Blemmy logoBlemmyBack home

Private by default

Privacy Policy

Effective September 14, 2026

The short version

Blemmy has no user accounts, advertising, or cross-site tracking. The website uses cookie-free Cloudflare Web Analytics to measure aggregate traffic and performance. The app sends anonymous onboarding step counts unless you turn this off in Privacy settings. Blemmy processes your photos, products, routines, and history on your iPhone and does not send them to Blemmy LLC. When iCloud is enabled for Blemmy, that data syncs through the private CloudKit database for your Apple Account. Blemmy LLC cannot view, retrieve, or manage its contents. If you choose barcode lookup, the app sends the scanned code to Open Beauty Facts to retrieve a product name and brand.

1. Who we are and the scope of this policy

This Privacy Policy explains how Blemmy LLC, a Tennessee limited liability company (“Blemmy,” “we,” “us,” or “our”), handles information when you use the Blemmy iPhone app, visit blem.my, or contact us. Blemmy LLC is responsible for the processing described in this policy.

Washington residents should also read our separate Consumer Health Data Privacy Policy.

2. Information processed in the app

The app processes and stores the following information on your device:

  • photos you capture and information about each capture, such as date and time, camera and device information, crop and orientation, head-pose angles, face-to-camera distance, lighting or exposure measurements, quality warnings, and processing version;
  • skincare product information, including product name, brand, category, and notes;
  • routine schedules and completion or skip history; and
  • reminder preferences, app settings, and onboarding choices.

Blemmy uses this information to provide the features you request, including guided capture, photo alignment and comparison, progress views, routines, and reminders. The processing occurs on your device, except for the optional barcode lookup described below. Photos, retained capture information, products, routines, and completion or skip history may also sync through your private iCloud database as described in Section 5. Reminder preferences, app settings, and onboarding choices remain on your device. We do not operate an account system or Blemmy server that receives your synced app data.

If you choose "Scan barcode," the app sends the scanned barcode to the Open Beauty Facts API and requests only the product name and brand. Blemmy LLC does not receive or retain the request or response. Open Beauty Facts receives the barcode and technical information needed to handle the request, such as your IP address and Blemmy's API user-agent string, and handles that information under its own terms and privacy practices.

3. Camera, face tracking, and face data

During guided capture, Blemmy uses Apple’s ARKit and, on supported devices, the TrueDepth camera to detect that a face is present and estimate its position, orientation, movement, and distance from the camera. This lets the app provide framing and pose guidance and capture more consistently aligned photos.

Blemmy retains the photo you choose to capture and the capture measurements listed in Section 2 until you delete them. It does not retain the ARKit face mesh, facial expressions or blend-shape values, raw depth maps, or a biometric template. Blemmy does not use face data to identify or authenticate you, build an advertising profile, or infer your identity. Live face tracking and measurements are processed on your device. The retained photo and capture measurements may sync through your private iCloud database, but Blemmy LLC cannot access them.

4. Age assurance

Blemmy is intended for people age 16 and older. Where iOS reports that local law requires an age check, Blemmy uses Apple’s Declared Age Range framework to request an age range for the Apple Account. Blemmy receives only the range or a status indicating that no range was shared—not the account holder’s birth date. The result is used on the device only to decide whether the app is available. Blemmy does not transmit or retain the result, and a declined, canceled, uncertain, or failed request can be tried again.

5. iCloud sync, backups, Photos, and exports

When iCloud is enabled for Blemmy in iOS Settings, photos, retained capture information, products, routines, and completion or skip history sync through the private CloudKit database associated with your Apple Account. Apple provides and processes this iCloud service. Blemmy LLC cannot view, retrieve, or manage the contents of your private database. Synced data uses your iCloud storage and is subject to your iCloud settings and Apple’s terms and privacy practices.

CloudKit sync is separate from device backups. Blemmy data may also be included in an iCloud or computer backup, depending on your device and backup settings. If you choose “Save to Photos,” the selected image is copied to your Photos library. If you use an export or the iOS share sheet, a copy is sent to the person, app, or service you choose. Once a copy leaves Blemmy, its handling depends on your settings and the selected recipient or service.

6. Device permissions

Blemmy asks for access only when it is needed for a feature you choose:

  • Camera: to provide capture guidance, take photos, and scan a product barcode when you request it.
  • Photos (add only): to save an individual image when you request it.
  • Notifications: to schedule optional capture, routine, and trial reminders locally on your device. Apple may also deliver silent notifications so CloudKit can sync changes. Blemmy LLC does not operate a custom push-notification server or use notification tokens for advertising or user-visible reminders.

You can change permissions in iOS Settings. Blemmy does not request access to your precise location, contacts, microphone, or advertising identifier. Changing a permission does not delete information you previously saved.

7. Purchases and Apple services

Apple processes subscriptions through the App Store. Blemmy uses StoreKit on your device to retrieve product information, determine offer eligibility, and verify an active entitlement. We do not receive your payment-card details. Apple provides Blemmy LLC with aggregate App Store Connect Analytics reports about discovery, downloads, app usage, subscription performance, and stability. App usage and diagnostics depend on your device's analytics sharing settings. These reports do not include your Blemmy photos, products, routines, capture metadata, or history. Apple handles its information under its own privacy policy.

8. Anonymous app analytics

Unless you turn off Share Anonymous Analytics on the welcome screen or in Blemmy's Privacy settings, the app reports when an onboarding step is reached and when onboarding is completed. The welcome screen presents this setting before the app sends its first report. Each report contains the step number, app version, and iOS major version. It does not contain your onboarding answers, photos, products, routines, capture information, history, or notification choices. Blemmy does not send an account, device, installation, advertising, vendor, or session identifier.

The app sends these reports to a first-party endpoint on blem.my. A Cloudflare Pages Function validates the fixed set of fields and immediately increments a daily aggregate counter in Cloudflare D1. Blemmy does not store an individual event row or enable stored Function logs. Cloudflare processes technical information such as the request IP address to deliver and secure the endpoint, but Blemmy does not add that information to the analytics counter.

We use these aggregate counts to understand where people leave onboarding and to improve that flow. We do not use them for advertising, profiling, personalization, or tracking across apps or websites. Where permitted, we rely on our legitimate interest in measuring and improving onboarding. You can object at any time by turning off Share Anonymous Analytics. This does not affect Blemmy's features.

9. Communications with us

If you email us, we receive the email address, message, attachments, and ordinary delivery information you provide. Please do not send skin photos or sensitive health information unless it is necessary for your request. We use communications to respond, provide support, protect Blemmy, and comply with law. Our email-routing and mailbox providers process those messages for us. We retain them only as long as reasonably needed for those purposes, including any legal, security, or recordkeeping needs.

10. Website information

This website does not use user accounts, advertising cookies, or cross-site tracking. We use Cloudflare Web Analytics to understand aggregate website traffic and performance. Its browser beacon measures visits, page views, page-load timing, Core Web Vitals, URL paths without query strings, referring sites, country, device type, browser, and operating system. Cloudflare states that Web Analytics does not use cookies or local storage, fingerprint visitors, or track individuals across sites. We use its aggregate reports only to improve the website’s reliability, performance, and content—not for advertising, profiling, or identifying visitors.

The analytics beacon reports through Blemmy’s Cloudflare-served domain. Cloudflare says it retains unsampled beacon data for seven days before aggregation and makes analytics available for the previous six months. Cloudflare and our website host also process limited technical information needed to deliver and secure the site, such as IP address, browser and device information, request date and time, requested page, referring page, and security signals. We use this information only for site delivery, analytics, reliability, abuse prevention, and security. Technical logs are kept according to the shortest periods reasonably needed for those purposes and provider settings.

Because the site does not use advertising or cross-site tracking technologies, it does not change its behavior in response to “Do Not Track” or Global Privacy Control signals.

11. How information is disclosed

We do not sell or rent personal information, and we do not share personal information for cross-context behavioral advertising. We disclose information only as follows:

  • Apple services: to provide private CloudKit sync when iCloud is enabled for Blemmy, and when your settings or choices use an Apple backup or Photos.
  • Service providers: to Cloudflare for aggregate app analytics and website hosting and analytics, and to our email providers for communications. Their processing is limited to providing those services.
  • Open Beauty Facts: when you choose barcode lookup, limited to the scanned barcode and technical information needed to make the API request. Open Beauty Facts returns the product name and brand to the app.
  • Legal and safety reasons: when reasonably necessary to comply with law, protect rights and safety, investigate misuse, or establish or defend legal claims.
  • Business changes: in connection with a merger, financing, reorganization, or sale of assets, subject to applicable law and appropriate notice.

Blemmy LLC cannot access your private CloudKit database and cannot disclose its contents from a Blemmy server.

12. Retention, deletion, and security

In-app information remains on your device and, when sync is enabled, in your private iCloud database until it is deleted. Deleting an item or using “Delete All Data” removes it from the current device and sends the deletion to iCloud and your other devices when they connect. Deleting the app alone may leave synced data in iCloud. Copies already placed in Photos, a backup, an export, or another service must be managed through the relevant service or recipient.

Blemmy does not store the scanned barcode after the lookup finishes. Open Beauty Facts controls any retention of the technical information it receives with the API request.

Blemmy keeps anonymous daily onboarding counts for up to 13 months. Because the app does not send an identifier and the server does not store individual events, we cannot use an aggregate count to identify, retrieve, or delete one person's report.

Blemmy stores app images using iOS data protection and relies on Apple’s platform and private CloudKit database protections. Blemmy marks original photo assets for CloudKit encryption. We use reasonable administrative and technical measures for the limited website and communication information we receive. No storage or transmission method is guaranteed to be completely secure.

13. Your choices and privacy rights

In Blemmy’s Privacy & Data settings, you can export capture metadata, routines, and history as a readable JSON file. Photos can be saved individually. You can delete individual captures or all photos, products, routines, and history stored by the app; deleting all data also turns off Blemmy reminders. You can manage Blemmy’s iCloud access in iOS Settings. Turning off access stops future sync but may not remove data already stored in iCloud. Because Blemmy LLC cannot access your private database, we cannot retrieve, manage, or delete its contents for you.

You can turn off Blemmy's onboarding analytics at any time under Settings > Privacy > Share Anonymous Analytics. This stops future reports and does not affect app features.

You can control whether Apple shares app usage and diagnostics with Blemmy LLC under Settings > Privacy & Security > Analytics & Improvements > Share With App Developers. This choice does not affect Blemmy's core features.

Depending on where you live, you may have rights concerning personal information we do hold, including rights to request access, correction, deletion, restriction, portability, or an objection to certain processing. You may also have a right to appeal a decision or complain to your local privacy regulator. Send requests to privacy@blem.my. We may need to verify your identity and may retain information where law permits or requires it. We will not discriminate against you for exercising a privacy right.

14. International information

Blemmy is based in the United States. Apple and our website and communication providers may process information in the United States and other countries, where privacy laws may differ. Where required, we use legally recognized safeguards for international transfers of information handled on our behalf.

For people in the European Economic Area, United Kingdom, or Switzerland, the legal bases for the limited processing described here depend on the context: providing app features or support you request, our legitimate interests in operating and securing Blemmy and responding to communications, consent where required, and compliance with legal obligations. You may object to processing based on legitimate interests and may withdraw consent at any time where consent applies, without affecting earlier lawful processing. You may complain to the data-protection authority where you live or work.

15. Children’s privacy

Blemmy is intended only for people age 16 and older. We do not knowingly receive personal information from anyone under 16. If you believe a person under 16 has sent personal information to us through email or the website, contact us so we can review and delete it as appropriate. In-app information remains on the user’s device and may sync through the user’s private iCloud database, which Blemmy LLC cannot access.

16. Changes to this policy

We may update this policy as Blemmy changes. We will post the revised version here and update the effective date. If a change materially affects how information is handled, we will provide additional notice where appropriate or required by law.

17. Contact

Questions or privacy requests can be sent to:

Blemmy LLC
116 Agnes Road, Suite 200
Knoxville, TN 37919
United States
privacy@blem.my

Blemmy logoBlemmy

© 2026 Blemmy LLC. Your skin, clearly.

SupportHealth DataTermsLegal