Privacy Policy
1. Introduction
This Privacy Policy describes how TRY2APP LTD ("TRY2APP", "we", "us", "our") collects, uses, and shares information when you use the Tanning Assistant iOS application (the "App", "Service").
We've designed the App to collect as little personal information as possible. You do not need to create an account. We do not ask for your name, email, phone number, date of birth, or any other personally identifying information. This document explains exactly what we do collect, why we collect it, and the choices you have.
Plain English summary: We don't know who you are. We process the selfie you upload only to estimate your skin type and generate a bronzed preview. We use your coarse location only to fetch the local UV index. We never sell your data, never train AI models on your photos, and never use your selfie for advertising.
2. Information We Collect
Anonymous Identifier
When you first open the App, our backend (Google Firebase Authentication) generates a random anonymous user ID for your installation. This ID is not linked to your real identity, your Apple ID, or any other personal information you've shared with Apple. The ID exists so the App can sync your subscription status and scan history across sessions on the same device.
Onboarding Answers
Before your first scan we ask you five multiple-choice questions about your skin tone, hair color, eye color, how easily you burn, and how deeply you tan. These answers are used to estimate your Fitzpatrick skin type (I–VI) and generate your personalized tanning routine. They are stored under your anonymous user ID and never shared with third parties.
Selfies and Photos You Upload for Scanning
When you start a scan, you either take a selfie with the camera or select a photo from your iOS Photo Library. The selected image is uploaded to our AI image-generation provider (FAL.ai) over an encrypted connection so the AI model can produce a "bronzed preview" visualization. A lightweight, on-device brightness analysis is also run locally on your phone to refine the Fitzpatrick estimate.
We do not store the uploaded selfie on our own servers. Once the generation is complete, the original selfie is no longer accessible to us. Our AI provider's data retention policy is described in their own privacy policy (linked below).
Bronzed Previews (Generated Images)
The AI-generated bronzed previews produced from your selfie may be stored as URLs under your anonymous user ID so they can be re-displayed within the App. You can delete any scan from the App at any time. The image files themselves are hosted on our AI provider's temporary CDN and expire after a limited time window.
Precise-Approximate Location (UV Index)
If you grant location permission, the App uses Apple WeatherKit together with your device's coarse location to fetch the local UV index. This is used solely to size your tanning routine (e.g. "UV 7 · 20 minutes") and is never sent to our servers. Your location is read from the iOS Core Location API and passed directly to Apple WeatherKit on-device; we do not log, store, or transmit your coordinates. If you decline location permission, the App falls back to a time-of-day estimate instead of live UV data.
Scan History (Metadata Only)
For each scan you complete, we store under your anonymous user ID: the resolved Fitzpatrick skin type, the UV index used, and a timestamp. This metadata lets you view your own history inside the App. It does not include your selfie or any other identifying information.
Subscription and Purchase Data
When you purchase a subscription, the transaction is processed entirely by Apple. We use a service called RevenueCat to verify and sync your subscription status. We receive only:
- The product identifier you purchased
- The purchase status (active, expired, refunded)
- The expiration date for active subscriptions
We do not see your Apple ID, your credit card number, your billing address, or any other payment information. All payment processing is handled by Apple.
Push Notifications (Optional)
If you grant the App permission to send push notifications, Apple provides us with a push token used to deliver notifications (e.g. "time to flip", "reapply SPF") during an active tanning routine. We use the token solely for routine-related reminders. You can revoke notification permission at any time in your iOS Settings.
Crash and Performance Diagnostics
We may collect anonymous, aggregated diagnostic information about App crashes and performance (device model, iOS version, stack traces). This data does not include your selfie, your location, or any personally identifying information.
What We Do Not Collect
For absolute clarity, we do not collect:
- Your name, email address, phone number, or postal address
- Your precise GPS coordinates beyond what Apple WeatherKit needs to resolve a UV index on-device
- Your contacts, calendar, or messages
- Any photos other than the one you explicitly select for a scan
- Your Apple ID or any account information
- Your IDFA or any advertising tracker data
- Browsing history or activity outside the App
- Biometric data within the meaning of GDPR Art. 9 — the Fitzpatrick estimate is a categorical self-assessment, not a biometric identifier
3. Face Data
Summary: The only "face data" the App handles is a single selfie image that you knowingly choose to upload for each scan. We do not build, store, or share a facial recognition template, face geometry map, faceprint, face embedding, or any other persistent biometric identifier derived from your face. Your selfie is never used to identify you, match you against other people, or train any AI model.
What face data we collect
When you tap "Start Scan" inside the App, you explicitly choose a photo of yourself from your iOS Photo Library or capture a new one with the camera. That single still image (a 2D JPEG, typically of your face and upper body in natural light) is the only face-related data we process. We do not:
- Extract or store a face template, face geometry mesh, or face embedding vector
- Use the Apple ARKit face-tracking / TrueDepth API or any other biometric face API
- Run facial recognition, face identification, face verification, emotion detection, age detection, or gender detection
- Record video of your face
- Collect any faceprint within the meaning of Illinois BIPA, Texas CUBI, or similar biometric privacy laws
Why we process your selfie (planned uses)
Your selfie is used for exactly two purposes, both triggered only by your explicit action:
- AI bronzed-preview generation. Your selfie is sent to our AI image-generation provider (FAL.ai, model
fal-ai/nano-banana/edit) which returns a new image depicting how you might look with an even, safe tan. This is a purely aesthetic, creative visualization. - Fitzpatrick skin-type refinement. A lightweight brightness analysis is run entirely on your device to refine the Fitzpatrick skin type (I–VI) estimate produced by your onboarding answers. The raw pixel data never leaves your device for this step.
We do not use your selfie for any other purpose — not for advertising, not for analytics, not for training any AI model, not for identifying you, not for matching you against any database.
Third-party sharing and storage location
Your selfie is transmitted over a TLS 1.2+ encrypted connection to FAL.ai (FAL AI, Inc., United States), our sole AI image-generation provider. FAL.ai processes the image on its GPU infrastructure to generate the bronzed preview and returns a URL to the generated image. FAL.ai's privacy policy is available at https://fal.ai/legal/privacy-policy.
The uploaded selfie is not stored on TRY2APP LTD servers. We do not write the original selfie to our Cloud Firestore database, Firebase Storage, or any other server under our control. The only server-side record we keep of a scan is a metadata document under your anonymous user ID containing: (a) the resolved Fitzpatrick skin type (I–VI), (b) the UV index used for your routine, and (c) a timestamp. The URL of the generated bronzed preview (not the original selfie) may be stored under your anonymous user ID so the image can be re-displayed inside the App.
We do not share your selfie with any advertising network, data broker, analytics provider, or any third party other than FAL.ai as described above.
Retention
- Your original selfie: Not retained by TRY2APP LTD at any point. After upload, the selfie is held only on FAL.ai's infrastructure for the duration of the generation request. FAL.ai's own retention policy governs any caching on their side (see their privacy policy linked above). Typical retention on FAL.ai is limited to a short temporary window required to serve the generation.
- AI-generated bronzed preview URL: Stored under your anonymous user ID in our database for up to 90 days, after which it is automatically deleted. You can delete any scan manually at any time from within the App.
- Scan metadata (Fitzpatrick, UV, timestamp): Retained while your installation is active or until you request deletion. Automatically purged after 18 months of inactivity.
- Face templates, face embeddings, faceprints: Not applicable. These are never generated, so no retention period exists.
Your control
You can delete any individual scan (including the generated preview URL) from within the App at any time. You can also email [email protected] with the subject line "Tanning Assistant — Face Data Deletion" and we will delete all records associated with your anonymous user ID, typically within 7 days and always within 30 days, as required by GDPR.
4. How We Use Your Information
We use the limited information we collect for the following purposes only:
- To estimate your Fitzpatrick skin type and generate the AI bronzed preview you requested
- To size a personalized, UV-aware tanning routine
- To sync your subscription and scan history across sessions on your device
- To deliver routine-stage push notifications (only if you opted in)
- To prevent fraud, abuse, and violations of our Terms of Service
- To comply with legal obligations
- To improve App performance and reliability through aggregated, anonymous analytics
We do not sell your personal information. We do not share your personal information with advertisers. We do not use your photos to train AI models. We do not use your data for profiling in the sense of GDPR Art. 22.
5. Third-Party Services
The App relies on a small number of trusted third-party services. Each is bound by its own privacy policy and the limited purpose for which we use it.
FAL.ai (AI Image Generation)
We use FAL.ai for AI-powered bronzed-preview generation. When you start a scan, your selected selfie is sent to FAL.ai for processing. The model used is fal-ai/nano-banana/edit.
FAL.ai privacy policy: https://fal.ai/legal/privacy-policy
Google Firebase
We use Firebase Authentication for anonymous account creation and Cloud Firestore to store your subscription status, onboarding answers, and scan metadata under your anonymous user ID. Firebase is operated by Google LLC.
Google privacy policy: https://policies.google.com/privacy
Apple WeatherKit and Apple Core Location
We use Apple WeatherKit to fetch the current UV index for your approximate location. WeatherKit is operated by Apple Inc. and receives only the coordinates required to resolve the nearest weather station. Your coordinates never touch our servers.
Apple WeatherKit terms: https://developer.apple.com/weatherkit/data-source-attribution/
RevenueCat
We use RevenueCat to handle subscription validation and synchronization. RevenueCat receives the anonymous user ID and the App Store transaction details only.
RevenueCat privacy policy: https://www.revenuecat.com/privacy
Apple
The App is distributed through Apple's App Store. Apple processes all payments and handles push notification delivery (APNs).
Apple privacy policy: https://www.apple.com/legal/privacy/
6. Data Retention
We retain the limited information we collect for as long as your installation is active, plus a reasonable period thereafter to comply with our legal obligations.
- Selfies you upload: Not stored by us. Sent to our AI provider for the duration of generation only. Our AI provider retains them according to their own retention policy.
- Generated bronzed preview URLs: Stored in our database for up to 90 days, after which they are automatically deleted. You can delete them sooner from within the App.
- Onboarding answers and scan metadata: Retained while your installation is active. Deleted on request (see "Your Rights" below) or when the account is inactive for more than 18 months.
- Anonymous user ID: Retained while your installation is active. Deleted on request.
- Subscription records: Retained for the duration of your subscription plus the period required by tax and accounting laws (typically 7 years).
- Location data: Never stored. Processed on-device only.
7. Your Rights
Depending on where you live, you may have the following rights regarding your personal information:
European Union and United Kingdom (GDPR / UK GDPR)
- Right to access the personal data we hold about you
- Right to rectification of inaccurate data
- Right to erasure (the "right to be forgotten")
- Right to restriction of processing
- Right to data portability
- Right to object to processing
- Right not to be subject to solely automated decision-making
- Right to withdraw consent at any time where consent is the legal basis
- Right to lodge a complaint with a supervisory authority
California, USA (CCPA / CPRA)
- Right to know what personal information is collected
- Right to delete personal information
- Right to correct inaccurate personal information
- Right to opt out of the sale or sharing of personal information (we do not sell or share)
- Right to limit use of sensitive personal information
- Right to non-discrimination for exercising your privacy rights
Other Jurisdictions
Brazil (LGPD), Canada (PIPEDA), Australia (Privacy Act), and other jurisdictions provide similar rights. You may exercise them through the same channel below.
How to Exercise Your Rights
To exercise any of these rights, contact us at [email protected] with the subject line "Tanning Assistant — Privacy Request". Because we use anonymous identifiers, please include your anonymous user ID (you can find it in the App's Settings screen) so we can locate your data. We will respond within the timeframe required by applicable law (typically within 30 days for GDPR).
8. Children's Privacy
The App is not intended for children under 13 years of age (or under the minimum digital consent age in your jurisdiction, which may be 14 or 16 in some EU member states). We do not knowingly collect personal information from children.
Tanning and direct sun exposure carry specific risks for children and adolescents. The App is intended for adults making informed decisions about their own sun exposure.
If you are a parent or guardian and believe a child has provided personal information to us, please contact us at [email protected] and we will delete it promptly.
The App's content rating in the App Store is set in accordance with Apple's age rating guidelines.
9. AI Processing Disclosure (EU AI Act Compliance)
In compliance with Regulation (EU) 2024/1689 (the "EU AI Act") and global best practices for transparent AI, we disclose the following:
- The App uses generative artificial intelligence to create a bronzed preview visualization from your selfie. The output is synthetic content generated by an AI system and is a creative approximation of how you might look with a natural tan. It is not a medical prediction or a guarantee of any actual outcome.
- Bronzed previews are clearly marked as AI-generated within the App.
- The AI model used is
fal-ai/nano-banana/edit, provided by FAL.ai. - The AI generation process is initiated only by your explicit action (tapping "Scan" or similar). The App does not generate content automatically.
- The Fitzpatrick estimate produced by the App is a self-assessment supplement based on your onboarding answers and a lightweight on-device brightness analysis of your selfie. It is not a medical diagnosis and is not suitable for any medical or legal decision.
- You are responsible for the lawful use of any content generated by the App. Use of generated content to deceive others, create deepfakes of real people without consent, or otherwise violate applicable law is strictly prohibited by our Terms of Service.
10. Skin & Health Information — Important
The App is a lifestyle and wellness tool, not a medical device. The Fitzpatrick estimate, UV index display, and tanning routine are educational and informational only. They are not medical advice, not a diagnosis, not a treatment plan, and not a substitute for consultation with a qualified dermatologist or health professional.
The onboarding answers you provide relate to your skin and are treated as ordinary personal data under GDPR. They are not "special category data" (Art. 9 GDPR) because they are self-reported phenotypic characteristics used for aesthetics and wellness, not health processing. We nonetheless apply enhanced care to these fields:
- They are stored only under your anonymous user ID
- They are never shared with advertisers or data brokers
- They are never combined with external data sources to identify you
- You can delete them at any time by contacting us or deleting your installation
If you have a personal or family history of skin cancer, melanoma, photosensitivity, or any photodermatosis, you should consult a dermatologist before using the App's routine suggestions.
11. International Data Transfers
The App's backend services (Google Firebase, RevenueCat, FAL.ai, Apple WeatherKit) operate from data centers located in the United States and the European Union. By using the App, you consent to the transfer of your information to these regions for processing.
For transfers of personal data from the European Union or United Kingdom to countries outside the EEA, we and our processors rely on Standard Contractual Clauses approved by the European Commission and other appropriate safeguards.
12. Security
We protect the limited information we collect using industry-standard measures, including:
- TLS 1.2+ encryption for all data in transit
- Encryption at rest provided by Google Cloud and our other infrastructure providers
- Anonymous identifiers — no real-name linkage
- Least-privilege backend access restricted to authorized personnel
- Regular security review of third-party providers
- Firestore security rules that scope reads/writes to the user's own anonymous document
No system is perfectly secure. If you become aware of a security incident affecting your data, please contact us immediately at [email protected].
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Update the "Last updated" date at the top of this policy
- Notify users via in-app message or push notification (if granted)
- For significant changes, provide a plain-language summary of what changed
Continued use of the App after changes are posted constitutes acceptance of the updated policy.
14. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your data, contact us at:
Controller: TRY2APP LTD
Email: [email protected]
Subject: Tanning Assistant — Privacy Inquiry
We will respond as soon as possible, typically within 7 business days.