ACNEPILOT PRIVACY NOTICE
Effective date: 15 September 2026
This notice explains what information AcnePilot uses, when information leaves your iPhone and the choices available to you.
Local by default
AcnePilot is a local-first skin tracker. Your profile, goals, routines, products, check-ins, notes, Product trials, conversation history and progress photos are stored on your iPhone by default.
AcnePilot has no login or AcnePilot cloud account and does not automatically synchronize your tracker between devices. The app contains no advertising. Optional usage analytics are described below.
Progress photos remain on your iPhone unless you explicitly attach one to a Skin Guide request. Camera alignment and face-position guidance are processed on the device. AcnePilot never selects, takes or sends a photo automatically.
Skin Guide
Skin Guide is an optional online AI feature. When you open or return to Skin Guide, and when your subscription status changes, the app may contact online services to synchronize access and usage limits. These technical requests can include an anonymous app identifier, app version and build, IP address, request timing and technical or error information. Online services use this information to check subscription access and maintain usage counters. These checks do not include your tracker content, conversation text, notes or photos.
Before you send your first question, AcnePilot explains that Skin Guide shares information with external AI services and asks you to accept this processing. Accepting allows the app to send the information described below when you choose to submit a question. Opening a privacy document alone does not authorize a question or photo upload.
Skin Guide uses these external providers:
• OpenAI: safety and content-moderation checks on the text shared with Skin Guide and any photo you attach.
• Segmind: AI inference used to generate Skin Guide replies from your question, conversation context, selected tracker context and any attached photo that proceeds to AI processing.
These providers receive the content needed for their part of the request. They do not automatically receive your entire local tracker or photo library. You can continue using the local tracker without sending questions to Skin Guide.
When you press Send, a Skin Guide request can include:
• Your question, a limited amount of recent conversation and selected earlier messages from you to preserve context.
• Your language, the question date and time, time zone and relevant profile selections.
• A compact summary of active routines, products, recent skin check-ins and Product trial observations.
• Written notes and instructions only if you enable them in Profile → Preferences → Skin Guide sharing.
• A photo only when you explicitly attach one.
You can review and change the tracker categories included with new questions in Profile → Preferences → Skin Guide sharing. Skin profile, routines/products, recent check-ins and Product trial observations (with Plus) are enabled by default; existing saved preferences are preserved. Gender and cycle details are not included automatically.
The shared text, including conversation context and selected tracker records, and any attached photo are processed for safety checks before AI guidance. Questions rejected by a safety check are excluded from future conversation context in the app.
An attached photo is sent as a smaller compressed copy. The original photo on your iPhone is not modified.
While Skin Guide is waiting for a reply, the pending request and any compressed attached photo are kept temporarily in protected local storage on your iPhone. This allows the app to recover the same reply after it is closed or interrupted. The temporary copy is removed after the recovered reply is added to its conversation, when you discard the pending request, or when you delete all app data.
External services process requests to deliver, protect and operate Skin Guide. Segmind’s published logging documentation says it stores prompts and associated configuration parameters, does not store input image files used for inference, and stores generated outputs for 7 days. It does not publish a fixed retention period for text prompts on that page. Provider processing remains subject to the applicable service terms, data policies and legal obligations. Do not send information or images that you do not want external services to process.
Provider information:
Segmind logging and retention: https://docs.segmind.com/docs/serverless-api/logging
OpenAI API data controls: https://developers.openai.com/api/docs/guides/your-data
Skin Guide responses are stored in the local conversation on your iPhone. An attached photo is not added to that conversation history.
Purchases
App Store purchases and payments are handled by Apple. RevenueCat is used to show available subscription plans and determine whether AcnePilot Plus is active. It may receive an anonymous technical identifier, product identifiers, purchase status and basic app or device information required to provide that service.
AcnePilot does not receive your complete payment-card details. Deleting local data or deleting the app does not cancel an App Store subscription.
Optional setup statistics
AcnePilot counts how often each general setup step is viewed, advanced or skipped, to help the developer improve setup. Statistics are enabled by default. You can turn them off at any time in Profile → Data & Privacy → Share usage statistics. A previous choice to disable analytics is preserved. Turning this off stops new requests and cancels requests still in progress; a count already received cannot be recalled.
The app sends only a generic step number and one action (view, advance or skip) to a dedicated Cloudflare Worker. The service immediately increments a daily UTC counter in a separate European D1 database. It does not store individual events, customer identifiers, session identifiers, cookies, IP addresses, device fingerprints or exact event times. It is not connected to the Skin Guide database. The optional cycle screen is combined with the general personalization step.
Requests do not include profile answers, health information, photos, messages, notes, product details or purchase records. The analytics transport uses no cookies or persistent event queue. No PostHog SDK runs in this version of the app. Debug builds and creative previews do not send statistics.
After each UTC day closes, only the total for each step and action is sent to PostHog’s EU service. PostHog receives these daily totals from the backend, not individual requests from your iPhone. Its required series identifier is a single constant for the entire app, not a customer or device ID. Person profiles, location enrichment and screen recordings are not used for these statistics. Counts cannot measure unique people, connect visits across days or establish an individual’s journey. Repeated visits and interrupted connections can affect totals.
Cloudflare necessarily handles connection information such as IP addresses while delivering and protecting network requests. The application does not record or forward this information to PostHog, and Worker request logging is disabled. Infrastructure providers may process operational/security information under their applicable terms; this design does not claim that internet connections reveal no IP address to the hosting provider. The developer uses limited technical processing to operate, secure and improve the service, based on legitimate interests where applicable. You may object to processing by contacting the developer.
Daily counters in D1 are removed after 90 days. PostHog contains only aggregate reports from this version; those reports may be retained to compare setup performance over time. Because there is no individual identifier in the counters, they cannot be searched or deleted by customer. They are not used for advertising or combined with subscription, Skin Guide or other customer records.
Previous versions may have sent pseudonymous individual events to PostHog, including a RevenueCat customer ID. This update stops that integration but does not automatically erase historical events. Where a previous Analytics ID exists, it remains locally available as “Previous analytics ID” in Data & Privacy solely for deletion requests. Contact mmdevopios@gmail.com with that ID to request deletion of the historical record. Enabling the new statistics does not reconnect that historical identity.
Provider privacy information:
Cloudflare: https://www.cloudflare.com/privacypolicy/
PostHog: https://posthog.com/privacy
Permissions and reminders
Camera and Photos access are used only when you choose to take or select a picture. If you enable reminders, AcnePilot schedules local notifications on your iPhone. You can change these permissions in iPhone Settings.
Retention and deletion
Local information remains on your iPhone until you delete it or remove the app and its data.
To operate Skin Guide, the server keeps a limited usage record associated with the anonymous app identifier. This can include subscription access level, usage counters, app version and build, and the dates when the record was checked or updated. A generated response may also be cached for up to 24 hours so that an interrupted app can recover the same reply without consuming the request twice. Questions and photos are not stored in this usage record.
• You can delete an individual photo while keeping its check-in, signals and notes.
• Delete all photos removes every local progress photo while keeping the rest of your tracker.
• Delete all app data removes the local profile, routines, products, check-ins, photos, Product trials, conversations and preferences, removes the associated Skin Guide usage record from the server, then returns AcnePilot to onboarding. Statistics are turned off. Any previous Analytics ID is kept locally for historical deletion requests. This action does not automatically erase old PostHog events or change your RevenueCat customer identifier. New aggregate statistics are never linked to that identifier.
Deleting all app data requires an internet connection. The app first requests deletion of the Skin Guide server record, then removes local tracker data. If server deletion cannot be confirmed, local data is kept so you can retry. Deleting only local progress photos does not require this server request.
Deleting local information cannot recall a Skin Guide request that an external service has already processed or retained under its applicable policy.
Security
AcnePilot uses reasonable safeguards for information stored on your iPhone and encrypts online requests in transit. No storage or transmission method can be guaranteed to be completely secure.
Adults only
AcnePilot is intended only for adults aged 18 or older. People under 18 must not use the app or submit information or photographs through Skin Guide. AcnePilot does not knowingly request information from minors.
Changes and contact
This notice may change when AcnePilot’s features or data practices change. The effective date will be updated when the notice changes.
The developer is the person or legal entity identified as AcnePilot’s provider on its App Store product page. For privacy questions or requests, email mmdevopios@gmail.com or use the App Support link published on that product page.