Legal
Privacy Policy
Effective Date: September 4, 2026 Last Updated: September 4, 2026
Juni is a product of GlowMax, Inc. ("GlowMax," "we," "us," "our"), a Delaware corporation. GlowMax, Inc. is the data controller for personal data processed through the Juni Services, except as stated in the regional modules below.
- Notice address: 1111b South Governors Av #42569, Dover, DE 19904, USA
- Privacy contact: legal@juni.skin
- Website: https://juni.skin
This Privacy Policy explains what we collect, why, how long we keep it, who we share it with, and your rights. It incorporates the Terms of Service and the Biometric Consent. Regional modules for the EEA/UK, U.S. states, Canada, Australia, and MENA appear in Sections 14–18.
1. SCOPE AND PRECEDENCE
1.1 This Policy covers the Juni website (juni.skin), iOS/Android apps, the Juni hardware device, the waitlist, subscriptions, and support channels (collectively, the "Services"). It applies to all users globally from day one, subject to Section 14.1's EEA gating. If you are under 18, you may not use the Services (see Section 12).
1.2 Single age clause. Terms of Service §2.1 (18+ floor) is the single source of truth for eligibility and is incorporated here by reference. Nothing in this Policy authorizes collection from, or sale of data of, minors.
1.3 Master precedence clause. Conflicts are resolved in this order: (1) the Biometric Consent (Biometric Data); (2) this Privacy Policy, including its regional modules (data collection, retention, sale, rights); (3) the Terms of Service. Within this Policy, the regional modules (Sections 14–18) control over the general sections for users in those regions, and Sections 5.1 (retention table), 7.3 (never-sold categories), and 15.4 (consumer health data no-sale rule) control over any general statement elsewhere in this Policy or the Terms, including Terms §8.
2. DATA CATEGORIES WE COLLECT
| # | Category | Examples | Source |
|---|---|---|---|
| 1 | Account & Identity | Name, email, date of birth, password hash | You |
| 2 | Survey & Profile | Age, skin type, skin concerns, goals | You |
| 3 | Facial Images & Scans | Facial photographs; skin scan outputs; TEWL, pressure, bioimpedance, and other sensor readings | You / Device |
| 4 | Biometric Data | Faceprints / facial geometry, templates, and embeddings derived from photos; other data defined as biometric under local law | Derived from images you submit |
| 5 | Connected Health Data | Data you authorize from Apple HealthKit / Google Health Connect | Your device, with permission |
| 6 | Location | Precise or approximate geolocation (UV/climate features) | Your device, with permission |
| 7 | Device & Identifiers | Device model, OS version, IDFA/GAID, Juni hardware ID, IP address | Automatic |
| 8 | Usage & Analytics | Screen views, feature usage, session duration, taps, scan frequency, crash logs | Automatic |
| 9 | Transactions | Purchases, subscription status, payment metadata (card data held by processor) | You / processor |
| 10 | Communications | Support messages, feedback, marketing engagement | You |
| 11 | Inferences | Skin scores, recommendations, segments, model-derived attributes (excluding inferences derived from Connected Health Data, which are never sold or shared — Section 7.3) | Derived |
Sensitive data. Categories 3–5 (and inferences drawn from them) may constitute sensitive personal information, biometric information, health data, or "consumer health data" under various laws. We process them only as described here and in the Biometric Consent, with the consents required by your jurisdiction. Category 4 (Biometric Data) and Category 5 (Connected Health Data) are firewalled: neither is ever sold, and neither is de-identified into commercial datasets — see Sections 5.1, 7.3, and Terms §§9–10.
3. PURPOSES OF PROCESSING
We process the categories above to:
1. Provide, operate, and personalize the Services (scan analysis, recommendations, UV/climate features); 2. Create and manage accounts, the waitlist, orders, warranty service, and subscriptions; 3. Train, validate, and improve AI/ML models (on-device, cloud, or hybrid), including through third-party AI providers acting as our processors; 4. Create, sell, license, and commercialize De-Identified/aggregated datasets, models, analytics, and derived products, and — only with a valid opt-in Commercial Data Consent (Terms §8.3) where the user is identifiable — license individual-level data to commercial partners, including cosmetics, skincare, and beauty companies (see Section 7); 5. Quality assurance and accuracy validation, including review by external dermatologists and skincare professionals under confidentiality obligations (internal QA only; not marketed as medical review); 6. Analytics, product improvement, debugging, and security; 7. Marketing and communications (with opt-out; consent where required); 8. Legal compliance, fraud prevention, enforcement of our Terms, and defense of legal claims.
EEA/UK legal bases are listed in Section 14.
4. AI TRAINING AND THIRD-PARTY AI PROVIDERS
4.1 Your User Data — including skin images, sensor readings, and survey responses — is used to train Juni's proprietary models under the Service License (Terms §8.2). Biometric Data is trained on only per the Biometric Consent and destroyed per Section 5.1; Connected Health Data is used only for the Services' health/wellness features (Terms §10.2). HIPAA framing: where you direct a HIPAA-covered entity (e.g., your physician or health plan) to share records with Juni, Juni is not a "Business Associate" of that entity, and those records are not regulated under HIPAA once in Juni's possession, though such data remains "consumer health data" under applicable state laws (Section 15.4); they are instead governed by this Policy and the Connected Health Data firewall (Sections 2, 5.1, 7.3), which this sentence does not weaken.
4.2 Processing may occur on-device, in our cloud, or via third-party AI/ML providers (e.g., Anthropic, OpenAI, Google, or successors) acting as our processors/sub-processors under written contracts requiring confidentiality, security, use limitation, and zero-retention / no-training settings for identifiable data. The current sub-processor list, with processing locations, is maintained at juni.skin/legal/subprocessors with change notice.
4.3 EEA/UK users: AI training beyond what is necessary to provide the Services relies on the legal bases in Section 14, and opt-in consent is used where required.
5. RETENTION
5.1 Retention Schedule (CPRA per-category disclosure; identical to Terms §9.2 for Biometric Data)
| Category | Retention Period |
|---|---|
| Account & identity | Duration of account + 2 years after deletion or last activity |
| Survey & profile | Duration of account + 2 years |
| Facial images & scans (identifiable) | While account is active; de-identified (per §5.3 standard) upon deletion |
| Scan derivatives (non-biometric features only — no faceprints, templates, embeddings, or anything from which identity can be reconstructed) | May be retained for model training and datasets |
| Biometric Data (faceprints/templates/embeddings) | Permanently destroyed (not de-identified) at the earliest of: (a) verified account deletion/deletion request; (b) withdrawal of biometric consent; (c) 3 years after your last interaction with the Services. No model-training exception. Identical schedule in Terms §9.2. An independent third-party auditor verifies the destruction method and the non-reconstructibility of retained features (audit log available to regulators on request); our Data License Agreements represent that retained features are non-biometric, with indemnity. |
| Connected Health Data (Apple Health / Health Connect) | Deleted upon account deletion or sync revocation + 30 days. Never sold, never used for advertising/marketing/data brokerage, never de-identified into datasets or licensed products; inferences derived from it are excluded from all sold/shared categories. |
| Location (precise) | Raw precise location: up to 12 months; derived climate/UV context: retained with scan data. Precise geolocation is not sold. |
| Device & identifiers | Duration of account + 1 year |
| Usage & analytics | 3 years, then aggregated/anonymized |
| Transactions & tax records | 7 years (legal/accounting requirement) |
| Marketing data | 2 years after last engagement or opt-out |
| Communications/support | 3 years after resolution |
| Waitlist data | Until launch + 2 years, or until you unsubscribe |
5.2 Point-of-Collection Notice
The retention periods above are disclosed at or before the point of collection (short-form notice on the signup and first-scan screens linking to this table, plus in-app notices), as required by CPRA §1798.100(a)(3).
5.3 De-Identification Standard and Post-Deletion Retention
De-identification standard (CPRA §1798.140(m) / FTC standard adopted verbatim): de-identified data is (a) processed so it cannot reasonably be linked to any consumer or household; (b) subject to our public commitment not to re-identify; (c) protected by technical and organizational controls preventing re-identification; and (d) shared only under contracts prohibiting re-identification and requiring recipients to honor deletion flow-downs. Deletion removes identifiable personal data; it does not require retrieval of data meeting this standard, truly aggregated data, or trained models. It does trigger our downstream deletion-propagation obligations for identifiable data previously sold/licensed (Section 6.4(c)).
6. DELETION PROCESS
6.1 How to request: In-app (Settings → Privacy → Delete My Data) or email legal@juni.skin with subject "Deletion Request."
6.2 Verification: We verify identity via account authentication and, where needed, additional information proportionate to the sensitivity of the data.
6.3 Timing: We fulfill verified requests within 45 days (+45 extension with notice) per CCPA/CPRA; GDPR one-month standard (+two-month extension) honored for EEA/UK users.
6.4 Scope: Deletion covers identifiable personal data in production systems, subject to: (a) legal holds and compliance obligations (e.g., 7-year transaction records); (b) backups, which roll off on their normal cycle (≤90 days); (c) downstream propagation — for identifiable data previously sold or licensed, our Data License Agreements require each recipient (and its sub-licensees, by flow-down) to delete your data upon our notice within a contractual SLA, and we transmit deletion notices for all verified requests and upon any revocation of the Commercial Data Consent (Terms §8.3(b)) — our Data License Agreements mandate delete-or-certify on revocation, not only on account deletion; and (d) data meeting the Section 5.3 de-identification standard, aggregated data, and trained models, which are exempt.
6.5 Biometric deletion: Identifiable Biometric Data (including templates/embeddings) is permanently destroyed upon verified deletion request, consent withdrawal, or the Section 5.1 schedule, whichever is earliest.
7. SALE, SHARING, AND MONETIZATION OF DATA
7.1 Our model. Licensing and selling data-derived products is a core part of our business. We may sell or license: (a) aggregated and De-Identified (per §5.3) datasets; and (b) individual-level data (skin images, scan data, survey responses) only where the user has opted in via the Commercial Data Consent (Terms §8.3), and never in the categories listed in Section 7.3 regardless of consent.
7.2 CCPA/CPRA opt-out. California residents may opt out of "sale"/"sharing" at any time via the "Do Not Sell or Share My Personal Information" link and in-app toggle (Settings → Privacy), at juni.skin/do-not-sell, or through a recognized Global Privacy Control (GPC) signal on web; for in-app/SDK-side sale, the in-app toggle serves as the equivalent opt-out mechanism. These mechanisms are live and tested before we claim compliance. Opt-outs are symmetric (no dark patterns).
7.3 What we never sell (controlling over Sections 7.1 and 7.4): (a) Biometric Data (faceprints/templates/embeddings) — prohibited outright (BIPA §15(c)); (b) Connected Health Data and inferences derived from it — prohibited by platform policy and Terms §10.2; (c) "Consumer health data" of Washington, Nevada, or Connecticut residents — prohibited outright by MHMD/NV SB 370/CT law; consent cannot cure this, and this no-sale rule controls over Section 7.1(b) and Terms §8; (d) precise geolocation; (e) data of any person under 18 — the Services are 18+ (Terms §2.1), and we do not knowingly collect from or sell data of minors at all.
7.4 Categories that may be sold/shared (forward-looking disclosure). Pre-launch statement: we have not sold or shared any personal information in the preceding 12 months. Upon launch of the Commercial Data Consent program, the categories that may be sold/shared to data partners (cosmetics/skincare/beauty companies) and analytics/advertising partners are: identifiers; commercial information; internet/electronic activity; coarse (non-precise) location/derived climate context; sensory data (non-biometric images, only under a valid Commercial Data Consent); and inferences (excluding any inference derived from Connected Health Data). Consent gate (controlling): every category listed in this Section 7.4 is disclosed to commercial data partners and analytics/advertising partners only under a valid Terms §8.3 Commercial Data Consent (opt-in); the §8.3 consent instrument — not your non-opted-out status under Section 7.2 — is the sole gate for all commercial disclosure under this Section. This table will be updated to reflect actual practice annually.
7.5 Text-Messaging Consent Data. Your SMS/text-messaging opt-in status and consent data are not shared with, sold to, or disclosed to any third party for that third party's marketing (consistent with 10DLC/CTIA requirements), except to service providers administering the messaging program on our behalf. They are used only to administer the Juni messaging program and to honor opt-outs (Terms §24).
7.6 No dark patterns. Opt-out mechanisms are symmetric, non-deceptive, and as easy as opt-in (CPRA regs §7004).
8. THIRD-PARTY SHARING CATEGORIES
We disclose personal data to the following categories of recipients, under contract:
| Recipient Category | Purpose | Data Categories |
|---|---|---|
| Cloud hosting & infrastructure | Hosting, storage, compute | All (excluding Biometric Data except per Biometric Consent) |
| AI/ML model providers (zero-retention/no-training for identifiable data) | Model training & inference | Images, scans, survey, inferences |
| Payment processors | Payments, fraud prevention | Transactions, identity |
| Email/SMS platforms (e.g., Brevo) | Communications, marketing | Contact, engagement |
| Analytics providers (named on sub-processor page; no scan/consent-screen capture) | Usage analytics | Usage, device, identifiers |
| Professional partners (dermatologists/skincare advisors) | Internal QA, accuracy validation | Scans, images (minimized) |
| Commercial data partners (cosmetics/skincare/beauty) | Licensed datasets/insights under Data License Agreement with deletion flow-down, re-identification ban, and audit rights | Per Section 7 |
| Legal, auditors, insurers | Compliance, defense | As needed |
| Government/law enforcement | Valid legal process only | As required |
| Successor entities | Merger, acquisition, asset sale | All (with notice where required) |
We do not permit service providers to use personal data for their own purposes except as permitted by law.
9. COOKIES AND TRACKING
9.1 We use cookies, SDKs, pixels, and similar technologies for: strictly necessary operations; preferences; analytics; and (with consent where required) advertising/measurement. Analytics vendors are named on the sub-processor page.
9.2 Pre-collection consent: EEA/UK and other consent-required jurisdictions see a consent banner before any non-essential tracking. California users see a pre-collection consent banner before analytics SDKs or any session-replay tooling loads (CIPA §631 compliance); declining disables those SDKs. Analytics SDKs are contractually and technically prohibited from capturing scan, photo, or consent screens.
9.3 Controls: All users can control cookies via browser settings, use GPC (honored as an opt-out of sale/share), reset mobile ad IDs, and use Apple App Tracking Transparency (no IDFA access before ATT consent) / Android privacy settings.
9.4 Cookie Policy. Full details — cookie types (strictly necessary, preference, analytics, and, with consent where required, advertising), first- and third-party cookies, purposes, retention periods, and how to manage preferences — are in our standalone Cookie Policy at juni.skin/legal/cookies. GPC honoring applies as stated in Section 9.3.
10. SECURITY
We maintain administrative, technical, and physical safeguards appropriate to the sensitivity of the data, including encryption in transit (TLS) and at rest, access controls and least-privilege, segregation of biometric templates, vendor security review, and incident-response procedures. We will notify you and regulators of breaches as required by law.
Payment processing (PCI-DSS). Card payments are processed by PCI-DSS-validated payment processors. As of the Last Updated date, Juni receives and stores only the minimum necessary card data (e.g., last four digits and card brand for receipts); Juni does not store full card numbers, CVVs, or magnetic-stripe data.
11. INTERNATIONAL TRANSFERS
11.1 Data is processed primarily in the United States. For transfers of EEA/UK/Swiss personal data to countries without an adequacy decision, we rely on: (a) the European Commission's Standard Contractual Clauses (2021/914) and the UK IDTA/Addendum; (b) documented Transfer Impact Assessments (TIAs) for each transfer and sub-processor, addressing third-country government-access laws (including FISA 702), retained and produced to supervisory authorities on request; (c) supplementary measures (encryption with keys under our control, access controls, pseudonymization) selected per TIA; and (d) where applicable, adequacy regulations. Sub-processor locations are published at juni.skin/legal/subprocessors. Where a TIA concludes protections are insufficient for a data category, that category is processed in-region or not transferred.
11.2 Canada (PIPEDA/Law 25): Data may be processed outside Canada/Quebec; we use contractual protections comparable to Canadian requirements, conduct Law 25 PIAs for cross-border communication, and provide required transparency.
11.3 Australia: Overseas disclosures are made with reasonable steps to ensure recipients comply with the APPs (APP 8), or with consent.
11.4 MENA/PDPL: Transfers from KSA/UAE and other PDPL jurisdictions occur only with the safeguards or consents those laws require.
12. MINORS
12.1 The Services are for users 18 and older (Terms §2.1, the single source of truth). We do not knowingly collect personal information from anyone under 18, and not from children under 13 under any circumstances (COPPA).
12.2 Age assurance and purge protocol: date-of-birth entry, Terms acceptance, in-app confirmation, and automated face-analysis age screening on scan uploads. Uploads flagged as potentially depicting a minor are rejected and purged within 24 hours, without being used for training, sale, or any other purpose. Suspected minor accounts are terminated and their data deleted. This technical protocol supplements — and does not rely solely on — user representations.
12.3 If you believe a minor has provided data, contact legal@juni.skin; we will delete it.
12.4 Should we ever offer the Services to users 13–17, every governing document (Terms §2.1, this Section, and Section 7) will be amended simultaneously before launch, and we will first implement jurisdiction-specific consent: verifiable parental consent (COPPA, under 13), minor or parental opt-in for sale/share (CPRA, 13–15), GDPR member-state digital-consent ages (13–16), and equivalent mechanisms elsewhere.
13. YOUR RIGHTS
13.1 All Users
Access your data, correct inaccuracies, delete your account, withdraw consent (with effect going forward), revoke the Commercial Data Consent, and export core data via in-app tools or legal@juni.skin.
13.2 U.S. State Privacy Rights (CA, VA, CO, CT, UT, TX, OR, MT, and similar laws)
Subject to verification and legal exceptions: Access/Know; Delete (Section 6 process, including downstream propagation per §6.4(c)); Correct; Portability; Opt out of sale/share, targeted advertising, and certain profiling (Section 7.2; GPC honored); Limit use of sensitive PI (CA); Non-discrimination (except disclosed data-value programs reasonably related to the value of your data); Appeal denied requests by replying "Appeal."
Authorized agents may submit requests with proof of authorization; we may verify you directly.
13.3 EEA/UK/Switzerland
Access, rectification, erasure, restriction, portability, objection, withdrawal of consent, automated-decision safeguards, and the right to lodge a complaint with your supervisory authority. See Section 14.
13.4 Canada
Access and correction (PIPEDA); Quebec residents additionally have rights to de-indexation, portability (Law 25), and to contact our Privacy Officer at legal@juni.skin.
13.5 Australia
Access and correction under APPs 12–13; complaints to us and then the OAIC.
13.6 MENA
Rights under applicable PDPLs via legal@juni.skin.
14. EEA/UK/SWITZERLAND MODULE (GDPR/UK GDPR)
14.1 Controller: GlowMax, Inc. EU Representative (Art. 27) and UK Representative will be appointed, and their identities published here, before any EEA/UK/Swiss user is accepted onto the waitlist or Services; until then, EEA/UK/Swiss signups are not accepted. DPO: formally assessed and appointed (external/as-a-service permitted) before EEA launch given large-scale special-category processing; contact: legal@juni.skin.
14.2 Legal bases (Art. 6/9):
| Purpose | Legal basis |
|---|---|
| Provide Services, scans, recommendations | Contract (Art. 6(1)(b)); explicit consent for special-category data (Art. 9(2)(a)) |
| Account, orders, subscriptions, warranty | Contract; legal obligation (Art. 6(1)(c)) |
| AI training & product improvement | Legitimate interests (Art. 6(1)(f)) where balancing supports it; otherwise consent |
| Sale/licensing of identifiable personal data | Explicit opt-in consent only (Art. 6(1)(a), 9(2)(a)) — never a condition of service |
| Marketing | Consent or soft opt-in where permitted |
| Security, fraud, legal claims | Legitimate interests; legal obligation |
14.3 Consent is not a condition. Where consent is the basis, refusal or withdrawal does not prevent use of the core Services (GDPR Art. 7(4)). Consent screens are granular (separate toggles for AI training, data licensing, marketing, biometrics). This Section is consistent with Terms §8: the Terms' condition-of-use Service License (§8.2) covers only service operation and De-Identified datasets, while sale/licensing of identifiable data (Terms §8.3) is optional and revocable everywhere.
14.4 No solely automated decisions with legal/significant effect are made without safeguards (Art. 22).
14.5 Complaints: your local supervisory authority (EEA) or the ICO (UK).
15. U.S. STATE MODULE
15.1 California (CCPA/CPRA): Sections 2, 5, 7, and 8 constitute our CPRA notices at collection. Rights in Section 13.2. "Do Not Sell or Share": juni.skin/do-not-sell and in-app toggle; GPC honored on web with in-app equivalent for SDK-side sale. Non-discrimination per Section 13.2.
15.2 Illinois (BIPA): Written informed release before capture (Terms §9.1); public retention/destruction schedule (Section 5.1, identical to Terms §9.2); destruction — not de-identification — of templates/embeddings at the earliest trigger; no sale, lease, trade, or profit from Biometric Data; disclosure only with consent, to contracted service providers, to complete a requested transaction, or as legally required.
15.3 Texas (CUBI; TDPSA): Biometric identifiers captured only with informed consent; not sold; destroyed per schedule. TDPSA rights per Section 13.2.
15.4 Washington MHMD / Nevada SB 370 / Connecticut (controlling provision): Consumer health data is collected only with separate, MHMD-compliant consent presented before first scan for WA/NV/CT users. We do not sell consumer health data — period; this prohibition is categorical, cannot be cured by consent, and controls over Section 7.1(b), Section 7.4, and Terms §8. No geofencing around health facilities. MHMD rights (deletion, third-party-sharing confirmation) via legal@juni.skin.
15.5 Other states (VA, CO, CT, UT, OR, MT, IA, IN, TN, DE, NJ, NH, RI, etc.): Rights in Section 13.2 apply per each statute's scope; sensitive-data opt-in consent obtained where required. Data-broker note: we will register where required under the CA Delete Act (SB 362) and TX/OR/VT broker statutes following completion of a per-state analysis before the first commercial data sale, including readiness for the California DELETE Act central deletion mechanism (2026).
16. CANADA MODULE (PIPEDA / QUEBEC LAW 25)
16.1 Privacy Officer: legal@juni.skin. We collect, use, and disclose personal information with knowledge and consent, except as permitted by law.
16.2 Quebec: This Policy, the Terms, and all consent flows are provided in French at Quebec launch (adhesion-contract requirement — not merely on request); privacy settings default to the highest level for non-essential functions; we conduct PIAs for cross-border communication and biometric processing and will make any required CAI declaration before operating a biometric database in Quebec.
16.3 Rights: access, correction, and (Quebec) portability and de-indexation.
17. AUSTRALIA MODULE (PRIVACY ACT 1988 / APPs)
17.1 We handle personal information per the Australian Privacy Principles. Sensitive information is collected only with consent (APP 3.3).
17.2 Overseas disclosure: Section 11.3. Access/correction: Section 13.5. Complaints: legal@juni.skin, then the OAIC.
17.3 Notifiable Data Breaches: we notify affected individuals and the OAIC of eligible data breaches.
18. MENA MODULE (KSA PDPL, UAE PDPL, AND SIMILAR LAWS)
18.1 Personal data of users in KSA, UAE, and other MENA jurisdictions is processed per applicable PDPLs: lawful basis or consent as required; sensitive-data consent obtained; cross-border transfers per Section 11.4 and local rules.
18.2 Rights: access, correction, deletion, withdrawal of consent, and complaint to the competent authority (e.g., SDAIA in KSA) via legal@juni.skin.
19. CHANGES TO THIS POLICY
We may update this Policy. Material changes get at least 30 days' advance notice by email and prominent in-app notice, and renewed consent where required by law (including GDPR, Law 25, and MHMD). The "Last Updated" date reflects the current version.
20. CONTACT / DPO
GlowMax, Inc. dba Juni — Privacy / Data Protection 1111b South Governors Av #42569, Dover, DE 19904, USA Email: legal@juni.skin
Privacy rights requests: in-app (Settings → Privacy) or legal@juni.skin. We respond within the statutory period applicable to you (45 days CCPA; one month GDPR; 30 days PIPEDA).
21. LAW-ENFORCEMENT AND GOVERNMENT REQUESTS
21.1 We review every law-enforcement or government request for user data case by case and require valid legal process (subpoena, court order, or warrant, as applicable to the data sought). We may object to or seek to narrow requests we believe are overbroad, unlawful, or inconsistent with user rights, where reasonably practicable.
21.2 User notice. Where legally permissible, we notify affected users of a request before producing data, so they may seek protective remedies. We do not provide notice where prohibited (e.g., a valid gag order or delayed-notice order) or where notice would create a risk of harm.
21.3 Transparency. We aspire to publish a periodic transparency report summarizing the number and types of government requests received and complied with.
22. DECEASED USERS
22.1 Upon the death of a user, the user's heirs, estate executor, or other legal representative may request access to, a copy of, or deletion of the user's account data by contacting legal@juni.skin, subject to RUFADAA default rules, the user's online-tool directions, and the Section 6.4 exceptions.
22.2 We require verification before acting: proof of the user's death, proof of the requester's identity, and documentation of the requester's relationship and legal authority (e.g., letters testamentary, court appointment). We will not grant account login credentials.
22.3 We honor the deceased-user data rights provided by the user's jurisdiction (including, where applicable, state fiduciary-access laws such as RUFADAA and GDPR-member-state succession rules). Account data is otherwise retained and deleted per Section 5.