Legal

Privacy Policy

Last updated: November 20, 2025

1. Introduction

SkinAware ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains what we collect, how we use it, and your choices when using the SkinAware mobile app to track dermatillomania episodes.

2. Information We Collect

2.1 Information You Provide

  • Account Information: Email address and display name (required for account login).
  • Health Data: Episode logs (picked/resisted), triggers, body parts, severity ratings, personal notes.
  • Goals & Progress Tracking: Goal titles, target values, completion logs, progress notes, achievement unlocks.
  • Accountability Friends: Partnership invitations, chat messages with accountability partners, friend nicknames (stored locally only on your device), partnership status.
  • Progress Photos: Images you capture to document healing progress. Photo files remain on your device; see Section 4.
  • Subscription/Entitlements: Purchase status (entitlements, product identifier, expiration) via RevenueCat. We do not receive your card details; payments are processed by Apple App Store / Google Play.

2.2 Automatically Collected Information

  • Technical identifiers for purchases: RevenueCat and the app stores may process technical identifiers (e.g., app/user identifiers, platform identifiers) strictly to operate subscriptions, verify receipts, and prevent fraud.
  • Analytics Data (PostHog): App usage events (onboarding step views, screen navigation, feature interactions), device type, OS version, app version. We do NOT collect device identifiers for advertising purposes.

We do not collect: Crash reports, device location, advertising identifiers, or precise device fingerprinting for tracking.

3. How We Use Your Information

  • Provide core app functionality (episode tracking, goals, insights, achievements, accountability partnerships)
  • Sync and back up eligible data across devices (see Section 5)
  • Operate subscriptions: entitlement checks, purchase restoration, anti‑fraud
  • Enable accountability partnerships and secure messaging between users
  • Track goal progress and send achievement notifications
  • Analyze app usage patterns to improve features (via PostHog analytics)
  • Provide customer support

We do not use your data for advertising or ad measurement, and we do not sell your data.

4. Camera & Photos

Why we request camera/media permissions: to let you take/store progress photos.

How we protect your photos:

  • Photo files are stored locally on your device and never automatically uploaded to our servers.
  • We may sync photo metadata (e.g., timestamp and optional notes, not the image file) to enable history across devices.
  • No facial recognition or image analysis is performed.
  • You can delete photos locally at any time within the app.

5. Data Storage and Security

  • Local Storage: Photos, goals, episode data, and chat messages are stored on your device using secure app storage.
  • Cloud Sync: Episode data, badges, goals, goal logs, partnership data, messages, custom options, and photo metadata (not photo files) may be synced to Appwrite.
  • Hosting Region: Appwrite is hosted in Frankfurt, Germany (EU).
  • Encryption: All data in transit uses TLS encryption.
  • Access Controls: Authentication is required for access to your synced data.

6. Third‑Party Services (Processors)

We use service providers to operate the app. They process data on our behalf:

  • Appwrite: Authentication and secure data storage (EU hosting, Frankfurt)
  • RevenueCat: Subscription management and receipt verification (no card details)
  • PostHog: Product analytics and usage insights (US/EU hosting available, no device-level ad tracking enabled)
  • Apple App Store / Google Play: Distribution and payment processing (we do not receive card details)
  • Expo: App tooling and updates (no analytics/crash telemetry is enabled)

We do not share your data with third parties for their own marketing or advertising purposes.

7. Your Privacy Rights

Depending on your jurisdiction, you may have the right to:

  • Access a copy of your personal data
  • Rectify inaccurate information
  • Erase your data (see deletion below)
  • Data portability (export your data from Settings)
  • Object or restrict certain processing where applicable

How to exercise your rights: Email linus@skinawareapp.com or submit the request form at https://forms.gle/bSW1ZKHChCiBh3CGA. We respond within 30 days.

8. Data Retention and Deletion

  • We retain your data while your account is active.
  • You can export data in‑app (Settings → Export Data).
  • Account Deletion: You can delete your account in-app (Settings → Delete My Account), which attempts to delete:
    • Episodes, badges, goals, goal logs
    • Partnerships, invitations, and messages
    • Custom options and photo metadata
    • Local photos and all app data
  • Message Content: Deleting a partnership removes your access to messages but does not delete messages from the partner's view.

If you prefer manual deletion, submit a request via email or the form above. We delete without undue delay and no later than 30 days after confirming your identity, subject to limited backup delays.

9. International Transfers

  • Appwrite data is hosted in Germany (EU).
  • RevenueCat processes subscription data in the United States. Where applicable, we rely on Standard Contractual Clauses or equivalent safeguards for transfers.
  • PostHog may process analytics data in the United States or EU depending on configuration.

10. Children's Privacy

SkinAware is not intended for children under 13. We do not knowingly collect personal information from children under 13. If you believe a child provided information, contact us to request deletion.

11. Medical Disclaimer

SkinAware is a wellness tracking tool and is not medical advice, diagnosis, or treatment. Always consult qualified healthcare professionals for medical concerns.

12. Changes to This Policy

We may update this Policy periodically. We will update the "Last updated" date above. Continued use of the app after changes constitutes acceptance of the updated Policy.

13. Contact

For privacy questions or requests:

  • Email: linus@skinawareapp.com
  • Response time: within 30 days
  • Developer: Amibi AB
  • Address: Tjärhovsgatan 22, 11621, Stockholm, Sweden