Legal

Privacy Policy

Last updated: August 21, 2026PRIV-2026-08-21

1. Who We Are

Operator: Skindex ("Skindex," "we," "us," or "our") is the operator of the Skindex mobile application and related services. For formal or legal notices, a mailing address is available upon verified request to the privacy contact below.

General support: support@skindex.app

Privacy inquiries (rights requests, appeals, GDPR questions): theskindexapp@gmail.com

Privacy controls: skindex.app/privacy-controls

2. Scope

This Privacy Policy applies to personal information processed through:

  • The Skindex iOS app (the "App").
  • Our website and hosted flows linked from the App — including account deletion, privacy controls, password reset, and legal pages.
  • Backend services and databases used to operate accounts, professional workflows, and optional cloud features.

If you connect third-party booking or business tools through Skindex, those providers may process data under their own policies. See Section 8 (Sharing and Subprocessors).

3. Information We Collect

We collect information you provide, information generated through your use of the Services, and limited technical data as described below.

3.1 Account and Identity

  • Credentials and identifiers: email address, password or authentication tokens, user ID, role (for example, client or esthetician), and session data needed to maintain your account.
  • Profile and practice information: name, phone number, business or practice name, professional codes or identifiers you choose to provide, profile photo or avatar, and subscription or plan status where applicable.

3.2 Professional Verification (Estheticians)

Where enabled, we may collect license-related information and documents — for example, license numbers, state or jurisdiction, legal name, and proof uploads — to operate verification workflows. These are sensitive professional records retained as long as needed to operate verification, meet regulatory or fraud-prevention requirements, and as required by applicable law.

3.3 Client–Provider Relationship Data

Depending on your role and features used, the Services may process:

  • Connection data: practice codes and linked account relationships.
  • Consultation and intake responses: skin-related questionnaire fields, goals, routines, and lifestyle information you enter.
  • Treatment and visit records: services, notes, products, and dates entered by you or your provider.
  • Progress entries and comments.
  • Allergies and clinical-adjacent notes you choose to record.
  • Messages and notification metadata needed to deliver in-app or push communications.
  • Internal professional notes where the product allows provider-only fields.

3.4 Photos and Media

With your permission, the App may access the camera or photo library to upload treatment photos, face map images, progress photos, message attachments, or license proof documents. On iOS, the App is configured to select images from your library and capture new photos. It does not add images to your Photos library.

Face Map photos have additional controls described in Section 3.6. A general Client Data Sharing Consent, acceptance of these Terms, or device camera/photo permission does not by itself authorize Face Map processing.

3.5 Voice Notes (Esthetician Features)

With permission, estheticians may record short voice notes (for example, dashboard to-do notes) using the device microphone. These items are stored in on-device storage only and are not transmitted to Skindex servers.

3.6 Face Map and Skin Snapshot (Decision-Support Features)

Decision-Support Only — Not Medical Advice

Face Map and Skin Snapshot outputs are observational decision-support tools only. They are not medical advice, diagnosis, treatment, or guaranteed outcomes. Professional judgment and applicable scope-of-practice rules always apply.

  • Optional and provider-initiated: Face Map is optional. Your connected Provider decides whether to offer or use it; Skindex does not require every Provider to use Face Map.
  • Separate client opt-in: Before Skindex collects, uploads, stores, or processes Face Map photos or related observational signals for a Provider, the Client must separately affirmatively opt in. Accepting general Client Data Sharing Consent or these Terms does not by itself authorize Face Map processing.
  • Provider disclosure and consent duties: Before the first capture, and before a material change to purpose, captured data, or sharing, the Provider must explain whether Face Map will be used, its purpose, what may be captured, how it may be stored or shared, that participation is optional, and how the Client may decline or withdraw. The Provider must document that disclosure, obtain any professional or legally required consent, and confirm the separate Skindex Face Map opt-in is active before capture.
  • Storage and access: When enabled, a Provider may capture or upload Face Map photos through Skindex. Skindex stores those photos in private, access-controlled Supabase Storage and stores related storage paths, annotations, notes, quality information, and observational skin-pattern signals in protected Face Map records. Access is relationship-scoped and may use signed, time-limited URLs. Clients see Face Map records only when their Provider explicitly shares them through the Services.
  • Processing boundaries: Face Map is used only for observational skin-pattern support for professional review. It is not identity recognition, identity matching, surveillance, advertising, public model training, medical diagnosis, treatment, or emergency guidance. In the current production flow, Face Map photos are not sent to OpenAI, RevenueCat, or Sentry. Skindex does not create, upload, or store facial geometry, facial landmarks, face embeddings, face templates, identity vectors, or facial-recognition profiles.
  • Declining, withdrawal, and retention: A Client may decline or withdraw Face Map consent without losing unrelated core portal features. Withdrawal blocks future Face Map capture and processing; it does not automatically erase previously created Provider records that may need to be retained for professional, legal, security, dispute-resolution, or backup-retention purposes.
  • Material changes: If we materially change Face Map's purpose, captured data, or sharing, we will update the applicable privacy and consent disclosures before enabling that changed processing.
  • Skin Snapshot is a derived summary built from information already in your profile — intake fields, visit and progress entries, face map metadata, and allergy notes — and is not a separate standalone upload type.

3.7 Diagnostics and Analytics (Optional — Off by Default)

The App offers toggles for diagnostic error reporting and analytics. Both default to off.

  • Crash and error reporting: Error events and performance transactions are not sent unless you enable "Send diagnostic data" in Settings. See Section 6 for full disclosure.
  • Product analytics: A preference toggle exists for optional usage analytics. No third-party product analytics SDK is active in the current build unless separately disclosed in a future update to this Policy.

3.8 Payments and Subscriptions

If you purchase subscriptions through the App Store, Apple processes payment card data — we do not receive your full card number. We use a third-party subscription management service to manage entitlements and subscription status using platform receipts. A current list of payment subprocessors is available upon request.

3.9 Push Notifications

If you grant permission, we register a device push token to deliver notifications you request (for example, messages or reminders). You can withdraw notification permission at any time in your device Settings.

3.10 Logs and Technical Data

Server and application logs may include IP address, timestamps, device and app version, and error details as needed to secure and operate the Services. Diagnostic tools, when enabled by you, may collect stack traces and performance metadata as described in Section 6.

For licensed-professional decision-support features, we may also process limited account-scoped interaction and outcome records when those features are used. Examples include feature action type, query category, feedback outcomes, visit or progress outcome signals, timestamps, safety and rate-limit events, model and policy version metadata, and technical request fingerprints — used for service operations, security, abuse prevention, audit logging, and bounded quality improvement.

3.11 Decision-Support Service Improvement Data

Skindex may collect and process limited data generated through use of AI Assist, Skin Snapshot, Face Map, intake, progress, and related professional workflow features to improve service quality and safety:

  • Professional-side interaction data: accepted, edited, dismissed, or ignored suggestions; feature actions; query category; feedback signals; safety overrides; rate-limit events; and timestamps.
  • Client-side interaction and outcome data: intake updates, progress check-ins, connected-profile activity, feedback signals, and service outcome indicators.
  • System metadata: model, prompt, policy, and ruleset version; request status; error state; and privacy-preserving technical fingerprints used for security, abuse prevention, deduplication, and auditability.

We use this information to operate the Services, detect unsafe or low-quality outputs, improve ranking and retrieval, test policy changes, identify workflow friction, maintain audit logs, and evaluate whether decision-support features are producing helpful, safe, and explainable results. Where feasible, we minimize, aggregate, de-identify, or pseudonymize this data before review or analysis.

We do not use this data for facial identity recognition, surveillance, cross-context behavioral advertising, or sale of personal information for money. We do not knowingly use raw client photos, free-text notes, or protected health information to train public foundation models unless expressly disclosed, contractually permitted, and legally authorized.

3.12 Open-Source Software

Skindex includes third-party open-source software components used for core app functionality, including optional on-device image analysis. Our engineering policy is to use permissive-license software (MIT, BSD-3-Clause, Apache-2.0) and to exclude copyleft and non-commercial licenses from the default mobile bundle. An open-source notice summary is available upon request at theskindexapp@gmail.com.

4. How We Use Information

We use information to:

  • Provide, maintain, and improve the Services.
  • Authenticate users and secure accounts.
  • Facilitate relationships between clients and licensed professionals — including scheduling, records, and messaging features as offered.
  • Evaluate, test, and improve decision-support quality, safety, retrieval, ranking, prompts, policies, and workflow performance using bounded service improvement data described in Section 3.11.
  • Operate optional verification, billing, and integrations you enable.
  • Send transactional or service-related communications — for example, password reset emails and account notices.
  • Comply with applicable law, respond to lawful requests, and enforce our Terms of Use.
  • With separate opt-in where required: collect diagnostics to fix bugs or analytics to understand aggregate usage.

We do not sell your personal information to third parties. We do not use your personal information for targeted advertising. We do not use client care data to train AI models for third parties.

5. Health and Wellness Disclaimer

Not Medical Advice

Skindex supports professional skincare practice workflows. Skindex is not a substitute for professional medical advice. Face Map and related outputs are observational decision-support only — they are not medical advice, diagnosis, treatment, cure, or guaranteed outcomes. Users and providers remain responsible for compliance with applicable laws and professional standards.

6. Diagnostics Detail

When you enable "Send diagnostic data" (or equivalent) in Settings, the App may send error reports and performance traces to our crash reporting service. The following controls apply in the current build:

  • Default PII collection: Off.
  • Session replay: Disabled.
  • Events and transactions: Dropped unless diagnostics opt-in is active.

A current list of diagnostic subprocessors is available upon request at theskindexapp@gmail.com.

8. Sharing and Subprocessors

We do not sell, rent, or trade your personal information. We may share information with the following categories of service providers, each bound by contractual data protection obligations:

  • Supabase cloud infrastructure and storage: Stores and manages application data, authentication records, and uploaded files, including private Face Map media and protected Face Map records, under access controls appropriate to the Services.
  • AI processing infrastructure: When AI Assist features are used, structured account records are sent to AI processing services to generate decision-support outputs. Face Map photos are not sent to this infrastructure in the current production flow. These services operate under data processing agreements. A current list is available on request.
  • Crash and diagnostics service: Receives anonymized crash reports and diagnostic data when you opt in. Face Map photos are not sent to this service in the current production flow. See Section 6.
  • Subscription management service: Manages entitlements and subscription status using App Store receipts when subscription features are enabled.
  • Push notification infrastructure: Routes push notifications to your device using your device token.
  • App Store and payment processing (Apple): Manages in-app subscriptions and billing. Apple's privacy practices are governed by Apple's Privacy Policy.
  • Integration partners: If you connect third-party booking or scheduling tools, those providers process data under their own policies.
  • Professional advisors and legal authorities: We may disclose information to legal counsel, auditors, or regulators as required by applicable law, court order, or to protect the rights, property, or safety of our users or others.

A current subprocessor list is available upon request at theskindexapp@gmail.com.

9. Data Retention

Retention periods depend on your role, the type of data, and applicable legal requirements:

  • Account data: Retained until you delete your account or we terminate the Services, subject to a reasonable grace period for recovery and backup rotation.
  • Treatment and clinical-adjacent records: May be retained longer where professional or legal recordkeeping obligations apply. Providers are responsible for understanding applicable recordkeeping rules in their jurisdiction.
  • Professional verification documents: Retained as needed for fraud prevention, audit, and regulatory compliance, then deleted or minimized per our internal policy.
  • Face Map media and records: Platform-held Face Map photos and related protected records are retained under the applicable account-deletion process, subject to backup rotation and lawful retention exceptions. Provider-held professional records may remain where professional, legal, security, or dispute-resolution obligations require.
  • On-device data (voice notes and temporary analysis frames): Temporary on-device data is not stored on Skindex servers. Retention is governed by your device and operating system.
  • AI Assist inputs: Not retained by AI processing services beyond what is operationally necessary to return the output, consistent with our data processing agreements.
  • Server logs and optional diagnostics: Retained for security and troubleshooting for a limited period, typically days to months.
  • Financial transaction records: Retained for up to 7 years as required by applicable US tax and financial law, regardless of account deletion.
  • Anonymized aggregate data: May be retained indefinitely where it cannot be linked to any individual.
  • Legal holds: Data subject to pending litigation, regulatory inquiry, or legal hold will be retained until the hold is released.

To request account deletion, visit skindex.app/account-deletion or contact us. Some records may be retained where law, dispute resolution, or legitimate security reasons require.

10. Security

We implement administrative, technical, and organizational measures appropriate to the nature of the Services — including encryption in transit, encryption at rest, role-based access controls, least-privilege design, and documented incident response procedures.

No method of transmission or storage is 100% secure. We cannot guarantee absolute security of your data. If we become aware of a security incident affecting your personal information, we will notify you as required by applicable law. To report a suspected security vulnerability, email theskindexapp@gmail.com with the subject "Security Report."

11. Your Choices and Rights

  • Account settings: Update profile fields where the App allows.
  • Notifications: OS-level controls for push notifications; in-app preferences where provided.
  • Diagnostics and analytics: Settings toggles in the App (both default to off).
  • Face Map: Decline or withdraw the separate Face Map opt-in through available privacy controls or by contacting your connected Provider or Skindex support. Withdrawal blocks future Face Map capture and processing.
  • Account deletion: skindex.app/account-deletion
  • Privacy requests: skindex.app/privacy-controls

11.1 California Residents (CCPA / CPRA)

California residents have the right to:

  • Know what personal information we collect and how it is used.
  • Request deletion of personal information.
  • Request correction of inaccurate personal information.
  • Opt out of sale or sharing of personal information. We do not sell or share personal information for advertising purposes.
  • Limit use of sensitive personal information.
  • Non-discrimination for exercising these rights.

Submit requests at skindex.app/privacy-controls or theskindexapp@gmail.com. We acknowledge within 10 business days and fulfill within 45 calendar days (extendable to 90 with notice).

11.2 Texas Residents (TDPSA)

Texas residents have the right to access, correct, delete, and obtain a portable copy of personal data, and to opt out of targeted advertising, sale of personal data, or certain profiling. We do not engage in these activities.

Submit requests at skindex.app/privacy-controls. We respond within 45 days (extendable to 90 with notice). If your request is denied, you may appeal by emailing theskindexapp@gmail.com with the subject "Privacy Appeal."

11.3 EEA and UK Residents (GDPR)

You may have the following rights under the General Data Protection Regulation:

  • Right of access (Article 15)
  • Right to rectification (Article 16)
  • Right to erasure — "right to be forgotten" (Article 17)
  • Right to restriction of processing (Article 18)
  • Right to data portability (Article 20)
  • Right to object to processing (Article 21)
  • Rights related to automated decision-making (Article 22) — AI Assist outputs always require esthetician review; no fully automated decisions affecting client records are applied without human action.

Contact theskindexapp@gmail.com. Response time: within 30 calendar days (extendable to 3 months for complex requests). You also have the right to lodge a complaint with your local data protection supervisory authority.

12. Children's Privacy

The Services are not directed to children under 13 (or the applicable age in your jurisdiction). We do not knowingly collect personal information from children. If you believe we have collected information from a child, contact us at theskindexapp@gmail.com and we will delete it promptly.

13. International Transfers

Skindex is operated from the United States. If you access the Services from outside the United States, your information may be processed in the United States and other countries where we or our service providers operate. For EEA and UK transfers, we may rely on Standard Contractual Clauses, adequacy decisions, or other lawful transfer mechanisms. Contact us for details on the mechanisms applicable to your jurisdiction.

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated version at skindex.app/legal/privacy and update the "Last updated" date. If changes are material, we will provide additional notice — for example, via in-app notification or email — where required by applicable law. A material change to Face Map's purpose, captured data, or sharing will require updated privacy and consent disclosures before that processing is enabled.

Version History

PRIV-2026-08-21 (v1.6) — August 21, 2026 — Clarified the optional, Provider-initiated Face Map workflow; added separate client opt-in, Provider disclosure, private storage, sharing, withdrawal, retention, and processor-boundary disclosures.

PRIV-2026-08-02 (v1.5) — August 2, 2026 — Updated "last updated" date; cross-linked Privacy Controls, Account Deletion, and Data Compliance pages; no substantive policy changes.

PRIV-2026-05-26 (v1.4) — May 26, 2026 — Expanded professional and client-side service-improvement data disclosure; added voice note, subscription management, and open-source disclosures; expanded Face Map biometric safeguards; restructured legal bases as standalone section; added Texas TDPSA rights; removed specific infrastructure vendor names.

PRIV-2026-05 — May 20, 2026 — Added AI Assist, Face Map on-device, and Skin Snapshot disclosures.

PRIV-2026-04 — April 4, 2026 — Initial published version.

15. Apple App Store

If you use the iOS app:

  • Subscriptions are billed by Apple. Refunds and billing disputes are handled per Apple's policies — visit reportaproblem.apple.com.
  • Apple may collect usage or crash data under their own policies independent of Skindex.
  • App Privacy labels for the Skindex listing on the App Store are maintained to align with this Privacy Policy.

16. Contact

Privacy requests and inquiries:
theskindexapp@gmail.com

General support:
support@skindex.app

Privacy controls and account deletion:
skindex.app/privacy-controls · skindex.app/account-deletion