Privacy Policy

This policy explains what the Sunly mobile app collects, why it collects it, who it is shared with, and the choices you have. It covers the app on both the Apple App Store (including TestFlight) and Google Play.

Effective: 2 September 2026 Last updated: 2 September 2026 Applies to: Sunly iOS and Android apps

The short version

Contents

  1. Who we are
  2. What we collect
  3. Scan photos
  4. Location
  5. Notifications
  6. Sunny chat
  7. Why we use your data
  8. Who we share it with
  9. How long we keep it
  10. Your rights
  11. Deleting your account
  12. Security
  13. Children
  14. International transfers
  15. Apple App Store and TestFlight
  16. Google Play
  17. Changes
  18. Contact

1. Who we are

Sunly is a sun-safety app that estimates sunscreen coverage from a photo, tracks the UV index where you are, reminds you to reapply, and keeps a record of your protection habits over time.

In this policy, "Sunly", "we" and "us" mean the team that publishes the Sunly app. The app is distributed on the Apple App Store under the Apple Developer account Con Filactos and on Google Play under the Sunly developer account.

For any privacy question, or to exercise any right described here, contact support@consunly.com. We are the data controller for the information described below.

2. What we collect

We only collect what the features you use actually need. Nothing below is bought from third parties or inferred from data brokers.

CategoryWhat it isWhen we get it
Account Email address, password (stored only as a bcrypt hash, never in readable form), display name. When you register.
Sun profile Skin type, lifestyle choices, time zone, and an optional home location (approximate latitude and longitude). During onboarding and whenever you edit your profile.
Scan results Estimated coverage score, confidence level, which body zones looked unprotected, and the assessment text generated for that scan. Each time you run a scan. See section 3 for the photo itself.
Location Approximate or precise coordinates, used to look up the UV index. While the app is open and you have granted location permission. See section 4.
Habits and wellbeing Daily self-reported check-ins: whether you applied sunscreen, hydration, mood, and similar sun-safety habits. Only when you fill in a daily check.
Progress data Daily sun-safety scores, streaks, challenge participation, badges and points. Calculated from your activity in the app.
Family members Names or nicknames you add for people you are tracking, their protection status, and invite codes. Only if you use the family feature. See the note below.
Chat messages Messages you send to Sunny, the in-app assistant, and its replies. When you use the chat. See section 6.
Notification settings Reminders you set, quiet hours, and a push notification token for your device. When you enable notifications or set a reminder.
Diagnostics Crash reports and technical error data, including device model, operating system version and a crash stack trace. Automatically, if the app crashes.
About family members: when you add someone to your family view, you are giving us information about another person. Please only add people who have agreed to it, and only add a nickname rather than a full name for children. You are responsible for having their permission.

Sunly does not collect your contacts, your photo library, your browsing history, your advertising identifier, or your microphone audio. The app declares a microphone permission on iOS only because the camera library it uses references that API; Sunly never records audio.

3. Scan photos

This is the part of Sunly people ask about most, so here is exactly how it works.

When you take a scan, the photo is analysed on your device. The app uses on-device machine learning to separate you from the background, find body landmarks, and estimate how much of each visible zone looks covered by sunscreen. The result of that analysis is a small set of numbers: a coverage value per body zone and a confidence level.

By default, only those numbers leave your device. The photo does not.

If you separately turn on cloud assist for a scan, the photo is uploaded to our storage so a vision model can give a second opinion on coverage. This is an explicit, per-scan choice and it is off unless you turn it on. Uploaded images are used to produce your result, and are used to improve the scan model only if you also give training consent.

You can withdraw cloud assist or training consent at any time in the app, or by emailing us. Withdrawing consent stops future uploads; to have images already uploaded deleted, contact us.

4. Location

Sunly requests when in use location only. The app reads your location while you have it open, sends the coordinates to a UV data provider, and shows you the UV index and forecast for that spot.

Sunly does not track your location in the background, does not build a location history, and does not use location for advertising.

On iOS you may see purpose strings mentioning "always" location. Those exist because the location library the app is built on references those system APIs, and Apple requires a description for every referenced API. Sunly never requests always-on authorization.

You can revoke location permission at any time in your device settings. The app still works; you will need to tell it where you are for UV data, and some UV features will be limited.

5. Notifications

If you allow notifications, we register a push token for your device so we can send UV alerts, reapply reminders, and streak notices. The token identifies the installation, not you personally, and is deleted when it stops working or when you delete your account.

You control which notifications you get and set quiet hours in the app, and you can turn notifications off entirely in your device settings.

6. Sunny chat

Sunny is the in-app assistant. Messages you send and the replies you get are stored against your account so the conversation has continuity and so we can improve how well Sunny understands requests.

Most replies are produced by a rule-based engine that runs on our own server. Some requests fall back to a third-party language model provider, in which case the text of your message is sent to that provider to generate a reply. Do not put sensitive personal or medical details into the chat.

7. Why we use your data, and our legal basis

PurposeData usedLegal basis (UK/EU GDPR)
Create and secure your accountAccountPerformance of a contract
Estimate sunscreen coverage and show resultsScan results, sun profilePerformance of a contract
Upload a scan photo for a cloud second opinionPhotoConsent
Use a scan photo to improve the modelPhotoConsent
Show the UV index where you areLocationConsent (device permission)
Send reminders and alertsPush token, notification settingsConsent (device permission)
Track scores, streaks, challenges and badgesHabits, progress dataPerformance of a contract
Answer questions in chatChat messagesPerformance of a contract
Fix crashes and keep the app stableDiagnosticsLegitimate interests

Some of what Sunly stores, such as your skin type, your scan results and your daily wellbeing check-ins, may be treated as health-related data in your country. Where that is the case, we rely on your explicit consent, given when you enter that information. You can withdraw it by deleting the data or your account.

8. Who we share it with

We do not sell your personal data and we do not share it for cross-context behavioural advertising. We share data only with service providers who process it on our instructions:

ProviderWhat it receivesWhy
Google Firebase (Cloud Messaging, Crashlytics) Push token, device identifiers, crash diagnostics Delivering notifications and reporting crashes
UV data providers (Open-Meteo, and depending on configuration WeatherAPI or OpenUV) Coordinates only, with no account identifier attached Looking up the UV index and forecast for a location
Language model provider (OpenRouter and the model it routes to) Chat message text; scan image only when you enable cloud assist Generating a chat reply or a second opinion on coverage
Hosting provider All data stored by the service Running our servers and database

We may also disclose data if we are legally required to, to enforce our terms, or to protect the rights and safety of our users. If Sunly is ever acquired or merged, data may transfer as part of that transaction, and we will tell you before it becomes subject to a different policy.

9. How long we keep it

10. Your rights

Depending on where you live, you may have the right to:

If you are in California, you also have the right to know, delete, correct, and to opt out of sale or sharing. We do not sell or share personal information as those terms are defined by the CCPA, and we will not discriminate against you for exercising any right.

To exercise any of these, email support@consunly.com from the address on your account. We respond within 30 days.

11. Deleting your account

In the app: open Settings, scroll to the bottom, and tap Delete account. You are signed out immediately and the account is erased. There is no waiting period and no undo.

By email: if you cannot sign in, email support@consunly.com with the subject "Delete my account", from the email address registered to the account.

Full details are on the account deletion page.

We will delete your account record, sun profile, scan results and any uploaded scan images, daily check-ins, scores, streaks, challenge history, badges, points, family entries, reminders, notification settings and chat history. Backups are purged on their normal rotation. We may keep a minimal record of the deletion request itself to show we honoured it.

Deleting the app from your phone does not delete your account. Uninstalling only removes the app and the data held on the device.

12. Security

Passwords are stored only as bcrypt hashes and are never recoverable in readable form. Sessions use signed tokens that expire. Traffic between the app and our servers travels over HTTPS. Scan image uploads use short-lived signed URLs rather than open endpoints. On the device, credentials are held in the platform keychain or keystore.

No system is perfectly secure. If we ever discover a breach affecting your personal data, we will notify you and the relevant regulator as required by law.

13. Children

Sunly is not directed at children and is not intended for anyone under 13, or under 16 in countries where that is the minimum age for consent. We do not knowingly collect personal data from children. If you believe a child has given us data, email us and we will delete it.

Parents may track a child's sun protection through the family feature. In that case we recommend using a nickname rather than a full name, and you remain responsible for that information.

14. International transfers

Our service providers operate in several countries, so your data may be processed outside the country you live in, including in the United States. Where data leaves the UK or the European Economic Area, we rely on the appropriate safeguards, such as the European Commission's standard contractual clauses or an adequacy decision.

15. Apple App Store and TestFlight

This section covers the iOS version of Sunly, distributed through the Apple App Store and, during testing, through TestFlight.

App Privacy disclosures

What we declare on our App Store product page matches this policy:

Permissions the app asks for

Every one of these is optional and can be revoked in iOS Settings.

TestFlight builds

If you are testing Sunly through TestFlight, Apple separately collects information about your testing session, including installation and crash data and any feedback or screenshots you submit through TestFlight. That collection is governed by Apple's privacy policy, not this one. Test builds may be unfinished and may contain bugs; do not rely on them for real sun-safety decisions.

Subscriptions and payments

Sunly does not process payments itself. If in-app purchases are offered, Apple handles the transaction and we never receive your card details.

Health data

Sunly does not read from or write to Apple HealthKit. Information such as skin type and sun-safety check-ins is entered by you in the app and stored as described above. It is not used for advertising and is never shared with data brokers.

16. Google Play

This section covers the Android version of Sunly, distributed through Google Play.

Data safety disclosures

Our Google Play Data safety form matches this policy. In summary:

Permissions the app declares

Google Play services

The Android app uses Google Play services for push notifications and crash reporting through Firebase. Google's handling of that data is covered by the Google Privacy Policy.

Health apps declaration

Sunly provides general sun-safety guidance. It is not a medical device, it does not diagnose or treat any condition, and scan results are estimates rather than clinical measurements. Always follow the directions on your sunscreen label, and speak to a healthcare professional about any concern regarding your skin.

17. Changes to this policy

We update this policy when the app changes. The effective date at the top always reflects the current version. If a change materially affects how we use your data, we will tell you in the app or by email before it takes effect, and where the law requires it we will ask for your consent again.

18. Contact

Questions, requests, or complaints about privacy go to support@consunly.com.

If you are in the UK or the EEA and are not satisfied with our response, you can complain to your national data protection authority.