Prameya Privacy

Consumer Health Data Privacy Policy — OmniDerm

Effective date: 8 August 2026
Publisher: Prameya LLC ("Prameya", "we", "us"), a United States limited liability company
Contact: admin@prameya.legal
Applies to: the OmniDerm iOS app

This is a separate policy, required by the Washington My Health My Data Act (RCW ch. 19.373) and provided to meet the parallel duty under Nevada SB 370 (2023). It sits alongside, and does not replace, the OmniDerm Privacy Policy. Where the two overlap, both are true; this one goes into more detail about health information specifically.

It applies to everyone who uses OmniDerm. Washington and Nevada residents have specific statutory rights, set out at the end.


The short version


Why this policy exists even though nothing leaves your device

Apple's App Store privacy labels define "collect" as transmitting data off the device. By that definition, OmniDerm collects almost nothing.

Washington's definition is much broader. Under RCW 19.373.010, "collect" means to buy, rent, access, retain, receive, acquire, infer, derive, or otherwise process consumer health data in any manner. That reaches data that is merely accessed on your device, and it would reach anything a model infers or derives from a photograph of your own skin.

So we do not use the Apple definition to argue our way out of Washington law, and we are not going to tell you that state health-privacy rules do not apply because nothing is uploaded. They apply. This policy is written to them.


1. Categories of consumer health data collected, and why

"Collected" below is used in Washington's broad sense — accessed, processed, inferred or derived — not "sent to Prameya". None of the following is transmitted to Prameya.

Category What it actually is Why the app processes it
Images of your skin A photo of a mole, a lesion, or an area of skin Not processed in the shipping app. The photo screen is behind a clearance gate that is switched off and cannot be opened, so the app does not read an image at all. If the gate were ever opened, the image would come only from Apple's photo picker, one image you chose, held in memory and never saved or uploaded.
Inferences derived from a skin image Any observation a model might produce about an image None. The shipping app produces no observations, flags or ratings about a photo, and does not contain the image model that would generate them.
Skin-care habit records Date, and whether you did morning sunscreen, reapplied, did barrier care, did a self-check To show your history, streak and consistency in the app
Derived habit measures Streak length, 30-day consistency percentage, a plain-language summary Computed on your device from your own habit records, to show you your own patterns
Health and fitness data from Apple Health Step count, sleep analysis, active energy — last 7 days only, read only, and only if you switch it on To show, on your device, how activity and sleep line up with your logged habits
Your stated goals Free text you type, such as "build daily SPF habit" To personalise the cards the app shows you
Bodily or health-adjacent status you type in Anything you choose to write into a goal or note Only what you choose to enter

Not collected, in any sense: your location (precise or approximate), biometric identifiers, genetic data, contacts, microphone or audio, camera input, clinical health records from any provider, prescriptions, diagnoses, insurance or payment information, gender-affirming or reproductive health information, or any identifier that would let anyone link this app's data to you by name.

The app does not use geofencing of any kind, and does not use a geofence around any health care facility.

2. Sources of the data

Source What comes from it
You Habit logs, goals, notes — everything you type or tap
Your photo library Nothing, in the shipping app: the photo screen cannot be opened, so no image is read. If the gate were ever opened, Apple's picker would hand the app only the one image you chose, and the app still could not browse or read the rest of your library.
Apple Health on your device, only with your separate permission Steps, sleep, active energy for the last 7 days, read only
The app itself, on your device Streaks, consistency and summaries computed from your own habit logs

There are no other sources. We do not buy data, rent data, receive data from data brokers, or obtain anything about you from advertising networks, social platforms, affiliates, or public records.

3. How the data is used

Nothing is used to train AI. The AI models in OmniDerm are downloaded already-trained and are never updated with your data.

4. Categories of consumer health data that are shared

None.

We share no consumer health data, of any category, with anyone. There is no category to list because the list is empty.

5. Categories of third parties and specific affiliates we share with

None. For completeness, since some third parties are involved in the app without receiving any health data:

Party Role Consumer health data they receive
Apple Distributes the app; provides iOS, on-device storage, Apple Health and, if you enable it, the private iCloud database inside your own Apple Account None from us. If you turn on iCloud sync, only non-health preferences go to your own private iCloud, which we cannot read.
Hugging Face Hosts the AI model files the app downloads to your phone None. The request is for a model file. It carries no photo, no habit log, no health data, no identifier of you.

What iCloud sync can carry, precisely. Sync is off unless you switch it on, and when it is on it is limited in code to seven settings: appearance mode, whether reminders are on, the reminder hour, the tab the app opens on, which AI model you selected, whether you have acknowledged the app's disclosure, and whether citations are expanded by default. Each of those accepts only a fixed set of values, so free text cannot travel with them. Habit logs, streaks, consistency scores, goals, photos and Apple Health data are on an explicit deny list, and none of the app's local database is mirrored to iCloud. Records go to the private database in your own Apple Account, which Prameya cannot read.

We have no affiliates. We use no processors, no analytics vendor, no cloud provider that touches your data, no advertising network, and no AI service provider. We do not disclose consumer health data to law enforcement or anyone else, because we do not have it — a demand made to Prameya for your health data cannot be satisfied.

6. Selling consumer health data

We do not sell consumer health data, and we will not.

Washington law requires a separate, signed authorization with specific contents before any sale of consumer health data. We have never asked anyone for one and do not intend to. If that ever changed, it would require your explicit, separate, written authorization, revocable at any time — not a buried checkbox and not a policy update.

How consent works in OmniDerm.

How to withdraw consent — all of these are immediate and do not require contacting us:

To withdraw Do this
Photo access Nothing is needed for this version, since the app does not read photos. If you want the permission closed off regardless: iOS Settings → Privacy & Security → Photos → OmniDerm → None.
Apple Health access Switch the toggle off in the app, or iOS Settings → Health → Data Access & Devices → OmniDerm → turn off.
iCloud sync Switch the sync toggle off in the app's Settings.
Reminders Switch reminders off in the app, or in iOS Settings → Notifications.
Everything at once Delete the app.

Withdrawing consent does not lock you out of the rest of the app. Nothing here is conditioned on giving up your health data.

8. Your rights

Washington's My Health My Data Act gives you the right to:

Nevada's SB 370 provides substantially the same rights to Nevada residents. Residents of other states and countries may exercise these rights too — we apply them to everyone rather than checking your address.

Our standing answers, so you know before you ask:

How to make a request. Email admin@prameya.legal. Say what you want and which state you are in. There is no form and no account to create.

How we handle it.

Enforcement. A violation of the My Health My Data Act is an unfair or deceptive practice under Washington's Consumer Protection Act (RCW ch. 19.86), which carries a private right of action under RCW 19.86.090. In other words, you are not limited to complaining to a regulator.

9. How we protect it

Retention. We retain none of it, because we receive none of it. On your device, data stays until you delete it using the steps above.

Breach notification. If we ever learn of a security breach involving health-related information from this app, we will notify affected users and regulators as required, including under the FTC's Health Breach Notification Rule and applicable state law.

10. HIPAA

HIPAA does not apply to OmniDerm. Prameya is not a health plan, a health care provider, a clearinghouse, or a business associate of any of them. We have no relationship with your doctor or your insurer. We do not claim to be HIPAA compliant, and you should be wary of any consumer app that does.

Your rights here come from Washington's My Health My Data Act, Nevada SB 370, the California Consumer Privacy Act and similar state laws — and from the fact that the data never leaves your phone.

11. Children

OmniDerm is not directed to children and has no accounts, no ads, no purchases and no way for anyone to send us anything. We do not knowingly collect consumer health data from anyone under 13. If you believe a child has sent us information, email admin@prameya.legal and we will delete it.

12. Changes to this policy

If we change how OmniDerm handles consumer health data, we will update this policy and change the effective date at the top before the change takes effect in the app, and we will tell you inside the app.

What changed on 8 August 2026. This revision corrected the policy against the code that actually ships. Internal review notes that had been published by mistake were removed, and the statements they questioned were rewritten to match the shipping build: the photo rows now say the feature is gated off and reads no image at all rather than describing processing that does not happen, and the iCloud section now names the exact seven non-health settings that can sync. We also removed a security statement the app does not support. Nothing in this document describes a capability the shipping app does not have.

Washington law does not allow us to collect, use or share consumer health data beyond what this policy discloses, and any new category, purpose, or recipient requires your fresh, affirmative consent. We will ask. We will not treat continued use of the app as agreement to a new use of your health data.

Previous versions remain available at https://prameyallc.github.io/privacy/.

13. Contact

Prameya LLC
admin@prameya.legal

For privacy requests, tell us which state or country you are in. You do not need an account, a form, or a lawyer to ask us anything.


Main policy: OmniDerm Privacy Policy · All Prameya app policies: https://prameyallc.github.io/privacy/