SUNKIND
Privacy Policy
Effective date: July 22, 2026
SunKind (the “App”) is provided by Hamza Canbaz (“we,” “our,” or “us”). This Privacy Policy explains how we collect, use, share, and protect information when you use SunKind.
1. Introduction
SunKind provides environmental UV forecasts, outdoor timers, protection reminders, a personal routine, and an optional selfie appearance scan. It is designed to keep outdoor-session history on your device while securely storing selfies and scan results you choose to save. SunKind does not use advertising, tracking, HealthKit, or background location.
2. Information we collect
We may collect the following categories of information:
- Local profile and routine data: Your selected outdoor goal, self-reported skin response, sunscreen setting, chosen SPF, and the resulting 10-week routine. Your profile and the routine are stored locally; completed onboarding answers and the resulting routine are also stored with your anonymous Firebase app identity so the plan can be restored for that identity.
- Local activity and timer data: Outdoor-session records, timer state, session notes, dates, duration, and local totals. These records remain on your device and are not uploaded to our servers.
- Location and forecast data: If you choose “Use my location,” the App receives an approximate location while it is open, sends it to Apple Weather to request local conditions, and stores a general place label and forecast in its local cache. We do not save coordinates in your session history or send them to Firebase or RevenueCat.
- Optional selfie appearance scan: If you choose “Take a selfie,” the App uploads the selfie to your private Firebase Storage area and sends it to OpenAI through a Firebase Function to derive four cosmetic appearance indicators: shade, glow, evenness, and redness. The selfie and result are saved to your private in-app photo album.
- Anonymous account information: An anonymous Firebase Authentication user ID and a related Firebase record containing account creation and last-seen timestamps, plus completed onboarding answers, the generated routine, and selfie scan metadata and results.
- Purchase and subscription information: Subscription and entitlement status, product identifiers, renewal status, transaction identifiers, and related event timestamps supplied by Apple and RevenueCat. We do not receive your full payment-card details.
- Support information: Information you provide when you email support, such as the contents of your email and any device details you choose to include.
3. How we collect information
- Directly from you: When you complete onboarding, use an outdoor timer, save a session, choose to use your location, take an optional selfie, purchase or restore a subscription, or contact support.
- Automatically through the App: When the App creates an anonymous Firebase identity, saves app data locally, obtains the forecast you request, or checks your subscription entitlement.
- From service providers: When Apple, Firebase, OpenAI, or RevenueCat provide weather, authentication, AI analysis, purchase, subscription, or infrastructure information needed to operate the App.
4. How we use information
- To provide local UV conditions, timers, protection reminders, and your personal routine.
- To provide and save the optional cosmetic appearance indicators you request from a selfie. These indicators are not medical advice, a diagnosis, a skin-health assessment, or a safe-exposure calculation.
- To create and maintain an anonymous app identity and restore the routine associated with it.
- To provide SunKind Plus, restore purchases, and confirm premium access.
- To respond to support requests and maintain the security and operation of the App.
- To comply with legal obligations and protect our rights, users, and services.
5. Local and cloud storage
SunKind keeps core activity data on your device and stores the connected data described below in Firebase:
- Outdoor activity: Timer state, outdoor-session logs, cached forecasts, profile information, and the routine are stored locally in the App’s storage.
- Location: The App requests location only after you choose to use it and only while the App is open. It requests approximate accuracy, uses the location to obtain local UV conditions from Apple Weather, and does not retain coordinates in your history.
- Selfie appearance scan: Your chosen selfie is stored in a user-scoped Firebase Storage location. Our Firebase Function reads the image in memory and sends it to OpenAI for the requested analysis; the Function requests that OpenAI not store the API response. The photo and its four appearance scores remain available in your private photo album until you delete your app identity.
- No cloud session log: We do not upload your outdoor-session logs or location coordinates to our backend or RevenueCat.
6. Data sharing and disclosure
We do not sell personal data or use the App to serve third-party advertising. We may share limited information with the following recipients:
- Apple: To provide WeatherKit weather data, system location services, in-app purchases, and payment processing.
- Firebase: For anonymous authentication, user-scoped selfie storage and scan results, the anonymous user record, completed onboarding answers, the generated 10-week routine, and the minimal subscription-event records needed to maintain server-managed SunKind Plus status.
- OpenAI: To analyze the selfie you choose to submit and return the four cosmetic appearance indicators. We request API response storage to be disabled.
- RevenueCat: For subscription and purchase management using the anonymous app identity.
- Legal or safety reasons: If required by law or reasonably necessary to protect rights, users, systems, or services.
Apple, Firebase, and RevenueCat process data under their own privacy policies.
7. Data retention and deletion
We retain information only for as long as necessary for the purposes described in this Privacy Policy.
- Local data: Your profile, timer, cached forecast, routine, and outdoor-session history remain on your device until you delete them in the App, delete the App, or clear the App’s storage.
- Anonymous account, scans, and plan data: You can select “Delete app identity & local data” in Profile. This removes the anonymous Firebase identity, associated onboarding answers and routine, subscription-event records, stored selfies and scan results, and the local App data described above.
- Purchase records: Apple and RevenueCat may retain purchase and transaction information under their own retention practices, including where needed for accounting, fraud prevention, or legal obligations. Deleting local data or the anonymous identity does not delete those records.
- Support communications: We retain support emails only as needed to respond to and manage your request or meet legal obligations.
8. Your choices
- Location: You can decline location access and use the clearly labelled preview state, or change location permission in iOS Settings.
- Camera: You can decline camera access or change camera permission in iOS Settings. The optional appearance check is unavailable unless you choose to grant access and take a selfie.
- Local deletion: You can delete all local App data from Profile.
- Identity deletion: You can delete your anonymous Firebase identity and the connected App data from Profile.
- Subscriptions: You can manage or cancel a subscription through your Apple ID subscription settings and restore eligible purchases from Profile.
- Support: You decide whether to contact us by email and what information to include.
9. Security
We use reasonable administrative, technical, and organizational measures designed to protect information. However, no method of storage or transmission is completely secure, and we cannot guarantee absolute security.
10. Children's privacy
SunKind is not directed specifically to children under 13. If you believe a child has provided personal information in a way that requires removal, please contact us.
11. International data transfers
Our service providers, including Apple, Firebase, OpenAI, and RevenueCat, may process information in countries other than your own. By using SunKind, you understand that relevant information may be processed and stored in other jurisdictions, subject to applicable law.
12. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the effective date above. Your continued use of SunKind after the updated policy becomes effective means you accept it.
13. Contact us
If you have questions or privacy requests, contact us at spanky.global@gmail.com.