Prameya Privacy

OmniSalub Privacy Policy

Effective date: 8 October 2026
Last updated: 8 October 2026
Publisher: Prameya LLC ("Prameya", "we", "us")
Applies to: OmniSalub for iPhone, iPad, Mac, Apple Vision Pro and Apple TV (bundle identifier legal.prameya.omnisalub), and the OmniSalub Apple Watch app that comes with the iPhone app (legal.prameya.omnisalub.watchkit)
Contact: admin@prameya.legal

Washington and Nevada residents — and anyone who wants the health-specific detail: we publish a separate Consumer Health Data Privacy Policy. Prameya collects no consumer health data; processing is on-device. Apple's App Privacy label is Data Not Collected. Please read the separate policy alongside this one.

Other Prameya app policies: prameyallc.github.io/privacy.


The short version

OmniSalub helps you keep track of a chronic condition — blood pressure, heart failure, kidney disease — on your own device.

Where this policy says "we do not do X", it means the capability is absent from the software — or, where we say so explicitly, that it exists in the code but is hard-wired off and fails closed.


1. Who we are and what this covers

Prameya LLC is a US limited liability company. OmniSalub is a direct-to-consumer app. You buy or download it from Apple; you do not create an account with us, and we do not know who you are.

This policy covers the OmniSalub app on iPhone, iPad, Mac, Apple Vision Pro and Apple TV, its Home Screen widget, and the OmniSalub Apple Watch app. What each device can do differs, and the differences are stated where they matter: the app connects to Apple Health only on iPhone and iPad, so on a Mac or Vision Pro it shows only what was entered on that device; the Apple Watch app and the Apple TV app keep no readings at all (section 8).

This policy does not cover Apple's services (the App Store, Apple Health, iCloud, Handoff, Siri, Apple Intelligence), which are governed by Apple's privacy policy, or any app or service you choose to send an export to.


2. Subscriptions and In-App Purchases

Available tiers

There is one paid upgrade, OmniSalub Pro, sold as three products. Buying any one of
them grants exactly the same Pro — there are no separate feature tiers.

Product Price (US) Billing
OmniSalub Pro Monthly $4.99 Auto-renews monthly. 7-day free trial.
OmniSalub Pro Annual $29.99 Auto-renews yearly. 7-day free trial.
OmniSalub Pro Lifetime $79.99 One-time purchase. Not a subscription.

Family Sharing is enabled on all three. Subscriptions renew until you cancel (how, on each
device, is under Cancellation and refunds below); Lifetime is a one-time non-consumable. Apple decides whether your Apple Account is eligible for the free trial, and the app offers it only when Apple says it is.

The knowledge layer is free and stays free. Without paying anything you get
90 days of history in the app, the full reference and your own readings, with no account and no time limit. Pro adds the visit pack (a PDF summary for a clinician), lifts the 90-day limit on history in the app (it then shows up to the last 400 days), and formatted export (a formatted CSV and a FHIR bundle). Older readings are never deleted because you are on the free tier: they stay on your device and are included in the free raw export.

Pro does not add cloud sync, and there is no paid iCloud option. OmniSalub stores your
records on your device in every case, paid or not. If a subscription lapses you keep your
own data and can still export it in its raw form; only the Pro tools stop.

Free vs paid tier data collection

Both tiers process the same consumer health data (listed in the Consumer Health Data Privacy Policy).

In both tiers:
- Health readings stay on your device
- No health data transmitted to Prameya
- Same HealthKit permissions and data types
- Same on-device processing

Subscription unlocks features. It does not change what data is collected or where it goes.

Cancellation and refunds

Subscriptions are managed by Apple:
- Cancel on iPhone or iPad: Settings → your name → Subscriptions → OmniSalub
- Cancel on a Mac: the App Store app → your name → Account Settings → Subscriptions → Manage
- Cancel on Apple Vision Pro: Settings → your name → Subscriptions → OmniSalub
- Refund requests: reportaproblem.apple.com

Prameya cannot cancel your subscription or issue refunds. Apple controls all billing.

StoreKit and your purchase record

When you buy or restore Pro, Apple's StoreKit on your device completes the purchase with the App Store. Apple processes the payment and keeps its own record of the transaction under Apple's terms. Each time the app starts, StoreKit tells it which OmniSalub Pro products your Apple Account is entitled to, and the app uses that answer only to turn the Pro tools on or off.

An earlier version of this policy said the app stores the transaction ID, product ID and dates itself and deletes them with "Delete All Data". That did not describe the app: the app stores none of them.


3. Apple Health (HealthKit)

This is the most important section, so it is the longest. The app connects to Apple Health only on iPhone and iPad. On a Mac or Apple Vision Pro the app does not connect to Apple Health at all, and the Apple Watch and Apple TV apps do not use it.

3.1 What the app asks to read

Nothing is read from Apple Health until you tap Connect Apple Health (on Today, on Record or in Settings; once you have readings the button is called Refresh from Apple Health). Finishing setup does not open Apple's permission sheet, and the app does not read Apple Health in the background.

What the permission sheet asks for. When you tap Connect Apple Health, Apple's sheet lists the types the conditions you have switched on use (for General health, its small core set). That is the default: the switch Import everything from Health in Settings is off unless you turn it on. The blood pressure programme, for example, asks for blood pressure, weight, exercise minutes and any symptom records its alert rules check, and if you add a condition, the next tap asks for the new types. With the switch on, the sheet lists every type in the table below — every type the app can use — whichever conditions you have switched on. If you chose Hide food and calorie prompts during setup, that wider sheet leaves out the nutrition types and energy burned, and the app does not import them. For each type on the sheet that you allow, the app then imports your history from Apple Health into its database on your device — the last 400 days of readings, sleep, workouts and Watch notifications, and all of your records of the symptom types it asked for — and afterwards refreshes those types. If you turn Import everything from Health off after allowing more types, Apple Health remembers your earlier answers, but the app then reads only the types your conditions use; what it already imported stays on your device until you delete it (section 14). Apple's sheet appears only for types you have not already answered.

Changed on 24 September 2026: the revision of 23 September described an app that asked only for the types your conditions use, with Import everything from Health adding General health's extra types. The app update this revision describes asks for every type in the table below by default, and that switch is how you limit it.

Changed on 8 October 2026: the revision of 24 September described an app that asked for every type in the table below by default, with Import everything from Health as the way to limit it. The app update this revision describes asks only for the types your conditions use by default, and that switch, off unless you turn it on, is how the sheet widens to the table.

The table below is every type the app's Apple Health request can name, and with Import everything from Health on it is what the sheet lists (without nutrition and energy burned if you chose to hide food and calorie prompts). No condition programme uses some of them; they are there because the app's own screens show them — the readings list, charts and exports show every reading the app holds, the symptom list every symptom record, and Today counts Watch notifications. They are breathing disturbances during sleep; Apple's hypertension and sleep apnea notifications; and the nausea, abdominal cramps, bloating, constipation, heartburn, fatigue, headache, mood changes, appetite changes, sleep changes and skipped heartbeat symptom records. With the switch off, the sheet never lists these.

Group What is requested
Vitals Blood pressure, heart rate, resting and walking heart rate, heart-rate recovery, heart rate variability, AFib burden, oxygen saturation, respiratory rate, body temperature (including basal and wrist temperature), peripheral perfusion index
Body Weight, BMI, body fat, lean mass, height, waist circumference
Glucose and related Blood glucose, insulin delivery, blood alcohol content
Alcohol Number of alcoholic drinks
Breathing tests FEV1, forced vital capacity, peak flow, inhaler use
Activity and fitness Steps, exercise minutes, move and stand time, energy burned, flights climbed, distances (walking and running, cycling, swimming, wheelchair, snow sports), push count, swimming strokes, VO₂ max, time in daylight, UV exposure, running and cycling metrics
Workouts Workout records, from which the app reads duration, active energy and distance
Mobility Walking speed and steadiness, step length, asymmetry, double-support percentage, stair speeds, six-minute walk distance, times fallen
Sleep Sleep analysis records — time in bed, time asleep, and sleep stages — and breathing disturbances during sleep
Notifications from a Watch Exactly six record types: high heart rate, low heart rate, irregular rhythm notification, low cardio fitness, and Apple's hypertension notification and sleep apnea notification
Hearing Environmental and headphone audio-exposure levels
Nutrition Energy, carbohydrates, protein, fats, cholesterol, fibre, sugar, water, caffeine, and minerals including sodium and potassium (both matter clinically in hypertension and kidney disease), plus calcium, iron, magnesium and zinc
Symptoms The symptom records the app can represent: breathlessness, chest tightness or pain, dizziness, palpitations, skipped heartbeat, fainting, nausea, vomiting, fever, diarrhoea, abdominal cramps, bloating, constipation, heartburn, fatigue, headache, mood changes, appetite changes, sleep changes

Added on 2026-08-08: number of alcoholic drinks and the skipped heartbeat symptom record. The alcohol-use programme previously had no Apple Health source at all, so every drink had to be entered twice; and Apple Health records a skipped heartbeat separately from palpitations, which made it the one cardiac symptom the app could not import.

What the app keeps with an imported reading. Besides the value and time, the app keeps what Apple Health says about where the reading came from: the name and version of the app that saved it, and — where Apple Health has it — the name, manufacturer, model, software versions and identifiers of the device that measured it (for example a blood pressure cuff). This stays in the app's database on your device and can appear in a FHIR export (section 9).

What the app does not ask for. These types were in an earlier build's request and have been removed from it:

None of these is in the app's request table, so none can appear on the permission sheet. For reproductive and sexual health records, profile facts, and the mindful, stand-hour, audio-exposure-event, toothbrushing and handwashing records, automated tests check the widest request the app could build — every type in the table above at once, which is the sheet while Import everything from Health is on, not the default request — and fail if any of them returns: noReproductiveHealthTypeIsEverRequested, noCharacteristicTypeIsEverRequested and unconsumedCategoryFamiliesStayOutOfTheRequest. Medications and Clinical Health Records are refused by a separate check that runs before any request is made (section 3.3).

You are not obliged to grant any of it. Apple's sheet has an individual toggle for every category, and the app works with whatever subset you allow. If you only want blood pressure to come through, leave Import everything from Health off, so that the sheet lists only what your conditions use, and turn on only blood pressure — or turn the switch on only when you want the wider sheet. You can also skip Apple Health entirely and type readings in.

We are listing the removed categories explicitly, rather than quietly dropping them, because an earlier version of this policy told you the app asked for them. It no longer does, and you should be able to check that against the permission sheet.

3.2 What the app writes back to Health

The app writes back a much narrower set, and only readings you typed into OmniSalub yourself:

Readings that came from Health are never written back, so the app cannot create duplicates of your own data. Symptoms carrying an extra clinical qualifier — "breathlessness on waking", for example — stay only on your device, because writing them as a plain symptom would misrepresent what you recorded.

Writing to Health is how your readings reach your other Apple devices. Data inside Health is managed by Apple under Apple's terms and encryption. We never see it.

3.3 What the app does not read

3.4 Withdrawing permission

Go to Settings → Privacy & Security → Health → OmniSalub, or use the Health app. Revoking permission stops future reads and writes. It does not delete anything already in Health — you control that in the Health app — and it does not delete readings the app already imported; use Delete everything this app stored (section 14) for those.

3.5 Apple's extra rules for health apps

Apple's App Store Review Guideline 5.1.3 imposes obligations beyond ordinary privacy law. This is how the app stands against them:


4. What is stored on your device

What Where it lives Leaves the device?
Readings you record or import, with where each imported reading came from (section 3.1) Local database in the app's private storage Only to Apple Health, for readings you typed, if you allow it; and in exports you make (section 9)
Symptoms you report Same database Same
Alerts the app raised Same database — which guideline rule fired, when, at which rule-set version No
Activity log (section 12) Same database No
Which conditions you track, whether you asked to hide food and weight scoring, whether Import everything from Health is on, your visit date, whether visit reminders are on, your visit questions, and when you accepted the first-run acknowledgements On-device preferences. Only while Show your visit record on the Home Screen is on (iPhone and iPad), your visit questions are also copied into the widget's file (below), and so is your visit date when there is no reading of the measurement Today leads with Never to us, and never to iCloud sync — treated as health information. Like your other on-device preferences, they are included in a device backup, including iCloud Backup if you use it (section 6.4)
Your settings — theme, guideline set, app lock, whether onboarding is done, which tab you last had open On-device preferences, and a separate preferences database Only to your own iCloud, and only if you turn sync on (section 5)
A "where you left off" note — which tab you were on, the identifier of the Learn topic you were reading if that was the last thing you opened, when, and your appearance choice Apple's iCloud key-value storage, written only while settings sync is on Only to your own iCloud, and only while settings sync is on; your other devices, including Apple TV, can read it (section 5)
What the Home Screen widget's files hold — by default none of your information; only if you turn on Show your visit record on the Home Screen, your visit record (the name of the measurement Today leads with, the date of your latest reading of it or your visit date, and your saved visit questions), plus that reading if it is from today, and the name of what to log next (which the widget never shows) — and whether that switch is on Small files in the app's shared container, so the widget can read them No
Assistant settings — whether Ask is on, whether the model may download over cellular (on a Mac or Apple Vision Pro, over a Personal Hotspot), which model is installed On-device preferences No
Optional Ask model files Application Support folder, about 400 MB, excluded from device backup No
Your Ask conversation Held on screen only while Ask is open; not saved No
A temporary copy of an export you create The app's temporary folder, excluded from backup; the app clears these copies Only where you send it (section 9)
Bookmarks recording how far the Apple Health import has got On-device preferences No

The health database is stored in Application Support (not a user-visible folder). On iPhone, iPad and Apple Vision Pro it is set to Data Protection "complete", which means the operating system encrypts it with a key tied to your device passcode and it cannot be read while the device is locked. The database and its two working files are marked as excluded from iCloud backup.

The widget's file is also excluded from device backup, and the exclusion is re-applied every time the app writes the file, so files left behind by older versions of the app are covered too. On iPhone and iPad that file is encrypted at rest until the first time you unlock the device after a restart, rather than being locked again whenever the screen locks. That is a deliberate difference from the health database: the Home Screen widget has to be able to redraw while the phone is locked, and it could not do that under the stronger setting. On iPhone and iPad the app writes this file whether or not you add the widget. By default it holds none of your information, and the widget shows only its name, "Visit record", and a fixed line describing it. If you turn on Show your visit record on the Home Screen (off by default), the file holds your visit record — the name of the measurement Today leads with, such as "Blood pressure", the date of your latest reading of it (or your visit date, if there is no such reading yet), and your saved visit questions, in full (up to three) — and the name of what to log next. If your latest reading of that measurement is from today, the file also holds it in display form, for example "132/84", and in the words VoiceOver would read, with its time and, where it has one, its morning or evening label. That reading stays in the file until the app next rewrites the file, even after the day ends. The widget can show your visit record and that reading on your Home Screen, but never the name of what to log next. While the device is locked (including in StandBy until you unlock it) and while the always-on display is dimmed, it shows only its name and that fixed line, none of your information. What the switch puts in the file has weaker protection at rest than the health database, so leave the switch off if you would rather it were not there at all. Turning the switch off rewrites the file at once without your information. Whether the switch is on is kept in a second small file beside it, protected and excluded from backup in the same way.


5. iCloud and your other devices

Your health data is never stored in iCloud by this app. That is an architectural boundary, not a setting, and it is also required by Apple's Guideline 5.1.3(ii).

Settings sync

If — and only if — you turn on Sync settings with iCloud in Settings, exactly six things are stored in your own iCloud account so they match across your devices:

This uses Apple's CloudKit private database, which is your iCloud account and not ours. We cannot read it. The setting is off by default, the app does not even create the syncing database until you say yes, and a change takes effect the next time the app opens.

Deliberately never synced: readings, symptoms, alerts, the activity log, which conditions you track, your visit date and questions, and your answer to the food-and-weight screening question. The list of fields allowed to sync is enforced by an automated test, not by a promise.

The "where you left off" note

Only while Sync settings with iCloud is on, the app also writes a small note through Apple's iCloud key-value storage: which tab you were on, the identifier of the Learn topic you were reading if that was the last thing you opened (for example a topic about PSA test numbers), the time, and your appearance choice. It never contains a reading. Apple stores the note in your own iCloud account, not with us — we cannot read it — so that your other devices signed in to the same Apple Account can use it: the Continue row on Apple TV shows that Learn topic (section 8.2), and another of your devices with sync on takes your appearance choice from it. With sync off the app neither writes the note nor reads one: turning sync off removes it from your iCloud, and whenever the app opens with sync off it removes any note it finds there, including one another of your devices or an older version of the app left. Delete everything this app stored clears the note.

Handoff

On iPhone, iPad, Mac and Apple Vision Pro the app tells Apple's Handoff which tab you are on, so a nearby device signed in to the same Apple Account can offer to open the app on the same tab. What it passes is that tab (Today, Learn, Record or More) and when you opened it — never the Learn topic you are reading, and never a reading. Handoff is Apple's service between your own devices; it does not reach us. You can turn Handoff off in your device's settings.


6. When the app connects to the internet

Earlier versions of this policy said the app "makes no network requests of its own". That statement was wrong, and it was corrected. Here is the complete and accurate list.

6.1 Hugging Face — the optional Ask model

Ask can use a small language model that runs on your device where Apple Intelligence is not available (section 7). That model is not bundled with the app. If you choose to download it — the Download local model button in Settings → Assistant or in Ask — the app downloads the model files from huggingface.co, a public model host run by Hugging Face, Inc.

For completeness: the app is built on the MLX machine-learning packages mlx-swift-lm, swift-huggingface and swift-transformers. These are how the model is downloaded and run. They are not analytics, advertising or tracking libraries, and none of them transmits your content.

6.2 iCloud settings sync

Off by default. Described in section 5, together with the "where you left off" note that the same switch controls. This goes to Apple, into your own account — not to us.

6.3 The App Store

If you buy or restore OmniSalub Pro, StoreKit on your device talks to Apple's App Store. StoreKit also fetches the Pro prices when you open the Pro screen, and checks your entitlement with Apple when the app starts. Apple processes payments. Nothing about a purchase is sent to us (section 2).

6.4 Apple's own services, which the app uses but does not control

6.5 What does not exist

There is no Prameya server. No API, no backend, no endpoint that receives your data. We could not read your readings if we wanted to. There is no analytics SDK, no advertising SDK, no crash-reporting SDK, no attribution SDK, and no third-party code in the app that transmits user content.

The Mac version of the app carries macOS's outgoing-network entitlement, and it is there for the connections named above and no others we have built: iCloud settings sync and the optional Hugging Face model download. Neither carries health data or anything you have written.

The app also contains no code for location, camera, photo library, contacts, microphone recording, the advertising identifier, App Tracking Transparency, or Sign in with Apple.

An unfinished multi-device sync engine exists in the app's source code. It is not built into any shipping app — no app target links it. If it is ever completed, this policy will be updated before that build ships.


7. Ask, the on-device assistant

Ask is on by default (Settings → Assistant → On-device assistant). It works on iPhone, iPad, Mac and Apple Vision Pro, and — through your iPhone — from Apple Watch. On Apple TV it only quotes the built-in library (section 8.2).


8. Widgets, the Lock Screen, Siri, Apple Watch and Apple TV

8.1 Apple Watch

The Watch app shows the built-in Learn library, a few prompts (start a guided walk on the iPhone, open Record on the iPhone, open tonight's Learn topic), and Ask iPhone. It stores no readings and does not use Apple Health. Its watch-face complications show a fixed title, such as "Log on iPhone", and never a reading.

None of this reaches Prameya.

8.2 Apple TV

The Apple TV app shows the built-in Learn library, a Continue row, an Ask tab, and an About tab with the app's wellness notice, the short version of this policy and the terms of use. It stores no readings, does not use Apple Health, does not download a model and makes no network connection of its own. Ask on Apple TV refuses questions about your own readings and answers others by quoting the built-in library. The Continue row shows the Learn topic named in the "where you left off" note (section 5), which your iPhone, iPad, Mac or Apple Vision Pro leaves in your own iCloud only while its Sync settings with iCloud is on; when there is no such note, it shows nothing to continue. The Apple TV app only reads that note, through Apple's iCloud key-value storage: it never writes, changes or removes it, has no sync switch of its own, and reads nothing else from your iCloud.


9. Exports and sharing

The app can produce a record of your readings to give to a clinician: a raw CSV of your readings and a CSV of your symptoms (free), and, with Pro, a PDF visit summary, a formatted CSV file, or a FHIR bundle.


10. Notifications

The app asks permission to send notifications only when you set a visit date and turn on visit reminders, which are off until you do. If you allow it, the app schedules local notifications on your device at 19:00 on each of the seven days up to and including the visit day, titled "OmniSalub" and reading "today's reading for the visit on" followed by the date. They do not name a condition. If you hide notification previews, iOS shows "Reminder" instead of that text. Turning the switch off, or Delete everything this app stored, removes pending reminders.

A reminder's Later button, and the snooze on an Apple Watch prompt, schedule one more local reminder — and only while visit reminders are on. Tapping a notification only opens the app; only its action buttons do anything.

There is no notification server, and no notification content is transmitted anywhere. Alerts about a concerning reading are shown in the app, never sent as a notification. Apple TV shows no notifications from this app.


11. Diagnostics and analytics

This version records no usage analytics. There is no counter, no event log of what you tapped, and nothing to send even if there were a place to send it.

On iPhone, iPad, Mac and Apple Vision Pro the app subscribes to Apple's MetricKit, which delivers performance and crash diagnostics for the app to the app itself. The app writes a few of Apple's own aggregate figures from those reports — average launch and hang times, disk writes, and counts and types of crashes and hangs — to the device's system log, and keeps nothing else. Nothing from MetricKit is stored by the app, and nothing is transmitted. The Apple Watch and Apple TV apps do not use MetricKit.

The app also writes short operational messages to the device's system log — for example errors, the progress of the model download, or the name of a measurement type it could not read. It never writes a reading's value, and its messages about Ask are marked private, so the system redacts them. The system log stays on your device unless you choose to share diagnostics with Apple.

The app does contain the scaffolding for future on-device usage counting, built so that any event name must come from a fixed, closed list — a reading could not end up in one even by mistake — kept only on your device and deleted after 180 days. Nothing switches it on today. If a future version does, this section will be updated before that version ships.

The app's privacy manifest, which Apple ships inside the app and which anyone can inspect, declares that the app does no tracking and collects no data types. It declares these "required reason" API uses: storing settings in UserDefaults (the app's own, and the container it shares with its widget), checking available disk space before the model download, and reading the timestamps and sizes of files inside the app's own container, which the model download uses to manage its files. The Home Screen widget, the Apple TV app and the Apple Watch app each carry their own manifest. The widget's declares UserDefaults (its own, and the container it shares with the app) and the disk-space check; the Apple TV app's declares UserDefaults and the disk-space check; the Apple Watch app's declares the disk-space check only. None of those three ever runs that check — none of them downloads the model — but its code is part of each of them, so it is declared. The Watch's watch-face extension uses none of these APIs and carries no manifest.


12. The activity log

The app keeps a local log of security-relevant events: when its database was opened; when readings were imported from or written to Apple Health; when a record was edited or deleted, or everything was erased; when the app asked for Apple Health permission; when an alert was raised; when settings sync was turned on or off; and when someone unlocked the app or failed to.

This log:

It exists so that "what happened to my data?" has an answer, which is impossible after the fact if nothing recorded it.


13. Security

No security measure is absolute. Because your data lives on your device, its safety depends heavily on that device having a passcode and up-to-date software.


14. Keeping and deleting data

We hold nothing, so there is nothing at Prameya to delete. On your device:

Erasing data in OmniSalub does not delete anything the app previously wrote to Apple Health. That data is yours and lives in the Health app, where it may also be arriving from a cuff, a watch or a clinic. Delete it there if you want it gone.


15. Your privacy rights

Because we neither collect nor receive your personal data, we hold no record about you to disclose, correct, port or delete. There is nothing for us to sell or share. But you retain complete, direct control:

Right How you exercise it
Know / access Everything is visible in the app, and exportable as a raw CSV of readings and a CSV of symptoms, or with Pro as a PDF, formatted CSV or FHIR bundle
Portability Use the raw CSV, or with Pro the FHIR or formatted CSV export
Correction Edit or delete any entry in the app
Deletion Settings → Delete everything this app stored, or delete the app
Limit processing Revoke Health permission; turn off settings sync; turn off On-device assistant; do not download the Ask model
Withdraw consent Any permission can be revoked at any time in your device's Settings

If you believe we hold data about you and want to make a request anyway, write to admin@prameya.legal. We will respond within 45 days. In almost every case the honest answer will be that we hold nothing.

California (CCPA/CPRA)

We do not sell or share (for cross-context behavioural advertising) personal information, as those terms are defined in the CCPA, and we have not done so in the preceding twelve months. We do not use or disclose sensitive personal information — which includes health information — for purposes beyond those permitted by the CCPA, because we do not receive it in the first place. There is no financial incentive programme and we do not discriminate against anyone for exercising a privacy right.

Note that health data is treated as sensitive personal information under the CPRA. The app processes it on your device, under your control, and none of it reaches us.

Washington and Nevada consumer health data

Washington's My Health My Data Act (RCW ch. 19.373) and Nevada's consumer health data law (SB 370, NRS ch. 603A) both require a separate, distinctly-labelled consumer health data privacy policy. Ours is here:

→ OmniSalub Consumer Health Data Privacy Policy

Prameya collects no consumer health data. Readings stay on your device (and in your own Apple Health account if you allow that). We receive nothing. Apple's App Privacy nutrition label for this app is Data Not Collected. The separate policy states that same position, plus how to exercise your rights, including deletion and appeal. Please read it. Washington's law also makes a violation an unfair practice under the Washington Consumer Protection Act (RCW ch. 19.86), which gives individuals their own right to sue under RCW 19.86.090.

Other US states

Several other states (Colorado, Connecticut, Virginia, Texas, Oregon and others) give residents rights of access, correction, deletion, portability and opt-out, with extra protection for health data. The same answer applies everywhere: we hold no personal data about you, we run no targeted advertising, we do no profiling, and we do not sell data. Requests can be sent to admin@prameya.legal.

If you are in the EU, EEA or UK (GDPR / UK GDPR)

For the processing that happens entirely on your device, Prameya LLC is the controller. Our lawful basis is your consent (Article 6(1)(a)) and, because health data is a special category, your explicit consent (Article 9(2)(a)) — given through the in-app acknowledgements and through iOS's own Health permission sheet. You may withdraw consent at any time as described in the table above, without affecting anything that already happened. You have rights of access, rectification, erasure, restriction, portability and objection; in practice you exercise all of them directly in the app, because we hold no copy. You may complain to your supervisory authority.

Where the app is available is set on the App Store, not here, and can change. This subsection applies to you if you obtained the app in the EEA or the UK.

HIPAA — plainly

HIPAA does not apply to OmniSalub. HIPAA covers healthcare providers, health plans and clearinghouses, and the contractors that handle data for them. Prameya is none of those, and we are not a business associate of any of them. You are using a consumer app you chose yourself, not a service arranged by your doctor or insurer.

We say this because it matters: it means the protection your data has here comes from this app's design and from consumer-protection law, not from HIPAA. It also means we do not claim HIPAA compliance and you should be sceptical of any consumer app that does. If OmniSalub is ever distributed through a clinic, employer or insurer, that analysis changes and this policy will change with it.


16. Children

OmniSalub is intended for adults managing a chronic condition. It is not directed to children under 13, is age-rated for older teenagers and adults because it contains medical information, and we do not knowingly process children's data. Because the app collects nothing and transmits nothing to us, we hold no children's data and there is nothing for us to delete on request. We serve no advertising of any kind, so there is no advertising or behavioural profiling of anyone, children included.

A parent or guardian concerned about a child's use of the app can remove the app's data by using Settings → Delete everything this app stored, or everything by deleting the app. Questions: admin@prameya.legal.


17. What OmniSalub is not

Stated here because it affects how you should treat what the app shows you.

OmniSalub is a general wellness tool. It does not diagnose, treat, cure or prevent any disease, and it is not a medical device. It does not give medical advice and does not give medication instructions. When it flags something, it tells you what it observed and suggests you speak to a doctor. Ask's answers are written by a language model and can be wrong.

It is not a substitute for professional medical care and must never be relied on in an emergency. If you think you are having a medical emergency, call your local emergency number.


18. Changes to this policy

If this policy changes, we will change the effective date at the top and publish the new version at prameyallc.github.io/privacy/omnisalub.

Where a change materially affects how your data is handled — in particular if any future version were to transmit health data off your device, add an account, add a server, or enable cloud or third-party AI processing — we will show you the change in the app and ask for your consent before it takes effect. We will not quietly widen what we do and rely on you re-reading this page.

8 October 2026 — what changed. This revision describes an app update to what Connect Apple Health asks for (sections 3.1 and 14, and the short version):

Nothing the app sends to Prameya changed: it still sends us nothing.

7 October 2026 — what changed. This revision describes an app update to the Home Screen widget, made so that none of your information reaches the widget's file or your Home Screen unless you turn that on (sections 4, 8 and 14). It also corrects one statement about backups (sections 4 and 6.4):

The short version is unchanged. Nothing the app sends to Prameya changed: it still sends us nothing.

Later on 27 September 2026 — what changed. This revision makes three statements true for the Mac and Apple Vision Pro. Nothing the app does with your data changed:

The short version is unchanged. Nothing the app sends to Prameya changed: it still sends us nothing.

27 September 2026 — what changed. This revision corrects one statement and describes an update to the Apple TV app:

Nothing the app sends to Prameya changed: it still sends us nothing.

24 September 2026 — what changed. This revision describes an app update:

Nothing the app sends to Prameya changed: it still sends us nothing.

23 September 2026 — what changed. This revision describes what the app does today, on every device it runs on:

Nothing the app sends to Prameya changed: it still sends us nothing.

Earlier revisions (8–21 August 2026). Those revisions corrected statements in the previous version so that they matched the code that shipped then. The main correction narrowed the description of what the app asks to read from Apple Health, removing reproductive-health and profile categories that were taken out of the request (section 3.1), and replaced a placeholder note about the widget's file with a statement of what the app does.

Material changes are also described in the Consumer Health Data Privacy Policy, which has its own change process.


19. Contact

Questions, requests or complaints about privacy in OmniSalub:

admin@prameya.legal
Prameya LLC
Postal address available on request by email.


This policy describes OmniSalub version 1.0 and later. It replaces the previous OmniSalub privacy policy dated 8 August 2026 (last updated 21 August 2026), which described a narrower Apple Health request than the app makes, did not describe Ask with Apple Intelligence, the Apple Watch, Apple TV and Vision Pro apps, Handoff or notifications, and said the app stored purchase records it does not store. That policy in turn replaced one dated 7 August 2026, which incorrectly stated that the app makes no network requests and that it reads your medication records.

Consumer Health Data Privacy Policy

OmniSalub processes consumer health data. Washington State law requires a separate policy for that data, published at its own address:

OmniSalub Consumer Health Data Privacy Policy

Terms of Use

The terms governing OmniSalub, including subscription auto-renewal and cancellation, and dispute resolution:

OmniSalub Terms of Use