1. Who is responsible for your data
The data controller responsible for processing personal data in connection with the Tanion app and this website is:
Elias Hüngerle
Bungertstrasse 23
8802 Kilchberg
Switzerland
Email: eliashuengerle8@gmail.com
If you have any questions about this policy or your data, contact us at the email address above.
2. Privacy at a glance
- No account required. Tanion works without a login, username or password. We do not ask for your name, email or phone number to use the app.
- Local-first by design. Your routines, progress history, survey answers, settings, Vitamin D log, streaks and achievements are stored on your device.
- Photos stay on your device and are only transmitted at the moment you request an AI progress scan.
- No advertising and no data sales. We do not use advertising trackers and we never sell your data.
3. What information we process
3.1 Data stored only on your device
The following information is created and stored locally on your device (using secure on-device storage and the app's private file area). It is not transmitted to or stored by us, except as described in the AI analysis and location sections below:
- Skin profile & onboarding answers — such as your skin type, how your skin reacts to the sun, natural skin tone, freckles, eye and hair color, optional gender, and your tanning goals.
- Tanning routines & sessions — your routine steps, timing and completion history.
- Progress scans — photos you capture and the resulting analysis metrics (for example shade, tan level, evenness, sun stress and recovery), saved to your private progress timeline.
- Vitamin D goal and log, estimated from your sessions.
- Streaks, achievements and app settings.
Because this data lives on your device, you control it. Deleting the app removes this local data.
3.2 Progress photos and AI analysis
When you choose to run an AI progress scan, the selfie you capture is sent to our AI processing provider (OpenAI) to generate the skin and tan metrics described above. The photo is transmitted only to perform that analysis; we do not retain a server-side copy of the image, and the photo itself is kept in your device's private storage.
The optional onboarding skin scan is simulated and processed entirely on your device — that image is never uploaded.
3.3 Anonymous usage limit
To keep AI scans fair and prevent abuse, Tanion enforces a monthly scan allowance. To do this we store a randomly generated, anonymous identifier together with a scan count and reset date with our backend provider (Supabase). This identifier is not linked to your name, email or Apple ID and cannot be used to identify you.
3.4 Location data
If you grant location permission, Tanion uses your device's approximate coordinates to fetch the live UV index and weather forecast for your area. The coordinates are sent to our weather service to retrieve this data (via providers such as Apple WeatherKit and/or Open-Meteo). Location is used only to provide UV and weather features and is not used to track or identify you.
3.5 Notifications
If you enable reminders and alerts, Tanion schedules notifications (for example, the best time to tan, reminders to reapply, and session updates). Delivering push notifications may involve a device push token processed by Apple Push Notification service.
3.6 Camera and photo library
Tanion requests camera and photo access only to let you capture progress selfies and scan your skin tone. Access is used solely for these features and only after you grant permission.
3.7 Subscriptions
Tanion Pro subscriptions are purchased and managed through the Apple App Store. Apple processes your payment and manages billing; we do not receive or store your payment card details. We may receive your subscription status (active, expired, renewed) to unlock Pro features.
3.8 Technical & diagnostic data
Like most mobile apps, Tanion and its underlying platform (Expo and Apple) may process limited technical information such as app version, device model and crash diagnostics to keep the app working reliably. We do not use this information to build advertising profiles.
4. Why we process your data and our legal bases
Where the EU/UK General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (FADP) apply, we rely on the following legal bases:
- Your consent (Art. 6(1)(a) GDPR) — for camera, photo library, location and notification access, and for sending a photo for AI analysis. You can withdraw consent at any time in your device settings.
- Performance of a contract (Art. 6(1)(b) GDPR) — to provide the app features you request, including Tanion Pro subscription functionality.
- Legitimate interests (Art. 6(1)(f) GDPR) — to secure the service, prevent abuse of AI scans, and maintain and improve app reliability.
6. International data transfers
Some of our service providers (for example, OpenAI and Supabase) may process data on servers located outside Switzerland and the European Economic Area, including in the United States. Where data is transferred internationally, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses and equivalent mechanisms recognized under Swiss law.
7. How long we keep data
- On-device data remains on your device until you delete it within the app or uninstall Tanion.
- Progress photos are not retained on our servers after analysis; they remain in your device storage until you delete them.
- The anonymous scan counter resets monthly and is retained only as long as needed to enforce usage limits.
8. Your privacy rights
Subject to applicable law, you have the right to access, correct, delete, restrict or object to the processing of your personal data, to request portability, and to withdraw consent at any time. BecauseTanion is local-first, you can exercise most of these rights directly: edit or delete your entries in the app, revoke permissions in your device settings, or uninstall the app to remove local data.
To make a request regarding any data we process, email eliashuengerle8@gmail.com. You also have the right to lodge a complaint with a supervisory authority — in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC); in the EU, your local data protection authority.
9. Children
Tanion is not directed to children. The app is intended for users aged 16 and over. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can address it.
10. Security
We use technical and organizational measures to protect your data, including on-device secure storage for sensitive values, encrypted connections (HTTPS/TLS) for any data in transit, and data minimization throughout the app. No method of transmission or storage is completely secure, but we work to protect your information using appropriate safeguards.
11. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes to the app or legal requirements. When we do, we will revise the "Last updated" date above. Significant changes will be communicated within the app where appropriate.
12. Contact
For any privacy questions or requests, contact:
Elias Hüngerle
Bungertstrasse 23, 8802 Kilchberg, Switzerland
eliashuengerle8@gmail.com