SkinLab Privacy

Last updated: 17 July 2026

Local-first records

SkinLab stores its timeline, original photos, settings, and connected-service credentials on the user’s iPhone. Oura credentials are stored in the iOS Keychain.

Optional analysis

After explicit in-app consent, selected metadata-free image copies and bounded structured timeline data may be sent through the protected SkinLab service to Google Gemini for experimental visual analysis or Coach responses. The service does not retain request images or timeline content.

Oura data

Read-only Oura API records are fetched directly by the iPhone, kept in a bounded local archive for at most 42 days, and omitted from general exports. In this personal-use build, the user-controlled “Include Oura in AI analysis” setting (on by default) adds daily Oura summaries—readiness, daytime stress, resilience, and temperature deviation—to the bounded packets sent to Google Gemini for analysis and Coach responses. Turning the setting off keeps direct Oura records out of every Gemini and Coach packet. Disconnecting Oura removes its credential and imported Oura records from SkinLab. This data flow must be reviewed against Oura’s API terms before any public release.

Control

The user chooses which Apple Health permissions to grant. Disconnecting Oura removes its credential and imported Oura records from SkinLab. SkinLab’s local reset removes the app’s local archive and protected photos.