1. Overview
WxSignal ("we", "us", "our") operates a weather intelligence platform. This Privacy Policy explains what data we collect, how we use it, and your rights. We collect the minimum data necessary to provide the Service and never sell your personal information.
2. Data We Collect
Account Data
- Email address — required for authentication via magic link or Google OAuth.
- Google profile — name and avatar if you sign in with Google (we store only what Supabase Auth captures).
Usage Data
- Saved locations — lat/lng coordinates and display names you save to your account.
- Alert preferences — NWS alert types you subscribe to per location.
- Page views — anonymous analytics via Vercel Analytics (no cookies, no cross-site tracking).
Payment Data
Payment is handled entirely by Stripe. We store only your Stripe customer ID and subscription status. We never see or store full card numbers.
Location Data
If you use the "use my location" feature, your browser's geolocation API is queried locally. We transmit coordinates to fetch weather data, but we do not persistently store coordinates from unauthenticated sessions. Authenticated users' saved locations are stored in our database and subject to this policy.
3. How We Use Your Data
- Authenticate your account and maintain your session.
- Deliver weather alerts and notifications you opt into.
- Generate your location-based weather dashboard and saved locations.
- Process your subscription payments via Stripe.
- Send transactional emails (magic links, alert digests) via Resend.
- Improve the Service through aggregate, anonymized analytics.
We do not use your data to train AI models. We do not sell or rent your data to third parties.
4. Data Sharing
We share data only with the following service providers, each under their own privacy policies:
- Supabase — database and authentication (EU data residency available).
- Stripe — payment processing.
- Resend — transactional email delivery.
- OneSignal — web push notifications (only if you opt in).
- Vercel — hosting and edge network (anonymous analytics only).
- Anthropic / Groq — AI text generation for AFD summaries (only NWS text is sent, never personal data).
5. Data Retention
- Account data is retained while your account is active.
- Upon account deletion, personal data is purged within 30 days.
- Aggregated, anonymized analytics data may be retained indefinitely.
- Stripe payment records are retained as required by financial regulations (typically 7 years).
6. Cookies and Tracking
WxSignal uses minimal cookies. Supabase Auth sets a session cookie to maintain your signed-in state. We use Vercel Analytics which does not set cookies or track you across sites. We do not use Google Analytics, Facebook Pixel, or other third-party advertising trackers.
7. Your Rights
You have the right to:
- Access your personal data (available in account settings).
- Correct inaccurate data.
- Delete your account and associated data.
- Export your saved locations (contact us if this feature isn't yet available in-app).
- Opt out of push notifications at any time via browser settings or account preferences.
If you are in the EU/UK/EEA, you also have rights under GDPR including the right to data portability and to lodge a complaint with your supervisory authority. We process EU data lawfully under the legitimate interests basis for service provision.
8. Security
We use industry-standard security practices including encrypted connections (TLS), row-level security in our database, and no password storage (magic links only). Despite these measures, no system is completely secure; use the Service accordingly.
9. Children's Privacy
The Service is not directed to children under 13. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has provided us data, contact us and we will delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify active subscribers of material changes by email. The effective date at the top of this page reflects the most recent revision.
11. Contact
For privacy questions, data requests, or to exercise your rights, contact us at privacy@wxsignal.com.