Privacy Policy
Last Updated: August 12, 2026
1. Information We Collect
1.1 Account and Purchase Information
When you use Sign in with Apple, we may process:
- A Firebase account identifier
- Your email address, which may be an Apple private relay address
- Your name if Apple makes it available
- Account creation, sign-in, and service activity timestamps
Apple processes payments. RevenueCat helps us manage purchases and entitlements. We may process product and offering identifiers, purchase status and history, subscription status, and an account identifier. We do not receive your full payment card details.
1.2 Location and Weather Data
If you grant location permission, the app processes your device coordinates to show local weather and identify nearby places. Coordinates are sent to Apple WeatherKit when needed to request weather data. IsoWeather does not include raw GPS coordinates in its custom Google Analytics events.
Locations you view, save, favorite, or create may include a place name, country, coordinates, and an IsoWeather city identifier. This data is stored locally and may also be stored in Firebase when you sign in and use synchronization, custom-city, or cloud progress features.
Weather data may include conditions, weather alerts, temperatures, forecasts, and derived weather categories.
1.3 App Content and Feature Data
- Favorites, recent locations, settings, and cached weather images
- Image-generation requests, including place, country, weather category, theme, AI model, and timestamps
- Purchase entitlements, usage limits, and custom-city allowances
- Optional Pins progress and weather observations when you enable saved progress while signed in
- Collector Card progress, which is primarily stored locally
Saved Pins progress can include consent status, city and country information, weather category, temperature, distance to the city, progress counters, and unlock timestamps. Some Pins progress and Collector Card data also remains on your device.
1.4 Analytics Data
When Analytics collection is active, the app and website send pseudonymous usage data to Google Analytics. This may include:
- A pseudonymous app-instance or vendor identifier, session identifiers, an
advertising identifier if available and permitted, or a website client
identifier stored in a first-party cookie such as
_ga - App version, device model, operating system, language, time zone, browser, and referring page
- Country, region, or city approximated from the connection IP address; Google states that the IP address itself is not logged or stored in Google Analytics
- App launches, screen views, onboarding steps, location-permission status, feature interactions, image views and generation, shares, and settings use
- Catalog city identifiers, country codes, location type, weather category, image mode, and AI model
- Paywall interactions, product or offering identifiers, purchase and restore outcomes, subscription status, and purchase amount or currency where reported by Apple or Firebase
- Pins and Collector Cards use, including pin identifiers, progress counts, unlock status, and activation state
- On the website, page title, page URL and path, and clicks on App Store or “Learn More” links
Our custom Analytics events are designed not to include your name, email address, Firebase account identifier, raw GPS coordinates, custom-location names, custom/current-location identifiers, or raw error messages. We do not currently set your Firebase account identifier as the Google Analytics User-ID.
The saved-progress control for Pins and Collector Cards is separate from general Analytics. Turning off saved progress stops the optional cloud progress processing, but does not currently disable general Analytics collection.
1.5 Crash and Diagnostic Data
Firebase Crashlytics may collect crash reports, stack traces, app and device details, and pseudonymous installation identifiers so we can diagnose stability problems. Debug logging is off by default. If you enable it or manually send diagnostics, technical logs and device information may be uploaded to Firebase or sent to us via our email service provider.
2. How We Use Your Information
We use the data described above to:
- Provide accounts, weather, saved places, synchronization, widgets, Pins, and other requested features
- Generate and cache AI-powered weather visualizations
- Manage subscriptions, purchases, entitlements, and usage limits
- Measure feature adoption, onboarding, engagement, and purchase funnels
- Understand website use and referrals
- Diagnose crashes, improve compatibility and performance, prevent abuse, and secure the service
3. Data Storage and Security
3.1 Cloud Storage
- Account and feature data is processed using Firebase Authentication, Firestore, Cloud Functions, and Cloud Storage
- IsoWeather Cloud Functions primarily run in the EU region
europe-west3 - Our raw Analytics export is stored in a BigQuery dataset in the EU region
europe-north2 - Google Analytics processing is not necessarily limited to those EU regions
- Generated images are cached in Google Cloud Storage. Signed access links usually expire after 30 days, while cached image files may be retained or replaced for continued service operation
3.2 Local Storage
- Favorites and recent locations are stored on your device
- Cached weather images are stored locally
- Some Pins and Collector Card progress is stored locally
- Uninstalling the app removes its local data, but does not delete data that has already been transmitted to service providers
3.3 Security Measures
- All data transmission uses HTTPS encryption
- Firebase security rules restrict data access
- Administrative access is limited and authenticated
- Our custom Analytics payloads exclude names, email addresses, raw GPS coordinates, and raw error text
4. Third-Party Services
IsoWeather uses the following third-party services:
4.1 Apple WeatherKit
Provides weather data for requested coordinates. See Apple's Weather Attribution requirements and Apple's Privacy Policy.
4.2 AI Image Generation (Google Gemini & Black Forest Labs FLUX)
Depending on the selected model, we may send the following to Google or Black Forest Labs:
- City name and country
- Weather category and prompt instructions
- Theme mode and requested image dimensions
We do not intentionally include your Apple or Firebase account identifier in the AI prompt. See Google's Privacy Policy and Black Forest Labs' Privacy Policy.
4.3 Firebase, Crashlytics, Google Analytics, and BigQuery (Google)
Google provides authentication, cloud functions, databases, storage, crash reporting, app and website Analytics, and Analytics export hosting. Google processes the usage, device, identifier, and approximate-location data described above to provide these services. Learn more from Firebase Privacy and Security, Google's Privacy Policy, and How Google uses information from sites and apps that use its services.
4.4 Sign in with Apple
Handles Apple authentication. See Apple's Privacy Policy.
4.5 RevenueCat and Apple App Store
Apple processes payments and RevenueCat manages purchase and subscription entitlements. See Apple's Privacy Policy and RevenueCat's Privacy Policy.
4.6 Brevo
If you choose to send diagnostic logs by email, Brevo processes that message for delivery. See Brevo's Privacy Policy.
5. Data Sharing
We do not sell your personal data. We disclose data only as needed to provide, secure, support, and measure IsoWeather, including to:
- Apple for WeatherKit, authentication, and purchases
- Google/Firebase for authentication, cloud infrastructure, crash reporting, Analytics, and BigQuery hosting
- Google or Black Forest Labs for AI image generation
- RevenueCat for purchase and entitlement management
- Brevo when you send diagnostic logs by email
- Authorities or other recipients when required by law or necessary to protect users, IsoWeather, or the service
6. Your Choices and Rights
- Location: Control location permission in iOS Settings. Some functionality will be limited if permission is disabled.
- Saved progress: Leave Pins and Collector Cards saved progress disabled, or disable and remove it from the app's settings.
- Diagnostics: Leave debug logging disabled, turn it off, or clear locally stored logs in the app.
- Website Analytics: Block or delete Analytics cookies in your browser or use the Google Analytics Opt-out Browser Add-on.
- App Analytics: The current app version does not provide an in-app Analytics opt-out. You may contact us to object to this processing or ask about available controls.
- Account deletion: Deleting your account in the app deletes your Firebase Authentication account. Contact us to request deletion of other associated server data.
- Privacy requests: Depending on your location, you may request access, correction, deletion, restriction, or a portable copy of your personal data, object to processing, or withdraw consent where processing is based on consent.
Pseudonymous Analytics records are not currently linked to your Firebase account identifier. This can limit our ability to locate a specific person's Analytics records without the relevant app-instance or website client identifier.
7. Data Retention
- Account and cloud feature data is retained while your account is active or as needed to provide the service, unless you request deletion or a longer period is required by law.
- Local app data is retained until it is cleared, replaced, or the app is uninstalled.
- Local debug logs are limited to approximately 24 hours. Uploaded diagnostic log batches are assigned a 30-day expiration timestamp.
- Generated images may remain in the shared service cache. Signed download links usually expire after 30 days.
- Google Analytics user- and event-level data is retained according to the setting configured for our Analytics property. Standard Google Analytics properties support a retention setting of 2 or 14 months. See Google Analytics data retention.
- Google Analytics cookies such as
_gamay normally persist for up to two years and can be refreshed by later activity. See Google Analytics cookie usage. - Analytics events exported to our BigQuery dataset are currently stored without automatic expiration and remain until we delete them.
- Firebase Crashlytics generally retains crash stack traces and associated identifiers for 90 days before removal begins.
Uninstalling the app or deleting your authentication account does not automatically delete data already sent to service providers or pseudonymous Analytics exports.
8. Children's Privacy
IsoWeather is not directed to children under 13. We do not knowingly collect personal data from children under 13. If you believe a child has provided us with personal data, please contact us.
9. International Data Transfers
Some Firebase backend resources and our BigQuery Analytics export are hosted in EU regions. Google, Apple, RevenueCat, Black Forest Labs, Brevo, and their subprocessors may process data in other countries. Where required, transfers are protected using contractual and other safeguards recognized by applicable law.
10. Changes to This Policy
We may update this policy as the service or legal requirements change. We will post updates here, change the “Last Updated” date, and provide additional notice where required.
11. Contact Us
For privacy-related questions or requests:
- Website: isoweather.web.app
- Email: jonas@appfrilans.se
- Subject: "IsoWeather Privacy Request"
12. Legal Bases and EEA/UK Rights
Where the GDPR or UK GDPR applies, the legal basis depends on the processing:
- Providing requested app, account, purchase, and synchronization features: performance of a contract or steps requested before entering a contract
- Security, abuse prevention, crash diagnosis, and service improvement: our legitimate interests, where those interests are not overridden by your rights
- Optional saved Pins progress: your consent, which you can withdraw in the app
- Analytics: our legitimate interests in understanding and improving IsoWeather where permitted, and consent where applicable law requires it
- Legal and regulatory obligations: compliance with law
IsoWeather in Sweden is the data controller for the processing described in this policy. You may lodge a complaint with the Swedish Authority for Privacy Protection (IMY) or your local data protection authority.