§ 00 · Privacy policy Effective 26 May 2026 · Version 1.0

Privacy is a feature.

Not a footer link, not a popup to dismiss. This page is the long version. The short version, if you only read one sentence: your photos and journal entries stay on your device by default, we don't run AI on your face, and there is no third-party backend.

iOS 18.4+ On-device by default No AI photo analysis No brand deals
§ 01 — TL;DR

The short version.

Nurtli is an iPhone app for understanding your skin through the lens of microbiome and barrier. It is published by Arilabs. We designed it so the most sensitive information you give it — your face and your daily notes — never leaves your phone unless you choose to back it up to your own iCloud private database.

What we promise
Your face is not training data. Your journal is not behavioural fuel. Your subscription pays for the work — not the surveillance.
What we will never do
  • Run AI on your photos. Not for analysis, not for "AI features," not ever.
  • Sell or share your data. No data brokers, no advertisers, no partners.
  • Ship analytics that touch image bytes or your journal text.
  • Take brand deals or affiliate revenue. Subscriptions are our only revenue.
  • Use streaks, shame, or dark patterns to keep you opening the app.
§ 02 — Device storage

What stays on your device.

By default, the following information is stored locally on your iPhone using Apple's file system with complete file protection (encrypted while your device is locked) and Apple's Core Data framework. None of it is transmitted to us:

  • Daily check-ins — your selected feeling (great / fine / off / rough), any optional flags (stinging, redness, breakout, etc.), products used, free-text notes.
  • Photos attached to check-ins — the image file, its capture time, and a lighting hash we compute on-device to advise on consistency between shots.
  • Your routine — the products in your AM and PM stacks.
  • App preferences — appearance settings, optional cycle phase, anything you've toggled in Settings.

The ingredient library and the Microbiome Minutes are bundled with the app at install time; reading them does not contact a server. The Nurtli Notes are also bundled, but the app checks Apple's public CloudKit database for newly published Notes — an anonymous, read-only download of public content that sends no personal data and works from the bundled copy when you're offline.

§ 03 — iCloud sync

Sync, when it arrives.

Today, Nurtli does not sync your journal, photos or routine anywhere — they live only on the device you created them on. There is no backup we hold and nothing to turn on yet.

We are building optional iCloud backup for a future release. If and when we ship it, it will be strictly opt-in, it will write only to your own private CloudKit database in your Apple account (we never get a server it passes through, and we cannot read it), and we will update this policy before it goes live.

This is separate from the shared community product database described in §8 — that holds product information people contribute, never your journal, photos or routine.

§ 04 — Camera & photos

Photos & the camera.

Photos are optional on every single check-in. When you choose to add one, Nurtli opens its camera with a silhouette overlay and an ambient-light advisory designed to help you take consistent shots over time. The capture, the lighting hash, and the link back to that day's entry are saved to your device — and to your iCloud private database if you've enabled sync (see §3).

Photos are viewed in the context of their check-in entry, not in a separate gallery. If you'd like a visual timeline, the "photos-only" filter in the Journal tab is a Plus feature — it surfaces the photos you've already taken; it never sends them anywhere.

You can delete a photo by deleting its check-in. You can delete every photo Nurtli has ever stored from Settings → Erase all data. When you do this, the image files are removed from disk and from your iCloud private database (if sync is on).

§ 05 — AI & image analysis

No AI on your skin.

We do not run machine-learning models on your photos. Not on-device, not in the cloud, not for "skin analysis," not for "personalised insights," not for any future feature we might think of.

The lighting hash we compute is a small numerical fingerprint of ambient brightness — it is used to tell you when a new shot is taken in different conditions to the last one. It is not a model of you and it cannot reconstruct any image.

The published content in Nurtli — ingredient summaries, the Microbiome Minutes, the Nurtli Notes — is written by a microbiologist. No AI-generated material ships in the published library.

§ 06 — Subscriptions

How payment works.

Nurtli Plus is offered as a monthly or yearly subscription through Apple's StoreKit 2 framework. Apple processes the payment, and your subscription status is read on-device from Apple — there is no third-party subscription processor in between.

  • Apple sees the purchase — handled under Apple's own privacy policy and the App Store's terms.
  • We do not store your payment information and do not run a payments database. Your subscription status is checked on-device against Apple's StoreKit. To cancel, manage your subscription in iOS Settings → your Apple Account → Subscriptions.

The 7-day trial on the yearly subscription is administered by Apple and follows the standard App Store trial rules.

§ 07 — Analytics

What we measure (and don't).

We may use a strictly anonymous analytics service to count things like "how many users opened the app today" or "did the onboarding finish." If we do, it will be a privacy-first service that does not collect identifiers, IP addresses, or content.

The hard rule
No analytics SDK shipped in Nurtli will touch image bytes, photo metadata, journal text, or any field you typed yourself.

If you would prefer to opt out of even anonymous event counts, you can do so from Settings → Privacy → Anonymous usage events.

§ 08 — Third parties

Who else is in the room.

The list is deliberately short. We do not integrate marketing pixels, behavioural analytics, ad networks, or social SDKs.

  • Apple — iOS, StoreKit 2 (subscriptions), CloudKit, and the App Store itself.
  • The community product database — product details you contribute (brand, name, barcode, ingredient list) are stored in Apple's shared public CloudKit database, tied to an anonymous Apple-issued identifier, so others can see and confirm them. It never contains your journal, photos or routine.
  • Optional, anonymous analytics — if enabled in a future build, we will name the vendor here and link their policy.

That's the full list. If we ever add another, this page changes first and the change is announced in-app.

§ 09 — Your rights

Your data, your call.

Because most of your data never leaves your phone, "exercising your rights" mostly means using the device controls that already work:

  • Access — every entry, photo and routine is visible in the app.
  • Export — from Settings → Export you can produce a JSON archive of your journal plus the original photos. It is written to your device's Files app.
  • EraseSettings → Erase all data wipes the local store and the photo files on your device.
  • Withdraw consent — because nothing leaves your device, deleting a check-in or erasing all data is how you withdraw it; it takes effect immediately and we retain nothing to "undelete" with.

If you are in the UK or EU, you have the additional rights described in the UK GDPR and the EU GDPR. To the limited extent we hold any information that identifies you (essentially: your email address, if you have contacted us), you can write to us at the address in §13 and we will action your request within thirty days.

§ 10 — Children

Children.

Nurtli is not directed at children under 13 and is not intended for use by anyone under that age. We do not knowingly collect data from children. If you believe a child has used the app and recorded information, please contact us and we will delete what we can.

§ 11 — Not a medical device

Educational, not medical.

Nurtli is an educational tool. It does not diagnose, treat, cure or prevent any condition, and the content within does not constitute medical advice. We deliberately do not name specific dermatological conditions as something Nurtli addresses.

If your skin is genuinely struggling — persistent inflammation, painful breakouts, unexplained changes — please see a dermatologist. Nothing in Nurtli substitutes for that conversation.

§ 12 — Changes

When this policy changes.

When we change this policy, the version number and the effective date at the top of the page change too. Material changes — anything that affects what data is collected or who it is shared with — will be announced inside the app the next time you open it, and we will ask you to re-acknowledge the policy before continuing.

The version number and effective date at the top of this page always reflect the current policy, so you can see when it last changed.

§ 13 — Contact

Talk to a person.

Privacy questions, data requests, things we got wrong here — all of it goes to a real human inbox we read:

Everything else — press, partnerships you're proposing that we'll politely decline, the occasional thank-you — reaches the same inbox.

Published by Arilabs · Version 1.0 · 26 May 2026