Privacy Policy
Effective September 1, 2026
Dermasync, Inc. Privacy Policy
Dermasync is committed to your privacy and utilizes various protections intended to safeguard your data transmission and storage. All Member Consumer Health Data is encrypted and only you hold the decryption key. Below you will find our complete Privacy Policy. Thank you for taking the time to read it.
Privacy Policy Summary
This summary provides a plain-language overview of how Dermasync handles your personal information and data connected with your use of Dermasync. This summary does not replace the full Privacy Policy below, which controls if there is any inconsistency. Please read this Privacy Policy together with our Terms of Service Agreement. Initial capitalized words are defined in and have the meanings described to such terms in the Privacy Policy below.
1. Introduction
Dermasync, Inc., a Delaware corporation ("we," "us," or "Dermasync") respects your privacy and is committed to protecting the privacy, confidentiality, integrity, and security of your personal information. This Privacy Policy explains what categories of personal information we collect, how we process and use personal information, when personal information may be disclosed, how we work to protect personal information, and what rights may be available to you under applicable law.
Dermasync is a skincare guidance platform that uses a deterministic, rules-based recommendation engine — supported by AI-assisted phrasing, as described in Section 9 — to base suggestions on menstrual-cycle tracking information and certain other information that you provide or authorize to be provided to us. Our Services include our mobile applications, websites, social media pages, email communication, and customer support offerings (the "Services"). The Services provide skincare education, routine support, menstrual-cycle tracking (including cycle and symptom logging, phase identification, and period and ovulation indicators), and personalized skincare guidance based on information you submit and features you authorize.
For purposes of this Privacy Policy, the following terms will have the following meanings:
Consumer Health Data has the meaning provided under applicable consumer health data laws. It may include information relating to menstrual-cycles and symptoms, medications, allergies, pregnancy status, health and wellness observations, and similar types of health and wellness information. Consumer Health Data does not include de-identified, aggregated, anonymized, or publicly available information that does not include information that identify, relate to, or can be reasonably linked to an individual, household, or device — and to the extent excluded by applicable law.
Health Data means Personal Information that relates to or can reasonably be linked to an individual's physical or mental health, including health conditions, symptoms, treatment, medications, reproductive health, menstrual-cycles, fertility, pregnancy, biometric or genetic information, and use of health-related products or services. It includes information you provide or authorize, such as skincare information, wellness observations, and Apple HealthKit data. Health Data may include Consumer Health Data where applicable under law. Health Data does not include de-identified, aggregated, anonymized, or publicly available information that does not include information that identify, relate to, or can be reasonably linked to an individual, household, or device and to the extent excluded by applicable law.
“Personal Information” means information that identifies, relates to, or can reasonably be linked to an individual, household, or device, directly or indirectly, as applicable under law. Personal Information does not include de-identified, aggregated, anonymized, or publicly available information that does not include information that identify, relate to, or can be reasonably be linked to an individual, household, or device and to the extent excluded by applicable law.
2. Application of Policy; Geographic Scope
This Privacy Policy applies to Personal Information you provide or authorize us to collect or process, or that is generated in connection with your use of the Services, including the App, software, websites, online services, customer support services, beta testing programs, research, analytics, product evaluation, product improvement activities, and any other services, features, or offerings that link to or expressly incorporate this Privacy Policy.
The Services are directed to and made available only to Members located in the United States, although the Services may not be available in every state at this time. Dermasync does not currently provide the Services to residents of the European Union, United Kingdom, or European Economic Area or certain states in the United States. The Services are not currently offered to residents of Washington State. If that changes, we will update this Policy and our Consumer Health Data Privacy Policy before making the Services available to residents in Washington. If you access the Services from outside the United States or from a state where Dermasync is not currently available, you do so on your own initiative and are responsible for complying with applicable local laws.
3. Subscription-Based Business Model; No Data Broker Status
Dermasync is first and foremost a subscription-based service. Our revenue comes primarily from Member subscription fees. We do not sell, license, rent, or otherwise commercialize your identifiable Personal Information including Health Data and Consumer Health Data, such as reproductive health data or menstrual-cycle data, and we do not participate in data brokerage activities. Dermasync is not registered as a "data broker" under California Civil Code §1798.99.80 or any similar state data broker registry statute, and we do not meet the statutory definition of a data broker.
4. Privacy Principles
Data Minimization. We collect Personal Information only to the extent reasonably necessary to enable and improve the Services or as may be required by applicable law.
Purpose Limitation. We use and process Personal Information only for purposes disclosed in this Privacy Policy, purposes compatible with these disclosures, purposes you authorize, or purposes permitted or required by law.
Security by Design. We incorporate reasonable administrative, technical, organizational, and physical safeguards into the Dermasync platform to protect Personal Information against unauthorized access, acquisition, disclosure, alteration, misuse, loss, or destruction.
Encryption by Default. We apply encryption and other technical protections to Health Data, including menstrual-cycle data and health and wellness information Members share or authorize to share with us. Encryption occurs at transit and at rest. This includes all Health Data Members provide or have authorized to import and provide to us through Connected Service provider Apple HealthKit.
Member Control. We provide in-app mechanisms to enable Members to manage consents, export their data, delete their data, change their onboarding data, and set and modify account settings (such as communications and marketing preferences and in-app push notification reminders).
5. Categories of Information We Collect
You must affirmatively acknowledge that you have read, understand, and accept this Privacy Policy and Consumer Health Data Privacy Policy, and have received the outline of State-level Consumer Health Data Protections included in the Consumer Health Data Policy before we can set up a personal Dermasync account for you or before we can collect any Personal Information from you.
We process the following general categories of information, depending on how you use the Services, what information you provide, and which features you enable.
A. Account Data
“Account Data” is data or information that is reasonably needed to create, maintain, and administer your Dermasync personal account. Account Data may include the name you wish use (it does not have to be your legal name), an email address that you wish to use, account identifiers, subscription selections and billing status, communication preferences, consent records and privacy setting selections, account settings, and audit and recovery records used to document privacy consents and requests. Account Data does not include Health Data or Consumer Health Data, such as menstrual-cycle data, reproductive health information, symptom information, medication or allergy information, pregnancy information, data from Apple HealthKit or other Connected Services, or personal photographs.
We do not receive, collect, or maintain payment account or credit or debit card information or bank account numbers. You payment of fees and charges are processed by third-party payment processing Service Providers selected and utilized by you, and all payment information is collected, processed, and stored by the third-party payment processing Service Providers under their own terms.
Login by you to your personal Dermasync account and to use Dermasync’s Services is passwordless through sign-in with Apple, Google sign-in, or a one-time email code. We do not enable access through or store a Member Dermasync password.
Other than for age eligibility purposes described in Section 6, we do not ask for or maintain Members' dates of birth or age unless required by applicable law or necessary for verification in accordance with this Privacy Policy or fraud-prevention purposes.
B. Usage Data
“Usage Data” is data and information about how you interact with the Services, our websites, mobile applications, emails, advertisements, social media pages, and related digital properties. Usage Data may include device and browser information; app, website and social media events, pages or screens viewed; referring and exit pages; clickstream data; session information; feature interactions; subscription status; campaign identifiers; advertising identifiers where permitted by law and platform settings; approximate location derived from IP address; precise device geolocation if you enable Precise Weather; social media engagement metrics such as likes, shares, opens; diagnostics, crash reports, performance data, and similar technical or engagement information. Usage Data does not include your Health Data or Consumer Health Data, such as menstrual-cycle data, reproductive health information, symptom information, medication or allergy information, pregnancy information, data from Apple HealthKit or other Connected Services, or personal photographs.
We and our Service Providers may use Software Development Kits (SDKs) and similar technologies to operate the Services, support authentication and security, perform analytics, measure app and website engagement, diagnose crashes, monitor performance, evaluate feature usage, support product development, measure subscription funnels, and understand advertising and marketing effectiveness. We do not permit these technologies to collect or receive Health Data or Consumer Health Data such as menstrual-cycle data, reproductive health information, symptoms, medications, allergies, pregnancy information, data provided by Apple HealthKit or other Connected Services, or personal photographs. Our Services may use SDKs to facilitate our offering to you. No Health Data or Consumer Health Data is ever shared with SDKs. SDKs are implemented by Dermasync in accordance with governing laws and disclosed consistent with this Privacy Policy.
C. Health Data (Including Menstrual-Cycle Data)
Health Data including menstrual-cycle tracking are used by Dermasync to provide personalized cycle-aware skincare routine suggestions and educational information. The Health Data used for the Services may include:
- Skincare information: skin type (including Fitzpatrick skin-type classification, shade, and likelihood of sunburn, and whether your skin is oily, combination, or dry), skin tone, skin history, sensitivity, skincare concerns and conditions, the day-to-day skin status you log (such as oily, dry, bumpy, acne, redness, or other skin observations), sun reaction, and medications;
- Menstrual-cycle and reproductive information: menstrual-cycle dates, period start and end dates, cycle length, menstrual flow information, period and ovulation indicators, hormonal phase information, contraceptive method and use (including hormonal birth control), pregnancy status, lactation status, and perimenopause and menopause status, including irregular or absent periods, and other reproductive health history you choose to provide;
- Symptoms and wellness observations: mood, energy, amount of sleep, basal and wrist temperature, alcohol consumption, sugar consumption, diet, hydration, stress level, exercise or physical activity (including whether you have worked out or expect to sweat), cramps, headaches, and other Member-logged symptoms;
- Allergies and product sensitivities: allergies or known sensitivities to skincare active ingredients or products, and any patch-test or reaction results you choose to log;
- Product and ingredient information: the skincare and cosmetic products, ingredients, or barcodes you search for, scan, or select from Dermasync's in-house product and ingredient database (built from a combination of purchased industry product and ingredient data together with Dermasync's own development and curation). These searches, scans, and selections are processed by Dermasync's own systems — not shared with any outside company — to return matching product and ingredient information for your Product Shelf; and
- Imported information: information you authorize us to import from Connected Services such as Apple HealthKit, and local weather and UV Index data provided by Apple WeatherKit or Open-Meteo. Weather services receive only an approximate location unless precise location is accepted in permissions — and they never receive Health Data or Consumer Health Data.
Your control over information and data. While menstrual-cycle tracking is needed to enable Dermasync to provide personalized cycle-aware skincare suggestions and information, you decide what cycle data you enter, provide, or authorize to provide to us. If you do not provide or authorize the import of menstrual-cycle data, the Services will still provide a more basic skincare experience including general education and routines. But menstrual-cycle-personalization of menstrual-phase-based skincare guidance and period and ovulation indicators will not be available and cannot be provided by the Services.
Photographs. Your personal photographs to document your user journey are purely optional. In the current Dermasync platform, personal photographs are only stored on your personal device. We do not see, have access to, analyze or store your photographs. If the collection or storage of your personal photographs by us is added in the future, we will update this Privacy Policy before that feature becomes available. Because Dermasync currently does not store or have access to your photographs, your photographs cannot be used by us to create facial-recognition templates, facial geometry maps, retina or iris scans, voiceprints, or other biometric identifiers as those terms are defined under applicable biometric privacy laws.
D. Information From Connected Services
With your permission and authorization, certain Health Data and other Personal Information is provided to us from connected services provided by third parties, such as Apple HealthKit, a weather data provider (Apple WeatherKit or Open-Meteo), or similar digital personal information storage services ("Connected Services"). Connected Services are separate from and are not affiliated with Dermasync. Your Health Data that is shared with us from Apple HealthKit is encrypted and inbound only. We do not share any Personal Information, including Health Data or Consumer Health Data with Apple HealthKit.
We use the Personal Information you authorize to be obtained from Apple HealthKit, Apple WeatherKit or Open-Meteo, or similar Connected Services to provide the core offering of our Services: cycle awareness and personalized insights and routines synced to your cycle and local environment (weather). We do not sell or use Personal Information from Apple HealthKit, weather data providers, or similar Connected Services for third-party advertising, or otherwise processed except as described in this Policy, the applicable Connected Service requirements, and applicable law.
6. Age Eligibility and Children's Privacy
The Services are intended only for members who are 18 years of age or older. We do not knowingly permit registration or use of the Services by individuals under the age of 18. Members must provide an age eligibility attestation confirming that they satisfy the minimum age requirement. Unless required by applicable law or necessary for age verification or fraud prevention, we do not store your date of birth or age. If we become aware that we have collected Personal Information from an individual under the age of 18, or in violation of applicable law or this Policy, we will take reasonable steps to delete the information or otherwise comply with applicable legal requirements.
Children Under 13 (COPPA). The Services are not directed to children under the age of 13, and we do not knowingly collect personal information from children under the age of 13 with respect to the Children's Online Privacy Protection Act (COPPA).
Consumers Under 16 (CCPA). We do not knowingly sell or share the Personal Information of consumers under the age of 16 with respect to the California Consumer Privacy Act (CCPA).
7. Privacy-by-Design Architecture
Dermasync is designed to restrict access to Health Data, including menstrual-cycle data, and to limit the extent to which Health Data is accessible to our personnel, Service Providers, or other third parties.
Field-Level Encrypted Information. Health Data, including menstrual-cycle data, is encrypted in transit and stored only as ciphertext. Metadata relating to non-Health Data such as your account identity, record type, record keys, timestamps, and other non-Health Data Account Data and Usage Data may remain readable to us in order to facilitate the Services and other purposes.
Member Photographs. In Dermasync's current platform design, your personal photographs, if you choose to retain them, are stored only on your personal device and are not provided to, seen by, or stored by us. Dermasync does not have access to your personal photographs.
Operational Information. Certain Personal Information (but not Health Data) remains accessible to Dermasync to be able to operate the Services, including usage names you provide, email address you provide, account identifiers, subscription information, billing status, customer support communications, consent records, audit logs, security logs, and regulatory compliance records.
8. How We Use Information
We may use Personal Information to:
- Provide personalized cycle-aware skincare insights, suggestions, routines and reminders synchronized to your menstrual-cycle, health, lifestyle, environment, and weather information you have provided or authorized.
- Provide menstrual-cycle tracking features, including logging periods and symptoms, identifying cycle phases, indicating possible period and ovulation windows, and generating cycle history summaries;
We may also use information to create and manage your account, process subscriptions, authenticate your Member status, maintain platform functionality, provide technical support, administer the Services, detect fraud, prevent misuse, investigate security incidents, protect your interests and the interests of other Members and our systems, enforce our terms and policies, respond to your inquiries, improve your experience, comply with legal obligations, preserve records, resolve disputes, and protect legal rights.
We may conduct internal research, analytics, and service improvement using aggregated, masked, or de-identified information. We do not sell, license, or commercialize any identifiable Personal Information, including Health Data and menstrual-cycle data, for research purposes.
We may also use Usage Data and Account Data to evaluate app performance, website traffic, app and website engagement, feature usage, customer acquisition, subscription funnel performance, advertising effectiveness, attribution, email and push campaign performance, referral campaign performance, remarketing or retargeting for Dermasync products and services, and other marketing analytics, subject to applicable law, platform rules, and available privacy choices. We do not use Health Data or Consumer Health Data, such as menstrual-cycle data, reproductive health data, symptoms, medications, allergies, pregnancy information, HealthKit or Connected Services data, or personal photographs for these purposes.
9. Artificial Intelligence; Automated Decision-Making
Dermasync’s personalized skincare guidance, menstrual-cycle-aware suggestions, and cycle indicators are generated by a deterministic, rules-based engine — a predefined set of decision trees that maps your information to suggestions according to fixed, auditable rules — that does not use artificial intelligence or machine learning and is not trained on or changed by your data.
Separately, Dermasync uses artificial intelligence, in the form of a third-party large language model ("AI"), to phrase the wording of already-determined suggestions and educational content in clear, approachable language, informed by a curated library of evidence-based frameworks drawn from peer-reviewed dermatological and cycle-science literature. It is not designed to independently search the open internet, does not independently make personalization decisions, and operates subject to internal content guardrails that block medical-claim and other prohibited language before it reaches you.
Dermasync’s AI phrasing layer is provided by a third-party AI provider (Anthropic) that only receives a routine step, a time of day, an ingredient name, and one educational sentence identical for every Member who receives that suggestion, together with any supporting research citations — never any raw cycle data, symptoms, health conditions, or other Health Data that identifies you.
Suggestions, menstrual-cycle indicators, and personalized content provided to you by the Services — including the deterministic engine’s suggestions and their AI-assisted phrasing — are informational only. The Services provided by Dermasync to you or other Members do not produce legal effects concerning Members or similarly significant effects on Members, as those concepts are used under applicable privacy laws. Menstrual-cycle indicators are estimates based on your information and only such information that you choose to provide or authorize to provide, and thus should not be relied upon for contraception, fertility planning, or medical decisions. You may update or change personalization features, or delete or export your Health Data or Consumer Health Data in your personal Dermasync account profile of the mobile application at any time. If you do not provide us with your menstrual cycle data or consent to the use or sharing of such information, the Services platform cannot provide you with personalized features tied to your menstrual cycle. Similarly, if you do not authorize or remove consents to connect to local environment (weather), personalized skincare guidance related to weather, humidity, or UV Index cannot be provided.
10. No Medical or Health Advice; Non-HIPAA Status
Dermasync does not provide medical or healthcare advice, diagnosis, treatment, or healthcare services of any kind, including with respect to menstrual, reproductive, or fertility health. We do not use AI technologies to diagnose medical conditions, provide medical treatment, or replace advice from qualified healthcare professionals. The Services, including the menstrual-cycle tracking feature, are not intended to be, and should not be interpreted as, a medical device, a contraceptive tool, a fertility diagnostic, or a substitute for professional medical advice, diagnosis, or treatment. You should consult a qualified healthcare professional regarding any medical concerns, symptoms, conditions, medications, allergies, pregnancy-related matters, or other health-related questions.
Non-HIPAA Status. Dermasync is not a "covered entity," "business associate," or "subcontractor" under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), and the Services are not HIPAA-regulated. Consumer Health Data, including menstrual-cycle data, is protected by this Privacy Policy, our standalone Consumer Health Data Privacy Policy, and applicable consumer health data laws, not by HIPAA.
11. No Sale of Personal Information; No Targeted Advertising Using Health Data
A. No Sale of Personal Information (including Health Data)
We do not sell your identifiable Personal Information, your Health Data, or your Consumer Health Data, including your data or information relating to reproductive health, menstrual-cycle, pregnancy, health and medical symptoms, medication, allergy, photographs or images, wellness, or health data. Some of this information may be maintained on your personal device or are otherwise encrypted as described elsewhere in this Privacy Policy. We do not participate in data brokerage activities and do not monetize identifiable Member Health Data.
At account creation, we ask every Member for affirmative consent to include their information in aggregated, anonymized, or de-identified data sets (data devoid of any identifiable Personal Information — including Health Data or Consumer Health Data). We obtain this consent now so that such data sets are available to us if we later choose, in our sole discretion, to sell, license, or share them — including with academic researchers, research institutions, commercial partners, or in connection with a financing, acquisition, or similar transaction. We do not currently sell, license, or share any such data set, and we may never do so. If we do, the data set will be built only from information collected under this consent, and computed in a manner consistent with the encryption and privacy-by-design commitments in Sections 4 and 7. Where we de-identify personal information, and consistent with California Civil Code §1798.140(m) and analogous state laws, we will take reasonable measures to ensure that the information cannot be associated with, or reasonably linked to, a Member, directly or indirectly. We commit through this Policy to maintain and use the information only in de-identified form and not attempt to reidentify it.
B. No Targeted Advertising Using Health Data
We do not use Personal Data, including Health Data and Consumer Health Data, such as reproductive health information, menstrual-cycle information, symptom information, pregnancy information, medication information, allergy information, HealthKit or other Connected Services data, and personal photographs, for targeted advertising, behavioral advertising, cross-context behavioral advertising, retargeting, remarketing, advertising audience creation, lookalike audiences, marketing attribution, advertising profiling, third-party marketing campaigns, marketing third-party products or services, or disclosure to advertising networks, pixels, SDKs, data brokers, attribution platforms, social media advertising systems, or other third parties for advertising or marketing purposes. We use Usage Data and Account Data (which does not include Health Data or Consumer Health Data) for digital use measurement, analytics, attribution, and remarketing for Dermasync products and services, subject to applicable law and your privacy choices.
12. Member Communications, Personalization, and Marketing
A. Categories of Communications
Current communications methods that we utilize include (1) push communications to you on your personal device, such as morning and evening skincare routine reminders and (2) email communications to you for customer service, security, account administration and promotional purposes, as well as for purposes relating to product experience messages, referral invitations, research invitations, or beta invitations. Push communications in-app and email communications that we send to you do not require us to send or disclose your Health Data to a third-party service provider. We will implement and disclose communication channels consistent with applicable law. Your consent to accept email communications can be revoked at any time. We do not provide cell phone text or short message service (“SMS”) communications at this time, and if we add SMS communications in the future, your consent will be required and can be revoked at any time.
B. Data Used
To make Dermasync relevant and useful to you (personalized), we use Account Data, Usage Data, and Health Data you provide or authorize to operate and provide the Services. We may use Usage Data and Account Data (which does not include Health Data or Consumer Health Data) to market Dermasync products and services, measure campaign performance, create or measure advertising audiences, conduct attribution, and conduct remarketing or retargeting for Dermasync products and services, subject to applicable law, platform rules, and available privacy choices. We do not use Health Data or Consumer Health Data (including menstrual-cycle data, reproductive health data, symptoms, medications, allergies, pregnancy information, Apple HealthKit or other Connected Services data, or personal photographs) for marketing, advertising, attribution, remarketing, retargeting, advertising audience creation, or lookalike audiences.
C. Channels and Consent
For any marketing email communications we send to you, we will do so in compliance with applicable law, including the U.S. Controlling the Assault of Non-Solicited Pornography and Marketing Act (CAN-SPAM Act). If we offer marketing text messages in the future (we currently do not ask for or store cell phone numbers), we will send text messages only with your prior consent as required by the U.S. Telephone Consumer Protection Act (TCPA) and applicable state laws.
D. Opt Out
You can set or change your marketing and communications preferences in your in-app Profile at any time. You also can opt out of receiving email communications at any time by selecting the unsubscribe link in the email. If SMS is started, you also can reply "STOP" to cell phone text messages or SMS to opt out at any time. Opting out of Dermasync email communications for marketing purposes does not affect communications from us to you regarding transactional or service purposes.
E. Referral Programs
If you refer another individual to Dermasync, we process the referred individual's contact information solely to deliver an invitation to the Services and administer any applicable referral benefit.
13. Cookies, SDKs, and Similar Technologies
A. Cookies and Web Technologies
On our websites and browser-accessible portions of the Services, we and our Service Providers may use cookies, local storage, and similar web technologies for strictly necessary functions to operate such technologies, functional preferences, aggregate analytics, marketing, and advertising. You will be provided the opportunity to accept or decline cookie preferences on our websites to control the information you share with us.
The use of the Dermasync platform and Services are not available through a web browser (only a mobile app); therefore, our websites and landing pages do not request, track, or maintain any Health Data or Consumer Health Data. Our websites provide pricing and education about the Services, customer support services, and methods to outreach to us, as well as directing visitors to an app subscription provider (e.g., Apple App Store) to open an account for the Services or to our social media channels for more information. We do not use cookies on any page of our websites to obtain any Health Data or Consumer Health Data (such as menstrual-cycle data or reproductive health data) because those functions do not exist on our websites.
B. Third-Party Software Development Kits and Analytics
We employ tools to aid with performance monitoring, crash reporting, site analytics, authentication, technical diagnostics, and marketing and advertising support. Visitors of our websites are provided an opportunity to accept or decline cookie preferences. Your Health Data and Consumer Health Data (including reproductive health data, menstrual-cycle information, pregnancy information, symptoms, medications, allergies) are encrypted and only provided in our app. They are never provided on our website and, therefore, are not disclosed to SDKs, analytics providers, advertising networks, or third parties who use software tools that track a customer's journey across websites and ads to see which campaigns drive sales.
14. Sharing of Information
We may disclose your Personal Information as described in this Privacy Policy, with your authorization, or as otherwise required by applicable law. The table below summarizes the categories of recipients with whom we may share information, the categories of information shared, and the purposes of sharing.
15. Recipients of Information
Service Providers. Certain functions of the Services are provided by third party Service Providers to operate, support, and improve the Services (each, a "Service Provider" and collectively, "Service Providers"). Service Providers may include cloud hosting Service Providers, payment processing Service Providers, customer support Service Providers, security and fraud prevention Service Providers, infrastructure Service Providers, communications Service Providers, AI Service Providers, and SDK Providers, each as described in this Policy.
Service Providers receive only the information reasonably necessary to perform their contracted functions and must protect it according to contractual obligations or applicable law. Health Data and Consumer Health Data is never shared. Service Providers that process Personal Information on our behalf are subject to contractual obligations that may include confidentiality protections, appropriate technical and organizational safeguards, restrictions on processing for unauthorized purposes, compliance with retention and deletion requirements, compliance with applicable privacy and consumer health data laws, and prompt notification of security incidents where required by contract or law. Health Data and Consumer Health Data is encrypted as cyphertext.
Legal Compliance and Protection of Rights. We may disclose Personal Information or Usage Data to legal, regulatory, or governmental authorities when required or permitted by applicable law, regulation, subpoena, court order, governmental request, legal process, or other legally enforceable obligation, or when we reasonably believe disclosure is necessary to protect legal rights, enforce agreements, prevent fraud, address security incidents, or protect safety. Where health information, including menstrual-cycle data, is encrypted or otherwise not accessible to us in readable form, our ability to disclose it in readable form is not possible as only Members hold their decryption keys.
Successors and Assigns. If Dermasync is involved in a merger, acquisition, financing, restructuring, reorganization, sale of assets, or similar transaction, your Personal Information may be transferred to the applicable successor or assign as part of the transaction, subject to applicable law and existing privacy commitments including this Privacy Policy.
16. Legal Basis for Processing
Where applicable law requires us to identify a lawful basis for processing Personal Information, we may rely on one or more of the following bases: your consent; performance of a contract with you; compliance with legal obligations; and legitimate business interests, including fraud prevention, platform security, customer support, debugging, service improvement, analytics, and performance monitoring. We balance our legitimate business interests against your privacy rights where required by applicable law.
17. International Data Transfers
We may process, store, or transfer Personal Information in the United States and other jurisdictions where we or our Service Providers operate. Privacy laws in those jurisdictions may differ from the laws in your country or state of residence. Where required by applicable law, we intend to implement appropriate safeguards for international data transfers, including contractual protections and other legally recognized transfer mechanisms.
18. Member Rights and Privacy Controls
Privacy Controls Within the Services. You may change available privacy preferences at any time through in-app settings found in your personal Dermasync account profile. From your personal Dermasync account profile, you can export your data, delete your data, change the data you submitted at onboarding, enable or disable Connected Services such as Apple HealthKit and weather-based personalization (Apple WeatherKit or Open-Meteo), and set or change communications and marketing preferences.
To set up a personal Dermasync account, you are asked to read and acknowledge that you have read the Privacy Policy, the Consumer Health Data Policy, and the state-level data privacy protections as outlined in the Consumer Health Data Policy. You will not be able to establish your personal Dermasync account, and no Personal Information can be shared with us through your personal Dermasync account until you provide your acknowledgment that you have read the Privacy Policy, the Consumer Health Data Policy, and the state-level data privacy protections as outlined in the Consumer Health Data Policy. You can terminate your personal Dermasync account at any time.
Global Privacy Control (GPC). We recognize and honor Global Privacy Control signals and other browser-based or platform-based opt-out preference signals recognized under applicable law as valid requests to opt out of the sale or sharing of personal information and processing for targeted advertising, to the extent applicable.
Legal Rights. Depending on your jurisdiction of residence and applicable law, you may have rights to request access, correction, deletion, export or portability, restriction of processing, withdrawal of consent, or appeal of certain decisions. At any time, you can export or delete your data, change information provided during onboarding, stop the sharing of information from Apple HealthKit or weather-data Connected Services, and change communications and marketing preferences. These privacy options can be managed in your profile section of the Dermasync mobile application. If you need assistance with your profile or privacy controls, you can contact Dermasync Customer Care or privacy@trydermasync.com for assistance. Before fulfilling privacy requests, we may verify your identity to protect account security, prevent fraud, and prevent unauthorized disclosure of personal information. Authorized agents may be required to provide proof of authorization and sufficient information to verify both your identity and the agent's authority.
19. Data Retention
We retain Personal Information depending on the information collected, why it was collected, your use of the Services, applicable legal and contractual requirements, operational needs, security requirements, dispute resolution needs, recordkeeping obligations, and legitimate business purposes. The general retention practices below are intended to align with current functionality of the Dermasync platform and stated compliance objectives. Actual retention periods may vary based on specific circumstances and applicable law.
Deleted information is removed within a reasonable period following the applicable retention period, subject to backup systems, legal obligations, security requirements, dispute resolution needs, fraud prevention, and other legitimate business purposes permitted by applicable law. Automated retention sweeps and purge mechanisms will be implemented and maintained to reflect the retention periods stated in this Policy. Unidentified or anonymized information does not contain any Personal Information (including no Health Data or Consumer Health Data) and may be stored and retained by us.
20. Account Deletion and Data Removal
You can delete your account at any time in your personal Dermasync account profile on your personal device. Once your account has been deleted, the information may not be retrievable. (Note: Deleting your Dermasync account does not terminate your subscription through Apple or Google subscription services; Subscription termination must be done through your subscription provider (e.g., Apple Subscriptions).
Upon initiation or completion of the deletion process, personal identifiers will be permanently disconnected from account information; account information will become inaccessible through normal account functions; and backup systems may require up to ninety (90) days or longer for complete removal or overwriting. Once deletion of your account is completed, recovery of the deleted account and associated information may not be possible. We may retain certain records where required or permitted by applicable law, including for compliance, fraud prevention, security, dispute resolution, accounting, tax, audit, or legal defense purposes.
In the event of a Member's death, we may honor requests from a duly authorized legal representative to access limited account information or delete the Member’s personal Dermasync account, subject to identity verification and applicable law. We do not provide access to Health Data or Consumer Health Data of a deceased Member except where required by court order or applicable law.
21. Research and Analytics; De-Identification Standard
We may use aggregated, anonymized, or de-identified information for internal product improvement, statistical analysis, educational content, performance monitoring, quality assurance, and service improvement. At account creation, we ask every Member for affirmative consent to include their information in this de-identified data set, so that it is available to us if we later choose, in our sole discretion, to share, license, or sell aggregated, anonymized, or de-identified information (no identifiable Member information) for research or commercial purposes. We do not currently do so, and we may never do so. Where we de-identify personal information, and consistent with California Civil Code §1798.140(m) and analogous state laws, we take reasonable measures to ensure that the information cannot be associated with, or reasonably linked to, a Member, directly or indirectly. We publicly commit through this Policy to maintaining and using the information only in de-identified form and not attempting to reidentify it; and we contractually obligate any recipient of the de-identified information to comply with these requirements, including any prohibition on reidentification.
22. Security
We use administrative, technical, organizational, and physical safeguards intended to protect Personal Information, including Health Data and Consumer Health Data, against unauthorized access, acquisition, disclosure, alteration, loss, misuse, or destruction. These safeguards may include encryption at rest, encryption in transit, field-level encryption, role-based access controls, multi-factor authentication, security monitoring, audit logging, penetration testing, vulnerability management, and Service Provider security reviews, as appropriate to the nature and sensitivity of the information.
Privacy and Security Governance. We may, in our discretion but without obligation, periodically conduct privacy, security, and data protection assessments to evaluate security risks, regulatory compliance obligations, Service Provider privacy and security practices, potential impacts to privacy, data minimization practices, and effectiveness of safeguards.
Security Incidents and Breach Notification. If we become aware of a security incident involving Personal Information, we will take reasonable steps to investigate, contain, mitigate, and remediate the incident; notify affected Members where required by applicable law; notify regulators or governmental authorities where required by applicable law; and cooperate with law enforcement or regulatory authorities where legally required. Depending on the circumstances, remediation may include account suspension, invalidating active sessions, requiring Members to sign in again, token rotation, enhanced monitoring, temporary service restrictions, additional security controls, and other measures designed to reduce risk of harm.
Because login is passwordless through “sign in” access through Apple sign-in, Google sign-in, or one-time codes, there is no Dermasync password. We may sign you out and ask you to sign in again for security or other purposes. Health Data and Consumer Health Data is maintained and stored in encrypted ciphertext and should be protected unless the unauthorized accessor obtained keys not maintained on server where that information is stored.
Breach-notification timing, form, and content are governed by the specific state or federal law that applies. No security system can guarantee absolute security, and no method of transmission or storage is completely secure.
23. Changes to This Privacy Policy
We may amend or update this Privacy Policy from time to time. Changes become effective as of the effective date identified in the revised Policy unless otherwise required by applicable law. Where required by applicable law or where we make material changes, we will provide notice through the Services, website, email, SMS, or another appropriate means.
24. Contact Us
Privacy Officer
Dermasync
453 S. Spring Street, Suite 1212
Los Angeles, California 90013
For privacy requests, data requests, or Consumer Health Data requests, please see your Member profile section. If you have an additional request not found there, please contact us at privacy@trydermasync.com.
Appendix A — Member Feedback and Grievance Procedure
Dermasync is committed to addressing Member questions, concerns, and complaints regarding our privacy practices. You may submit feedback, concerns, or complaints about this Privacy Policy or our handling of personal information by contacting privacy@trydermasync.com or through in-app privacy support channels. Submissions should describe the concern with reasonable specificity and include account information needed for identity verification. We will acknowledge receipt within a reasonable period, generally within ten (10) business days, and will investigate and provide a substantive response within a reasonable period, generally within forty-five (45) days, subject to extension where reasonably necessary based on complexity. If you are not satisfied, you may request internal review by the Privacy Officer by submitting a written appeal within thirty (30) days. You may also lodge a complaint with the applicable state attorney general, data protection authority, consumer protection agency, or other regulatory authority. We will not retaliate against any Member who submits feedback, concerns, complaints, or exercises rights under applicable privacy law.
Appendix B — U.S. State Privacy Rights
Our U.S. State Privacy Rights disclosures are provided on their own page so they are easy to find and use. Read the U.S. State Privacy Rights page.
Consumer Health Data Privacy Policy
Our Consumer Health Data Privacy Policy is provided on its own page so it is easy to find, read, and use. Read the Consumer Health Data Privacy Policy.