the current version.
Purpose: understand which features are used, for example how many people take a photo on day two, so we can improve the app.
Receives: event names such as “screen viewed”, “photo taken”, or “routine completed”, timestamps, an anonymous device identifier, device model, OS and app version, and a coarse region derived from your IP address.
Never receives: photo content, notes, product names you typed, or usernames. We do not record your screen. We do not track you across other apps or websites, so iOS will never show you a tracking prompt for Maju.
Hosted in: the United States.
PostHog privacy policy.
Supabase, for accounts and sync
Purpose: host the optional account described in section 10.
Receives: everything in section 10.
Hosted in: the United States.
Supabase privacy policy.
Push notifications, possibly later
Today every reminder is scheduled on your device. If we add server push for friend activity, we would store a device push token with your account so Apple can deliver the notification. We will update this section before that ships.
Each provider is bound by a data processing agreement and may use the data only to provide its service to us, never for its own purposes.
Other disclosures. Beyond these providers, we disclose personal data only when the law requires it, such as a valid court order; when necessary to protect the safety or rights of you, us, or others; or if Maju is sold or merged, in which case the new owner takes the data under this policy and our promises still apply.
10. Accounts, sync, and friends
Applies only once you create an account. Nobody is forced to. Local-only mode stays available.
Signing in. You sign in with Apple. We receive Apple’s user ID for Maju and, if you allow it, your email address and name. Apple’s Hide My Email relay is supported. We use your email only to identify your account, verify requests, and send service notices.
What syncs. Your profile (skin type, concerns, username, reminder times, and commitment target), your daily logs without the photo (the date, whether a photo was taken, your note, the routine steps you completed, and the two skin-signal numbers), your routines, and your product shelf. Face alignment data and demo content never leave your phone.
Who can see what.
- Your notes and logs: only you. Your photos: nobody, because they are never uploaded.
The feed is not switched on yet. When it is:
- A feed post: your friends. A post carries the day number and rhythm stats. Including the photo is opt-in per post and off by default. You can change the default in Settings.
- Comments, likes, and reactions: the friends who can see the post they are on. There is no public profile and no public feed.
- Routine changes: shared only if you tap “share this?” on each one. Nothing is ever auto-posted.
Friends. You add friends by username or by invite link. Usernames are chosen by you, are unique, and are filtered for profanity and slurs. Friends see your username and what you choose to share, nothing else.
Face alignment data stays on your phone. The two skin-signal numbers sync with your log, are visible only to you, and are deleted with it.
No automated decisions. We make no automated decisions with legal or similarly significant effects on you, and build no advertising profiles.
11. How long we keep data
- On your device. Until you delete it in the app, or delete the app.
- Account data. For as long as your account exists. When you delete your account we delete it immediately, and it drops out of our encrypted database backups within 7 days. Photos are never on our servers, so nothing about them is in those backups. We keep a record only where tax or legal rules require it, and only for as long as they require.
- Purchase records. Kept by Apple under Apple’s policies, and by RevenueCat for as long as we use their service.
- Crash reports. 90 days, then deleted by Sentry.
- Analytics events. Up to 7 years with PostHog, which sets that period and does not offer a shorter one. You can ask us to delete the analytics data tied to your device at any time.
- Server and website logs. Our hosting providers keep request logs, which include your IP address, for 7 days. The maju.cc website sets no cookies and runs no analytics.
- Support emails. Up to two years after your request is closed, so we have a record of what we told you.
12. Deleting your data
- Local-only. In the app, Settings › Delete everything removes every photo, log, routine, product, and setting on the device. There is no undo. Deleting the app does the same.
- With an account. In the app, Settings › Delete account. This deletes your account and every copy of your data on our servers, immediately. Your photos were never there. Database backups roll off within 7 days, as section 11 explains.
- Cannot open the app? Email support@maju.cc from the address on your account and we will delete it within 30 days of confirming the request came from you.
- Analytics. Email us and we will delete the analytics data tied to your device.
- Subscriptions are managed by Apple. Deleting your data or your account does not cancel a subscription. Cancel in Settings › Apple Account › Subscriptions.
Step-by-step instructions are on the support page.
13. Your rights
Wherever you live, you can ask us to access, correct, delete, or export the personal data we hold about you, to object to or restrict how we use it, or to withdraw consent. Email support@maju.cc. We will verify your identity, respond within 30 days, and will not treat you differently for exercising your rights. If we refuse a request, we will say why and how to appeal. In local-only mode we hold nothing about you, so the fastest route is the app’s own export and delete controls.
UK, EU, and EEA. Our legal bases are: performing our contract with you, for accounts, sync, and subscriptions (Article 6(1)(b) GDPR); our legitimate interest in keeping the app secure and working, for crash reports and server logs (Article 6(1)(f)); consent for product analytics where the law requires it, and otherwise legitimate interest; and your explicit consent for syncing your self-reported skin type and concerns (Article 9(2)(a)). You can withdraw consent at any time by deleting your account or emailing us. You also have the right to complain to your data protection authority. We have not appointed a representative in the EU or UK, because our processing of data about people there is occasional. If the law comes to require one, we will appoint one and name them here.
California and other US states. In the past twelve months we have collected, directly from you or your device and for the purposes in sections 9 and 10, these categories: identifiers (account and device IDs, and your email address and name if you provide them), purchase records, usage and crash data once those services are on, and, if you create an account and sync, self-reported skin information. We treat that skin information as sensitive personal information and, where state law uses the term, as consumer health data. We disclose these categories only to the service providers in section 9. We do not sell personal information, do not share it for cross-context behavioural advertising, use sensitive information only to provide the service, and offer no financial incentives for data. You have the right to know, correct, delete, opt out, and limit the use of sensitive information, and not to be discriminated against for exercising those rights. You can appoint an authorised agent to make a request for you.
International transfers. Maju is operated from the United States. If you create an account from outside the US, your data is transferred to and processed in the US by us and our providers, under standard contractual clauses or an equivalent safeguard where the law requires one.
14. Children
Maju is for people aged 16 and over. It is not directed to children, and we do not knowingly collect personal information from anyone under 16. If you believe someone under 16 has created an account, email support@maju.cc and we will delete it.
15. Security
Data on your iPhone is protected by iOS data protection and your passcode. The app uses only the standard encryption built into iOS. Data sent to our providers travels over encrypted connections and is stored encrypted at rest. Your photos are never sent to our servers, so there is no cloud copy of them to secure. No system is perfectly secure, so we keep what we hold to the minimum the service needs. If a breach affects your data, we will notify you and the relevant authorities as the law requires.
16. Changes to this policy
If we change this policy in a way that matters, for example when one of the services in section 9 is turned on, we will tell you in the app before the change takes effect and update the date and version at the top. A change that weakens one of our promises, or expands how we use sensitive data, will apply to data already collected only with your fresh consent. Earlier versions are available on request.
17. Contact
FBMUSSA, LLC · New York, United States · Postal address available on request
support@maju.cc