Prameya Privacy

OmniDent Privacy Policy

Effective date: 7 October 2026 (supersedes the 27 September 2026 version; describes the Home Screen widget as the photo-journal glance it now is, where the previous version called it a care-status line; says what a Mac shows if you add your iPhone's widgets to it; says that Delete All Scans & Data also removes an old copy of the database the app moved aside, and asks the system to redraw the widget, and names the one rare case it cannot reach; and says that a photo you take on its own is filed under no view)
Publisher: Prameya LLC, a United States limited liability company ("Prameya", "we", "us")
Contact: admin@prameya.legal
This policy lives at: https://prameyallc.github.io/privacy/omnident/
All Prameya app policies: https://prameyallc.github.io/privacy/

Consumer health data

OmniDent processes consumer health data. Washington State law requires a separate policy for that. It is here, and it is a distinct document from this one:
OmniDent Consumer Health Data Privacy Policy
If you live in Washington or Nevada, please read it. It applies to you in addition to this policy.


The short version


1. What OmniDent does

OmniDent is a direct-to-consumer app for your own oral care. The tabs a person reads are You / Record / Do / Ask / More. Capture is a full-screen cover, not a tab. It lets you:

OmniDent has no FDA authorization. Analysis of dental images for clinical purposes is a regulated activity in the United States. We do not make a blanket "the app does not diagnose" claim, because it would not be true of everything on screen. What each AI feature does with its output is set out in section 4 and section 18. The short form: taking a photo runs no AI model, and no model writes anything about it; the photo reading shows what the models wrote, headed "This looks like", and can name a condition; Ask checks its answers against a fixed list of condition names. Do not act on any of it. Ask a dentist.

Some feature descriptions in the app still use dental-condition wording — "caries, erosion, stain & gum risks", "gingival inflammation" — to describe what a feature is about. That is subject-matter wording, not a finding the app has made about your mouth.


2. Subscriptions and In-App Purchases

Available tiers

There is one paid upgrade, OmniDent Pro, sold as three products. Buying any one of
them grants exactly the same Pro — there are no separate feature tiers.

Product Price (US) Billing
OmniDent Pro Monthly $4.99 Auto-renews monthly. 7-day free trial.
OmniDent Pro Annual $29.99 Auto-renews yearly. 7-day free trial.
OmniDent Pro Lifetime $79.99 One-time purchase. Not a subscription.

Family Sharing is enabled on all three. Subscriptions renew until you cancel (how, on each
device, is under Cancellation and refunds below); Lifetime is a one-time non-consumable.

The knowledge layer is free and stays free. Without paying anything you get
your routine, the reference library, a visit-prep outline and the visit sheet, with no account and no time limit. You can take as many photos as you like; the free timeline, compare and visit sheet show your three most recent, and every photo stays on your device and in your export. Pro adds full photo history (on iPhone and iPad, the only devices that keep photos), cadence reminders and the print-ready visit sheet.

Pro does not add cloud sync, and there is no paid iCloud option. OmniDent stores your
records on your device in every case, paid or not. If a subscription lapses you keep your
own data and can still export it in its raw form; only the Pro tools stop.

Free vs paid tier data collection

Both tiers process the same consumer health data (listed in the Consumer Health Data Privacy Policy).

In both tiers:
- Photos stay on your device
- Photos, analysis, your health profile, habit logs, visits and documents never go to iCloud; what does go to your iCloud (section 6) is the same in both tiers
- No transmission of photos or analysis to Prameya
- Same AI models, same on-device processing

Subscription unlocks features. It does not change what data is collected or where it goes.

Cancellation and refunds

Subscriptions are managed by Apple:
- Cancel on iPhone or iPad: Settings → your name → Subscriptions → OmniDent
- Cancel on a Mac: the App Store app → your name → Account Settings → Subscriptions → Manage
- Cancel on Apple Vision Pro: Settings → your name → Subscriptions → OmniDent
- Refund requests: reportaproblem.apple.com

Prameya cannot cancel your subscription or issue refunds. Apple controls all billing.

What the app keeps about a purchase

OmniDent keeps no purchase record of its own. Each time it needs to know whether you have Pro, it asks StoreKit — Apple's purchase system on your device — for your current entitlements and keeps the answer in memory only. Apple processes the payment and keeps its own transaction records, on your device and in your Apple Account, under Apple's terms. The app sends nothing about a purchase to Prameya, and we never see payment details. "Delete All Scans & Data" does not touch Apple's purchase records, and does not need to: they are Apple's, not ours.


3. Photographs of your mouth

Photographs of a person's mouth are sensitive. Here is exactly what happens to them.

Where they are stored

When you take a photo in OmniDent on iPhone or iPad, the image is written as a JPEG file into the app's own private storage on your device — the Documents/Scans folder inside the OmniDent sandbox. A small thumbnail and the date are stored in the app's local database, also on your device, with the caption and view tag if you add them. A photo you take as part of a set of photos is also filed under the view of your mouth that the set asked for; one you take on its own is not (earlier versions filed it as Smile). Taking a photo runs no AI model, so nothing a model wrote is stored with it.

On iPhone and iPad that storage is protected by iOS Data Protection at the Complete level. In practical terms, the files are encrypted with a key tied to your device passcode and are unreadable while the device is locked. This is why OmniDent requires a passcode-protected device to be meaningful — if you have no passcode, iOS has nothing to protect the files with.

The Mac and Apple Vision Pro apps have no camera capture. Photos taken on your iPhone or iPad are not copied to them.

Where they are not stored

One thing this does not mean: OmniDent does not mark the Documents/Scans folder as excluded from your device backup. If you back your iPhone or iPad up to iCloud or to a computer, those files are part of that backup, in your own Apple Account or on your own computer, under Apple's terms rather than ours.

One important exception: your own Photos library

OmniDent has a setting called auto-save captures to Photos. When it is on, every new photo you take in the app is also copied into your device's system Photos library, the same place your ordinary camera photos go. You can also save a single past photo there with its Save button.

This setting is off by default. You have to turn it on.

While a child profile is active, auto-save is forced off, even if you turned the setting on. A child's mouth photos must not silently enter iCloud Photos.

If you turn it on (and you are not in a child session) and you use iCloud Photos, that means new mouth photos will be backed up to your personal iCloud Photo Library, under your Apple Account, subject to Apple's terms — not ours. This is still your data in your account, and Prameya still never sees it. But it does leave OmniDent's protected container, and you should know that.

You can turn it on at Settings → Photos inside OmniDent. You can also revoke OmniDent's permission to add to your Photos library at any time in iOS Settings → Privacy & Security → Photos. OmniDent asks only for permission to add to your library; it cannot read it.

Household mouths stay on this device

Settings → Household (and Family & kids mode) adds people on this device. Each person has one mouth. Photographs, visits and documents are keyed to the active mouth. A child session cannot open another person's photos, Ask, Settings, Paywall, dentist share, the photo reading, or the visit packet.

Leaving a child session for an adult record asks the device to confirm it is you: Face ID or Touch ID, or the device passcode on iPhone and iPad; Touch ID or your Mac password on a Mac (a Mac without Touch ID asks for the password); Optic ID or the device passcode on Apple Vision Pro. The app does not keep a second password. If the device has no passcode or password, the system cannot lock, and Household settings says so.

The household itself — names, roles and photos — does not sync, and no person's name goes to iCloud or through Handoff. While iCloud Sync is on, the name of the person whose record is active does go to one other device: your paired Apple Watch, which shows it. With iCloud Sync off, the Watch does not get it. Section 6 explains.

A passphrase-sealed transfer file moves names and roles to another of your devices. Photos, visits and documents stay on the sending device. This is not iCloud household sync, and there is no Household subscription. StoreKit Family Sharing covers Pro on other Apple IDs; it does not share this record.

Files you pick

Record lets you add a document you pick with the system file picker (or drop onto the photo comparison screen), and Household lets you open a transfer file with the same picker. OmniDent receives only the file you pick or drop. The in-app chat does not take photos: a picture is never attached to an Ask question.

Files you share yourself

Share care summary (under More, adult sessions only) builds a short summary — the active person's display name, their care streak, the number of recent care days, the dates of the photos you select — and, with Pro, a one-page PDF of it, and hands that together with small previews of the photos you selected to the iOS share sheet. On a Mac or Apple Vision Pro, which keep no photos, it shares your care days alone. Export My Data (section 10) and the household transfer file work the same way. OmniDent sends none of these anywhere itself: each goes only where you send it from the share sheet.

Visit dates in Spotlight

When you log a visit, OmniDent adds an entry to your device's Spotlight search index so you can find it from system search. The entry's title is the date alone — for example "Visit on 2026-09-01" — with no practice name, no notes, no document and no person's name. Deleting that visit removes its entry, and Delete All Scans & Data removes all of them. Photos, documents, marks you draw and Handoff activities are not added to Spotlight.

Deleting photos


4. The on-device AI, and what it downloads

Everything runs on your device

OmniDent uses two kinds of on-device model:

When you ask a question or ask the app to read a photo, the image and the text are processed in memory on your device. They are not transmitted to Prameya, to a cloud AI provider, or to anyone else. There is no remote inference path in the app, and no remote fallback. Settings → General → Enable on-device answers switches off Ask, the photo reading, and Ask iPhone on Apple Watch (section 6). Taking a photo runs no model, with the switch on or off.

Ask

Taking a photo

Taking a photo runs no AI model. The photo is saved as you took it, and no model writes anything about it. The only feature that runs a model over a photo is the reading below, and only when you tap its button.

"What this photo looks like"

On a saved photo, an adult session shows a Read this photo on-device button. Tapping it:

  1. runs the vision model you downloaded (SmolVLM) over a reduced copy of that photo, on your device, and
  2. passes the vision model's written notes — text, not the photo — to Apple Intelligence, or, if Apple Intelligence is not answering, to a text model you downloaded, which writes a short reading headed "This looks like", one care job for the week, and questions to take to a dentist.

Both texts are shown as the models wrote them. They are not checked against the word list, and they can name a dental condition. The card says it is not FDA-authorized. The reading is not saved: it disappears when you close the photo, and it is not in the export.

Model files come from Hugging Face

The downloadable models are not shipped inside the app. Downloads come from Hugging Face (huggingface.co), the public repository where these open models are published.

Question Answer
Which models? Three, each pinned to one published version: Qwen2.5 0.5B (mlx-community/Qwen2.5-0.5B-Instruct-4bit, about 280 MB, text), Gemma 4 E2B (mlx-community/gemma-4-e2b-it-4bit, about 850 MB, text) and SmolVLM Instruct (mlx-community/SmolVLM-Instruct-4bit, about 1 GB, reads photos). iPhone and iPad offer all three. The Mac and Apple Vision Pro offer the two text models only: they take no photo and receive none, so SmolVLM is not offered there, not used and not loaded; a copy already downloaded there still appears under your downloaded models so you can delete it.
What is sent to Hugging Face? Requests for the model's files — the repository name and the files being fetched. Like any web request, it shows Hugging Face your IP address and a user-agent that names OmniDent.
Is any of your content sent? No. No photograph, no analysis result, no habit log, no question you typed, no identifier of you.
When does it happen? Only when you tap Download in Settings → AI Models → Manage Models. Taking a photo, reading a photo, asking in Ask or asking from Apple Watch never starts a download — if the model is not already on disk, the feature says so instead.
Over what connection? On iPhone and iPad, Wi-Fi only, unless you turn on Download over cellular in Manage Models; with it off, a download waits for Wi-Fi. On a Mac or Apple Vision Pro, which have no cellular connection, the same switch is Download over Personal Hotspot; with it off, a download waits for a network that is not a Personal Hotspot. It is off by default on every device.
Where do they go? Onto your device, inside the app's storage. You can delete any downloaded model from the same screen. Delete All Scans & Data also deletes them.

Each model row shows its approximate download size. Settings names huggingface.co under AI Models. The app does not show the model's licence before a download begins. This section is that disclosure.

Earlier versions of OmniDent offered Llama 3.2 1B, Gemma 3 4B and PaliGemma 3B. They are no longer offered, and OmniDent deletes any copy of them from your device when it starts.

Hugging Face is not our processor and receives nothing about you from us. Your connection to them is governed by their own privacy policy.


5. Sign in with Apple, and how to delete your account

Signing in is optional. OmniDent works fully without it, and iCloud Sync does not depend on it: sync uses the iCloud account your device is signed in to. Signing in does move one switch: it turns iCloud Sync on, the same switch as Settings → iCloud Sync, so what syncs is exactly what section 6 lists, as when you turn it on yourself. Signing out turns it off (below). You can turn it back on in Settings without signing in.

If you choose Sign in with Apple (at the top of Settings), this is what we get and where it goes:

All three are stored in your device's Keychain, on this device only. Settings shows them back to you. When the app starts, and when you open Settings, iOS asks Apple whether that sign-in is still valid, and OmniDent removes the stored identifier, name and email if Apple says it was revoked or not found. None of it is sent to Prameya. We have no account record for you, no profile database, and no way to look you up.

Deleting your account

Apple requires that an app offering Sign in with Apple also lets you start account deletion from inside the app. Where an app has exchanged Apple's authorization code for tokens on its own server, Apple additionally requires those tokens to be revoked through Apple's Sign in with Apple REST API.

OmniDent has no server and never exchanges the authorization code. No access token and no refresh token for OmniDent is ever minted, so none exists anywhere to revoke, and the app makes no revocation call. The only thing that ever exists is the app-scoped identifier sitting in the Keychain on your own device, and deleting that is the whole of the deletion rather than part of it.

In OmniDent, Settings → (your account, at the top) → Delete Account & All Data does all of the following:

  1. clears the Apple user identifier, name and email from this device's Keychain, ending the association;
  2. turns iCloud Sync off on this device, as signing out does, and removes the iCloud "continue" note;
  3. removes the records this app placed in your private iCloud database, by deleting the app's CloudKit zone — if you are not signed into iCloud, are offline, or the zone was never created, there is nothing there to remove and the step simply completes;
  4. runs Delete All Scans & Data (section 10).

Because OmniDent sets up its iCloud connection when it starts, preference syncing stops completely the next time you open the app, as it does when you turn the switch off yourself. Until then, the reset, first-launch preferences can still be written back to your private iCloud database. Nothing is written to the continue note while the switch is off. You can turn iCloud Sync back on in Settings whenever you want it.

If you also want OmniDent removed from the list of apps you have used Sign in with Apple with, that control belongs to Apple, not to us: iOS Settings → your name → Sign in with Apple → OmniDent. You can use it at any time, before or after deleting in the app.

You can also sign out without deleting. That clears the Keychain entries on that device, leaves your data in place, and turns iCloud Sync off.


6. iCloud sync, Continue and your other devices

iCloud Sync is on by default when your device is signed in to iCloud. You can turn it off at Settings → iCloud Sync. Signing in with Apple turns it on, and signing out turns it off (section 5); you do not need to sign in to turn it on. While it is on, OmniDent puts two things in your own iCloud account. Neither goes to Prameya, and we cannot read either.

Your preferences (CloudKit)

Your app preferences sync between your devices through CloudKit, into your private iCloud database, inside your own Apple Account. We have no CloudKit administrative access to your private database.

Syncs Does not sync
App preferences (which AI models you prefer, whether on-device answers are on, the auto-save-to-Photos setting, the iCloud Sync setting) Photographs and thumbnails
The list of models you have downloaded Your health profile (age, brushing frequency, sugar intake, smoking, diabetes, dry mouth)
Habit logs, cost scenarios and 30-day programme progress
Household people and mouths, visits, plan lines, documents, visit packets, and marks you draw on a photo
Whether you have seen the welcome screen, and whether and when you acknowledged the wellness disclaimer — kept on each device

The set of records permitted to sync is pinned in the app by an allow-list: exactly one record type, the preferences record. If anything ever drifts from it, CloudKit mirroring switches itself off rather than send something it should not.

Turning iCloud Sync off stops preference syncing the next time you open the app.

The "continue" note (iCloud key-value store)

So that your other devices can offer to pick up where you left off, OmniDent keeps a short "continue" note on your device: the tab you were on; the identifier of the education topic you last opened — for example diabetes_and_oral_health or gum_health_and_periodontal_disease, which can reveal what you were reading about; the identifier of the last photo record you opened — a random string, not the photo; the display name of the person whose record is active — for example, a child's first name or nickname — if there is one; and when it was written. Handoff and your paired Apple Watch get parts of it, as set out below.

Only part of it goes to iCloud. OmniDent writes one small entry to iCloud's key-value store for this app, in your iCloud account. It contains:

and, as a second entry, your appearance choice (light, dark or system).

It never contains a person's name or the education topic, and never a photo, a thumbnail, a file path, an analysis, or anything from your health profile, habit log, visits or documents. Each new entry replaces the last one; it is not a history. Earlier versions of OmniDent also put the topic identifier and the active person's name there, and a device still running one can write such an entry again until it is updated. OmniDent replaces an entry like that with the tab and the record identifier when it starts and each time it saves the note, or removes it if iCloud Sync is off.

This entry is written only while iCloud Sync is on. Turning iCloud Sync off removes both entries from iCloud straight away, and that device writes nothing more there while it is off. Delete All Scans & Data also removes them. Continue then starts again from what you do next, if iCloud Sync is still on.

The iCloud Sync switch is set on each device separately. Turning it off on your iPhone does not turn it off on your iPad or Mac: a device where it is still on keeps writing its own entry — the tab and a record identifier — to the same place. Turn it off on every device if you want none written.

Deleting the app from one device does not by itself remove these entries, or your preferences, from iCloud. Use Delete All Scans & Data, or turn iCloud Sync off, before you delete the app.

Handoff

While you use OmniDent on iPhone, iPad, Mac or Apple Vision Pro, it tells Apple's Handoff where you are, so a nearby device signed in to the same Apple Account can offer to open the same place. While iCloud Sync is on, the Handoff message carries the tab, the topic identifier and the photo-record identifier from the continue note described above — never a person's name. With iCloud Sync off it carries only the tab. Its title names the tab, never the topic. While you are taking a set of photos, or have a visit packet open, and iCloud Sync is on, it can instead carry random identifiers of that capture session or packet, of the mouth record and of a visit, and which photo views of an unfinished set are done (for example the upper or lower arch). With iCloud Sync off, those identifiers do not travel either: a set of photos or an open packet hands off the tab alone. It never carries a photo or a file path, and OmniDent does not add it to Spotlight. You can turn Handoff off for all apps in your device's settings (on iPhone: Settings → General → AirPlay & Continuity).

Apple Watch

The Apple Watch app works with the iPhone app over Apple's paired-device connection (WatchConnectivity). Nothing it does reaches Prameya.

Apple TV

The Apple TV app has four tabs: Continue, Library, Ask and About. It uses the same bundle identifier as the iPhone app. It reads the continue entry from your iCloud key-value store, which holds no name and no topic: while iCloud Sync is on, its Continue tab says which tab you were last in on another device and offers the Library. The TV shows no person's name and does not open the topic you last read. Ask on Apple TV answers only with a matching passage from the built-in library (a short list of question words gets a fixed reply instead); it runs no language model and downloads nothing. About shows the app's educational disclaimer, the short version of this policy, and the addresses of this policy, the Consumer Health Data Privacy Policy and the terms, as text built into the app: it fetches nothing and opens no link. The TV app has no camera, photos, household records, Apple Health or purchases.

Mac and Apple Vision Pro

The same app runs on Mac and Apple Vision Pro, with the same iCloud Sync, continue note, Handoff and Ask as on iPhone. Neither has camera capture, and the Mac app has no Apple Health. Because neither keeps a photo, neither offers the photo-reading model (SmolVLM) or the photo reading: they offer the two text models, and their download switch is Download over Personal Hotspot (section 4).

No push notifications

OmniDent has no push-notification entitlement, so neither Apple nor Prameya can push anything to it. iCloud changes are picked up while the app is running. OmniDent sends no marketing or promotional notifications, and Prameya sends you no notifications at all. The only notifications are the local care reminders you turn on yourself (section 7).


7. Apple Health and care reminders

Apple Health

OmniDent's Apple Health switch is off until you turn it on at Settings → Apple Health → Sync with Apple Health. Turning it on asks iOS for permission.

If you enable it:

With the switch off, nothing OmniDent does writes to Apple Health or asks iOS for Apple Health permission — not a care session, not the 30-day programme, not Apple Watch, a reminder or the Log care action.

Apple Health data lives in Apple's Health store on your device, under your control. Prameya never receives it. You can revoke that permission at any time in iOS Settings → Health → Data Access & Devices.

OmniDent does not request access to Health Records (clinical records from a provider) and cannot read them. There is no Apple Health on the Mac app.

Care reminders

Care reminders are off until you turn them on at Settings → Care reminders. Switching on a morning or evening reminder is the only thing in OmniDent that asks iOS for permission to send notifications. OmniDent then schedules local notifications on your device for about the next week — generic brushing nudges that name no person and no condition. Each has Confirm, Snooze and Not now buttons: Confirm records a brush (and, if the Apple Health switch is on, writes a toothbrushing entry), Snooze schedules one more reminder, and Not now does nothing. Nothing about a reminder is sent to Prameya or to any server. Turn them off on the same screen, or in iOS Settings → Notifications → OmniDent.

Widget and Lock Screen

The Home Screen widget, Photo journal, shows one line that the app writes to a storage area shared only with its own widget: the date of the most recent photo in the active person's record (for example "Last photo Oct 6"), "Same spot" when two of that person's photos are of the same view (the view tag you gave them, or the view the set of photos asked for when you took them), and "You're set for today" once today's care is logged. With no photo yet it says "No photos yet" or "Keep one photo". It shows no photograph and no name. OmniDent on a Mac or Apple Vision Pro keeps no photos, so the widget it puts there never shows a photo date. If you add your iPhone's widgets to your Mac, a feature of macOS, the Mac shows your iPhone's line, photo date included: your iPhone passes it to your Mac, and OmniDent sends nothing for it. Anyone who can see a screen you put the widget on can see that line. Tapping it opens OmniDent at your photo journal, or, on iPhone and iPad, at the camera if there is no photo yet.

During a care session, a Live Activity on the iPhone Lock Screen and Dynamic Island shows the timer, the step, and the name of the person whose session it is. Anyone who can see your Lock Screen can see it. It is started and updated on the device; it uses no push.


8. Everything the app sends over the network — the complete list

Destination What goes there When Contains your content?
huggingface.co Requests for AI model files Only when you tap Download in Manage Models No
Apple iCloud (CloudKit), your private database App preferences; a request to delete the app's zone when you delete your account While iCloud Sync is on, and at account deletion No health data
Apple iCloud key-value store, your account Part of the continue note: the tab and the last photo-record identifier, never a name or a topic; and your appearance choice While iCloud Sync is on No: no name, no topic, and a random identifier rather than the photo; see section 6
Apple Handoff, to your nearby devices While iCloud Sync is on: the tab, the last topic identifier and the last photo-record identifier, never a name, or, during a capture or with a visit packet open, random identifiers of it, the mouth record and a visit, and which photo views are done. While it is off: only the tab While you use the app The topic identifier can reveal what you read about, while iCloud Sync is on; see section 6
Your paired Apple Watch (WatchConnectivity) The continue note (only the tab while iCloud Sync is off) and care prompts to the Watch; your taps and Ask questions to the iPhone, and the answers back When the iPhone app connects to the Watch, and when you use the Watch app Your Ask question, and the active person's name while iCloud Sync is on
Apple (Sign in with Apple) The sign-in exchange, and iOS's check of whether it is still valid Only if you choose to sign in No
Apple StoreKit / App Store Purchase, restore and entitlement checks; the review prompt if you tap Rate OmniDent When you buy or restore, and when the app checks whether you have Pro No health content

There is no token-revocation request in that list, because there is no OmniDent token to revoke — see section 5.

Files you share yourself from the iOS share sheet — the export, the care summary, the household transfer file — go wherever you send them; the app itself sends them nowhere (section 3).

Links to sources in the reference library, and links to this policy, open in your browser; the site you open sees an ordinary visit. Send Feedback opens your own email app.

All connections the app makes use HTTPS. The app disallows unencrypted connections at the platform level.

That is the whole list. There is no analytics endpoint, no crash-reporting endpoint, no advertising network, no attribution SDK, no remote AI service, and no Prameya server of any kind. The app's privacy manifests declare no collected data, no tracking and no tracking domains, and no crash-reporting SDK is built into the app. The app does subscribe to Apple's MetricKit, which hands it daily performance and crash summaries on the device; the app writes them to the device's own log and sends them nowhere.

What Prameya does receive

Almost nothing, and none of it from the app:


9. Things we do not do

One line each, because the honest answer is short.


10. Retention, export and deletion

Retention. Because your content lives on your device, you decide how long it is kept. We impose no retention period because we hold nothing to retain. If you delete the app, iOS deletes its container and everything in it. What is in your iCloud (section 6) is not removed by deleting the app. Delete All Scans & Data resets your preferences to first-launch values; if iCloud Sync is on, the reset preferences are written back to iCloud. Delete Account & All Data deletes the app's records from your private iCloud database and turns iCloud Sync off on that device; preference syncing then stops completely the next time you open the app (section 5). The continue note is removed when you turn iCloud Sync off or use Delete All Scans & Data, and starts again if iCloud Sync is on on any of your devices.

Export. Settings → Privacy & Security → Export My Data produces a .zip file, generated entirely on your device, and hands it to the standard iOS share sheet so you can put it wherever you want. Inside it:

If a photograph's file is missing from your device — it was removed outside the app, for example — the scan entry is still exported, marked photoFileMissingOnDisk, with the thumbnail. It is not quietly dropped, and the file does not claim a picture it does not carry. If a photograph is on your device and cannot be read, no file is produced at all and the app tells you which one: a short export that looks complete is worse than no export.

The file does not contain: the photo reading, household names, visits, plan lines, documents, visit packets, marks you drew, or the settings-store items (care-day history, Smile Points, widget snapshot, reminder schedule, cost-model sliders). Email admin@prameya.legal if you need help getting at any of those; they are on your device, not with us.

Deletion.

To delete Where
One photo You → All your photos → tap the photo → Delete this photo (or press-and-hold the row). A child session cannot delete photos; the owner deletes them from an adult session.
A visit you logged Record → the visit → Delete this visit
A document you filed Record → the document → Delete this file
One logged care day Do → Your care log → tap the day → Delete this care day (or press-and-hold the row)
One saved what-if scenario More → What-if → Saved Scenarios → tap it → Delete this scenario
One claimed partner promotion Settings → Privacy & Security → Claimed offers → Delete this claim (the row is shown only if you have one)
Your 30-day programme progress 30-Day Reset → Delete my 30-day progress
Your oral-health profile Settings → Edit My Health Profile → Delete my health profile
The iCloud continue note (tab, photo-record identifier) Settings → iCloud Sync → turn it off (removes it at once), or Delete All Scans & Data
Everything in the next paragraph Settings → Privacy & Security → Delete All Scans & Data
Your Sign in with Apple association, your iCloud preference records for this app, and everything Delete All removes (it also turns iCloud Sync off on that device) Settings → (your account, at the top) → Delete Account & All Data
OmniDent from your Apple Account's Sign in with Apple list iOS Settings → your name → Sign in with Apple → OmniDent
Data written to Apple Health The Apple Health app
Photos copied to your Photos library The Photos app

Delete All Scans & Data removes: your photos and their files, thumbnails and analyses; habit logs; what-if scenarios; claimed promotions; 30-day programme progress; your oral-health profile; household people and mouths; visits, plan lines, documents and their files, visit packets, and marks you drew; the settings store behind them (care-day history, profile names, Smile Points, widget snapshot, reminder schedule, cost-model sliders, the Apple Health switch); any old copy of the app's database that it moved aside because it could not open it at launch (the app tells you on screen when this happens); whether you have seen the welcome screen and acknowledged the wellness disclaimer on this device; the widget's shared storage, after which it asks the system to redraw the Home Screen widget, which then has no photo date to show; every downloaded model and its bookkeeping; the record of brushes confirmed from Apple Watch, a reminder or the Log care action; the visit entries in Spotlight; care reminders already scheduled; the iCloud continue note, and the name your paired Apple Watch was showing; and it resets your synced preferences to their first-launch values.

It leaves, and we list them so you are not surprised:

If you want help with any of this, or you want us to confirm in writing that we hold nothing about you, write to admin@prameya.legal.


11. Security

The strongest security property here is structural rather than technical: there is no Prameya server holding your data, so there is no Prameya breach that can expose it. The corresponding limitation is equally real — the security of your data depends on the security of your device and your Apple Account. Use a passcode. Use two-factor authentication on your Apple Account.


12. Children

OmniDent's account holder is an adult. There is no child Apple ID, no child sign-up, and the App Store listing is not in the Kids category.

Kids mode is a parent tool on the parent's device. Settings → Family & kids mode and Household add a person with the child role. The app does not create a kids profile unless you add one. A child person gets the shorter care session. Photographs, visits and documents for that person stay on this device, keyed to that mouth.

When a child profile is active:

A child's name can leave the device, in one way. While iCloud Sync is on and the child's record is active, the child's display name goes to your paired Apple Watch, which shows it. It does not go to iCloud or through Handoff, and Apple TV does not show it. Whatever the switch, it shows on the Lock Screen during that child's care session (section 6 and section 7). Use a nickname, or turn iCloud Sync off, if you would rather it did not.

The Children's Online Privacy Protection Act (COPPA) applies to operators of services directed to children under 13, or who have actual knowledge that they are collecting personal information from a child under 13. OmniDent's kids mode is a tool for a parent, on the parent's own device, with no transmission to us and no child-facing sign-up; on that basis we do not treat OmniDent as directed to children. We are stating the feature rather than relying on the conclusion, so that you can judge it.

If you believe a child's information has been entered into this app and you want it removed, write to admin@prameya.legal — although in almost every case the information is on your own device. Delete All Scans & Data also clears household people, their names and care-day history, including a child's; the continue note in iCloud; and the name your paired Apple Watch was showing. Deleting the app removes the container.

A parent supervising a child's brushing should know that photographing a child's mouth stores those photos on this device. Auto-save to Photos is forced off while that child is active. The consumer health data policy lists children's health data as its own categories.


13. California residents

If you live in California, the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA) gives you specific rights.

Categories of personal information. Over the past 12 months, OmniDent has handled, on your device and in your own iCloud account, the following categories as defined by the CCPA:

Category What it is here Do we receive it?
Identifiers Apple sign-in identifier, name, email — Keychain only; the active household person's display name — on your paired Apple Watch while iCloud Sync is on, never in iCloud or Handoff (section 6) No
Sensitive personal information — health data Mouth photographs, oral-health profile, habit logs, analysis output, questions you ask; the last education topic you opened, carried by Handoff to your own nearby devices and sent to your paired Apple Watch while iCloud Sync is on, never to iCloud No
Internet or network activity The connection to Hugging Face when a model downloads No

We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have not done either in the preceding 12 months. We do not use or disclose sensitive personal information for any purpose other than the purposes permitted under the CCPA regulations without your direction — in practice, we do not receive it at all, so the "limit the use of my sensitive personal information" right has nothing to operate on. We provide the control anyway: turning off on-device answers, iCloud Sync and Apple Health stops most of that processing — section 6 lists what those switches do not stop (Handoff, which still carries the tab).

Your rights are to know, to access, to correct, to delete, to opt out of sale or sharing, to limit the use of sensitive personal information, and not to be discriminated against for exercising any of them.

How to exercise them. Because we hold no personal information about you on any server, the fastest route for access, correction and deletion is the in-app controls in section 10 — they are immediate and require no verification step. If you would rather make a formal request, or you want written confirmation of what we hold, email admin@prameya.legal with "California privacy request" in the subject. We will respond within 45 days, and may extend once by a further 45 days if we tell you why. We will verify a request by corresponding with you at the address you write from; we will not ask you for additional identity documents, because we have nothing to match them against. An authorised agent may act for you with your written permission.

We do not use personal information for automated decision-making that produces legal or similarly significant effects.


14. Washington and Nevada residents — consumer health data

Washington's My Health My Data Act (RCW ch. 19.373) and Nevada's SB 370 give you rights over consumer health data, and Washington requires a separate, distinctly linked policy for it.

That policy is here: OmniDent Consumer Health Data Privacy Policy. Both policies are also linked inside the app, as two distinct links, in Settings.

Two points worth stating in this document as well:


15. Other US states

Several other states — including Colorado, Connecticut, Virginia, Utah, Texas, Oregon and Montana — give residents rights to access, correct, delete and port personal data, and to opt out of targeted advertising, sale, and profiling. Some require opt-in consent for sensitive data including health data.

We honour all of these. The mechanics are the same as everywhere else in this policy: the in-app controls are the fastest route, and admin@prameya.legal is the formal route. We do not conduct targeted advertising, sale of data, or profiling, so those opt-outs have nothing to switch off.


16. Outside the United States

If you use OmniDent in the European Economic Area, the United Kingdom or Switzerland, the GDPR or UK GDPR may apply. Prameya LLC is the controller for the limited processing described in this policy.


17. HIPAA does not apply

We say this clearly because it is genuinely useful to know, and because plenty of health apps are vague about it.

The Health Insurance Portability and Accountability Act (HIPAA) does not apply to OmniDent. HIPAA regulates covered entities — health plans, health care clearinghouses, and health care providers who bill electronically — and their business associates. Prameya is none of those. You are our user, not our patient. We have no treatment relationship with you and no contract with your dentist.

Two consequences follow, and the second is the important one:

  1. Data you put into OmniDent is not protected health information under HIPAA.
  2. Do not read this as OmniDent having weaker protection. Your photos and records do not leave your device, so the practical protection is strong. But it is not HIPAA protection, and we will not imply that it is. Anyone who tells you their consumer app is "HIPAA compliant" when they have no covered-entity relationship is telling you something meaningless.

If OmniDent is ever offered through a dental practice or a dental service organisation, this analysis changes and this policy will change with it, before that happens.


18. No FDA authorization, and not medical advice

OmniDent has no FDA authorization, clearance or approval of any kind. It is not a substitute for examination by a licensed dentist, and it cannot see what a dentist sees. Analysis of dental images is a regulated activity in the United States. OmniDent is not an authorized device and does not claim to be.

We are not replacing that with a blanket "the app does not diagnose" claim. What can be checked:

If something in your mouth hurts, bleeds, changes, or worries you, see a dentist. Do not wait for an app.


19. Changes to this policy

We will update this policy when the app's behaviour changes — and we will update it before the change ships, not after.

7 October 2026 — what changed. OmniDent was changed, and this policy describes the app with those changes:

Sections 1, 3, 7 and 10 are updated. The short version is unchanged. No category of data, source, purpose or recipient is added, and nothing is sent to Prameya.

27 September 2026, third revision — what changed. The short version and section 5 said Sign in with Apple "does not change what syncs". What syncs is the same whether or not you sign in, but signing in turns the iCloud Sync switch on and signing out turns it off. That was already true of the app, and this policy now says so in the short version and sections 5 and 6. iCloud Sync can still be turned on or off in Settings without signing in. No category of data, source, purpose or recipient is added, and nothing is sent to Prameya.

Later on 27 September 2026 — what changed. OmniDent was changed for the Mac and Apple Vision Pro, and this policy describes the app with those changes. iPhone and iPad are unchanged.

Sections 2, 3, 4, 6 and 10 are updated. The short version is unchanged. No category of data, source, purpose or recipient is added, and nothing is sent to Prameya.

27 September 2026 — what changed. The previous version said that leaving a child session asks for Face ID or the device passcode, on every device. That is what an iPhone or iPad with Face ID asks for. An iPhone or iPad with Touch ID asks for Touch ID, a Mac asks for Touch ID or your Mac password (the password alone on a Mac without Touch ID), and Apple Vision Pro asks for Optic ID; each can fall back to the device passcode or Mac password. The lock itself did not change; OmniDent's own Household screen now names the unlock for the device it runs on, and this policy names each. The short version and sections 3 and 12 are corrected. Nothing is sent to Prameya.

26 September 2026 — what changed. OmniDent was changed, and this policy describes the app with those changes:

The short version and sections 3, 6, 8, 10, 12 and 13 are updated. No Prameya server was added, and nothing is sent to Prameya.

24 September 2026 — what changed.

Also on 24 September 2026, OmniDent was changed, and this policy describes the app with those changes:

No Prameya server was added, and nothing is sent to Prameya.

23 September 2026 — what changed. We re-read the app as it is built today and corrected this policy where it was wrong or silent:

Also on 23 September 2026, OmniDent was changed to fix defects that the version above disclosed, and this policy now describes the app with those fixes:

No Prameya server was added, and nothing is sent to Prameya.


20. Contact

Prameya LLC
Privacy questions, data requests, complaints: admin@prameya.legal

Please put "Privacy" in the subject line. We answer every request, including the ones where the answer is "we do not have any of your data, and here is how to confirm that yourself."

All Prameya app privacy policies: https://prameyallc.github.io/privacy/
OmniDent consumer health data policy: https://prameyallc.github.io/privacy/omnident/health-data/

Consumer Health Data Privacy Policy

OmniDent processes consumer health data. Washington State law requires a separate policy for that data, published at its own address:

OmniDent Consumer Health Data Privacy Policy

Terms of Use

The terms governing OmniDent, including subscription auto-renewal and cancellation, and dispute resolution:

OmniDent Terms of Use