Privacy policy
Draft for review. This policy is not yet in effect and has not been reviewed by a lawyer. It describes the app as planned and will be checked against the released app before it is published.
TODO before publishing: follow the go-live gate in docs/DEPLOY.md (remove this notice and the noindex tag, add this page to the sitemap, set the date, and confirm every statement against the shipped server and app).
Draft of 10 October 2026. WeatherSafeAlerts is made by John Larson.
The short version
WeatherSafeAlerts has no accounts, and it does not ask for your name, email address or phone number. It contains no analytics, advertising or tracking code. Your exact location and your alert history stay on your phone.
Private here means three things: we do not track you, we do not collect data to sell, and we do not share anything with advertisers or data brokers.
To decide which warnings to send you, our server has to know a few things: the rounded areas you want alerts for, each about 2 km across, which kinds of alerts you chose, and what it needs to reach your phone. Records you stop renewing are removed after 30 days, and Delete my data in the app removes them at once.
What stays on your phone
- Your exact location, when you let the app use it. The phone rounds it to an area about 2 km across before anything is sent.
- The names you give your places, such as Home or Work.
- Your alert history. Our server keeps only a short note of which alerts it sent, so you do not get duplicates: 72 hours, or until the warning ends if that is later, and never more than 14 days. Your history is on your phone. You choose how long the phone keeps it, and you can clear it at any time.
- The app's private keys, held in your iPhone's Secure Enclave. They never leave the phone.
What our server stores
| What | Why | How long |
|---|---|---|
| A random device ID, made up by the app | To tell installs apart. It is not tied to your name, Apple Account or phone number. | Until your record lapses or you delete it |
| Two public keys from your phone | One checks that requests really come from your phone. The other is used to encrypt alerts so only your phone can read them. | Same |
| An Apple push token | So Apple's push service can deliver to this phone. | Same |
| Rounded areas for up to 10 places, each about 2 km across (a 0.02 degree grid) | To know which warnings apply to you. If you choose to follow your location, the phone sends a new rounded area only when you have moved a good distance. | Same |
| Your alert choices for each place, and whether you allowed Critical Alerts in iOS | To send the kinds of alerts you asked for, at the level you chose. | Same |
| Alerts not yet delivered, encrypted | So an alert can still reach a phone that was briefly offline. | Up to 24 hours, or until your phone confirms it arrived |
| A note of which alerts were sent to your device | So you do not get the same alert twice, and so the server knows when a warning you were sent has ended. | 72 hours, or until the warning ends if that is later; never more than 14 days |
| Short-lived security records | A one-time code used when the app registers, single-use request numbers that stop a recorded request from being replayed, and a session for loading radar. | Registration codes 5 minutes; request numbers 10 minutes; radar sessions 1 hour |
| An Apple App Attest key: a random key ID, its public key and a counter | Apple's way of showing that requests come from a genuine copy of the app on a real iPhone. It holds no location, choices or push token. | While your record exists. If your record lapses, up to 400 days so the phone can sign back in. Delete my data removes it at once. |
| Public weather details for an area, such as which county and forecast zone it is in | A cache of public weather service data, so the server does not ask again for each phone. It is kept per area, not per person. | Up to 30 days |
| Recent storm positions taken from public warnings | To estimate how far a storm is and whether it is moving toward a place. Kept per storm, not per person. | 6 hours |
Renewal and expiry. The app checks in with the server regularly, usually about once a day. Each check-in renews your record for 30 days. If the app stops checking in, for example because you deleted it, your record, places, choices, waiting alerts and sent-alert notes are removed 30 days later. Only the App Attest key described above is kept, for up to 400 days, so a returning phone can register again.
Radar. Radar images load through our server. It sees which map areas you view for radar and keeps nothing about that beyond short-lived caches of the public radar images.
Server logs hold counts and only short, non-identifying fragments of IDs, for troubleshooting. They do not hold your areas, your push token or the text of your alerts, and they are kept for 7 days.
How an alert reaches you
Our server reads the weather service's warnings, matches them against the rounded areas and choices it holds, and writes the alert for your phone. The server therefore sees the alert in plain text, as it is the one writing it.
Warnings drawn as an outline on the map, such as tornado warnings, are matched to your places right away. Alerts issued for whole forecast zones, such as most watches, depend on extra weather service data about each area, so when that data is slow, a place may get them a little later.
It then encrypts the alert on our server to a key only your phone holds, and hands it to Apple's push service. Your phone unlocks the alert and stores it.
To Apple, the alert itself is unreadable. Apple can see that a notice was sent to your phone and when, how urgently it should be shown, and when it expires. It also sees a label that lets an update replace an earlier notice; that label is an unreadable value made separately for your phone and does not say which warning it is.
This is not end-to-end encryption between you and someone else. What limits what our server knows is that it is given so little: rounded areas, no identity, no alert history, and records that expire.
Who else handles data, and what they see
- Apple delivers notifications using your push token, as described above, and checks the App Attest key when the app registers. The map and place search in the app use Apple Maps, under Apple's privacy policy.
- Cloudflare sits at the network edge in front of our server. It sees your IP address as each request passes through, under Cloudflare's own privacy policy; we do not ask it to keep anything for us. Because Cloudflare forwards requests to our server, it can also see the registration details on their way (public keys, push token, rounded areas and choices), but not the content of your alerts. It also sees radar session and radar image requests, and the tile coordinates in those requests show which map areas you load. Our server limits how often one IP address can call it, and those counters are held in memory and dropped after about 10 minutes.
- The National Weather Service and NOAA. Forecasts, warning outlines and storm outlooks (from NOAA's Storm Prediction Center) are requested by the app directly from the weather service and NOAA, so they see your IP address and the area requested: a rounded area, or the states on screen. Radar is different: it goes through our server, so NOAA does not see your IP address for radar.
What we do not do
- No accounts, no email address, no phone number.
- No analytics, advertising or tracking code, and no crash-reporting service of our own. If you have chosen in iOS to share diagnostics or App Store usage statistics with app developers, Apple may pass along anonymous crash reports and usage figures.
- No selling or renting of your data. It goes only to the services listed above, and only to deliver alerts.
- No sharing with advertisers or data brokers.
- No storing your exact location on our server. The phone rounds it first.
- No alert history on our server, beyond the short note that prevents duplicates (72 hours, or until the warning ends if that is later, at most 14 days).
Deleting your data
In the app, Settings, Delete my data removes everything our server holds for your phone: device ID, public keys, push token, places, choices, waiting alerts, sent-alert notes and the App Attest key. It then erases the keys, places and alert history on your phone. The one exception is the public weather details cached per area: they are not linked to you or your phone, and may stay for up to 30 days.
If our server cannot be reached at that moment, the app offers to erase everything on your phone now and shows the date by which the server copy will lapse on its own. The next time the app opens, it tries the server deletion once more.
No guarantee
WeatherSafeAlerts relays warnings as fast as it can, but an alert can be late or never arrive: phones run out of battery, networks fail, and services along the way, including ours and Apple's, can go down. Keep a second way to hear warnings, like a weather radio. The government alerts your iPhone receives on its own, such as Wireless Emergency Alerts (Settings, Notifications, Government Alerts), are separate from this app and keep working without it.
Where the weather data comes from
Warnings, forecasts and radar come from the National Weather Service and NOAA, whose data is in the public domain. WeatherSafeAlerts is not affiliated with or endorsed by the National Weather Service, NOAA or FEMA.
Children
The app is not directed at children, and it collects no name, contact details or exact location from anyone.
This website
This site sets no cookies, runs no scripts and loads nothing from other companies. Its font is served from the site itself. The company that hosts the site handles your IP address in order to send you the pages.
Changes and contact
If this policy changes, the date at the top changes with it, and changes to what the app stores are made in the same release as the app change. Questions: john@jjlarson.com.