The short version
- Your sunscreen scan photo is analysed on your device. It is only uploaded if you separately turn on cloud assist.
- Location is read only while the app is open, and only to fetch the UV index where you are. Sunly has no background location tracking.
- We do not sell your data, share it with data brokers, or use it for advertising. There is no advertising SDK in the app.
- You can delete your account from inside the app, under Settings, and everything in it goes with it. You can also ask us at support@consunly.com.
- Sunly gives sun-safety guidance, not medical advice.
Contents
1. Who we are
Sunly is a sun-safety app that estimates sunscreen coverage from a photo, tracks the UV index where you are, reminds you to reapply, and keeps a record of your protection habits over time.
In this policy, "Sunly", "we" and "us" mean the team that publishes the Sunly app. The app is distributed on the Apple App Store under the Apple Developer account Con Filactos and on Google Play under the Sunly developer account.
For any privacy question, or to exercise any right described here, contact support@consunly.com. We are the data controller for the information described below.
2. What we collect
We only collect what the features you use actually need. Nothing below is bought from third parties or inferred from data brokers.
| Category | What it is | When we get it |
|---|---|---|
| Account | Email address, password (stored only as a bcrypt hash, never in readable form), display name. | When you register. |
| Sun profile | Skin type, lifestyle choices, time zone, and an optional home location (approximate latitude and longitude). | During onboarding and whenever you edit your profile. |
| Scan results | Estimated coverage score, confidence level, which body zones looked unprotected, and the assessment text generated for that scan. | Each time you run a scan. See section 3 for the photo itself. |
| Location | Approximate or precise coordinates, used to look up the UV index. | While the app is open and you have granted location permission. See section 4. |
| Habits and wellbeing | Daily self-reported check-ins: whether you applied sunscreen, hydration, mood, and similar sun-safety habits. | Only when you fill in a daily check. |
| Progress data | Daily sun-safety scores, streaks, challenge participation, badges and points. | Calculated from your activity in the app. |
| Family members | Names or nicknames you add for people you are tracking, their protection status, and invite codes. | Only if you use the family feature. See the note below. |
| Chat messages | Messages you send to Sunny, the in-app assistant, and its replies. | When you use the chat. See section 6. |
| Notification settings | Reminders you set, quiet hours, and a push notification token for your device. | When you enable notifications or set a reminder. |
| Diagnostics | Crash reports and technical error data, including device model, operating system version and a crash stack trace. | Automatically, if the app crashes. |
Sunly does not collect your contacts, your photo library, your browsing history, your advertising identifier, or your microphone audio. The app declares a microphone permission on iOS only because the camera library it uses references that API; Sunly never records audio.
3. Scan photos
This is the part of Sunly people ask about most, so here is exactly how it works.
When you take a scan, the photo is analysed on your device. The app uses on-device machine learning to separate you from the background, find body landmarks, and estimate how much of each visible zone looks covered by sunscreen. The result of that analysis is a small set of numbers: a coverage value per body zone and a confidence level.
By default, only those numbers leave your device. The photo does not.
If you separately turn on cloud assist for a scan, the photo is uploaded to our storage so a vision model can give a second opinion on coverage. This is an explicit, per-scan choice and it is off unless you turn it on. Uploaded images are used to produce your result, and are used to improve the scan model only if you also give training consent.
You can withdraw cloud assist or training consent at any time in the app, or by emailing us. Withdrawing consent stops future uploads; to have images already uploaded deleted, contact us.
4. Location
Sunly requests when in use location only. The app reads your location while you have it open, sends the coordinates to a UV data provider, and shows you the UV index and forecast for that spot.
Sunly does not track your location in the background, does not build a location history, and does not use location for advertising.
On iOS you may see purpose strings mentioning "always" location. Those exist because the location library the app is built on references those system APIs, and Apple requires a description for every referenced API. Sunly never requests always-on authorization.
You can revoke location permission at any time in your device settings. The app still works; you will need to tell it where you are for UV data, and some UV features will be limited.
5. Notifications
If you allow notifications, we register a push token for your device so we can send UV alerts, reapply reminders, and streak notices. The token identifies the installation, not you personally, and is deleted when it stops working or when you delete your account.
You control which notifications you get and set quiet hours in the app, and you can turn notifications off entirely in your device settings.
6. Sunny chat
Sunny is the in-app assistant. Messages you send and the replies you get are stored against your account so the conversation has continuity and so we can improve how well Sunny understands requests.
Most replies are produced by a rule-based engine that runs on our own server. Some requests fall back to a third-party language model provider, in which case the text of your message is sent to that provider to generate a reply. Do not put sensitive personal or medical details into the chat.
7. Why we use your data, and our legal basis
| Purpose | Data used | Legal basis (UK/EU GDPR) |
|---|---|---|
| Create and secure your account | Account | Performance of a contract |
| Estimate sunscreen coverage and show results | Scan results, sun profile | Performance of a contract |
| Upload a scan photo for a cloud second opinion | Photo | Consent |
| Use a scan photo to improve the model | Photo | Consent |
| Show the UV index where you are | Location | Consent (device permission) |
| Send reminders and alerts | Push token, notification settings | Consent (device permission) |
| Track scores, streaks, challenges and badges | Habits, progress data | Performance of a contract |
| Answer questions in chat | Chat messages | Performance of a contract |
| Fix crashes and keep the app stable | Diagnostics | Legitimate interests |
Some of what Sunly stores, such as your skin type, your scan results and your daily wellbeing check-ins, may be treated as health-related data in your country. Where that is the case, we rely on your explicit consent, given when you enter that information. You can withdraw it by deleting the data or your account.
9. How long we keep it
- Account and profile: until you delete your account.
- Scan results, scores, streaks and check-ins: until you delete your account, because the point of the feature is a history you can look back on.
- Uploaded scan photos: only where you gave cloud assist consent, and deleted on request.
- Chat messages: until you delete your account. Chat sessions themselves expire after 15 minutes of inactivity.
- Push tokens: removed automatically once they stop working.
- Crash diagnostics: retained by Firebase Crashlytics under Google's retention schedule, typically up to 90 days.
10. Your rights
Depending on where you live, you may have the right to:
- ask what personal data we hold about you and get a copy of it,
- correct anything inaccurate,
- delete your data,
- restrict or object to how we use it,
- withdraw a consent you gave, without affecting what we did before you withdrew it,
- ask us to transfer your data to another service,
- complain to your local data protection authority.
If you are in California, you also have the right to know, delete, correct, and to opt out of sale or sharing. We do not sell or share personal information as those terms are defined by the CCPA, and we will not discriminate against you for exercising any right.
To exercise any of these, email support@consunly.com from the address on your account. We respond within 30 days.
11. Deleting your account
In the app: open Settings, scroll to the bottom, and tap Delete account. You are signed out immediately and the account is erased. There is no waiting period and no undo.
By email: if you cannot sign in, email support@consunly.com with the subject "Delete my account", from the email address registered to the account.
Full details are on the account deletion page.
We will delete your account record, sun profile, scan results and any uploaded scan images, daily check-ins, scores, streaks, challenge history, badges, points, family entries, reminders, notification settings and chat history. Backups are purged on their normal rotation. We may keep a minimal record of the deletion request itself to show we honoured it.
Deleting the app from your phone does not delete your account. Uninstalling only removes the app and the data held on the device.
12. Security
Passwords are stored only as bcrypt hashes and are never recoverable in readable form. Sessions use signed tokens that expire. Traffic between the app and our servers travels over HTTPS. Scan image uploads use short-lived signed URLs rather than open endpoints. On the device, credentials are held in the platform keychain or keystore.
No system is perfectly secure. If we ever discover a breach affecting your personal data, we will notify you and the relevant regulator as required by law.
13. Children
Sunly is not directed at children and is not intended for anyone under 13, or under 16 in countries where that is the minimum age for consent. We do not knowingly collect personal data from children. If you believe a child has given us data, email us and we will delete it.
Parents may track a child's sun protection through the family feature. In that case we recommend using a nickname rather than a full name, and you remain responsible for that information.
14. International transfers
Our service providers operate in several countries, so your data may be processed outside the country you live in, including in the United States. Where data leaves the UK or the European Economic Area, we rely on the appropriate safeguards, such as the European Commission's standard contractual clauses or an adequacy decision.
15. Apple App Store and TestFlight
This section covers the iOS version of Sunly, distributed through the Apple App Store and, during testing, through TestFlight.
App Privacy disclosures
What we declare on our App Store product page matches this policy:
- Data linked to you: contact info (email), user content (scan results, chat messages, and scan photos where you enable cloud assist), health and fitness (skin type, sun-safety check-ins), identifiers (account ID, push token), and usage data tied to your account.
- Data not linked to you: diagnostics and crash reports.
- Data used to track you: none. Sunly does not use the App Tracking Transparency framework because it does not track you across apps or websites owned by other companies, and it contains no advertising SDK.
Permissions the app asks for
- Camera to take the sunscreen coverage scan.
- Location, when in use to show the UV index where you are.
- Notifications to send reapply reminders and UV alerts.
Every one of these is optional and can be revoked in iOS Settings.
TestFlight builds
If you are testing Sunly through TestFlight, Apple separately collects information about your testing session, including installation and crash data and any feedback or screenshots you submit through TestFlight. That collection is governed by Apple's privacy policy, not this one. Test builds may be unfinished and may contain bugs; do not rely on them for real sun-safety decisions.
Subscriptions and payments
Sunly does not process payments itself. If in-app purchases are offered, Apple handles the transaction and we never receive your card details.
Health data
Sunly does not read from or write to Apple HealthKit. Information such as skin type and sun-safety check-ins is entered by you in the app and stored as described above. It is not used for advertising and is never shared with data brokers.
16. Google Play
This section covers the Android version of Sunly, distributed through Google Play.
Data safety disclosures
Our Google Play Data safety form matches this policy. In summary:
- Data collected: personal info (name, email address), location (approximate and precise), photos (only where you enable cloud assist), health and fitness information, app activity, and app info and performance (crash logs and diagnostics).
- Data shared: location coordinates with UV data providers, and message or image content with a language model provider where a feature needs it. We do not share data with advertisers or data brokers.
- Data is encrypted in transit.
- You can delete your account and data from inside the app, or request it at techbrio.agency/consunly/delete-account.html. See section 11.
- No data is sold.
Permissions the app declares
CAMERAto take the sunscreen coverage scan.ACCESS_FINE_LOCATIONandACCESS_COARSE_LOCATIONto look up the UV index at your position. Sunly declares no background location permission.POST_NOTIFICATIONSto send reminders and alerts.RECEIVE_BOOT_COMPLETEDto restore your scheduled reminders after the device restarts.VIBRATEfor notification feedback.
Google Play services
The Android app uses Google Play services for push notifications and crash reporting through Firebase. Google's handling of that data is covered by the Google Privacy Policy.
Health apps declaration
Sunly provides general sun-safety guidance. It is not a medical device, it does not diagnose or treat any condition, and scan results are estimates rather than clinical measurements. Always follow the directions on your sunscreen label, and speak to a healthcare professional about any concern regarding your skin.
17. Changes to this policy
We update this policy when the app changes. The effective date at the top always reflects the current version. If a change materially affects how we use your data, we will tell you in the app or by email before it takes effect, and where the law requires it we will ask for your consent again.
18. Contact
Questions, requests, or complaints about privacy go to support@consunly.com.
If you are in the UK or the EEA and are not satisfied with our response, you can complain to your national data protection authority.