Consumer Health Data Privacy Policy — OmniDerm
Effective date: 8 August 2026
Publisher: Prameya LLC ("Prameya", "we", "us"), a United States limited liability company
Contact: admin@prameya.legal
Applies to: the OmniDerm iOS app
This is a separate policy, required by the Washington My Health My Data Act (RCW ch. 19.373) and provided to meet the parallel duty under Nevada SB 370 (2023). It sits alongside, and does not replace, the OmniDerm Privacy Policy. Where the two overlap, both are true; this one goes into more detail about health information specifically.
It applies to everyone who uses OmniDerm. Washington and Nevada residents have specific statutory rights, set out at the end.
The short version
- OmniDerm processes information about your skin-care habits. Under Washington law that is consumer health data, even though it stays on your phone.
- We do not receive any of it. Prameya has no server that takes it, no database that holds it, and no account that identifies you.
- We share it with no one. Not affiliates, not processors, not advertisers, not data brokers, not researchers, not AI companies.
- We do not sell it. We never have and we will not.
- The photo self-check is switched off in the shipping app. The screen that would take a photo of your skin sits behind a clearance gate that is closed, so the app does not open your photo library, does not read an image, and infers nothing from one.
- You can withdraw consent and delete everything yourself, immediately, without asking us.
Why this policy exists even though nothing leaves your device
Apple's App Store privacy labels define "collect" as transmitting data off the device. By that definition, OmniDerm collects almost nothing.
Washington's definition is much broader. Under RCW 19.373.010, "collect" means to buy, rent, access, retain, receive, acquire, infer, derive, or otherwise process consumer health data in any manner. That reaches data that is merely accessed on your device, and it would reach anything a model infers or derives from a photograph of your own skin.
So we do not use the Apple definition to argue our way out of Washington law, and we are not going to tell you that state health-privacy rules do not apply because nothing is uploaded. They apply. This policy is written to them.
1. Categories of consumer health data collected, and why
"Collected" below is used in Washington's broad sense — accessed, processed, inferred or derived — not "sent to Prameya". None of the following is transmitted to Prameya.
| Category | What it actually is | Why the app processes it |
|---|---|---|
| Images of your skin | A photo of a mole, a lesion, or an area of skin | Not processed in the shipping app. The photo screen is behind a clearance gate that is switched off and cannot be opened, so the app does not read an image at all. If the gate were ever opened, the image would come only from Apple's photo picker, one image you chose, held in memory and never saved or uploaded. |
| Inferences derived from a skin image | Any observation a model might produce about an image | None. The shipping app produces no observations, flags or ratings about a photo, and does not contain the image model that would generate them. |
| Skin-care habit records | Date, and whether you did morning sunscreen, reapplied, did barrier care, did a self-check | To show your history, streak and consistency in the app |
| Derived habit measures | Streak length, 30-day consistency percentage, a plain-language summary | Computed on your device from your own habit records, to show you your own patterns |
| Health and fitness data from Apple Health | Step count, sleep analysis, active energy — last 7 days only, read only, and only if you switch it on | To show, on your device, how activity and sleep line up with your logged habits |
| Your stated goals | Free text you type, such as "build daily SPF habit" | To personalise the cards the app shows you |
| Bodily or health-adjacent status you type in | Anything you choose to write into a goal or note | Only what you choose to enter |
Not collected, in any sense: your location (precise or approximate), biometric identifiers, genetic data, contacts, microphone or audio, camera input, clinical health records from any provider, prescriptions, diagnoses, insurance or payment information, gender-affirming or reproductive health information, or any identifier that would let anyone link this app's data to you by name.
The app does not use geofencing of any kind, and does not use a geofence around any health care facility.
2. Sources of the data
| Source | What comes from it |
|---|---|
| You | Habit logs, goals, notes — everything you type or tap |
| Your photo library | Nothing, in the shipping app: the photo screen cannot be opened, so no image is read. If the gate were ever opened, Apple's picker would hand the app only the one image you chose, and the app still could not browse or read the rest of your library. |
| Apple Health on your device, only with your separate permission | Steps, sleep, active energy for the last 7 days, read only |
| The app itself, on your device | Streaks, consistency and summaries computed from your own habit logs |
There are no other sources. We do not buy data, rent data, receive data from data brokers, or obtain anything about you from advertising networks, social platforms, affiliates, or public records.
3. How the data is used
- To show you your own information inside the app.
- To compute your streak and consistency on your device.
- To provide the educational content and reminders you asked for.
- Nothing else. Not to advertise to you, not to profile you, not to train any model, not to build a data set, not for research, and not for any purpose we have not described here.
Nothing is used to train AI. The AI models in OmniDerm are downloaded already-trained and are never updated with your data.
4. Categories of consumer health data that are shared
None.
We share no consumer health data, of any category, with anyone. There is no category to list because the list is empty.
5. Categories of third parties and specific affiliates we share with
None. For completeness, since some third parties are involved in the app without receiving any health data:
| Party | Role | Consumer health data they receive |
|---|---|---|
| Apple | Distributes the app; provides iOS, on-device storage, Apple Health and, if you enable it, the private iCloud database inside your own Apple Account | None from us. If you turn on iCloud sync, only non-health preferences go to your own private iCloud, which we cannot read. |
| Hugging Face | Hosts the AI model files the app downloads to your phone | None. The request is for a model file. It carries no photo, no habit log, no health data, no identifier of you. |
What iCloud sync can carry, precisely. Sync is off unless you switch it on, and when it is on it is limited in code to seven settings: appearance mode, whether reminders are on, the reminder hour, the tab the app opens on, which AI model you selected, whether you have acknowledged the app's disclosure, and whether citations are expanded by default. Each of those accepts only a fixed set of values, so free text cannot travel with them. Habit logs, streaks, consistency scores, goals, photos and Apple Health data are on an explicit deny list, and none of the app's local database is mirrored to iCloud. Records go to the private database in your own Apple Account, which Prameya cannot read.
We have no affiliates. We use no processors, no analytics vendor, no cloud provider that touches your data, no advertising network, and no AI service provider. We do not disclose consumer health data to law enforcement or anyone else, because we do not have it — a demand made to Prameya for your health data cannot be satisfied.
6. Selling consumer health data
We do not sell consumer health data, and we will not.
Washington law requires a separate, signed authorization with specific contents before any sale of consumer health data. We have never asked anyone for one and do not intend to. If that ever changed, it would require your explicit, separate, written authorization, revocable at any time — not a buried checkbox and not a policy update.
7. Consent, and how to withdraw it
How consent works in OmniDerm.
- The photo feature is not available at all in this version — the clearance gate is closed, so there is nothing to consent to and no image is read.
- Apple Health is off until you switch it on, and iOS then asks you separately.
- iCloud sync is off until you switch it on.
- Reminders are a toggle, and it starts on. They are local notifications from your own phone; iOS still asks you separately before it can show you one, and you can switch them off in the app or in iOS Settings at any time.
- Habit logging happens only when you tap the toggles.
How to withdraw consent — all of these are immediate and do not require contacting us:
| To withdraw | Do this |
|---|---|
| Photo access | Nothing is needed for this version, since the app does not read photos. If you want the permission closed off regardless: iOS Settings → Privacy & Security → Photos → OmniDerm → None. |
| Apple Health access | Switch the toggle off in the app, or iOS Settings → Health → Data Access & Devices → OmniDerm → turn off. |
| iCloud sync | Switch the sync toggle off in the app's Settings. |
| Reminders | Switch reminders off in the app, or in iOS Settings → Notifications. |
| Everything at once | Delete the app. |
Withdrawing consent does not lock you out of the rest of the app. Nothing here is conditioned on giving up your health data.
8. Your rights
Washington's My Health My Data Act gives you the right to:
- Confirm whether we collect, share, or sell your consumer health data, and to access it;
- Get a list of all third parties and affiliates with whom we have shared or to whom we have sold it, with contact information for each;
- Withdraw consent to our collection and sharing of it;
- Delete it, including from any backups and archives.
Nevada's SB 370 provides substantially the same rights to Nevada residents. Residents of other states and countries may exercise these rights too — we apply them to everyone rather than checking your address.
Our standing answers, so you know before you ask:
- Do we collect your consumer health data? Not in the sense of receiving it. It is processed on your device. We never obtain a copy.
- Do we share it? No, with no one.
- Do we sell it? No, and never have.
- List of third parties we shared with or sold to? Empty.
- Can you access it? Yes — from the app itself, at any time. Settings → Export Full Data (JSON) gives you a complete file of your habit logs, your streak snapshot and your goals.
- Can you delete it? Yes, and you do not need us. Settings → Clear All Local Data deletes your habit logs, goals and reminder settings and cancels pending reminders. Deleting the app removes everything else, including downloaded models and stored keys. No photo was ever read or saved, so there is nothing to delete there. If you enabled iCloud sync, remove the app's iCloud data in iOS Settings → your name → iCloud → Manage Account Storage.
- Do we hold backups or archives of your data? No. We have no copy to restore, so there is no archive for a deletion request to miss.
How to make a request. Email admin@prameya.legal. Say what you want and which state you are in. There is no form and no account to create.
How we handle it.
- We respond within 45 days of receiving the request. If we need more time, we may extend once by a further 45 days, and we will tell you why before the first 45 days are up.
- We do not charge for this.
- Because there is no account, we cannot and will not demand identity documents to verify you. If a request would require us to identify you and we cannot, we will say so and explain exactly how to do the thing yourself on your device.
- If we deny your request, we will tell you why and give you instructions for appealing. You appeal by replying to that email. We will respond to an appeal in writing within 45 days, with our reasoning.
- If we deny your appeal, we will give you a way to complain to the Washington State Attorney General at https://www.atg.wa.gov/file-complaint. Nevada residents may complain to the Nevada Attorney General's Bureau of Consumer Protection.
Enforcement. A violation of the My Health My Data Act is an unfair or deceptive practice under Washington's Consumer Protection Act (RCW ch. 19.86), which carries a private right of action under RCW 19.86.090. In other words, you are not limited to complaining to a regulator.
9. How we protect it
- Consumer health data stays on your device, inside the app's sandbox, and your device passcode or Face ID is the main protection for it.
- What we do not claim: the app does not enable iOS's strictest file-protection level, the one that would keep its files unreadable the whole time your device is locked. Its stored files get the standard protection iOS gives app data and nothing beyond it.
- No skin photo is read or written at all in this version, and no code path in the app writes an image to a file, a database, the Keychain, or iCloud.
- Sensitive keys and flags are stored in the device Keychain, marked this device only, so they never travel to another device.
- All network traffic uses HTTPS; the app refuses unencrypted connections.
- Access inside Prameya is limited by architecture rather than by policy: no employee, contractor or system of ours can access your consumer health data, because it never reaches us.
Retention. We retain none of it, because we receive none of it. On your device, data stays until you delete it using the steps above.
Breach notification. If we ever learn of a security breach involving health-related information from this app, we will notify affected users and regulators as required, including under the FTC's Health Breach Notification Rule and applicable state law.
10. HIPAA
HIPAA does not apply to OmniDerm. Prameya is not a health plan, a health care provider, a clearinghouse, or a business associate of any of them. We have no relationship with your doctor or your insurer. We do not claim to be HIPAA compliant, and you should be wary of any consumer app that does.
Your rights here come from Washington's My Health My Data Act, Nevada SB 370, the California Consumer Privacy Act and similar state laws — and from the fact that the data never leaves your phone.
11. Children
OmniDerm is not directed to children and has no accounts, no ads, no purchases and no way for anyone to send us anything. We do not knowingly collect consumer health data from anyone under 13. If you believe a child has sent us information, email admin@prameya.legal and we will delete it.
12. Changes to this policy
If we change how OmniDerm handles consumer health data, we will update this policy and change the effective date at the top before the change takes effect in the app, and we will tell you inside the app.
What changed on 8 August 2026. This revision corrected the policy against the code that actually ships. Internal review notes that had been published by mistake were removed, and the statements they questioned were rewritten to match the shipping build: the photo rows now say the feature is gated off and reads no image at all rather than describing processing that does not happen, and the iCloud section now names the exact seven non-health settings that can sync. We also removed a security statement the app does not support. Nothing in this document describes a capability the shipping app does not have.
Washington law does not allow us to collect, use or share consumer health data beyond what this policy discloses, and any new category, purpose, or recipient requires your fresh, affirmative consent. We will ask. We will not treat continued use of the app as agreement to a new use of your health data.
Previous versions remain available at https://prameyallc.github.io/privacy/.
13. Contact
Prameya LLC
admin@prameya.legal
For privacy requests, tell us which state or country you are in. You do not need an account, a form, or a lawyer to ask us anything.
Main policy: OmniDerm Privacy Policy · All Prameya app policies: https://prameyallc.github.io/privacy/