Photo privacy
Where your selfie goes when a skin app scans it
The short version for Dermly: to a server, once, and then it is gone. The long version is below, hop by hop, because a face is not something you should hand over on a slogan.
On device or on a server? On a server.
It is worth saying that clearly rather than letting a phrase like "private by design" do the work. Dermly does not run the analysis on your iPhone. The photo is sent to a server, which passes it once to a vision model. What Dermly can promise is narrower and more checkable than on device processing, and it is written out below.
The whole path, in six hops
- You consent, on the deviceNothing leaves the phone until you explicitly agree in the app. There is no background upload and no silent first scan.
- The photo is compressed locallyThe selfie is normalized and encoded as a JPEG on your iPhone. That file, and nothing else about you, is what gets sent.
- It travels encrypted to the Dermly serverOne HTTPS request to the analysis endpoint. There is no account attached to it, because Dermly has no accounts.
- The server passes it once to Anthropic ClaudeThe image is held in memory only for the length of that call. It is never written to disk, never put in a bucket, never queued.
- Scores come back, the image is goneThe response carries the numbers, the observations and the routine. The server keeps a log line with a status code, a response time and a language tag. No image data, no identifiers.
- Everything is stored on your iPhoneScores, routine and history go into a local database. The selfies kept for the photo timeline are written to a folder excluded from iCloud and device backups.
Who touches the photo, and what they do
| Company | Role | Sees your photo |
|---|---|---|
| Anthropic | Runs the vision model that produces the scores. | Yes, for the one call. Not used for training under the API agreement. |
| Vercel | Hosts this website and the analysis endpoint. | The image passes through in memory. Nothing is stored. |
| Apple | Handles the download and any subscription. | No. Payment details are never seen by Dermly either. |
The complete legal text lives in the Privacy Policy.
Six questions to ask any app that wants your face
This list is not about Dermly. Use it on every face scanning app you consider, including this one, and install whichever one answers all six.
Does it say where the analysis runs?
On device or on a server is the first question, and a surprising number of apps never answer it. Vagueness here is itself an answer.
Does it name the processors?
Not "trusted partners". The actual companies, and what each one does. If the operator will not name them, you cannot evaluate them.
Does it say how long the image exists?
A retention period, or an explicit statement that there is none. "We take your privacy seriously" is not a retention period.
Does it need an account?
An account links every scan to an identity and makes a breach far more expensive for you. Ask why one is required.
Is training on your images excluded?
Look for an explicit exclusion, not silence. Silence generally means the terms permit it.
Can you delete everything in one action?
And does deleting the app actually delete the data, or only your copy of it?
Privacy questions
Does Dermly analyze my skin on my phone or on a server?
On a server. This is the honest answer and it is worth stating plainly, because plenty of apps let you assume otherwise. Your selfie is compressed on the iPhone and sent over an encrypted connection to the Dermly analysis endpoint, which passes it once to the Anthropic Claude vision model. The image exists in memory for the duration of that call and is not written to disk anywhere in between. Your results, your history and your saved selfies then live on your phone only.
Is my photo stored on Dermly servers?
No. The analysis endpoint holds the image in memory for one request and returns the scores. Nothing is persisted: no image files, no results, no user records. The only thing written down is a log line containing the HTTP status, how many milliseconds the request took, and the language tag. Image data is never logged.
Is my face used to train an AI model?
No. Your photo is not used to train any model, by Dermly or by Anthropic under the API agreement that covers this processing. It is also never sold, rented or shared with advertisers or data brokers.
Do I need an account?
No. There is no sign up, no login, no email collection and no profile. Nothing that arrives at the server identifies you as a person. That is also why a scan cannot be recovered if you delete the app: there is no copy anywhere else.
What is the legal basis in the EU?
Your explicit consent, under Article 6(1)(a) GDPR, given in the app before any photo leaves the device. Because nothing is retained, most data rights are satisfied by design: withdrawing consent means stopping, and erasure means deleting the app or using the delete option in settings, since all your data is on your device.
How do I delete everything?
Open the app settings and choose to delete all data. That removes every scan, every stored photo and every setting from the device. Deleting the app itself does the same thing. Note that deleting the app does not cancel a subscription; subscriptions are managed by Apple in your iPhone Settings.
More on reading your own skin
What your skin score means
The seven cosmetic dimensions Dermly reads, and how to make sense of each number.
Skin age test
What an AI skin age estimate is, what it is not, and why it moves between photos.
Build a skincare routine
A four step AM and PM routine at the category level, without a 12 step shopping list.
Track skincare progress
How to photograph and measure your skin so a twelve week change is actually visible.
App or dermatologist
What a phone camera can answer, and the much longer list of what only a doctor can.