OmniDent Consumer Health Data Privacy Policy
Effective date: 7 October 2026 (supersedes the 27 September 2026 version; says what the line in the widget's shared storage now carries, the date of the active person's last photo and whether two of their photos are of the same view, and that a Mac you add your iPhone's widgets to shows that line; and says that Delete All Scans & Data also removes an old copy of the database the app moved aside, and asks the system to redraw the widget, and names the one rare case it cannot reach.)
Publisher: Prameya LLC, a United States limited liability company ("Prameya", "we", "us")
Contact: admin@prameya.legal
This policy lives at: https://prameyallc.github.io/privacy/omnident/health-data/
Main OmniDent privacy policy: https://prameyallc.github.io/privacy/omnident/
All Prameya app policies: https://prameyallc.github.io/privacy/
Why this is a separate document
Washington State's My Health My Data Act (RCW ch. 19.373) requires any business that collects consumer health data to maintain a consumer health data privacy policy that is separate and distinct from its general privacy policy, and to link to it prominently. Nevada's SB 370 (codified in NRS ch. 603A) imposes closely analogous duties.
This is that document. It applies to everyone who uses OmniDent, and it gives specific rights to residents of Washington and Nevada.
It is separate from, and additional to, the main OmniDent Privacy Policy. Read both. Both are also linked separately inside the app, in Settings.
A note about the word "collect"
Apple's App Store privacy labels use "collect" to mean transmitting data off the device. Under that definition, OmniDent would collect very little.
Washington's definition is much broader. RCW 19.373.010 defines "collect" as to buy, rent, access, retain, receive, acquire, infer, derive, or otherwise process consumer health data in any manner. Data that never leaves your phone is still collected, because the app accesses, retains, processes and derives from it.
We use Washington's definition throughout this document. We do not use the narrow App Store definition to imply that state health-privacy law does not reach us. It does.
Consumer health data collected, and why
RCW 19.373.020(1)(a)(i) requires us to state the categories of consumer health data collected and the purpose of collection, including how it will be used. Here is the complete list.
| Category | What it is | Why it is collected and how it is used |
|---|---|---|
| Photographs of your oral cavity | Images of your teeth, gums, tongue and mouth taken with the in-app camera on iPhone or iPad | So you can keep a dated visual record of your own mouth over time, and so the on-device AI can produce general educational information about what you are looking at |
| The "What this photo looks like" reading (only if you tap Read this photo on-device) | Text an on-device vision model writes about a saved photo, and a reading written from that text by Apple Intelligence or a model you downloaded, headed "This looks like", with one care job and questions for a dentist. It can name a dental condition | To show you what the models wrote. It is not a diagnosis. It is shown on screen and not saved |
| Questions you ask, and the answers | What you type into Ask on the phone, tablet, Mac, Vision Pro or Apple TV, or into Ask iPhone on Apple Watch, and the answer the on-device model writes | To answer you on your device. The conversation is held in memory and not saved. Ask iPhone on Apple Watch is not answered while on-device answers are off or a child session is active |
| Marks you draw on a photograph | A rectangle you draw on a photo of your own mouth, kept so a later photo can show the same place | So you can compare the spot you marked. The app does not name a tooth condition from the mark |
| Visit records | Date, practice name, kind of visit, what was done in your words, optional amount you typed, next due date you typed | So you can keep a log of visits you attended. The app does not book the visit or decide what was done. The date of each visit (only the date, as "Visit on" and the date) is added to your device's Spotlight search index so you can find it from system search |
| Documents you file | A treatment plan, radiograph, clinic photo, receipt or explanation of benefits you drop into the app | So those files sit next to your photos on this device. They stay in the app container, out of Spotlight and out of Handoff |
| Visit packet | One page of identifiers for photos, standing questions, and a visit | So you can open a one-pager at a sitting. The packet is identifiers, not a diagnosis |
| Notes you type about your mouth | Free text you write, optionally attached to a mark you drew | So you can remember what you wanted to tell a dentist. The app does not classify the note |
| Household names on this device | Display names, roles (owner, child, adult you care for, caregiver), and which mouth record is active | So more than one person in a household can keep a separate mouth record on this phone. Kids care sessions stay opt-in under Family & kids mode. The household does not sync, and no name goes to iCloud or through Handoff; while iCloud Sync is on, the active person's name goes to your paired Apple Watch in the continue note (next row) |
| The continue note | The tab you were on, the identifier of the education topic you last opened (for example diabetes_and_oral_health), the identifier of the last photo record you opened, the display name of the active household person, and when it was written |
So your other devices can offer to continue where you left off. The topic identifier can reveal the subject you were reading about. The name and the topic never go to iCloud, and the name never goes through Handoff. Everything but the tab leaves this device only while iCloud Sync is on; where each part goes is set out under "Where this data lives" |
| Children's display names and roles (only if you add a child) | A first name or nickname you type, the child role, and that this mouth is the active one | So the parent can switch to that child's record. There is no child Apple ID and no child sign-up |
| Photographs of a child's mouth (only if you photograph that child) | Images keyed to that child's mouth on this device | So the parent can keep a dated record of that child's mouth. A child session cannot open another person's photos. Auto-save to Photos is off while that child is active |
| A child's care-day log (only if you log care for that child) | Dates the shorter kids care session was completed for that person | So the parent can see whether today's care was logged for that child. This is not a wellness score |
| Oral-health profile | Age, brushing frequency, sugar intake level, smoking status, whether you have diabetes, whether you have dry mouth, and the goals you choose | To tailor the general information and habit suggestions the app shows you |
| Home-care habit logs | Daily records of brushing, flossing, mouthwash use and sugary drinks, including a brush you confirm from Apple Watch or a reminder notification | To show you your own streaks, trends and progress |
| Watch and reminder brush record | A record, kept on the iPhone, of whether you confirmed the morning and the evening brush from Apple Watch, a reminder notification or the Log care action, for the last day on which you confirmed one; each new confirm drops any earlier day | To tell whether both brushes of the day are done |
| Programme progress | Your progress through the in-app 30-day home-care programme | To let you resume where you left off |
| Illustrative cost scenarios | "What if" projections built from figures you enter, and any narrative text generated on-device alongside them | To let you explore an illustrative cost model. These are examples, not predictions about your health |
| Care reminder schedule (only if you turn reminders on) | Whether morning and evening reminders are on, and their times | To schedule local notifications on your device. The notifications name no person and no condition |
| App Group care snapshot | Whether today's care is logged, the streak, a one-line glance (the date of the active person's most recent photo, whether two of their photos are of the same view, and whether today's care is logged), a short prompt to open the app or start today's care, where a tap on the widget opens (the photo journal, or, on iPhone and iPad, the camera when there is no photo yet), the active person's display name, the Smile Points balance, and the time the snapshot was written, in storage shared only with the app's own widget | So the widget can show that one line. The widget shows only that line: no name, no count and no photograph. No photograph is in that suite |
| Care-session Live Activity (during a care session) | The timer, the step, and the name of the person whose session it is, on the iPhone Lock Screen and Dynamic Island | So you can follow the session without unlocking. Anyone who can see the Lock Screen can see it |
| Health data written to Apple Health (only while OmniDent's Apple Health switch is on) | A toothbrushing event when you finish a care session in which you brushed; a dietary sugar entry for sugary drinks logged in a care session; a toothbrushing event when you confirm a morning or evening brush from Apple Watch, a reminder notification or OmniDent's Log care action; and a toothbrushing event when you tick the brushing habit in the 30-day programme done. With the switch off, nothing is written and iOS is not asked for Apple Health permission. OmniDent reads nothing from Apple Health and does not ask to | So your entries appear alongside the rest of your health data in Apple Health, under your control |
Purposes, stated completely. All of the above is collected for one purpose: to operate the features of OmniDent that you choose to use, on your device, for you.
It is not used for advertising, for marketing, for profiling, for research, for training AI models, for sale, or for any secondary purpose whatsoever. There is no secondary purpose. If that ever changes, RCW 19.373.020(1)(d) requires us to disclose the new purpose and obtain your affirmative consent before processing for it, and we will.
Sources of consumer health data
RCW 19.373.020(1)(a)(ii) requires the categories of sources. There are four, and all of them are you or your own devices:
- You, directly — habit logs, profile answers, goals, notes, questions you ask, cost-model inputs, household names, and a child's display name you type in; and taps you make on your Apple Watch.
- Your device's camera, when you take a photo in the app on iPhone or iPad (including a photo of a child's mouth, if you take one).
- Files you pick, when you add a document to Record or open a household transfer file with the system file picker. OmniDent receives only the file you pick. It has no permission to read your photo library.
- The on-device models, which derive the photo reading from a photo when you ask for one, and answers from your questions. Taking a photo runs no model.
We obtain consumer health data from no other source. We do not buy it, rent it, receive it from data brokers, receive it from health care providers, infer it from third-party sources, or derive it from advertising identifiers.
Where this data lives
- On your device. Photographs are stored as files in OmniDent's private app container, encrypted at rest by iOS Data Protection at the Complete level. Everything else is in the app's local database, its settings store, or the storage it shares only with its own widget, on the same device. The date of each visit you log is also in your device's Spotlight search index (date only).
- Not on any Prameya system. Prameya operates no server that receives your consumer health data. We have no user database and no copy of anything described above.
- Not sent for AI processing. The AI runs on your device's own chip — Apple Intelligence on the device, or a model you downloaded. Photographs and text are never transmitted for analysis. A question you type on Apple Watch goes to your paired iPhone to be answered there, and the answer comes back to the Watch.
- Your own iCloud, for two things, while iCloud Sync is on (it is on unless you turn it off, at Settings → iCloud Sync):
- App preferences (which models you prefer, whether on-device answers are on, the auto-save setting, which models are downloaded), in your private CloudKit database. The set of records permitted there is pinned by an allow-list in the app to that one preferences record; photographs, analyses, the profile, habit logs, household people, visits and documents are classified so they cannot sync. Whether and when you acknowledged the wellness disclaimer, and whether you have seen the welcome screen, stay on each device and do not sync.
- Part of the continue note — the tab and the last photo-record identifier, never a person's name or the education topic — and your appearance choice, in iCloud's key-value store for this app. Apple TV reads it from there to say which tab you were last in; it shows no name. An entry an earlier version left there with a name or a topic (a device still running an earlier version can write one until it is updated) is replaced when the app starts and each time it saves the note, or removed if iCloud Sync is off. Turning iCloud Sync off removes it from iCloud straight away; so does Delete All Scans & Data.
- Handoff, to your nearby devices signed in to the same Apple Account, carries the tab, the last topic identifier and the last photo-record identifier while iCloud Sync is on, never a person's name — or, while you are taking a set of photos or have a visit packet open, random identifiers of that capture session or packet, of the mouth record and of a visit, and which photo views of an unfinished set are done — and only the tab while it is off, during a set of photos or with a packet open as well.
- Your paired Apple Watch receives the continue note from the iPhone, and shows the active person's name, while iCloud Sync is on; with it off, the Watch gets only the tab.
- Your Mac, if you add your iPhone's widgets to it (a feature of macOS), shows the line OmniDent's widget shows on your iPhone: the date of the active person's last photo, whether two of their photos are of the same view, and whether today's care is logged. Your iPhone passes it to your Mac, and OmniDent sends nothing for it. OmniDent's own widget on a Mac or Apple Vision Pro never shows a photo date, because OmniDent keeps no photos there.
- A household transfer file you make yourself is names and roles, sealed with a passphrase you type. Photographs, visits and documents stay on the sending device.
One honest limit on the first point: OmniDent does not mark its scan folder as excluded from your device backup. If you back your device up to iCloud or to a computer, those files are included in your own backup, under your Apple Account or on your own machine, governed by Apple's terms rather than ours. That is your backup of your device, not a transfer of data to us or to anyone else by the app.
Children's consumer health data
Washington requires children's health data to be listed distinctly. OmniDent does not collect it unless an adult on this device adds a child and uses that profile.
| What | Where it lives | Who can see it |
|---|---|---|
| Child's display name and child role | Local household row on this device. While that child's record is active and iCloud Sync is on, the name also goes to your paired Apple Watch in the continue note — never to iCloud or through Handoff — and, whatever the switch, it is on the Lock Screen during that child's care session | Anyone holding the unlocked phone who is in that child's session, or the owner looking at Household; anyone who can see your Apple Watch or Lock Screen while it is shown |
| Photographs of that child's mouth | Local journal keyed to that mouth | A child session sees only that mouth. An adult record is behind the device's own unlock: Face ID, Touch ID or Optic ID, or the device passcode or Mac password |
| Care days logged for that child | Local care-day tags for that person | Same as photographs |
| Visits or documents the owner files for that mouth | Local visit graph keyed to that mouth | A child session cannot open the visit packet. The owner opens Record after unlocking |
COPPA posture. The adult Apple ID on this device is the account holder. There is no child sign-up, no child Apple ID, no Kids-category listing, and nothing is sent to Prameya. Kids mode is a parent tool.
What a child session cannot do. Ask (including Ask iPhone from a paired Apple Watch), the photo reading, Settings, Paywall, dentist share, export, delete, Smile Points, auto-save to Photos.
What this is not. It is not Apple Screen Time, not Family Controls, not a remote parent dashboard, and not a live camera of the child.
Subscription tiers and consumer health data
No new collection when you subscribe
OmniDent offers one paid gate, OmniDent Pro (monthly, annual, or lifetime), in addition to the free tier. Household coverage is StoreKit Family Sharing of that Pro gate, not a separate Household product. Upgrading does NOT trigger new consumer health data collection.
Free and Pro:
- Process the same categories of consumer health data (listed above)
- Use consumer health data for the same purpose (operating features you choose to use)
- Store data in the same location (on your device)
- Send data to the same places (the continue note described above, in both tiers; nothing to Prameya)
Pro unlocks full photo history (on iPhone and iPad, the only devices that keep photos), reminder cadence, and a print-ready visit sheet. It does not change what data is collected, how it is processed, or where it goes.
What changes between tiers
| What subscription affects | What subscription does NOT affect |
|---|---|
| How much photo history the timeline, compare and visit sheet show (the three most recent photos vs full history; every photo is kept and exported in both tiers) | Whether anything the app shows is a diagnosis (never, in any tier) |
| Reminder cadence and the print-ready visit sheet | Where photos are stored (on-device in all tiers) |
| What goes to your iCloud (the same in every tier) | |
| What the on-device models may say about your mouth |
Purchase records
OmniDent keeps no purchase record of its own. When it needs to know whether you have Pro, it asks Apple's StoreKit on your device for your current entitlements and keeps the answer in memory. Apple keeps the transaction records — on your device and in your Apple Account — under Apple's terms, and processes your Apple Account and payment method when you subscribe. The app sends nothing about a purchase to Prameya. Those records say which product you bought and when; they say nothing about your mouth.
Consumer health data that is shared, and with whom
RCW 19.373.020(1)(a)(iii) requires the categories of consumer health data shared, and (1)(a)(iv) requires a list of the categories of third parties and the specific affiliates we share it with.
Categories of consumer health data we share with a third party for its own use: none.
Categories of third parties we share consumer health data with: none.
Specific affiliates we share consumer health data with: none. Prameya LLC has no affiliates that receive it.
Some of your data does leave the device and go to Apple — into your own iCloud account, through Handoff, and into your own Health store — as set out below. We list it all, so you can judge it. Here is every third party the app touches at all, and what each one gets:
| Third party | What they receive | Is it consumer health data? |
|---|---|---|
| Apple — iCloud / CloudKit | App preferences, held in your private iCloud database under your Apple Account, while iCloud Sync is on | No |
| Apple — iCloud key-value store | Part of the continue note — the tab and a photo-record identifier, never a person's name or the education topic — and your appearance choice, held in your iCloud account while iCloud Sync is on | No. It names no person and no topic, and the record identifier is a random string, not the photo. Apple holds it as your iCloud provider; Prameya cannot read it |
| Apple — Handoff | The tab, the identifier of the last education topic you opened and a photo-record identifier, never a person's name — or, during a set of photos or with a visit packet open, random identifiers of it, the mouth record and a visit, and which photo views are done — passed to your own nearby devices on the same Apple Account, while iCloud Sync is on; only the tab while it is off | The topic identifier can reveal what you were reading about. We list it here for that reason. Prameya cannot read it |
| Apple — StoreKit / App Store | Purchase and entitlement checks | No |
| Apple — Sign in with Apple | The sign-in exchange, if you choose to sign in | No |
| Apple — Apple Health | Toothbrushing and dietary sugar entries you logged, written into your Health store on your device, only while OmniDent's Apple Health switch is on | Yes. It is written into your own device's Health store; Apple does not receive it from us for any purpose of theirs |
| Hugging Face | Requests for AI model files, only when you tap Download | No. No photograph, no analysis, no habit data, no question, no identifier of you |
There is no advertising network, no analytics vendor, no crash-reporting vendor, no data broker, no dental practice, no insurer, and no research partner in that list, because there is none in the app.
You can also share data yourself through the iOS share sheet: Export My Data, the household transfer file, and Share care summary (the active person's display name, care streak and recent care-day count, the dates and small previews of the photos you select, and, with Pro, a one-page PDF). OmniDent sends none of these itself; each goes only to the recipient you choose, and is not a disclosure by us.
Prameya has never received or shared your consumer health data.
Selling consumer health data
We do not sell consumer health data. We never have. We will not.
Washington requires a signed, specific written authorization before any sale, valid for no more than one year and revocable (RCW 19.373.070). We have never sought such an authorization from anyone and do not intend to. Nevada imposes a parallel requirement, and the same answer applies.
If you are ever shown a document asking you to authorise the sale of your OmniDent health data, it did not come from us.
Your rights
RCW 19.373.020(1)(a)(v) requires us to explain how you exercise the rights in RCW 19.373.040. Nevada provides closely comparable rights.
1. The right to confirm and access
You may ask whether we are collecting, sharing or selling your consumer health data, and to access it — including a list of all third parties and affiliates with whom we have shared it, and contact information for each.
Fastest route (immediate, no waiting): Settings → Privacy & Security → Export My Data in the app produces a .zip file of your on-device records, generated on your device and handed to the standard iOS share sheet. Inside it:
export.json— your photo records, the caption and view tag you wrote on each one, your logged care days, your saved what-if scenarios, your claimed partner promotions, your 30-day programme progress, and your oral-health profile. A scan entry carries coded dental vocabulary terms, capability labels and a number of findings only where an analysis is saved with that photo. Taking a photo runs no AI model and saves no analysis, so the entry for a photo you take leaves those fields out.Photos/— every photograph you took in OmniDent, at full resolution, with location and camera details removed.Thumbnails/— the small preview of each one.
Where a photograph's file is no longer on your device, the record is still exported and marked photoFileMissingOnDisk, with the thumbnail, rather than dropped. Where a photograph is on your device and cannot be read, no file is produced at all and the app names the file: an export that looks complete and is short one picture is the failure this rule exists to prevent.
One limit worth knowing when you use it as an access request: the export covers the records listed above and not everything the app holds. Not in the file: the photo reading (which is never saved), household people and names, visits, plan lines, documents, visit packets, marks and notes on a photo, the Watch and reminder brush record, and the settings-store items — care-day history, profile names, Smile Points, widget snapshot, reminder schedule and the cost-model sliders. They are on your device and visible in the app. Email admin@prameya.legal if you want help getting at them.
Formal route: email admin@prameya.legal. We will confirm in writing that we hold no consumer health data about you on any Prameya system, that we have shared none, and that we have sold none. What is in your own iCloud (the preferences and the continue note) is in your Apple Account, and the in-app controls below remove it.
2. The right to withdraw consent
You may withdraw consent to our collection and sharing of your consumer health data at any time, for any part of it or all of it.
| To withdraw consent to | Do this |
|---|---|
| Camera and photographs | iOS Settings → Privacy & Security → Camera → OmniDent, or simply stop taking photos |
| A child on this device | Settings → Privacy & Security → Delete All Scans & Data (clears household people and names, and the continue note in iCloud) |
| Adding photos to your library | iOS Settings → Privacy & Security → Photos → OmniDent |
| On-device AI (Ask, Ask iPhone on Apple Watch, and the photo reading) | OmniDent → Settings → General → Enable on-device answers → off |
| Apple Health | OmniDent → Settings → Apple Health → off stops every write and every Apple Health permission request from OmniDent. iOS Settings → Health → Data Access & Devices → OmniDent revokes the permission itself |
| Care reminders | OmniDent → Settings → Care reminders, or iOS Settings → Notifications → OmniDent |
| iCloud sync, and the continue note in iCloud | OmniDent → Settings → iCloud Sync → off, on each of your devices (the switch is per device, and a device where it is still on keeps writing its own continue note). The continue note is removed from iCloud at once; preference syncing stops the next time you open the app |
| Handoff | Turn Handoff off in your device's settings (on iPhone: Settings → General → AirPlay & Continuity). With OmniDent's iCloud Sync off, Handoff carries the tab alone |
| Everything at once | Delete All Scans & Data, turn iCloud Sync off, then delete the app. Deleting the app alone removes its container but not what is in your iCloud |
Withdrawing consent does not undo processing that already happened, and it does not by itself delete data. Use the deletion right for that.
3. The right to delete
You may have your consumer health data deleted, including from backups and archived systems. We must delete it from all parts of our network.
Fastest route (immediate and permanent):
| To delete | Where |
|---|---|
| A single photograph — any of them, not only the most recent | You → All your photos → tap the photo → Delete this photo. Press-and-hold a row, or swipe it, for the same control. A child session cannot delete; the owner deletes from an adult session |
| A visit you logged | Record → the visit → Delete this visit |
| A document you filed | Record → the document → Delete this file. The file is removed from the app container |
| A single logged care day | Do → Your care log → tap the day → Delete this care day. Press-and-hold or swipe for the same control |
| A single saved what-if scenario | More → What-if → Saved Scenarios → tap it → Delete this scenario |
| A single claimed partner promotion | Settings → Privacy & Security → Claimed offers → Delete this claim. The row appears only if you have one; the app no longer lists partner offers, so no new claim can be made |
| Your 30-day programme progress — the start date and every ticked habit | 30-Day Reset → Delete my 30-day progress |
| Your oral-health profile — age, brushing frequency, sugar and acid intake, smoking, diabetes, dry mouth, goals | Settings → Edit My Health Profile → Delete my health profile |
| Your photographs and their analysis, habit logs, household people, visits, documents and everything else listed below the table — but not quite everything; see the list of what it leaves | Settings → Privacy & Security → Delete All Scans & Data |
| The continue note in iCloud (tab, photo-record identifier) | Settings → iCloud Sync → off (removes it at once), or Delete All Scans & Data |
| Your Sign in with Apple association, the app's records in your private iCloud database, and everything Delete All removes (it also turns iCloud Sync off on that device) | Settings → (your account, at the top) → Delete Account & All Data |
| Everything left on the device, including the items the controls above leave behind | Delete the app from your device — iOS removes the whole container. It does not remove what is in your iCloud; use the rows above first |
| Data written into Apple Health | The Apple Health app |
| Photographs copied into your Photos library | The Photos app |
The first eight rows are per-record controls. Every record type you can create now opens as its own screen and deletes on its own, behind a confirmation that names exactly what goes and says what the deletion cannot reach — an Apple Health sample OmniDent wrote, or a copy of a photograph in your own Photos library.
Correcting rather than deleting. Two of these records can be corrected in place instead: a logged care day, because it is your own account of a day and you are the only source it ever had, and the caption and view tag on a photograph, because you typed them. The rest are records of something that happened — a projection that was run from particular inputs on a particular day, a promotion you claimed — and editing one would leave it claiming a result that did not come from the inputs shown. Those say so on screen and offer deletion instead. Whichever it is, the screen tells you which.
"Delete All Scans & Data" removes the scan records and the JPEG files on disk, the analysis attached to each scan, trajectory snapshots, habit logs, claimed partner promotions, 30-day programme progress, the oral-health profile itself, household people and mouths, visits, plan lines, documents and their files, visit packets, marks drawn on photos, any old copy of the app's database that it moved aside because it could not open it at launch (the app tells you on screen when this happens), App Group leftovers (after which it asks the system to redraw the Home Screen widget, which then has no photo date to show), every downloaded model and its bookkeeping, the Watch and reminder brush record, the visit dates in Spotlight, care reminders already scheduled, and the continue note in iCloud and the name your paired Apple Watch was showing; and it resets the synced preferences to their first-launch values. It also clears the app's settings store: care-day history, profile names, Smile Points, widget snapshot, reminder schedule, the Apple Health switch, the self-reported care and risk inputs for the cost model, and whether you have seen the welcome screen and acknowledged the wellness disclaimer on this device. A save or file failure is shown in Settings rather than reported as success.
What it leaves: your iCloud Sync switch, on purpose, so deleting data does not change your sync choice; your Sign in with Apple entries (Delete Account removes those); anything already in Apple Health or your Photos library; and, in one rare case, the app's database file itself: when OmniDent can neither open it at launch nor move it aside, it says on screen that it is running on temporary storage, and Delete All in that session cannot reach the file (run Delete All again after a launch that does not say so, or delete the app). If iCloud Sync is still on, the reset preferences are written back to your iCloud, and the continue note starts again from what you do next.
Delete Account & All Data also turns iCloud Sync off on that device and removes the continue note from iCloud. Preference syncing stops completely the next time you open the app; until then, the reset preferences can still be written back to your private iCloud database.
On the Sign in with Apple row, one thing should be stated precisely rather than implied. Apple's deletion rule for apps offering Sign in with Apple also requires token revocation where the app exchanges Apple's authorization code for tokens on its own server. OmniDent has no server and never performs that exchange, so no Apple token for OmniDent exists and the app makes no revocation call — the app-scoped identifier in your device's Keychain is the entire association, and deleting it is the entire deletion. If you also want OmniDent removed from your Apple Account's Sign in with Apple list, that is Apple's own control, at iOS Settings → your name → Sign in with Apple → OmniDent.
What Apple holds for you as your iCloud provider — the preferences and the continue note — is removed by the controls above, not by a request to us, because it is in your Apple Account and we cannot reach it.
Formal route: email admin@prameya.legal. Because we hold no consumer health data on any Prameya system, there is nothing on our side to delete and no backup or archived copy of it anywhere in our network. We will confirm that in writing. What is in your own iCloud is deleted with the in-app controls above. Washington permits up to six months for deletion from archived or backup systems solely to allow restoration; we have no such systems containing your consumer health data, so that extension never applies to us. Backups you make of your own device are yours, held under your Apple Account or on your own computer, and we cannot reach into them.
4. Timing, and how to appeal
- We respond to a request within 45 days of receiving it.
- We may extend once by a further 45 days where reasonably necessary given the complexity or number of your requests. If we do, we will tell you within the first 45 days and explain why.
- If we refuse to act on your request, we will tell you why, without undue delay and within the same 45 days, and we will tell you how to appeal.
- To appeal, reply to our response or email admin@prameya.legal with "Appeal" in the subject line. A different person than the one who handled the original request will review it. We will decide the appeal and give you a written explanation within a reasonable time.
- If we deny your appeal, we will provide you with a method to contact the Washington State Attorney General to submit a complaint. You can reach the Washington Attorney General's consumer protection division at atg.wa.gov. Nevada residents may complain to the Nevada Attorney General at ag.nv.gov.
5. Verifying who you are
We will not ask you for identity documents. We cannot match them against anything, because we hold no record of you. If you email us, we will correspond with you at the address you wrote from. We will not ask you to create an account or provide additional personal information in order to make a request — doing so would mean collecting more data than we hold in the first place.
We will not discriminate against you for exercising any right in this policy. There is no paid tier that depends on your data, and no feature is withheld because you said no.
Geofencing
We do not use geofencing.
Washington makes it unlawful to implement a geofence around any entity providing in-person health care services in order to identify or track consumers, collect consumer health data, or send them health-related advertisements or notifications (RCW 19.373.080).
OmniDent does not request location permission, does not have a location entitlement, contains no geofencing code, sends no marketing notifications (its only notifications are the care reminders you turn on, scheduled on your device), and shows no advertisements of any kind. There is no geofence around a dental office, a hospital, a pharmacy, or anywhere else.
Nevada residents (SB 370)
Nevada's consumer health data law, enacted as SB 370 and codified in NRS ch. 603A, took effect on 31 March 2024. Its duties closely track Washington's.
Everything in this policy applies to you:
- The categories of consumer health data, sources, purposes and uses set out above are the same.
- We do not share your consumer health data with any third party for its own use. What the app puts in your own iCloud, sends to your own devices through Handoff, or writes to your own Apple Health is listed above.
- We do not sell your consumer health data, and we have never sought the separate written authorization Nevada requires for a sale.
- You have the right to confirm whether we collect, share or sell your consumer health data, the right to access it, the right to have it deleted, and the right to withdraw consent to its collection and sharing. Use the same routes described above.
- You may complain to the Nevada Attorney General at ag.nv.gov.
Processors
RCW 19.373.020(1)(e) requires that any contract with a processor be consistent with this policy.
We use no processor for consumer health data. There is no vendor, no contractor, no cloud provider and no analytics service that processes your consumer health data on our behalf, because your consumer health data never reaches us to hand on. Apple provides iCloud, Handoff and Apple Health to you under your own agreement with Apple; OmniDent writes the items described above into them, and Prameya has no contract with Apple for them and no access to them. If that ever changes, we will name the processor in this policy, bind it by contract to these terms, and — where the law requires it — obtain your consent first.
Employees and contractors
Access to consumer health data is restricted to those who need it to provide the service. In practice that number is zero: no Prameya employee or contractor can access your consumer health data, because it exists only on your devices and in your own Apple Account, and we have no channel to it.
Enforcement
A violation of Washington's My Health My Data Act is a violation of the Washington Consumer Protection Act, RCW ch. 19.86. That means it may be enforced by the Washington State Attorney General and may also be pursued by an individual under RCW 19.86.090.
We take that seriously, and it is the reason this document describes what the app actually does rather than what would be convenient to claim. Where a statement here would otherwise depend on a change that has not shipped, we describe the behaviour of the app as it exists today instead — including where that is less flattering.
Changes to this policy
If we change the categories of consumer health data we collect, add a source, add a purpose, or add anyone we share it with, we will:
- update this policy and change the effective date;
- obtain your affirmative consent before collecting or processing for the new category or purpose, as RCW 19.373.020(1)(c) and (1)(d) require — before the change takes effect, not after;
- show an in-app notice describing what changed.
7 October 2026 — what changed. OmniDent was changed, and this policy describes the app with those changes:
- The Home Screen widget is now a photo-journal glance. The line it shows, kept in the storage the app shares only with its widget, now includes the date of the active person's last photo and whether two of their photos are of the same view. The snapshot also says where a tap on the widget opens. It is derived from photographs already listed above, and OmniDent sends nothing off your device for it. The App Group care snapshot row now lists all of this; it used to say only "a short status line". If you add your iPhone's widgets to your Mac, the Mac shows your iPhone's line, and "Where this data lives" now says so.
- If OmniDent cannot open its database when it starts, it moves the old file aside and starts fresh, and tells you so on screen. Delete All Scans & Data, and so Delete Account & All Data, did not remove that old file: it kept the records it held, including photo thumbnails, the oral-health profile, habit logs and household names, a child's included, until you deleted the app. "What it leaves" did not name it, and it should have. Delete All now removes it, and a file it cannot remove is shown as a failure. "What it leaves" now also names the one rare case Delete All cannot reach: a database the app could neither open nor move aside, while it runs on temporary storage.
- Delete All Scans & Data now also asks the system to redraw the Home Screen widget. Before, the widget could keep showing its last line, including the date of a photo you had deleted, until you next opened the You or Do tab or ran a care session, or until midnight.
No category, source, purpose or recipient is added, and nothing is sent to Prameya.
Later on 27 September 2026 — what changed. This policy now says that Pro's full photo history is on iPhone and iPad. The Mac and Apple Vision Pro take no photo and receive none, so there Pro unlocks the reminder cadence and the print-ready visit sheet. No category, source, purpose or recipient is added, and nothing is sent to Prameya.
27 September 2026 — what changed. The children's table said an adult record is behind Face ID or the device passcode. It is behind whatever unlock the device has: Face ID or Touch ID on iPhone and iPad, Touch ID or your Mac password on a Mac, Optic ID on Apple Vision Pro, or the device passcode. The lock itself did not change. No category, source, purpose or recipient is added, and nothing is sent to Prameya.
26 September 2026 — what changed. OmniDent was changed, and this policy describes the app with those changes:
- No person's name and no education topic identifier go to iCloud. With iCloud Sync on, the continue note in your iCloud key-value store holds only the tab and a photo-record identifier; it used to carry the last education topic you opened and the active household person's name as well. An entry an earlier version left there with either is replaced when the app starts, or removed if iCloud Sync is off. The list of what Apple receives now says so, and no longer counts the iCloud key-value store entry as consumer health data.
- Handoff never carries a person's name. With iCloud Sync on it still carries the topic identifier and the photo-record identifier to your own nearby devices; with it off, the tab alone, as before.
- Apple TV no longer shows the active person's name, including a child's, and no longer opens the topic you last read.
- Your paired Apple Watch still receives the active person's name while iCloud Sync is on.
- Whether and when you acknowledged the wellness disclaimer, and whether you have seen the welcome screen, are kept on each device and no longer sync to your private iCloud database. Delete All Scans & Data clears them.
No category, source, purpose or recipient is added, and nothing is sent to Prameya.
24 September 2026 — what changed.
- It removes the category "information derived from those photographs", and the capture note from the sources and the export limits. The previous version said an on-device vision model writes a short note when you capture a photo, kept with the photo, along with coded vocabulary terms and a capture-quality score. OmniDent does none of that: taking a photo saves it and runs no AI model. The one thing an on-device model derives from a photo is the "What this photo looks like" reading, which you start and which is not saved; it keeps its own row. The export description now says the entry for a photo you take carries no analysis fields.
Also on 24 September 2026, OmniDent was changed, and this policy describes the app with the change:
- With iCloud Sync off, Handoff no longer carries the random identifiers of a set of photos you are taking or of a visit packet you have open, of the mouth record or of a visit, or which photo views are done. It carries the tab alone, as the continue note already did. With iCloud Sync on it carries them as before, and the list of what Apple receives now names them.
No category, source, purpose or recipient is added, and nothing is sent to Prameya.
23 September 2026 — what changed. We re-read the app as it is built today and corrected this policy:
- It adds the continue note — the last education topic you opened and the active household person's name — which goes to your own iCloud key-value store while iCloud Sync is on (the default), to your nearby devices through Handoff, and to your Apple Watch; and it says Apple TV and Apple Watch show that name. The previous version said nothing health-related went to iCloud.
- It adds questions you ask in Ask (answered on your device), the "What this photo looks like" reading (which can name a condition and is not saved), care reminders, the Lock Screen care timer, the Watch and reminder brush days, and the visit dates added to your device's Spotlight search.
- It says a brush confirmed from Apple Watch or a reminder writes to Apple Health even with OmniDent's Apple Health switch off; that the 30-day programme and the Watch can raise iOS's Apple Health permission request while the switch is off; exactly which entries are written; and that no Apple Health data is read today.
- It says the iCloud Sync switch is set on each device separately, and describes the care summary you can share yourself.
- It corrects deletion: Delete All now also removes household people, visits, documents and the continue note in iCloud, keeps your iCloud Sync switch, and leaves the brush-day list and the Spotlight visit dates; Delete Account does not turn iCloud Sync off; deleting the app does not empty iCloud.
- It corrects purchases (the app keeps no transaction record of its own), the export description, and the withdraw-consent routes, and removes the Studio projection and "collective priors" toggle, which are no longer in the app.
Also on 23 September 2026, OmniDent was changed to fix defects that the version above disclosed, and this policy now describes the app with those fixes:
- Apple Health writes only while OmniDent's Apple Health switch is on, from every path, and nothing asks iOS for Apple Health permission while it is off. The 30-day programme writes only when you tick the brushing habit done. OmniDent no longer asks to read step count, sleep, mindful minutes or active energy, so that category is removed.
- Ask iPhone on Apple Watch now respects Enable on-device answers and a child session, and never starts a model download.
- With iCloud Sync off, Handoff and your Apple Watch get only the tab — not the topic, the record identifier or the active person's name.
- Delete All Scans & Data now also removes the Watch and reminder brush record (which now keeps only the last day on which you confirmed a brush), the visit dates in Spotlight and the reminders already scheduled, and clears the name on your Apple Watch.
- Delete Account & All Data now turns iCloud Sync off on that device.
Nothing is sent to Prameya, and no new third party receives your data.
The 20 September 2026 revision lists children's health data as its own categories, and names the child-session lock (Face ID or the device passcode), mouth isolation, auto-save to Photos off while a child is active, and the names-only household transfer file. The 19 September 2026 revision added categories the shipping app already stores: visit records, documents you file, visit packets, marks you draw on a photograph, notes you type about your mouth, household names on this device, and the App Group care snapshot. It also replaces leftover Plus/Premium subscription language with the one Pro gate. Those categories are collected only on your device. The 24 August 2026 revision replaced the export description and the single-photograph deletion route so they match the shipping app: the export is a .zip carrying every photograph at full resolution, and the deletion table names the per-record controls. The 21 August 2026 revision restates auto-save captures to Photos as off until you turn it on (the main policy is the source for that setting). The 8 August 2026 revision was a correction pass rather than a change of practice. We re-read the shipping source code and rewrote every statement that did not match it. The deletion section previously said that deleting your account revokes your Sign in with Apple token; it does not, because the app has no server, never exchanges the authorization code, and therefore has no token in existence to revoke. That section now states what deletion actually does. We also corrected the name of the deletion control, described the placeholder percentages in the Studio Regenerative Projection feature, noted that scan files are not excluded from your own device backup, described the export file accurately, and confirmed the statements that had been pending internal verification and are now true of the build.
Previous versions are available on request. We do not make material changes quietly.
Contact
Prameya LLC
Consumer health data requests, questions, appeals and complaints: admin@prameya.legal
Put "Health data request" or "Appeal" in the subject line so it is routed correctly.
Main OmniDent privacy policy: https://prameyallc.github.io/privacy/omnident/
All Prameya app privacy policies: https://prameyallc.github.io/privacy/