Privacy Policy
Spectra Tone Kit
This policy explains how this application handles information and how to contact us about privacy.
Information we process
Spectra Tone Kit stores the light sources in your current scene, named recipes, experiment history, challenge results, language and reminder choices, and pending sync changes on your device in its local SQLite database. It creates a random installation secret in the iOS Keychain when synchronization is used. If you turn on synchronization, the app sends your recipes, scene parameters, experiment dates, result colors and color-difference scores, along with the installation secret used to authorize requests, to our service. The service stores recipes and history in PostgreSQL and stores only a SHA-256 hash of the secret with those records. Requests to the service also expose ordinary connection information such as IP address, request time and route to Railway infrastructure. We do not ask for a name, account, email address, precise location or contacts.
How we use information
The app uses scene settings to display additive light mixing, restore your work, calculate color matches and daily streaks, and let you save and edit recipes. Optional synchronization keeps recipes and history for this installation on the service and retries queued changes after a connection returns. A daily reminder, if enabled, is scheduled locally on the device. The public website serves product and privacy information. Service request information is processed to deliver and operate the API.
Service providers and sharing
Optional synchronized records and API requests are hosted by Railway and its underlying infrastructure as our hosting provider; Railway may process connection and operational log data to provide that service. The app uses Apple's iOS storage, Keychain and local notification facilities. We do not include advertising, analytics, social sign-in, email delivery or mapping SDKs, and we do not sell user data. We have not configured another recipient of recipes or history.
Data retention
Local scenes, recipes, history and pending changes remain until you delete them or remove the app, The local SQLite database is marked excluded from iOS device backups. The Keychain secret is restricted to this device and is removed by Delete all installation data; iOS may otherwise retain Keychain items according to its own lifecycle. Synchronized recipes and history remain in the service until individually deleted or Delete all installation data succeeds online. The live PostgreSQL rows are deleted by those actions. Railway may retain infrastructure logs and provider-managed database backups under its own operating policies; we do not claim a fixed duration or immediate removal from those copies because that period is not configured or verified in this product.
Deleting your information
You can delete individual recipes and history entries in the app. Settings offers Clear history and Delete all installation data with confirmation. If synchronization has ever been enabled on this installation, full deletion requires a server connection so the app can delete the installation's server records before clearing local records, pending changes and the Keychain secret. If the server is unavailable, the app keeps the data and shows an error rather than falsely confirming remote deletion. Removing the app deletes its local database under iOS behavior but does not by itself delete synchronized server records; the device-only installation secret cannot be recovered on another device. The local SQLite database is marked excluded from iOS backups, so app data is not expected to migrate with a device restore. Contact CaiusVanehurst2000@icloud.com about deletion questions or inaccessible synchronized records, understanding that without the installation secret we may be unable to identify which private records are yours.
Permissions and your choices
The core light mixer, recipes and challenges require no device permission. If you enable the optional daily reminder, iOS asks for local notification permission; the reminder is scheduled on the device and can be disabled in the app or iOS Settings. You can withdraw notification permission in iOS Settings. The app does not request location, camera, photos, microphone or contacts permission.
Your privacy rights
You can view, edit and delete your local recipes and history in the app, disable optional synchronization, and request information or raise a privacy concern by emailing CaiusVanehurst2000@icloud.com. We may need information sufficient to identify a particular installation's records before acting on a request; there is no user account or cross-device recovery. Rights under applicable law may also apply. The contact address is for privacy inquiries only and is not an in-app messaging service.
Security
The app uses HTTPS for service requests and a randomly generated installation-specific secret stored in the iOS Keychain. Private API routes require that secret; the service stores its SHA-256 hash rather than the plain secret and scopes recipe and history queries to the hash. Local data is stored in the app's SQLite container. Access to Railway and PostgreSQL depends on the hosting platform's controls. No system can guarantee absolute security, and losing the device-only secret prevents recovery of its synchronized data through the app.
Children’s privacy
Spectra Tone Kit is designed for adults interested in lighting design and is not directed to children. We do not provide a child account or knowingly request children's personal information. If you believe a child has used the service in a way that raises a privacy concern, contact CaiusVanehurst2000@icloud.com.
Changes to this policy
We may revise this policy when app behavior, hosting or data practices change. The current version and effective date will appear on this page. Material changes will be reflected here before or when the changed practice begins. Privacy questions can be sent to CaiusVanehurst2000@icloud.com.