Privacy Policy

AnySkin · Last updated 2026-09-18

This policy explains what AnySkin does with your information. The short version is that almost all of it never leaves your phone — and the parts that do are listed below, in full, including the ones that are not flattering.

Your profile, history and chats stay on your phone

This is the design, not a setting you have to find. Your skin and hair profile, your scan history, your saved products, My Shelf, My Routine and every conversation with Ivy are stored in the app on your device, and there is no copy of any of it on our server. The one thing here that leaves the phone is a question you put to Ivy: the message, the conversation so far and a short summary of your profile are sent so it can be answered, and "Where OpenAI comes into it" below is the whole of what happens to them.

That includes the names you give products yourself. If you rename a scan — a product name, a brand, or both — what you type is kept on this phone only. It is not sent to us, nobody else scanning the same bottle sees it, and it survives a re-scan of the same barcode.

There is no account. AnySkin asks what to call you, and that name stays on this phone with the rest of your profile — it is never sent to us. No email address, no password, no sign-in.

The practical consequence is worth being clear about: nobody can hand over your profile, because nobody has it. It also means that if you delete the app or lose the phone, that data is gone — which is why Back up & restore exists in Profile, writing a file you keep yourself.

What our server does hold

The main thing is a shared database of products and ingredients. Barcodes, product names, ingredient lists, our risk ratings and the scores calculated from them. It is the same for everyone, it contains nothing about any person, and it is what makes a scan fast for the next person who scans the same bottle.

The only other thing is a small ledger that counts skin checks per install. It is described in the next section and again under "Deleting everything", and it is named here so this section is not read as saying there is nothing else.

What our server can see when you use it

Being honest about this matters more than sounding clean, so here is the whole list.

Your IP address, because every internet request carries one. It is used to limit how many requests can come from one place, so the service is not run up as a bill by a script. It is not stored alongside anything about you and is not used to work out where you are.

A random device id, created on first launch. It is a counter key for those same limits. It is not derived from your phone, your account or anything else about you, and it identifies a copy of an app rather than a person. Reinstalling produces a new one.

That id is stored in one case, and it is worth naming: the skin check is a free one-per-phone before you subscribe and has a daily ceiling after you subscribe, and neither can be enforced by a counter that forgets every time a server restarts. So we keep the id, two counters — the free check, and how many checks a subscribed install has run in the current window — and three dates. Nothing else is attached to it — no findings, no photograph, no profile, nothing you typed — and nothing else in the app refers to it.

The ingredient list of a product you scan, and the barcode. That is the thing being analysed, and the result is added to the shared database for everyone.

What you type into ingredient search, so the ingredient can be looked up.

Which product and ingredient pages you open, so each can show the latest of what we hold.

What you type to Ivy, plus a short summary of your profile — skin type, hair type, concerns, goals, your avoid list, and whether you have told the app you are pregnant — when it is relevant to answering. If a product page is open when you ask, that product goes too — its name, its brand, its score and a few of its ingredients — so the answer can be about the bottle you are holding. It is sent so the question can be answered and is not stored on our server afterwards.

Services besides ours hear from every copy of the app each time it starts, and they belong on this list too. RevenueCat is asked whether this install has an active subscription; that request carries your IP address and the anonymous id described under "Deleting everything". Expo, which delivers updates to the app, is asked whether there is a newer version; that request carries your IP address, the app version, which update of its code is installed, and a random id Expo creates for this install — not the one described above. If the app hit a fatal error in its first seconds, the next request to Expo also carries that error message. Erase my data changes neither of those ids. The app adds none of your profile, scans, photographs or chats to these requests, and each company’s own policy governs what it keeps. The usage statistics described below go to a third service, PostHog. Crash reporting adds one more of these, and "Crash reports" below is the whole of it: while it is switched on, Sentry is told that a run of the app has started and that it has ended, which is what turns a crash count into a crash rate.

Where OpenAI comes into it

Ingredient analysis and Ivy run on OpenAI models, so the text involved is sent to OpenAI to be processed. For a scan that is an ingredient list off a label. For the skin check it is the one photograph of your face, read for the observations; we do not keep it, and what OpenAI may keep is under "Your camera". For a chat it is your message, the conversation so far, and the profile summary described above.

This is the part a privacy policy is most tempted to bury. Do not read "your data stays on your phone" as meaning nothing is ever sent anywhere — what you ask Ivy is sent to a third party, because that is the only way it can be answered. If you would rather a question did not leave the phone, do not ask it in the chat.

OpenAI processes it to return an answer and, under their API terms, does not use it to train their models. Their own policy governs what they do with it in transit.

Your camera

The camera is used only while the scanner or the skin check is open. A barcode scan sends the number and no picture. It goes to our server, which looks it up in Open Beauty Facts, a public product database, whenever it has no finished record of that barcode. If our server cannot be reached or cannot answer, your phone asks Open Beauty Facts directly, and they see the barcode and your IP address. A photo of an ingredient label is sent so the ingredients can be read from it, and it is not kept afterwards — only the text of the list is.

One more case, and it is the only photograph of a product besides the label that leaves your phone: when nothing we can reach has a brand or a name for the bottle, the picture of the front is sent once so those can be read off it. It is discarded like the label — only the text is kept. The brand goes into the shared record for that barcode: as the brand if there is none, and otherwise as a second opinion that is stored but shown to nobody until another photograph of the same bottle agrees with it, at which point it replaces what was there. The product name is sent back to your phone and kept only there, because it is the field we read wrong most often and nobody else should inherit our mistake. Front photographs of products we can already name never leave the device.

The skin check is a photograph of your face, and it is the most personal thing this app touches, so here is exactly what happens to it. It is taken by you, on purpose, from a screen that explains this first. It is sent to be read, and on our side it is discarded — it is never written to a database, a file or a log, it is never attached to an error report, and on our side there is no copy of it afterwards, ever. Nor on your own phone: the temporary file the camera writes is deleted as soon as the photo has been sent. The one place a copy can outlive the request is OpenAI, which reads the photograph: under their own policy they may keep what is sent to them for up to 30 days for abuse monitoring, after which it is gone.

What is kept is the short list of observations — "mild redness on the cheeks" and the like — and it is kept on your phone, in the same local profile as your quiz answers. One check at a time: a new one replaces the last. There is no history of them, no comparison between them, and no graph, by design and not by omission.

One place they can go, and you are the one who sends them: Profile → Back up & restore writes a file containing your profile, and that includes these observations. The photograph is never in it. Where the file goes afterwards is entirely up to you — we never see it — so treat it the way you would treat any file with something personal in it.

Product images shown in the app come from Open Beauty Facts, the public product database, or are the front photographs you took yourself, which are stored on your phone and deleted with everything else by "Erase my data". A picture from Open Beauty Facts is loaded by your phone from their servers, so they see your IP address and which product it is a picture of.

Your location

Permission to use your location is asked for only in Sun & UV. Once you have given it, your location is read only while the app is open, for Sun & UV and for the UV strip on Home. Your coordinates go to Open-Meteo, a public weather service, to fetch the local UV index, and to Apple’s location service, which turns them into the name of the place you are in.

The latest reading is kept on your phone together with the coordinates it was taken at and that place name. It is reused for an hour and shown for the rest of the day if a new one cannot be fetched, and if your location cannot be read that day, its coordinates are used to fetch a fresh forecast. The next reading replaces it; Erase my data does not remove it. The coordinates never reach our server.

Anonymous usage statistics

This is the one place something is measured, so it gets its own section rather than a line at the bottom.

AnySkin records anonymous, aggregated usage events — that a scan was started, that the quiz was finished, that a screen was opened. It is how we find out where the app is confusing or broken, which we otherwise have no way of knowing.

What that never includes: who you are, what you scanned, any ingredient list, anything from your profile, anything you said to Ivy, and any photograph. Not now and not later — those are conditions on the tool, not current settings.

We never identify you to it. There is no user id attached, because there is no user id to attach. Nothing is captured automatically either: every event is one we wrote by name, so what is sent can be checked by reading the code rather than taken on trust. Session recording is not installed.

The data is processed by PostHog on EU servers.

To be exact about what changed: the strong claim above — that your profile, history, shelf, routine and chats are stored only on your phone — is untouched and is still the design of the app. This section is a smaller thing: we can see that *someone* got as far as the quiz and stopped, without being able to see who or what they scanned.

Crash reports

When the app crashes, a report of the crash is sent so it can be found and fixed. It gets its own section rather than a line in the list above, because a crash reporter is the part of an app most likely to carry your content off the phone by default — and most of this section is those defaults, switched off by name.

What a report contains: the error itself — its type, its message, and the stack trace, which is the chain of functions AnySkin was inside at the moment it failed — along with the version of the app, the build it came from, and the operating system it was running on. Separately from crashes, the app reports that a run has started and that it has ended. That is what makes a crash rate a rate: so many crashes out of so many launches, rather than a number with nothing to divide it by.

What that never includes: no screenshot, and no copy of what was on the screen, so a crash during a skin check or a chat does not photograph it. No trail of what you did beforehand — the log lines, the taps and the request addresses a crash reporter normally attaches are not filtered out of the report, they are never collected: the app throws each one away at the moment it is made, strips any trail off every report it builds itself, and the trail it asks the reporter to hold is zero entries long. No user id, because there is none to attach. Nothing from your profile, no ingredient list, no photograph, and nothing you said to Ivy.

One thing is not switched off, because it cannot be: a report is an internet request, so it carries your IP address to whoever receives it, exactly as every other request described in this policy does. What the app does not do is attach that address, or your device’s name, to the report itself — that setting is off, and so is every other setting named in this section, for every report the app can send. A report the app builds is stripped down to the error before it leaves as well; a crash that stops the app too suddenly for it to build one is packaged by the phone itself and sent the next time you open the app, and there it is those switched-off settings that do the work.

Crash reports are processed by Sentry, on EU servers.

What we do not do

We do not sell your data, share it with advertisers, or build an advertising profile about you.

Brands cannot pay to change an Ingredient Score, and cannot pay for placement.

Deleting everything

Profile → Erase my data clears the profile — the skin-check observations with it — along with your history, saved items, shelf, routine and chats. Deleting the app does the same thing.

What Erase my data does not reach, named here rather than left to be found: the last UV reading described under "Your location", which the next reading replaces; the ids Expo and RevenueCat keep for this install, described under "What our server can see when you use it"; and the copies of product pictures the phone keeps so they load faster.

Erase my data also mints a new random device id for this phone, and that matters because of the one row on our side that is about a phone rather than a product: the skin-check ledger described above. We do not delete that row. It holds only counters and dates, and after an erase it is filed under an id your app has stopped sending.

Beyond that there is nothing of yours in our own systems to delete. The shared product database records that a barcode was scanned, not who scanned it.

Your subscription is the one thing neither of us can erase, and it is worth saying whose it is. Apple takes the money and holds the purchase. RevenueCat — the service we use to ask Apple whether a subscription is still active — keeps a record of it against an anonymous id it generates for the install, never a name or an email, because we never collected one to give it.

Your rights

If you are in the EU or UK, the GDPR gives you rights over personal data held about you — access, correction, export, erasure, and objection to processing.

Those rights are satisfied by the app's design rather than by a request process: the personal data is on your device, under your control, and we hold no copy of it to produce or erase. The exceptions are named above: under *Deleting everything*, the skin-check ledger, which an erase disconnects this phone from rather than deleting, and the subscription record Apple and RevenueCat hold; and under *What our server can see when you use it*, the ids RevenueCat and Expo receive each time the app starts. If you think that is wrong, or you want to ask about it, write to jetunitbusiness@gmail.com.

Children

AnySkin is not intended for children under 13, and collects nothing that would identify one.

Who is responsible, and how to reach us

AnySkin is responsible for the app and this policy. There is one contact route and a person reads it: jetunitbusiness@gmail.com.

Changes

If this policy changes in a way that affects you, we will say so in the app rather than quietly updating the date at the top.