← Legal Hub
JOY
Security Policy
Effective: June 27, 2026  ·  Last Updated: June 27, 2026  ·  Joy Health Technologies LLC
JOY handles photos, voice recordings, and daily wellness data belonging to older adults and their families. We take the security of this data seriously. This policy describes our security practices and how to report a vulnerability.

1. Data Encryption


2. Access Control


3. Infrastructure Security

JOY runs on Google Firebase and Google Cloud Platform, which maintain:

Google's infrastructure security documentation is available at cloud.google.com/security.


4. Authentication Security


5. Vulnerability Disclosure

We operate a responsible disclosure policy. If you discover a security vulnerability in JOY, please report it privately — do not publicly disclose it until we have had a reasonable opportunity to investigate and address it.

To report a vulnerability:

We will acknowledge receipt within 48 hours and provide a status update within 7 days. We do not currently offer a bug bounty program, but we are grateful to researchers who help keep JOY secure and will publicly acknowledge responsible disclosures (with permission) after patching.


6. Incident Response

In the event of a security incident affecting user data, we will:


7. What You Can Do

Security reports: joy@joyhealthtechnologies.com

Subject: Security Vulnerability Report · Response within 48 hours