Skip to main content
PolyWeather

Privacy

What we collect, and what we don't.

A plain description of PolyWeather's current data posture. It reflects what the product actually does today — not aspirations.

Effective 29 June 2026

What we collect

Account & sign-in. Subscriber accounts are handled by our identity provider. When you sign up or sign in, that provider processes the data you give it (such as your email and authentication credentials). We rely on it for that account record rather than storing passwords ourselves.

Entitlement status. We keep the minimal subscriber metadata needed to gate access — principally whether an account is an approved subscriber — so the subscriber pages can check entitlement.

Billing metadata. If paid billing is enabled, our payment processor may handle checkout, subscriptions, invoices, taxes, and refunds. We may store minimal billing metadata needed to operate access and support, such as customer ID, subscription ID, plan, status, invoice references, and timestamps. We do not store card numbers or full payment credentials.

Usage events. The public pages send a small number of first-party events (for example, a page view or that a visitor scrolled past the hero) to our own endpoint, which records them as structured log lines. These events are limited to a coarse event name, the page path, the referring origin, and which headline variant was shown. We do not load a third-party analytics SDK, and these events are not used to build a personal profile.

Operational & security logs. Like any hosted service, our infrastructure produces server and security logs that can include IP address, user-agent, and request metadata. We use these to keep the service running, diagnose problems, and guard against abuse. In the usage-event path specifically, an IP is only hashed transiently for rate-limiting and is not stored as part of the event.

Cookies and session storage

Signing in relies on necessary cookies and session tokens — set by our identity provider and the app — to authenticate you, keep you signed in, and protect the session against abuse. These are required for the subscriber area to work; if you block them, sign-in will not function. We do not use advertising or cross-site tracking cookies.

What we do not collect or do

We do not sell personal data, run targeted advertising, or share your data with advertisers. We do not custody funds or hold any customer money — PolyWeather never touches your balances. If paid billing is enabled, our payment processor handles checkout and payment method collection.

Server-side service tokens and API keys are operational configuration held on our servers. They are not your personal data and are never exposed to the browser.

Third parties we rely on

Identity provider — subscriber identity, sign-in, and session management. Your account data is processed under that provider's own terms and privacy policy.

Payment processor — if paid billing is enabled, our payment processor may handle checkout, subscriptions, invoices, taxes, and refunds. Payment information is processed under that processor's own terms and privacy policy.

How we use what we collect

To operate accounts and sign-in, to gate subscriber-only pages by entitlement, to administer paid subscriptions and support requests, to keep the service reliable and secure (including rate-limiting and abuse prevention), and to understand aggregate usage of the public funnel. We do not use it to make automated decisions about you beyond checking whether your account is entitled to subscriber access.

Access, deletion, and contact

You can request access to, or deletion of, the account data associated with you. Account and identity data is managed through our identity provider; billing data may also exist with our payment processor where required for payment, tax, invoice, refund, or compliance records. Contact support@polyweather.app and we will act on requests within a reasonable period.

Changes

We may update this page as the product changes. Material changes will be reflected in the effective date above. Related reading: the terms, the refund policy, and the risk disclosure.

About this document

This page is a practical transparency baseline describing what the product does today. It is not legal advice and should be reviewed by counsel before a broad public launch.