This Privacy Policy explains what data Sunstop collects, why, how it is used, and the rights you have over it. The app is operated by Aylan Apps (“we”, “us”, “our”). By using the app you accept this policy.
If anything here is unclear, email support@aylanapps.com.
1. What Sunstop is
Sunstop is a UV index and tan timer. From your skin type and the local UV forecast it estimates how long skin like yours can be in the sun today before burn risk rises, then runs a timer with flip, reapply and stop reminders. It is not a medical device and gives no medical advice. See the Sun Safety Information page.
The core of the app runs entirely on your device. You can use the UV forecast and the burn-time estimate without creating an account, and nothing about you is sent to our servers unless you sign in or turn on notifications.
2. Data we collect
2.1 Location
- With your permission, your device location (while the app is in use) is used to fetch the UV forecast for where you are. You can instead search for a city and never grant location access.
- On iOS the forecast comes from Apple Weather (WeatherKit), requested by the app directly from your device. Apple's handling of that request is governed by Apple's privacy policy.
- If Apple Weather is unavailable, the app falls back to Open-Meteo, an open weather API that receives only the coordinates and returns the forecast. The app shows which source it used.
- Your location is not stored on our servers unless you enable the UV or seasonal alerts (see 2.5), in which case a rounded position is kept so the alert can be computed for your area.
2.2 Skin profile and sessions
- Your answers to the skin type quiz, the resulting Fitzpatrick skin type, your sun goal, SPF and vitamin D target. These stay on your device.
- Your sun sessions (start and end time, planned and actual minutes, rounds, peak UV, place name). These stay on your device.
- If you sign in, the profile and sessions above are mirrored to our backend so your history follows you to a new phone. Signing in is optional.
2.3 Apple Health
- With your explicit HealthKit permission, Sunstop writes UV exposure, time in daylight and estimated dietary vitamin D for each completed session to Apple Health. It does not read any Health data.
- Health data is written only to the Health app on your device. It is never sent to our servers, never shared with third parties, and never used for advertising or marketing. It is not used to make decisions about you.
2.4 Account data (optional)
- If you create an account: an email address and a hashed password, or a sign-in token from Sign in with Apple or Google Sign-In. With Sign in with Apple you may hide your email; we then only receive Apple's relay address.
- Anonymous accounts use a random per-install identifier instead of an email.
2.5 Notifications
- Session reminders (flip, reapply, cool-off, done) are local notifications scheduled on your device. Nothing leaves the phone.
- If you turn on the morning UV alert or the seasonal alert, the app registers a push token (Firebase Cloud Messaging) together with a random install identifier, your time zone, your alert threshold, the app version and a rounded location. We use these only to send the alerts you enabled. Turning the alerts off stops the sending; deleting the app invalidates the token.
2.6 Purchases
Subscriptions are processed by the App Store or Google Play. RevenueCat receives the store receipt and tells the app (and, if you are signed in, our backend) whether your subscription is active. We never see your card details.
2.7 Diagnostics
Anonymised crash reports (Firebase Crashlytics) so we can fix bugs. They contain device model, OS version and a stack trace, not your profile or location.
3. How we use the data
- Compute the UV forecast and your burn-time estimate for where you are (contract).
- Run the session timer and its reminders (contract).
- Sync your profile and history across devices when you sign in (contract).
- Send the alerts you enabled (consent).
- Manage your subscription (contract).
- Fix crashes (legitimate interest).
We never:
- Sell your data.
- Show ads or share anything with advertisers.
- Send your Health data anywhere.
- Use your data to train AI models.
4. Third parties
- Apple Weather (WeatherKit): coordinates, to return the forecast. Requested from your device.
- Open-Meteo: coordinates, fallback forecast only.
- Apple HealthKit: session results written to the Health app on your device, with your permission.
- Firebase (Google): push tokens and crash reports.
- RevenueCat: subscription receipts and entitlement state.
- Apple App Store / Google Play: purchases and restores.
We do not transfer your data to any other third party for their own use.
5. Storage and retention
- Everything the app needs works from local storage on your device. Deleting the app deletes it.
- Our backend (for signed-in users and alert tokens) is hosted in the United States. The database is encrypted at rest and passwords are stored as salted hashes.
- Push tokens that have not been seen for 180 days are deleted.
- If you delete your account, your profile, sessions and tokens are removed within 30 days, except where law requires records to be kept.
6. Age
Sunstop is intended for users aged 16 and older. We do not knowingly collect data from children. If you believe a child has created an account, email us and we will delete it.
7. Your rights
- Access / portability: email support for an export.
- Correct: Me tab, edit your skin profile.
- Delete: Me tab, Settings, Delete account. See the Account Deletion page.
- Withdraw location or Health permission: your device Settings, at any time.
- Stop alerts: Me tab, or your device notification settings.
EU / UK users may lodge a complaint with their local data protection authority. California residents have the right to know, delete, correct and opt out of any “sale” or “sharing” of personal information. We do neither.
8. Security
- All API calls use HTTPS / TLS 1.2+.
- Access tokens are short-lived; refresh tokens live in the device keychain.
Report security issues to support@aylanapps.com.
9. Changes
We update this policy when our practices change. Material changes trigger an in-app notice.
10. Contact
Email: support@aylanapps.com