Who we are
Seize Light (Latin: Carpe Lucem) is an iPhone and Apple Watch app published by Sebastian Totte. It's a motivational and educational companion for daylight, vitamin D, and your circadian rhythm — it helps you find the right light at the right time. It is not a medical device and does not diagnose, treat, or monitor any condition.
This policy describes how the Seize Light app and this website handle information. It's written to be honest and specific rather than to cover every theoretical case with boilerplate — if a practice isn't described here, it's because the app doesn't do it.
The one-paragraph data flow
When you open the app, it asks iOS for your approximate location and computes the sun's real path for your spot on your device. It sends that coarse location to Apple Weather (WeatherKit) — by way of a small relay we run, which forwards the request and keeps no record of it (see Location and Apple Weather) — to fetch the UV index and cloud cover. If you choose to connect Apple Health, it reads your Time in Daylight to score your day and build a streak. All of the vitamin-D and solar math runs locally. Your daily log is stored on your device and, if you're signed into iCloud, synced through your own private iCloud account. The one thing outside this flow is advertising: an occasional ad loads through the CloudX mediation platform when you return to the app (see Advertising below), and it never receives any of the data above.
What the app reads, and where it goes
Here is everything the app touches, exactly as declared in its App Store privacy report — the two things the app itself uses, and the advertising data handled by our ad partners.
| Data | Why | Leaves your device? |
|---|---|---|
| Time in Daylight from Apple Health |
Score your daily light, draw your 90-day trend, and build a streak. | No. Read-only, used and stored on-device. Never written back to Health. |
| Coarse location city-scale, ~10 km |
Place the sun's position and look up the local UV index and cloud cover. | Yes — to Apple, via our relay. Used only to fetch the forecast. The relay keeps no logs and no record of it. How this works. |
| Your profile & history skin type, age, goals, day logs |
Tailor the vitamin-D estimates and remember your daily progress. | No third party. On your device; synced through your own iCloud if signed in. |
| Advertising & device identifiers IDFA only if you allow it; IP-based coarse region |
Show and measure the free app's ads (CloudX mediation). | Yes — to our ad partners. Ad-related signals only. Never your Health data, Weather location, profile, or history. |
Apple Health (Time in Daylight)
If you tap Connect Time in Daylight, the app requests read-only access to a single Apple Health type — Time in Daylight, the minutes of bright outdoor light your Apple Watch records. It reads today's total and a trailing 90-day daily series to draw your trends and score your day.
- The app never writes anything to Apple Health. It requests no write permission at all.
- It only asks for Health access when you tap the button in Settings (or, later, during onboarding) — never silently on launch.
- Your Health data is used to compute your Light Score and trends on your device. It is not sent to us, to Apple Weather, or to any third party.
- If you have no Apple Watch, or you decline Health access, the app still works — that data is simply absent and is never treated as a zero or held against you.
Apple Health data is among the most sensitive on your phone, which is why Apple keeps it gated behind your explicit permission. You can review or revoke Seize Light's access any time in iOS Settings → Privacy & Security → Health, or in the Health app under Sharing.
Location and Apple Weather
To place the sun and read the sky, the app needs to know roughly where you are. It deliberately asks for the least precise location iOS offers:
- It requests reduced (coarse) accuracy — roughly city-scale, on the order of a kilometre — not your precise GPS pin.
- It uses location only while you're using the app (when-in-use). It never asks for "Always" or background location.
- For the weather lookup, your coordinates are rounded to about 0.1° (≈10 km) so the same neighbourhood reuses the same cached forecast.
- That rounded location is sent to Apple Weather (WeatherKit) to retrieve the UV index and cloud cover. Apart from the ad requests described under Advertising, it is the only data the app sends off your device. The ad requests never include it.
- The request reaches Apple through a small relay we operate — see below. It carries the rounded coordinates and nothing else: no name, no account, no device or advertising identifier, nothing from Apple Health, and no way to tie the request to you.
- A city name is shown for context; the app derives it on-device by reverse-geocoding through Apple's services.
Why the request goes through us
Apple offers two ways to reach Apple Weather. The one that runs entirely on your phone stopped working for this app — Apple's on-device weather service refuses to issue it a token, which is why UV readings were unavailable for a period. So the app now uses Apple's web version of the same service, and that method requires a signing key that must be kept on a server rather than shipped inside an app. Apple's own guidance is explicit about this: "Never distribute your private key … create an authenticated service to create and sign your own tokens."
That service is a single small function on Cloudflare that does exactly one thing: attach our key to the request, pass the rounded coordinates to Apple, and hand back the UV and cloud figures. Specifically, it:
- keeps no logs and no database. Your coordinates are never written down — not to a log line, not to storage. Request logging is switched off deliberately, precisely because a log line would record the coordinates in the request. Nothing about a request survives it.
- never receives an identifier. There is no account, cookie, login, or device ID involved, so there is nothing to attach a request to.
- rounds again on arrival, so even a mis-sent precise coordinate is discarded before it goes anywhere.
- caches by area, not by person. One lookup covers roughly a 10 km square for about 45 minutes, so everyone nearby shares a single result. In practice this means fewer requests reach Apple than when each phone asked separately.
The relay runs on Cloudflare, which hosts it for us and necessarily handles the request in transit as our infrastructure provider, under its own privacy policy. As with any internet request, your device's IP address is visible to it in the moment of connecting; we neither record it nor use it for anything.
Being straightforward about the trade-off: your coarse location now passes through infrastructure we control before it reaches Apple, where previously it went to Apple directly. We think the design above makes that a fair exchange for a working feature — no record is kept and nothing identifies you — but it is a real change, and this page would be misleading if it did not say so.
Apple Weather is provided by Apple under its own terms; Apple states it does not associate WeatherKit location requests with your Apple Account or use them to build a profile of you. Weather attribution and Apple's data policy link are shown in the app wherever weather data appears. The UV index is a forecast, never a sensor reading — your phone has no UV sensor.
You can change or revoke location access any time in iOS Settings → Privacy & Security → Location Services → Seize Light, including toggling Precise Location off. With location off, the app falls back to sun-position guidance and simply can't show the UV-based windows.
What stays on your device
The parts of the app that feel the most personal are the parts that never travel:
- All the science runs locally. The sun's position, your morning-light and vitamin-D windows, the live vitamin-D estimate, and the sunburn countdown are all computed on your device from public astronomy and the weather forecast.
- Your profile is local. Settings such as your skin type, age, wake time, daylight goal, and units live in your device's app storage and are used only to personalise the estimates.
- Your daily history is local first. Each day's daylight minutes and your self-reported "morning light" and "evening wind-down" taps are saved on your device.
iCloud sync — your own private account
So your history and streak follow you between your own iPhone, iPad, and Apple Watch, the app stores your daily logs in CloudKit — Apple's private iCloud database tied to your Apple Account.
- This sync runs entirely within your private iCloud. It never touches any system of ours — we cannot see, query, or receive this data. (The one service we do run, the weather relay described under Location and Apple Weather, has no part in this and never sees any of it.)
- If you're not signed into iCloud, the app falls back to a local-only store. Your history still works on that device; it just doesn't sync.
- Your iCloud data is governed by Apple's iCloud terms and your iCloud security settings.
No accounts, no data brokers — in the app
To be clear about what the Seize Light app does and doesn't do (this website is a little different — see This website below):
- No accounts. There's no sign-up, no login, no password, and no user profile held by us.
- Third-party code only for the ads. The app is built on Apple's own frameworks (HealthKit, WeatherKit, CoreLocation, CloudKit). The only third-party SDKs are the advertising ones — CloudX, which shows the ads, and InMobi CMP, which asks your consent — used solely as described in Advertising below.
- No analytics SDK in the app. We don't embed an analytics or telemetry SDK and don't collect usage statistics about you for ourselves. The ad partners receive only the ad-related signals listed under Advertising — not app-usage analytics for us.
- Tracking is your choice. Ads may use the advertising identifier (IDFA) only if you allow it through Apple's App Tracking Transparency prompt. Decline, and ads are non-personalized and no IDFA is used. Nothing else in the app tracks you across apps or websites.
- No data brokers, no selling by us. We don't sell or rent your data. The only thing any system of ours receives is the rounded location passed to Apple Weather (see Location and Apple Weather), which is never logged or stored. Ad-related data goes to our advertising partners under their own policies — never to data brokers — and in US states with an opt-out right, Privacy choices in the app's Settings lets you opt out of it being shared for targeted advertising.
- Your Health and location stay private. Connecting Health and sending a coarse location to Apple Weather work exactly as described above, and the advertising described here never receives that data.
Diagnostic messages the app logs (for example, a failed weather fetch) are written only to your device's local system log to help with on-device troubleshooting. They aren't transmitted to us.
Advertising
Seize Light is free, and it's supported by ads: an occasional full-screen ad shown when you come back to the app — never on a cold launch, never during onboarding, and at most one every few minutes. The ads are sourced from advertising networks (for example, Meta Audience Network) through the CloudX mediation platform. This is the one third-party corner of the app, and it's walled off from everything personal described above — the ads never receive your Apple Health data, your Apple Weather location, your profile, or your on-device history.
Consent comes first
Before any ad loads, the app runs a privacy gate:
- In the EEA, the UK, and other regions where GDPR-style consent applies, the app shows a consent form from InMobi CMP, an IAB-certified consent management platform, so you can accept or manage how ads use your data. You can change or withdraw your consent any time from Settings → Privacy → "Privacy choices" inside the app — withdrawing doesn't remove ads, it makes them non-personalized.
- In US states with privacy laws, the same Settings → Privacy → "Privacy choices" screen lets you opt out of the sale or sharing of your personal information for targeted advertising.
- Everywhere, iOS shows Apple's App Tracking Transparency prompt before ads may use your device's advertising identifier (IDFA). If you decline — or never respond — the IDFA is not used and ads are non-personalized. You can change your answer any time in iOS Settings → Privacy & Security → Tracking.
What the ad partners may process
To serve and measure ads, CloudX and the winning ad network may process:
- Device and advertising identifiers — the IDFA only if you allowed tracking, plus the networks' own ad and device identifiers.
- Approximate location inferred from your IP address — roughly country or region. The app never shares its own coarse Weather location, or any GPS data, with ad partners.
- Ad and device data — that an ad was requested, shown, or tapped, and basic device and OS information needed to deliver it.
Each partner handles this data under its own privacy policy — see CloudX, InMobi, and the ad networks' policies (for example, Meta Audience Network's, linked above). It is kept separate from Apple Weather and from the on-device science: the ad partners never see your Health data, your coarse Weather location, your profile, or your daily history. Your related rights are covered under Your rights below.
Notifications
If you allow notifications, the app schedules local reminders — sunrise-anchored nudges for morning light, the vitamin-D window, and evening wind-down. These are computed on your device and delivered by iOS. We don't run a push server and don't send you remote notifications.
This website
carpe-lucem.com is a simple marketing and information site. It uses Google Analytics (GA4) to understand aggregate traffic — for example, how many people visit and which pages they read — so we can improve the site. It doesn't set advertising cookies and isn't used to build an advertising profile of you. The "Get notified" and "Support" links open your email app so you can write to us if you choose — that's the only information you'd share directly, and only because you typed it.
This is separate from the app: the Google tag runs only on carpe-lucem.com in your browser. It never runs inside the Seize Light app, and it has no access to your Health data, location, or on-device app data described elsewhere in this policy.
Children
Seize Light is a general-audience wellness and education app and is not directed to children under 13 (or the equivalent age in your region). We don't knowingly collect personal information from children. Because the app keeps your data on your own device and your own iCloud and has no accounts, there's no profile for a child or anyone else to create with us. The app is not directed to children, and its ads are served as general-audience, non-child-directed inventory. A parent or guardian who has questions can reach us using the contact below.
Data retention and deletion
Because the app stores nothing about you on our side, retention and deletion are in your hands:
- On your device: deleting the app removes its local data — your profile, settings, and on-device history — from that device.
- In your iCloud: your synced day logs live in your private iCloud. You can remove the app's iCloud data in iOS Settings → your name → iCloud → Manage Account Storage (or the equivalent), or by signing out of iCloud.
- Apple Health: revoking the app's Health access stops further reads; your Time-in-Daylight data itself belongs to you in Apple Health and is managed there.
- Caches: the app keeps a short-lived weather snapshot (about 45 minutes) on your device to stay within Apple Weather's limits; it's overwritten as conditions update and removed when you delete the app.
- Advertising data: the ad-related data described under Advertising is held by our ad partners under their own policies. Withdrawing consent or declining tracking stops further personalized use; the partners' privacy policies linked above describe their retention and deletion practices.
We hold no store of your app data, so there is nothing on our side to delete. The weather relay is the only system we run that your device contacts, and because it writes nothing down, a request leaves nothing behind to erase. The one record we can delete for you is the website analytics described under This website — Your rights sets out how to ask. If you ever want to confirm any of this, the contact below reaches a real person.
Your rights
Depending on where you live, privacy laws such as the EU/UK GDPR and the California CCPA/CPRA give you rights over your personal data. Seize Light is designed so you can exercise those rights directly: your data is on your device and in your own iCloud, you control it through iOS, and we hold no copy to access, sell, or withhold.
The rights you have
Under the UK and EU GDPR, they are:
- Access — to be told whether your personal data is being processed, and to receive a copy of it.
- Rectification — to have inaccurate personal data corrected, and incomplete data completed.
- Erasure — to have your personal data deleted.
- Restriction — to have processing paused rather than deleted while a question about its accuracy or its grounds is settled.
- Objection — to object to processing, including to direct marketing and the profiling that goes with it.
- Portability — to receive the personal data you provided in a portable, machine-readable form, or have it passed on.
- Complaint — to complain to a data protection supervisory authority. In the UK that is the Information Commissioner's Office (ICO), ico.org.uk; in the EEA it is your national authority. You can go to them directly — you don't have to come to us first.
Rights under the California CCPA/CPRA run in parallel: to know what is collected, to delete it, to correct it, to opt out of its sale or sharing, and not to be treated differently for exercising any of them. The app is free either way; the only thing your choice changes is whether ads are personalized.
How to exercise them
For everything the app itself holds, your own device is the fastest route, because that's where the data is — Data retention and deletion above sets out exactly how to review, keep, or remove each piece of it through iOS, Apple Health, and iCloud. There is no copy of your app data on our side to access, correct, restrict, or export: we run no accounts and no database, and the weather relay writes nothing down.
There are two exceptions. The first is the ad-related data described under Advertising. In the EEA and UK, personalized ads rest on your consent, which you can withdraw any time via Settings → Privacy → "Privacy choices" in the app; in US states with an opt-out right, the same screen lets you opt out of your data being sold or shared for targeted advertising. For access, correction, or deletion of data held by the ad partners themselves, their privacy policies linked above apply, and the request goes to them.
The second is the website analytics described under This website. Google Analytics gives your browser a client ID and derives an approximate location from your IP address; even with no name attached, that counts as personal data under the UK and EU GDPR, and rights apply to it. It concerns carpe-lucem.com only — never the app. To stop it, block the Google tag in your browser or install Google's Analytics opt-out add-on; clearing this site's cookies discards the client ID your browser has been using, and a fresh one starts if you return. To see or erase what has already been recorded, write to us with that client ID — it's the value stored in the _ga cookie for carpe-lucem.com — and we'll look it up in Google Analytics and delete it. That ID is the only handle we have; without it there is nothing we can match to you.
To exercise any of these rights with us, or to ask a person what we hold, write to [email protected] — the same address as Contact below. Tell us which right you mean, and we'll reply within one month — the deadline the GDPR sets, which it also lets us extend by up to two further months where a request is complex or you've made several. If that ever applied, we'd tell you inside the first month and say why.
Outside those two exceptions, because there are no accounts and nothing on our side is tied to you, we usually can't match a request to a person. That isn't a refusal — it's the same answer as most of this page: there's nothing held about you here to produce, correct, or erase. We'll say so plainly rather than ask you for identity documents we'd have no use for.
Wellness, not medical advice
Seize Light is a wellness and educational tool — not medical advice or a medical device. UV and vitamin-D figures are estimates, not measurements: your phone has no UV sensor and the app does not measure vitamin D in your blood.
Follow local sun-safety guidance, don't burn, protect your skin at UV 3 and above, and consult a healthcare professional before making decisions about sun exposure, supplements, or your health.
Changes to this policy
If we change how the app handles data, we'll update this page and revise the effective date. This version reflects three changes: the addition of advertising via the CloudX mediation platform (see Advertising), the weather relay that now carries your coarse location to Apple (see Location and Apple Weather), and a fuller account of your rights and of retention and deletion — the rights the GDPR gives you set out one by one, the route for each, and the website analytics named as data those rights cover (see Your rights and Data retention and deletion). If a future version ever introduced a materially different practice — for example a new third-party service, or any feature that sent more of your data off your device — we'd describe it here plainly and update the App Store privacy labels before shipping it.
Contact
Questions about your privacy, or this policy? We read every message.