Sunpath
  • Home
  • Terms

Privacy Policy

Last updated: 8 March 2026

Sunpath ("we", "us", "our") is operated by Nick Babenko trading as Sunpath. This policy explains what personal data we collect, why we collect it, and your rights under UK GDPR.

1. Who We Are

Data controller: Nick Babenko trading as Sunpath
Contact: privacy@sunpath.energy

2. What We Collect

CategoryExamplesWhy
Account dataName, email address, bcrypt-hashed passwordTo create and manage your account
Energy readingsPV power, battery SoC, grid power, EV power (5-min intervals)To display live dashboards, history, and insights
Third-party credentialsSunsynk, Hypervolt, Octopus Energy login detailsTo poll your devices and tariff on your behalf — encrypted at rest with AES-256-GCM
System profileBattery capacity, inverter max output, solar panel orientationTo run optimisation simulations
PreferencesPush notification settingsTo send the alerts you've opted into
Device tokensAPNs push tokenTo deliver push notifications via Apple
Usage eventsAnonymous feature event names (e.g. "tariff_compare_run")To understand which features are used; no PII attached
Solar forecastsForecast data fetched from Solcast using your panel locationTo optimise battery scheduling

We do not collect or store:

  • Precise geolocation beyond the approximate location you provide for solar forecasting
  • Advertising identifiers or cross-site tracking data
  • Payment information (billing handled by Apple)

3. Legal Basis

Processing activityLegal basis
Providing the core app functionalityContract performance (Article 6(1)(b)) — necessary to deliver the service you signed up for
Analytics event trackingLegitimate interests (Article 6(1)(f)) — to improve the app; events are non-identifiable
Sending push notificationsConsent (Article 6(1)(a)) — requested at app launch; you can withdraw in iOS Settings
Security loggingLegitimate interests (Article 6(1)(f)) — to detect and prevent abuse

4. How We Store and Protect Your Data

  • All data is stored on self-hosted infrastructure (Hetzner VPS, UK-accessible). We do not use AWS, Google Cloud, or Azure for user data.
  • Credentials are encrypted with AES-256-GCM before storage. The encryption key is held separately from the database.
  • Passwords are hashed with bcrypt (cost factor 12). We never store plaintext passwords.
  • All API traffic uses TLS 1.2+ in transit.
  • The iOS app stores JWT tokens in the iOS Keychain (not UserDefaults).

5. Third-Party Data Processors

We share data with the following processors, strictly to deliver the service:

ProcessorPurposeData shared
Sunsynk (api.sunsynk.net)Fetch inverter readingsYour Sunsynk username/password (encrypted in transit and at rest)
Hypervolt (api.hypervolt.co.uk)Fetch EV charger readingsYour Hypervolt credentials
Octopus Energy (api.octopus.energy)Fetch tariff rates and account dataYour Octopus API key
Solcast (api.solcast.com.au)Solar forecastsYour panel location and capacity
Apple (APNs)Push notificationsYour device push token

We do not sell your data to any third party. We do not use your data for advertising.

6. Data Retention

Data typeRetention period
Account data (name, email, password hash)Until you delete your account
Energy readingsWhile your account is active; deleted on account deletion
Daily summariesWhile your account is active; deleted on account deletion
Push tokensUntil replaced by a new token or account deletion
Password reset tokens15 minutes (auto-purged)
Usage event logs90 days

7. Your Rights (UK GDPR)

You have the right to:

  • Access — request a copy of the data we hold about you (use "Download My Data" in the app)
  • Rectification — correct inaccurate data (update name/email in Settings → Account)
  • Erasure — delete your account and all associated data (Settings → Account → Delete Account)
  • Portability — export your data in machine-readable JSON format ("Download My Data" in Settings → Account)
  • Restriction — ask us to stop processing your data while a dispute is resolved
  • Objection — object to processing based on legitimate interests

To exercise any right not covered by in-app features, email privacy@sunpath.energy. We will respond within 30 days.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

8. Automated Decision-Making

We do not make any automated decisions that produce legal or similarly significant effects. Battery scheduling recommendations are advisory — you remain in control.

9. Children

Sunpath is not directed at children under 18. We do not knowingly collect data from children.

10. Changes to This Policy

We will update this page when our practices change. Material changes will be notified via a push notification or in-app banner. The "last updated" date at the top will always reflect the current version.

11. Contact

Email: privacy@sunpath.energy
Data controller: Nick Babenko trading as Sunpath


© 2026 Sunpath · Nick Babenko

  • Privacy Policy
  • Terms of Service
  • Contact