This policy explains what the Suntan Workout mobile app ("the app") does with your data. It is written to match, item for item, the answers we gave in Apple's App Privacy questionnaire and Google Play's Data safety form.
The app is published by ТОО «EMAKHO», Almaty, Kazakhstan ("we", "us").
The short version
- There is no advertising in the app, and no advertising identifier is requested.
- There is no analytics SDK. We do not measure how you use the app.
- We do not track you across other apps or websites, and never show the App Tracking Transparency prompt.
- We do not sell your data, and we do not hand it to anyone for their own purposes.
- You can delete your account and all of its history from inside the app.
Using the app without an account
Signing in is optional. In guest mode the app keeps everything in local device storage: your skin type, the level you have reached, the time of your last session, the cooldown clock, your last skin reaction, and your voice-prompt and notification preferences.
None of that is transmitted to us or to anyone else. It lives on the phone, it is included in your device backup if you have one enabled, and it is destroyed when you uninstall the app.
The one exception is the UV lookup described below, which happens in guest mode too — it is how the app knows how long your session should be.
What the app collects
This table is the complete list. If something is not here, the app does not collect it.
| Data | Why | Where it goes |
|---|---|---|
| GPS coordinates | To look up the UV index and temperature where you actually are, so the session length fits the real sun | Sent to Open-Meteo with each request. Never stored by us, in any form. |
| Place name | To show you where a session was measured | Firestore, saved alongside the session. Resolved from the coordinates by your phone's own geocoder. |
| Email address, name | To create and identify your account | Firebase Authentication. |
| User identifier (uid) | To attach sessions to your account, and to identify you to the purchase validator | Firebase, RevenueCat. |
| Session history | Your progress and statistics | Firestore: duration, session number, program name, date, place name, UV index, temperature, skin reaction. |
| Skin type, level reached, time of last session | To position you on the twelve-session programme and to time the pause between sessions | Firestore, and on the device. |
| Purchase history | To check whether your subscription is active | RevenueCat, App Store / Google Play. |
Skin reaction is health information
After a session the app asks how your skin reacted — normal, pink, or burned. We record the answer because the whole programme depends on it: a pink reaction repeats the session instead of advancing, a burn moves you two steps back and lengthens the pause before you may go out again.
We would rather name this plainly than bury it under "usage data": in substance it is information about your health, and where the law treats it as a special category, we process it on the basis of your explicit consent, given by entering it. You are never required to answer; if you skip it, the app treats the session conservatively.
Location
The app asks for location while in use. Your coordinates are sent to Open-Meteo, a weather service, which returns the UV index, the clear-sky UV index, cloud cover and temperature for that point. The request carries the coordinates and nothing that identifies you — no name, no email, no account identifier.
We do not keep your coordinates. What is saved with a session is the place name, not the position.
You may refuse location access and still use the app. It then falls back to a conservative estimate based on your latitude, which deliberately errs towards shorter sessions.
What the app does not do
Each of these can be checked in the app's configuration, so we state them without hedging:
- No advertising and no advertising identifier — the AD_ID permission is not requested.
- No analytics. The analytics SDK is not merely disabled, it is not built into the app at all.
- No tracking across other companies' apps or websites; the App Tracking Transparency prompt is never shown, because there is nothing to ask for.
- No push notifications from a server. Reminders are scheduled locally on your phone, so no notification token exists.
- No sale of personal data and no sharing of it with third parties for their own purposes.
- No profiling, no automated decisions with legal effects, and no attempt to identify you by device fingerprint.
Why we are allowed to process this
Where the GDPR or a comparable law applies, our legal bases are:
- Performance of a contract — running your account, syncing progress between your devices, and giving you the subscription you paid for.
- Your consent — location access, and the skin-reaction entry that counts as health information. You may withdraw either at any time, in your device settings or by leaving the question unanswered.
- Our legitimate interest — keeping the dose calculation correct and the service secure, weighed against the fact that the data involved is minimal and never used to advertise to you.
How long it is kept
Account data and session history are kept for as long as your account exists, because the history is the feature — the programme cannot place you correctly without it.
When you delete your account, it goes immediately, as described below. Data held on the device disappears when you uninstall the app. Purchase records at Apple, Google and RevenueCat are kept as long as those companies' own rules and tax law require, and are outside our control.
Deleting your data
If you have already uninstalled the app and cannot reach that button, write to us at info@emaho.dev from the address the account uses, and we will delete it for you.
Deleting your account does not cancel a subscription — subscriptions live in your App Store or Google Play account and must be cancelled there. See the Terms of Use for how.
Your rights
Depending on where you live, you may have the right to see the data we hold about you, to correct it, to delete it, to receive a copy in a portable form, to object to processing, or to withdraw consent. Write to info@emaho.dev and we will act on it; deletion you can also do yourself, instantly, in the app.
If you believe we have handled your data badly, you may complain to your national data-protection authority. We would rather you told us first.
Where the data is held
We are in Kazakhstan. Firebase, RevenueCat and Open-Meteo operate infrastructure in the European Union and the United States, so your data may be processed outside your country. Those transfers rely on the safeguards those providers offer, including the European Commission's standard contractual clauses.
Security
Traffic between the app and its services is encrypted in transit. Your session history is readable only by your own account: Firestore security rules scope every document to the signed-in user's identifier. We never store your password — authentication is handled by Firebase, and if you sign in with Google or Apple we never see a password at all.
Children
The app is not intended for children and we do not knowingly collect data from them. If you believe a child has created an account, write to info@emaho.dev and we will remove it.
Changes to this policy
If we change what the app collects or who receives it, we will update this page and change the date at the top. Where the change is significant, we will also tell you in the app before it takes effect.
Contact
Questions about this policy, requests to see or delete your data:
info@emaho.devТОО «EMAKHO», Almaty, Kazakhstan