Skip to content

Privacy Policy

MySun uses only the information needed to sign you in, provide weather and sun exposure estimates, keep your sun log, power optional one-to-one Together sharing, and manage an optional subscription. Your sun, skin, friend, and location data is never used for advertising, never sold, and never used to track you across other apps or websites.

Last updated: 13 August 2026

Support and contact

For any question, feedback or support request, email appmysun@gmail.com. We aim to reply within a few business days.

Profile recovery and what stays on your device

After profile setup is complete, MySun stores a small profile recovery snapshot in Firestore so Home can be restored when you reinstall MySun and sign in to the same account. The snapshot contains only:

  • Skin type and how it was selected
  • Current tan and target tan, if set
  • Default SPF and clothing
  • UV alert threshold
  • Vitamin D goal
  • Whether your first session has been started

Firestore rules limit access to the signed-in account owner. The snapshot does not contain your session or check-in history, tan photos, cached forecasts, reminder settings, or Health permissions. Those details stay in the app's local data container on your device and are not uploaded for profile recovery.

Signing out can leave local data on your device for the same account. Switching to a different account or deleting your account clears the app's local profile data.

Account information

You sign in with Apple or Google. Authentication is processed by Firebase Authentication (a Google service). We store the following in our Firestore database:

  • Your account identifier
  • Your sign in provider (Apple or Google)
  • Your last seen time
  • Any name or email supplied by your sign in provider
  • The completed-profile recovery snapshot described above

If you use Sign in with Apple you can hide your real email address; we only receive the private relay address Apple gives us.

Purchases and subscriptions

The optional Sun+ subscription is processed by Apple and RevenueCat. They handle subscription status and purchase information. MySun never receives your full payment card details. Subscriptions are managed and canceled through your Apple ID settings.

Apple Ads attribution

When MySun is installed after an Apple Ads campaign, Apple's AdServices framework can provide a privacy-limited attribution token. RevenueCat sends that token to Apple and stores the campaign, ad group, keyword, placement, claim type, and download or redownload information Apple returns so we can measure which Apple Ads campaigns lead to trials, subscriptions, and revenue. This standard attribution does not use the IDFA or IDFV and does not require App Tracking Transparency permission. MySun does not request the detailed click or impression timestamp available with tracking permission.

This information is used only to evaluate MySun's own marketing. It is not used to show ads inside MySun, build advertising profiles, track you across other companies' apps or websites, or personalize advertising. RevenueCat may associate the attribution with its subscription customer record so later renewals can be evaluated with the original campaign.

Product analytics

Firebase Analytics collects an app-instance identifier, basic app and device information, a coarse region, and app lifecycle and product interaction events. After sign in, MySun associates Analytics events with your internal Firebase account identifier so we can measure registration, onboarding, personal plan views, guided or extra session starts and completions, paywall views, and subscription attempts and successes.

MySun does not add your name, email, precise location, skin profile, photos, Health data, UV values or tanning session duration to Analytics events. IDFA and IDFV collection, automatic screen reporting, ad-network registration, on-device conversion measurement and personalized advertising are disabled. We do not use Analytics for advertising or cross-app tracking.

Deleting your account clears the Analytics user ID and resets Analytics data and the app-instance identifier on that device. Previously collected Analytics data follows Google Analytics retention and deletion controls.

Location and weather

With your permission, your coordinates are used to request local UV and weather data from Apple Weather and to show a nearby place name. A recent forecast, including its coordinates, can be cached on your device. If location is unavailable, the app uses its displayed default city. Apple Weather processes these requests under Apple's privacy terms.

Together friends

Together uses mutual, single-use invitations to create a private connection between two people. Before joining, the invitation shows the inviter's display name and small avatar and explains that total recorded tanning time and location sharing begin when the invitation is accepted.

A new friendship starts with recorded-time and location sharing on for both people. You can change either choice independently for each friend at any time. If iOS location permission is unavailable, the friendship still works but MySun does not upload coordinates.

When recorded-time sharing is on, MySun calculates one all-time total on your device from the actual elapsed time of finished records, including partial and Extra Tanning, and uploads only that total and its update time for the friendship. Friends do not receive individual session records, dates, UV, SPF, skin details, notes, photos, or modeled dose. The total is a record, not a target or recommendation. Turning recorded-time sharing off makes the total unavailable to that friend.

When location sharing is on, MySun uploads the current coordinates iOS provides—precise when Precise Location is on and approximate otherwise—a nearby place name and an update time to Firestore only while MySun is open. The last uploaded location and its update time can remain visible after the app closes. MySun does not request background or Always location access and does not collect or upload a new location while closed. Turning sharing off removes the saved location fields for that friendship.

You can remove, report or block each friend. Removing or blocking ends the friendship and its sharing; blocked accounts cannot reconnect.

Apple Health

Apple Health access is optional and off until you connect it. iOS presents one system authorization sheet in which read and write access can be chosen separately:

  • Reading. MySun reads Time in Daylight only, and only to show it as context inside the app.
  • Writing. If you also turn on Save Sessions to Health, MySun writes a finished session's observed peak UV index to Apple Health as UV exposure over that session's time range. Deleting a session in MySun also removes its linked sample.

MySun never writes vitamin D, dietary data or any other data type to Apple Health. The vitamin D figures shown inside the app are model estimates and stay inside the app.

Notifications

Care reminders, UV summaries, program check in invitations and session alerts are scheduled as local notifications on your device.

MySun associates a device-scoped Firebase Cloud Messaging registration token with your account so it can deliver optional Together events, such as an accepted friend invitation. Registration begins only after you first create or accept a Together friend invitation. Apple Push Notification service and Firebase Cloud Messaging use that token for delivery. Before sign out, MySun requests deletion of the account record and invalidates the device token. If token invalidation cannot be confirmed, it is retried on the next launch; the server also prunes invalid token records. Confirmed account deletion removes the whole token collection.

What we do not do

  • No third-party ads inside MySun
  • No tracking across other companies' apps or websites
  • No selling or renting of your data
  • Your tan photos never leave your device

Third party services

MySun relies on these providers, each under their own privacy policy:

  • Apple (Sign in with Apple, App Store purchases, Apple Ads attribution, Apple Weather, Apple Health)
  • Firebase / Google (authentication, the member database, messaging and product analytics)
  • Apple Push Notification service and Firebase Cloud Messaging (optional Together notifications)
  • RevenueCat (subscription management and Apple Ads attribution)
  • Google Sign In (if you sign in with Google)

Your choices and data deletion

  • You can decline location, notification or Health access at any time in iOS Settings.
  • You can delete individual sessions and photos inside the app.
  • Delete Accountin the Profile screen removes local app data after reauthentication and confirmed deletion of your Firebase account. That confirmed deletion triggers server-side removal of your profile recovery snapshot, invitations, friendships, shared recorded-time totals, shared locations, reports, block records, and push tokens from our database. If local cleanup is interrupted, MySun retries it on the next launch. Subscription records required by Apple remain subject to Apple's retention rules.

Children

MySun is not directed at children under 13, and we do not knowingly collect personal information from children under 13.

Important health note

UV values, exposure guidance, skin response and vitamin D values shown in MySun are model estimates. They are not diagnoses, measurements or medical advice, and they are not a guarantee against skin damage. Always protect your skin and consult a clinician for medical questions.

Changes to this policy

If our data practices change we will update this page and the date at the top. Meaningful changes will also be reflected inside the app. See also our Terms of Use.