Legal
Privacy Policy
Effective date: September 9, 2026 · WeatherAlarm
The short version
- ✅WeatherAlarm does not require an account, email address, or any personal information.
- ✅The only data stored on our servers is the locations you choose to monitor and a random device identifier used to send you push notifications.
- ✅Your data is never sold, rented, or shared with any third party — ever.
- ✅We do not use analytics, advertising SDKs, or any form of tracking.
- ✅You can delete all of your data at any time by removing all locations from the app.
1. Who we are
WeatherAlarm is an iOS and Android application that monitors locations you choose for severe weather alerts issued by the National Weather Service (NWS) and NOAA's Storm Prediction Center (SPC), and delivers push notifications to your device when a warning or dangerous outlook is issued.
For questions about this policy, contact us at contact@weatheralarm.net.
2. What we collect and why
We collect the minimum information necessary to deliver the service.
- Monitored locations. The addresses and coordinates of locations you manually add to the app (for example, a family member's home address). These are stored on our servers solely to check for weather alerts in those areas. We do not access your device's GPS or location services in the background.
- Push notification token. On iOS, Apple Push Notification service (APNs) provides your device with an anonymous token. On Android, Firebase Cloud Messaging (FCM) provides an equivalent token. We store this token to deliver weather alerts to your device. The token does not identify you personally.
- Anonymous account identifier. The app generates a random UUID on first launch. On iOS, this ID is synced through iCloud Key-Value Storage so your locations are shared across your Apple devices. On Android, it is persisted in Android Auto Backup so it survives reinstalls on the same Google account. This identifier is used to associate your locations with your devices. It contains no personal information and is never linked to your identity.
Data we access on-device but do not transmit. A few features read data on your device locally; none of it is sent to our servers unless you explicitly turn it into a monitored location:
- Contacts picker (optional). If you tap "Choose from Contacts" while adding a location, the app opens the system contact picker and reads only the single contact you pick — their postal address, their name to prefill the label, and their contact photo if they have one, which is saved on your device as that location's picture and can be changed or removed at any time. Nothing from the contact is uploaded to us; only the address you confirm becomes a monitored location. We do not read, store, or upload your contact list. If you do not use this feature, we never request contacts permission on iPhone.
- Location photo (optional). You can choose a picture from your photo library for each monitored location, or let it come across from a contact you pick. The app opens the system photo picker and reads only the single image you pick. The cropped result is stored on your device and, on iPhone and iPad, mirrored through your own iCloud account so the same picture appears on your other devices. It is never sent to WeatherAlarm. We have no access to it, it is never included in a notification, and it is never shared with anyone. Deleting the location, or choosing “Remove Photo”, removes the picture from your devices and from iCloud. If you do not use this feature, we never request photo-library permission.
- Map interactions. The "Add Location" map lets you tap or search for an address. Only the address or coordinate you confirm is ever saved or sent to us — we do not record your pans, zooms, or search text. On iPhone the address suggestions come from Apple’s own Maps search, so what you type in that box goes to Apple as you type it; Apple's privacy policy applies.
We do not collect your name, email address, phone number, payment information, contact list, photos, browsing history, background location, or any other personal data. A picture you choose for a location is stored on your device and mirrored through your own iCloud account, as described above — it is never transmitted to us, so it is not data we collect.
3. How we use your information
The data listed above is used exclusively to provide the core functionality of WeatherAlarm:
- Checking your saved locations against active NWS alerts and SPC outlooks
- Sending push notifications to your device when severe weather is detected
- Synchronizing your saved locations across multiple devices you own
We do not use your information for advertising, profiling, or any purpose beyond operating the app.
4. Third-party sharing
We do not sell, rent, trade, or otherwise share your information with any third party.
The app communicates with the following external services as part of normal operation:
- Apple Push Notification service (APNs) — iOS only. Used to deliver notifications to your device. Apple's privacy policy applies.
- Firebase Cloud Messaging (FCM) — Android only. Used to deliver notifications to your device. Google's privacy policy applies. Only your FCM token is shared with Google; no monitored-location data is sent to FCM.
- Apple iCloud Key-Value Storage — iOS only. Used to sync your anonymous account identifier across your Apple devices. Apple's privacy policy applies.
- Android Auto Backup — Android only. Google's standard app-backup mechanism; used so your anonymous account identifier survives a reinstall. Google's privacy policy applies.
- Map basemap tiles (OpenFreeMap / MapTiler) — both platforms. The app renders maps with MapLibre using open vector map tiles (derived from OpenStreetMap) served by OpenFreeMap and/or MapTiler. As you pan or zoom, tile requests reveal the map area you are viewing to the tile provider; no account identifier or list of your monitored locations is sent. Each provider's privacy policy applies.
- iPhone search (Spotlight). On iOS, the label and address of each location you save are added to your iPhone's own on-device search index, so you can find a saved location by name from the home screen. This index is local to your device and is never uploaded to us or published to the web; Apple's privacy policy applies to it. Removing a location removes it from the index, and signing in under a different account clears the whole index.
- Address lookup (geocoding). When you add a location, the address you type is converted to coordinates by your device's built-in geocoder — Android's system Geocoder on Android, Apple's CLGeocoder on iOS. Apple's / your device platform's privacy policy applies. WeatherAlarm does not send your address searches to Google Maps or Google Places; see the Google Pollen API entry for the one Google service that does receive a saved location’s coordinates.
- NOAA / National Weather Service APIs. Public U.S. government APIs used to fetch weather alert data, Storm Prediction Center outlooks, and forecasts for your saved locations. When you open a weather instrument's history, the app also contacts NWS directly: your saved coordinates are used to find an observation station, then its station identifier and a time window are used to retrieve readings. NWS receives your device's IP address for direct requests. Your account identifier and location labels are never sent to NOAA.
- Google Pollen API — both platforms. To show a pollen forecast for a saved location, our server sends that location's coordinates (no name, label, or account identifier) to Google's Pollen API. Google's privacy policy applies. This is the only Google service that receives a monitored location's coordinates.
- AirNow (EPA air quality) — both platforms. Our server sends a saved location's coordinates to the AirNow API to retrieve the local Air Quality Index and forecast. No account identifier or location label is sent.
- Vaisala Xweather (lightning) — both platforms. To show recent cloud-to-ground strikes near a warned location, our server sends that location's coordinates (rounded to about 10 metres) to Vaisala's Xweather API. No account identifier or location label is sent. Vaisala's privacy policy applies.
- Wildfire data (National Interagency Fire Center / Esri) — both platforms. To show nearby wildfire perimeters, the app queries the public WFIGS service using a bounding box around a saved location. The request carries that area and your device's IP address; it never carries your account identifier or the location's label. Esri's privacy policy applies.
- Storm reports and archived warnings (Iowa Environmental Mesonet) — both platforms. To show National Weather Service storm reports after a warning ends, and archived warning outlines in map history, the app queries Iowa State University's Iowa Environmental Mesonet. These requests carry a time window only — no coordinates, no area, no label and no account identifier — and the results are narrowed to the area near your saved location on your own device. Future-radar map tiles from the same service do reveal the map area you are viewing, in the same way any map tile request does. IEM's privacy policy applies.
- River gauges (NOAA National Water Prediction Service) — both platforms. During an active flood warning, the app asks NOAA's public water API which river gauges sit near a saved location and how high the water is. The request carries a bounding box around that location and your device's IP address; it never carries your account identifier or the location's label. This is a U.S. government service.
- Public radar archives (AWS Open Data / Unidata). Radar imagery is downloaded directly by the app from public NOAA archives. These requests carry your device's IP address and which radar site you are viewing — never a location, label, or account identifier.
- Power-outage status — and the one case where an address is sent. To tell you a loved one may be without power, the app reads utility outage data directly. For almost every utility this means downloading a public list of all current outages and matching it against the location on your own device, or sending only the location’s coordinates — the address itself never leaves your phone. One utility works differently. DTE Energy (southeast Michigan) publishes no outage list at all, so for a location DTE serves, the app sends that location’s address to DTE’s public address-lookup service to ask whether that specific home has power. This happens only when you open that location, only for locations in DTE’s service area, and the address goes only to DTE — never to any other utility, and never with your account identifier or the location’s label. DTE’s privacy policy applies. No outage information is ever used to send you a notification.
- Directions and utility lookups (only when you tap them). Tapping "Directions" hands the location's coordinates to Apple Maps or Google Maps, and the power-provider row opens a web search built from the location's area. Both happen only on your tap, in the app you choose.
- Apple / Google in-app billing (optional tip jar). If you choose to leave a tip, the transaction is handled entirely by Apple (StoreKit) or Google (Play Billing). WeatherAlarm never sees your payment details.
We have no advertising partners, analytics providers, or data brokers.
5. Data retention and deletion
Your locations and device token are retained on our servers for as long as the app is installed and in use. You can delete your data at any time:
- To delete a single location, open it in the app and tap Delete (swipe-left on iOS, long-press or use the menu on Android).
- To delete all data, remove all locations from the app. Once no locations remain, your account record is no longer used. An account that holds no locations, is more than 30 days old, and has had no active device for 30 days is deleted automatically, along with its device tokens.
- Accounts we can no longer reach. An account that still holds saved locations, but has had no app installation capable of receiving a notification for 90 days, is also deleted automatically, along with those locations. We keep saved locations in order to send alerts about them; once no device remains to alert, holding the addresses of someone's family serves no purpose, so we do not keep them indefinitely. Opening the app again on any device restores your saved locations from your own device's backup and re-registers it, so ordinary use — even after a long quiet spell — keeps an account well clear of this.
- If you uninstall the app, your push notification token naturally becomes invalid. On iOS, Apple reports invalid tokens to us within minutes and we purge them automatically. On Android, FCM may take up to ~24 hours to report invalidation; your token is purged as soon as we receive that signal.
To request manual deletion of any data associated with your device, contact us at contact@weatheralarm.net.
6. Data security
All communication between the app and our servers is encrypted using HTTPS/TLS. Access to our backend is protected by a secret key embedded in the app. We do not store any sensitive personal information, which minimizes risk in the event of any unauthorized access.
7. Children's privacy
WeatherAlarm is not directed at children under the age of 13. We do not knowingly collect any information from children. Because we collect no personal information from any user, the app is inherently low-risk for users of all ages.
8. Changes to this policy
If we make material changes to this privacy policy, we will update the effective date at the top of this page. We encourage you to review this page periodically. Continued use of the app after any changes constitutes acceptance of the updated policy.
9. Contact
If you have any questions or concerns about this privacy policy or how your data is handled, please contact us:
contact@weatheralarm.net