This Privacy Policy explains what personal data WX Alerts, Inc. ("WxAlerts," "we," "us," or "our"), a Florida not-for-profit corporation, collects through the WxAlerts website (wxalerts.org and its subdomains), our mobile and desktop applications, our APIs and MQTT feeds, and related services (together, the "Service"), why we collect it, who else sees it, how long we keep it, and what you can do about it. It is incorporated by reference into our Terms of Service.
The Short Version
- You can read the site and use the live map without an account and without giving us anything.
- We store one location reading per device: the latest one. Each new reading overwrites the last. We do not keep location history.
- No analytics, no advertising, no trackers, no data brokers. We do not sell or rent personal data, and we never will.
- An account needs an email address. Push alerts need a notification token. That is close to the whole list.
- You can delete your account and its data yourself, at any time, at wxalerts.org/delete or from inside the app.
- We are a nonprofit run by volunteers. Nobody here has a growth target that your data would feed.
The sections below are the binding version. Where the summary and the detail disagree, the detail governs.
1. Who We Are; What This Covers
WX Alerts, Inc. is the data controller for the personal data described in this policy. You can reach us at privacy@wxalerts.org, or at support@wxalerts.org for anything that is not specifically a privacy question.
This policy covers the website, the apps for iOS, Android, macOS, Windows and Linux, our public API, and our MQTT feeds. It does not cover third-party services you reach from here, such as our Discord server, GitHub, an app store, or a payment processor's own checkout page, each of which applies its own privacy policy to what you do there. It also does not cover Home Assistant, MeshMonitor or any other software you run yourself against our feeds; that installation is yours, and its data stays on your hardware.
Features that are not live yet. Some parts of this policy describe things we have built toward but have not shipped. Those sections are marked, and they take effect only when the feature does. Nothing described as "not yet live" is collecting anything from you today. SMS text alerts are live and are described in Section 7.
2. What We Collect
2.1 If you just visit the website
No account, no sign-up, no tracking. Your browser requests pages and weather data, and our servers and CDN keep ordinary request logs (IP address, timestamp, the URL requested, user agent, and response status) which exist to keep the service running and to stop abuse. Alert, lightning and location-search requests you make to api.wxalerts.org appear in those logs too; a location search sends the text you typed (for example "Milton, FL") so the API can return matching places, and that query is not tied to an identity or kept beyond the log window in Section 10.
2.2 If you create an account
Accounts are handled by our own identity server (Authentik), running on our own infrastructure, not by a third-party login provider. Creating one collects:
- Email address: your login and how we reach you about your account.
- Username and, if you provide one, a display name.
- A password, stored only as a salted hash. We never see or store your password itself.
- Sign-in metadata: timestamps, IP address, and device or browser identifiers for recent sessions, used to secure the account and let you spot access you do not recognise.
- Your acceptance of the Terms and the Life-Safety Disclaimer: the date, time and version.
If we later offer sign-in through an outside provider, that provider would share your name and email address with us to create the account, we would say so here first, and you would still be choosing to use it.
2.3 If you use the apps
The apps register a device record with us so alerts can reach it. That record holds:
- A push notification token issued by Firebase Cloud Messaging (Android, iOS, desktop). It addresses your app installation and nothing else: it is not a phone number and not an advertising ID.
- Your most recent location reading, and only that. See Section 3.
- Basic device context (platform, app version, and notification settings) so we can send the right payload and diagnose delivery failures.
- Saved places you create yourself: a label and coordinates for home, a school, a campsite, a venue. These are stored until you delete them, because a saved place is only useful if it persists.
- Alert delivery records, meaning which alert went to which device and when, kept briefly so we do not send you the same warning four times, and so a "the alert never arrived" report can actually be investigated.
Authentication tokens live in the operating system's secure storage on your own device (Keychain on Apple platforms, Keystore on Android, the platform secret store on desktop). They are not transmitted anywhere except to our identity server when refreshing your session.
2.4 If you donate
Donations are processed by Stripe. Your card number never touches our servers, because checkout happens on Stripe's own hosted page. What comes back to us and is stored in our donation ledger is: the amount, the currency, whether the gift was one-time or recurring, the tier it maps to, Stripe's identifiers for the payment and (for recurring gifts) the subscription, and the email address you gave at checkout, if you gave one. We keep that so a receipt can be reissued and a gift reconciled. Stripe's own handling of your payment details is governed by Stripe's privacy policy.
2.5 If you contact us or join the community
Email you send us, whether a bug report, an alert that arrived wrong or a rights request, is kept as long as needed to deal with it and to keep a record of what was decided. Our Discord server is operated by Discord Inc. under its own privacy policy; what you post there is visible to that server and is not covered by this policy except where we copy something out of it into a bug report.
2.6 If you hold an API or MQTT key
We store the key, the account it belongs to, its rate limits, and request counts and timestamps for it: the minimum needed to enforce limits and to contact you if your key starts behaving strangely. The public read-only MQTT feed requires no key and identifies nobody.
2.7 What we never collect
No analytics or product-usage telemetry. No advertising or attribution SDKs, no advertising identifiers, no fingerprinting, no session recording, no third-party trackers or ad pixels. No contacts, photos, microphone, camera, calendar, health data, or files. No browsing history from outside our own service. We do not buy personal data, we do not enrich what you give us against outside datasets, and we do not track you across other companies' apps or sites, which is why the apps do not show Apple's App Tracking Transparency prompt.
3. Location: The Last-Reading-Only Rule
We store exactly one location reading per device: the most recent one. Every new reading overwrites the previous one. We do not build, retain or derive a location history, a movement trail, a track, or a pattern of where you go. There is no table to sell, subpoena or lose, because there is no table.
This is how the product is built, not a promise laid over a database that does otherwise. A weather warning is a polygon on a map, and the only question we need to answer is whether the point where you are right now falls inside it. Answering that needs one point. Answering it tomorrow needs tomorrow's point, not today's.
It is entirely optional. The apps ask for location permission and you can say no; the live map on the website never asks for your browser's location at all. Decline, and you can still use everything except location-based alerting. Set up a saved place instead and get alerts for that fixed point, which many people prefer.
3.1 Background location
The Android and iOS apps can ask for background ("all the time") location permission, because a tornado warning at 3 AM is exactly the case where the app is not open. This is a separate permission, asked separately, and declining it leaves the rest of the app working: you simply get alerts based on where you were when the app last ran, or on your saved places.
When granted, the app sends a coarse location heartbeat while it is closed. Fine-grained readings are taken only while the app is actually running in the foreground or while an active threat is being tracked near you. Every one of those readings, coarse or fine, follows the same rule: it replaces the stored one and nothing is appended. You can revoke the permission at any time in your device settings, and the apps do not degrade or nag if you do.
3.2 Saved places are different, and deliberately so
A saved place is a fixed point you typed in yourself: your house, a child's school, a field site. We keep those until you delete them, because that is the entire point of saving one. They are not derived from your device's location and they are not a history of your movements.
3.3 What we never do with location
We do not sell it, rent it, trade it, or share it with data brokers, advertisers, analytics companies or aggregators, not in identified form, not "anonymised," not in aggregate as a product. We do not use it to profile you or to advertise. The live map shows storms, not people. We do not publish or expose any user's location to any other user.
4. Cookies and Local Storage
There is no cookie banner on this site because there is nothing on it that a banner would need to ask about. We set no advertising or analytics cookies of any kind. What we do set:
| Name | What it holds | Life |
|---|---|---|
wx_view | Where you left the map: latitude, longitude and zoom, rounded to about 11 metres. Carries nothing identifying. | 1 year |
wx_layers | Which map layers you had switched on. | 1 year |
| Session cookies / tokens | Keeping you signed in, if you have an account. Strictly necessary. | Session or until sign-out |
Clearing your browser's cookies removes all of them, and the map simply opens on wherever the most active weather is instead. The apps use your device's own preference storage for the same kind of settings, and its secure storage for sign-in tokens.
5. How We Use Your Data
Every use is one of these. There is not a further list held somewhere else.
- Sending you the alerts you asked for: matching warning polygons and lightning against your current location and saved places, and delivering the result by push, email or (when it exists) SMS.
- Running your account: signing you in, keeping your settings, answering your support email.
- Keeping the service up and honest: diagnosing failed or late deliveries, investigating your bug reports, finding abuse, enforcing rate limits, and stopping attacks.
- Processing donations: taking the payment, issuing the receipt, keeping the accounting records a nonprofit is required to keep, and counting supporters on the support page.
- Meeting legal obligations: tax and corporate records, and responding to lawful process.
We do not use your data to train advertising models, to profile you, or to make automated decisions that produce legal or similarly significant effects about you. Deciding that a warning polygon contains your location is arithmetic on a map, and it is the service you signed up for.
6. Legal Bases (GDPR/UK GDPR)
If you are in the European Economic Area, the United Kingdom or Switzerland, we rely on these lawful bases:
| What | Basis |
|---|---|
| Account, saved places, push and email alert delivery | Contract, Art. 6(1)(b). It is the service you signed up for. |
| Device location, including background location | Consent, Art. 6(1)(a), given through the operating system permission prompt and withdrawable in device settings at any time. |
| SMS text alerts (when offered) | Consent, Art. 6(1)(a), given separately at opt-in. |
| Security, abuse prevention, rate limiting, delivery diagnostics, server logs | Legitimate interests, Art. 6(1)(f), in keeping a public-safety service available and unabused. We have weighed this against your rights and keep the data minimal and short-lived. |
| Donation and accounting records | Legal obligation, Art. 6(1)(c), and contract for the gift itself. |
Withdrawing consent does not affect processing that already happened lawfully, and it does not delete your account. For that, see Section 11.
7. Push, Email and SMS
Push notifications are opt-in and are delivered through Firebase Cloud Messaging, which receives your push token and the alert payload in order to route it to your device. You choose which severity tiers you receive, and you can switch them off in the app or in your device settings at any time. Delivery depends on Firebase, your device and your network, and is not guaranteed.
Email alerts go to the address on your account or to any address you add. Every alert email carries an unsubscribe link, and you can change or remove the address in your settings.
SMS alerts go to a mobile number you enter on your own account and then confirm with a code we text to that handset. Nothing but that code is ever sent to an unconfirmed number. They are part of the supporter tiers at or above $8 a month, because each message costs us money to send. Specifically:
- You opt in affirmatively and separately, with a box that starts unchecked, not bundled into accepting the Terms, and we log that consent: the exact wording shown to you, its version, the date and time, and the IP address and browser it came from. That record is what a carrier audit asks for, and we keep it even after you opt out, so that the withdrawal is auditable too.
- Message frequency varies with the weather. You choose which saved places and which classes of alert are worth a text, so you control it. Message and data rates may apply.
- Reply STOP to any message to stop them, or HELP for help. STOP works instantly from the handset and needs no sign-in. You can also remove the number from your account page, which does the same thing.
- Your phone number goes to Twilio, our messaging provider, purely to deliver the message. We store the number itself, the last four digits for display, and a record of which alerts were sent to it.
- No mobile information or SMS opt-in consent data will be shared with any third party or affiliate for marketing or promotional purposes. It is used only to send you the alerts you asked for.
- Consent to SMS is not a condition of using WxAlerts. Every alert is free on the website, in the apps and over the API whether or not you ever give us a number.
Saved places. A saved place is a coordinate and a name you chose. It is what a warning polygon is matched against to decide whether to text you, so it is as sensitive as your address, and it is stored in a separate database schema from anything the public parts of our API can read. You can remove one at any time from your account page.
8. Who We Share Data With
We do not sell your personal data, and we do not share it for cross-context behavioural advertising. We have never done either and have no business model that would want to. The only outside parties that touch your data are the service providers that make the thing run, each under a contract that limits them to acting on our instructions:
| Provider | What it receives | Why |
|---|---|---|
| Google (Firebase Cloud Messaging) | Push token, alert payload | Delivering push notifications to your device |
| Stripe | Payment details, email if given | Processing donations; Stripe is the system of record for money |
| Cloudflare | IP address, request metadata | Serving, caching and protecting the site and API |
| Twilio | Phone number, message text | Delivering SMS alerts and confirmation codes |
| CARTO and the Iowa State Mesonet | Your IP address and the map tiles your browser requests | Basemap and NEXRAD radar imagery on the live map. They see tile requests, not your account. |
| Google Fonts | Your IP address when the page loads its typeface | Web typography. We are moving to self-hosted fonts to remove this request entirely. |
Our identity server, alert ingest, database and MQTT broker run on infrastructure we operate ourselves. Account credentials are not handed to an outside login provider.
Beyond those providers, we disclose personal data only: (a) when you tell us to; (b) to comply with law, a valid subpoena or other lawful process, where we will give you notice unless legally barred from doing so; (c) to investigate or stop abuse, fraud, or a threat to someone's safety or to the integrity of the service; or (d) to a successor nonprofit or trustee if WX Alerts, Inc. ever merges, reorganises or winds down, in which case this policy continues to govern the data until you are notified otherwise, and the successor cannot quietly repurpose it.
9. International Transfers
WX Alerts, Inc. is based in the United States and our infrastructure and providers are US-based. If you use the Service from the EEA, the UK or Switzerland, your personal data is transferred to and processed in the United States. Where we rely on providers for those transfers, we rely on the safeguards they offer. Several of our providers are certified under the EU-US Data Privacy Framework and its UK Extension, and we otherwise rely on the European Commission's Standard Contractual Clauses together with the technical measures described in Section 14. Write to privacy@wxalerts.org if you want the detail for a specific provider.
10. How Long We Keep Things
| Data | Kept for |
|---|---|
| Your last location reading | Until the next reading replaces it, or until you delete your account or revoke the permission |
| Account, settings and saved places | While the account exists |
| Push tokens | While the installation is registered; removed when it is uninstalled, expires, or you delete the account |
| Alert delivery records | 90 days, for de-duplication and delivery investigations |
| Server, CDN and API request logs | 30 days, then deleted |
| Sign-in and security events | 90 days |
| Support and rights-request correspondence | 2 years after the matter is closed |
| Donation and accounting records | 7 years, as required for tax and nonprofit recordkeeping |
| Encrypted backups | 35 days on a rolling cycle, then overwritten |
Backups. When you delete something, it goes from our live systems immediately, but a copy can survive in an encrypted backup until that backup rotates out on the schedule above. Those backups are put beyond use: they are not queried, mined or restored to reinstate deleted data, and are touched only to recover from a failure. If a restore ever did resurrect deleted data, we re-apply the deletion.
11. Deleting Your Account and Data
You can delete your account and its associated personal data yourself, without asking anyone, in two places:
- In the app: Settings → Account → Delete Account, on every platform we ship.
- On the web: wxalerts.org/delete.
This is a real deletion, not a deactivation, a freeze or a hidden account that could be brought back. It removes your account, your saved places, your device registrations and push tokens, your stored last location, and your alert preferences. We act on it immediately and complete it across our systems within 30 days, with the backup rotation in Section 10 as the outer bound.
What survives, and why. Donation and accounting records are kept for the period in Section 10 because tax and nonprofit recordkeeping law requires it, but they are unlinked from your account. We may also retain the minimum necessary to comply with a legal obligation, to enforce a suspension for abuse, or to establish, exercise or defend a legal claim. Anything we keep for those reasons stays subject to this policy.
Deleting the app from your device is not the same as deleting your account: it stops push notifications, but the account still exists until you delete it. And you can always uninstall, revoke location permission, or turn off individual channels without deleting anything at all.
12. Your Rights and Choices
Wherever you live, you can ask us to: access a copy of the data we hold about you; correct anything wrong; delete it; export it in a portable format; restrict or object to a particular use; or withdraw consent you previously gave. We do not charge for this, and we will not treat you differently for asking. Most of it you can do yourself in your settings; for the rest, write to privacy@wxalerts.org.
We answer within 30 days, and will tell you if a request is genuinely complex and needs longer. We may need to verify that the request comes from you, usually by confirming control of the account's email address, and we will ask for no more than is necessary to do that. An authorised agent may act for you with written proof.
If you are in the EEA, the UK or Switzerland, these are your rights under the GDPR and UK GDPR, and you also have the right to lodge a complaint with your national supervisory authority. We would appreciate the chance to put it right first.
If you are in the United States, several state privacy laws give comparable rights. As a nonprofit, WX Alerts, Inc. falls outside the scope of the California Consumer Privacy Act and most equivalent state statutes, which apply to for-profit businesses. We honour access, correction, deletion and portability requests anyway, from everyone, because the alternative would be to treat the law as the ceiling rather than the floor. For the record: we do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not process sensitive personal information for purposes beyond providing the service you asked for.
We have not appointed a representative in the EU or the UK under Article 27. Until we do, send anything you would send to a representative directly to privacy@wxalerts.org, and we will handle it ourselves.
13. Children
The Service is a general-audience public-safety tool and is not directed to children. You must be at least 13 to use it, per Section 2 of the Terms, and we do not knowingly collect personal information from anyone under 13. In a school, daycare, camp or club setting, the account holder is the responsible adult or the organisation, never a child, and it is the adult's account, contact details and settings that we hold.
If we learn that we hold personal information from a child under 13, we delete it and close the account. If you are a parent or guardian and believe your child has given us something, write to privacy@wxalerts.org and we will deal with it promptly and confirm when it is done.
14. Security
Everything is served over TLS, and traffic between our own services is encrypted as well. Passwords are stored only as salted hashes. Access to production data is limited to the small number of volunteers who need it, over authenticated connections, and backups are encrypted at rest. We patch the stack we run and keep dependencies current.
The strongest control here is the one in Section 3: the safest data is the data that was never collected. A location history cannot be breached if it was never written down, and that is the main reason we do not write it down.
No system is perfectly secure, and we will not pretend otherwise. If you find a vulnerability, tell us at security@wxalerts.org before telling anyone else, and we will work with you in good faith.
15. Breach Notification
If a personal data breach occurs, we will notify the competent supervisory authority within 72 hours of becoming aware of it where the GDPR requires it, notify affected users without undue delay where the breach is likely to result in a high risk to them, and comply with applicable US state breach notification laws. Notice will say what happened, what data was involved, what we have done, and what you should do.
16. Do Not Track and Global Privacy Control
We do not track you across other companies' sites or apps, so there is nothing for a Do Not Track or Global Privacy Control signal to switch off. We honour those signals in the sense that matters: the behaviour they are designed to prevent does not happen here, whether or not you send one.
17. Weather Data Sources
Alert and weather data flows one way. We fetch public data from the National Weather Service, NOAA, GOES satellite feeds and other public sources, and we do not send your personal data, your location or your identity to any of them. Nobody upstream learns that you exist because you received a warning. WxAlerts is not affiliated with, endorsed by, or an official product of NOAA or the National Weather Service.
18. Changes to This Policy
We will update this policy when what we do changes, including when SMS or paid tiers go live. The current version always sits at wxalerts.org/privacy with the "Last updated" date at the top, and we keep the previous version available on request.
For material changes (a new category of data, a new purpose, a new class of recipient) we will give account holders at least 30 days' notice by email or in-app before it takes effect, and where the law requires consent for the change, we will ask for it rather than assume it. Continued use after the effective date means the updated policy applies.
19. Contact
WX Alerts, Inc.
A Florida not-for-profit corporation
Privacy: privacy@wxalerts.org
Support: support@wxalerts.org
Security reports: security@wxalerts.org
Legal notices: legal@wxalerts.org
Privacy questions get a human, not a ticket queue. If something here reads as vague or as though it is hiding something, tell us. That is a bug in this page and we would rather fix it than have you assume the worst.
