The short version
- Saved photos and descriptions stay encrypted on your device.
- Device analysis is the default and the offline model is included with the app.
- When Sunny AI Cloud is selected, the photo you choose is sent for analysis with your explicit consent.
- Sunny is not a medical device and does not diagnose.
01
What Sunny stores, and where
Photos you capture or choose, the model’s six-field description, reference-based size estimates, active photo-check progress, and PDF reports are stored in the app’s private storage on your device.
This data, ABCDE responses, and reminder metadata are encrypted at rest using a key protected by Android Keystore—hardware-backed where the device supports it. Sunny uses AES-GCM for files and preferences and SQLCipher for its database.
An optional app-lock PIN is stored only as a strong salted verifier, never in plain text, and additionally wraps the data-encryption key. Repeated incorrect attempts are rate-limited using boot-aware monotonic time.
02
What leaves your device
Device mode
Device analysis is the default. The offline model is delivered as part of the Google Play installation and prepared in private app storage; scan photos and descriptions do not leave your phone for inference.
Sunny AI Cloud
When you select cloud analysis and consent to processing, the chosen photo is sent to Sunny’s configured inference server. The generated visual description is returned to the app. Sunny does not claim that its Android client can independently enforce server-side retention or logging; those controls are operated and documented separately.
Optional model-improvement contribution
Contribution is off by default and requires a separate, versioned opt-in. When enabled, Sunny may send the photo, body area, model output, corrected output, device model, and app version to the configured contribution endpoint. Turning it off prevents future submissions.
Anonymous quota accounting
Sunny creates a random installation identifier that contains no hardware, advertising, account, or user identifier. The access service stores an opaque one-way derivative plus daily and monthly request counts. Inactive counters are deleted after 62 days. Reinstalling creates a different identifier.
Sharing and backup
When you choose Share, Sunny decrypts a report into an operating-system pipe for the destination you select and does not leave a plaintext sharing copy in its cache. Full backups are streamed into a password-derived AES-256-GCM archive and leave the app only when you choose a destination.
03
Permissions
04
No advertising tracking
Sunny contains no advertising SDKs and no third-party analytics SDKs. The random installation identifier is used only for abuse-resistant quota accounting.
This website
This website uses no advertising pixels, third-party analytics, or advertising cookies. Standard infrastructure logs may temporarily record technical request information such as IP address, browser type, requested path, and timestamp for security and reliability.
Sunny waitlist
If you join the waitlist, the email address you provide and its subscription status are sent to Brevo, Sunny’s email-list provider, so Sunny can send product updates, testing openings, and launch news. Sunny does not request health information through the waitlist. Your email is retained while you remain subscribed; every marketing message provides an unsubscribe option. You can also request access or deletion by contacting Sunny.
05
Medical disclaimer
Sunny is a tracking tool only. It provides visual descriptions, not medical diagnoses or advice. Sunny is not a medical device and does not diagnose, treat, cure, or prevent any medical condition. Always consult a qualified healthcare professional for medical advice, diagnosis, or treatment.
06
Model and dataset notices
Sunny AI Cloud and Sunny Offline use modified SmolVLM 500M models derived from HuggingFaceTB/SmolVLM-500M-Instruct under the Apache License 2.0. Sunny fine-tuned the model, merged the adapter, converted the result to GGUF, and quantized it for deployment. Hugging Face does not endorse Sunny.
The fine-tune used 2,292 accepted smartphone images from PAD-UFES-20: Pacheco et al., doi:10.17632/zr7vgbcyr2.1, licensed under CC BY 4.0. Images were resized and normalized, non-diagnostic appearance descriptions were generated, records were split by lesion, and model weights were trained and quantized. The dataset creators and institutions do not endorse Sunny.
07
Your control
Deleting a scan removes its photos, measurements, and reminders from the device. Delete all local data removes scans, photos, measurements, private notes, ABCDE answers, reminders, active photo-check progress, reports, and encrypted backup archives while leaving the installed model and app preferences.
Uninstalling removes app data unless you explicitly choose an Android option that retains fragile user data. Deleting app data does not automatically delete a contribution that was previously submitted; contribution retention and deletion procedures must be documented before that optional beta capability is offered externally.
08
Contact
For privacy questions, waitlist access or deletion requests, deletion requests concerning submitted beta contributions, or concerns about this policy, contact:
aditya@adityaps.workSunny · sunny.adityaps.work