Tan Buddy · Legal

Tan Buddy Privacy Policy

Tan Buddy is made by iOS Visual. This policy explains what the app does with information, and what it does not do.

Last updated: 16 August 2026

The short version

There are no accounts, and everything the app knows about you personally — your skin type, your sessions, your photographs — stays on your iPhone and is never sent anywhere.

Two limited, anonymous exceptions exist, and they are set out in full below: an approximate location is sent to a weather service to fetch the UV forecast, and anonymous usage and purchase events are sent to our own analytics so we can see which parts of the app people struggle with. None of it identifies you, and none of it is used for advertising or tracking.

Who is responsible

iOS Visual is the data controller for the limited processing described below. You can reach us at support@iosvisual.com about anything in this policy, including any request to exercise the rights described under Your rights.

What we do not collect

There is no sign-up, no login, no account and no user profile held by us. We do not collect:

  • your name, email address, phone number or any other contact detail;
  • your skin type, tan level, session history, progress photographs, notes, or any other information you enter into the app;
  • your precise location;
  • device identifiers, advertising identifiers, or the IDFA;
  • your contacts, calendar, health records, or any data from other apps;
  • any information for advertising, profiling, or cross-app or cross-site tracking.

The app contains no advertising SDK and no third-party advertising or tracking technology. It does not track you across other companies’ apps or websites, and therefore does not present Apple’s App Tracking Transparency prompt.

What we do receive is anonymous, and limited to the UV forecast lookup, the anonymous analytics and the subscription reporting described below.

What stays on your device

Everything you tell the app, and everything it works out about you, is written to a private file inside the app’s own storage area on your iPhone. This includes:

  • the name and age you enter;
  • your Fitzpatrick skin type, current tan level and accumulated UV dose;
  • your goal, pace, plan length and program progress;
  • your recorded sessions, including durations, UV levels, estimated dose and how you said your skin felt;
  • your settings and reminder preferences;
  • any progress photographs you take, which are stored as image files inside the app’s own storage.

This data is protected by iOS’s app sandbox and by your device passcode and encryption. We cannot see it, and neither can any other app.

If you delete the app, this data is deleted with it. There is no copy anywhere else, and no way for us to restore it. If you use iCloud Backup or an encrypted local backup, a copy may exist in that backup under Apple’s terms and your own iCloud settings; that backup is between you and Apple, and we have no access to it.

The UV forecast lookup

To tell you the UV index where you are, the app needs a UV forecast for your location. It gets this from Open-Meteo, a free weather API.

When the app refreshes the forecast, it sends only a latitude and longitude, rounded to four decimal places, to Open-Meteo’s servers over an encrypted HTTPS connection. Nothing else is sent: no name, no device identifier, no account, no session data, and nothing that identifies you or your device to us or to them.

The request does not pass through any server of ours. It goes from your iPhone straight to Open-Meteo, which is an independent third party with its own privacy policy that we do not control. Like any web service, it will see the IP address your request comes from. You can read their policy at open-meteo.com/en/terms.

If you do not grant location permission, or you deny it later, the app still works: it falls back to a clear-sky estimate calculated on your device from the sun’s position, and it labels that estimate as such so you know it ignores cloud cover.

Anonymous usage analytics

We collect anonymous product analytics so we can see where people get stuck — in particular which step of the setup people abandon, and whether the subscription screen makes sense. Without it we are guessing, and the app gets worse rather than better.

What is sent. Nothing but the following, to our own analytics service:

  • a random identifier generated on your device when you install the app, which is not your device’s identifier, not the IDFA, and not linked to you or to anything else about you. Deleting the app destroys it; reinstalling creates a new, unconnected one;
  • a random identifier for the current app session;
  • the name of the event — for example that the app was opened, that a particular setup screen was reached, that setup was finished, that the subscription screen was shown or closed, or that a subscription was started;
  • the time it happened, and the version of the app;
  • for a small number of events, the preference that event was about: the tan goal, the pace and the plan length you chose, and which subscription plan was bought and whether it began with a free trial.

What is never sent. Your name, your age, your email, your skin type, your sessions, your dose, your photographs, your location, your device model, your IP-linked identity, or any advertising identifier. We do not build a profile of you and we have no way of connecting the random identifier to a person.

Where it goes. To analytics infrastructure we run ourselves, hosted in the European Union. It is not shared with any advertising network, data broker or analytics vendor, and it is not sold.

Events are queued on your device and sent when there is a connection, so being offline never loses them and never blocks the app.

Subscriptions and RevenueCat

We use RevenueCat to tell us how many people subscribe, start free trials, renew or cancel. It receives the transaction record for a purchase and an anonymous identifier it generates itself. It does not receive your name, your email, your payment details, or anything you have entered into the app — we never have those either.

RevenueCat acts as our data processor and publishes its own privacy policy at revenuecat.com/privacy. Its servers are in the United States, so this involves a transfer outside the EEA, made under the European Commission’s Standard Contractual Clauses.

Location

The app requests “While Using the App” location access only. It never requests background or “Always” location access, and it cannot see where you are when it is not open.

Your coordinates are used for exactly two purposes:

  • to request a UV forecast from Open-Meteo, as described above; and
  • to work out the sun’s position, sunrise and sunset on your device, for the sun-arc display and the offline fallback.

Your location is not stored by us, not logged by us, not linked to any identifier, and not used for advertising or profiling. The most recent forecast, which includes the coordinates it was fetched for, is cached on your device so the app still shows something useful when you are offline.

You can revoke location permission at any time in iOS Settings → Privacy & Security → Location Services → Tan Buddy.

Photographs and the camera

If you use the progress-photo feature, the app will ask for permission to use your camera or photo library. Photographs you take or choose are saved inside the app’s own private storage on your iPhone.

Photographs are never uploaded anywhere. They are not sent to us, not sent to any third party, and not processed by any remote service. You can delete any photograph from inside the app at any time, and deleting the app deletes all of them.

Notifications

The app uses local notifications only — reminders scheduled by the app on your own device for flips, sunscreen reapplication, the end of a session, your morning forecast, and the end of a free trial. There is no push notification server, and no notification token is generated or transmitted. You can turn reminders off inside the app, or all notifications off in iOS Settings → Notifications → Tan Buddy.

Payment

Tan Buddy Pro is sold through Apple’s In-App Purchase system. All payment processing is handled entirely by Apple. We never see and never receive your name, billing address, payment card, Apple Account details, or any other financial information — neither do we pass any of it to RevenueCat, because we never have it.

The app asks Apple’s StoreKit framework whether the current Apple Account holds an active subscription, and receives a yes or no answer plus the transaction record for that subscription. That exchange happens between your device and Apple. We have no subscriber database.

Apple’s handling of your purchase is governed by Apple’s own privacy policy.

Your rights

Data-protection law — including the EU and UK General Data Protection Regulation, and the California Consumer Privacy Act — gives you rights over personal data held about you. Those rights include access, correction, deletion, restriction, portability, objection, and the right not to be discriminated against for exercising them.

Everything you enter into the app is held only on your device, so you already have complete and direct control over it:

  • To see it or change it: open the app. Everything is there.
  • To delete all of it: delete the app from your iPhone.

The anonymous analytics and subscription records described above are not linked to your identity and we have no means of connecting them to a named person, so in the ordinary case we cannot locate “your” records in order to produce or erase them. If you want the analytics record for a particular installation deleted, write to us from the device in question and we will do our best to help; we may have to explain that we cannot verify which record is yours, in which case we will say so plainly rather than delete someone else’s.

You can stop analytics being generated at any time by deleting the app.

We do not sell or share personal information as those terms are defined under the CCPA, and we have not done so in the preceding twelve months. We do not engage in cross-context behavioural advertising.

If you believe we have processed your personal data improperly, you may complain to your local supervisory authority. In Italy this is the Garante per la protezione dei dati personali (garanteprivacy.it).

Children

Tan Buddy is not directed at children and is not intended for anyone under 13 (or the minimum age of digital consent in your country, whichever is higher). We do not knowingly collect personal data from children, and the anonymous analytics described above cannot identify anyone’s age. If you believe a child has used the app in a way that concerns you, contact us at support@iosvisual.com.

Security

Your data is protected by iOS’s app sandbox, by file-system encryption, and by your device passcode or biometric lock. Network requests use HTTPS. No method of electronic storage or transmission is completely secure. Because everything personal stays on your phone, the security of that data depends principally on the security of your own device: keep iOS up to date, use a passcode, and be careful about who has physical access to your iPhone.

International transfers

The forecast request described above is sent by your device directly to Open-Meteo, whose servers may be located outside your country and whose practices are governed by their own terms. Our analytics infrastructure is hosted in the European Union. RevenueCat is in the United States, and that transfer is made under the European Commission’s Standard Contractual Clauses.

Retention

Data on your device is retained for as long as you keep the app installed, and is destroyed when you delete it.

Anonymous analytics events are kept for as long as they are useful for understanding how the app is used, and in any case no longer than 24 months, after which they are deleted or irreversibly aggregated. Subscription records held by RevenueCat are retained for as long as we operate the subscription, as required for accounting and tax purposes.

Changes to this policy

We may update this policy from time to time — for example if a future version of the app adds a feature that changes what data is handled. The “Last updated” date above will change, and material changes will be described in the app’s release notes. Continuing to use the app after an update means you accept the revised policy. Previous versions are available on request.

Contact

support@iosvisual.com

We aim to reply to privacy questions within 30 days.