Privacy Policy
For the Rash: When to See a Doctor iOS app and the website at rashcheck.bulpara.com.
Last updated: 26 July 2026 · Effective: on first release of the app. Publisher: Bulpara Inc.
Draft pending legal review. This policy describes how the app actually behaves,
but it has not yet been reviewed by counsel, and the app has not been released.
Items marked [TO BE COMPLETED] are placeholders for the registered entity, its address
and its jurisdiction.
Washington residents, and anyone whose consumer health data we handle: a separate policy governs consumer health data, as Washington's My Health My Data Act requires. It is not merged into this one. Read the Consumer Health Data Privacy Policy.
1. The short version
- There is no account, no sign-in, no email address and no password.
- Your checklist answers, your results and your history stay on your phone. We never receive your history.
- A photo, if you choose to add one, is uploaded, analysed, and deleted from our servers the moment the analysis finishes. We keep no copy. There is no server-side photo library to breach, subpoena or leak.
- We collect no location of any kind. Location data is stripped from the photo on your device before it is uploaded.
- There is no advertising SDK, no advertising ID, no App Tracking Transparency prompt, no attribution SDK and no third-party analytics.
- We do not sell or share your personal information, and we do not sell consumer health data.
2. What we collect, why, and how long we keep it
| What | Why | Where it goes | How long |
|---|---|---|---|
| Your photo of a skin concern — health data | Only to produce the optional photo supplement: a description of what is visible, conditions that can look similar, and questions to ask your clinician. | Uploaded to a private Cloudflare R2 bucket, then passed to Replicate and Google's Gemini model by a short-lived signed link that is never shown to you or to anyone else. The bucket has no public read access. | Deleted as soon as the analysis reaches a final state — typically a few seconds. A bucket lifecycle rule deletes anything left behind within 24 hours. |
| Your checklist answers — health data | The care level and timeframe are computed on your device. A copy of the answers accompanies the photo so the supplement is relevant to your situation. | Computed on device. Sent to our server only if you send a photo. | Held in memory for the length of the job. Not written to any database. |
| A random device token | To enforce the fair-use limit on photo analyses. It is a random value generated on your device and stored in the iOS Keychain. | Our server, with a per-day and per-month counter. | Kept while the app is installed. It is never derived from any Apple-issued ID and is never joined to anything else. |
| Purchase status | To unlock what you bought. | Apple. We may verify a receipt with Apple's servers. | Per Apple. We store no payment details; we never see your card. |
| Crash and performance diagnostics — optional, off by default | To fix crashes. | Apple, only if you opt in. | Per Apple. Never linked to your photos or answers. |
3. What we never collect
- Location, of any kind — no GPS, no coarse location, no IP-based location lookup, and no location permission is ever requested. Location data is removed from the photo on your device before it is uploaded.
- An advertising ID. There is no ad SDK, no App Tracking Transparency prompt and no SKAdNetwork.
- An account, an email address, a name, a phone number or a password.
- Contacts, calendar, microphone, or your photo library beyond the single image you pick.
- Face or body measurements. We do not create a template, a faceprint or any biometric identifier from your photo.
4. Who processes your data
Only these three companies ever touch your photo, and only as our processors:
| Processor | Role | What it sees |
|---|---|---|
| Cloudflare, Inc. (R2 object storage) | Short-term transit buffer | The image bytes, for seconds. The bucket is private; there is no public link. |
| Replicate, Inc. | Runs the model | The signed image link, the instructions we send, and the model's output. |
| Google LLC | Provides the model (Gemini 2.5 Flash), through Replicate | The same. |
No other third party receives your photo, your answers or your results. Ever. [TO BE COMPLETED — counsel to confirm the written no-training and retention terms obtained from Replicate, and the sub-processor list, before release.]
5. We do not sell or share your information
We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not sell consumer health data. There is no mechanism in this app or on this site by which we could: there is no ad SDK, no advertising ID, no attribution partner and no data broker relationship. We have never sold personal information or consumer health data, and we do not intend to.
6. Your choices and your rights
Because there is no account, most of your data is on your own device and under your direct control. For anything we hold, you may ask us to:
- Know what categories and specific pieces of personal information we hold about you, where it came from, why we have it, and who we disclosed it to.
- Delete it.
- Correct personal information that is wrong.
- Limit our use of sensitive personal information. We already limit it: your photo and answers are used only to provide the service you asked for, which is the use that California's limitation right exempts.
- Opt out of sale or sharing. There is nothing to opt out of, because we do neither.
- Withdraw consent to sending photos, at any time, in Settings.
You will never be treated differently for exercising any of these rights. If you are outside the United States, note that the app is offered in the United States only; we nevertheless apply the same standards of explicit consent, purpose limitation and deletion to everyone.
How to make a request, and how fast we answer
Email privacy@bulpara.com. We answer every privacy request within 45 days, and we require our processors to complete deletions within the same 45 days. If a request is genuinely complex we may extend once, and we will tell you why before the first 45 days are up.
Because we do not maintain accounts, we cannot verify you by looking you up. Verification, where the law requires it, will rely on information tied to the specific request or device. You may use an authorised agent; we may ask for proof of that authorisation.
7. Deleting everything
- In the app: Settings → Delete everything. One tap, one confirmation. This purges every record, every stored photo, your notes, and resets your consent to un-granted. Because we hold nothing on our servers, this is genuinely complete — we are not promising a server-side sweep that would have nothing to sweep.
- Server-side, anyway: the app can also ask our server to delete any object or job reference it still holds, and shows you a signed receipt of what was deleted.
- By email: privacy@bulpara.com, honoured within 45 days, including by our processors.
One thing is deliberately not deleted: the counter behind the fair-use limit on photo analyses. Deleting your history must not become a way to reset that counter. It contains no personal information — only a random token and a count.
8. Age
This app is not directed to children and is not designed for children. Its App Store carries the highest age tier Apple offers, and the Terms of Use require you to be 18 or older to use it. If a photograph is of a child, you must be that child's parent or guardian. We do not knowingly collect personal information from children. If you believe a child has provided us information, write to privacy@bulpara.com and we will delete it.
9. Security
Traffic is encrypted in transit. The storage bucket is private, with public read access disabled and asserted by an automated test. Photos are reachable only through a signed link that expires in minutes and is never given to the client, never logged, and never shared. Requests to our API require a key. No system is perfectly secure, and we do not claim otherwise — the mitigation we rely on most is simply not keeping your data.
If we ever suffered a breach involving health data, we would notify affected people within 60 days, and notify regulators and, above the legal threshold, the media, as the FTC's Health Breach Notification Rule requires.
10. Changes to this policy
If we make a material change we will update the date at the top and, where appropriate, tell you in the app. A material change to what we do with your photo re-prompts the in-app consent screen; it does not carry over silently.
11. Contact
- Privacy questions and rights requests: privacy@bulpara.com (45-day response)
- Product support: support@bulpara.com
- Postal address:
[TO BE COMPLETED] - Publisher: Bulpara Inc.,
[TO BE COMPLETED — registered entity and jurisdiction]