Privacy Policy

Privacy Policy

Last Updated: [17.04.2025]

At FJCode OÜ (hereinafter referred to as the “Company”, “we”, “us”, or “our”), we deeply respect your privacy and are committed to protecting the personal data you share with us when using the SkinAI mobile application (the “App”) and related services, including the websites skinai.pro and skinailab.com (collectively, the “Services”). This Privacy Policy (the “Policy”) explains what data we collect, how we process it, who has access to it, and what rights you have in relation to your data.

If you have any questions, please contact us using the contact details provided at the end of this document. If you do not agree with any terms in this Policy, please stop using the Services.


1. About the Company

This Policy applies to all personal data processed in connection with your use of the SkinAI App and related Services.


2. Scope and Acceptance of the Policy

By using the App or related Services, you agree to the terms and conditions of this Policy. If you do not agree, please stop using the Services.

We may update or modify this Policy from time to time. The updated version will be published on skinai.pro, skinailab.com, and/or within the App. In the event of significant changes, we will use reasonable efforts to notify users (e.g., via email or in-app notification). We recommend periodically reviewing this Policy to stay informed about updates.


3. What Data We Collect

We may collect and process the following categories of personal data:

3.1. Data Provided Directly

  • Registration data: email address, username, password (if required), and other information you provide when creating an account.
  • Contact data: first and last name, email address, phone number, address, etc. (if voluntarily provided).
  • Health/medical information: skin images, skin condition details, skin type and risk questionnaire responses, date of birth, gender, and any comments you choose to add. This is sensitive data and requires your explicit consent for processing.
  • Payment data: if you use paid features, we may collect card details, billing information, or other data needed to process payments.
  • Support and feedback: messages you send us (via email, chat, surveys, etc.).
  • For professional (B2B) users: job title, organization name, legal and contact details. If you upload data of third parties (e.g., patients), you act as a data controller and we process the data on your behalf in compliance with applicable laws.

3.2. Data Collected Automatically

  • Device technical data: smartphone model, OS version, browser type, IP address, language settings, app version, access time.
  • Cookies and similar technologies: when visiting skinailab.com, skinai.pro
  • or using web services, we may use cookies for login, preferences, traffic analytics, and technical functionality.

  • Interaction data: pages and features accessed, time and date of actions, error and exception logs.

3.3. Third-Party Data

We advise against uploading third-party data (e.g., skin images of others) without their explicit consent. The App is intended for personal use. If you want to help others, we recommend inviting them to register their own account.

SkinAI allows users to submit anonymized skin images for automated analysis of dermatological conditions. The images are not linked to any personal data and cannot be used to identify individuals.
The analysis is performed using CE-marked technology provided by Skinive B.V., acting as a third-party service provider under a commercial agreement. Skinive functions as a technical processor of anonymized data only and does not store, reuse, or repurpose submitted images beyond the immediate analysis task.All processing complies with the requirements of the General Data Protection Regulation (GDPR) as the data being handled is not personally identifiable and falls outside the scope of personal data regulation.
Learn more about Skinive’s technology and compliance approach at:skinive.com

If used professionally, you must comply with data protection laws when uploading third-party data.

3.4. Use of Third-Party Services and SDKs

We use third-party services and SDKs for analytics, functionality, error tracking, and payments:

  • Analytics: Firebase, Google Analytics, Appsflyer, AppMetrica, Amplitude
  • Crash logging and monitoring: Firebase Crashlytics, Sentry
  • Payments and subscriptions: Stripe, Adapty.io
  • Cloud storage: Amazon S3
  • Marketing: Facebook SDK, AdMob

These services may process technical identifiers, app events, and anonymized data necessary for their functionality.

Privacy policies of third-party providers:


4. Purposes of Data Processing

We process your data for the following purposes:

  1. Providing app functionality and services:
    • User registration and account management
    • Analyzing uploaded skin images using AI algorithms
    • Delivering preliminary recommendations, notifications, and service messages
  2. Improving and developing the Services: analyzing user experience, testing new features, and ensuring the quality and efficiency of algorithms.
  3. Customer support and communication:
    • Responding to requests via email or contact forms
    • Sending notifications (including via email) about analysis results, recommendations, and reminders to consult a doctor
  4. Marketing and feedback:
    • Sending newsletters and promotional emails (with consent)
    • Inviting you to participate in surveys or provide feedback
    • Contacting you with updates and offers (unless you opt out)
  5. Scientific research and statistics:
    • Anonymizing or de-identifying data to improve algorithms and conduct research (e.g., in dermatology)
    • Collaborating with research institutions and partners (only anonymized or depersonalized data is shared)
  6. Legal compliance and protection:
    • Meeting legal obligations, including tax and accounting
    • Protecting the rights and interests of the Company and users (e.g., legal disputes, investigations, official inquiries)

5. Legal Bases for Processing

Your data is processed based on the following legal grounds (depending on the situation and jurisdiction):

  • Contractual necessity: e.g., when processing is required to provide the app’s features or to fulfill our Terms of Use.
  • Legitimate interests: such as improving and promoting the Services, ensuring security, fraud prevention, and similar activities that do not infringe your rights and freedoms.
  • Legal obligations: to comply with legal requirements (e.g., financial record retention).
  • Consent: for processing certain data types (e.g., sending marketing emails, using cookies, uploading medical images), we obtain your consent.
  • Explicit consent: for processing sensitive health-related data, we request your explicit consent. Without it, we cannot provide the relevant services.

6. Data Sharing with Third Parties

We may share your data with third parties in the following cases:

  • Third-party providers and contractors: hosting services, cloud platforms, payment systems, email services, analytics providers — all bound by data processing agreements that comply with GDPR.
  • Social media and plugins:
    • We may offer login via social platforms (e.g., Telegram, Facebook), receiving a limited set of data (usually email). We do not control their privacy practices.
    • “Share” or “like” buttons may be present on our site. These platforms may collect data if you interact with them. We are not responsible for such processing.
  • Legal requests or rights protection: we may disclose your data to government authorities (e.g., in response to an official request) or to protect our legal interests, in compliance with applicable laws.
  • Business transfers: in the event of a merger, acquisition, or asset sale, your data may be transferred to the successor entity under confidentiality terms.

7. Data Retention and Deletion

  • We retain personal data no longer than necessary for the purposes described in this Policy or as required by law.
  • If you request account deletion or withdraw consent, we will retain your personal data for up to 12 months (if needed for legal or rights protection purposes), after which it will be securely deleted or anonymized.
  • Images and other medical data may be stored in anonymized form for research or AI training, if you have explicitly consented to such use.
  • Some data may be stored longer if required by law, dispute resolution, or legitimate interests (e.g., security logs).

8. Data Security

  • We process your data in accordance with the EU General Data Protection Regulation (GDPR).
  • We implement technical and organizational safeguards: encrypted data transmission (TLS), encrypted storage, access control, change logs, etc.
  • Access to sensitive data is restricted to authorized employees and contractors under confidentiality agreements.
  • Despite our best efforts, no method of transmission is entirely secure. In case of a data breach, we will notify supervisory authorities and affected users as required by law.

9. Age Restrictions

The SkinAI App and Services are not intended for individuals under 18 years of age. We do not knowingly collect children’s data. If you believe a minor has provided personal data without parental consent, please contact us and we will delete the information.


10. Your Rights

Under applicable laws (e.g., GDPR), you have the right to:

  • Request access to your personal data (get a copy, understand how it is used).
  • Request rectification of inaccurate data.
  • Request erasure of your data (“right to be forgotten”) if no legal grounds exist to keep it.
  • Restrict processing in certain cases, e.g., if you contest data accuracy.
  • Receive your data in a machine-readable format (data portability).
  • Withdraw consent at any time (if processing is based on consent).
  • Object to processing based on legitimate interests, including marketing.

To exercise your rights, email us at mail@skinai.pro. We may ask for identity verification (e.g., a masked copy of an ID) to confirm your request.

You may also contact your local data protection authority if you have concerns or complaints.


11. Contact Information

If you have any questions or requests regarding this Privacy Policy or the processing of your personal data, please contact us using the details above.


12. Final Provisions

  • This Policy may be supplemented by other documents (e.g., Cookie Policy) published on our website.
  • Your use of the App and Services signifies your acceptance of this Policy.
  • If any provision of this Policy is found to be invalid or unenforceable, the remaining provisions shall remain in effect.

Effective date of this version: [17.04.2025].