Privacy notice

Controller and contact details

Giuseppe Nesca

Privacy: giuseppenesca87@gmail.com
Support: giuseppenesca87@gmail.com

At a glance: no account

SkyRewind does not require registration. This notice describes versions 1.0 and 1.0.1, which have no advertising, purchases, advertising SDKs or commercial behavioural analytics. We do not sync an account or favourites to the cloud and do not sell users’ data.

Weather features require the requested location to be sent to the service and, in versions offering manual search, the search text. Having no account does not mean that no data is processed: the sections below distinguish local data, service data and providers’ technical data.

On your device

Version 1.0 supports up to five saved cities plus a separate GPS location: the list, order, home location and last selected location remain on your device. Version 1.0.1 follows your current GPS location and does not present a list of favourite locations. It stores the identifier of the approximate GPS weather location or the single manually chosen town, settings and reminder preferences locally. Temporary weather copies are also kept locally; application cleanup makes copies older than 48 hours and malformed data eligible for removal.

Your phone also stores signed location tokens, valid for 90 days, and sends them back when requesting history preparation. They are not accounts or advertising identifiers and do not contain the server secret. Original GPS coordinates and accuracy are not saved in preferences; they may be kept in memory during use to assess movement and limit repeated requests. Removing a local preference does not delete the shared weather archive. App-container deletion and system copies depend on iOS settings and behaviour.

Location and manual alternative

When you use manual search, search text is sent over HTTPS to our Cloudflare service and, when not already cached, to Open-Meteo geocoding. Search is intended for locations: do not enter private addresses, people’s names or other unnecessary information. Normalised text is retained in a shared cache, not an account-level search history.

First launch in version 1.0.1 offers device location. Location is acquired only with iOS permission: you may deny it or revoke it in iOS Settings. The phone sends coordinates and accuracy to the Cloudflare service, which reduces coordinates to the centre of a geographical cell a few kilometres across, varying with latitude, before storing them or contacting Open-Meteo. The application database does not retain the original precise coordinates or accuracy. This reduces precision but does not guarantee anonymity.

If you deny GPS permission, you can choose one town manually in version 1.0.1 to view weather, forecasts and history without sharing device location and without adding other locations or favourites. The town is labelled as manual and does not follow your movements; a new manual choice replaces the previous one. You can return to GPS mode by granting permission: if you re-enable it in iOS Settings, the app may resume GPS when you reopen it.

We retain the approximate centre and a shared cell identifier to reuse weather data. The application database does not keep a movement trail for each user. There is no background location tracking. In the mode that follows GPS, the app checks location only in the foreground and with existing permission, including when you return to the app. It reduces service requests when no significant movement is detected and reuses available weather data. The weather-cache reuse period does not describe how often GPS is checked. Permission may be revoked in iOS Settings.

Purposes and legal bases

We process searches, requested locations and strictly necessary technical data to provide the weather features and support you request: performance of the service under GDPR Article 6(1)(b). Without a requested location we cannot display its weather. Device location is optional and based on consent under Article 6(1)(a); you may withdraw it without affecting earlier lawful processing.

To prevent abuse, maintain availability and reduce repeated provider requests, we use pseudonymous counters and shared caches: legitimate interests under Article 6(1)(f). We limit counter data and retention, keep counters separate from searches and cells in the database and do not use them for advertising. You may object or request information about the balancing of interests using the privacy contact.

Data-rights requests and processing required by law rely on Article 6(1)(c). We do not make solely automated decisions with legal or similarly significant effects on you or carry out commercial profiling.

Service retention and security

Forecasts: 30 minutes of ordinary reuse and up to six hours as clearly marked stale data. Copies become eligible for deletion two days after the reuse window ends. Search: one day of ordinary reuse and up to seven days of reuse when needed; copies become eligible for deletion after two further days. Cleanup is periodic and batch-limited, so physical deletion does not necessarily happen at the exact expiry time.

Locations, approximate cells and historical reanalyses form a shared weather archive without account associations. They are kept for the operation of the service and have no automatic inactivity expiry. This is not a personal history; removing a favourite does not delete these common data.

To enforce request limits, we derive a daily HMAC cryptographic key from the IP address and retain counts by operation type. The application database does not write the original IP address. The key is pseudonymous, not anonymous. Client counters expire within 24 hours; aggregate minute/hour quota counters after two days and day/month counters and admission metadata after 32 days. Periodic batch cleanup follows.

D1 also maintains a Time Travel recovery window: Cloudflare documents seven days on the Free plan and 30 days on the Paid plan. Data removed from the operational database may therefore remain recoverable in recovery copies during the applicable window. Relevant deletions must be reapplied after a restore.

Requests use HTTPS. Per-request application logs are disabled in the release configuration; this does not disable network and security data processed by Cloudflare or the provider logs described below. History-preparation jobs contain location and month references, not a user account.

Providers and international transfers

Cloudflare provides HTTPS, Workers execution, the D1 database and processing queues. It processes service content on the controller’s behalf under applicable terms and also acts as an independent controller for some network and security data. It may process IP addresses, traffic metadata and security data. Its network is global, with possible processing in the United States and other countries: an indicative database location does not guarantee that all processing stays in the EEA. Its DPA describes the Data Privacy Framework for covered transfers and Standard Contractual Clauses where applicable. Information about providers, safeguards and copies of those safeguards is available through the links below or on request using the privacy contact.

OpenMeteo GmbH, Switzerland, receives search text and city coordinates or approximate GPS cell centres from our backend. Our code does not forward the phone’s IP address or advertising identifiers to Open-Meteo. The provider states that its technical logs may contain coordinates and are deleted after 90 days. Switzerland benefits from an EU adequacy decision; this does not identify the location of every part of the provider’s infrastructure.

Reminders and voluntary contact

The daily reminder is optional, local and managed by iOS. We do not register push tokens on the server or send backend notifications. It is not a weather warning or an updated forecast while the app is closed. Turn it off in the app or revoke permission in iOS Settings.

If you email support or the privacy contact, we receive your email address, message and any attachments to respond. The listed mailbox uses Gmail, so messages are also processed by Google’s email service under its terms. They are not added to marketing lists. Retention depends on handling your request: after closure, only messages needed to document obligations or handle possible disputes are retained for the period relevant to those purposes. Do not send passwords or unnecessary sensitive information.

Your rights and choices

You may request access, rectification, erasure, restriction, objection and, where applicable, portability by writing to the privacy contact above. A response is due without undue delay, normally within one month; any GDPR-permitted extension must be communicated and explained. You may withdraw location and notification consent without affecting earlier processing.

The app has no account with which to identify you. Limited additional information may be needed to locate the data a request concerns. We do not collect new identifiers merely to reconstruct a personal history. Rights apply to your personal data, not indiscriminate deletion of the common weather archive.

You may lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it) or another competent supervisory authority, such as the authority where you live or work. Changes to this notice show an updated date. Incompatible new purposes or new optional features will require information and, where necessary, a new choice.

Provider documents and supervisory authority