Skylar Weather Privacy Policy (interim)
Effective date: October 6, 2026 Interim policy: this policy covers the Skylar Weather test and early-access releases. A full policy will replace it before public launch. We will post the new version here and update the date.
Who we are
Skylar Weather ("Skylar", "we", "us") is run by Skylar Weather LLC, a company in North Carolina, USA. If you have a question about privacy, or a request about your data, email [email protected].
The short version
- No account needed for the free version: the app identifies your install with a random device ID that it creates itself. Sign-in (planned) will be optional for free use and required only to buy a paid plan (Pro or StormTracker). See "Sign-in, notifications and purchases".
- Location: we use it to give you the forecast for the place you choose. The app asks for your location only while you are using it, never in the background.
- AI providers: questions you ask Skylar's chat are answered by outside AI providers that work for us. They receive your question and the location it is about. They do not receive your device ID.
- No selling, no ads, no tracking code: we do not sell your data, and we do not show ads. The app contains no advertising, analytics or crash-reporting code.
- Deleting your data: you can delete it from the app at any time (Settings → Your data), or by emailing us.
What we collect, and why
Location
- What we receive: the coordinates of the place you want weather for. That is either where you are or a place you search for or save.
- When the app asks:
- The app asks for your location only while you are using it, and only when it needs "here", for example for the Home forecast or a chat question about where you are.
- It never reads your location in the background.
- The app only uses approximate location. It does not ask for precise location.
- You can turn location access off and type place names instead.
- Why: to calculate your forecast, alerts and air quality, to plan routes, and to name the place on screen.
- What we keep:
- Places you save (for example "Home"), and the locations of your favorites, plans and weather-alert areas, until you delete them.
- During a live drive you are tracking, only your latest position, and only until the trip ends. Then it is erased. We keep no history of where you have been.
- Forecast caches for an area about 1 km across. These are not linked to you.
- Usage statistics with the location rounded to about 11 km. These hold no device ID and no question text.
Your device ID
The app creates a random ID the first time it runs. We use it to keep your saved places, favorites, plans, chat history and usage limits together, and to delete them when you ask.
It is not an advertising ID, and it does not contain your name, phone number or email address.
Anyone who has your device ID can see or delete the data stored under it. So keep your device secure. Sign-in, when we add it, will protect this better.
Chat questions and answers
- What we keep: the text of your questions and Skylar's answers, so you can see your chat history. A conversation is deleted automatically 30 days after its last message. You can delete any conversation sooner in the app.
Paid subscribers (once paid plans launch): chat history is kept up to 12 months while you are subscribed. You can delete it anytime.
- AI providers: to answer, we send an AI provider:
- your question
- the recent messages in the same conversation
- the place it is about (coordinates and/or a place name)
- our forecast data
We do not send your device ID, your name or your IP address. The requests come from our server. The providers are:
- Fireworks AI (USA): main provider for chat answers.
- DeepInfra (USA): backup for chat answers. When that feature is on, it also writes summaries of public weather-service forecast discussions, which contain no user data.
- Groq (USA): last-resort backup for chat answers. It also handles short helper tasks, such as understanding what you asked, writing a chat title, and reading the text of your favorites, plans and preferences.
These providers process the data only to give us the answer. What their published terms say:
- Fireworks AI and DeepInfra: they do not store prompts or answers, and they do not use them to train models.
- Groq: it does not keep request data by default. It may keep logs for up to 30 days when it investigates errors or abuse.
We requested data processing agreements from Fireworks AI and DeepInfra on 2026-10-04; signature is pending.
- Diagnostic copies: to find and fix wrong answers, we keep internal diagnostic logs of chat questions and answers.
- The location in them is either rounded to about 1 km, or it appears in the full text we sent to the AI provider.
- They hold no device ID, or only a short one-way code made from it.
- We are setting these to be deleted automatically after 30 days.
- We may keep de-identified excerpts (with device identifiers and location removed) to test and improve answer quality.
- Please don't put sensitive personal information, such as health details, into chat or free-text fields. We don't need it to answer weather questions.
Favorites, plans, saved places and preferences
- What we keep:
- The favorites and plans you create, including any text you type (for example "morning run if under 80°F").
- Your saved places.
- Your settings, such as units, theme, language and sensitivity profile.
- Any free-text preferences you write.
- AI processing: text you type into favorites, plans and preferences is sent to an AI provider, as described above, so Skylar can understand it.
- Checking how preferences change answers: to make sure your preferences change Skylar's verdicts the way they should, we may keep a short record each time they do. It contains:
- which part of the app was used and the activity
- the location rounded to about 11 km
- the result with and without your preferences
It does not contain your chat questions or answers. It can include the short weather rules Skylar made from your preferences (for example "wind above 15 mph"). It is stored with a one-way code made from your device ID. We are setting these records to be deleted after 12 months, and they are removed when you delete your data.
- How long:
- Plans are deleted automatically 24 hours after the event ends.
- Your position during a tracked drive is erased as soon as the drive ends. The rest of the drive's record is deleted more than 7 days after the drive ends.
- Everything else stays until you change it, delete it, or delete your data.
Ratings, feedback and reports on answers
- What we keep: if you rate an answer, write feedback, or report an answer, we keep:
- the rating
- your optional text
- a short excerpt of the question and answer
- technical details of the answer, such as which Skylar tier wrote it
- Reported answers go into a queue that a person on our team reviews.
- Why: to improve Skylar's answers.
- How long: ratings and feedback are kept 180 days, then deleted automatically. Reported answers are also kept 180 days; we are setting up their automatic deletion. This data is stored with a one-way code made from your device ID, not the ID itself. It is still removed when you delete your data.
Shared links
If you share a forecast, the app creates a link to a snapshot of it.
Shared links are public: anyone with the link can see the shared forecast snapshot until it expires (90 days) or you delete it. A deleted link may stay visible in caches for up to an hour. Shared snapshots never include your device ID, notes (unless you choose to include them), or precise coordinates (rounded to about 1 km).
We keep the snapshot until the link expires or you delete it.
Weather reports you send
- What we keep: if you send a weather report (for example "heavy rain here"), we keep:
- its location and the place name
- the condition
- any notes you add
- Who sees it: other Skylar users can see the report, including its location and notes. They cannot see your device ID.
- Photos: photo reports are currently turned off. If we turn them on, we will first remove location data stored inside photos, and we will update this policy.
- How long: until you delete your data.
Beta tester feedback (test builds only)
Test builds have a feedback tab. If you send feedback from it, we keep:
- your comment
- an optional screenshot
- the screen you were on
- your app version, phone model, operating system version, screen size, language and network type
- the location attached to the feedback
Store builds do not include this tab. We use the feedback to fix problems. It is kept until you delete your data.
Usage counts
We count how many times each install uses certain features each week (for example chat questions or route plans) to apply the free limits.
For requests without a device ID, we count by a one-way code made from the IP address with a secret key. We never store the IP address itself.
Weekly counts are kept until you delete your data.
Requests for new data
If you ask for a type of weather data we don't have yet, we keep:
- the request
- any short text you add (filtered, up to 300 characters)
- a one-way code made from your device ID
We use it to decide what to build next. They are kept until you delete your data.
Server logs
Our server keeps logs of requests for about 14 days, to run and secure the service. A request's address can contain:
- your device ID
- the coordinates you asked about
- place names you typed for a route
Our server's logs do not record your IP address. Our security and delivery provider, Cloudflare, does see it, as described below.
Sign-in, notifications and purchases (planned)
None of these features is active in this release. We list them so you know what will change.
- Sign-in (planned): Google Firebase Authentication. If you sign in, Google processes, on our behalf:
- your sign-in identifiers: a Firebase user ID and the sign-in method;
- your email address, if the sign-in method uses one (for example email or Google sign-in).
Sign-in is optional for the free version. It is required to buy a paid plan (Pro or StormTracker), because a purchase is tied to an account. If you sign in, we link your data to your account, so you can keep it across devices and delete it by account.
- Notifications (planned): Google Firebase Cloud Messaging. Google receives a notification token for your device and the text of each notification. You can turn notifications off in the app or in your phone's settings.
- Purchases (planned): RevenueCat, with the Google Play and Apple app stores. If you buy a subscription:
- The app store handles the payment. We never see your card details.
- RevenueCat receives your purchase receipts and an app user ID, so it can confirm what you bought.
Who else receives data
Service providers that process data for us:
| Provider | What they receive | Purpose |
|---|---|---|
| Cloudflare (USA) | All traffic between the app and our server, including your IP address | Security, delivery and encryption (HTTPS) |
| Hetzner Online (data center in Helsinki, Finland) | Our server and everything stored on it | Hosting |
| Fireworks AI, DeepInfra, Groq (USA) | Chat questions, conversation context, location of the question, text of favorites, plans and preferences; never your device ID | Writing answers (see above) |
| GitHub (Microsoft, USA) | Encrypted backup files they cannot read | Off-site backup |
| Google Firebase (USA), *planned* | Sign-in identifiers, email if the sign-in method uses it, notification tokens and notification text | Sign-in and notifications |
| RevenueCat (USA), *planned* | Purchase receipts and an app user ID | Subscriptions |
Public data services: we look up information for the place you asked about. These services receive the place's coordinates, or a place name you typed. They receive them from our server, without your device ID or IP address.
- US National Weather Service: forecasts and alerts.
- US EPA AirNow: air quality.
- UK Met Office: UK weather warnings.
- OpenStreetMap Nominatim: turns place names into coordinates. For naming a spot on the map, it receives coordinates rounded to about 1 km.
- Project OSRM: the start and end points of a route, to calculate the drive.
Maps: radar, satellite and base-map images all load through our own servers. The image providers see only our server, never your IP address. They include Iowa Environmental Mesonet at Iowa State University and NASA GIBS.
These services have their own privacy policies.
We do not sell or share personal data for advertising, and we do not use data brokers.
Where your data is stored
Our server is in Helsinki, Finland (EU). We are a US company, and some of the providers above are in the USA. So data about you is handled in the EU and the USA.
If you are in the EU, UK or Switzerland, your data is transferred to the USA. We are putting data processing agreements, including the EU Standard Contractual Clauses, in place with these providers.
Backups
Each night we make an encrypted backup of the server. It includes the databases for:
- chat history
- saved places and preferences
- usage counts
- weather-alert areas
- weather reports
- the notification registry
We keep the last 7 nightly backups. So data you delete can remain in an encrypted backup for up to 7 more days, and then it is gone.
How long we keep data
| Data | How long |
|---|---|
| Chat conversations | 30 days after the last message, or until you delete them. Paid subscribers (once paid plans launch): up to 12 months while subscribed. |
| Diagnostic chat logs | We are setting a 30-day limit |
| Ratings, feedback, reported answers | 180 days (automatic deletion of reported answers is being set up) |
| Plans | 24 hours after the event ends |
| Tracked-drive records | Deleted more than 7 days after the drive ends; your position is erased when the drive ends |
| Shared links | 90 days, or until you delete the link or your data |
| Preference-effect records | We are setting a 12-month limit |
| Saved places, favorites, preferences, alert areas, weather reports, beta feedback, requests for new data | Until you delete them or delete your data |
| Usage counts | Until you delete your data |
| Server request logs | About 14 days |
| Encrypted backups | 7 days |
Deleting your data
- In the app: go to Settings → Your data → Delete. The app first shows what will be deleted, and then you confirm. Everything stored under your device ID is deleted right away:
- your profile fields
- preferences, saved places, favorites and plans
- chat history
- ratings and reports
- usage counts
- alert areas
- weather reports
- beta feedback
- requests for new data
- all of your shared links
- records of how your preferences changed answers
You get a confirmation listing what was removed.
- A copy of your data: Settings → Your data → Download gives you one file with everything stored under your device ID.
- By email: write to [email protected]. We will delete the data within 30 days.
- Include your device ID. You can find it at Settings → Your data → Your device ID. The row shows the start of the ID; tap it to copy the full ID, then paste it into your email.
- Once sign-in launches, you can instead write from the email address of your account.
- We can only find your data with your device ID or, once sign-in launches, your account. If we cannot identify your data, we will tell you. Data from an install you no longer use stays until the limits above remove it.
- What deletion can't reach:
- server logs (gone within about 14 days)
- diagnostic logs (we are setting these to be deleted after 30 days)
- encrypted backups (gone within 7 days)
- data held by Cloudflare and the AI providers under their own terms
Full details: https://api.skylarweather.com/legal/account-deletion.
Your rights
Depending on where you live, you may have the right to:
- access, correct, delete or get a copy of your data
- object to or restrict how we use it
If you are in the EU or UK, you can also complain to your local data protection authority.
To use any of these rights, use the in-app tools or email [email protected]. We will not treat you differently for using them.
Children
Skylar is not directed to children under 13 (or under 16 in the EU and UK), and we do not knowingly collect their personal data. Parents can use Skylar's child sensitivity setting to plan activities for a child. That setting is about the child's comfort and safety in the weather, and it collects nothing about the child.
If you believe a child has given us personal data, email [email protected] and we will delete it.
Security
How we protect data:
- Traffic between the app and our server is encrypted.
- Our databases are reachable only on the server itself.
- Administrative tools need a separate key.
- Backups are encrypted.
No system is perfectly secure.
Changes to this policy
We will post any change on this page and update the effective date. If a change is significant, we will also tell you in the app.
Contact
Skylar Weather LLC, North Carolina, USA. Email: [email protected]