Last updated: August 4, 2026 · Effective: the date you first open the app
Who we are
Jineo is published and operated by Universal AI LLC, a Maryland limited liability company ("we", "us", "Jineo"). The app is distributed on the App Store under the Universal AI LLC organization account.
Optional health & wellness inputs — if you turn on cycle-aware skincare, add a pregnancy filter, or list ingredient allergies, those entries (your last-period date / cycle phase, pregnancy status, and allergy list) are included in the relevant AI request via our secure proxy so Hana and your scan results can respect them. They are stored on your device, never stored on our servers, never used for advertising or tracking, and deleted with your data. (OpenAI, acting as our processor, may retain the request up to 30 days for abuse monitoring, then deletes it.) These features are optional — skincare guidance works without them.
Your selfie for skin analysis is sent, over an encrypted connection via our secure proxy, to OpenAI's Vision API for a single one-time analysis, then discarded — it is never stored on our servers and never used to train any model. You give explicit consent before any photo is sent.
Your skin scores, scan history, and diary entries stay on your device. If you opt in to Glow Circle, only your ritual-completion dates and a pseudonymous handle sync to power buddy streaks.
We do not sell your personal data. We do not use it to train AI. We do not share it with advertisers.
Purchase processing happens through Apple. We see whether you're a paying subscriber (via RevenueCat) but we never see your payment method.
What we collect
Stored on your device
Your onboarding answers (skin goals, season, sensitivity)
Your scan results (scores, skin type, personal color, concerns and sub-scores), your routines and your scan history — these live on your device and are never persisted to our servers
A copy of each scan selfie, saved for your skin timeline — normally a downscaled thumbnail (see "Camera and photos" below)
Your diary entries (photos + notes you save yourself)
Your streak and ritual progress
Sent to OpenAI for a one-time analysis, then discarded
Your selfie for skin analysis — transmitted over an encrypted connection, via our Supabase edge proxy, to OpenAI's Vision API for a single analysis. It is not stored on our servers, not used to train any model, and not forwarded to anyone after analysis. (OpenAI, acting as our processor, may retain the API request up to 30 days for its own abuse monitoring under its API terms, then deletes it.)
Kept on our servers (pseudonymous, for abuse-prevention + cost control)
An anonymous user ID (a UUID we generate) and your Pro subscription status (via RevenueCat)
A scan-activity record — a device/account identifier, the scan type, and a salted one-way hash of your IP address (never the image, never your skin results) — kept up to 90 days, then auto-deleted
Not collected
Any copy of your selfie on our servers (the image sent for analysis is discarded immediately afterwards; the timeline copy described under "Camera and photos" stays on your device and is never uploaded)
Any facial-recognition template — we do not identify you from your face
Your contacts, location, bank details, social accounts
Advertising identifiers
Your Apple ID password
Your payment details
How we use what we collect
Provide the service — your scan scores drive product matches and nightly protocols
Subscription restore, not data sync — there is no cloud sync of your skin data. Your scan scores, routines, diary and scan history stay on the device that created them and do not follow you to another iPhone or iPad. Only your Pro entitlement restores across your own devices, through Apple
AI coaching — Hana, your in-app coach, is powered by a large language model from OpenAI; your questions and relevant profile context are sent to generate each reply
Subscription management — RevenueCat tracks entitlement state so Pro unlocks across devices
Crash diagnostics — Sentry is active in the app today (this policy previously described it as something we might add later). It is consent-gated in Settings, and email, IP and username are scrubbed before send — but your pseudonymous Jineo account id IS attached to each event, so these reports are linked to your anonymous account rather than fully anonymous. Product analytics (PostHog) works the same way
We never:
Sell your data to third parties
Use your selfies, scan scores, or diary to train any machine-learning model
Share your data with advertisers
Read your photo library beyond what you explicitly pick
Camera and photos
Jineo requests camera access to capture a skin-analysis selfie and to scan product ingredient labels / barcodes. Each selfie is:
Captured only after you give explicit consent on our AI-consent screen
Sent over an encrypted connection, via our secure Supabase edge proxy, to OpenAI's Vision API for a single one-time analysis
Discarded immediately after your score returns — never stored on our servers, never used to train any model
One thing that is kept, so you are not surprised by it: after each scan a copy of your selfie is saved on your device for your skin timeline, so you can see your progress over time. This is a downscaled thumbnail. (In app versions 1.0.1115 and earlier, if the downscaling step failed the original image was saved instead; from the next release onward nothing is saved at all when downscaling fails, so the copy on your device is always a thumbnail.) Either way it is kept on your device only — excluded from iCloud and iTunes backup, never uploaded to our servers, and removed when you delete your data or your account (Settings → Delete account). The copy sent to our AI proxy for analysis is separate and is not kept on our servers.
If you choose "Save to photos" on a result share card, that's the only time a Jineo-generated image reaches your photo library — and you initiate it explicitly.
Biometric information (Illinois, Texas, Washington)
When you scan, Jineo's AI examines the geometry and surface of your face — the position and appearance of features, pores, and marks — to produce your cosmetic skin read. We treat this as biometric information. We do not create a facial-recognition template, we do not use it to identify you, and we do not retain the facial geometry: your image and every coordinate derived from it are sent to the OpenAI Vision API for a single analysis and discarded immediately after your score returns. No readable image data persists on our servers.
Residents of Illinois, Texas, and Washington: by checking the biometric-consent box on our AI-consent screen and taking a selfie, you give informed, written, opt-in consent to this biometric collection under 740 ILCS 14/15 (BIPA), Texas Bus. & Com. Code §503.001 (CUBI), and RCW 19.375 (Washington). Retention & destruction: the selfie sent for analysis and the facial geometry derived from it are held only transiently on our servers — in memory for the one-time analysis — and are destroyed upon return of your score; they are never written to durable storage on our servers, and the facial geometry is never written to durable storage anywhere. The on-device timeline copy described under "Camera and photos" stays on your device only and is deleted when you delete your account. You may withdraw consent at any time by deleting your account (Settings → Delete account).
Subscriptions and payments
Jineo offers in-app subscriptions:
Weekly: $9.99 / week (no free trial — billed immediately)
Annual: $79.99 / year (includes a 3-day free trial)
Payment is processed by Apple. Subscriptions auto-renew unless canceled at least 24 hours before the end of the current period. Manage or cancel anytime in Settings → Apple ID → Subscriptions.
We use RevenueCat to verify entitlement state. RevenueCat stores an anonymous identifier and subscription status — never your payment details.
Your rights
Depending on where you live, you have rights to:
Access your data
Request deletion of your data
Correct inaccurate data
Port your data to another service
Object to certain processing
Email contact@universalaillc.com with the subject line "Jineo Data Request" and we will respond within 30 days.
EU / UK users (GDPR): our legal basis for processing is (a) performing the service you asked for, (b) your consent where required, and (c) our legitimate interest in operating a safe product. You have the rights listed above plus the right to lodge a complaint with your local supervisory authority (e.g. ICO in the UK, CNIL in France).
California users (CCPA / CPRA): we do not sell or share personal information for cross-context behavioral advertising. We do not knowingly collect data from minors under 16. You may request a copy of categories collected, deletion, and correction by emailing the address above; we will not retaliate for exercising these rights.
How to delete your account: in the app go to Settings → Delete account, or email contact@universalaillc.com with the subject "Delete my Jineo account". We will erase your data within 30 days.
Data retention
Selfies: discarded immediately after the one-time OpenAI analysis (never written to our durable storage; OpenAI may retain the API request up to 30 days for its own abuse monitoring, then deletes it)
Scan-activity record (device/account id, scan type, salted IP hash — never the image): up to 90 days, then auto-deleted
Scan scores, routines and scan history: stored on your device — kept until you delete your data, delete your account, or remove the app. They are never persisted to our servers, so there is nothing on our side to retain
Scan timeline thumbnail: stored on your device on the same basis as your scores above, and removed when you delete your data or your account
Diary entries: retained until you delete them or close your account
Subscription status: retained as long as required by tax + accounting law (typically 7 years post-termination)
Children
Jineo is rated 4+ for content, but the service is not directed to children under 13. We do not knowingly collect information from children under 13. If we learn we have, we will delete it. Parents/guardians can email us to request deletion.
Third-party services
We use a small number of well-known vendors:
Apple — app distribution, in-app purchases
Supabase (US) Inc. — edge-function proxy + account database
OpenAI — AI skin-scan analysis (Vision API) and the Hana coach (language model)
RevenueCat, Inc. — subscription entitlement verification
ElevenLabs — Hana voice text-to-speech (Pro only; text-only payloads, no user identifiers)
Each vendor processes data only as our contracted data processor. None of them receives your data to sell or to train their own models on your identity.
Each vendor processes data only as our contracted data processor. We have data-processing addenda with all of them.
International transfers
Our primary servers are in the United States. If you use Jineo from outside the US, your data may be transferred to and processed in the US. Where required by law (e.g. EU → US), we rely on Standard Contractual Clauses or the EU-U.S. Data Privacy Framework.
Security
All traffic is encrypted (TLS 1.2+)
Stored data is encrypted at rest
Access is restricted to authorized engineers via SSO
We run regular dependency audits
No service is 100% secure. If we discover a breach that affects you, we will notify you within the legal notification window.
Changes to this policy
We may update this policy. Material changes will be announced in the app and via the "Last updated" date above. Continued use after a material change constitutes acceptance of the revised policy.