NailGuard AI
Privacy Policy
Last updated August 12, 2026
NailGuard keeps your journal local by default. This policy explains what remains on your device, what is sent when you confirm cloud analysis or separately contribute a selected photo, and the choices available to you.
1. Local journal data
Scans, photo-journal trackers, notes, and check-ins are stored on your device. JTR Labs does not collect this local information through ordinary journal use.
2. Cloud AI analysis
NailGuard runs local image-quality checks first. To request an AI appearance estimate, you must confirm cloud processing for the selected photo each time. The app resizes and re-encodes that photo to remove embedded metadata, then sends the prepared JPEG over HTTPS to JTR Labs. JTR Labs relays it to Meta Model API using Muse Spark 1.1 and returns the structured estimate.
JTR Labs does not add cloud-analysis photos to the contribution library or retain them as model-development contributions. Meta and infrastructure providers process the photo to provide and secure the requested feature under applicable service terms and agreements. That processing may include limited security logging or retention governed by those terms. Journal notes, tracker names, and check-ins are not sent for cloud analysis.
To protect the service and enforce AI allowances, NailGuard uses Apple's App Attest. The app sends an installation-scoped, hardware-backed key identifier and signed attestation or assertion data. JTR Labs stores the verified public key, attestation receipt, assertion counter, and created, last-used, and revocation times, and associates that installation record with model-use reservations and allowance records. This identifier is used for app integrity, fraud prevention, replay protection, and allowance enforcement—not advertising or cross-app tracking.
To limit automated abuse, the service derives a daily rotating pseudonymous value from the source network address and a server secret. The original address is not stored in an analysis record. A cloud-analysis photo is not used to train a NailGuard model unless you separately use the contribution feature below.
3. Optional photo contributions
Contribution is off by default, unpaid, and not required for core features. Opting in only enables a contribution control; nothing uploads automatically. You must select and confirm each photo separately.
For a photo you explicitly contribute, NailGuard sends:
- a re-encoded JPEG copy intended to remove embedded metadata such as capture location;
- the appearance label you select;
- the app's estimate, confidence, analysis disposition, and model version;
- app version, photo date, consent version and time; and
- random contribution and participant identifiers not based on your name, email, Apple ID, advertising ID, or hardware identifier.
Journal notes, tracker names, check-ins, name, email, and device identifiers are not attached to a contribution.
To limit automated abuse, the service combines the source network address with a server secret to create a daily rotating pseudonymous rate-limit value. The original address is not stored in the contribution record, and the rotating value is not attached to the photo.
4. Use and service providers
JTR Labs may review contributed photos and use them to develop, train, test, validate, improve, and commercialize NailGuard models and related safety systems. Contributions are not sold, used for advertising, or used for cross-app tracking. Infrastructure providers may process or store contributions on JTR Labs' behalf and must protect the data consistently with this policy.
5. Retention, withdrawal, and deletion
You can stop future contributions at any time in the app without losing core features. Stopping future contributions does not delete previously submitted copies. Each accepted contribution receives an opaque deletion credential stored securely on your device.
Request deletion of a retained photo from Settings → Contribution History. Raw contributions are kept only while useful for the disclosed development and validation purposes or until a valid deletion request is completed. They are reviewed periodically and removed when no longer needed.
Deletion may not remove information already incorporated into aggregated measurements, completed model training, or model versions created or released before the request. A deleted raw photo will not be used in new training or validation work after deletion is completed.
A minimal tombstone containing the opaque contribution ID, consent version and time, deletion time, and a one-way deletion-credential hash may be retained to document and secure the completed request. Daily rate-limit records are kept only for a short abuse-prevention window.
App Attest installation-integrity and related allowance records are retained while reasonably needed to validate the installation, prevent abuse and replay, enforce allowances, document service transactions, and resolve security or billing disputes. They may remain after the app is removed because JTR Labs cannot automatically detect an uninstall. You may contact [email protected] about these records; legal, security, and fraud-prevention obligations may require limited continued retention.
6. Security
Cloud-analysis requests and contributions are transmitted over HTTPS. Retained contributions are stored in non-public infrastructure. No method is perfect, but JTR Labs uses reasonable technical and organizational safeguards designed to limit unauthorized access.
7. Analytics, ads, and notifications
NailGuard does not include third-party analytics or advertising SDKs at this time. Daily check-in reminders are local notifications; check-in data is not sent off-device for reminders.
8. Subscriptions and AI allowances
Apple processes subscription purchases and provides NailGuard with transaction and entitlement information needed to unlock paid features, restore purchases, respond to refunds or revocations, and manage AI usage allowances. NailGuard does not receive your full payment-card details.
The app may send Apple-signed entitlement proof to JTR Labs with a cloud-analysis request so the service can confirm access and enforce a request allowance. JTR Labs uses that proof for subscription access, fraud prevention, allowance accounting, and customer support—not advertising or cross-app tracking.
9. Website data
This informational website does not ask you to create an account or upload a nail photo. Like most hosted services, infrastructure may process basic request information such as network address, browser type, requested page, time, and security events to deliver and protect the site. NailGuard does not use this website information for advertising or cross-app tracking.
10. Age limits
NailGuard is not directed to children under 13. Photo contribution is limited to people who confirm that they are at least 18 and have the right to share the selected photo.
11. Your choices and contact
Delete local journal data from Settings → Local Data. Use Contribution History for server-copy deletion. If an in-app request cannot be completed, email [email protected] with the opaque contribution ID and deletion code if available. Do not email the nail photo.