Vowli LLC / Skinli app privacy

What Skinli knows,
and what it never sees.

This notice covers the Skinli app for iPhone. It was last updated on 21 September 2026. The marketing websites have their own notice.

The short version.

  • Your profile, your journal, your routine, your readings and your photographs live on your iPhone. We do not hold a copy of them.
  • To read your skin, the app sends five photographs and six answers to our server, which passes them to an AI model run by Google. Our server erases the photographs when the analysis ends, and in any case within ten minutes.
  • Signing in with Apple gives us no name and no email address. We never ask for them.
  • We do not sell your information, we show no advertising, and we do not track you across other companies’ apps or websites.

Skinli is published by Vowli LLC, which is the controller of the information described here.

What stays on your iPhone.

Almost everything. The answers you give when you set the app up — including the health-related ones, such as skin conditions, medicines, pregnancy, isotretinoin treatment and cycle tracking — your routine, your journal and its photographs, the products you save, every reading, and the five photographs behind each one are written to the app’s private storage on your device. We never upload that record, and signing in does not copy it to us.

Two things follow from it being on your phone. It is part of your iPhone’s own backups, to iCloud or to a computer, in the same way as other apps’ data, under your Apple settings rather than ours. And if you use the app’s export, the file it creates contains your personal information and photographs and is not encrypted: keep it somewhere you trust. The export never includes your sign-in, and it never includes anything that would let somebody else use your membership.

Journal photographs can come from the camera or from your photo library. The app receives only the pictures you pick.

Photographs of your face.

A scan is five photographs: straight on, left, right, up and down. When you approve them they are sent over an encrypted connection to our server together with six answers (see below). Our server removes the information embedded in the image files, such as camera details and any location tag, and passes the pictures to Google’s Gemini model, which returns the reading. We ask Google not to store the request.

What goes with the photographs is deliberately small. Your name, your account, your location, your journal and photographs from earlier scans are never sent.

Our server holds the photographs only for the job. They are erased when the analysis finishes, fails or is cancelled, and a hard limit removes them after ten minutes whatever happens. They are never written to our database backups. The finished reading waits on the server until your phone confirms it has saved it, and is then erased; if your phone never collects it, it is erased after 24 hours.

We do not use your photographs to train anything, and we do not look at them.

Answers that travel with a request.

With a scan

Six answers, and nothing else: your age in years, how oily your skin is, how reactive it is, your skin tone, the concerns you chose and the areas of your face they affect.

With a product verdict or a shelf review

To judge whether a product suits you, the model needs more, and some of it is about your health. These requests add: your skin conditions, your pregnancy answer, whether you are taking or have recently taken isotretinoin, the medicines you told the app about, your sensitivities, pigmentation, signs of ageing, sun exposure and experience with skincare; the products in your routine and when you use them; what your latest reading observed; your language; and, if you use them, the general climate where you are and your cycle phase.

They never include your name, your coordinates, a medicine’s dose, your weight, your journal, your photographs or the record of what you agreed to.

These requests are handled exactly as a scan is: processed by Google’s Gemini model, removed from our server within ten minutes, and the answer erased once your phone has it or after 24 hours.

Your account.

You sign in with Apple. We ask Apple for no name and no email address, and Apple shares neither. What we keep is a one-way fingerprint of the identifier Apple gives us for you, so that the same person is recognised next time, and an encrypted Apple token that lets us check the sign-in is still valid and revoke it when you delete your account.

To make sure requests come from a genuine copy of Skinli on a real iPhone, the app uses Apple’s App Attest. We keep the public half of a key created on your device and Apple’s certificate for it, and Apple tells us roughly how many such keys this app has created on the device in the past thirty days, which helps us stop one phone pretending to be many. Sessions last an hour and we store only a fingerprint of each.

We keep a count of the analyses, verdicts and shelf reviews your account has used each month, because the free allowance and membership depend on it. The count carries no content.

Like any internet service, our server and our hosting provider see the IP address the app connects from. We use it to limit abuse. We do not store it with your account or with your requests.

Purchases.

Membership is bought through Apple. We never see your card or your Apple ID. Apple sends us a signed record of the subscription — which plan, when it started and renews, whether it is a trial — tied to a random token we issued for your account, and we keep its current standing so the app knows what you may use. We do not keep the raw receipts.

Deleting your Skinli account does not cancel a subscription. Apple bills it, so it is cancelled in your Apple ID’s subscription settings.

Weather and location.

Weather is optional, and iOS asks your permission first. The app asks your phone only for an approximate position, then rounds it on the device to a grid of about eleven kilometres before anything leaves it. That rounded point and your time zone go to our server, which asks Apple’s WeatherKit for the conditions there.

We never store the position and never attach it to your account. Forecasts are held in memory for at most thirty minutes, shared anonymously between everybody in the same area. We keep a count of how often your account refreshed, for a day, to keep use fair.

Notifications.

Reminders — for your routine, a rescan, your journal or your cycle — are scheduled on your phone by your phone. Nothing about them is sent to us, and every one starts switched off.

Two alerts do come from our server, and only if you ask for them:

  • “Tell me when it’s ready.” While an analysis or a recommendation is being prepared, you can ask to be told when it is done. We hold your device’s push address for that one job and erase it when the alert is sent, when you cancel, when your phone collects the result, or after a day.
  • “Tell me when it’s added.” If you ask us to add a product that is not in the catalogue, you can also ask to be told when it arrives. We then keep your device’s push address together with that product’s barcode until we have sent the one alert, or for 90 days, whichever comes first, and for at most twenty products at a time. This is the one place our server links you to a specific product. Until it is erased, this record may also sit in our encrypted database backups.

The alerts themselves say only that something is ready or that a product has arrived. They never name a product or describe a result.

Products you ask about.

Browsing the catalogue and scanning a barcode are not tied to you. When you ask us to add a missing product, we add one to a count for that barcode. To avoid counting you twice, we keep a fingerprint that changes every day and cannot be turned back into your account, for two days. Reading a barcode happens on your phone, and only its number is looked up. Product images are cached on your phone for up to thirty days and are fetched without your account or any cookie.

How the app is used.

Skinli can share which screens you open and which controls you use, so we can see where people get stuck. This is on unless you switch it off. The switch is shown when you set the app up and stays in the You tab, and turning it off stops it immediately.

What is shared is a fixed list of event names, how long a screen was open and whether something succeeded. It never includes your photographs, your readings, your answers, anything you write, or which product you looked at. Each report carries a random identifier that is not your account and is replaced every time the app starts. Our server forwards these events to PostHog, our analytics provider, without storing them, with your IP address withheld and location lookup disabled.

Who else is involved.

  • Google — its Gemini model reads the photographs and answers described above to produce your readings and recommendations.
  • Apple — sign-in, the genuine-device check, purchases, the weather service and the delivery of push notifications.
  • PostHog — receives the usage events described above.
  • Hetzner Online — hosts our server, in Germany.

Google, PostHog and Hetzner handle this information on our behalf, for the purpose named and nothing else. Apple handles its part under its own privacy policy. We share information with nobody else, unless the law requires it.

Where it is kept, and for how long.

Our server is in Germany. Google, Apple and PostHog process what reaches them in their own facilities, so that information may be handled outside your country, including in the United States. Everything between the app and our server is encrypted in transit.

  • Photographs and answers sent for analysis: until the job ends, and never more than ten minutes.
  • A finished reading or recommendation: until your phone confirms it has it, and never more than 24 hours.
  • A “tell me when it’s ready” push address: at most one day.
  • A “tell me when it’s added” push address and barcode: until the alert is sent, and never more than 90 days.
  • The daily fingerprint for a product request: two days.
  • Weather and analytics rate counts: one day and one hour.
  • Account, device key, monthly usage counts and membership standing: for as long as you have an account.

Our database backups are encrypted and never contain photographs, answers, readings or “tell me when it’s ready” addresses.

Deleting things.

You can delete your account in the app, under You. Because it cannot be undone, Apple asks you to confirm it is you. Our server then closes the account, stops any work in progress, revokes the Apple token, and removes your sign-in and your device key. Your monthly usage counts are kept for one more day so that work already under way can finish, then removed. A record that the deletion happened — which no longer points to you — is kept for thirty days so the app can confirm it completed. If you have a paid membership, its standing is kept until the paid period ends plus seven days, so that signing in again with the same Apple ID restores what you paid for. Only when the server confirms all this does the app erase what is on your phone.

You can also erase the app’s data from the device without deleting your account, and removing the app removes its storage. Copies in your own iPhone backups and any export files you made are yours to remove.

Your rights.

Wherever you live, you can ask us what we hold about you, ask us to correct or delete it, and object to how we use it. Because so much of your information is on your phone rather than with us, the quickest route is often the app itself: the export gives you a complete copy, and account deletion removes what our server holds.

If you are in the European Economic Area, the United Kingdom or Switzerland: we process the photographs and health-related answers you send on the basis of your explicit consent, which you give when you set the app up and can withdraw by not sending further requests or by deleting your account; we provide the service you asked for on the basis of our contract with you; and we keep abuse-prevention records, and the usage events described above, on the basis of our legitimate interest in a secure service that works, which you can object to at any time — for usage events, with the switch in the app. You also have the right to complain to your data protection authority.

If you are in California: we do not sell or share personal information as those terms are defined, we do not use sensitive personal information for anything beyond providing the service, and we will not treat you differently for exercising your rights.

Age.

Skinli is for people aged thirteen and over, and the app does not accept a younger age. We do not knowingly collect information from children under thirteen. If you believe a child has used the app, contact us and we will remove what our server holds.

Changes and contact.

When the app changes what it collects or who it shares it with, this notice changes first, and the date at the top changes with it.

Contact [email protected] with any question or request. We may need to confirm a request comes from the person concerned before acting on it.