Privacy Policy
Effective 21 July 2026 · Last updated 22 July 2026
Itchi is a skin wellbeing app that helps you track daily habits and discover patterns that may affect your skin. Because some of the information you record in Itchi is health data, we take privacy seriously. This policy explains, in plain language, what we collect, why, where it lives, and how you can delete it.
The short version: your data is stored securely in the EU, it is used only to provide the app to you, we do not sell it, we do not share it with advertisers, and we do not use it to train AI. You can delete everything, permanently, from inside the app at any time.
1. Who is responsible for your data
The data controller is:
Nuemad OÜ
Registry code: 16961291
Ahtri tn 12, Kesklinna linnaosa, Tallinn, 15551, Harju maakond, Estonia
Email: hello@itchi.me
Nuemad OÜ is an Estonian company. Our lead supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, AKI).
2. What this policy covers
This policy covers the Itchi iOS app and the itchi.me website. The app and the website collect different things; each is described in its own section.
3. Data we collect in the app
Information you provide
- Account information. Your email address and a password (stored only in encrypted, hashed form), or (if you use Sign in with Apple) the identifier Apple provides and, if you choose to share them, your name and email address. Apple lets you hide your real email; we fully support this.
- Profile information. An optional username and an optional profile photo.
- Onboarding survey. Your answers about your skin condition, its severity, and related lifestyle factors. This is health data (see Section 5).
- Daily check-ins. Your daily gut, mind, and body ratings and any related entries you record. This is health data.
- Skin photos. Photos you choose to take or upload to your photo diary. These are health data and are stored in a private storage area accessible only to you (see Section 7).
Information collected automatically
- Apple Health data (only with your permission). If you grant access, we read your step count and Mindful Minutes from Apple Health to show them alongside your check-ins. If you complete a breathing exercise in Itchi and grant the separate permission, we save that mindful session to Apple Health for you. We only access the categories you approve, and you can revoke access at any time in the iOS Health app.
- Device timezone. The timezone set on your device (for example "Europe/Helsinki"), used so your check-in days and streaks match your local calendar day, and to understand our users' approximate regional distribution. We do not collect GPS location, IP-based location, or any precise location data.
- App usage. When you open the app, we record that an app open occurred (timestamp, your local date, timezone, app version, platform). This is stored in our own database only. We use it to understand overall usage of the app, for example how many people use Itchi daily. We do not use any third-party analytics service in the app.
- A device identifier. A random identifier generated on your device, used so that progress you make before creating an account (for example, early badges) can be linked to your account when you sign up.
What we do not collect
We do not collect your precise location, your contacts, your browsing history, or advertising identifiers. The app contains no third-party advertising or tracking SDKs.
4. Why we use your data and on what legal basis
| Purpose | Data used | Legal basis (GDPR) |
|---|---|---|
| Creating and operating your account, providing the app's core features | Account and profile information | Performance of a contract (Art. 6(1)(b)) |
| Recording and displaying your check-ins, challenges, photos, survey results, and Apple Health data | Health data you provide or approve | Your explicit consent (Art. 9(2)(a)), given when you grant Health access, complete the survey, or record entries |
| Understanding overall app usage and improving Itchi | App open events, timezone, app version | Our legitimate interest in operating and improving the app (Art. 6(1)(f)), processed only in our own systems, never shared |
| Sending you local reminders you schedule | Notification settings on your device | Performance of a contract; notifications are generated on your device and require your iOS permission |
| Complying with legal obligations | Account records as required | Legal obligation (Art. 6(1)(c)) |
You can withdraw consent for health data at any time: by revoking Health access in iOS, by not recording entries, or by deleting your account (which erases everything).
5. Health data: how we treat it
Some data in Itchi (your survey answers, check-ins, skin photos, and Apple Health data) is special category data under GDPR Article 9. We treat all of it under stricter rules:
- It is stored in the European Union and protected by per-user access controls: our database is configured so each account can only ever read its own rows.
- It is used only to provide the app's features to you: your history, streaks, insights, and challenge recommendations.
- It is not used for advertising or marketing, not shared with or sold to third parties, and not used to train AI models.
- Apple Health data specifically is never used for advertising, other use-based data mining, or disclosure to third parties, and is never sold, in line with Apple's HealthKit requirements. We read only the categories you approve (step count and Mindful Minutes). The only data we ever write to Apple Health is a mindful session you yourself complete in Itchi, and only if you grant that permission.
Itchi is a wellbeing and tracking tool. It does not diagnose, treat, or provide medical advice. Always consult a healthcare professional about your condition and treatment.
6. Who can access your data
Nobody but you and, where strictly necessary, us. We use a small number of service providers ("processors") to run Itchi. They store or transmit data on our behalf under data processing agreements and cannot use it for their own purposes:
- Supabase: our database, authentication, and file storage provider. Your app data is stored in Supabase's European Union region.
- Apple: provides Sign in with Apple and the on-device Health framework, under Apple's own terms and privacy policy.
- Netlify: hosts the itchi.me website (website only; no app data).
- Plausible Analytics: provides visitor analytics for the itchi.me website only. No health data, photos, or check-ins ever reach Plausible. Data is stored in the EU.
We do not sell personal data. We do not share it with advertisers or data brokers. We do not send app data to any analytics company. If this ever changes, we will update this policy first and, where the law requires it, ask for your separate consent. If we ever offer the option to contribute data to health research, participation will be a separate, clearly explained choice that is entirely optional; your data will not be included unless you actively opt in.
7. How your data is protected
- All data is encrypted in transit (TLS) and at rest.
- Database access is enforced row by row: your account can only read and write its own data.
- Your photos are stored in a private bucket. They are never publicly accessible; the app retrieves them through short-lived, signed links that expire automatically.
- Passwords are hashed; we never see or store your password in readable form.
8. How long we keep your data
We keep your data for as long as your account exists. When you delete your account, everything is erased immediately (see below). We do not keep separate backups of deleted accounts; our infrastructure provider retains routine technical backups for approximately 7 days, after which deleted data is unrecoverable.
9. Deleting your account and data
You can delete your account at any time inside the app: Profile › Settings › Account › Delete Account.
Deletion is immediate and complete. It permanently erases your account, your survey answers, all check-ins, challenges, streaks, badges, insights, your profile, your profile photo, and every skin photo in storage. If you signed in with Apple, we also revoke the connection with your Apple ID so Itchi no longer appears in your Apple account. There is no grace period and no way to recover deleted data.
You do not need to email us or give a reason, though you are always welcome to contact us instead, and we will carry out the deletion for you.
10. Your rights
Under GDPR you have the right to:
- Access the personal data we hold about you
- Rectify inaccurate data
- Erase your data (the in-app deletion above, or by contacting us)
- Receive a copy of your data in a portable format
- Restrict or object to certain processing
- Withdraw consent at any time, without affecting past processing
To exercise any of these rights, contact us at hello@itchi.me. We respond within one month.
You also have the right to lodge a complaint with a supervisory authority: our lead authority, the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, www.aki.ee), or the data protection authority in your own EU/EEA country.
11. The itchi.me website
The website is separate from the app and collects far less. No app data (no health data, no photos, no check-ins) ever passes through the website.
- Analytics. We use Plausible Analytics to understand website visits (which pages are viewed, roughly how many visitors, and where they arrive from). Plausible sets no cookies and stores no personal data. You cannot be identified as an individual, and you are not tracked across websites or devices. All data is aggregated and stored in the EU.
- Waitlist / contact. If you submit your email address on the site, we use it only to contact you about Itchi and delete it on request.
12. Children
Itchi is not directed at children. You must be at least 16 years old to create an account. We do not knowingly collect data from anyone under 16; if you believe a child has created an account, contact us and we will delete it.
13. International transfers
Your app data is stored and processed in the European Union. We do not transfer your health data outside the EU/EEA. Website analytics data stays in the EU. Where a provider operates globally, such as Apple (Sign in with Apple, HealthKit), any transfer is protected by recognized safeguards such as the EU-U.S. Data Privacy Framework and the EU Standard Contractual Clauses.
14. Changes to this policy
If we change this policy in a way that matters (for example, a new category of data or a new recipient), we will notify you in the app before the change takes effect and, where the law requires it, ask for your consent. The "Last updated" date at the top always reflects the current version.
15. Contact
Nuemad OÜ
Ahtri tn 12, Kesklinna linnaosa, Tallinn, 15551, Harju maakond, Estonia
Email: hello@itchi.me
Questions? Write to us at hello@itchi.me. We're a small team and we read every message.