Prameya Privacy

OmniDent Privacy Policy

Effective date: 8 August 2026
Publisher: Prameya LLC, a United States limited liability company ("Prameya", "we", "us")
Contact: admin@prameya.legal
This policy lives at: https://prameyallc.github.io/privacy/omnident/
All Prameya app policies: https://prameyallc.github.io/privacy/

Consumer health data

OmniDent processes consumer health data. Washington State law requires a separate policy for that. It is here, and it is a distinct document from this one:
OmniDent Consumer Health Data Privacy Policy
If you live in Washington or Nevada, please read it. It applies to you in addition to this policy.


The short version


1. What OmniDent does

OmniDent is a direct-to-consumer app for your own oral care. It lets you:

In the configuration OmniDent ships in, the app does not give you a diagnosis and does not name a dental disease as a finding about your photograph. Analysis of dental images for clinical purposes is a regulated activity in the United States. Any feature that would produce a clinical or diagnostic finding is disabled by default and stays disabled unless and until the relevant regulatory clearance is in place.

Two things in the shipping app are worth stating plainly, because they involve numbers and disease words even though they are not findings about you:


2. Photographs of your mouth

Photographs of a person's mouth are sensitive. Here is exactly what happens to them.

Where they are stored

When you take a photo in OmniDent, the image is written as a JPEG file into the app's own private storage on your device — the Documents/Scans folder inside the OmniDent sandbox. A small thumbnail and some metadata (the date, a capture-quality number, the analysis output) are stored in the app's local database, also on your device.

That storage is protected by iOS Data Protection at the Complete level. In practical terms, the files are encrypted with a key tied to your device passcode and are unreadable while the device is locked. This is why OmniDent requires a passcode-protected device to be meaningful — if you have no passcode, iOS has nothing to protect the files with.

Where they are not stored

One thing this does not mean: OmniDent does not mark the Documents/Scans folder as excluded from your device backup. If you back your iPhone or iPad up to iCloud or to a computer, those files are part of that backup, in your own Apple Account or on your own computer, under Apple's terms rather than ours.

One important exception: your own Photos library

OmniDent has a setting called auto-save captures to Photos. When it is on, every new photo you take in the app is also copied into your device's system Photos library, the same place your ordinary camera photos go.

This setting is ON by default.

If you use iCloud Photos, that means new mouth photos will be backed up to your personal iCloud Photo Library, under your Apple Account, subject to Apple's terms — not ours. This is still your data in your account, and Prameya still never sees it. But it does leave OmniDent's protected container, and you should know that.

You can turn it off at Settings → Photos inside OmniDent. You can also revoke OmniDent's permission to add to your Photos library at any time in iOS Settings → Privacy & Security → Photos.

Photos you pick from your library

Some screens let you attach a photo from your library to an on-device chat. That uses Apple's system photo picker. OmniDent receives only the single image you pick. It has no access to the rest of your library.

Deleting photos


3. The on-device AI, and the one thing it downloads

Analysis happens on your device

OmniDent uses Apple's MLX framework to run vision and language models locally, on your device's own chip. When you analyse a photo or ask a question in the chat, the image and the text are processed in memory on your device. They are not transmitted to Prameya, to a cloud AI provider, or to anyone else. There is no remote inference path in the app, and no remote fallback.

Model files come from Hugging Face

The models themselves are large files that are not shipped inside the app. To use an AI feature you first download a model, and that download comes from Hugging Face (huggingface.co), the public repository where these open models are published.

What that means precisely:

Question Answer
What is sent to Hugging Face? A request for a model file — the repository name and the file being fetched. Standard web request information such as your IP address is visible to Hugging Face, as it is to any website you connect to.
Is any of your content sent? No. No photograph, no analysis result, no habit log, no chat message, no identifier of you.
When does it happen? Only when you tap Download in Settings → AI Models → Manage Models. Taking a photo or running an analysis will never silently start a download — if a model is not already on disk, the app declines to run rather than fetch it.
Which models? Open 4-bit and 8-bit builds published by the mlx-community organisation, including SmolVLM-Instruct-4bit, gemma-3-4b-it-qat-4bit, paligemma-3b-mix-448-8bit, Qwen2.5-0.5B-Instruct-4bit, Llama-3.2-1B-Instruct-4bit and gemma-4-e2b-it-4bit.
Where do they go? Onto your device. You can delete any downloaded model from the same screen.

The app does not currently show a disclosure sheet naming the download host, the file size and the model licence before a download begins. This section is that disclosure.

Hugging Face is not our processor and receives nothing about you from us. Your connection to them is governed by their own privacy policy.


4. Sign in with Apple, and how to delete your account

Signing in is optional. OmniDent works fully without it.

If you choose Sign in with Apple, this is what we get and where it goes:

All three are stored in your device's Keychain. They are used for one thing: to associate your device with your own private iCloud data so it can roam between your devices. They are not sent to Prameya. We have no account record for you, no profile database, and no way to look you up.

Deleting your account

Apple requires that an app offering Sign in with Apple also lets you start account deletion from inside the app. Where an app has exchanged Apple's authorization code for tokens on its own server, Apple additionally requires those tokens to be revoked through Apple's Sign in with Apple REST API.

OmniDent has no server and never exchanges the authorization code. No access token and no refresh token for OmniDent is ever minted, so none exists anywhere to revoke, and the app makes no revocation call. The only thing that ever exists is the app-scoped identifier sitting in the Keychain on your own device, and deleting that is the whole of the deletion rather than part of it.

In OmniDent, Settings → iCloud Sync → Delete Account & All Data does all of the following:

  1. clears the Apple user identifier, name and email from this device's Keychain, ending the association;
  2. removes the records this app placed in your private iCloud database, by deleting the app's CloudKit zone — if you are not signed into iCloud, are offline, or the zone was never created, there is nothing there to remove and the step simply completes;
  3. turns iCloud sync off;
  4. deletes your local data, including the photo files in Documents/Scans, your scans and analyses, habit logs, trajectory scenarios, programme progress and your oral-health profile.

If you also want OmniDent removed from the list of apps you have used Sign in with Apple with, that control belongs to Apple, not to us: iOS Settings → your name → Sign in with Apple → OmniDent. You can use it at any time, before or after deleting in the app.

You can also sign out without deleting, which clears the Keychain entries on that device but leaves your data in place.


5. iCloud sync

OmniDent can sync a small amount of data between your own devices using CloudKit, Apple's iCloud service. Two things are true of this and both matter:

  1. The data goes into your private iCloud database, inside your own Apple Account. It does not go to Prameya. We cannot read it. We have no CloudKit administrative access to your private database.
  2. Only non-health data syncs. Your photographs, your analysis results, your oral-health profile and your habit history do not sync. They stay on the device that created them.

What syncs:

Syncs Does not sync
App preferences (which AI model you prefer, whether AI features are enabled, auto-save-to-Photos setting) Photographs
Interface state (whether you have seen the welcome screen, whether you acknowledged the wellness disclaimer) Analysis results and any finding derived from a photograph
The list of models you have downloaded Your health profile (age, brushing frequency, sugar intake, smoking, diabetes, dry mouth)
Habit logs (brushing, flossing, mouthwash, sugary drinks)
Cost trajectory scenarios and 30-day programme progress

That list is not a description of good intentions: the set of records permitted to sync is pinned in the app by an allow-list, and if anything ever drifts from it, sync switches itself off entirely rather than send something it should not.

You can turn sync off entirely at Settings → iCloud Sync.

Because sync uses CloudKit, iOS uses Apple's push service to tell the app that something changed. That is a silent, content-free signal. OmniDent sends no marketing or promotional push notifications, and Prameya sends you no push notifications at all.


6. Apple Health

Apple Health integration is off until you turn it on and grant permission through iOS.

If you enable it:

Apple Health data lives in Apple's Health store on your device, under your control. Prameya never receives it. You can revoke either direction at any time in iOS Settings → Health → Data Access & Devices, or turn the whole integration off in OmniDent's settings.

OmniDent does not request access to Health Records (clinical records from a provider) and cannot read them.


7. Everything the app sends over the network — the complete list

Destination What goes there When Contains your content?
huggingface.co A request for an AI model file Only when you tap Download in Manage Models No
Apple iCloud (CloudKit), your private database App preferences and interface state; a request to delete the app's zone when you delete your account While iCloud Sync is on, and at account deletion No health data
Apple push notification service A silent signal that iCloud data changed While iCloud Sync is on No
Apple (Sign in with Apple) The sign-in exchange itself, handled by iOS Only if you choose to sign in No

There is no token-revocation request in that list, because there is no OmniDent token to revoke — see section 4.

All connections use HTTPS. The app disallows unencrypted connections at the platform level.

That is the whole list. There is no analytics endpoint, no crash-reporting endpoint, no advertising network, no attribution SDK, no remote AI service, and no Prameya server of any kind. The app's privacy manifest declares no crash data, no tracking and no tracking domains, and no crash-reporting SDK is built into the app.

What Prameya does receive

Almost nothing, and none of it from the app:


8. Things we do not do

One line each, because the honest answer is short.


9. Retention, export and deletion

Retention. Because your content lives on your device, you decide how long it is kept. We impose no retention period because we hold nothing to retain. If you delete the app, iOS deletes its container and everything in it. Data synced to your private iCloud database is removed when you delete your account in the app, or when you delete the app's iCloud data from iOS Settings → your name → iCloud.

Export. Settings → Privacy & Security → Export My Data produces a JSON file, generated entirely on your device, containing your scan metadata, habit logs, trajectory scenarios and profile. It contains metadata only — not the raw photographs, which you already have in the app and, if you enabled auto-save, in your Photos library, and not the text of your notes.

Deletion.

To delete Where
One photo Scan details → Delete
All app data on this device Settings → Privacy & Security → Delete All Scans & Data
Your Sign in with Apple association, your iCloud records for this app, and all local data Settings → iCloud Sync → Delete Account & All Data
OmniDent from your Apple Account's Sign in with Apple list iOS Settings → your name → Sign in with Apple → OmniDent
Data written to Apple Health The Apple Health app
Photos copied to your Photos library The Photos app

If you want help with any of this, or you want us to confirm in writing that we hold nothing about you, write to admin@prameya.legal.


10. Security

The strongest security property here is structural rather than technical: there is no Prameya server holding your data, so there is no Prameya breach that can expose it. The corresponding limitation is equally real — the security of your data depends on the security of your device and your Apple Account. Use a passcode. Use two-factor authentication on your Apple Account.


11. Children

OmniDent is intended for adults. It is not directed to children, we do not knowingly collect personal information from a child under 13, and there is no sign-up flow, no advertising, no analytics and no social feature through which a child's information could be collected or shared.

The Children's Online Privacy Protection Act (COPPA) applies to operators of services directed to children under 13, or who have actual knowledge that they are collecting personal information from a child under 13. We believe neither applies to OmniDent. That said, oral hygiene is a subject parents share with children. If you believe a child under 13 has provided information through this app, write to admin@prameya.legal and we will help you remove it — although in almost every case the answer is that the information is on your own device and you can delete it yourself in seconds using the controls in section 9.

A parent supervising a child's brushing should be aware that the app can photograph a child's mouth and store it on the device, and that with auto-save on, those photos also go to the device's Photos library.


12. California residents

If you live in California, the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA) gives you specific rights.

Categories of personal information. Over the past 12 months, OmniDent has handled, on your device, the following categories as defined by the CCPA:

Category What it is here Do we receive it?
Identifiers Apple sign-in identifier, name, email — Keychain only No
Sensitive personal information — health data Mouth photographs, oral-health profile, habit logs, analysis output No
Internet or network activity The connection to Hugging Face when you download a model No

We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have not done either in the preceding 12 months. We do not use or disclose sensitive personal information for any purpose other than the purposes permitted under the CCPA regulations without your direction — in practice, we do not receive it at all, so the "limit the use of my sensitive personal information" right has nothing to operate on. We provide the control anyway: turning off AI features, iCloud sync and Apple Health stops the app processing that data.

Your rights are to know, to access, to correct, to delete, to opt out of sale or sharing, to limit the use of sensitive personal information, and not to be discriminated against for exercising any of them.

How to exercise them. Because we hold no personal information about you on any server, the fastest route for access, correction and deletion is the in-app controls in section 9 — they are immediate and require no verification step. If you would rather make a formal request, or you want written confirmation of what we hold, email admin@prameya.legal with "California privacy request" in the subject. We will respond within 45 days, and may extend once by a further 45 days if we tell you why. We will verify a request by corresponding with you at the address you write from; we will not ask you for additional identity documents, because we have nothing to match them against. An authorised agent may act for you with your written permission.

We do not use personal information for automated decision-making that produces legal or similarly significant effects.


13. Washington and Nevada residents — consumer health data

Washington's My Health My Data Act (RCW ch. 19.373) and Nevada's SB 370 give you rights over consumer health data, and Washington requires a separate, distinctly linked policy for it.

That policy is here: OmniDent Consumer Health Data Privacy Policy. Both policies are also linked inside the app, as two distinct links, in Settings.

Two points worth stating in this document as well:


14. Other US states

Several other states — including Colorado, Connecticut, Virginia, Utah, Texas, Oregon and Montana — give residents rights to access, correct, delete and port personal data, and to opt out of targeted advertising, sale, and profiling. Some require opt-in consent for sensitive data including health data.

We honour all of these. The mechanics are the same as everywhere else in this policy: the in-app controls are the fastest route, and admin@prameya.legal is the formal route. We do not conduct targeted advertising, sale of data, or profiling, so those opt-outs have nothing to switch off.


15. Outside the United States

If you use OmniDent in the European Economic Area, the United Kingdom or Switzerland, the GDPR or UK GDPR may apply. Prameya LLC is the controller for the limited processing described in this policy.


16. HIPAA does not apply

We say this clearly because it is genuinely useful to know, and because plenty of health apps are vague about it.

The Health Insurance Portability and Accountability Act (HIPAA) does not apply to OmniDent. HIPAA regulates covered entities — health plans, health care clearinghouses, and health care providers who bill electronically — and their business associates. Prameya is none of those. You are our user, not our patient. We have no treatment relationship with you and no contract with your dentist.

Two consequences follow, and the second is the important one:

  1. Data you put into OmniDent is not protected health information under HIPAA.
  2. Do not read this as OmniDent having weaker protection. The data does not leave your device, so the practical protection is stronger than most HIPAA-covered arrangements. But it is not HIPAA protection, and we will not imply that it is. Anyone who tells you their consumer app is "HIPAA compliant" when they have no covered-entity relationship is telling you something meaningless.

If OmniDent is ever offered through a dental practice or a dental service organisation, this analysis changes and this policy will change with it, before that happens.


17. Not a medical device, not medical advice

OmniDent gives general educational information about oral health. It does not diagnose, treat, cure, mitigate or prevent any disease or condition. It is not a substitute for examination by a licensed dentist, and it cannot see what a dentist sees.

Analysis of dental images is a regulated activity in the United States, and FDA has authorised specific devices for it. OmniDent is not one of them and does not claim to be. Features that would produce a clinical or diagnostic finding are switched off by default and remain off pending appropriate regulatory clearance. The percentage ranges shown by the Studio screen's Regenerative Projection feature are placeholder values built into the app and are not a clinical estimate of anything (section 1).

If something in your mouth hurts, bleeds, changes, or worries you, see a dentist. Do not wait for an app.


18. Changes to this policy

We will update this policy when the app's behaviour changes — and we will update it before the change ships, not after.


19. Contact

Prameya LLC
Privacy questions, data requests, complaints: admin@prameya.legal

Please put "Privacy" in the subject line. We answer every request, including the ones where the answer is "we do not have any of your data, and here is how to confirm that yourself."

All Prameya app privacy policies: https://prameyallc.github.io/privacy/
OmniDent consumer health data policy: https://prameyallc.github.io/privacy/omnident/health-data/

Consumer Health Data Privacy Policy

OmniDent processes consumer health data. Washington State law requires a separate policy for that data, published at its own address:

OmniDent Consumer Health Data Privacy Policy