Weather InTouch
Home Features Pricing Blog
English
  • English
  • Čeština
  • Deutsch
  • Español
  • Français
  • Italiano
  • Polski
  • Português
  • Русский
  • Українська
  • 中文
  • 日本語
  • 한국어
  • हिन्दी
  • العربية
  • Türkçe
  • Nederlands
  • Bahasa Indonesia
  • Tiếng Việt
  • ไทย
Home Features Pricing Blog

Language

  • English
  • Čeština
  • Deutsch
  • Español
  • Français
  • Italiano
  • Polski
  • Português
  • Русский
  • Українська
  • 中文
  • 日本語
  • 한국어
  • हिन्दी
  • العربية
  • Türkçe
  • Nederlands
  • Bahasa Indonesia
  • Tiếng Việt
  • ไทย
Weather InTouch

Privacy Policy

Last updated: Jun 9, 2026

1. Who we are (Data Controller)

Weather InTouch (“we”, “us”, “the Service”) at weatherintouch.com and app.weatherintouch.com is operated by:

  • Controller: Martin Hubálek, self-employed individual (OSVČ), Business ID (IČO) 08827303
  • Address: Dolní Štěpanice 29, 514 01 Benecko, Czech Republic
  • Contact / privacy requests: privacy@weatherintouch.com

We are the controller for personal data processed through the marketing website, the web application, and the backend API.

2. Scope

This policy applies to:

  • weatherintouch.com — marketing website (static), newsletter sign-up.
  • app.weatherintouch.com — the weather web application.
  • api.weatherintouch.com — backend API serving weather, geocoding and alerts.

It does not cover third-party sites we link to, which have their own policies.

3. What we process and why

Data Purpose Legal basis (GDPR Art. 6)
IP address (transient) Deliver the requested forecast/map/radar; security, rate-limiting, abuse prevention. Processed technically; not used for cross-site tracking or profiling. Legitimate interest (6(1)(f)) / performance of requested service (6(1)(b))
Approximate/precise location (if you grant browser geolocation, or a place you search) Show weather for your location Consent (6(1)(a)) for device geolocation; otherwise your explicit search input
Preferences (theme, units, language, saved places) Remember your settings (stored locally in your browser) Necessary for the service you requested
Account data (email, OAuth identifier from Google/Apple) — only if you create an account (P1) Authentication, account management Performance of contract (6(1)(b))
Newsletter email Send the newsletter you signed up for Consent (6(1)(a))
Billing data (Stripe customer/subscription IDs, transaction records) — only if you subscribe (P2) Process payments, comply with accounting law Contract (6(1)(b)) + legal obligation (6(1)©)
Analytics & error data (only after you opt in) Understand usage, fix crashes Consent (6(1)(a))
AI assistant prompts & conversations (your prompt text and the rounded location of the place you ask about; for Plus/Pro, your recent chat history stored on our servers) Provide the AI assistant and AI forecast summaries, and remember your recent conversations if you are a paying user Performance of contract (6(1)(b)); consent (6(1)(a)) for the assistant. Prompts are processed by Google (Gemini API) as our sub-processor; the paid Gemini API is not used to train models — see §5. Optional cloud spoken playback is processed by Google (Cloud Text-to-Speech API), which does not train models on this data.

We do not sell your personal data. We do not use advertising cookies or cross-site tracking.

4. Cookies & similar technologies

See the dedicated Cookie Policy. In short: only strictly-necessary storage runs by default; analytics and error monitoring run only after you opt in through the consent banner. You can change your choice any time via “Manage consent” in the footer.

5. Third-party recipients (sub-processors)

Some features send data (typically your IP, as a technical necessity of any internet request) to third parties. The full register is in the Data Processing & Sub-processors document. Highlights:

  • Weather data providers (Open-Meteo; OpenWeatherMap; and the official national meteorological services we relay severe-weather warnings from — NWS, ČHMÚ, DWD, MET Norway, ECCC, IMD and Met Éireann) — receive a location (and the technically unavoidable IP of any request) to return a forecast or warning; no account identifiers are sent. The full list, including which countries we cover for official warnings, is on our Data Sources & Coverage page.
  • Map & radar tiles (RainViewer / MeteoLab Inc.; CARTO / MapTiler / Protomaps; Mapy.com / Seznam.cz) — your IP reaches these providers only after you actively request the radar/map (click-to-load). We do not auto-load them.
  • Product links (Amazon / Amazon Associates) — your IP reaches Amazon only after you actively click a product link (first-party redirect). We do not send data on page load. Premium subscribers do not see these links.
  • Google (Gemini API) — summarizes and translates free-form warning text and answers the AI assistant; receives the text to process (and, for the assistant, your rounded location and prompt), no account identifiers. The paid Gemini API does not train on this data.
  • Google (Cloud Text-to-Speech API) — converts text into spoken audio for the optional cloud “natural voice” playback; receives only the text to be spoken and a two-letter language code, with no account identifiers. The default voice uses your device’s built-in speech engine, which sends no data. This is a server-to-server call, meaning Google receives our server’s IP address, not yours. Spoken AI assistant replies are never cached, while spoken forecast narratives are cached on our servers for approximately 30 minutes. Google does not train its models on this data.
  • MailerLite — newsletter delivery (only if you sign up).
  • Google reCAPTCHA — newsletter anti-spam (shares IP with Google when the form is submitted).
  • Sentry — error monitoring (only after analytics consent; PII is scrubbed before transmission).
  • Stripe — payments (only if you subscribe; P2).
  • MongoDB Atlas — database (only for account/billing data; P1+).
  • Hosting — Websupport.cz (web/app) and Roští.cz (API).

6. International transfers

Some recipients are outside the EEA (e.g. Sentry, Stripe, Google in the US; RainViewer in Ukraine; Amazon in the US/Luxembourg). Where required, transfers rely on the EU Standard Contractual Clauses, adequacy decisions, or your explicit consent. We minimise transfers and, where feasible, prefer EU-hosted or self-hosted alternatives.

7. Retention

  • Transient IP / request logs: kept only as long as needed for delivery, security and abuse prevention, then deleted or aggregated.
  • Local preferences: stay in your browser until you clear them.
  • Consent record: up to 182 days (then re-asked), or until you change it.
  • Account data: for the life of your account; deleted on erasure request (see §10).
  • AI chat conversations (Plus/Pro): stored on a rolling basis and automatically deleted after 90 days (Plus) or 365 days (Pro); removed immediately when you delete your account. Free-tier chats are kept only in your browser, not on our servers.
  • Waitlist email: kept until we launch and contact you; then deleted if you do not create an account, or retained under the Newsletter rule above if you opted in to updates.
  • Billing/transaction records: retained for the statutory accounting period (5–10 years depending on jurisdiction) in anonymised form after account deletion (financial fields kept, identity removed).
  • Newsletter: until you unsubscribe.
  • Backups: encrypted database backups are kept on a rolling basis; when you delete your account, your personal data is removed from live systems immediately and disappears from backups within 35 days as old backups age out. Backups are never restored selectively to re-introduce deleted data.
  • Audit/security logs: technical security events are kept for up to 13 months and contain no plaintext identity — only irreversible (hashed) references.

8. How we protect your data

TLS in transit, security headers (CSP, HSTS), least-privilege access, secrets kept out of source control, and PII scrubbing before any error report is sent. Authentication uses httpOnly cookies, not browser-accessible storage.

9. Children

The Service is not directed to children under 16 (or the age of digital consent in your country). We do not knowingly collect their data.

10. Your rights

Everyone can: ask what we hold (access), correct it, delete it, object to or restrict processing, export it (portability), and withdraw consent at any time. To exercise these, email privacy@weatherintouch.com. We respond within the legal deadline (e.g. 30 days under GDPR). You may lodge a complaint with your supervisory authority.

Region-specific additions:

  • EU/EEA & UK (GDPR / UK GDPR): rights above; right to complain to your DPA / the ICO.
  • California (CCPA/CPRA): right to know, delete, correct, and to opt out of “sale”/“sharing” — note we do not sell or share personal data for cross-context behavioural advertising; no financial-incentive discrimination.
  • Brazil (LGPD): access, correction, anonymisation, portability, deletion, information about sharing.
  • Canada (PIPEDA): access and challenge accuracy.
  • South Africa (POPIA), Australia (Privacy Act), Switzerland (revFADP): equivalent access/correction/objection rights.

11. Changes

We update this policy as the Service evolves. Material changes are reflected in the version/date above and, where consent is affected, by re-prompting the consent banner.

12. Contact

Privacy questions and requests: privacy@weatherintouch.com.

Weather InTouch

Weather that warns you in time — before conditions change.

Site

Home Features Pricing Blog

Legal

Privacy Policy Terms of Service Cookie Policy Data Sources & Coverage Affiliate disclosure

Notebook

How this was built, the tradeoffs, and what's next.

Read the notes →

© 2026 Weather InTouch. All rights reserved.

Built by Martin Hubalek