Last updated: April 29, 2026 | Effective date: April 29, 2026
1. What Are Cookies?
Cookies are small text files stored on your device (phone, tablet, computer) that websites and apps use to remember information about you.
Types of Cookies
- Session Cookies: Deleted when you close the app/browser
- Persistent Cookies: Remain on your device for a specified period (days, months, years)
- First-Party Cookies: Set by SunSpots
- Third-Party Cookies: Set by our partners (analytics, payments, etc.)
Note: SunSpots is a Mobile App
SunSpots is primarily a mobile app (iOS/Android), not a website. We don't use traditional HTTP cookies on mobile. Instead, we use:
- Local Storage: App-level data storage (auth tokens, preferences)
- Secure Keychain: Passwords and sensitive tokens (encrypted)
- Device Identifiers: To track installation and analytics
Web Version: If you access SunSpots via web (sunspots.app), we use traditional cookies as described below.
3. Tracking on SunSpots Mobile App
Authentication & Session Management
- JWT Tokens: Stored securely on your device (iOS Keychain, Android Keystore)
- Never Stored in Plain Text: Encrypted before storage
- Device Token: Identifies your installation (used for push notifications)
Analytics (PostHog)
- What we track:
- Feature usage (which screens you visit)
- Button clicks and interactions
- Search queries (keywords only, not location)
- Spot views and visits
- Crashes and errors
- What we DON'T track:
- Your exact GPS coordinates (sent to you, not to analytics)
- Personal messages or reviews
- Payment information
- Friend relationships (unless you opt-in)
- Opt-Out: Settings → Privacy → Disable Analytics (requires app restart)
Crash Reporting (Sentry)
- What we capture:
- Error messages and stack traces
- Device info (OS version, device model)
- App version
- What we DON'T capture:
- User IDs or email addresses (automatically redacted)
- Sensitive data (passwords, tokens, PII)
- Screenshots or memory dumps
- Retention: 30 days, then automatically deleted
Ad Tracking (None Currently)
SunSpots does NOT use:
- Google Ads (GAID, IDFA)
- Mobile attribution networks
- Behavioral advertising
- Cross-app tracking
This means we won't target you with ads across other apps (good for your privacy!).
4. Third-Party Cookies & Integrations
Google Maps Platform
- What they track: Map views, location searches, place interactions
- Cookies: NID (Google analytics), SameSite cookies
- Privacy Policy: Google Privacy Policy
Supabase (Authentication & Database)
- What they store: Auth tokens, user credentials (encrypted)
- Cookies: Session management, CSRF protection
- Privacy Policy: Supabase Privacy Policy
PostHog (Analytics)
- What they track: Anonymized usage events
- Cookies: posthog_id, session identifiers
- Privacy Policy: PostHog Privacy Policy
- Opt-Out: Settings → Privacy → Disable Analytics
Sentry (Error Reporting)
- What they capture: Error traces, device info (PII redacted)
- Cookies: None (native mobile, no cookies)
- Privacy Policy: Sentry Privacy Policy
RevenueCat (Payments)
- What they store: Subscription receipts (not payment methods)
- Cookies: None (native mobile)
- Privacy Policy: RevenueCat Privacy Policy
iOS Permissions
- Current launch scope: location, photos/media when used, and camera for AR sun-path overlay.
- Tracking: None for platform permissions.
- Privacy Policy: Apple Privacy Policy
5. Your Cookie & Tracking Choices
🔐 Strictly Necessary Cookies (Cannot be Disabled)
These cookies are required for SunSpots to function. You cannot disable them without losing access to the app.
- Authentication tokens
- Session management
- CSRF protection
⚙️ Functional Cookies (Can be Disabled)
These improve your experience but aren't required. You can disable:
- Language preference
- Theme preference (light/dark mode)
How to disable: Clear app data (Settings → Apps → SunSpots → Clear Storage)
📊 Analytics Cookies (Opt-In)
Default: OFF (you must opt-in)
How to enable/disable: Settings → Privacy → Analytics
🍪 Browser Cookie Controls
If you access SunSpots via web:
- Chrome: Settings → Privacy → Cookies and other site data
- Safari: Preferences → Privacy → Manage Website Data
- Firefox: Preferences → Privacy → Cookies and Site Data
- Edge: Settings → Privacy → Cookies and Site Data
📱 Mobile App Data & Privacy
iOS:
- Settings → Privacy → SunSpots → toggle off permissions (Location, Photos, Camera)
- Settings → SunSpots → toggle off analytics/personalized ads
Android:
- Settings → Apps → SunSpots → Permissions → toggle off Location, Photos, Camera
- Settings → Google → Manage your Google Account → Data & Privacy → Personalization
❌ Opt-Out Methods
- PostHog (Analytics): In-app toggle or email dpo@qubitumai.com
- Sentry (Crash Reports): Disable in app settings (may limit bug fixes)
- All Tracking: Delete the app
6. App Store & Play Store Requirements
🍎 Apple App Store — App Privacy
Apple requires apps to disclose what data they collect:
- Data Used to Track You: Device ID (IDFA) — disabled by default in SunSpots
- Data Linked to You: Email, location, friend relationships (optional)
- Data NOT Linked to You: Crash data, analytics events (anonymized)
View our disclosures: App Store → SunSpots → Privacy section
🎮 Google Play Store — Data Safety
Google requires disclosure of:
- Data types collected (location, photos, etc.)
- Data security practices (encryption, SSL/TLS)
- User rights and controls
View our disclosures: Play Store → SunSpots → About → Data Safety
7. "Do Not Track" Signals
Some browsers support "Do Not Track" (DNT) signals. SunSpots respects DNT in the following ways:
- If DNT is enabled, we disable PostHog analytics automatically
- We still capture crash data (needed for security)
- Essential cookies cannot be disabled
Enable DNT:
- Chrome: Settings → Privacy → Do Not Track
- Safari: Preferences → Privacy → Prevent cross-site tracking
- Firefox: Preferences → Privacy → Do Not Track
8. GDPR & CCPA Cookie Compliance
🇪🇺 GDPR (EU Residents)
Consent Requirement: We must have your consent before using non-essential cookies.
- Essential: No consent needed (required for service)
- Analytics: Consent required (opt-in by default)
- Marketing: Consent required (we don't use for marketing)
Consent Management:
- You see a cookie notice on first visit to sunspots.app
- You can change preferences anytime in Settings
- Consent is recorded and saved
🇺🇸 CCPA (California Residents)
Consumer Rights:
- Right to Know: What cookies we use (list above)
- Right to Delete: Request deletion of cookies (via clear app data)
- Right to Opt-Out: Disable analytics and tracking (settings)
Do Not Sell My Personal Information: We don't sell your data. Cookies aren't "sold" in CCPA terms.
9. Changes to This Cookie Policy
We may update this policy to reflect:
- New features or integrations
- Changes in third-party services
- Legal requirements (GDPR, CCPA, etc.)
- Improved privacy practices
Notification: We'll notify you via:
- In-app notification (for major changes)
- Email (for security-related changes)
- Updated "Last Updated" date (top of this page)
Your continued use means you accept the updated policy.
10. Questions About Cookies?
Cookie-Related Inquiries
Email: dpo@qubitumai.com
Subject: "Cookie/Tracking Question"
Response time: 48 hours
Privacy Requests
To opt-out of all tracking or request data deletion:
- Open Settings → Privacy
- Click "Submit Privacy Request"
- Select "Disable All Tracking"
- We'll confirm within 24 hours
Last Updated: April 29, 2026
This Cookie Policy is available in English and French. In case of conflict, the English version prevails.