Privacy Policy
Last updated: January 30, 2026
1. Introduction
Bask ("we," "our," or "us") operates the Bask mobile application (the "App"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our App.
2. Information We Collect
2.1 Personal Information You Provide
During onboarding, we collect:
- Biological Profile: Age, weight, weight unit preference
- Skin & Eye Color: Visual color selection (6 skin tones, 5 eye colors)
- Sun Reaction Assessment: Always burns / Burns then tans / Rarely burns
- Outdoor Time Assessment: Daily outdoor time ranges
- Supplementation Status: Daily / Occasionally / None
- Blood Test Baseline (Optional): 25(OH)D level (ng/mL or nmol/L), test date
- Primary Goals (Multi-select): Optimizing Vitamin D Levels, Safe Tanning & Burn Prevention, Circadian Rhythm & Better Sleep, Longevity & Natural Immunity
2.2 Automatically Collected Information
- Location Data (When In Use): We access your precise location to fetch real-time UV index and weather data for your area. Location is only used when the app is active.
- HealthKit Data (If Authorized):
- Read: "Time in Daylight" to automatically track sun exposure
- Write: Dietary vitamin D to sync your supplement intake with Apple Health
- Usage Data: We collect data about your sun exposure sessions, supplement logs, and cofactor tracking (stored locally on your device).
2.3 Third-Party Services
We integrate with:
- Apple WeatherKit: For real-time UV index, weather forecasts, and solar event data. Subject to Apple's Privacy Policy.
- RevenueCat: For in-app subscription management. Subject to RevenueCat's Privacy Policy.
- Apple HealthKit: For bidirectional sync of vitamin D and daylight data. Subject to Apple's Privacy Policy.
3. How We Use Your Information
We use your information to:
- Personalize Recommendations: Calculate vitamin D synthesis based on your skin type, age, weight, and clothing
- Provide Real-Time UV Data: Fetch accurate UV index for your location
- Track Progress: Store your sun exposure sessions, supplements, and cofactors
- Generate Reports: Create physician reports for medical appointments
- Send Notifications: Alert you before optimal D-Windows (if you opt in)
- Improve the App: Analyze aggregated, anonymized usage data to enhance features
4. Data Storage & Security
- Local Storage: All personal data is stored locally on your device using SQLite. We do not transmit your personal health data to our servers.
- Cloud Backup: If you use iCloud backup, your device data may be included in your iCloud backups (controlled by your iOS settings).
- Security Measures: We use industry-standard encryption and security practices to protect your data.
5. Data Sharing & Disclosure
We do not sell your personal data. We may share data in the following limited circumstances:
- With Your Consent: If you export a physician report, you control where it's shared.
- Service Providers: We use Apple WeatherKit and RevenueCat to provide core features (subject to their privacy policies).
- Legal Obligations: We may disclose data if required by law or to protect our rights.
6. Your Rights & Choices
- Access & Deletion: You can delete your onboarding data by using "Redo Onboarding" in Settings, which resets your profile.
- Location Permissions: You can revoke location access in iOS Settings > Privacy & Security > Location Services > Bask.
- HealthKit Permissions: You can revoke HealthKit access in iOS Settings > Privacy & Security > Health > Bask.
- Notification Permissions: You can disable notifications in iOS Settings > Notifications > Bask.
7. Children's Privacy
Bask is not intended for users under 13. We do not knowingly collect data from children under 13. If you believe we have collected data from a child, contact us at support@getbask.app.
8. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted in the App with an updated "Last Updated" date.
9. Contact Us
If you have questions about this Privacy Policy, contact us at:
Email: support@getbask.app
Website: bask.io/privacy