Compliance

Data, Security & Compliance

Last updated: August 21, 2026COMP-2026-08-21

1. Product Role

Skindex is a professional skincare workflow and decision-support platform. It supports client intake, professional notes, progress tracking, Face Map, Skin Snapshot, AI Assist, and related workflow tools.

All data access is scoped by user role. Professionals can only access records belonging to clients they have approved within their own practice. Clients can only access information specifically shared with them by their connected Professional. No user has access to another user's account or records.

Not Medical Advice — Platform-Wide Notice

No feature of the Skindex platform — including AI Assist, Skin Snapshot, Face Map, and all records and communications — constitutes medical advice, medical diagnosis, or clinical treatment. Skindex is not a medical device. All decision-support outputs require independent professional review by a licensed esthetician before application.

2. What Decision-Support Improvement Means

Some Skindex features improve behind the scenes using limited interaction, workflow, safety, and outcome signals. The system may evaluate how features are used and whether suggestions are helpful, ignored, edited, unsafe, rate-limited, or associated with later feedback or outcomes.

The goal is to improve service quality and safety, including:

  • Better AI Assist responses and more relevant Skin Snapshot context.
  • Safer recommendations and stronger policy gates.
  • Better retrieval, ranking, playbooks, and prompt behavior.
  • Reduced repeated mistakes, duplicate suggestions, and irrelevant outputs.
  • Improved abuse prevention, rate limiting, auditability, and reliability.

This improvement system runs in infrastructure. Professionals and Clients do not need to manually manage it during normal use.

3. Data Used for Improvement

Professional-Side Data

  • Feature actions such as view, accept, edit, reject, dismiss, save, or export.
  • AI Assist query category and workflow context.
  • Professional feedback, corrections, and outcome signals.
  • Rate-limit events, safety events, policy-gate decisions, and errors.
  • Model, prompt, policy, ranking, app, and ruleset version metadata.

Client-Side or Regular-User Data

  • Intake updates, progress check-ins, profile updates, and connected workflow activity.
  • Feedback, preference, and outcome indicators provided through the Services.
  • Client-side feature interactions, timestamps, and technical status where applicable.
  • Safety, support, or account events needed to operate and secure the Services.

Technical Safeguards Data

  • Privacy-preserving request fingerprints for deduplication, collision avoidance, abuse prevention, and auditability.
  • Account or user identifiers needed to enforce access boundaries.
  • Logs and technical metadata needed for security, reliability, and troubleshooting.

4. Data Not Used for Prohibited Purposes

Skindex does not use decision-support improvement data for:

  • Facial identity recognition.
  • Biometric surveillance.
  • Cross-context behavioral advertising.
  • Sale of personal information for money.
  • Circumventing professional judgment or scope-of-practice rules.

Skindex does not knowingly use raw client photos, free-text notes, or protected health information to train public foundation models unless expressly disclosed, contractually permitted, and legally authorized.

5. Role-Based Data Access and Isolation

Access controls are enforced at the application and database level:

  • Professionals — Can create, view, edit, and manage records only for clients who have submitted a connection request via their practice code and whose request the Professional has approved. Professionals cannot access records belonging to another Professional's clients.
  • Clients — Can view only information that their connected Professional has explicitly assigned or shared within the private portal. Clients have no access to other clients' data, messages, records, or identities.
  • AI Assist — Scoped to records within the requesting Professional's own client portal only. AI processing does not cross client or account boundaries.
  • Connection gating — Client access is not automatic. A client must obtain a unique practice code from their Professional, submit a connection request, and receive Professional approval before the portal link is active.
  • Administrators — Have elevated platform-level access for operational, support, and compliance purposes only, bound by internal data access policies and confidentiality obligations.

6. AI Assist and Decision-Support Safety

AI Assist

  • Inputs: Structured records from the Professional's account — including intake forms, profile history, visit history, session notes, routine and product history, and Skin Snapshot evidence. AI Assist does not process raw images.
  • Outputs: Decision-support observations and suggestions, generated for Professional review only. Outputs are not medical advice and may be incomplete, outdated, or incorrect.
  • Human in the loop: No AI Assist output is applied to a client record automatically. All outputs require deliberate Professional action. There are no fully automated decisions affecting client records.
  • Scope limitation: AI processing is limited to records within the requesting Professional's account. AI does not cross client or account boundaries.
  • No training on your data: Client care data is not used to train AI models for third parties or for any purpose outside of generating in-session outputs for the requesting provider.
  • Third-party AI infrastructure: AI Assist uses third-party AI processing services operating under data processing agreements. A current subprocessor list is available upon request.

Skin Snapshot

  • Purpose: Guides Professionals through a structured assessment process, producing structured data records tied to a client's visit history.
  • Outputs are decision-support only: Skin Snapshot results are structured data for Professional reference — not diagnostic findings. Professionals are responsible for independently evaluating all outputs before applying them professionally.

Face Map

  • Provider control and separate opt-in: Skindex provides platform controls but does not decide whether a Provider uses Face Map. The Provider controls its professional use and required client disclosure. Before capture or processing, the Client must separately opt in to Skindex Face Map processing; general Client Data Sharing Consent does not authorize Face Map.
  • Storage and access: When a separately opted-in Client's Provider chooses to use Face Map, the Provider may capture or upload photos through Skindex. Photos are stored in private, access-controlled Supabase Storage; related storage paths, annotations, notes, quality information, and observational skin-pattern signals are stored in protected Face Map records. Client access is limited to records their Provider explicitly shares through the Services.
  • No identity recognition: Face Map is not used for facial recognition, biometric identification, identity matching, or surveillance. Skindex does not create, upload, or store facial geometry, facial landmarks, face embeddings, face templates, identity vectors, or facial-recognition profiles.
  • Decision-support only: Face Map outputs provide observational skin-pattern support for professional review. They are not diagnostic instruments, treatment directions, emergency guidance, or guaranteed results.
  • Processor boundaries: Face Map photos are not sent to OpenAI, RevenueCat, or Sentry in the current production flow, and are not used for advertising or public model training.

7. Privacy and Security Controls

Skindex is designed to apply controls appropriate to the sensitivity of professional and client workflow data, including:

  • Data minimization: We collect only data necessary to operate enabled features. AI Assist processes only structured records — not raw media. Face Map workflow photos may be securely stored when the separate opt-in and Provider-initiated workflow are active; they are not sent to unrelated AI, analytics, advertising, or identity-recognition services in the current production flow.
  • Role-scoped access by default: No data is accessible beyond the user's role scope. Access isolation is enforced at both the application and database layer, not only in the UI.
  • Encryption in transit: All data transmitted between the app and our servers uses TLS 1.2 or higher.
  • Encryption at rest: Stored data is encrypted at rest using AES-256 where supported by our infrastructure.
  • Authentication: User sessions are managed via secure, short-lived authentication tokens. Credentials are never stored in plaintext.
  • Least-privilege access: Internal access to production data is role-restricted and follows least-privilege principles.
  • Pseudonymization and aggregation: Where feasible, service improvement data is pseudonymized, aggregated, or de-identified before review or analysis.
  • Audit logs: Maintained for safety, reliability, and compliance review.
  • Human review: Material changes to prompts, policies, or ranking rules go through controlled evaluation and human review before broad rollout.
  • No advertising data use: Client care data, AI Assist inputs and outputs, and Face Map records are never used for advertising, profiling for third parties, or any purpose outside of operating your account.
  • Deletion by design: Account deletion triggers data removal within 30 days for all personal records, subject to legal holds and retention requirements described in Section 9.
  • Vendor oversight: Third-party service providers operate under data processing agreements and are evaluated for security posture.
  • Vulnerability reporting: To report a suspected security issue, email theskindexapp@gmail.com with the subject "Security Report."

We do not claim any formal certification (SOC 2, ISO 27001, FedRAMP, etc.) at this time. No system provides absolute security. We commit to continuous improvement of our security posture.

8. HIPAA Positioning

Skindex is a software platform for licensed estheticians. Esthetics is generally not a HIPAA-covered healthcare specialty under US federal law; licensed estheticians are not considered covered entities or their business associates under HIPAA solely by virtue of using this Platform.

Skindex does not claim universal HIPAA certification or that every deployment is appropriate for HIPAA-regulated use. Any Business Associate Agreement (BAA) or practice agreement, if separately offered or signed, applies only to its stated parties and scope and does not replace a Provider's own compliance analysis, client disclosures, or professional obligations.

If you operate within a context that may involve HIPAA-covered entities (such as a medically supervised medspa or dermatology-affiliated practice), consult qualified legal counsel to assess your specific compliance obligations before using this Platform for that purpose. Biometric, consumer-health, privacy, and professional-recordkeeping obligations may also vary by jurisdiction. Contact theskindexapp@gmail.com with subject "Compliance Inquiry" for questions.

9. Service Providers and Subprocessors

CategoryPurposeData Involved
Supabase cloud infrastructure and storageStores and manages application data, authentication records, uploaded files, and private Face Map mediaAll app data including profiles, records, images, messages, Face Map photos, and protected Face Map records
AI processing infrastructureAI Assist — generates decision-support outputs from structured recordsStructured account records (intake, visit history, notes, Skin Snapshot data); no raw images
Push notification serviceDelivers push notifications to user devicesDevice push tokens, notification metadata
App Store billing (Apple)In-app subscription billing and entitlement managementUser ID; no card data stored by us
Crash and diagnostics service (if enabled)Error monitoring and crash diagnostics when user opts inAnonymized crash reports, app runtime metadata

All subprocessors are bound by contractual data protection obligations. A current named subprocessor list is available upon request by emailing theskindexapp@gmail.com.

10. Data Retention and Deletion

Data TypeRetention PeriodDeletion Method
Account profile and credentialsDuration of account + 30 days post-deletionAccount deletion request
Client care records and treatment notesDuration of accountAccount deletion request
Skin Snapshot recordsDuration of accountAccount deletion request
Face Map annotations, notes, quality information, and observational signalsDuration of account, subject to professional, legal, security, dispute-resolution, or backup-retention needsApplicable deletion process; Provider records may remain where required
Platform-held Face Map photosDuration of account, subject to backup rotation and lawful retention exceptionsApplicable deletion process
Temporary on-device Face Map analysis framesNot stored server-sideN/A — not transmitted to Skindex servers
AI Assist inputs (sent to AI processor)Not retained beyond output generation per data processing agreementNot retained by AI processor beyond operational use
In-app messagesDuration of accountAccount deletion request
Professional verification recordsDuration of account + reasonable post-closure periodAccount deletion request (may be retained for fraud prevention)
Push notification tokensUntil revoked or account deletedApp uninstall or account deletion
Billing / financial transaction recordsUp to 7 years (US tax law)Cannot be deleted early — legal hold
Anonymized aggregate analyticsIndefinite (non-identifiable)N/A — cannot be linked to individuals

To request account deletion, visit skindex.app/account-deletion/.

A Client may decline or withdraw the separate Face Map opt-in without losing unrelated core portal features. Withdrawal blocks future Face Map capture and processing; it does not automatically erase Provider-held professional records that may be retained under applicable obligations.

11. Human Oversight and Rollout Governance

Behind-the-scenes improvement proposals are evaluated through controlled infrastructure processes before rollout. This includes testing, policy checks, safety gates, feature flags, canary rollout, and human review for material changes.

The system is intended to support better service operation and professional workflows. It is not intended to autonomously make client-care decisions without professional review.

12. California Rights (CCPA / CPRA)

California residents have the following rights:

  • Right to know what personal information is collected and how it is used.
  • Right to delete personal information.
  • Right to correct inaccurate personal information.
  • Right to opt out of sale or sharing of personal information. We do not sell or share personal information for advertising purposes.
  • Right to limit use of sensitive personal information.
  • Right to non-discrimination for exercising these rights.

How to request: skindex.app/privacy-controls/ or email theskindexapp@gmail.com.

Response timeline: Acknowledge within 10 business days. Fulfill within 45 calendar days (extendable to 90 with written notice).

13. Texas Rights (TDPSA)

Texas residents have the following rights under the Texas Data Privacy and Security Act:

  • Right to access personal data we process about you.
  • Right to correct inaccuracies in your personal data.
  • Right to delete personal data we hold about you.
  • Right to obtain a portable copy of your data.
  • Right to opt out of targeted advertising, sale of personal data, or certain profiling. We do not engage in these activities.

How to request: skindex.app/privacy-controls/

Response timeline: Within 45 days (extendable to 90 days with written notice).

Appeals: If your request is denied, appeal by emailing theskindexapp@gmail.com with subject "Privacy Appeal." We respond within 60 days.

14. EEA and UK Rights (GDPR)

EEA and UK users have the following rights under the General Data Protection Regulation:

  • Right of access (Article 15)
  • Right to rectification (Article 16)
  • Right to erasure / "right to be forgotten" (Article 17)
  • Right to restriction of processing (Article 18)
  • Right to data portability (Article 20)
  • Right to object to processing (Article 21)
  • Rights related to automated decision-making and profiling (Article 22) — AI Assist outputs always require Professional review; no fully automated decisions affecting client records are made without human action.

How to request: skindex.app/privacy-controls/ or email theskindexapp@gmail.com.

Response timeline: Within 30 calendar days (extendable to 3 months with notice for complex requests).

Supervisory authority: You have the right to lodge a complaint with your local data protection supervisory authority.

15. Incident Response

  • We maintain a documented incident response plan covering detection, containment, eradication, recovery, and post-incident review.
  • In the event of a data security incident affecting your personal information, we will notify you as required by applicable law — within 72 hours for GDPR-subject incidents, and as soon as reasonably practicable under applicable US state breach notification laws.
  • Breach notifications will describe the nature of the incident, the data affected, likely consequences, and measures taken or proposed.
  • To report a suspected security vulnerability or incident: email theskindexapp@gmail.com with subject "Security Report."

17. Compliance Contact

For data protection, compliance, or privacy-related inquiries:

Skindex
Privacy / Compliance Contact: theskindexapp@gmail.com

For privacy requests and account deletion: skindex.app/privacy-controls/ · skindex.app/account-deletion/

Version History

COMP-2026-08-21 — August 21, 2026 — Clarified the Provider-initiated, separately opted-in Face Map workflow; updated private storage, processor boundaries, retention, HIPAA/BAA positioning, and jurisdictional compliance language.

COMP-2026-05-26 — May 26, 2026 — Added service-improvement data disclosure; added human oversight section; added related pages section; removed specific infrastructure vendor names from subprocessors table; fixed account deletion URL; updated to new document structure.

COMP-2026-05 — May 20, 2026 — Added AI Assist, Skin Snapshot, and Face Map transparency; added privacy-by-design principles; added AI processing infrastructure to subprocessors.

COMP-2026-04 — April 4, 2026 — Initial published version.