Privacy Policy
Last updated: February 6, 2026
MyPoreAi is built on a simple principle: your data is yours. The app is offline-first, requires no account, and stores your data on your device. This policy explains exactly what data we access, why, and how it is handled.
1. Who we are
MyPoreAi is developed and operated by the developer of MyPoreAi. For privacy inquiries, contact us at privacy@mypore.ai.
2. Data we collect
2.1 Skin profile data
During onboarding and in settings, you provide information about your skin type, conditions, goals, sensitivities, birth year, and optionally pregnancy/nursing status, menopause status, and hormonal profile. This data is stored locally on your device only and is never transmitted to any server.
2.2 Product inventory
Product names, brands, ingredients, types, and usage tracking data are stored locally on your device only.
2.3 Routine and check-in data
Routine completions, daily skin check-ins, weekly check-ins, progress data, and streak information are stored locally on your device only.
2.4 Apple HealthKit data
If you grant permission, MyPoreAi reads the following HealthKit data types to personalize your skincare routine:
| Data type | Purpose |
|---|---|
| Menstrual flow | Correlate cycle phase with skin changes and adjust product recommendations accordingly |
| Sleep analysis | Detect poor sleep patterns that affect skin and adjust routine intensity (e.g., reduce active ingredients after poor sleep) |
| Dietary water intake | Correlate hydration levels with skin dryness and prioritize hydrating products when intake is low |
| Heart rate variability (HRV) | Estimate stress levels that can influence skin sensitivity and breakout patterns; prioritize soothing products during high-stress periods |
HealthKit data is read from your device and processed entirely on-device. It is never transmitted to any server, never sold, never shared with third parties, and never used for advertising or marketing purposes.
MyPoreAi has read-only access to HealthKit. It never writes data to HealthKit.
2.5 Location data
If you grant permission, MyPoreAi accesses your location to fetch local weather data for weather-based routine adjustments. Your coordinates are sent to Apple WeatherKit to retrieve weather data. If WeatherKit is unavailable, coordinates are sent to OpenWeatherMap via our Cloudflare proxy as a fallback. Your location is not stored on MyPoreAi servers.
Neither Apple WeatherKit nor OpenWeatherMap retains your location after providing weather data. See Apple's Privacy Policy and OpenWeatherMap's Privacy Policy for how these services handle data.
2.6 Photos and camera
When you use product scanning features, images are captured or selected from your photo library. See section 3 for how images are processed when using AI-assisted features.
During the beta period, you may optionally opt in to contribute anonymized product label images to help improve our label recognition models. If you opt in, label images are uploaded to our Cloudflare infrastructure and used solely for automated model training — no human reviews these images. No personal profile data, HealthKit data, or identifying information is included with uploaded images. You can opt out at any time in settings.
2.7 Analytics and tracking
MyPoreAi does not include any analytics SDKs, tracking pixels, or third-party telemetry. We do not track your behavior, screen views, or usage patterns.
3. AI-assisted features and data transmission
MyPoreAi includes optional AI-assisted features for product identification, ingredient analysis, and check-in note parsing. When you use these features:
- Image data or text is transmitted to our server proxy (hosted on Cloudflare), which forwards requests to AI providers (Anthropic and OpenAI) for processing.
- No personal profile data, HealthKit data, or identifying information is included in these requests.
- Images and text sent for AI processing are not stored by MyPoreAi after processing is complete, unless you have opted in to contribute training data (see section 2.6).
- AI provider data handling is governed by their respective privacy policies: Anthropic, OpenAI.
- AI-assisted features are entirely optional. The core app — routine generation, learning, and all personalization — functions fully offline without them.
4. On-device machine learning
MyPoreAi uses an on-device neural network (Apple CoreML) that learns your product preferences and effectiveness patterns over time. This model trains and runs entirely on your device. No training data or model parameters are transmitted to any server.
5. iCloud sync (optional)
If you enable iCloud sync, your data is synced across your devices via Apple CloudKit. Data is encrypted in transit and at rest per Apple's CloudKit policies. MyPoreAi does not operate any servers that store synced data — sync is handled entirely by Apple's infrastructure.
6. Data storage and security
All app data is stored in local device storage (UserDefaults and local files). There is no remote database, no user accounts, and no authentication servers. The app uses no external dependencies — it is built entirely on built-in Apple frameworks.
7. Data retention and deletion
- Deleting the app removes all locally stored data.
- iCloud data can be deleted via iOS Settings > [Your Name] > iCloud > Manage Storage.
- There is no server-side data to delete, except for transient AI-assisted feature requests which are not retained after processing. If you opted in to contribute training data (section 2.6), you may request deletion of your contributed images by contacting privacy@mypore.ai.
8. Children's privacy
MyPoreAi does not knowingly collect personal information from children under 13. If you believe a child under 13 is using the app, please contact us at privacy@mypore.ai.
9. International users
European Union (GDPR)
Because MyPoreAi stores data locally on your device and does not maintain server-side user records, most data subject rights (access, rectification, erasure, portability) are exercised by you directly on your device. For AI-assisted feature requests that transit our proxy server, our lawful basis for processing is your explicit consent (initiating the feature). You may exercise your rights by contacting privacy@mypore.ai.
California (CCPA)
MyPoreAi does not sell personal information. We do not share personal information for cross-context behavioral advertising. California residents may contact privacy@mypore.ai to exercise their rights under the CCPA.
10. Changes to this policy
We may update this policy from time to time. Material changes will be communicated through the app or on this page. The "Last updated" date at the top reflects the most recent revision.
11. Contact
For privacy questions or concerns, contact us at privacy@mypore.ai.