Your rosacea tracker says 'AI-optimized.' It never says where your face goes.
Trackers for a condition that lives on your face advertise smarter logging and stay silent on custody. The disclosure gap is the story, and on-device processing is the answer to it.
Three trackers, one missing sentence
Three shapes of rosacea tracker sit on the shelf right now. A printed patient diary from a nonprofit, the fill-it-in-by-hand kind. A face-scanning web tool that wants a selfie and hands back a score. A spreadsheet template from a small software shop, sold with a line about optimized logging and pattern detection.
All three tell you to photograph your face. Same angle, same light, once a week, for a couple of months, so your dermatologist has something sturdier than your memory of August. That's good advice, and dermatologists have been giving a version of it for years.
None of the three tell you where the photograph goes.
That gap isn't one company's oversight. Read across the listings and landing pages in this category and the same sentence keeps not being there: the plain one saying the image is processed on your device and never leaves it, or the equally plain one saying it's uploaded here, held this long, and reachable by these parties.
Custody before capability
Custody before capability. That's the bar we hold rosacea tracking to, and most of the category doesn't clear it.
A capability claim describes what software does with an image. Scores the redness. Counts papules, the small raised bumps that come with a flare. Surfaces a pattern across eight weeks. Those claims get the headline, the screenshot, the bolded bullet.
A custody claim describes where the image physically sits, who else can reach it, and what remains after you delete the account. Those turn up in paragraph nine of a privacy policy, written in the register of a legal disclaimer rather than a promise.
The order matters because a photo of your face isn't a photo of your ankle. Rosacea lives on the most identifying surface of the body, and it carries a documented social cost: across National Rosacea Society patient surveys, most respondents report lowered self-confidence, and a large share say the condition has made them avoid public contact or cancel social plans. An archive of that, dated and sequenced over months, is a dossier.
Encryption answers a different question
Ask whether the photos are secure and you'll get an answer about encryption. In transit, at rest, AES-256, the whole vocabulary. All of it can be true while the custody question stays wide open.
Encryption protects an image from someone intercepting it or lifting the disk. It does nothing about the party holding the key. That party can retain the file after you close your account, pass it to a subprocessor for storage or inference, reserve a training license in section seven, get acquired by a company with a different business model, or receive a subpoena. None of those events break the encryption. They just move the photo.
The same trapdoor sits under 'we never sell your data.' The FTC's health-app actions weren't about selling. They were about sharing, with advertising platforms, through tracking pixels and software kits the companies installed themselves. Selling and sharing are different verbs, and only one of them shows up in the reassurance.
The legal floor is lower than patients assume
HIPAA is the assumption most people bring to a skin-tracking app, and it's the wrong one. The law binds health plans, clearinghouses, providers who bill electronically, and the vendors working on their behalf. An app you download and use on your own is usually none of those. The same photo is protected inside your dermatologist's chart and unprotected inside a consumer app, on the same phone, taken the same morning.
What does apply is thinner than it sounds. The FTC has extended its Health Breach Notification Rule to reach health apps sitting outside HIPAA, and it has used that authority. GDPR treats health data as a special category, though a facial photograph only becomes regulated biometric data once it's processed specifically to identify a person, which is narrower than most readers assume. Illinois BIPA carries real statutory damages for face-geometry scans, and it protects Illinois residents.
Then there's the privacy label on the store listing. Developers write their own. Apple's guidance puts responsibility for accuracy on the developer, and no audit stands behind the summary you're reading.
$1.5M
GoodRx civil penalty, the first enforcement action under the FTC's Health Breach Notification Rule, for sharing user health information with advertising platformsFTC, 2023
$7.8M
BetterHelp settlement over sharing consumers' health data with advertisers after promising to keep it privateFTC, 2023
$100K
Premom (Easy Healthcare) penalty for disclosing users' sensitive health data to third partiesFTC, 2023
Photo, biometric, health record: three different legal objects
The same image of your cheek can be all three or none, depending on who holds it and what they do with it. In your dermatologist's chart, it's a protected health record under HIPAA. In a consumer app, it's ordinary personal data governed by that app's own policy and the FTC's general authority. Under GDPR, it becomes biometric data only when it's processed to identify you specifically, not merely because it shows your face. Assuming the strongest of the three applies is the mistake the category quietly relies on.
Eight weeks of Sundays
Picture eight weeks of Sundays. Same bathroom, same window, same angle on the left cheek, because your dermatologist asked for a baseline before starting anything. Call it twenty-four images, three per session. Alongside them you've logged what you drank, what the weather did, where you were in your cycle, and how the flare felt: burning, stinging, the sensory phenotype, meaning what the skin does rather than what it shows, which often runs ahead of visible redness on deeper skin tones.
That bundle is the single most useful thing you'll carry into the appointment. It's also the most sensitive file set you own, and its custody was settled by a design decision you never saw and can't read off the listing.
Three paths exist for those twenty-four images. The marketing copy treats them as interchangeable. They aren't.
The question
On-device only
The app's own cloud
Third-party vision vendor
Where the file actually lives
Your phone, in the app's sandbox, plus whatever backup you choose
The provider's storage, plus its backups and logs
The provider's storage plus the vendor's inference logs
Who can be compelled to produce it
You
The provider
The provider and a vendor you never picked
Blast radius if there's a breach
One phone
Every user in that bucket
Every user of every app on that vendor
What deleting the account removes
The files, as a file operation you can verify
Whatever the retention schedule says, on its own timeline
Unknown to the app, so unknowable to you
Who you have to trust
Your device maker
The company and its subprocessors
The company, its subprocessors, and the vendor's own policy
Structural comparison of the three custody models, scored on the questions a store privacy label doesn't answer. Not a ranking of named products.
What custody-first design costs
Treat custody as the requirement and the design narrows fast, in ways that cost something real.
Processing runs on the device by default, not as a toggle in settings that a later release can quietly flip. Nothing uploads in order for a feature to work. The app opens and functions without an account, because an account is an identity, and an identity is what converts a folder of photos into a record about a named person. Egress is user-initiated only: you export, you hand the file to your dermatologist, you decide. No analytics kit goes anywhere near the image path.
Here's the bill. Cloud-trained severity models are off the table. So is effortless cross-device sync. So is any in-app marketplace that routes your photos to a remote reviewer. A product that wants those features has to trade custody away to get them, and that's a legitimate trade for some people. It just has to be stated on the listing instead of buried in paragraph nine.
Where we land
Skinframe stores flare photos on the device that took them. No upload step, no bucket, no vendor in the middle. That decision fell out of the stakes analysis above, and it settled a second question we'd have had to answer anyway: we don't ship a face-scanning severity score. Adamson and Smith (JAMA Dermatology, 2018) set out how dermatology algorithms trained on light-skinned image sets underperform on darker skin, and Daneshjou and colleagues (Science Advances, 2022) measured that drop on a curated, diverse clinical image set. Building a scanner on that foundation would have meant shipping it worst for the users the literature already documents being failed.
What the app does instead is structure the record. Per-feature severity you score yourself instead of one blended number. Sensory symptoms logged next to visible ones. An export you hand to a clinician.
Skinframe doesn't diagnose anything, and neither does a photo archive. Take it to your dermatologist and let them read it. And if a tracker won't say where your face goes, read the silence as the answer.
Keep the photo record where it belongs. Get Skinframe and track flares with every image staying on your own device.
Skinframe is built by a small team that reads the dermatology literature before shipping a feature. Flare photos stay on the device that took them. There's no face-scanning severity score, because Adamson and Smith (2018) and Daneshjou et al. (2022) document what those models do to darker skin. And it's paid software, so the photo archive never has to earn its keep some other way.