Your data
Privacy Policy
Last updated August 17, 2026
AnyDermNow is a booking and records service that connects you with a dermatology clinic. This policy covers the AnyDermNow website and the AnyDermNow mobile app. It explains what we collect, how we collect it, every purpose we use it for, who else can see it, how long we keep it, and how you delete it.
Your care is delivered by the clinic you choose. That clinic keeps its own medical record about you, governed by its own privacy practices and its HIPAA Notice of Privacy Practices.
What we collect
Account details you enter. Your first and last name, email address, date of birth, and password. A phone number and a city or ZIP code if you choose to add them.
Health information you provide. The reason for your visit, photos of skin concerns that you upload, your insurance details and any photo of your insurance card, and messages you exchange with your clinic.
Records you choose to import. If you connect a health record from Epic or NextGen, we retrieve the history that connection covers, such as visits, conditions, and medications. This happens only after you sign in to that system and authorize it, and you can disconnect it at any time.
Appointment and account activity. The appointments you book, change, or cancel, your notification preferences, and a security log of when your record was read or written and by whom.
Technical information. Sign-in session tokens, and standard server logs that record request timing and errors using opaque identifiers. Our logs are built to exclude health information and personal identifiers by policy.
How we collect it
Almost all of it comes directly from you: you type it into a form, you upload a photo, or you authorize a connection to Epic or NextGen. We do not buy personal information, and we do not collect it from data brokers, advertising networks, or social networks.
The mobile app can use your device location, with your permission, to sort clinics by distance and center the map. That location is used on your device only, for as long as the app is open. It is never sent to our servers and never saved to your record. You can decline the permission and search by city or neighborhood instead.
How we use it
We use your information to create and secure your account, to show you clinics and available appointment times, to book and manage your appointments, to give the clinic you chose what it needs to prepare for your visit, to send you email about your appointments and account, to keep the security and audit records that health privacy law requires of us, and to diagnose faults and keep the service running.
That list is exhaustive. We do not use your information for advertising or marketing profiles, we do not use it to train machine learning models, and we do not sell or rent it to anyone. AnyDermNow runs no third-party analytics, advertising, or tracking software in its website or its mobile app, and does not track you across other companies' apps and sites.
Who we share it with
The clinic you book with. Staff at that clinic see the information you shared for your care. Staff at other clinics cannot. Access is limited by role, so front desk staff who only schedule do not see clinical details.
Vendors that run our infrastructure. Fly.io hosts the application and the encrypted database. Amazon Web Services stores uploaded photos and sends our email. These vendors store or transmit your information so the service can function. They do not use it for their own purposes.
Nobody else, unless you ask or the law requires it. We disclose information outside the above only with your direction, or where we are legally compelled to, such as a valid court order.
Two supporting services are worth naming because they are visible to you, and neither receives health information: Cloudflare provides our domain name service, and the map in the Android app is drawn by Google Maps, which receives only the map area being displayed. The iOS app uses Apple Maps.
What we require of those vendors
Every vendor that stores or transmits health information for us is under a signed business associate agreement, the contract HIPAA requires. That contract obliges them to protect your information to the same standard stated in this policy, to use it only to deliver the service to us, to report any breach, and to return or destroy the information when our relationship ends. It binds their own subcontractors to the same terms. We do not send your information to any company that has not signed one.
How we protect it
Your information is encrypted while stored and while moving across the network. Photos are held in encrypted storage and reached only through short-lived signed links. Every read and write of your record is written to an audit log that cannot be edited or erased after the fact. Access is granted by role and limited to the clinic treating you. You can add a second sign-in factor from your security settings.
No service can promise perfect security, and we do not. If a breach affects your information, we will notify you as health privacy law requires.
How long we keep it, and how to delete it
We keep your information while your account is open, and for as long afterward as law requires us to retain the associated security records.
You can delete your account at any time. In the mobile app, open Settings and choose Delete account. On the web, go to Settings, then Delete account. We ask you to confirm by typing your email address, because the deletion cannot be undone.
Deleting removes your profile, your insurance details, your uploaded photos, your appointments, your messages, any records imported from a connected health system, and your sign-in itself.
Two things survive, and you should know about both. The clinic that treated you keeps its own copy of your medical chart, which health law requires it to retain and which is outside our control. And the audit log recording who accessed your record is retained as required, in a form that identifies the record rather than describing your health.
Your choices and withdrawing consent
You can review and correct your profile at any time from Settings. You can turn off categories of email notification from your notification preferences, though we still send messages essential to an appointment you have booked. You can disconnect a linked Epic or NextGen record, which stops any further import. You can decline the location and photo permissions on your phone and still use the service. And you can delete your account outright, as described above, which withdraws your consent entirely.
Depending on where you live, you may have further rights to access, to correct, to export, or to restrict the use of your information. Write to us at the address below and we will honor them.
Children
AnyDermNow accounts are for adults booking care for themselves. We do not knowingly create accounts for children under 18. If you believe a child has created an account, write to us and we will delete it.
Changes to this policy
If we change this policy we will update the date at the top of this page. If a change materially affects how we handle information we already hold about you, we will tell you by email before it takes effect.
Contact us
Questions about this policy, or about the information we hold about you, go to privacy@anydermnow.com. We answer privacy requests within 30 days.