Privacy Policy
Photos stay on your iPhone unless you export them. This policy explains what that means.
Last updated: September 21, 2026 · Effective: September 21, 2026
1. Who We Are
Skintinel is a consumer photo diary for spots you choose to watch. It is not a diagnostic tool and is not a medical device.
The iOS application and the website at https://skintinel.com (together, the “Service”) are operated under the name Skintinel (“we”, “us”, “our”). For applicable data-protection law we are the data controller of personal data processed as described in this policy. The registered legal entity name, number, and address are TBD and will be added when incorporation is recorded. Until then this notice is incomplete on the identity of the controller.
Privacy requests: hello@skintinel.com. Put “privacy request” in the subject line. We respond within 30 days (or the shorter period required by your local law).
2. Scope
This Privacy Policy is intended to cover:
- the Skintinel iOS app (this version: no account);
- the Skintinel website, waitlist, and related emails;
- in-app purchases processed through the Apple App Store.
It does not cover a clinician, clinic portal, or other destination you send a PDF to. Those parties have their own policies.
Residents of Washington, Nevada, Connecticut, and certain other US states also have a separate Consumer Health Data Privacy notice. That notice is in addition to this policy. We do not claim that Skintinel is incorporated in Washington, Nevada, or Connecticut.
3. On-Device by Default
In the current version of the app, the diary stays on the iPhone. Photos, capture dates, body zone, optional notes you type, and skin-type answers are stored in the app sandbox. They are not uploaded to Skintinel servers. There is no Skintinel account in this version. We do not receive a copy of a photo unless you send it to us yourself.
A photo leaves the device only if you:
- export a PDF or share a file through the iOS Share Sheet (you choose the destination);
- include app data in an iCloud Backup that you have enabled in iOS Settings (see §13);
- later turn on a cloud-storage option. Cloud storage is off and not offered in this version. It will require a separate consent before any photo is sent to us.
We determine the purposes and means of the on-device processing the app performs. That processing still requires consent for health data, even though we do not receive the files.
Capture quality on the device. Before you save a frame, the app can check whether the photograph is usable - focus, angle, and distance. That check runs on the iPhone. It does not identify you. It is not stored as a biometric template. It does not leave the device. It is not an assessment of the spot. A failed check is only a reason to retake the photograph. Under the EU AI Act Article 50 this is an AI system in that narrow sense. It is not diagnostic AI.
4. Data We Process
We process only what is needed to run the diary, take payment through Apple, and operate the website.
A. On your device (health and diary data). This is special-category data under GDPR Article 9, sensitive personal information under the California CPRA, and consumer health data under Washington MHMD and similar state laws. In this version it is stored locally:
- Photos: JPEGs you take in the guided camera or import from your photo library, in the app sandbox - not in Camera Roll unless you export them.
- Spot records: body zone and position, capture dates, and optional notes you type.
- Skin type: an optional, static Fitzpatrick questionnaire. You may skip it. This is not an adaptive medical quiz.
- Consents and preferences: disclaimer acceptance, the three consents in §7, reminder on/off, language.
B. Device permissions. Camera to photograph a spot; photo library only if you import. Reminders use local notifications. This version does not send remote push notifications and does not use Apple HealthKit.
C. Subscription data (Apple). If you buy a plan, Apple processes the payment. Through StoreKit we receive product identifier, entitlement status, and renewal or expiry where Apple provides it. We do not receive your full card number.
D. Website and email. Waitlist or early-access instructions: email, locale, time of request. If you use a website crypto early-access claim (only when that form is shown), we also process the plan, asset, and network you selected, so we can confirm the request. No photos or diary contents on the website.
E. Website analytics (only after you accept the cookie banner): pseudonymous page views, interaction events, device and browser type. No email, name, or health content in analytics events. If you decline, no analytics cookies are set and no analytics events are sent.
F. Website security logs. Host connection data (IP address, user-agent, URL, timestamp) to deliver and secure the site. Not used for advertising.
G. App Store Connect. Apple may give aggregated, privacy-preserving statistics. We do not receive photos or diary contents that way. The iOS app does not include a third-party analytics, attribution, or crash SDK.
5. Data We Do Not Collect or Use
- We do not sell personal data.
- We do not build advertising profiles or use data for behavioural or cross-context advertising.
- We do not use IDFA, AppsFlyer, or an App Tracking Transparency prompt in this version.
- We do not access Apple HealthKit.
- We do not send photos, notes, or skin-type answers to analytics, ads, or crash tools.
- We do not operate a diagnose API and do not produce a risk score, verdict, or traffic-light on a lesion.
- We do not share diary data with insurers, employers, or healthcare providers. A PDF you take to a visit is your disclosure.
6. How We Use Data
- store and display spots you photograph, on this device;
- check on the device whether a frame is in focus and at a usable angle and distance (see §3);
- show two photographs of the same spot side by side, with their dates;
- generate a PDF you can take to a visit, on this device;
- fire local reminders you have turned on;
- honour App Store purchases and restore them on this Apple ID;
- send waitlist, launch, and purchase-instruction emails you asked for;
- understand and improve the website, if you accept analytics cookies;
- secure the website, prevent abuse, and respond to your requests.
We will not use photos to train or improve capture-quality models unless you have given the separate model-improvement consent in §7. That processing is not active in this version even if you opt in; we will not start it without an updated notice.
7. Consents for Health Data
Photos of skin, body-map location, notes about a spot, and Fitzpatrick skin type are health data. Consent is not buried in general terms. Before the first capture, the app asks for three separate, independently revocable consents:
- Process photos on this device - required to store pictures and show two photographs of the same spot side by side. Capture is blocked until this is on.
- Store a copy in the cloud - optional. Off by default. Not offered in this version. Turning the toggle on does not upload photos today. If we later offer sync, we will ask again before health data leaves the device.
- Help improve capture quality - optional. Never used to name or score a spot. Not active in this version.
You can refuse the optional consents and still use the diary. Withdrawing on-device photo consent means you should stop capture and may delete the app or individual spots. Website and email: unsubscribe link or hello@skintinel.com.
8. Legal Bases (GDPR / UK GDPR)
- Explicit consent (Article 6(1)(a) and Article 9(2)(a)): on-device health and diary data. Given by the consents in §7, not by installing the app alone.
- Contract (Article 6(1)(b)): Apple entitlement; waitlist or purchase-instruction emails you requested.
- Legitimate interests (Article 6(1)(f)): securing the website, preventing fraud on early-access claims, and - only after cookie consent where required - pseudonymous website analytics. Not used as a basis for health photos.
- Consent (Article 6(1)(a) and ePrivacy): analytics cookies on the website.
An EEA or UK representative under GDPR Article 27 is TBD. We will appoint one if we offer the Service in those territories as a targeted market.
9. Health Data; Not a Medical Device
We process health data so you can keep a photo history and, if you wish, take that history to a clinician. We do not use it to diagnose, treat, cure, or prevent disease, and we do not infer a risk of melanoma or any other condition.
Skintinel is not a medical device.
- This app does not diagnose your moles or evaluate the risk of melanoma, skin cancer or any other conditions.
- Not a medical device. Not intended for the diagnosis, cure, mitigation, prevention or treatment of any disease.
- This app is not a substitute for a visit to a healthcare professional.
If a spot is changing quickly, bleeding, or itching, see a clinician now. In an emergency, call 911 or your local emergency number.
Skintinel is not a HIPAA-covered entity or business associate. The US FTC Health Breach Notification Rule can still apply. If a breach of personal data we hold requires notice, we will notify affected people and regulators as that rule and other law require.
10. Sharing and Processors
We do not sell personal data. Recipients in this version (website and Apple; the app does not send diary health content):
| Recipient | Country | Purpose | Transfer basis |
|---|---|---|---|
| Apple | USA | App Store, StoreKit, App Store Connect aggregates; iCloud Backup only if you enabled it | Standard Contractual Clauses / Apple terms |
| Resend | USA | Waitlist and transactional email | Standard Contractual Clauses |
| PostHog | USA | Website analytics after cookie consent | Standard Contractual Clauses |
| Google Analytics 4 | USA | Website analytics after cookie consent; Consent Mode v2; no ad personalisation | EU-US Data Privacy Framework |
| Website host | USA | Hosting, delivery, and security logs | EU-US Data Privacy Framework and/or SCCs |
No photo, note, or other diary health content is sent to these services by the current app.
We may disclose data if required by law, to protect a person from serious harm, or in a sale of the operation, with notice.
11. International Data Transfers
Skintinel is operated from outside the EEA and the UK. The registered jurisdiction is TBD. If you submit an email or visit the website, that data may be processed in the United States. On-device diary data is not transferred by us, because we do not receive it.
12. Retention and Deletion
- On-device diary: until you delete a photo, a spot, or the app. Uninstall deletes the sandbox copy on that device. It does not delete an export you made, or an iCloud Backup until that backup expires or you delete it.
- Waitlist and purchase-instruction emails: until you unsubscribe, launch communications finish, or you ask us to delete them. We will not keep an inactive waitlist address longer than 24 months without a fresh lawful basis.
- Analytics: according to the provider's settings, typically 14 months or less for GA4.
- Security logs: typically 30 to 90 days, unless needed longer for an incident.
There is no Skintinel account to delete in this version. Diary: delete spots or the app. Website and email: hello@skintinel.com. We do not hold Path A diary photos on a server, so we cannot and do not promise deletion of server-side scans.
13. Security
The website uses TLS in transit. Diary files live in the iOS app sandbox. iOS applies the operating system's Data Protection to those files when the device is locked.
We do not currently add a separate application-layer encryption scheme. We are not end-to-end encrypted in the messaging sense.
iCloud Backup. If iCloud Backup is on for your iPhone, Apple may include the Skintinel sandbox in that backup. That is a transfer you control through Apple, not a Skintinel upload.
14. Your Rights (GDPR / UK GDPR)
If the GDPR or UK GDPR applies to you, you may:
- access your personal data;
- rectify inaccurate or incomplete data;
- request erasure;
- restrict or object to processing;
- receive a machine-readable copy (portability), where that right applies;
- withdraw consent;
- lodge a complaint with your supervisory authority (in the UK, the ICO; in the EEA, your local authority).
For data that exists only on your device, use the app. For data we hold, email hello@skintinel.com. We will respond within 30 days.
15. California Privacy Rights (CCPA / CPRA)
If you are a California resident, you have the right to:
- know what personal information we collect, use, and disclose;
- request deletion;
- correct inaccurate personal information;
- opt out of sale or sharing of personal information;
- limit the use of sensitive personal information.
We do not sell personal information and we do not “share” it for cross-context behavioural advertising. Sensitive personal information in this version is the on-device diary. We do not use it to infer characteristics for advertising.
To make a request, email hello@skintinel.com.
16. Other US State Health Privacy Laws
Washington, Nevada, Connecticut, and some other states regulate consumer health data more tightly than general personal data. How Skintinel treats that data is set out in the Consumer Health Data Privacy notice. We do not sell consumer health data. We do not geofence healthcare facilities for advertising.
17. Children
Skintinel is intended for adults. It is not directed at children. We do not knowingly collect personal information from children under 16 (COPPA floor: 13). Do not photograph a child's skin with this app unless you are the parent or guardian and the child is old enough under the law that applies to you.
If you believe we have received a child's email or other personal data, contact hello@skintinel.com and we will delete what we hold.
18. Automated Processing and On-Device AI
Skintinel does not use automated decision-making that produces legal or similarly significant effects. It does not classify a spot as malignant, benign, suspicious, or risky.
On-device image analysis checks whether a frame is usable (focus, angle, distance). It does not identify you, is not stored as a biometric template, and does not leave the device. Under the EU AI Act Article 50 this is an AI system in that narrow sense. It is not diagnostic AI.
20. Exports You Start
If you generate a PDF or share a photo, iOS hands the file to the destination you pick. That destination is not our processor for that act. You are disclosing your own health information.
21. Changes to This Privacy Policy
We review this policy at least once a year. If we start collecting diary data onto our servers, add tracking, or otherwise make a material change to health-data practices, we will notify you in the app or by email at least 30 days before the change takes effect, and we will obtain any new consent the law requires. Prior published versions, once this notice is no longer a draft, will be kept as an archive.
22. Contact
Privacy and deletion requests: hello@skintinel.com. Registered entity name and address: TBD.
Consumer health data rights: Consumer Health Data Privacy.