OmniDerm Privacy Policy
Effective date: 8 October 2026 (supersedes the 7 October 2026 version; what changed is listed under "Changes to this policy" at the end)
Publisher: Prameya LLC ("Prameya", "we", "us"), a United States limited liability company
Contact: admin@prameya.legal
This policy covers: the OmniDerm app — bundle ID legal.prameya.OmniDerm — on iPhone, iPad, Mac and Apple Vision Pro, its Apple Watch app, its Apple TV app, and its Home Screen and Apple Watch widgets. Prameya's other apps have their own policies.
Related pages
- Consumer Health Data Privacy Policy for OmniDerm — a separate, additional policy required by Washington's My Health My Data Act. If you live in Washington or Nevada, read that one too. It is a distinct document, not a section of this one.
- Privacy policies for all Prameya apps
- This policy lives at https://prameyallc.github.io/privacy/omniderm/
The short version
- The photo self-check (any assessment of a skin photograph) is switched off. It sits behind a regulatory clearance gate that is closed, so the shipping app produces no observations, flags, ratings or any other output about a photo of your skin.
- You can still save a journal photograph. That is a picture you picked, stored on this device, shown back to you. It is not analysed.
- There is no account and no password. We do not know who you are.
- Prameya runs no server that receives your data. We have no database of users. There is nothing on our side to hack, subpoena, or sell.
- Ask answers typed questions on your device. Where Apple Intelligence is on and ready, Apple's on-device model answers. Otherwise Ask can use an on-device model that you choose to download from Hugging Face in Settings, and only after you agree to that download. Your question is not sent to us, to Hugging Face, or to any AI service. The answer is shown as the model wrote it, unfiltered, and can be wrong.
- No ads. No analytics. No tracking. We do not sell your data, and we never will.
- iCloud Sync and Handoff stay off until you turn the one switch on. Remembering topics you open also stays off until you allow it. With the switch on, a small set of app settings goes to your own iCloud account, and Handoff can tell your other Apple devices which tab you are on. The identifier of a topic you open, and Handoff of that topic, go only when you have allowed remembering. The widget's suggested next topic can still go with the iCloud switch before that allow. Never your journal, photographs or habit logs. Switching sync off removes what OmniDerm put in iCloud (see "iCloud, Handoff and your other devices").
- Your device backup includes your journal notes and habit logs (not your journal photographs), if you back up your device.
- OmniDerm does not read Apple Health. Reminders start off — they are local notifications from your own device, and you turn them on in Settings.
- OmniDerm does not diagnose anything. It is not a substitute for a dermatologist. See "What OmniDerm will not do" below.
Who we are
OmniDerm is published by Prameya LLC, a US limited liability company. You can reach a human at admin@prameya.legal. We do not have a phone line.
What OmniDerm is
OmniDerm is a consumer app for skin-care habits and education. It helps you:
- keep a private journal of notes and optional photographs on this device;
- log daily habits (sunscreen in the morning, reapplying, barrier care, and whether you looked at the same area of skin today) and see your streak and consistency;
- read topics built into the app about sun protection and skin care, skin conditions, infections and infestations, and what looking at your own skin can and cannot show;
- ask general skin-care questions in Ask, answered by a language model on your device.
What OmniDerm will not do
OmniDerm is not a medical device and does not diagnose, screen for, or detect skin cancer or any other condition. It does not tell you whether a mole is dangerous. Nothing it shows about your own photographs or notes tells you whether to see a doctor, though its education topics do list general warning signs that call for a dermatologist.
Features that would produce an assessment of a photograph of your skin are behind a clearance gate that is switched off. In the version of OmniDerm on the App Store, the app does not produce observations, flags, ratings, or any other output about a photo of your skin. The photo self-check that earlier builds carried, closed behind that gate, was removed from the app on 26 September 2026: there is no button for it, no screen behind it and no vision model, and the app never downloads one. The gate itself stays in the code, closed, on the type that would carry such a result. A photo feature would come back only as a new feature, and only once it has the regulatory clearance it would need.
In practice there is no assessment screen to open: Understand has no button for one. You can still save a journal photograph. Settings → Legal & Safety states what the app does and does not do.
Ask never sees a photograph. It is given only the question you type, the last few lines of the current conversation, and passages from OmniDerm's built-in topics. It is not given your journal, your photographs or your habit logs. The model is instructed not to assess anyone's skin, but OmniDerm does not check or filter what the model writes: the answer is shown as written and can be incomplete or wrong.
If you notice a new spot, a changing spot, or anything that worries you, see a licensed clinician. Do not use this app to decide not to.
Subscriptions and In-App Purchases
Available tiers
There is one paid upgrade, OmniDerm Pro, sold as three products. Buying any one of
them grants exactly the same Pro — there are no separate feature tiers.
| Product | Price (US) | Billing |
|---|---|---|
| OmniDerm Pro Monthly | $4.99 | Auto-renews monthly. 7-day free trial for eligible accounts. |
| OmniDerm Pro Annual | $29.99 | Auto-renews yearly. 7-day free trial for eligible accounts. |
| OmniDerm Pro Lifetime | $79.99 | One-time purchase. Not a subscription. |
Family Sharing is enabled on all three. Subscriptions renew until you cancel (how, on each
device, is under Cancellation and refunds below); Lifetime is a one-time non-consumable. The paywall shows the free trial only when Apple reports that your account is eligible for it.
The knowledge layer is free and stays free. Without paying anything you get
your journal, your photographs, habit logging, the education library, Ask and the full export, with no account and no time limit. Pro adds the whole journal series with photographs on screen (the free plan shows the last 30 days in full), what you marked on every logged day (the free plan shows the marks for the last 90 days, and lists older days by date), same-area compare (pick an earlier and a later photograph of one body area and view them blended or side by side), and the formatted appointment pack.
Pro does not add cloud sync, and there is no paid iCloud option. OmniDerm stores your
records on your device in every case, paid or not. If a subscription lapses you keep your
own data and can still export it in its raw form; only the Pro tools stop.
Free vs paid tier data collection
Both tiers process the same consumer health data (listed in the Consumer Health Data Privacy Policy).
- Free: journal entries and photographs stored on this device. The journal timeline shows the last 30 days in full; older entries are listed below it under Older entries (date, body area and note, without the photograph), and each one opens to be read, corrected or deleted. The list of logged habit days shows what you marked for the last 90 days; older days are listed below it under Older days (the date only), and each one opens to Delete this logged day.
- With Pro: the same records in the same place, with the whole journal series and its photographs on screen, the whole habit history with its marks, same-area compare and the appointment pack.
In both tiers:
- Journal photographs stay on your device and are not in its backup
- Journal entries, photographs and habit logs are never synced to iCloud by iCloud Sync (device backups are separate — see "Everything the app stores, and where")
- Nothing is transmitted to Prameya
- The same on-device processing applies
Subscription unlocks features. It does not change what data is collected or where it goes. The export (Export my record) is free in both tiers and always contains every record, whatever the screen is showing.
Cancellation and refunds
Subscriptions are managed by Apple:
- Cancel on iPhone, iPad or Apple Vision Pro: the Settings app → your name → Subscriptions → OmniDerm → Cancel Subscription
- Cancel on a Mac: the App Store app → your name → Account Settings → Subscriptions → Manage
- In the app: while Pro is active, Manage Subscription in OmniDerm's Settings opens Apple's subscription controls (on a Mac, Apple's subscriptions page)
- Refund requests: reportaproblem.apple.com
Prameya cannot cancel your subscription or issue refunds. Apple controls all billing.
StoreKit transaction data
When you buy or restore Pro, Apple's StoreKit on your device completes the purchase with Apple and tells OmniDerm which Pro product is active and, for a subscription, when it renews. OmniDerm uses that answer to unlock Pro and does not write the transaction into its own storage: it asks StoreKit again at launch and after each purchase. Nothing about a purchase is sent to Prameya, and we never see your name, payment details or Apple Account.
Your purchase records are Apple's, kept by Apple under Apple's terms. Clear All Local Data does not remove them and does not cancel a subscription; Restore Purchases gets Pro back after a reinstall.
Your skin photos
Two different things used to be described as if they were one. They are not.
Journal photographs (shipping). You can attach a photo to a journal entry using Apple's photo picker, which hands OmniDerm only the one image you pick; the app cannot browse your library and does not ask for camera access. OmniDerm re-encodes the picture as a JPEG no larger than 1,600 pixels on its long side, with its location and other metadata removed, and stores it on this device under Application Support (OmniDerm/JournalPhotos), with the strictest file protection on iPhone, iPad and Apple Vision Pro (on a Mac, macOS and FileVault protect it; see "Security"), excluded from device backup, never uploaded, never synced to iCloud, and never assessed. If the picture cannot be re-encoded, nothing is attached. Clear All Local Data deletes those files.
Photo self-check (removed). The photo self-check sat behind an FDA clearance gate that was off. It was removed from the app on 26 September 2026: the app has no screen that produces an observation about a photograph, and offers no vision model.
If the gate were ever opened, this is how the assessment path is built:
| Question | Answer |
|---|---|
| Where would a photo come from? | Only from you, through Apple's standard photo picker, one image at a time. |
| Is the photo uploaded to Prameya? | No. We have no server that could receive it. |
| Is the photo sent to any AI company or cloud model? | No. Any processing happens on your device. |
| Is a journal photo uploaded? | No. Journal JPEGs stay on this device. |
One honest caveat. Your own device backup and your own iCloud Photos settings are Apple's, not ours. Journal JPEGs are excluded from this app's backup; the rest of the journal is not (see "Everything the app stores, and where"). Originals in Apple Photos follow your Photos settings.
Everything the app stores, and where
| What | Where it lives | Leaves your device? |
|---|---|---|
| Journal entries: date, body area, note, lighting note, and whether a photograph is attached | On your device, in the app's local database | Only inside your device backup, if you back up your device. Never synced, never uploaded by OmniDerm. |
| Journal photographs you save | On your device, as JPEG files under Application Support (OmniDerm/JournalPhotos), metadata removed. Excluded from device backup. Deleted with Clear All Local Data. Never assessed. |
No |
| Habit logs (date; whether you did morning SPF, reapplied, did barrier care, or looked at the same area today; and where the log was made, for example Do or your Apple Watch) | On your device, in the app's local database | Only inside your device backup |
| Your goals list, reminder on/off and hour, appearance, landing tab, first-run acknowledgement, the iCloud Sync and Handoff switch, whether you allow remembering topics you open, and an internal reference to the journal entry you saved last | On your device, in app preferences | Only inside your device backup — and, if you turn on iCloud Sync and Handoff, the five settings listed under "iCloud, Handoff and your other devices". The remembering allow stays on this device; it is not one of those five. |
| Your reminder hour, only while reminders are on | On your Apple Watch, in storage that only the OmniDerm Watch app and its watch-face complication share | It comes from your iPhone over the connection between the two devices (see "Apple Watch"), and goes nowhere else |
| Your answer to the Ask model download, with the model and version it was given for, and which of the offered models you chose | On your device, in app preferences | Only inside your device backup |
| The downloaded Ask model's files, only if you chose to download one | On your device, under Application Support (OmniDerm/HubCache). Excluded from device backup. |
No |
| Questions you type in Ask, and the answers | In memory, for the conversation on screen. Not written to storage. | No |
| The identifier of a topic you open in Understand (the topic held for continuing), the list of topics you have opened, and the widget's next suggested topic | The suggested topic is in your own iCloud key-value storage while iCloud Sync and Handoff is on. An opened-topic identifier and the opened list go there, and into the Handoff activity, only after you also allow remembering | Yes — to your iCloud and your own devices, not to us. The Watch receives an opened-topic identifier only when remembering is allowed (see "Apple Watch") |
| A temporary copy of an export you make | A backup-excluded scratch folder, cleared afterwards | Only where you share it |
| Diagnostic log messages | Apple's on-device system log | No |
We do not build a profile of you. We could not: we receive nothing.
If you back up your device to iCloud or a computer, iOS includes the app's local database and preferences in that backup, under Apple's terms and your control. Journal photographs and the downloaded model are excluded, so they are not restored onto a new device; after a restore the journal entries come back and the app tells you their photographs did not.
Outside connections: Ask model downloads, and links you open
OmniDerm makes no connection to a server of ours; there is no such server. Apart from Apple's services (described elsewhere in this policy), the app connects to one outside service, and only when you ask it to.
Hugging Face, for the optional Ask model — only after you agree. In Settings → On-device Ask model, the switch Use an on-device model opens a consent sheet that names the model's size and Hugging Face as the source. Nothing downloads unless you tap Download on that sheet. After that, with the switch still on, a different model downloads only when you tap a button in that Settings section that names it and its size. The download runs only while OmniDerm is open, only over a connection the system does not mark as expensive or constrained (Wi-Fi, not cellular data or Low Data Mode), and only when the device has the free storage and memory the model needs.
Which model a device is offered depends on its memory, and devices without Metal 3 graphics are offered none:
| Device | Model offered first | Smaller model offered if memory is short | Optional larger model |
|---|---|---|---|
| iPhone or iPad with 6 GB of memory or less, Apple TV, Apple Watch | None | — | — |
| iPhone or iPad with 8 GB; Mac with 8 GB | MiniCPM5 2B ("Compact") | — | — |
| iPhone or iPad with 12 GB or more; Apple Vision Pro | Gemma 4 E2B ("Standard") | MiniCPM5 2B | — |
| Mac with 16–18 GB | Gemma 4 E2B ("Standard") | MiniCPM5 2B | Gemma 4 E4B ("Large"), if you choose it |
| Mac with 24 GB or more | Gemma 4 E4B ("Large") | Gemma 4 E2B | — |
| Model | From Hugging Face repository (pinned commit) | Download |
|---|---|---|
| MiniCPM5 2B ("Compact") | openbmb/MiniCPM5-2B-MLX (8a9ad753) |
about 1.4 GB |
| Gemma 4 E2B ("Standard") | mlx-community/gemma-4-E2B-it-qat-4bit (42f62737) |
about 4.4 GB |
| Gemma 4 E4B ("Large") | mlx-community/gemma-4-E4B-it-qat-4bit (0f35c6f6) |
about 6.8 GB |
If the device does not have enough free memory for the model it was offered first and its row lists a smaller model, Settings offers the smaller one as a separate download that you also agree to, by tapping the button that names it and its size. Settings shows the neutral names (Compact, Standard, Large) and sizes; the models' own names, publishers, licences and pinned versions are listed in Settings → Acknowledgements & Sources.
The downloaded files are the model's weights, its tokenizer and configuration files and a prompt-formatting template, pinned to one commit and checked against values built into the app — every file's size before each load, and its checksum the first time the downloaded files are seen — so files that do not match are not loaded: data the model reads, not executable code. Like any file download, the request gives Hugging Face your device's IP address and standard request headers (including a user-agent naming OmniDerm), and names the model repository, commit and files; Hugging Face handles it under its own terms. It carries no token or account, and nothing you typed, recorded or photographed. We do not receive that request.
To stop or remove it: turning Use an on-device model off withdraws your agreement, stops a download in progress and unloads the model; Remove the downloaded model deletes the files; Clear All Local Data and deleting the app also delete them.
Links you open. "Open the source" under a topic or in Acknowledgements & Sources, the Privacy Policy, Consumer Health Data Privacy Policy and Support links in Settings, and the privacy link on the Pro screen open that web page in your browser when you tap them (on a Mac, Manage Subscription opens Apple's subscriptions page). The site you visit sees that visit under its own terms. OmniDerm sends nothing with it.
The app's App Transport Security setting refuses unencrypted connections. There is no analytics endpoint, no crash-reporting SDK, no ad network and no remote "ask the cloud" fallback. If that ever changes, we will change this policy first and tell you in the app.
Ask
Ask answers general skin-care questions you type. It appears only on a device where something can answer: Apple Intelligence, or the model you downloaded in Settings.
- Where Apple Intelligence is on and ready (iPhone, iPad, Mac and Apple Vision Pro that support it), Apple's on-device language model answers. Your question stays on the device; it is not sent to us or to Apple.
- Where Apple Intelligence is not ready, Ask uses the model you downloaded, running on the device.
- Where neither can answer, Ask says it cannot answer and sends nothing anywhere. On Apple TV, where Apple Intelligence is not available and no model is offered, Ask does not appear. The Apple Watch app has no Ask.
What goes to the model is your question, up to the last six lines of the conversation on screen, a standing instruction, and matching passages from OmniDerm's built-in topics. Your journal, photographs and habit logs are never part of it. The answer is labelled with the model that wrote it and shown as written: OmniDerm removes only the downloaded model's hidden reasoning, and does not check, filter or rewrite the answer. It can be incomplete or wrong. Questions and answers are held in memory for the conversation on screen and are not saved.
Apple Health (HealthKit)
OmniDerm does not read Apple Health. The HealthKit entitlement, purpose string, and Settings toggle were removed: a previous toggle authorised a seven-day steps/sleep read whose only consumers were two log lines, and no screen rendered a correlation. If a Health integration returns, it returns with the screen that renders it, and this policy gains its row back in the same change.
iCloud, Handoff and your other devices
iCloud Sync
Off by default. The switch is Settings → iCloud Sync and Handoff. While it is off, OmniDerm writes nothing to iCloud and advertises nothing for Handoff. Remembering the identifier of a topic you open is a second allow, Remember topics I open, off until you allow it. The iCloud switch alone does not store that identifier. The app tells you inside the app and asks for your consent again before storing or syncing it. While the switch is on, it uses two parts of your own iCloud account, and Handoff (below):
1. A preference record in your private CloudKit database. When you switch sync on, and each time the app launches while it is on, OmniDerm reads this record and applies it. It writes the record only when you tap Sync Now. The record can hold only these five settings, each checked in code against a fixed set of values before it is written, so free text cannot ride along: appearance mode, whether reminders are on, the reminder hour, which tab the app opens on, and whether you have acknowledged the app's disclosure. Your Ask model choice is not synced.
2. iCloud key-value storage, for continuing where you left off. So that your Apple Watch, Apple TV and the Home Screen widget can offer to continue, OmniDerm stores, while the switch is on: the tab you were on; your appearance choice; the next suggested topic for the widget (its identifier, its title and a fixed line of the app's own); and a topic you tapped in the widget until the app opens it. The widget's suggested next topic follows the iCloud switch alone, before remembering is allowed, and it is not the list of topics you opened. The identifier of the topic held for continuing, and the list of topics you have opened, go only after you also allow remembering. The topic held for continuing is the last topic you opened in Understand, by any route — browsing the library, Start here, a related topic, the Home Screen widget, your Apple Watch or Handoff. When remembering is allowed, each topic you open while the switch is on is added to that list, and when you turn the switch on the topic held for continuing at that moment can be added too, even if you opened it while the switch was off. Each topic identifier names its topic, and topics cover skin-care subjects, skin conditions, rare diseases (for example epidermolysis bullosa) and infections and infestations. They can also name sexually transmitted or sexual-contact conditions: for example, the pubic lice topic quotes its source as saying they usually spread through sexual contact. So this list is, in effect, your reading history in Understand while remembering was allowed and the switch was on, stored in your iCloud account, and it can show that you read about sexual health. Declining remembering, or switching Remember topics I open off, removes stored topic identifiers and the opened list. Reading a topic does not require the allow. Nothing is sent to Prameya.
What iCloud Sync never carries: journal entries and notes, journal photographs, habit logs, anything derived from your habit logs (streaks, consistency, trends), your goals, your Ask questions and answers, and any observation about your skin. No part of the app's local database is mirrored to iCloud. (If you use iCloud Backup, your device backup is a separate matter — see "Everything the app stores, and where".)
Who can read it: you. Both stores are in your own Apple Account. Prameya has no ability to read, list, or recover them — that is how Apple's private iCloud storage works, not a promise we are asking you to take on faith.
To stop it: switch iCloud Sync and Handoff off. That stops every write and Handoff, removes OmniDerm's key-value entries from iCloud straight away (on every device, because the store is shared) and deletes the preference record from CloudKit; Clear All Local Data does the same. If the app cannot reach iCloud at that moment (for example, with no network), the record stays: the status line under Sync Now says so, and Clear All Local Data says so in its result. Switching sync on and off again, or Clear All, tries again, and you can also delete OmniDerm's iCloud data in Settings → your name → iCloud → Manage Account Storage (on a Mac, System Settings → your name → iCloud → Manage). Deleting the app does not by itself remove anything from iCloud.
With sync off, the widget shows the first suggested topic, Apple TV has nothing to continue, and your other devices are not offered Handoff. Declining remembering, or switching Remember topics I open off, removes stored topic identifiers and the opened list. Reading a topic does not require that allow. The Apple Watch's Read this topic card sends the identifier only when remembering is allowed; it goes over the connection between your iPhone and Watch.
Handoff
Only while iCloud Sync and Handoff is on and OmniDerm is open, iOS advertises it for Handoff so your other devices signed in to the same Apple Account can offer to continue. The Handoff record names the tab you are on. The same topic is named only when you have allowed remembering (described under "iCloud Sync" above). With the switch off, OmniDerm advertises nothing for Handoff. Handoff is Apple's service; the record is not public and is not indexed for search. You can also turn Handoff off for every app in iOS Settings → General → AirPlay & Continuity (on a Mac, in System Settings → General → AirDrop & Handoff).
Apple Watch
The Apple Watch app shows the built-in topics, and cards the iPhone sends it over Apple's connection between the two devices. It stores none of your journal, photographs or habit logs.
- Applied today's care — tapping Confirm logs today's morning sunscreen and barrier care on your iPhone (added to anything already logged today, marked as logged from the Watch). Photo reminder opens journal capture on the iPhone; Read this topic makes the iPhone send the Watch the identifier of the topic held for continuing only when you have allowed remembering, and the Watch opens it. Snooze and Not now record nothing.
- While reminders are on, the iPhone also sends the Watch your reminder hour, and the OmniDerm complication shows it on your watch face (for example "8:00"). The Watch keeps the hour in storage that only the OmniDerm Watch app and its complication share. While reminders are off, which is how they start, the iPhone sends no hour and tells the Watch to remove the one it kept, and the complication shows "Learn"; switching reminders off and Clear All Local Data do this too. watchOS hands each change to the Watch when it arrives, waking the OmniDerm Watch app briefly in the background if it is closed, so the watch face follows without you opening the app.
- The Watch reads the iCloud key-value storage described above, when sync is on, to match your appearance and, when remembering is allowed, to offer the topic held for continuing.
Apple TV, Mac, Apple Vision Pro and the widget
- Apple TV shows the built-in topic library, a Continue tab that reads iCloud key-value storage (so it has something to continue only when iCloud Sync is on in OmniDerm on another of your devices and you have allowed remembering), and an About tab with the app's notice, the short version of this policy and the addresses of the policies and terms, as text built into the app. Apple TV opens on the Continue tab. The topic held for continuing is shown there only after you have allowed remembering. It keeps no journal and offers no Ask and no model download.
- Mac and Apple Vision Pro run the same app as iPhone and iPad, with the same journal, the same iCloud Sync and Handoff switch and the same Ask; on those devices everything in this policy about "this device" applies to them.
- The Home Screen widget (listed as "Journal" in the widget gallery) shows the title of a suggested topic, one of the ten Start here topics, read from iCloud key-value storage; with sync off it shows the first topic. That suggested next topic can still go with iCloud Sync before remembering is allowed, and it is not the list of topics you opened. With sync on, once you have opened all ten it shows the words "Private journal" instead, and if the app cannot load its topics the widget says so. The medium size adds a fixed line of the app's own, "It does not name the thing." It cannot read your journal and never shows an entry, a photograph or a habit log.
Notifications
Reminders start off. The only thing in OmniDerm that asks iOS for notification permission is switching on Settings → Reminders (daily SPF/habit nudges); opening Settings does not. When reminders are on, OmniDerm schedules local notifications on your own device: one daily reminder at the hour you choose (8:00 by default) to log your morning sunscreen and barrier care, and, only if you start it, a one-off two-hour sunscreen reapply timer. There is no push server, and no notification is triggered by us. The reminder's text appears wherever your notification settings show it, such as the lock screen. Tapping it opens Do; it does not log anything. Turn reminders off in the app, or in the Settings app (on a Mac, System Settings → Notifications). If notifications are off for OmniDerm there, the Reminders switch says so and, on iPhone, iPad and Apple Vision Pro, offers Open Settings.
Things we do not do
One line each, because that is all they need.
- No accounts. No sign-up, no email, no password, no Sign in with Apple.
- No advertising. No ad SDK, no ad network, no sponsored content.
- No analytics. No usage tracking, no event logging, no session recording, no third-party analytics SDK of any kind.
- No tracking across apps or websites. The app declares no tracking and no tracking domains, and does not use the advertising identifier. Its privacy manifests declare no collected data types at all.
- No selling or sharing your data. Not to advertisers, not to data brokers, not to anyone, for money or for anything else.
- No location. OmniDerm does not request or use your location, precise or approximate, and removes location metadata from journal photographs. It uses no geofences.
- No camera, contacts, microphone, or health records.
- No background activity of its own. The app declares no background modes and schedules no background tasks. Apart from delivering local reminders you switched on, the widgets showing a suggested topic or, on your watch face, your reminder hour, your Apple Watch briefly taking in a reminder change your iPhone sent, and your iPhone briefly handling a card you tap in the Apple Watch app, it does nothing when you are not using it. A model download runs only while the app is open.
- No profiling and no automated decisions about you in the legal sense — the app makes no decision that produces legal or similarly significant effects.
What Apple may see
Apple runs the App Store, iCloud and the operating systems, and a few things flow to Apple rather than to us:
- Crash and performance reports. If you have turned on "Share with App Developers" in iOS Settings → Privacy & Security → Analytics & Improvements, Apple may give us aggregated crash and performance data through App Store Connect. This contains technical information about the crash. It does not contain your photos, your habit logs, or your health data. You can turn it off in iOS Settings.
- App Store transactions. Any download or purchase happens through Apple. We never see your name, payment details, or Apple Account.
- iCloud, Handoff, device backups and the Watch connection. What OmniDerm places there is described above; Apple stores or carries it for you under Apple's terms.
If you email us
If you write to admin@prameya.legal, we will have your email address and whatever you put in the message. We use it to answer you and we do not add you to any list. Our practice is to delete support threads once they are resolved — that is a commitment about how we work, not something you can verify from the app, so we state it as our intent rather than as a technical guarantee. Please do not send us photos of your skin — we do not want them and we have no secure place to put them.
Security
- Data the app stores stays in the app's own sandbox on your device, protected by the operating system.
- On iPhone, iPad and Apple Vision Pro, OmniDerm declares
NSFileProtectionComplete(com.apple.developer.default-data-protection), so journal photographs, notes, body areas and habit logs are unreadable while your device is locked. An export you prepare is written with the next level down, readable after first unlock, so the share sheet can finish after the screen locks, and is cleared afterwards. On a Mac, the files are protected by macOS and by FileVault if you use it. - All network traffic is HTTPS. The app refuses to make unencrypted connections.
- Downloaded model files are checked against sizes and checksums built into the app, and files that do not match are not loaded.
- Your device passcode, Face ID, Touch ID or Optic ID is the main protection for everything on your device, including this app's data. Please use one.
No system is perfect, and we will not pretend otherwise. What we can say plainly is that we hold nothing of yours on a server, so a breach of Prameya cannot expose your skin photos or your health data.
If something does go wrong. If we ever learn of a security breach involving health-related information from this app, we will notify affected users and the regulators we are required to notify — including under the FTC's Health Breach Notification Rule and applicable state breach laws — as promptly as the law requires.
Retention and deletion
We do not retain your data, because we never receive it. On your device:
- Delete individual entries: open a journal entry from the timeline (or hold the row) to delete it or just its photograph, and open a logged day under Do → Today's log → Days you have logged to delete that day with Delete this logged day. Each list draws your 365 most recent records at a time and offers Show older entries / Show older days at its foot, so an older record is a page away rather than out of reach. On the free plan, journal entries older than 30 days are listed under Older entries below the timeline, where each one opens to be corrected or deleted, and logged days older than 90 days are listed by date under Older days below the list of logged days, where each one opens to Delete this logged day.
- Delete a single journal photograph: open that journal entry and use Delete the photograph — the date, body area and note are kept. Deleting the entry deletes its photograph too, and Clear All Local Data deletes them all. Journal photographs are excluded from device backup and are never uploaded, so each of those deletes removes the only copy that exists. Originals in Apple Photos are yours — delete them there if you want them gone.
- Delete your habit logs, journal entries, photographs, goals, and reminder and appearance settings: open Settings → Export & Data Management → Clear All Local Data. It deletes your journal entries and photographs, habit logs, goals, reminder and appearance settings and pending reminders, the downloaded Ask model and your answer to its download, tells your Apple Watch to remove the reminder hour it kept, switches iCloud Sync and Handoff off, removes OmniDerm's iCloud key-value entries and deletes the CloudKit preference record. It does not remove your purchases or the record that you acknowledged the app's first-run notice. If a later file removal fails after the store is emptied, or the preference record could not be removed from iCloud, the app says so rather than claiming a complete delete.
- Delete the Ask model only: Settings → On-device Ask model → Remove the downloaded model.
- Delete everything on the device: delete the app. That removes the app's database, preferences, journal JPEGs and downloaded model files. It does not remove what is in iCloud or in a device backup you already made.
- Delete synced data: switch iCloud Sync and Handoff off. That removes the key-value entries and the preference record; if the app could not reach iCloud, remove the app's iCloud data in Settings (on a Mac, System Settings) as described above.
- Take your data with you first: Settings → Export my record produces your habit logs, journal entries (date, body area, note and lighting note), your consistency snapshot and your goals, and presents the share sheet. If you have saved journal photographs the export is a
.zipholding that file plus every photograph still on this device, in aPhotographsfolder; with no photographs saved it is a plain JSON file. The export screen names how many photographs are included before you share. With Pro, Export appointment pack produces a plain-text summary of the same dates, body areas, notes, habit marks and goals, without photographs. Exporting is the only route by which a copy of a journal photograph ever leaves the device — read what the file contains before you send it anywhere.
Health privacy law: what applies and what does not
HIPAA does not apply
OmniDerm is not covered by HIPAA. HIPAA applies to health plans, health care clearinghouses, most health care providers, and their business associates. Prameya is none of those, we have no relationship with your doctor or your insurer, and we are not acting on any provider's behalf. We are telling you this because "HIPAA compliant" is a phrase consumer apps throw around loosely. We are not making that claim.
This does not leave you without protection. Other laws apply — see below — and, more to the point, the app is built so there is nothing on our side to protect.
Washington and Nevada: consumer health data
Washington's My Health My Data Act (RCW ch. 19.373) and Nevada's SB 370 (2023) both regulate "consumer health data" much more broadly than Apple's App Store definitions do. Washington's definition of "collect" reaches data that is merely accessed, processed, inferred or derived — including entirely on a device. So the fact that nothing is transmitted to us does not end the analysis, and we do not argue that it does.
Because OmniDerm processes consumer health data, Washington law requires a separate consumer health data privacy policy. We have one:
It sets out the categories of consumer health data involved, where they come from, what they are used for, who they are shared with (no one), and how to exercise your rights, including the right to withdraw consent and the right to delete.
California (CCPA/CPRA)
California residents have rights to know, delete, correct, and opt out of the sale or sharing of personal information, and to limit the use of sensitive personal information — a category that includes health information.
Our answers, honestly:
- We do not collect personal information about you. No account, no identifiers, no server logs of your activity.
- We do not sell or share personal information as those terms are defined in the CCPA, and we have not in the preceding 12 months. Apple (StoreKit, iCloud, Handoff) and Hugging Face (the optional model download) are not cross-context behavioural advertising.
- We do not use sensitive personal information for any purpose you could need to limit, because we do not receive it.
- We do not discriminate against anyone for exercising a privacy right. There is nothing to withhold — the app is the same for everyone.
- To exercise a right: email admin@prameya.legal. We will respond within 45 days. In most cases our honest answer will be that we hold no personal information about you, and we will tell you exactly how to delete the data on your own device and in your own iCloud (see "Retention and deletion" above).
- Authorized agents may submit requests on your behalf with written proof of authorization.
Other US states
Several other states (Colorado, Connecticut, Virginia, Texas, Oregon, Montana and others) give residents similar rights of access, correction, deletion, portability, and opt-out of targeted advertising, profiling and sale. We do not target advertising, do not profile, and do not sell. The same route applies: email admin@prameya.legal.
Europe and the UK
We have not written this section around any assumption about which countries the App Store makes OmniDerm available in. Wherever it is available to you, this applies.
If OmniDerm is available where you are in the EEA, UK or Switzerland:
- Information about your skin and your health is special category data under Article 9 of the GDPR and the UK GDPR. Your journal, photographs and habit logs are processed only on your own device (and in any device backup you make), at your initiative, under your explicit choice to use the feature. If you turn on iCloud Sync and Handoff, app settings go to your own iCloud account by Apple, and Handoff can pass the tab you are on to your own devices through Apple. The identifier of a topic you open is stored there, and Handoff names that topic, only after you allow remembering. Prameya does not receive any of it and does not process it.
- Prameya is not in a position to access, export, or erase device-resident or iCloud data — you control it directly, and the deletion steps above are complete and immediate.
- For the little we might ever hold — an email you choose to send us — the legal basis is our legitimate interest in answering you, and you may ask us to delete it.
- You have rights of access, rectification, erasure, restriction, portability and objection, and the right to complain to your national data protection authority.
- If you choose to download the optional Ask model, that download is a connection from your device to Hugging Face, which may be outside your country. It carries your IP address and the names of the files requested, and nothing you typed, recorded or photographed. We do not receive it.
Children
OmniDerm is not directed to children. It is written for adults managing their own skin-care habits, it has no ads, no accounts, no social features and no chat with other people. It does offer one paid upgrade, OmniDerm Pro (monthly, annual or lifetime), described above. We do not knowingly collect personal information from anyone, including anyone under 13, and there is no mechanism by which a child could send us information — we have no server.
Under the Children's Online Privacy Protection Act (COPPA), an operator's obligations attach to collecting personal information online from children under 13. We collect none, from anyone.
If you are a parent or guardian and believe a child has somehow sent us information, email admin@prameya.legal and we will delete it.
Limitations you should know about
This is a privacy policy, but three facts about the app affect the choices you make with your own health data, so they belong here.
AI models perform differently across skin tones. Published, peer-reviewed research (Daneshjou et al., Science Advances, 2022) found that every dermatology AI model evaluated performed worse on darker skin tones and on less common conditions. This is one of the reasons the photo feature is switched off. The shipping app offers no image model and never looks at anyone's skin, of any tone. If a photo feature is ever cleared and enabled, this caveat becomes directly relevant and we will say so here first.
Smartphone skin apps have a poor track record. A systematic review in the BMJ (Freeman et al., 2020) concluded that current algorithm-based smartphone apps cannot be relied on to detect all cases of melanoma. That is a large part of why the assessment feature in OmniDerm is switched off.
Ask is a general-purpose language model. Its answers are shown as the model writes them, are not reviewed by a clinician, and can be incomplete or wrong. Do not use them to decide anything about your own skin.
Nothing in this app is screening. Marking that you looked at the same area is a record of what you did. It is not a self-check or a screening result, and it does not mean anything was checked properly. See a clinician.
Changes to this policy
If we change how OmniDerm handles your data, we will update this policy and change the effective date at the top. For any change that materially affects your privacy — a new network connection, a new category of data, a change to what syncs — we will:
- post the updated policy here before the change ships, and
- tell you inside the app, and
- ask for your consent again where the law requires it, including a fresh consent for any new collection or sharing of consumer health data under Washington's My Health My Data Act.
8 October 2026 — what changed. Remembering the identifier of a topic you open is a separate allow, off until you allow it. The app tells you inside the app and asks for your consent again before that identifier is stored or synced. Declining stops that storage and that sync. Reading a topic does not require the allow. The widget's suggested next topic can still go with iCloud Sync before the allow, and it is not the list of topics you opened. The short version, the storage table, "iCloud Sync", Handoff, Apple Watch and Apple TV now say this. On 7 October 2026 the Watch's Read this topic card sent the identifier whether or not iCloud Sync was on; it now sends that identifier only when remembering is allowed.
7 October 2026 — what changed. The app's topic library grew and some of its words changed. This page had not caught up, and it now follows the app:
- Topics you open. The built-in library added topics on rare skin diseases and a group on infections and infestations. One of them is pubic lice, which its source says usually spread through sexual contact. Like every topic, each of these can become the topic held for continuing and, while iCloud Sync and Handoff is on, join the list of topics you opened in your iCloud. So "iCloud Sync" now says what the identifiers can name, and that the list can show that you read about sexual health. What is stored, when, and where it goes are unchanged, and none of it reaches us. The app does not ask for a new consent for these topics. "Apple TV" now says that it opens on its Continue tab, and the storage table now names the Apple Watch's Read this topic card, which "iCloud Sync" already described.
- The list of topics you opened. "iCloud Sync" and the storage table now say that when you turn the switch on, the topic held for continuing at that moment can join the list, even if you opened it while the switch was off. This page said the list held only topics opened while the switch was on.
- The widget. It is listed as "Journal" in the widget gallery. It still shows a suggested Start here topic, or, with sync on, the words "Private journal" once you have opened all ten, and cannot read your journal; this page now says so. The line stored for the widget beside the topic's title is a fixed line of the app's own, not a summary of the topic.
- Habit logs. The fourth habit mark is "Looked at the same area today", as the app labels it. This page called it a self-check.
- What OmniDerm is. The ABCDE topic is withheld while the clearance gate is closed, so this page no longer says you can learn the ABCDE ideas in the app. It now lists what the topics cover.
- Understand. The tab where you read topics is called Understand in the app, and this page now uses that name. The Apple Watch app's tab, and the watch-face complication's word, are still "Learn". Earlier entries below keep the name they used.
The short version is unchanged. Nothing is sent to Prameya.
Later on 27 September 2026 — what changed. The revision earlier the same day said iCloud Sync and Handoff carried the same things as before. It did not describe a change the app had made that morning, and it gave iPhone paths where a Mac has its own. This revision corrects that:
- Topics you open. Every topic you open in Learn, by any route, now becomes the topic held for continuing, and while iCloud Sync and Handoff is on it is written to your iCloud key-value storage and added to the list of topics you have opened. Before, only a topic opened from the Home Screen widget or continued from another device was; this page said a topic opened by browsing Learn was not recorded. With the switch off, nothing is written to iCloud and nothing is offered for Handoff, as before. The Apple Watch's Read this topic card, which does not depend on the switch, now opens the last topic you opened in Learn.
- The photo self-check was removed. On 26 September 2026 the photo self-check, which was already switched off behind the FDA clearance gate, was taken out of the app. This page said the gate was enforced at a button and a screen; there is no longer a button or a screen.
- Mac paths. On a Mac you cancel in the App Store app → your name → Account Settings → Subscriptions → Manage, remove OmniDerm's iCloud data in System Settings → your name → iCloud → Manage, and turn notifications off in System Settings → Notifications. Journal photographs on a Mac are protected by macOS and FileVault, not by iOS file protection.
- Apple TV has an About tab with the app's notice, the short version of this policy and the addresses of the policies and terms.
- When to see a doctor. This page said the app does not tell you whether to see a doctor. Its free education topics do list general warning signs that call for a dermatologist; what stays true is that nothing about your own photographs or notes tells you that.
The short version is unchanged. Nothing is sent to Prameya.
27 September 2026 — what changed. One change in the app, and this page follows it:
- The reminder hour on your Apple Watch. The Watch complication was meant to show your reminder hour, but it never could: the Watch app and the complication kept separate storage, so the watch face always read "Learn". They now share storage that only the two of them can read, so the complication shows the hour. The iPhone now sends the hour only while reminders are on; before, it sent the hour even with reminders off, which is how they start. With reminders off, and after Clear All Local Data, the iPhone tells the Watch to remove the hour it kept. watchOS hands the Watch each change even when the OmniDerm Watch app is closed, waking it briefly in the background. The "Apple Watch" section, the storage table and "No background activity of its own" say this.
Nothing else changed: the same data stays on your device, the hour reaches your Watch only over the connection between your iPhone and Watch and never reaches us, and iCloud Sync and Handoff carries the same things, only while you have it on.
24 September 2026 — what changed. One change in the app, and this page follows it:
- Older logged days on the free plan. Logged habit days older than 90 days are now listed by date under Older days, below Days you have logged, and each one opens to Delete this logged day. What you marked on those days is still shown only with Pro. So the limit this page described on 23 September — that on the free plan a habit day older than 90 days could not be opened or deleted on its own, only removed with Clear All Local Data — no longer applies, and that sentence is gone.
Nothing else changed: the same data stays on your device, and iCloud Sync and Handoff carries the same things, only while you have it on.
23 September 2026 — what changed. This page was out of date with the app, and it now describes what OmniDerm actually does:
- Ask. It describes Ask, which answers typed questions on the device with Apple Intelligence or with a model you choose to download, and shows the answer as the model writes it. The earlier page did not mention Ask.
- The model download. It says the app now offers an optional on-device model download from Hugging Face, in Settings, only after you agree on a consent sheet, over Wi-Fi, and names each model, its size and which devices are offered it. The earlier page said the app downloads no model and that Hugging Face is never contacted.
- iCloud. It says iCloud Sync also stores, in your own iCloud key-value storage, the topic held for continuing, the next suggested topic and a list of topics opened from the widget or continued from another device, so your Watch, Apple TV and widget can continue; that switching sync off or Clear All removes those entries; and that the preference record is written only when you tap Sync Now. The earlier page said only seven settings sync.
- Handoff. It says Handoff tells your other devices which tab and topic you are on.
- Privacy fixes in the app, the same day. The switch is now called iCloud Sync and Handoff, and Handoff follows it: with the switch off, OmniDerm no longer offers your tab and topic to your other devices. Switching it off, or Clear All Local Data, now also deletes the preference record from your iCloud, so you no longer have to remove it in iOS Settings. Clear All now also removes your appearance setting, and forgets the topic it was holding so that switching sync back on cannot send it again. The preference record now holds five settings: two fields that carried no choice of yours (an old model identifier and whether citations start expanded) were removed. The app no longer contains an unused Keychain component.
- Backups. It says your device backup includes journal notes, body areas, habit logs and preferences, and excludes journal photographs and the model.
- Devices. It covers the Apple Watch, Apple TV, Mac and Apple Vision Pro apps and the widgets. The earlier page covered "the iOS app only".
- Corrections. It no longer says the app keeps small flags in the Keychain (it keeps none), or that the app stores your purchase transaction and Clear All deletes it (StoreKit holds purchases, and Clear All does not touch them). It says journal photographs are re-encoded with their location and other metadata removed, and it names Export my record, the Pro appointment pack, the free Older entries list and the free plan's 90-day list of logged days.
Nothing is sent to Prameya, and no data is sold or shared for advertising, as before.
What changed on 24 August 2026. Export began carrying the journal photographs themselves, and per-entry, per-photograph and per-day deletion was named. Parts of that version are superseded above.
What changed on 21 August 2026. Journal photographs you save are stored on this device (they always were; the previous page said the app touched none). HealthKit is not used. Reminders start off. File protection is NSFileProtectionComplete. The photo self-check remains gated off. That version's statement that Settings offers no model download is superseded above.
What changed on 8 August 2026. An earlier revision corrected internal review notes, gated the photo-assessment feature, and named the model-download host. Some of those sentences were already stale by 21 August and are superseded above.
We will keep previous versions available at https://prameyallc.github.io/privacy/ so you can see what changed.
Contact
Questions, requests, complaints, or corrections:
Prameya LLC — admin@prameya.legal
If you are exercising a privacy right, please say which state or country you are in, so we can apply the right rules. We will not ask you to create an account to make a request.
Consumer Health Data Privacy Policy
OmniDerm processes consumer health data. Washington State law requires a separate policy for that data, published at its own address:
Terms of Use
The terms governing OmniDerm, including subscription auto-renewal and cancellation, and dispute resolution: