Privacy Policy
Effective date: 3 September 2026 · Last updated: 3 September 2026
ANKO SOLUTIONS L.L.C (“we”, “us”, “our”) operates Easly (the “App”), a skin-tracking application for iOS and Android. This policy explains what the App collects, where that data goes, how long we keep it, and what you can ask us to do with it.
Easly asks for two of the most sensitive things there are: a photograph of your face and information about your health. This policy is written so you can decide whether to give them.
By installing or using the App you agree to this policy and to our Terms of Use. If you do not agree, do not install the App.
Short version. Your daily log and selfies live only on your device. Photographs of product labels are read on the phone and never uploaded. A selfie is sent through our skin-analysis service to OpenAI to be scored; we do not retain it after analysis. Approximate coordinates go to a weather service. We do not sell your data and we never use your photos, skin readings or health logs for advertising.
1. Who is responsible for your data
| Controller | ANKO SOLUTIONS L.L.C |
| Commercial registration no. | 1778509 |
| Licence no. | 1084972 |
| Registered address | Office 2401 A-33, Clover Bay Tower, Marasi Drive, Business Bay, Dubai, United Arab Emirates |
| Contact for privacy matters | a@anko.solutions |
Write to the address above for any request in this policy — access, correction, deletion, objection, or a question about a specific processing activity. We answer privacy requests within 30 days.
2. There is no account
Easly has no sign-up. There is no email address, no password, no social login, and we do not ask for your name. The App identifies your installation to our servers with a device-level identifier so that a request for a skin analysis can be authenticated.
Two consequences worth knowing:
- We normally cannot tell who you are from the data we hold. To act on a deletion request we may need you to send the device identifier the App shows in Settings, otherwise we cannot find the right records.
- Your logs are tied to that installation. Delete the App or move to a new phone and the timeline starts again — there is no cloud backup to restore from.
3. What the App collects
3.1 Photographs of your face
The App takes a selfie with the camera, or lets you pick one from your photo library. Before it is sent, the image is resized so its longest side is about 2048 pixels and re-encoded as JPEG.
Sent with the photo: your sex (only if you answered “male” or “female” in the questionnaire) and your age in years, because the analysis is calibrated on both. Nothing else — not your logs, not your location, not your name. The App sends this data to our analysis endpoint, which transfers it to OpenAI solely to produce the analysis.
What comes back and is stored on your device with the photo: a skin balance score out of 100, separate barrier, hydration, texture and complexion readings, and the coordinates of the areas the analysis marked. We do not retain the selfie after analysis.
Legal basis (GDPR/UK GDPR): your explicit consent to process biometric-adjacent and health data — Art. 9(2)(a). You give it by submitting the photo for analysis, and you can withdraw it at any time by not submitting further photos or writing to us.
3.2 Your skin and health profile
From the onboarding questionnaire and the setup screens:
- gender and age;
- skin concerns, how often you break out, how much it bothers you, what you have already tried;
- your current routine;
- allergies and ingredients you exclude;
- medications you are taking;
- if you choose to track it: menstrual cycle start date, cycle length and rhythm, and whether your skin changes with your cycle.
This is health data. It is processed on your explicit consent, and it exists so the App can compare like with like — a hormonal week should not get blamed on last night’s dinner.
3.3 Your daily log
What you ate, how you slept, stress, mood, your routine, products used, notes you type, and the elimination trials you run.
This stays on your device. It is written to an application database (easly_app.db) in the App’s private storage, together with the patterns computed from it. It is not uploaded to us, and it is removed when you delete the App.
3.4 Approximate location, for weather
Dry air, heat and strong sun show up on skin, so the App can attach weather to your logged days. You can:
- allow approximate location while the App is open, or
- type a city by hand, or
- skip it — the App works without weather.
If you allow it, coordinates are sent to Open-Meteo to fetch current, forecast and historical daily weather (temperature, humidity, UV and related fields), and to BigDataCloud to turn coordinates into a city name for display. City search by name also goes to Open-Meteo’s geocoding endpoint. No identifier, no log and no photo is sent with those requests.
We do not collect background location, and we do not build a location history.
3.5 Photographs of product labels
When you check a product, the App photographs the ingredient list and reads it with Google ML Kit text recognition running on the device. The image is not uploaded to us or to anyone else, and the feature works with no connection. The recognised text is compared against your exclusions locally, and you can correct a misread word before the verdict.
3.6 Recipes
Recipe content is fetched from TheMealDB. The App asks it for categories and dishes; it does not send your profile, your exclusions or any identifier. Filtering the results against your exclusions happens on your phone.
3.7 Device, diagnostic and usage data
Collected automatically to run, measure and fix the App:
- device model, operating system and version, app version and build, language and region, time zone;
- a device-level identifier used for authentication and for de-duplicating analytics;
- app-open, screen-view, onboarding-step, paywall and purchase events;
- crash reports and diagnostic logs — stack traces, device state at the time of the crash.
Legal basis: our legitimate interest in operating, securing and improving the App, and in measuring our own marketing. Where local law requires consent for analytics or advertising identifiers, we ask for it first.
3.8 Advertising identifier
We measure which advertising campaigns bring people to Easly, so we can spend less on ads. On iOS this uses your advertising identifier (IDFA) only if you allow it in the App Tracking Transparency prompt; decline and attribution runs without it. On Android the Google Advertising ID is used, and you can reset or limit it in system settings.
We do not use your photos, skin readings, questionnaire answers or daily logs for advertising, and we do not build advertising profiles from them.
3.9 Notifications
If you turn on reminders, daily check-in and weekly-summary notifications are scheduled on your device. We also register a push token with Firebase Cloud Messaging so we can send service and product messages. You can turn all of it off in the App or in system settings.
3.10 Purchases
Subscriptions are sold and charged by Apple or Google, not by us. We receive the subscription status and the store’s purchase identifiers so the App knows what to unlock. We never see or store your card number, bank details or billing address.
4. What we do with it
| Purpose | Data used |
|---|---|
| Score your skin and mark the photo | Selfie, sex, age |
| Track change over time | Photos, skin-analysis scores and markings |
| Find what affects your skin | Daily log, health profile, cycle, weather (on your device) |
| Tell you what to skip and what to eat | Confirmed patterns, exclusions, recipes |
| Check a product against your triggers | Label text read on device, exclusions, medications, skin type |
| Attach weather to your days | Approximate coordinates or chosen city |
| Send reminders you asked for | Notification settings, push token |
| Unlock what you paid for | Subscription status from the store |
| Keep the App working and safe | Device and diagnostic data, crash reports |
| Measure our own advertising | Install and event data, advertising identifier (with permission) |
We do not use your data to train third-party AI models for their own purposes, and we do not make automated decisions with legal or similarly significant effects about you.
5. Who we share it with
We do not sell personal information. We do not share it for cross-context behavioural advertising. We share only what each of these providers needs to do its job:
| Provider | What it receives | Why |
|---|---|---|
| Our skin-analysis service and OpenAI | Selfie, sex, age | Produce the score and marks |
| Google Firebase — Analytics, Crashlytics, Cloud Messaging | Device and usage events, crash reports, push token | Product analytics, crash fixing, notifications |
| AppsFlyer | Install and event data, advertising identifier (with permission) | Attribute installs to campaigns |
| Meta (Facebook) App Events | App events, advertising identifier (with permission) | Measure advertising on Meta platforms |
| Open-Meteo | Approximate coordinates or a city name | Weather and historical weather |
| BigDataCloud | Approximate coordinates | Turn coordinates into a city name |
| TheMealDB | Recipe queries only, no personal data | Recipe content |
| Apple App Store / Google Play | Purchase and subscription events | Sell and renew subscriptions |
| Google ML Kit | Nothing leaves the device | On-device label reading |
We may also disclose data where the law requires it, to protect our rights or someone’s safety, or to a buyer as part of a merger or sale of the business — in which case this policy continues to apply until you are told otherwise.
6. Where your data is processed
We are established in the United Arab Emirates. Our providers operate globally, so your data may be processed outside your country, including in the United States and the European Union.
For transfers of personal data out of the EEA, the UK or Switzerland we rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum where relevant) with each provider, together with the technical measures in section 8. For transfers out of the UAE we rely on the mechanisms permitted by Federal Decree-Law No. 45 of 2021.
7. How long we keep it
| Data | Retention |
|---|---|
| Daily log, health profile, patterns, trials | On your device until you delete them or uninstall the App. We hold no copy. |
| Selfies and their scores | Stored only on your device while you use the App, so later photos can be compared with earlier ones. We do not retain selfies after analysis. They are deleted when you delete them in the App or uninstall it. |
| Product-label photos | Never stored by us. Discarded by the App after the label is read. |
| Analytics and attribution events | Up to 26 months, then deleted or aggregated so they no longer identify a device. |
| Crash reports | Up to 90 days. |
| Purchase records | As long as tax and accounting law requires. |
8. How we protect it
Traffic between the App and our services runs over TLS. Requests to the analysis service are authenticated. Photos are downsized before they are sent, so no more of the image travels than the analysis needs. Access to production systems is limited to staff who need it. Your on-device data sits in the App’s private storage, protected by your device’s own encryption and passcode.
No system is perfectly secure. Keep your device locked and its software current — that is a real part of this.
9. Your rights
Wherever you live, you can ask us to:
- tell you what personal data we hold about you and how we use it;
- give you a copy in a portable format;
- correct anything inaccurate;
- delete it;
- stop or restrict a particular use, including analytics and attribution;
- withdraw consent to processing your photos or health data, at any time — withdrawal stops future processing and does not undo what was already done lawfully.
If you are in the EEA, the UK or Switzerland, these are your rights under the GDPR / UK GDPR, and you may complain to your national supervisory authority. If you are in the United Arab Emirates, they are your rights under Federal Decree-Law No. 45 of 2021. If you are in California, you have the rights to know, delete, correct and opt out under the CCPA/CPRA, and we will not discriminate against you for exercising them — note that we do not sell or share personal information as those terms are defined there.
In practice: most of your data is already only on your phone. Deleting the App deletes it. For anything on our side, write to a@anko.solutions — include the device identifier from Settings in the App, or we may not be able to locate your records.
You can also, at any time, revoke camera, photo-library, location, notification and tracking permissions in your device settings. The App keeps working; the features that need them do not.
10. Children
Easly is not for children. You must be at least 16 to use it (or older, if your country sets a higher age for consenting to health-data processing). We do not knowingly collect data from children. If you believe a child has used the App, write to us and we will delete the data.
11. Easly is not a doctor
Easly is a tracking and pattern-finding tool. It is not a medical device, it does not diagnose or treat skin conditions, and its findings are statistical associations in what you logged — not a clinical judgement about you.
The product check reads what is on a label, not how much of it is inside, and it is not a verdict on whether something is safe for you. See a dermatologist or your doctor for anything painful, spreading, or not improving, and do not stop prescribed treatment because of something this App told you.
12. Changes to this policy
We will update this page when the App changes. The date at the top always reflects the current version. If a change materially affects how we use data you already gave us, we will tell you in the App before it takes effect and, where the law requires it, ask for your consent again.
13. Contact
ANKO SOLUTIONS L.L.C Office 2401 A-33, Clover Bay Tower, Marasi Drive, Business Bay, Dubai, United Arab Emirates Commercial registration no. 1778509 · Licence no. 1084972 a@anko.solutions