Privacy Policy
Last updated: January 10, 2026
Overview
Kyle Seneker ("we," "us," or "our") operates the Sunroof mobile application ("Service"). This Privacy Policy describes how we collect, use, disclose, and safeguard your personal information when you use our Service. By accessing or using the Service, you consent to the collection and use of your information in accordance with this Privacy Policy. If you do not agree with our policies and practices, do not use the Service.
Children's Privacy
Sunroof is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@getsunroof.com and we will promptly delete such information.
Information We Collect
Photos & Videos: Media you capture is stored securely until your chosen unlock date.
Audio Memos: Voice recordings you create (up to 5 minutes each).
Text Notes: Written notes and reflections you add to your journeys.
Journey Data: Journey names, destinations, emojis, unlock dates, and cover images.
Account Info: Email address and profile data from Google OAuth or email sign-in.
Location & Weather
With your permission, we capture location and weather data with each memory to enrich your journey experience. This data is:
Only collected when you actively capture a memory
Stored with your memory and locked until the unlock date
Never shared with third parties for advertising
Controllable via your device settings and in-app preferences
AI Features
Our AI Recap feature generates journey summaries. Here's how we protect your privacy:
Only text notes are sent to AI—never photos, videos, or audio
AI processing is done via OpenAI's API
Recaps are saved to your account and can be deleted anytime
You choose when to generate a recap—it's never automatic
Push Notifications
With your permission, we send push notifications to remind you when journeys unlock and for daily capture reminders. We collect your device token to deliver these notifications. You can disable notifications at any time in your device settings or within the app.
Third-Party Services
We share data with the following third-party services to operate Sunroof:
Supabase (database, authentication, file storage) — stores your account and memory data
Sentry (error tracking, performance monitoring) — receives crash reports, app performance data, and error logs to help us improve stability
OpenAI (AI recaps) — receives only text notes, never photos or audio
OpenWeather (weather data) — receives your location coordinates
Unsplash (cover images) — receives search queries for destinations
We do not sell your personal information. We do not share your data with advertisers or data brokers.
Data Storage & Security
Your memories are stored securely using industry-standard practices:
Backend powered by Supabase with SOC 2 Type II compliance
Authentication tokens stored in secure device keychain
Media files stored in encrypted cloud storage
Offline captures are stored locally until synced
International Data Transfers
Your data may be transferred to and processed in countries other than your own, including the United States where our servers and third-party service providers are located. By using Sunroof, you consent to the transfer of your information to these countries, which may have different data protection laws than your jurisdiction.
Data Retention
We retain your data for as long as your account is active. When you delete your account, all your data including journeys, memories, and personal information is permanently deleted within 30 days. Backup copies may persist for up to 90 days before complete removal.
Your Rights
Access all your personal data through the app
Delete your account and all associated data
Export your unlocked memories
Control location and weather capture in settings
Opt out of AI features entirely
California Privacy Rights
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
Right to know what personal information we collect and how it is used
Right to delete your personal information
Right to opt-out of the sale of personal information (we do not sell your data)
Right to non-discrimination for exercising your privacy rights
To exercise these rights, contact us at privacy@getsunroof.com. We will respond to verifiable consumer requests within 45 days.
Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by posting the updated policy within the Service and updating the "Last updated" date above. We encourage you to review this Privacy Policy periodically for any changes. Your continued use of the Service after the posting of changes constitutes your acceptance of such changes.
Contact Us
If you have questions about this Privacy Policy or want to exercise your data rights, please contact us at privacy@getsunroof.com