BronzeMaxx

BronzeMaxx Privacy Policy

Effective 16 September 2026.

Who we are and what this policy covers

BERKAY TURK, entrepreneur individuel trading as BRT Apps, is the data controller for BronzeMaxx: UV & Tan Tracker and bronzemaxx.com. Our business address is 370 rue centrale, 01200 Valserhône, France. Contact support@bronzemaxx.com or +33 6 14 12 55 74.

This policy covers our website, support communications and iOS data handling. BronzeMaxx is intended for adults aged 18 and over and has no public social feed. The app is in development. Account connections, cloud backup and the cloud coach are not currently available. The separate section below explains the policy for those planned services; it does not announce their availability.

Website and support

Our website has no account form, advertising trackers, analytics cookies or session replay. Fonts and images are served with the website rather than loaded from third-party font or image services. Cloudflare delivers and protects the site and processes connection information such as IP address, requested URL, request time, browser information and security events. These technical operations are separate from advertising or behavioural analytics.

When you email us, we receive your email address, message, any attachments you choose to send and our subsequent correspondence. Cloudflare Email Routing forwards messages to a Google Gmail inbox managed by the founder. The inbox is not a Google Workspace account. We use the information to answer your question, handle an issue or act on a privacy request. Do not send passwords, access tokens, payment-card details, unnecessary health information or private photos. The app's support-draft export does not send a message by itself.

Your iOS data and choices

Your personal archive is stored locally: profile and onboarding answers, preferences, product shelf, routines, trips and selected places, sessions, water records, notes, conversations and journal photos. Optional profile fields can include skin response, sensitivity and medication context. These may reveal health information; you can skip personal questions and use a profile without a photo.

Camera, selected photos, location, notifications and Apple Health are separate permissions. You can change them in system settings. Manual city selection remains available. Requested weather sends the selected place's coordinates to Apple WeatherKit, even when you choose the city manually. This does not send your journal to Apple WeatherKit.

With the relevant Health permissions, the app can read water intake, time in daylight, UV exposure and recorded vitamin D intake; it writes only water entries you confirm and can remove its corresponding entries. It identifies the source of displayed Health records. Revoking permission does not erase records created by other apps. Health data and photos are not used for advertising.

Photo appearance estimates and labelled cosmetic simulations run on your device. They are uncertain, do not diagnose conditions and do not overwrite your manual profile. Original files may contain GPS or other metadata. Optimized, shared and AI-transfer copies remove unnecessary metadata while preserving the orientation and colour information needed to display them. Copies you save to Apple Photos or share elsewhere are controlled separately.

Apple and RevenueCat handle purchase history, transaction and app-user identifiers, products, entitlements and renewal information for purchase verification, access and restoration. RevenueCat also supplies purchase and subscription statistics for BronzeMaxx. We do not receive your payment-card details or send your profile, Health records or journal photos to RevenueCat. A pseudonymous purchase identifier is not a guarantee of anonymity, particularly if later linked to a verified account. Purchase processing and WeatherKit are separate from the unavailable cloud services.

PostHog is not active. We do not transmit optional product-analytics events or session replay. RevenueCat purchase statistics are separate from optional behavioural analytics. Any future optional analytics will have its own notice and choice; photos, conversations, email, precise location and sensitive profile fields are excluded. Turning off that choice also discards pending optional events.

Why we process information

  • Requested functionality and purchases: we rely on performance of our contract with you, or steps you request before entering one, for information necessary to provide the requested routine, weather, purchase, restore and related support functions (GDPR Article 6(1)(b)). This does not authorise unrelated uses of optional data.
  • Security and support: our legitimate interests are to deliver a reliable website, prevent abuse and fraud, resolve general enquiries and understand aggregate purchase and subscription statistics using proportionate, limited information (Article 6(1)(f)). We balance these purposes against your rights; you may object. We do not use this basis to justify advertising profiles or optional sensitive-data sharing.
  • Optional processing: we rely on consent where required for optional photo, location, Health and cloud-context processing (Article 6(1)(a)); processing that reveals health information requires explicit consent under Article 9(2)(a). A system permission alone is not consent to unrelated processing or cloud sharing. You can refuse or withdraw optional choices without losing access to existing records, export, deletion, support or purchase restoration. Withdrawal does not invalidate processing that was lawful before it.
  • Legal obligations and claims: we process only records needed to comply with an applicable legal duty (Article 6(1)(c)) or to establish, exercise or defend a legal claim where permitted. This does not justify keeping your full journal with financial records.

How long information is kept

Your local profile, routines, notes, sessions and conversations remain until you delete them. Subscription expiry or 12 months of inactivity does not automatically erase them. Normally deleted photos remain in Recently Deleted for 7 days; you can delete them permanently sooner. You can erase guest data without creating an account. We cannot erase copies you exported or saved in another service.

We delete closed support conversations and their attachments 30 days after closure. The procedure covers incoming and outgoing copies, saved attachments and permanent removal from Trash. Open requests remain while needed to resolve them; an accepted erasure request is not delayed merely to complete the ordinary support period. This is our mailbox-handling policy, not an automatic Gmail deletion schedule. Google's infrastructure and legally required copies follow its own retention processes.

Minimal purchase records are kept separately from journal content only while needed to maintain or restore a valid entitlement, reconcile a payment or refund, handle a dispute, or meet an applicable record-keeping duty. Relevant fields include transaction/product identifiers, app-user or account linkage, entitlement status and dates, refund/revocation status and the evidence needed for that purpose. We remove unnecessary linkage and records when those purposes and applicable claim or legal periods end. Apple and RevenueCat retain their own transaction and service records under their applicable policies and obligations.

Technical information is retained according to its purpose: delivery and short-term troubleshooting, investigation of a specific security incident, or a binding legal requirement. Our operational target for content-free technical logs is no more than 30 days unless a specific incident or legal obligation requires a justified extension. Provider-managed logs and recovery copies follow the provider's service-specific retention cycles; this target is not a promise that every provider uses the same period. We do not use technical logs to archive journal or photo content.

Providers and international processing

Apple supplies platform, weather and purchase services; RevenueCat supplies purchase verification and subscription statistics; Cloudflare hosts and protects the website and routes support email; Google stores support correspondence in Gmail. Access is limited to what is needed for the relevant service. See Apple Privacy, RevenueCat Privacy, Cloudflare Privacy and Google Privacy.

Providers can process information outside France and the European Economic Area. A European storage location does not make all support, logs and subprocessors European. Google's published safeguards include adequacy decisions, the EU–US Data Privacy Framework for covered recipients and standard contractual clauses where required. RevenueCat and Cloudflare describe standard contractual clauses and other applicable safeguards in their data-processing terms. You can contact us for information about the safeguards relevant to your data. Google transfer frameworks, RevenueCat processing terms, Cloudflare processing terms.

Planned optional cloud services — not currently available

The planned identity and record provider is Supabase, with its primary database configured in Paris, France. The planned photo store is a private Cloudflare R2 bucket restricted to the EU jurisdiction. Google Gemini is the planned cloud-coach provider. Before these services become available, their actual processing details will be reflected in this policy and the relevant in-app choices. Their setup does not make them available now or guarantee that all processing remains in the EU.

Backup will require a separate choice, showing which records and photos are selected. Creating or linking an account will not enable backup or AI sharing. Photo backup will offer optimized high-quality or original files. The allowance will be 100,000,000 bytes during an eligible trial and 1,000,000,000 bytes with paid access, including lifetime. Previews and trash count; recovery copies do not count twice. Full storage stops new uploads rather than deleting existing records.

For each cloud-coach request, you will choose the text and context sent: city name and time zone, weather, routine, product shelf and selected plan or trip. Separate profile/history choices can add skin response, sensitivity, medication context and up to three recent sessions. City coordinates are not included in that structured coach context; text you enter may still contain personal information. Photo requests will use only the one or two photos selected and authorised for that request. Backup permission will not authorise AI photo processing. Suggested actions will require your confirmation.

The planned coach allowances are 5 completed replies per eligible trial, 30 per paid weekly period, 120 per usage month for monthly/annual access and 60 per usage month for lifetime. Unused allowances do not roll over; restoring, linking or changing a plan does not reset consumption. A completed reply delivered in the app uses one unit, including one or two selected photos; errors, cancellation and undelivered replies do not. Local guidance and on-device photo work use no cloud allowance.

These future operational policies are not guarantees for a service offered today: our temporary AI copies will be removed after response/error, with a target of 24 hours for interrupted work; accepted full-account deletion will target active service data within 24 hours and recovery copies within 30 days. Google's paid Gemini terms exclude model/product improvement use of prompts and responses but allow limited security/abuse retention and international processing. No-training does not mean zero retention, and removing our copy does not instantly erase Google's copy. Gemini data terms, Gemini retention.

After trial or paid entitlement actually ends, the planned cloud-photo policy allows reading, downloading and deletion for 30 days, stops new uploads and warns 7 days and 1 day before removal. Renewed access cancels scheduled expiry cleanup. Local copies remain. Sign-out, cloud-archive deletion, local deletion and full-account deletion are separate actions; cloud-archive deletion disables automatic backup. Full-account deletion will offer export and subscription management, brief identity verification and final confirmation, without a mandatory support conversation, survey or waiting period. Failed or offline requests will not be labelled complete; accepted deletion stops writes and sync, and deletion records prevent older devices restoring erased content. Deleting an account will not cancel an Apple subscription, and restoring a purchase will not restore permanently deleted journal content.

Your rights and contact

Contact support@bronzemaxx.com to request access, correction, deletion, restriction or portability where applicable, withdraw consent, or object to processing based on legitimate interests. In-app viewing, export and deletion of existing records do not require another purchase. We do not make solely automated decisions that produce legal or similarly significant effects about you.

We respond without undue delay and normally within one month of receiving a rights request. For complex or numerous requests, the GDPR permits up to two additional months; we explain the extension within the first month. We request additional identity information only if reasonably necessary and normally handle requests free of charge, subject to the GDPR's limited exceptions. You may complain to the CNIL or another competent supervisory authority.

We update this policy when our services or processing change and show the effective date above. A material new use that requires your consent will have a separate choice before it begins.