Your data.
Your control.
Privacy policy for SpaceWeatherX and this support website.
Who is responsible
Ivan Tokić, Croatia, is responsible for the processing carried out by SpaceWeatherX. Send privacy questions or requests to tokicx@gmail.com.
This policy covers functions available in your iOS or Android version of the app. The app does not require a separate SpaceWeatherX user account. Phone notifications and advertising may depend on service activation and regional availability.
Settings and data sources
Your selected city, its coordinates, language and alert categories are stored on your device. The app does not request access to your contacts or continuous location tracking. The Android version does not request GPS permission; you enter the place or its coordinates manually.
The app retrieves public NOAA and NASA data. Apple Weather provides local weather, UV, cloud cover, sunrise and sunset through our service hosted on Cloudflare. NASA CME data also passes through this service. Providers receive connection information, including the IP address of the device or server connecting to them.
For a local forecast, our service receives the selected city, coordinates, time zone and language. It rounds coordinates to three decimal places before storing them or sending them to Apple. This remains precise location information. Apple receives the coordinates and time zone from our server, not your SpaceWeatherX installation identifier or notification token. The selected location can differ from your actual location.
City search on iOS uses Apple's geocoding service. The text you enter and coordinates of the results are processed by Apple to find the place and its time zone. We do not store a history of your search text on our server. City search does not request the device's GPS location. You can also enter coordinates manually. See Apple's Maps and location privacy information.
We make data protection at least equivalent to that described in this policy and required by Apple's App Review Guidelines a condition for sharing user data with third parties, including advertising networks and embedded SDKs. If we find that a provider cannot meet this condition, we will suspend data sharing with that provider until the issue is resolved. Apple and Google may act as independent controllers for their services; this does not remove our data-protection requirement.
Weather access and technical records
To access weather and NASA CME data, the device securely stores a randomly generated installation identifier and access credential. Our service stores the identifier, a hash of the credential, the platform, registration dates and expiry. This is separate from phone-notification registration and does not enable notifications. The weather-registration record itself contains no location.
Forecast responses containing coordinates are temporarily cached with a validity period of no more than one hour. Expired entries are removed during subsequent cleanup. These cache records do not contain an installation identifier or search history. Technical service logs may include request paths with installation identifiers, response status and processing times. We use these records to maintain the service and diagnose failures. Daily-changing hashed network identifiers and temporary counters help limit abuse.
The installation identifiers are pseudonymous: they do not require your name or an account, but records associated with one identifier can relate to the same installation. Infrastructure logs and backups follow separate retention periods and may remain after a live record is removed. See Cloudflare's privacy policy and Apple's privacy policy.
Phone notifications
If the notification service is available and you enable it, our service receives a separate installation identifier and credential hash, an Expo delivery token, your platform, selected city, coordinates rounded to three decimal places, time zone, language and alert preferences. These settings and delivery records are linked to the installation so that the service can select relevant alerts.
Expo and Apple's notification system on iOS, or Google Firebase Cloud Messaging on Android, process delivery identifiers and message contents to deliver notifications. On Android, Expo SDK registration includes installation identifiers, the native FCM token, and app and project identifiers. The message can include your selected city's name. Our service does not send the full location and preference registration to Expo. See Expo's privacy policy and Firebase's privacy information.
Turning off notifications in the app requests deletion of the registration and associated notification records; an internet connection and a successful service response are needed. A failed request can be retried. Disabling permission in device settings stops display but does not itself confirm deletion of the service registration. Deleting the app also does not immediately confirm server-side deletion. Turning off notifications in the Android app does not automatically delete the Expo registration, Firebase installation identifier or subscription records.
Subscriptions and payments
iOS — App Store
On iOS, Apple processes annual subscription purchases and renewals. The app checks subscription status, validity, expiry and transaction identifier through the App Store to remove ads. Subscription status and transaction information are kept on the device; the app does not send them to a SpaceWeatherX account server. SpaceWeatherX does not receive your payment card number. Apple's processing is also covered by the Apple privacy policy.
Android — Google Play
Google Play processes Android subscription purchases, payments and renewals. SpaceWeatherX does not receive your payment card details. When checking subscription availability or status, the app creates a separate random installation identifier and access credential in secure device storage. Our separate Android subscription service on Cloudflare stores the installation identifier and a hash of the credential. A hash of the installation identifier is sent to Google when you make a purchase.
To verify and restore purchases and track renewals, the service processes the purchase token, its hash and encrypted value, the Google order identifier, product, subscription status, expiry, auto-renewal state, and links between purchases and installations. The purchase token is sent to Google Play for verification. We use these records to provide paid features and prevent abuse. Data is transmitted over encrypted HTTPS connections. Google's processing is covered by Google's privacy policy.
Advertising and consent
TestFlight builds and internal Android test builds may display test ads. Both test and live ad requests can involve the data described below. An ad request is sent only when Google's consent system allows it.
When ads are enabled and you do not have an active subscription, the app uses Google AdMob. It requests non-personalized ads; this does not mean no data is processed. Google's SDK may process IP addresses and approximate location inferred from them, app or device identifiers, advertising and interaction data, and diagnostics such as crashes and performance. Some advertising information may be associated with a device identifier. It is used to deliver and measure ads, prevent misuse and improve the service. See Google's data disclosure guides for iOS and Android.
Before requesting an ad, the app checks your choices through Google's consent system. Where a choice is required, you can accept, refuse or later revise it in advertising privacy settings. On iOS, the app does not request IDFA tracking permission. On Android, Google's SDK may process the advertising identifier; you can manage it in Android settings. An active subscription removes ads.
Google operates under its own privacy policy. Changing a choice does not necessarily erase data a provider has already lawfully processed.
Support and this website
If you email us, we receive your address, message and any attachments you choose to send. We use them to respond and resolve your request. Include only information needed to describe the issue.
This website loads no advertising or analytics tools and sets no advertising or analytics cookies. The hosting provider may process network and security information needed to deliver and protect the site, including IP addresses. Cloudflare may add a security script and necessary cookies, such as __cf_bm, to distinguish automated traffic and protect the website. The __cf_bm cookie expires after 30 minutes of inactivity. These security mechanisms are separate from advertising and analytics. See Cloudflare's cookie information.
Purposes, legal bases and retention
Data necessary for requested features and subscriptions is processed to provide the service. Consent is used where required, including applicable advertising choices. Security and support may rely on legitimate interests; legal obligations apply where retention is required.
- Weather and notification registrations expire 90 days after their latest renewal. Continued use can renew them. Expired records are removed by service cleanup.
- Notification delivery records are scheduled for removal after seven days. Alert-state and episode records remain with the registration so the service can recognise changes and the end of an alert.
- After a confirmed registration deletion, a minimal record containing the installation identifier and credential hash is retained for about one day to prevent delayed requests from recreating that registration. It is then eligible for cleanup.
- Android subscription records, including installation registration, purchase tokens and purchase links, have no automatic deletion deadline. They are retained to verify status, restore purchases and prevent abuse. Expiry or cancellation does not automatically delete these records; the 90-day rule for weather and notification registrations does not apply to them. Contact us using the details below to request deletion.
- Firebase retains installation identifiers until an API deletion request is made, after which removal from live systems and backups can take up to 180 days. Turning off notifications in SpaceWeatherX does not make that Firebase request.
- Local settings remain until app data is deleted. Securely stored access credentials are managed separately by the operating system.
- Support messages are retained as needed to resolve the inquiry and any related claims or legal obligations. Infrastructure logs, backups and data independently held by providers follow their applicable retention periods.
Apple, Google, Expo, Cloudflare and other data or hosting providers may process information outside your country, including outside the EEA. Where required, transfers must have an appropriate legal basis and safeguards under applicable rules.
Your choices and rights
To request access to or deletion of data controlled by SpaceWeatherX, email tokicx@gmail.com and identify the data concerned. Do not send passwords, verification codes or card details. For data Apple or Google controls independently, use their privacy settings and rights-request procedures.
- Change your city, language and alert categories in the app.
- Turn off notifications in the app and in device settings.
- Revise advertising choices when privacy options are available.
- Manage your subscription through your Apple Account on iOS or Google Play on Android. Deleting the app does not cancel it.
Where GDPR applies, you may request access, correction, erasure, restriction or portability, or object to processing, depending on its legal basis. You may withdraw consent without affecting the lawfulness of earlier processing. You may complain to the competent authority, including AZOP in Croatia.
Policy changes
If features or processing change, we will update this policy and its date. We will provide additional notice of significant changes where required. A parent or guardian should supervise purchases and privacy settings when a child uses the app.
Contact support
Help with the app, your subscription or your personal data.
tokicx@gmail.comInclude your app version, device model, whether you use iOS or Android, and a short description. Do not send passwords, verification codes or card details.