Privacy Policy
Last updated: 28 August 2026
The short version
Geddy has no account and no login. It does need to know where you are — the whole product is a sun angle computed for your exact position — so this policy is mostly about what happens to that.
- Your location is used, and you should know where it goes. Geddy computes the sun's altitude on your device. It also sends your coordinates to Apple's WeatherKit to fetch the UV index and cloud cover, because those numbers decide both your dose estimate and your burn ceiling. Apple receives them. We never do.
- Your sessions, your dose history, and your blood test results are yours, and they sync through your own iCloud account. They go to your private iCloud database — the same place your other apps' iCloud data lives, under your Apple Account, encrypted, and reachable only by you and your devices. We have no server holding them, no access to your iCloud, and no way to look inside. Apple stores them for you; we never see them.
- Health is written to with your permission, and never read from. Geddy writes your sessions to Health as Time in Daylight. It asks for no read access at all. We do not receive your Health data, do not use it for advertising or marketing, and do not sell or share it with anyone.
- There is nothing to sign up for. No email address, no password, no profile. We do not know who you are.
- There is one advert, and it is a swap rather than a sale. The "Our fellows" card near the bottom of the Profile screen shows another independent developer's app, through Kickstart Exchange; their apps show Geddy in return, and no money changes hands. Kickstart is told that the card was shown and whether it was tapped. That is not linked to you and is not used to track you. Nothing else in Geddy reports your behaviour: we run no analytics SDK, and we do not measure which screens you open or which buttons you tap.
- We do not sell your personal information, and we do not track you across other companies' apps or websites.
The rest of this policy explains all of that precisely. If anything here is unclear, email [email protected] and we will answer.
Who we are
Geddy is made by Tagir Aiupov, a sole proprietor based in British Columbia, Canada ("we", "us", "our"). For data protection purposes we are the controller of the personal information described in this policy.
Geddy is a one-person operation run from a home office, so we do not publish a street address. Email reaches us directly, and we answer.
Email: [email protected]
This policy covers the Geddy iPhone app, its Live Activity, and the pages on our website that link to it (together, the "Services").
Contents
- What Geddy records, and where it is kept
- What leaves your device
- Location
- Health data
- What we never collect
- The Live Activity, notifications, and who can see them
- Why we are allowed to process your information
- Who else is involved
- How long we keep things
- How we protect your information
- Where your information goes
- Your privacy rights
- United States state privacy rights
- Children
- Do Not Track and Global Privacy Control
- Backups, sync, and what we cannot recover
- Changes to this policy
- How to contact us
1. What Geddy records, and where it is kept
Everything Geddy records about you:
- your profile: Fitzpatrick skin type, age, daily IU goal, and default coverage
- every session you run — start and end time, duration, the skin type and coverage it used, the estimated IU with its bounds, the peak UV index, the coordinates it was run at, and how much of your burn ceiling it consumed
- your blood 25(OH)D results, their dates, and any note you attach to them
- your saved locations: up to eight places you have set by hand, with their names, coordinates, and time zones
- your settings: reminder preferences, haptics, and whether you use a manual position
Where it lives. Two places, both yours:
- On your iPhone, in the app's own sandboxed storage, which other apps cannot read.
- In your private iCloud database, so that the same history appears on every device signed into your Apple Account, and survives losing a phone or reinstalling the app.
It is not uploaded to us. This is the distinction that matters most in this policy, so it is worth being exact about. Syncing means your records travel to your own iCloud account, held by Apple under your Apple Account, in the private database of Geddy's iCloud container. It does not mean they travel to us. We operate no server, hold no copy, and have no key, credential, or administrative route by which we could read your iCloud data. Apple's CloudKit gives a developer no access to any user's private database — not to ours, not to anyone's. What we can see about your account is nothing at all.
The private database is encrypted in transit and at rest by Apple, and its contents count toward your iCloud storage. It is governed by Apple's Privacy Policy and the iCloud terms you have with Apple, not by us.
You can switch it off. Sync follows iOS's own control: turn Geddy off under iOS Settings → your name → iCloud → Saved to iCloud → See All. With it off, Geddy keeps working and your history stays on the device it was recorded on. Nothing about the app depends on sync.
No account. Geddy has no sign-in of any kind. We never ask for your name, your email address, or a password in order to use the app. Your Apple Account is between you and Apple; we are never told whose it is.
2. What leaves your device
This is the complete list.
Your Geddy history, to your own iCloud. Everything in section 1 — sessions, blood results, saved locations, profile, and settings — is mirrored to the private database of Geddy's iCloud container so it reaches your other devices. It goes to Apple, as your iCloud provider, on your behalf. It does not go to us, and we cannot reach it. Section 1 explains this in full, including how to turn it off.
Your coordinates, to Apple. Section 3 covers this in full. In short: WeatherKit needs a position to return a UV index, and MapKit needs your typed text to turn "Kyoto" into a coordinate. Both go to Apple. Neither goes to us.
Subscription status — which does not reach us either. If you subscribe to Geddy Pro, Apple processes the payment and issues the receipt. Geddy checks whether your subscription is active on your device, by asking Apple's StoreKit framework directly; the receipt stays on the device and is never sent anywhere by us. There is no server of ours for it to be sent to. We never receive your card number, billing address, Apple Account credentials, or any record identifying you as a subscriber. What we see about sales is the aggregate App Store reporting described next, which is counts and totals rather than people.
Aggregate App Store data. Apple gives every developer aggregated, anonymised reports about downloads, sales, and app performance, and — only if you have turned on "Share With App Developers" in iOS Settings → Privacy & Security → Analytics & Improvements — aggregated usage and crash data. We see totals and trends, never an identifiable person. This is Apple's data collection, under Apple's control, and you can switch it off in that iOS setting at any time.
That an advert was shown, to Kickstart Exchange. The "Our fellows" card in Profile is served by the Kickstart Exchange SDK. When the card appears, the SDK asks their server for an advert and reports that it was displayed and whether you tapped it. Where StoreKit provides one it also sends Apple's signed App Transaction for this app, which proves Geddy is a genuine App Store install and which Kickstart checks and immediately discards; it says nothing about you. Their privacy manifest declares this as product-interaction and advertising usage data, not linked to your identity and not used for tracking. No coordinate, session, dose figure, blood result, or Health datum is involved, and it does not reach us either. Section 8 has their policy.
Anything you send us. If you email us, we receive what you write and the address you write from.
That is the entire list. There is nothing else. In particular, no session, no dose figure, no blood test result, and no coordinate ever reaches a server of ours, because we do not operate one.
3. Location
Geddy is a sun-angle instrument, so a position is not a nice-to-have — it is the input the entire product is computed from. Here is exactly how it is handled.
Two ways to give us one. Geddy asks for When In Use location access, which means it can read your position only while you have the app open or a session running. It never requests Always access and never reads your location in the background. If you would rather not grant it, setting your position by hand is a fully supported path, not a fallback — search for a place, pick it, and the app works the same way. A denied permission costs you nothing but the search.
What we do with it on your device. Solar elevation and azimuth, the daily window, sunrise and sunset, and the shape of the day's arc are all computed locally, from your coordinates and the date. That maths never touches a network.
What goes to Apple, and why. Two things do leave:
- Apple WeatherKit receives your coordinates in order to return the current UV index and cloud cover for that spot. Those two numbers feed your dose estimate and your burn ceiling, so the app cannot do its job without them, and it will not invent them if the request fails. Apple's handling of WeatherKit requests is governed by Apple's Privacy Policy.
- Apple MapKit receives what you type when you search for a place to set by hand, in order to return suggestions and resolve the one you choose into a coordinate. This only happens while you are typing in the location search.
Where it is stored. The coordinates a session was run at are saved with that session, on your device, so your log can tell a session in Reykjavík from one in Lisbon. Your saved locations are stored the same way. Neither is transmitted to us.
Turning it off. iOS Settings → Privacy & Security → Location Services → Geddy. Revoke it at any time; the app will fall back to your hand-set position.
4. Health data
Geddy integrates with Apple Health. Because Apple holds developers to specific commitments here, we state them plainly.
What Geddy writes. With your permission, each completed session is written to Health as Time in Daylight, so your exposure joins the rest of your health record.
What Geddy reads. Nothing. The app requests no read access of any kind, and the Health permission sheet it shows you carries a single row: permission to write. It previously asked for your date of birth to save you typing your age; that was removed, and the app now asks you for your age directly instead. There is no Health information flowing into Geddy at all.
Where that data lives. In Apple's HealthKit store on your device, under your control, protected by iOS and — if you have Health enabled for iCloud — encrypted in your own iCloud account. It is governed by Apple's terms.
Our commitments, which are absolute:
- We do not receive your Health data. It does not pass through any server of ours.
- We never use Health data for advertising, marketing, or any use-based data mining.
- We never sell Health data, and we never share it with a third party, data broker, or advertising network.
- Health data is used for one purpose only: providing the features described above, inside the app, on your device.
Blood 25(OH)D results do not go into Health. There is no writable serum vitamin D type in HealthKit — dietaryVitaminD measures intake in mass units, and filing a serum concentration there would put a wrong number under a wrong unit in your permanent health record. So the results you enter are stored only in Geddy, on your device. That also means Health's own privacy controls do not cover them; deleting the app deletes them.
Nothing here is load-bearing. Every value Health supplies has a manual equivalent in the app. Refusing the permission costs you a little typing and nothing else. Revoke it at any time in iOS Settings → Health → Data Access & Devices → Geddy, or in the Health app.
5. What we never collect
To be explicit, because a privacy policy that only lists what is taken is not much use:
- Your sessions, your dose history, your goal, and your blood test results. None of it reaches us. It syncs to your own iCloud account, which we cannot read — section 1.
- Your Health data. See section 4.
- Analytics of your behaviour inside the app. Geddy contains no analytics SDK, and we do not know which screens you open, which features you use, or how often you open the app. One narrow exception belongs to somebody else and not to us: Kickstart Exchange learns that its own advert card was shown and whether it was tapped. Nothing else about your use of the app, and nothing linked to you — sections 2 and 8.
- Your microphone, camera, photo library, contacts, or calendar. The app does not request access to any of them.
- Your advertising identifier (IDFA). Geddy does not show the App Tracking Transparency prompt, which means the app does not access your IDFA and does not track you across apps and websites owned by other companies.
- Payment details. Handled entirely by Apple.
There is exactly one advertisement in Geddy — the "Our fellows" card described in sections 2 and 8 — and it is not targeted at you in any way. We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under United States state privacy laws.
6. The Live Activity, notifications, and who can see them
Not a matter of what we collect, but the most realistic privacy exposure in an app like this one, so it belongs here.
The Live Activity. While a session runs, Geddy shows a Live Activity on your Lock Screen and in the Dynamic Island: elapsed time, accumulated IU, and how long until your burn ceiling. Anyone who can see your phone can read it, including on a locked screen, without your passcode. That is the feature working as intended — the whole point is that you can check it without unlocking while lying in the sun — but it does mean a number derived from your skin type is visible to whoever is next to you. It exists only while a session is running, and it disappears when the session ends.
Notifications. Geddy uses notifications for two things: a time-sensitive alert when you reach your burn ceiling, which is designed to break through Focus because the cost of it being silenced is a sunburn; and an optional reminder before your daily window opens. Depending on your iOS settings, their text may appear on your Lock Screen.
These are local notifications. Both are scheduled and delivered entirely by iOS on your device. We operate no push server, and no notification content ever passes through us or over the internet. The same is true of the Live Activity, which the app updates locally and never through a push channel.
One silent push, from Apple, which you never see. For completeness, because "no push at all" would no longer be exact: iCloud sync uses Apple's push service to tell the app that your other device changed something, so the new session appears without waiting for you to reopen the app. These carry no content and display nothing — they are a signal to go and check iCloud. They come from Apple's servers, not ours; we hold no device token and cannot send you a notification of any kind, silent or otherwise. If you turn sync off, they stop.
You control both. Turn notifications off in iOS Settings → Notifications → Geddy, hide previews in iOS Settings → Notifications → Show Previews, or turn off Live Activities in iOS Settings → Face ID & Passcode → Live Activities to keep them off the Lock Screen.
7. Why we are allowed to process your information
If you are in the European Economic Area, the United Kingdom, or Switzerland, the GDPR and UK GDPR require us to name a legal basis for each purpose:
| What we do | Legal basis |
|---|---|
| Run the app and provide the features you asked for | Performance of a contract |
| Sync your history to your own iCloud account so it reaches your other devices | Performance of a contract, and your consent through iOS's own iCloud controls, which you can withdraw at any time by switching Geddy off in iCloud settings |
| Use your location to compute the window and fetch UV data | Your consent, given through the iOS location permission prompt — or your own manual entry, which needs no permission |
| Read and write Health data | Your explicit consent, given through the HealthKit permission sheet (Article 9(2)(a) — health data is a special category) |
| Check on your device whether your subscription is active, so Pro features work | Performance of a contract |
| Receive aggregate App Store reports about the app's performance | Legitimate interests — keeping the app working and improving it |
| Send you the ceiling alert and window reminders | Your consent, given through the iOS notification prompt |
| Answer your emails and requests | Legitimate interests, and legal obligation for rights requests |
| Keep tax and transaction records | Legal obligation |
Health data and precise location are special-category and sensitive data under the GDPR and under United States state privacy laws. We process both only with your explicit consent, only for the purposes above, and — in the case of Health data — without ever receiving it.
Where we rely on legitimate interests, you have the right to object — see section 12. Where we rely on consent, you can withdraw it at any time in iOS Settings. Withdrawing consent does not affect processing that already happened.
If you are in Canada, we rely on your express or implied consent as permitted under PIPEDA, and on the exceptions that law provides.
8. Who else is involved
These are every third party that receives any information in connection with Geddy. Apple acts as an independent controller for weather and map requests, payments, and App Store distribution.
| Provider | What it receives | What it is for | Their policy |
|---|---|---|---|
| Apple Inc. — WeatherKit | Your coordinates | Returning the current UV index and cloud cover | apple.com/legal/privacy |
| Apple Inc. — MapKit | The place text you type in location search | Suggesting and resolving places to a coordinate | apple.com/legal/privacy |
| Apple Inc. — App Store | Payment details, Apple Account, aggregate app usage and crash reports | Distribution and subscriptions | apple.com/legal/privacy |
| Apple Inc. — iCloud (CloudKit) | Your sessions, blood results, saved locations, profile, and settings | Storing them in your own private iCloud database so they reach your other devices | apple.com/legal/privacy |
| Kickstart Exchange | That its advert card was shown and whether it was tapped; where StoreKit provides one, an Apple-signed App Transaction, which is verified and immediately discarded | Showing one other independent developer's app in Profile, and showing Geddy in theirs | exchange.kickstart.tools/privacy |
The iCloud row is the one most likely to be misread, so to be plain: Apple holds that data for you, in your account, not for us. We are the developer of the container, which gives us no ability to read what is in any user's private database. Nothing in that row is information we receive.
There is no sixth row. We use no analytics provider, no crash reporting service, no attribution SDK, and no data broker. Kickstart Exchange is the only advertising network in Geddy; it is a swap between independent developers rather than a paid placement, and what it receives is the row above and nothing more.
We may also disclose information if we are legally required to — for example in response to a valid court order — or in connection with a sale or transfer of the business, in which case this policy continues to apply to the information transferred.
9. How long we keep things
| Information | Retention |
|---|---|
| Your sessions, blood levels, saved locations, profile, and settings | On your device, and in your iCloud, until you delete them. Deleting a record in the app deletes it everywhere. Deleting the app leaves the iCloud copy in place, so a reinstall restores your history; to remove that copy as well, delete Geddy's data under iOS Settings → your name → iCloud → Manage Account Storage. We hold no copy either way. |
| Health data written by Geddy | In your Health store until you delete it there, under Apple's terms |
| Coordinates sent to WeatherKit and MapKit | Under Apple's retention terms, not ours; we never hold them |
| Subscription records | We hold none. Apple holds the transaction record under its own terms; the receipt on your device is Apple's and goes when the app does |
| Aggregate App Store reports | As long as they remain useful; they are anonymised and cannot be traced to you |
| Emails | Until the matter is resolved, or until you ask us to delete them |
10. How we protect your information
- Your sessions and blood results are stored inside the iOS application sandbox, which other apps cannot read.
- The synced copy sits in your private iCloud database, encrypted by Apple in transit and at rest, reachable only through your Apple Account. Protect it the way you protect the rest of your iCloud: a strong Apple Account password and two-factor authentication.
- Health data is protected by HealthKit's own encryption and permission model, which is stricter than the app sandbox alone.
- Everything that does leave your device travels over encrypted connections (TLS).
- The simplest protection of all: we hold no database of your history, so there is no store of your dose log or blood results for anyone to breach. Syncing does not change that — it puts a copy in your iCloud, not in ours. There is no "ours".
Two honest caveats. First, the strongest protection on your history is your device passcode — and, as section 6 explains, the Live Activity deliberately shows session figures on your Lock Screen. Second, no method of transmission or storage is completely secure, and we cannot guarantee that a determined attacker will never defeat our safeguards or those of our providers.
11. Where your information goes
We operate from Canada. Apple processes data in the United States and elsewhere.
When personal information of people in the EEA or UK is transferred outside those areas, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision — including the Commission's adequacy decision for Canada. Copies of the relevant safeguards are available on request.
12. Your privacy rights
Depending on where you live, you may have the right to:
- know what personal information we hold and get a copy of it
- correct information that is wrong
- delete your personal information
- restrict or object to how we process it, including profiling
- receive it in a portable format
- withdraw consent at any time
- not be discriminated against for exercising any of these rights
One thing that makes Geddy unusual, and that is worth understanding. Almost everything you care about — your sessions, your dose history, your blood results — is not held by us at all. It is on your device and in your own iCloud account, and neither is somewhere we can reach. That means we cannot produce it, correct it, or delete it on your behalf, because we do not have it. You exercise those rights directly and immediately:
- To see or edit your history: open the app.
- To delete a session or a blood result: delete it in the app.
- To delete everything: two steps, because there are two copies and both are yours. Delete Geddy from your iPhone, which removes the local store; then delete its iCloud data under iOS Settings → your name → iCloud → Manage Account Storage → Geddy. Until you do the second, reinstalling brings your history back — which is usually what people want, and occasionally is not.
- To stop syncing without deleting anything: switch Geddy off under iOS Settings → your name → iCloud → Saved to iCloud → See All. Your history stays on the device.
- To remove what Geddy wrote to Health: delete it in the Health app, which is separate from deleting Geddy.
- To stop location processing: revoke the permission in iOS Settings, or use a hand-set position.
We hold no subscription record to delete — see section 2. Subscription questions, refunds, and cancellations go to Apple, at reportaproblem.apple.com or in iOS Settings → your name → Subscriptions. For anything else, write to us at [email protected].
We will respond within 30 days (or 45 days for requests under United States state laws), and we will tell you if we need a permitted extension. Because we hold no account for you, we may need to ask for the Apple receipt or order ID to locate anything at all, and we will only use what you send for that purpose.
Complaints. If you are in the EEA or UK and you think we have handled your information unlawfully, you may complain to your national data protection authority or to the UK Information Commissioner's Office. In Switzerland, contact the Federal Data Protection and Information Commissioner. In Canada, the Office of the Privacy Commissioner of Canada. In Australia, the Office of the Australian Information Commissioner; in New Zealand, the Office of the Privacy Commissioner; in South Africa, the Information Regulator ([email protected]). We would rather you told us first, and we will try to put it right.
13. United States state privacy rights
If you live in California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, or another state with a comprehensive privacy law, you have the rights listed in section 12, and this section sets out the specifics those laws require.
Categories of personal information collected in the last twelve months:
| Category | Collected by us | What, specifically |
|---|---|---|
| A. Identifiers | Only if you write to us | Your email address, if you email us. Nothing else. A purchase receipt is created if you subscribe, but it stays on your device and never reaches us. |
| B. Protected classifications (age, gender, race, etc.) | On your device and in your iCloud | Your age parameterises the dose model. You type it in; it is not read from Health or from anywhere else. Stored on your device and synced to your own iCloud account. Never transmitted to us. |
| C. Commercial information | Aggregate only | Apple's sales reports tell us how many subscriptions were sold, not who holds one. Whether your subscription is active is checked on your device and never sent to us. No payment card data. |
| D. Biometric information | No | |
| E. Internet or network activity | Not by us | Geddy contains no analytics, and we do not record which screens or features you use. Kickstart Exchange is told that its own advert card was shown and whether it was tapped — unlinked to you, never sold, never shared for cross-context behavioural advertising. |
| F. Geolocation data | On your device, in your iCloud, and to Apple | Precise coordinates, used on your device, saved with each session and synced to your own iCloud, and sent to Apple WeatherKit for UV data. We never receive them. Apple's sales reports are broken down by storefront country, but as counts per country rather than as a country attached to you. |
| G. Audio, visual, or similar information | No | |
| H. Professional or employment information | No | |
| I. Education information | No | |
| J. Inferences and profiles | No | The dose estimate is computed on your device and goes no further than your own iCloud |
| K. Sensitive personal information | On your device and in your iCloud | Precise geolocation and health information — your skin type, sessions, and blood 25(OH)D results. All of it stays on your device and in your own iCloud account. We do not receive, use, or disclose any of it, and we cannot read the iCloud copy. |
We have not sold or shared personal information in the preceding twelve months, and we will not. We do not use or disclose sensitive personal information for purposes beyond those permitted under the CCPA, and we do not use it to infer characteristics about you.
Authorised agents. You may use an agent to make a request. We may ask for proof that you authorised them.
Right to appeal. If we decline your request, we will explain why. You may appeal by emailing [email protected] with "Privacy Appeal" in the subject line. We will respond within 60 days. If we deny the appeal, you may complain to your state Attorney General.
14. Children
Geddy is not directed to children. You must be at least 13 years old to use it, or 16 if you are in a country where 16 is the minimum age for consent to data processing.
We do not knowingly collect personal information from children below those ages. If you believe a child has provided us with personal information, email [email protected] and we will delete it.
Sun exposure limits for children are a matter for a parent, guardian, or doctor, not for this app. Please see section 3 of our Terms of Service.
15. Do Not Track and Global Privacy Control
Geddy is an app, not a website, and it does not track you across other companies' apps or sites — so there is nothing for a Do Not Track signal to switch off. We do not currently respond to browser DNT signals, because no uniform standard for them exists. Where we are legally required to honour an opt-out preference signal such as Global Privacy Control on our website, we will.
16. Backups, sync, and what we cannot recover
Sync exists so that losing a phone does not lose your history. With iCloud on, a new device signed into the same Apple Account downloads your sessions, blood results, and saved places, and reinstalling the app restores them. For most people, most of the time, that is the answer to "what happens if I drop my phone in the sea".
What we still cannot do. The same design that keeps us out of your dose log means we cannot get it back for you. Your history is in your iCloud, not ours, and no support request to us can reach it. If you switch sync off, delete Geddy's iCloud data, lose access to your Apple Account, or delete records from within the app, we have no copy to restore from — not because we mislaid it, but because we never had one. That is deliberate, and it is the same choice that means a breach of ours could not expose your blood results.
Two honest limits on sync as a backup:
- A deletion syncs too. Sync is not a backup; it is a mirror. Delete a session on one device and it goes from all of them. There is no undo and no trash.
- It depends on your iCloud. If you are signed out, out of iCloud storage, or have Geddy switched off in iCloud settings, nothing is being copied anywhere, and the app will not nag you about it.
So: keep an encrypted device backup switched on as well — iOS Settings → your name → iCloud → iCloud Backup, or an encrypted backup to a Mac — and keep your own record of anything, particularly lab results, that you would be sorry to lose. Questions about iCloud storage, iCloud backups, and account recovery are matters for Apple, whose terms govern that service.
The legal allocation of responsibility for data loss is set out in our Terms of Service and End User Licence Agreement.
17. Changes to this policy
We will update this policy when the app changes or the law does. The "Last updated" date at the top always reflects the current version, and it takes effect as soon as it is posted. If we make a material change — anything that meaningfully alters what we collect or what we do with it — we will tell you in the app or by notification before it takes effect.
18. How to contact us
Email: [email protected]
Tagir Aiupov, sole proprietor, British Columbia, Canada.
We read everything that comes in, and a real person replies. If you need our full registered details for a legal or regulatory purpose, ask by email and we will provide them.