Prameya Privacy

OmniDerm Privacy Policy

Effective date: 8 August 2026
Publisher: Prameya LLC ("Prameya", "we", "us"), a United States limited liability company
Contact: admin@prameya.legal
This policy covers: the OmniDerm iOS app only.

Related pages


The short version


Who we are

OmniDerm is published by Prameya LLC, a US limited liability company. You can reach a human at admin@prameya.legal. We do not have a phone line.

What OmniDerm is

OmniDerm is a consumer app for skin-care habits and education. It helps you:

What OmniDerm will not do

OmniDerm is not a medical device and does not diagnose, screen for, or detect skin cancer or any other condition. It does not tell you whether a mole is dangerous. It does not tell you whether to see a doctor.

Features that would produce an assessment of a photograph of your skin are behind a clearance gate that is switched off. In the version of OmniDerm on the App Store, the app does not produce observations, flags, ratings, or any other output about a photo of your skin. The gate is enforced in three places — the button that would open the feature, the screen behind it, and the type that carries the result — and the shipping app does not even include the vision model such a feature would need. That gate stays off unless and until the feature has the regulatory clearance it would need.

In practice this means the photo screen cannot be opened in the shipping app. Where the Learn section would offer it, you see an explanation of why it is switched off instead.

If you notice a new spot, a changing spot, or anything that worries you, see a licensed clinician. Do not use this app to decide not to.


Your skin photos

This is the most sensitive thing OmniDerm could touch, so it gets its own section.

In the shipping app, it touches none. Because the clearance gate is closed, there is no screen from which you can hand OmniDerm a photo. The app does not open your photo library, does not read an image, and does not analyse one.

If the gate were ever opened, this is how the feature is built, and this is what we would be bound by:

Question Answer
Where would a photo come from? Only from you, through Apple's standard photo picker, one image at a time. The picker hands the app only the image you chose; the app cannot browse, index or read the rest of your library.
Is the photo uploaded to Prameya? No. We have no server that could receive it.
Is the photo sent to any AI company or cloud model? No. Any processing happens on your phone.
Is the photo saved into the app's own storage? No. No code path writes an image to a file, a database, the Keychain, or iCloud.
Is the photo synced to iCloud by OmniDerm? No. Photos are on the explicit list of things that are never synced.
Is the photo backed up as part of the app's data? No, because the app does not store it.
How long would the app keep it? Only while the screen is open. It is held in the phone's working memory and released when you leave the screen or close the app.

The app does not ask for camera access. There is no camera permission request in OmniDerm and no photo-capture code in it.

How to remove a photo from OmniDerm. There is nothing to remove — the app never made a copy. If you want an original gone, delete it in Apple's Photos app; that is your photo library, which OmniDerm does not control.

One honest caveat. Your own iPhone backup and your own iCloud Photos settings are Apple's, not ours. If your photo library syncs to iCloud, your skin photos are in your iCloud like every other photo you take. That is a setting in iOS, and you control it.


Everything the app stores, and where

What Where it lives Leaves your device?
Habit logs (date, and whether you did morning SPF, reapplied, barrier care, a self-check) On your device, in the app's local database No
Your goals list, reminder setting On your device, in app preferences No
Which AI model you chose, and which models are downloaded On your device, in app preferences No
Downloaded AI model files On your device, in app storage No (they came to the device)
Small security flags and keys Your device Keychain, set to this-device-only No
Skin photos Nothing is stored: the photo screen is gated off, so no image is read at all No
Diagnostic log messages Apple's on-device system log No
Preferences and screen state, if you switch iCloud sync on Your own private iCloud, in your Apple Account Yes — to your iCloud, not to us

We do not build a profile of you. We could not: we receive nothing.


The one outside connection: AI model downloads

OmniDerm's AI runs on your phone. To do that, it first has to get the model files. When you choose to use the on-device AI, the app downloads model weights over HTTPS from Hugging Face (huggingface.co), a third-party model host.

What that request contains: the name of the model file the app wants. In the shipping app there is exactly one model in the catalogue — a text model of roughly 420 MB. Like any internet request, it also reveals your device's IP address and standard network information to Hugging Face.

What that request does not contain: your photos, your habit logs, your Apple Health data, your notes, your goals, your identity, or anything else about you. It is a file download, not an upload.

There is no vision model to download. The larger image model that a photo feature would need is not in the shipping catalogue at all; it is compiled out until and unless the feature is cleared.

What we do not do before that download, so you are not surprised by it. Settings names the model and shows its approximate download size before anything happens, and the download only starts when you tap the download button. Beyond that there is no confirmation step: OmniDerm does not warn you about download size thresholds and does not check whether you are on cellular data or Wi-Fi. If you are on a metered connection, the download will use it. If that matters to you, start it on Wi-Fi.

After the files are on your phone, everything the model does happens locally. Nothing you feed the model is transmitted anywhere.

Hugging Face is an independent company with its own privacy practices. We do not send them anything about you, but the connection itself is theirs to log, as with any website you visit.

The app is configured to refuse non-HTTPS connections entirely.

This is the only non-Apple server OmniDerm talks to. There is no analytics endpoint, no crash-reporting SDK, no ad network, no remote "ask the cloud" fallback for hard cases. If that ever changes, we will change this policy first and tell you in the app.


Apple Health (HealthKit)

Off by default. OmniDerm asks for Apple Health only if you turn the toggle on in Settings, and iOS then asks you separately.

If you allow it, OmniDerm reads three things from the last seven days:

It uses them on your device to show how your activity and sleep line up with your logged habits. That is all.

iCloud sync

Off by default. If you turn on sync in Settings, OmniDerm can copy a small amount of data into your own private iCloud database, inside your own Apple Account.

What syncs: seven settings, and nothing else. Appearance mode, whether reminders are on, the reminder hour, which tab the app opens on, which AI model you selected, whether you have acknowledged the app's disclosure, and whether citations are expanded by default. That list is enforced in code, not just described here, and each field only accepts a fixed set of values, so free text cannot ride along.

What never syncs: photos. Habit logs. Anything derived from your habit logs, including streaks, consistency scores, goals, and any observation about your skin. Anything from Apple Health. Those are on an explicit deny list, and no part of the app's local database is mirrored to iCloud.

Who can read it: you. Records go to the private database in your Apple Account. Prameya has no ability to read, list, or recover them — that is how Apple's private databases work, not a promise we are asking you to take on faith.

To stop it: switch the toggle off. To remove what is already there, sign out of iCloud for the app or delete the app's iCloud data in iOS Settings → your name → iCloud → Manage Account Storage.

Notifications

Reminders start on. The reminder setting in the app is on when you first open it, and iOS still asks you separately before the app can show you anything. When reminders are on, they are local notifications scheduled by your own phone. There is no push server, and no notification is triggered by us. Turn them off in the app or in iOS Settings.


Things we do not do

One line each, because that is all they need.

What Apple may see

Apple runs the App Store and iOS, and a few things flow to Apple rather than to us:

If you email us

If you write to admin@prameya.legal, we will have your email address and whatever you put in the message. We use it to answer you and we do not add you to any list. Our practice is to delete support threads once they are resolved — that is a commitment about how we work, not something you can verify from the app, so we state it as our intent rather than as a technical guarantee. Please do not send us photos of your skin — we do not want them and we have no secure place to put them.


Security

No system is perfect, and we will not pretend otherwise. What we can say plainly is that we hold nothing of yours on a server, so a breach of Prameya cannot expose your skin photos or your health data.

If something does go wrong. If we ever learn of a security breach involving health-related information from this app, we will notify affected users and the regulators we are required to notify — including under the FTC's Health Breach Notification Rule and applicable state breach laws — as promptly as the law requires.

Retention and deletion

We do not retain your data, because we never receive it. On your device:


Health privacy law: what applies and what does not

HIPAA does not apply

OmniDerm is not covered by HIPAA. HIPAA applies to health plans, health care clearinghouses, most health care providers, and their business associates. Prameya is none of those, we have no relationship with your doctor or your insurer, and we are not acting on any provider's behalf. We are telling you this because "HIPAA compliant" is a phrase consumer apps throw around loosely. We are not making that claim.

This does not leave you without protection. Other laws apply — see below — and, more to the point, the app is built so there is nothing on our side to protect.

Washington and Nevada: consumer health data

Washington's My Health My Data Act (RCW ch. 19.373) and Nevada's SB 370 (2023) both regulate "consumer health data" much more broadly than Apple's App Store definitions do. Washington's definition of "collect" reaches data that is merely accessed, processed, inferred or derived — including entirely on a device. So the fact that nothing is transmitted to us does not end the analysis, and we do not argue that it does.

Because OmniDerm processes consumer health data, Washington law requires a separate consumer health data privacy policy. We have one:

Consumer Health Data Privacy Policy for OmniDerm

It sets out the categories of consumer health data involved, where they come from, what they are used for, who they are shared with (no one), and how to exercise your rights, including the right to withdraw consent and the right to delete.

California (CCPA/CPRA)

California residents have rights to know, delete, correct, and opt out of the sale or sharing of personal information, and to limit the use of sensitive personal information — a category that includes health information.

Our answers, honestly:

Other US states

Several other states (Colorado, Connecticut, Virginia, Texas, Oregon, Montana and others) give residents similar rights of access, correction, deletion, portability, and opt-out of targeted advertising, profiling and sale. We do not target advertising, do not profile, and do not sell. The same route applies: email admin@prameya.legal.

Europe and the UK

We have not written this section around any assumption about which countries the App Store makes OmniDerm available in. Wherever it is available to you, this applies.

If OmniDerm is available where you are in the EEA, UK or Switzerland:

Children

OmniDerm is not directed to children. It is written for adults managing their own skin-care habits, it has no ads, no accounts, no social features, no chat with other people, and no in-app purchases. We do not knowingly collect personal information from anyone, including anyone under 13, and there is no mechanism by which a child could send us information — we have no server.

Under the Children's Online Privacy Protection Act (COPPA), an operator's obligations attach to collecting personal information online from children under 13. We collect none, from anyone.

If you are a parent or guardian and believe a child has somehow sent us information, email admin@prameya.legal and we will delete it.


Limitations you should know about

This is a privacy policy, but two facts about the app affect the choices you make with your own health data, so they belong here.

AI models perform differently across skin tones. Published, peer-reviewed research (Daneshjou et al., Science Advances, 2022) found that every dermatology AI model evaluated performed worse on darker skin tones and on less common conditions. This is one of the reasons the photo feature is switched off. The shipping app contains no image model and says nothing about anyone's skin, of any tone. If a photo feature is ever cleared and enabled, this caveat becomes directly relevant and we will say so here first.

Smartphone skin apps have a poor track record. A systematic review in the BMJ (Freeman et al., 2020) concluded that current algorithm-based smartphone apps cannot be relied on to detect all cases of melanoma. That is a large part of why the assessment feature in OmniDerm is switched off.

Nothing in this app is screening. Logging a self-check is a record of what you did. It is not a screening result and it does not mean anything was checked properly. See a clinician.


Changes to this policy

If we change how OmniDerm handles your data, we will update this policy and change the effective date at the top. For any change that materially affects your privacy — a new network connection, a new category of data, a change to what syncs — we will:

What changed on 8 August 2026. This revision corrected the policy against the code that actually ships. Statements that the app's behaviour did not support were rewritten or removed rather than left standing: internal review notes that had been published by mistake were taken out, the photo section now says the feature is gated off rather than describing it as if it ran, the model download section names the one model that ships and states that there is no download-size or cellular-data prompt, and the security section no longer implies file protection the app does not enable. Where the code now does what the policy said, we say so plainly. Nothing here describes a capability the shipping app does not have.

We will keep previous versions available at https://prameyallc.github.io/privacy/ so you can see what changed.

Contact

Questions, requests, complaints, or corrections:

Prameya LLCadmin@prameya.legal

If you are exercising a privacy right, please say which state or country you are in, so we can apply the right rules. We will not ask you to create an account to make a request.

Consumer Health Data Privacy Policy

OmniDerm processes consumer health data. Washington State law requires a separate policy for that data, published at its own address:

OmniDerm Consumer Health Data Privacy Policy