Privacy Policy
Last updated: April 21, 2026
Toasty (“we”, “us”) makes a tanning forecast app for iPhone. This policy explains what data we collect, why we collect it, and what we do with it. It’s short on purpose.
What we collect
Information you give us
- Skin profile: Fitzpatrick skin type, tan goal, SPF habit, tan frequency, optional display name, and typical surface (grass/concrete/sand/water/snow).
- Session history: when you tap PLAY, how long each session runs, and what percent of your burn-time ceiling it reached.
- Cancellation feedback (only if you cancel): your reason and any optional comment you add.
Information your device sends
- Approximate location: used only to request the UV forecast from Apple Weather. Location is processed on device and by Apple; we receive the resulting forecast values, not your GPS trace.
- Subscription status: whether you have an active Toasty Pro entitlement. We do not see your payment information — purchases are handled by Apple.
- Diagnostics (release builds only): anonymized crash reports and error breadcrumbs via Sentry, used to find and fix bugs. Free-text fields are stripped before upload.
What we do not collect
- Photos or selfies. Toasty has no camera access.
- Email or password. Accounts are anonymous by default — we don’t know who you are.
- Contacts, calendar, or health data.
- Precise GPS tracks or location history.
Where your data lives
Your profile and session data sync to Supabase, a managed Postgres host, under your anonymous account ID. Row-level security restricts every row to the device that created it — no other user, and no Toasty staff without elevated access, can read your rows.
Your profile photo, if you set one, is stored only on your device.
Third parties
- Apple Weather (WeatherKit):UV + cloud + temp forecast. Apple’s privacy terms apply.
- RevenueCat: processes subscription receipts from Apple and tells us whether your Pro entitlement is active. It sees an anonymous user ID and your purchase metadata, not your identity.
- Supabase: hosts your profile and session data under your anonymous account ID.
- Sentry (release builds only): receives crash reports with stack traces and short breadcrumbs. Free-text payloads are stripped before send.
Your choices
- Delete account. Profile → Delete account. We wipe your profile, every session, cancellation feedback, and your anonymous auth identity.
- Turn off notifications. Profile → Notifications. Or disable in iOS Settings.
- Manage subscription. Profile → Subscription. Apple handles billing — cancel anytime in your Apple ID settings.
Children
Toasty is not intended for children under 13 and does not knowingly collect data from them. If you believe a child has used Toasty, email us and we’ll delete the account.
Changes
If we change this policy we’ll update the “Last updated” date above. Material changes will be highlighted in the app before they take effect.
Contact
Questions about privacy: hello@toastyuv.com.