1. Overview
Skintel helps you record products, routines, actual use, subjective skin check-ins, and your own history. We do not sell personal information or use HealthKit data for advertising.
This Privacy Policy applies to the Skintel iOS application, skintel.app, and related services (together, the “Service”). Skintel is operated by CodesWhat (“Skintel,” “we,” “us,” or “our”). CodesWhat is the controller of personal data processed under this policy unless another party is identified at the point of collection.
You must be at least 18 years old to use the Service. Optional HealthKit, weather, reminders, and product analytics can be declined without losing the core manual tracking features.
2. Data we collect
| Category | Examples | Source |
|---|---|---|
| Account data | Automatically generated guest account ID; email address, sign-in provider, and optional display name only if you connect Apple or Google | Skintel; you; Apple or Google sign-in if connected |
| Profile and check-in data | Skin type, appearance concerns, known sensitivities, optional declared states, subjective daily ratings, context tags, and private notes | You |
| Products and routines | Your Cabinet, private custom products, sourced catalog facts, product status and sentiment, planned routines, and products marked used | You; attributed product-catalog sources |
| HealthKit data, if connected | Sleep duration, heart-rate variability, menstrual context, and workout duration | Apple HealthKit, with your permission |
| Weather context, if connected | Derived temperature, humidity, and UV values saved with a check-in | Apple Core Location, geocoding, and WeatherKit services |
| Product analytics, if enabled | A random app-generated identifier, app/build version, and a small allowlist of coarse completion, reliability, and feature-interaction events | Your use of the app |
| Technical and support records | Request timestamps, app version, security logs, and messages you send us | Your device; service providers; you |
Skintel automatically creates a guest account when you start tracking. It has a unique owner ID but no email address. The credential that opens this guest account lives on your device, so access may be lost if you delete or reinstall the app or move to a new device. You can recover your progress by connecting the guest account to Apple or Google before that happens.
The first external TestFlight does not collect or process face photos, does not request camera permission, does not create an automated face score, and does not send user data to an AI model provider. Product-photo recognition, generated guidance, community claims, personal-pattern conclusions, and paid features are also unavailable in this build.
3. How we use data
We use the information described above to:
- Create and secure your account.
- Save and edit your Cabinet, routines, check-ins, actual use, and factual history.
- Prepare device-local reminders and user-directed CSV or PDF exports.
- Show optional HealthKit and derived weather context with your own entries.
- Resolve attributed product-catalog searches and barcode lookups.
- Measure coarse beta activation, reliability, and retention when analytics is enabled.
- Prevent abuse, investigate failures, support deletion, and comply with law.
Using the tracking beta does not grant permission for raw-selfie training, evaluation, model improvement, deidentified face-metric contribution, or another future research program. A materially different program would require separate review, notice, and any affirmative choice required by law before it begins.
4. Optional HealthKit and weather context
Apple HealthKit
HealthKit access is optional and controlled through Apple’s permission settings. Skintel reads only the data types you authorize to add private context to your check-ins. We do not use HealthKit data for advertising, marketing, data-broker services, cross-context tracking, or model training. Revoking Apple Health access stops future reads but does not delete values already imported into your account; account deletion removes those live records.
Weather
If you choose current-location weather, Skintel requests When In Use location permission and refreshes context while you use the app so it can follow travel. You can instead enter a city/state or ZIP. That saved query stays in local app storage. Apple services resolve both options on the device, and raw coordinates are not sent to the Skintel backend or product analytics. Only bounded derived weather values are saved with a check-in.
5. Product analytics
When product analytics is enabled, Skintel sends PostHog a random app-generated identifier and allowlisted coarse events such as onboarding completion, product-add method and outcome, first routine creation, check-in success or failure, reminder setup, export completion, and feedback entry. The app caps this at 30 events per device per month.
Analytics does not include your account ID, email, product or barcode value, private note, concern or allergy selection, HealthKit value, location or weather query, exported content, photo, prompt, or model response. PostHog is configured to anonymize IP addresses and not create person profiles. You can turn analytics off in the app; sign-out and account deletion rotate the random identifier.
7. Retention and deletion
Live account and tracking data are retained while your account is active unless a shorter product or legal rule applies. In-app account deletion requires exact confirmation; Apple- or Google-connected accounts also require recent authentication. You can delete a guest account directly while its valid session remains on your device. Deletion removes the live Auth account, profile, entries, routines, Cabinet, and other owner-linked rows and objects. A content-free deletion audit may retain a protected one-way identifier, status, timestamps, failure category, and object count so a deletion can be verified and replayed safely.
Encrypted disaster-recovery backups and provider security logs may retain deleted records for their limited backup or security lifecycle and are not used for ordinary product access. Restored backups must have completed deletions replayed before serving traffic. Anonymous PostHog events follow the project’s configured retention. Contact us for the current retention details or to make a privacy request.
8. Your choices and privacy rights
You can decline or later disable optional Apple Health access, weather configuration, reminders, and product analytics. You can export your tracking history or delete your account in the app. Depending on where you live, you may also have rights to access, know, correct, delete, restrict, or appeal a decision about personal data and to use an authorized agent. We will authenticate requests and will not discriminate against you for exercising a privacy right.
9. Security, incidents, and children
We use row-level access controls, least-privilege server functions, encryption in transit and at rest, bounded inputs, dependency controls, security scans, and deletion safeguards. No system is perfectly secure. We investigate incidents and provide notices required by applicable law.
Skintel is not offered to anyone under 18. We require an affirmative 18+ attestation and do not intentionally collect a birthdate. Contact us if you believe a minor has created an account.
10. Changes and contact
We will update this policy before adding a materially different collection, sharing, image-analysis, training, or consumer-health-data purpose and will obtain a new choice where required. Questions, privacy requests, or complaints can be sent to CodesWhat, operator of Skintel, at hi@codeswhat.com. Please include “Skintel Privacy” in the subject line.