Prameya Privacy

Consumer Health Data Privacy Policy — OmniDerm

Effective date: 8 October 2026 (supersedes the 7 October 2026 version; what changed is listed in section 12)
Publisher: Prameya LLC ("Prameya", "we", "us"), a United States limited liability company
Contact: admin@prameya.legal
Applies to: the OmniDerm app (bundle ID legal.prameya.OmniDerm) on iPhone, iPad, Mac and Apple Vision Pro, its Apple Watch app, its Apple TV app, and its widgets

This is a separate policy, required by the Washington My Health My Data Act (RCW ch. 19.373) and provided to meet the parallel duty under Nevada SB 370 (2023). It sits alongside, and does not replace, the OmniDerm Privacy Policy. Where the two overlap, both are true; this one goes into more detail about health information specifically.

It applies to everyone who uses OmniDerm. Washington and Nevada residents have specific statutory rights, set out at the end.


The short version


Why this policy exists even though nothing reaches us

Apple's App Store privacy labels define "collect" as transmitting data off the device in a way the developer or its partners can access. By that definition, OmniDerm collects nothing.

Washington's definition is much broader. Under RCW 19.373.010, "collect" means to buy, rent, access, retain, receive, acquire, infer, derive, or otherwise process consumer health data in any manner. That reaches data that is merely accessed on your device, and it would reach anything a model infers or derives from a photograph of your own skin.

So we do not use the Apple definition to argue our way out of Washington law, and we are not going to tell you that state health-privacy rules do not apply because nothing is uploaded. They apply. This policy is written to them.


1. Categories of consumer health data collected, and why

"Collected" below is used in Washington's broad sense — accessed, processed, inferred or derived — not "sent to Prameya". None of the following is transmitted to Prameya.

Category What it actually is Why the app processes it Where it is kept
Journal photographs of your skin A photo you attach to a journal entry, re-encoded as a JPEG with its location and other metadata removed Shown back to you on your journal timeline, and in same-area compare with Pro This device only. Excluded from backup, never uploaded, never synced, never assessed.
Inferences derived from a skin image Any observation a model might produce about an image None. The shipping app produces no observations, flags or ratings about a photo, and offers no image model while the clearance gate is closed. —
Journal entries Date, body area, a note you type, a lighting note, and whether a photograph is attached Shown back to you on your journal timeline This device, and your device backup if you make one
Skin-care habit records Date, whether you did morning sunscreen, reapplied, did barrier care, and looked at the same area of skin today, and where the log was made (for example Do, or your Apple Watch) To show your history, streak and consistency in the app This device, and your device backup
Derived habit measures Streak length, 30-day consistency percentage, a plain-language summary Computed on your device from your own habit records, to show you your own patterns Computed on this device when shown, and written into an export you make
Your stated goals Free text you type, such as "build daily SPF habit" Kept so you can see and edit them in Settings, and included in your export and appointment pack. They do not change anything else the app shows or records. This device, and your device backup
Questions you type in Ask, and the answers Your question, the last few lines of the conversation, and the model's answer To answer the question, with Apple Intelligence or the model you downloaded, running on the device In memory for the conversation on screen; not saved, not synced, not sent to us or to any AI service
Skin-care topics you open The identifiers of the topic held for continuing (the last topic you opened in Understand, by any route), of the topics you opened in Understand while remembering was allowed and the switch was on, and of the next suggested topic. When remembering is allowed and you turn the switch on, the topic held for continuing at that moment can join that list too, even if you opened it while the switch was off. Each identifier names its topic. Some name skin conditions, rare diseases (for example epidermolysis bullosa) or infections and infestations. They can also name sexually transmitted or sexual-contact conditions: one names pubic lice, which the source the topic quotes says usually spread through sexual contact. So this list can reveal sexual-health information, such as that you read about pubic lice. To let you continue on your other devices and to suggest the next topic Opened-topic identifiers go to your own iCloud key-value storage, and, while the app is open, Handoff to your own nearby devices, only while iCloud Sync and Handoff is on and you have allowed remembering. The widget's suggested next topic follows the iCloud switch alone and is not that list. Switching sync off, Clear All Local Data, or declining remembering removes stored topic identifiers and stops Handoff of the topic. Apple TV opens on its Continue tab and shows the topic held for continuing only after remembering is allowed. Read this topic on your Apple Watch sends the identifier only when remembering is allowed. Reading a topic does not require the allow.

Not collected, in any sense: your location (precise or approximate — location metadata is removed from journal photographs), biometric identifiers, genetic data, contacts, microphone or audio, camera input, Apple Health data, clinical health records from any provider, prescriptions, diagnoses, insurance or payment information, gender-affirming or reproductive health information (a topic you open about sexual health, such as pubic lice, is part of "Skin-care topics you open" above and is handled as described there), or any identifier that would let anyone link this app's data to you by name.

The app does not use geofencing of any kind, and does not use a geofence around any health care facility.

2. Sources of the data

Source What comes from it
You Habit logs, goals, journal notes, Ask questions — everything you type or tap
Your photo library Only the one image you pick for a journal entry, via Apple's photo picker. The app cannot browse the rest of your library. Journal JPEGs stay on this device and are not assessed.
Your Apple Watch A habit log for today's morning sunscreen and barrier care, when you tap Confirm on the Watch's "Applied today's care" card. It is written on your iPhone and added to anything already logged that day.
Your other Apple devices The topic held for continuing, and topics opened there, when remembering is allowed and you continue through Handoff or have iCloud Sync on
The app itself, on your device Streaks, consistency and summaries computed from your own habit logs; answers written by the on-device language model

There are no other sources. We do not buy data, rent data, receive data from data brokers, or obtain anything about you from advertising networks, social platforms, affiliates, or public records.

3. How the data is used

Nothing is used to train AI. Ask's models are already trained when they reach your device, and your questions, journal and habit logs do not update them. Ask is never given your journal, your photographs or your habit logs — only your question, the conversation on screen and passages from the app's built-in topics.


Subscription tiers and consumer health data

No new collection when you subscribe

OmniDerm has a free tier and one paid upgrade, OmniDerm Pro (monthly, annual or lifetime; all three grant the same Pro). Upgrading does NOT trigger new consumer health data collection.

Both tiers:
- Process the same categories of consumer health data (listed above)
- Use consumer health data for the same purpose (operating features you choose to use)
- Store data in the same location (on your device)
- Send it to the same recipients (none — Prameya receives nothing in either tier)

Subscription unlocks features. It does not change what data is collected, how it is processed, or where it goes.

What changes between tiers

What Pro affects What Pro does NOT affect
How much history the screens show: the free journal timeline shows the last 30 days in full, with older entries listed under Older entries (date, body area and note, without the photograph); the free list of logged days shows what you marked for the last 90 days, with older days listed under Older days (the date only). Pro shows everything. What is stored: every record is kept on the device in both tiers, and Export my record always contains all of it
Same-area compare (an earlier and a later photograph of one body area, blended or side by side) Whether journal photos are saved (yes in both tiers, on this device only)
The formatted appointment pack (a text summary of your dates, body areas, notes, habit marks and goals) What iCloud Sync carries (the same in every tier, and never your journal, photographs or habit logs)
What categories of consumer health data are collected

StoreKit data is not consumer health data

When you buy or restore Pro, Apple's StoreKit on your device tells the app which Pro product is active and, for a subscription, when it renews. That is payment information, not consumer health data under RCW 19.373.010.

StoreKit information:
- Does not identify your health status, condition, disease, or treatment
- Is used only to unlock Pro
- Is not written into OmniDerm's own storage (the app asks StoreKit again at launch and after each purchase), is not sent to Prameya, and is not removed by Clear All Local Data — your purchase records are Apple's

Apple separately processes your Apple Account ID and payment method when you subscribe. That processing is governed by Apple's terms, not ours.


4. Categories of consumer health data that are shared

None.

We share no consumer health data, of any category, with anyone. There is no category to list because the list is empty.

5. Categories of third parties and specific affiliates we share with

None. For completeness, since some third parties are involved in the app without receiving any health data:

Party Role Consumer health data they receive
Apple Distributes the app; provides the operating systems, on-device storage, Apple Intelligence's on-device model, device backups, Handoff, the connection between your iPhone and Apple Watch, and, if you turn it on, iCloud storage inside your own Apple Account None from us. Apple stores or carries some of your data for you, at your direction, under your Apple Account: your device backup (journal notes, body areas, habit logs and goals — not journal photographs), if you back up your device; and if you turn on iCloud Sync and Handoff, five non-health settings and the widget's suggested next topic, and, through Handoff, the tab you are on, to your own nearby devices. The identifier of a topic you open, the list of topics you opened, and Handoff of that topic go only after you also allow remembering. When you tap Read this topic on your Apple Watch, the identifier of the topic held for continuing goes over the connection between your iPhone and Apple Watch only when remembering is allowed. Prameya cannot read any of it. Ask's questions go to Apple Intelligence's model on your device, not to Apple's servers.
Hugging Face Serves the optional on-device Ask model, only after you agree to that download in Settings None. The download request carries your IP address, standard request headers and the names of the model files, never a question, a journal entry, a photograph or anything else you entered.

What iCloud Sync can carry, precisely. Sync is off unless you switch it on (Settings → iCloud Sync and Handoff). Remembering the identifier of a topic you open is a second allow, Remember topics I open, off until you allow it. That allow stays on this device and is not one of the five iCloud settings. The app tells you inside the app and asks for your consent again before storing or syncing that identifier. When the iCloud switch is on, sync uses two stores in your own Apple Account:

iCloud Sync never writes journal entries and notes, journal photographs, habit logs, streaks, consistency scores, goals or Ask questions to iCloud, and none of the app's local database is mirrored to iCloud. (A device backup to iCloud is separate: it includes journal entries, habit logs and goals, but not journal photographs — see section 8.) Switching sync off, or Clear All Local Data, removes the key-value entries, deletes the preference record and stops Handoff. Declining remembering, or switching Remember topics I open off, removes stored topic identifiers and the opened list. Reading a topic does not require that allow. If the app cannot reach iCloud at that moment, Clear All says so, and you can delete OmniDerm's iCloud data in Settings → your name → iCloud → Manage Account Storage (on a Mac, System Settings → your name → iCloud → Manage).

We have no affiliates. We use no processors, no analytics vendor, no cloud provider of ours that touches your data, no advertising network, and no AI service provider. We do not disclose consumer health data to law enforcement or anyone else, because we do not have it — a demand made to Prameya for your health data cannot be satisfied.

6. Selling consumer health data

We do not sell consumer health data, and we will not.

Washington law requires a separate, signed authorization with specific contents before any sale of consumer health data. We have never asked anyone for one and do not intend to. If that ever changed, it would require your explicit, separate, written authorization, revocable at any time — not a buried checkbox and not a policy update.

How consent works in OmniDerm.

How to withdraw consent — all of these are immediate and do not require contacting us:

To withdraw Do this
Photographs (journal) There is no photo library permission to withdraw: Apple's photo picker gives the app only the image you pick, each time. Journal JPEGs already saved are deleted with Delete the photograph, with Clear All Local Data, or by deleting the app.
iCloud Sync and Handoff Switch iCloud Sync and Handoff off in the app's Settings. That stops every write and Handoff, removes OmniDerm's key-value entries from iCloud and deletes the preference record.
Remember topics I open Decline the notice, or switch off Remember topics I open in Settings. That removes stored topic identifiers and the opened list. Reading a topic does not require the allow.
Handoff, for every app iOS Settings → General → AirPlay & Continuity → Handoff off (on a Mac, System Settings → General → AirDrop & Handoff).
On-device Ask model Switch Use an on-device model off in Settings → On-device Ask model (stops a download and unloads the model), and use Remove the downloaded model to delete its files.
Reminders Switch reminders off in the app, or in the Settings app → Notifications (on a Mac, System Settings → Notifications).
Device backup Exclude OmniDerm from iCloud Backup (iOS Settings → your name → iCloud → Manage Account Storage → Backups), or stop backing up the device.
Everything at once Clear All Local Data, then delete the app.

Withdrawing consent does not lock you out of the rest of the app. Nothing here is conditioned on giving up your health data.

8. Your rights

Washington's My Health My Data Act gives you the right to:

Nevada's SB 370 provides substantially the same rights to Nevada residents. Residents of other states and countries may exercise these rights too — we apply them to everyone rather than checking your address.

Our standing answers, so you know before you ask:

How to make a request. Email admin@prameya.legal. Say what you want and which state you are in. There is no form and no account to create.

How we handle it.

Enforcement. A violation of the My Health My Data Act is an unfair or deceptive practice under Washington's Consumer Protection Act (RCW ch. 19.86), which carries a private right of action under RCW 19.86.090. In other words, you are not limited to complaining to a regulator.

9. How we protect it

Retention. We retain none of it, because we receive none of it. On your device, data stays until you delete it using the steps above.

Breach notification. If we ever learn of a security breach involving health-related information from this app, we will notify affected users and regulators as required, including under the FTC's Health Breach Notification Rule and applicable state law.

10. HIPAA

HIPAA does not apply to OmniDerm. Prameya is not a health plan, a health care provider, a clearinghouse, or a business associate of any of them. We have no relationship with your doctor or your insurer. We do not claim to be HIPAA compliant, and you should be wary of any consumer app that does.

Your rights here come from Washington's My Health My Data Act, Nevada SB 370, the California Consumer Privacy Act and similar state laws — and from the fact that the data never reaches us.

11. Children

OmniDerm is not directed to children and has no accounts, no ads, no social features and no way for anyone to send us anything. It offers one paid upgrade, OmniDerm Pro (monthly, annual or lifetime), which Apple processes. We do not knowingly collect consumer health data from anyone under 13. If you believe a child has sent us information, email admin@prameya.legal and we will delete it.

12. Changes to this policy

If we change how OmniDerm handles consumer health data, we will update this policy and change the effective date at the top before the change takes effect in the app, and we will tell you inside the app.

8 October 2026 — what changed. Remembering the identifier of a topic you open is a separate allow, off until you allow it. The app tells you inside the app and asks for your consent again before that identifier is stored or synced. Declining stops that storage and that sync. Reading a topic does not require the allow. The widget's suggested next topic can still go with iCloud Sync before the allow, and it is not the list of topics you opened. The short version, the category table, "What iCloud Sync can carry", consent, and the Apple Watch and Apple TV sentences now say this. On 7 October 2026 the Watch's Read this topic card sent the identifier whether or not iCloud Sync and Handoff was on; it now sends that identifier only when remembering is allowed.

7 October 2026 — what changed. The app's topic library grew, and parts of this policy were out of date with the app. It now says:

Nothing is sent to Prameya.

27 September 2026 — what changed. One change in the app, and this policy follows it:

Nothing is sent to Prameya.

24 September 2026 — what changed. One change in the app, and this policy follows it:

23 September 2026 — what changed. This policy was out of date with the app, and it now describes what OmniDerm actually does:

Nothing is shared with or sold to anyone, as before.

What changed on 24 August 2026. Per-entry, per-photograph and per-day deletion was named, and the export began carrying the journal photographs themselves.

What changed on 23 August 2026. Journal JPEGs you save are stored on this device. This page no longer says no photo was ever saved. Photo assessment remains gated off. Hugging Face was not contacted in the build of that date (superseded on 23 September 2026: see above).

What changed on 8 August 2026. An earlier revision corrected internal review notes and named iCloud’s seven non-health settings. Sentences from that date that said the app reads no image at all are superseded above, as is the statement that iCloud carries only those settings.

Washington law does not allow us to collect, use or share consumer health data beyond what this policy discloses, and any new category, purpose, or recipient requires your fresh, affirmative consent. We will ask. We will not treat continued use of the app as agreement to a new use of your health data.

Previous versions remain available at https://prameyallc.github.io/privacy/.

13. Contact

Prameya LLC
admin@prameya.legal

For privacy requests, tell us which state or country you are in. You do not need an account, a form, or a lawyer to ask us anything.


Main policy: OmniDerm Privacy Policy · All Prameya app policies: https://prameyallc.github.io/privacy/