
Privacy Policy HelloSun
Responsible person
Kevin Reutter,
Wiesengrund 16, 25715 Eddelak
Germany
**Last updated: 24 July 2026**
I am very delighted that you have shown interest in HelloSun. Data protection is of a particularly high priority for me. HelloSun is designed to work **entirely on your device**: it reads your daylight time HelloSun Apple Health and shows it back to you beautifully. It has **no servers of its own**, requires **no account**, and contains **no advertising, no analytics, and no third‑party tracking**.
The only time information leaves your device is when you enable sun‑protection: your approximate location is sent to **Apple WeatherKit** to retrieve the current UV index. In that case Apple acts as the processor under its own privacy terms. Your health data (time in daylight) **never leaves your device** and is never transmitted to me or to any third party.
The processing of any personal data shall always be in line with the General Data Protection Regulation (GDPR) and the country‑specific data protection regulations applicable to me as the controller. By means of this data protection declaration I would like to inform you of the nature, scope, and purpose of the personal data processed in connection with HelloSun, and of the rights to which you are entitled.
As the controller, Kevin Reutter has implemented technical and organizational measures to protect any personal data processed through HelloSun — first and foremost by keeping data on your device by default. However, Internet‑based data transmissions (such as the UV request to Apple WeatherKit) may in principle have security gaps, so absolute protection cannot be guaranteed.
---
## 1. Definitions
This data protection declaration is based on the terms used by the European legislator for the adoption of the General Data Protection Regulation (GDPR). It should be legible and understandable for the general public as well as for users. To ensure this, I would like to first explain the terminology used.
**a) Personal data** — any information relating to an identified or identifiable natural person (“data subject”). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
**b) Data subject** — any identified or identifiable natural person whose personal data is processed by the controller responsible for the processing.
**c) Processing** — any operation performed on personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
**d) Restriction of processing** — the marking of stored personal data with the aim of limiting their processing in the future.
**e) Profiling** — any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.
**f) Pseudonymisation** — the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and subject to technical and organisational measures.
**g) Controller** — the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data. For HelloSun, the controller is Kevin Reutter (see Section 2).
**h) Processor** — a natural or legal person who processes personal data on behalf of the controller. For HelloSun, Apple Inc. acts as a processor when providing the WeatherKit service.
**i) Recipient** — a natural or legal person to which personal data are disclosed, whether a third party or not.
**j) Third party** — a natural or legal person other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data.
**k) Consent** — any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she signifies agreement to the processing of personal data relating to him or her (for example, the iOS/watchOS permission prompts for Health and Location).
---
## 2. Name and Address of the Controller
Controller for the purposes of the GDPR and other data protection laws applicable in Member States of the European Union is:
**Kevin Reutter**
Wiesengrund 16, 25715 Eddelak
Germany
Phone: +49 1523 7967235
Email: humantechnologybykevinreutter@gmail.com
Website: appsbykevinreutter.com
---
## 3. What Data HelloSun Processes
This section describes, specifically and completely, how HelloSun handles data. In short: your data stays on your device, and I (the developer) receive **nothing**.
### a) Health data — time in daylight
With your permission, HelloSun reads the **“Time in Daylight”** value from Apple Health (HealthKit). This is used solely to display your daily progress, streaks, statistics, widgets and complications.
- Access is **read‑only**. HelloSun does **not** write any data to Apple Health.
- This data is **processed on your device only** and is **never transmitted** to me or to any third party.
- HealthKit data is not used for advertising, is not sold, and is not shared.
### b) Location — only for the UV index
If you enable sun‑protection features, HelloSun requests **one‑time, coarse (approximate) location access “While Using the App.”** Your approximate location is used **exclusively** to look up the current and daily UV index via Apple WeatherKit.
- Location is requested on demand (roughly up to twice per day) and is **not** continuously tracked.
- Your location is **not** stored on any server of mine and is **not** used to build any profile.
- Only the place **name** (e.g. city) returned for the lookup may be shown in the app and stored locally on your device.
### c) Weather / UV — Apple WeatherKit
To obtain the UV index, the app sends the coarse location to **Apple WeatherKit**. Apple processes this request under Apple’s own privacy policy and WeatherKit terms. See Apple’s Privacy Policy at https://www.apple.com/legal/privacy/ and Apple Weather/WeatherKit information at https://weatherkit.apple.com/legal-attribution.html.
### d) Local storage
Your goal, skin type, daylight history, UV snapshot and the counter of WeatherKit calls are stored **locally on your device** (in the app’s private storage / App Group container), so that the app, its widgets and its watch complications can display them. This data is removed when you delete the app. Data may be synchronised **between your own Apple Watch and iPhone** via Apple’s on‑device WatchConnectivity, so the watch can show the UV value the iPhone retrieved.
### e) No accounts, no tracking, no analytics
HelloSun has **no user accounts**, contains **no advertising**, uses **no analytics or tracking SDKs**, and performs **no cross‑app or cross‑site tracking**. No usage profiles are created. The App Store “Privacy Nutrition Label” and the bundled privacy manifest reflect this (no tracking, no data collected/linked to you).
### f) App Store
When you download HelloSun, Apple (the App Store operator) processes the data necessary for the download and, if applicable, payment. This processing is carried out by Apple and is subject to Apple’s privacy policy; I have no influence over it and do not receive personally identifiable purchase data.
---
## 4. Rights of the Data Subject
Because HelloSun keeps your data on your device and I hold **no personal data about you** on any server, you remain in full control at all times: you can grant or revoke Health and Location permissions in the iOS/watchOS Settings, and you can erase all app data by deleting the app. Independently of this, the GDPR grants you the following rights, which you may exercise at any time by contacting the controller (Kevin Reutter) using the details in Section 2.
**a) Right of confirmation** — You have the right to obtain confirmation as to whether or not personal data concerning you are being processed.
**b) Right of access** — You have the right to obtain information about your personal data and, where applicable, a copy of it, including the purposes of the processing, the categories of data, the recipients, the envisaged storage period, and the existence of your other rights listed here.
**c) Right to rectification** — You have the right to obtain, without undue delay, the rectification of inaccurate personal data concerning you and to have incomplete data completed.
**d) Right to erasure (right to be forgotten)** — You have the right to obtain the erasure of personal data concerning you where the grounds set out in Article 17 GDPR apply. As HelloSun stores data only on your device, deleting the app already erases all locally stored data.
**e) Right of restriction of processing** — You have the right to obtain restriction of processing where one of the conditions of Article 18 GDPR applies.
**f) Right to data portability** — You have the right to receive the personal data concerning you which you provided, in a structured, commonly used and machine‑readable format, and to transmit it to another controller, where the conditions of Article 20 GDPR are met. Within the app, you can export your daylight history as a CSV file at any time.
**g) Right to object** — You have the right to object, on grounds relating to your particular situation, to processing based on Article 6(1)(e) or (f) GDPR. As HelloSun does not process your data for direct marketing, no marketing objection is necessary.
**h) Automated individual decision‑making** — You have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects. HelloSun performs no such automated decision‑making (see Section 8).
**i) Right to withdraw consent** — Where processing is based on your consent, you may withdraw that consent at any time — for example by turning off Health or Location access in the system Settings — without affecting the lawfulness of processing carried out before the withdrawal.
**j) Right to lodge a complaint** — You have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your residence or place of the alleged infringement.
---
## 5. Legal Basis for the Processing
- **Art. 6(1)(a) GDPR (consent)** and, for health data, **Art. 9(2)(a) GDPR (explicit consent)** are the legal basis for reading your time‑in‑daylight from Apple Health and for accessing your approximate location for the UV lookup. You grant this consent through the iOS/watchOS permission prompts and may withdraw it at any time in Settings.
- **Art. 6(1)(f) GDPR (legitimate interests)** is the basis for the app’s core on‑device functionality where no consent is required — for example storing your goal and history locally so the app, widgets and complications can display your progress.
---
## 6. Legitimate Interests Pursued by the Controller
Where processing is based on Article 6(1)(f) GDPR, the legitimate interest is to provide you with a working, private, offline‑first app that reliably displays your daylight progress and sun‑protection information on your own device, without collecting personal data on any server.
---
## 7. Period for Which the Personal Data Will Be Stored
Data processed by HelloSun is stored **locally on your device** for as long as you keep the app installed and for as long as it is useful to display your history and current values. You can delete it at any time by removing the app or by revoking the relevant permissions in Settings. I, as the controller, retain **no personal data about you** on any server and therefore apply no server‑side retention period. Any statutory retention obligations relate only to legally required business records (e.g. tax documents) held by Apple in connection with a purchase, not to your health or location data.
---
## 8. Provision of Personal Data; Consequences of Non‑Provision
Providing Health and Location access is **entirely voluntary** and is not a legal or contractual requirement. HelloSun remains usable without it, with reduced functionality:
- Without **Health** access, the app cannot show your time‑in‑daylight, progress, statistics, widgets or complications.
- Without **Location** access, the app cannot show the UV index, the sunburn budget or sun‑protection recommendations.
There are no other consequences of declining these permissions.
---
## 9. Existence of Automated Decision‑Making
HelloSun does **not** use automated decision‑making or profiling within the meaning of Article 22 GDPR. Calculations such as your progress ring, streaks, UV curve and sunburn budget are simple, transparent computations performed on your device to display information back to you; they produce no legal or similarly significant effects.
---
## 10. Children
HelloSun is not directed at children and does not knowingly collect personal data from children. As no personal data is transmitted to me, no such data is held by me.
---
## 11. Changes to This Privacy Policy
I may update this privacy policy from time to time — for example, to reflect new app features or changes in the law. The current version, indicated by the “Last updated” date at the top, always applies. Material changes will be reflected in an app update.
---
## 12. Contact
If you have any questions about data protection in HelloSun, or wish to exercise any of your rights, please contact the controller:
**Kevin Reutter** · humantechnologybykevinreutter@gmail.com · appsbykevinreutter.com