Privacy Policy
Effective 2 July 2026
Short version: Your health and profile data lives on your device. We don't sell it.
The only thing we send off your device is your location coordinates, to a weather service, to get your
local UV forecast.
1. Who we are
OPSIN is operated by ZHC Labs Pte Ltd (Singapore) ("OPSIN", "we", "us"). We provide a
sunlight, vitamin D and circadian light tracking app and website (theopsin.com). This policy explains
what we collect and how we handle it, consistent with Singapore's Personal Data Protection Act (PDPA)
and, where applicable, the GDPR/CCPA. Contact: hello@theopsin.com.
2. Data we process
- Profile you provide: skin type, birth year/age, wake and bed times, clothing/exposure,
supplement dose, goals, and preferences. Used to personalize your estimates. Stored locally on your device.
- Location: your approximate coordinates, used to calculate sun position and fetch your
local UV/weather forecast. Coordinates are sent to our forecast provider (Open-Meteo) for this purpose.
We do not keep a server-side history of your location.
- Activity you log: sun sessions, supplement/diet entries, light readings, streaks.
Stored locally on your device (in app storage / your browser).
- Apple Health / device health data (mobile app, optional): with your explicit
permission, we may read data such as time in daylight, sleep schedule, age, and body metrics to
personalize your plan, and write your estimated vitamin D and light-exposure sessions back to Health.
This stays on your device and within Apple Health; we do not upload it.
- Camera (mobile "mirror" feature, optional): used on-device only to estimate light
level and detect exposed skin. Images are processed on your device and are not stored or uploaded.
3. What we do NOT do
- We do not sell your personal data.
- We do not upload your health records, photos, or logs to our servers.
- We do not use your data for third-party advertising.
4. Third-party services
To provide forecasts and geocoding we send your coordinates (or a city name you search) to
Open-Meteo. Their handling of that
request is governed by their own privacy terms. If we add optional analytics or crash reporting in the
future, we will disclose it here and, where required, ask for your consent.
5. Storage & security
Because your data is stored locally, it is protected by your device's own security. If you clear the
app's data, reset the app, or uninstall it, your locally stored data is deleted. We recommend using the
in-app export before switching devices or clearing data.
6. Your choices & rights
- You can revoke location, camera, and Health permissions at any time in your device settings.
- You can export your data (Settings → Data) and delete all of it (Settings → Reset all data).
- Depending on where you live (e.g. EEA/UK GDPR, California CCPA), you may have rights to access,
correct, or delete personal data. Since we hold little to no server-side personal data, most of these
rights you can exercise directly on your device; contact us for anything else.
7. Children
OPSIN is not directed to children under 13 (or the minimum age in your country), and we do not knowingly
collect their data.
8. Changes
We may update this policy; we'll change the effective date above and, for material changes, notify you
in the app.