Last updated: April 29, 2026 | Effective date: April 29, 2026
1. Who We Are
SunSpots is operated by:
- Company: QubitumAI SAS
- SIRET: 942469610
- Address: France (EU)
- Data Protection Officer: dpo@qubitumai.com
- Contact: contact@qubitumai.com
We are committed to the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and applicable international privacy laws.
2. Data We Collect
2.1 Account Information
- Email address — for account creation and recovery (Supabase Auth)
- Display name & profile photo — visible to your friends (optional)
- Authentication tokens — securely stored for session management
2.2 Location Data
- Precise GPS coordinates — when you search for nearby sunny spots (requires permission)
- Coarse location — city/region for faster searches
- Spot visit history — spots you explicitly save, check in to, or review
2.3 Health & UV Exposure
- Skin preference — optional display preference for non-medical UV condition cues
2.4 Photos & Media
- Story uploads — photos/videos you share (24-hour auto-deletion)
- Photo metadata (EXIF) — time, location, device info (automatically sanitized)
2.5 Social & Friends
- Friends list — contacts you add (encrypted)
- Presence data — whether you're "at a spot" or "nearby" (privacy-configurable)
- RSVP history — spots you've marked "going" or "attended"
2.6 Activity & Visits
- Visits — timestamp when you arrive/leave a spot
- Reviews & ratings — reviews you write about spots
- Wishlist — spots you save for later
2.7 Analytics & Telemetry
- PostHog events — anonymized user behavior (feature usage, screen views)
- Device info — OS version, device model, app version (diagnostic only)
- Performance metrics — app crashes, load times, API latency
2.8 Crash Reports & Debugging
- Sentry error reports — stack traces, error context (PII automatically redacted)
- Console logs — when a crash occurs (sanitized before transmission)
2.9 Payment Information
- RevenueCat receipt data — subscription status, auto-renewal preference
- Receipt validation tokens — never stored locally; verified server-side
2.10 Security & Fraud Prevention
- Device fingerprinting — to detect jailbreak/rooted devices
- Certificate pinning logs — MITM attack detection
- IP address — for DDoS protection and abuse detection
3. Why We Collect Your Data
Essential Service Delivery
- Find nearby sunny spots using your location
- Display real-time weather & UV index at each spot
- Connect with friends and share experiences
- Manage your subscription and in-app purchases
Personalization & Recommendations
- Recommend spots based on your skin type & history
- Provide non-medical UV condition alerts based on your chosen preferences
- Show spots your friends frequent
Product Analytics & Improvement
- Understand which features users love
- Identify and fix bugs quickly
- Measure app performance across devices
- Comply with App Store requirements (analytics)
Security & Fraud Prevention
- Protect accounts from unauthorized access
- Detect and block compromised devices
- Prevent abuse and inappropriate content
Legal & Compliance
- Fulfill tax obligations (GDPR, CCPA)
- Respond to lawful government requests
- Enforce Terms of Service
4. Legal Basis (GDPR)
| Data Category | Legal Basis | Duration |
|---|---|---|
| Account & Email | Contract (user agreement) | Duration of account |
| Location (GPS) | Consent (location permission prompt) | Until revoked |
| Analytics (PostHog) | Consent (cookie/analytics notice) | Until opt-out |
| Crash Reports (Sentry) | Legitimate Interest (security) | 30 days |
| Payment (RevenueCat) | Contract (subscription) | Duration of subscription |
| Friends List | Contract (social features) | Until deleted |
5. Third-Party Data Processors
We work with trusted partners to deliver SunSpots safely and reliably:
📍 Location & Mapping
- Google Maps Platform — reverse geocoding, place data
- OpenWeatherMap — real-time weather & UV index
🔐 Authentication & Security
- Supabase (EU Server) — account storage, authentication, database
- Location: Frankfurt, Germany (EU compliance)
- Data Processing Agreement: Signed B-16 compliance
💳 Payments & Subscriptions
- RevenueCat — in-app purchase management
- We never store credit card details (all processed by RevenueCat/Apple/Google)
📊 Analytics & Monitoring
- PostHog — feature analytics (anonymized events)
- Opt-in: can be disabled in Settings → Privacy
- Sentry — crash reporting (PII auto-redacted)
Optional Future Integrations
- Voice search providers — not enabled in the launch build; no microphone data is collected unless a future version asks for permission and updates this policy.
🍎 Platform Permissions
- iOS Photos — upload stories (user selected only)
- Android MediaStore — upload stories (user selected only)
- Apple Maps — device location API
6. Data Retention & Deletion
| Data Type | Retention Period | Auto-Delete? |
|---|---|---|
| Stories (photos/videos) | 24 hours | ✅ Automatic |
| Account Data | Until deletion request | ✅ On demand (Settings) |
| Visits & Reviews | Until deleted by user | ✅ User can delete |
| Friends List | Until cleared | ✅ User can clear |
| Analytics Events | 90 days | ✅ Automatic |
| Crash Reports | 30 days | ✅ Automatic |
| Location History | Until opted out | ✅ User can disable |
Delete Your Account
To delete your account and all associated data:
- Open Settings → Account → Delete Account
- Confirm your choice
- Your data will be permanently deleted within 30 days
- Receive confirmation email at your registered address
7. Your Privacy Rights
🇪🇺 GDPR Rights (EU Residents)
- Right to Access — Request a copy of your personal data
- Submit via Settings → Privacy → Download My Data
- Right to Rectification — Correct inaccurate data
- Edit profile in Settings → Account
- Right to Erasure ("Right to be Forgotten") — Delete all your data
- Settings → Account → Delete Account
- Right to Restrict Processing — Limit how we use your data
- Disable analytics, location history in Settings → Privacy
- Right to Data Portability — Export your data in machine-readable format
- Settings → Privacy → Download My Data (JSON format)
- Right to Object — Opt-out of marketing, analytics
- Settings → Privacy → Disable Analytics
- Right to Lodge a Complaint — Contact your national data protection authority
- CNIL (France): www.cnil.fr
🇺🇸 CCPA Rights (California Residents)
- Right to Know — What personal information we collect
- Request via contact form
- Right to Delete — Ask us to delete your information
- Settings → Account → Delete Account
- Right to Correct — Ask us to correct inaccurate data
- Edit profile in Settings
- Right to Opt-Out of Sale — We don't sell your data anyway
- But you can disable analytics in Settings → Privacy
- Right to Non-Discrimination — We won't penalize you for exercising these rights
🇨🇦 PIPEDA Rights (Canadian Residents)
- Right to access, correct, and delete your personal information
- Contact our DPO at dpo@qubitumai.com
🔐 Exercising Your Rights
To exercise any of these rights, contact us:
- Email: dpo@qubitumai.com
- In-App: Settings → Privacy → Submit Privacy Request
- Response time: 30 days (GDPR/CCPA requirement)
8. Children's Privacy (COPPA)
Minimum age: 13 years old globally | 16 years old in EU (GDPR)
SunSpots is not intended for children under 13. If we discover a child is using our service without parental consent, we will delete their account immediately.
If you're the parent or guardian of a child using SunSpots, please contact us at contact@qubitumai.com.
9. International Data Transfers
Our primary servers are in the EU (Supabase, Frankfurt). However, some third-party processors may transfer data internationally:
- Google Cloud (USA) — Google Maps, OpenWeatherMap
- RevenueCat (USA) — Payment processing (Apple/Google)
For these transfers, we rely on:
- ✅ Standard Contractual Clauses (SCCs) — EU-approved transfer mechanism
- ✅ Adequacy Decisions — Where applicable (e.g., UK)
- ✅ Processor Data Processing Agreements — Signed contracts with all vendors
10. Security & Protection Measures
We implement industry-leading security to protect your data:
Encryption in Transit
- ✅ TLS 1.3 — All API communications encrypted
- ✅ Certificate Pinning — Prevents MITM (man-in-the-middle) attacks
Encryption at Rest
- ✅ AES-256 — Sensitive data encrypted in database
- ✅ Supabase Encryption — EU data center with GDPR compliance
Application Security (OWASP Top 10)
- ✅ M1: Broken Access Control — RLS policies, JWT validation
- ✅ M3: Injection — Parameterized queries, no raw SQL
- ✅ M5: Security Misconfiguration — Regular audits, secure defaults
- ✅ M8: Software & Data Integrity Failures — Code signing, dependency scanning
Device Security
- ✅ Jailbreak Detection — Blocks compromised iOS/Android devices
- ✅ Obfuscation — Flutter native code obfuscated in release builds
- ✅ Secure Storage — Auth tokens stored in platform secure storage
Analytics & Monitoring
- ✅ Sentry — Real-time error monitoring with PII redaction
- ✅ PostHog — Anonymized behavior analytics
- ✅ Automated Alerts — Security team notified of suspicious activity
Incident Response
If we discover a data breach:
- Immediate investigation (within 24 hours)
- Notify affected users (within 72 hours per GDPR)
- Report to authorities if required
- Publish transparency report within 30 days
11. Changes to This Privacy Policy
We may update this policy to reflect new features, legal requirements, or security improvements.
When we make material changes:
- 📲 In-app notification — You'll be notified 30 days before changes take effect
- 📧 Email — Important changes sent to your registered email
- 🔔 Last Updated — Date stamp at top of this page
Your continued use of SunSpots after changes means you accept the updated policy.
12. Contact Us
Data Protection Officer
Email: dpo@qubitumai.com
Company: QubitumAI SAS
SIRET: 942469610
Jurisdiction: France (EU)
Privacy Requests
For any privacy request (access, deletion, correction, portability):
- Use in-app Settings → Privacy → Submit Privacy Request
- Or email dpo@qubitumai.com with "Privacy Request" in subject
- Include: your account email, request type, and details
- We respond within 30 days (GDPR requirement)
General Inquiries
Email: contact@qubitumai.com
13. Right to Complain
If you believe we've violated your privacy rights, you have the right to lodge a complaint with your national data protection authority:
🇪🇺 EU/EEA
- France: CNIL (Commission Nationale de l'Informatique et des Libertés)
- Germany: BfDI (Federal Data Protection Officer)
- Ireland: DPC (Data Protection Commission)
- Spain: AEPD (Agencia Española de Protección de Datos)
🇺🇸 United States
- California: California Attorney General
Before Filing a Complaint
Please contact us first. We're happy to resolve issues directly:
Last Updated: April 29, 2026
This Privacy Policy is available in English and French. In case of conflict, the English version prevails.