Storm Window — Privacy Policy
Storm Window is an activity-aware outdoor weather planning app. We designed it to need as little of your information as possible. We do not require an account, and we do not use advertising or cross-app tracking of any kind. Most app data stays on your device. If you opt in to Pro+ backend safety alerts or leave Pro+ server-generated Advisor narratives enabled, Storm Window sends limited feature data to SiPhy’s backend so those features can work; see below.
Summary
- We don’t collect personal information such as your name, email, or contacts.
- Your location is used only to retrieve a forecast for your area, personalize local risk guidance on your device, and, if you opt in, evaluate Pro+ backend safety alerts.
- Your saved locations, activity profile selections, and optional personal profile settings are stored on your device and shared with Storm Window widgets and Apple Watch support on your devices where needed.
- Pro+ Advisor narratives — hourly rating explanations, hazard education cards, “Should I Go?” recommendations, forecast-change explanations, and the 3-Day Summary — may use SiPhy’s backend and OpenAI when server-generated Advisor narratives are enabled, Apple Intelligence on device as a fallback (except hazard education, which falls back directly to Storm Window’s own text), or Storm Window’s own plain-language text. You can turn off server-generated Advisor narratives in Storm Window Settings.
- To produce a forecast and focused map context, approximate coordinates or the viewed map area are sent to third-party weather services (Open-Meteo and the U.S. National Weather Service / NOAA services, including nowCOAST, Digital Weather/NDFD, and HRRR wind data) and to Apple for place-name lookup. Pro Flow wind-map requests use SiPhy’s backend to fetch NOAA HRRR wind vectors for the viewed map area.
- If you use Storm Window Pro personalization, optional age range, heat tolerance, and air-quality sensitivity settings are used only on device to adjust risk classifications and recommendations. They do not change the reported weather values.
- If you subscribe to Storm Window Pro or Pro+, purchase and entitlement status is processed by Apple and RevenueCat so the app can unlock paid features and restore purchases.
- If you enable imminent hazard alerts or Pro+ proactive Safety Alerts, those notifications are scheduled locally on your device from the latest forecast unless a specific backend delivery path is enabled.
- If you opt in to Pro+ backend safety alerts, SiPhy’s backend stores the limited registration data needed to evaluate those alerts: an anonymous device identifier, subscription tier, enabled alert categories and drivers, a coarsened forecast grid location, location display name, and an activity profile selection for each activity you watch there. Precise GPS is not sent to or stored by SiPhy for these alerts; the app rounds coordinates on device to a 0.1 degree grid, roughly 11 km, before upload.
- If you opt in to push notifications, we use OneSignal to deliver them. OneSignal receives a push token, delivery metadata, and the notification payload needed for delivery — not your saved-location list, activity profile settings, personal profile settings, or precise GPS location.
- There are no ads and no advertising or cross-app tracking SDKs in the app.
Information the app uses
Location. With your permission, Storm Window can request a location fix to set your forecast area. For typed locations or one-time current-location setup, Storm Window uses a city-scale forecast location. If you enable Follow My Location, the app may refresh your location when you open or foreground the app so the active forecast can move with you. Storm Window does not continuously track your location in the background. Backend alert, Plan monitoring, and Live Activity update paths use a coarsened forecast grid rather than precise GPS; the app rounds coordinates on device to a 0.1 degree grid, roughly 11 km, before uploading those registrations. You can also skip location permission entirely and type a city, state, or ZIP/postal code.
Location storage. Your chosen location and the most recent forecast are cached locally on your device in a shared app container so the app and its home-screen/lock-screen widget can display your forecast without re-fetching. This data stays on your device.
Profiles and preferences. Storm Window may store saved locations, location names, activity profile selections, activity settings, and optional personal profile settings such as age range, heat tolerance, and air-quality sensitivity. These settings are stored on your device and used to personalize hazard states, recommendations, widgets, Apple Watch views, and safe-window calculations. If you opt in to Pro+ backend safety alerts, the backend receives the activity profile selection and alert preferences needed to evaluate those alerts, but not your custom activity profile details or personal profile settings.
Outdoor Session state. Outdoor Session keeps the current verdict, activity, selected place, start time, expected end, remaining low-risk time, and session controls available to supported iPhone, Apple Watch, widget, Lock Screen, Dynamic Island, Siri, Shortcut, and Control Center surfaces on your devices. This state is stored locally in the shared app container. Where Pro+ backend Live Activity updates are enabled, Storm Window may register limited session metadata such as anonymous device ID, session ID, coarsened forecast grid cell, activity label, location display name, expected end, and expiry so the backend can update or end the Live Activity while the app is not foregrounded. Storm Window does not use Outdoor Session as a workout tracker and does not collect pace, distance, calories, heart-rate data, route history, or precise GPS for Outdoor Session backend updates.
Advisor guidance. Storm Window Pro+ can explain already-calculated forecast guidance in plain language for hourly ratings, hazard education, “Should I Go?” recommendations, and forecast-change explanations. When server-generated Advisor narratives are enabled, the app requests this text from SiPhy’s backend and OpenAI first, using the limited forecast facts described below under “Server-generated Advisor narratives.” If that path is unavailable or the generated text is rejected, the app falls back to Apple Intelligence on supported devices (except hazard education, which falls back directly to Storm Window’s own explanation), and finally to Storm Window’s own plain-language text. The app keeps the deterministic risk rating as the source of truth at every step. On-device Apple Intelligence prompts and generated explanations are not sent to SiPhy.
Map imagery and wind-flow context. Storm Window can request focused Lightning Map and Wind Map imagery from NOAA/NWS nowCOAST and NOAA Digital Weather/NDFD. These map requests include the viewed map area or bounding box, requested weather layer, requested product time when selected, and normal technical request information needed to return an image or sampled wind context. When Pro Flow is selected, Storm Window sends the viewed map area, grid size, and forecast hour to SiPhy’s backend so the backend can fetch NOAA HRRR U/V wind vectors and return a regular wind grid. Storm Window does not include your name, account, saved-location list, custom activity profile details, personal profile settings, OneSignal identifier, or DTN identifier in NOAA map requests or wind-flow grid requests.
Server-generated Advisor narratives. Storm Window Pro+ can use SiPhy’s backend and OpenAI to generate Advisor narrative text — the 3-Day Summary, hourly rating explanations, hazard education cards, “Should I Go?” recommendations, and forecast-change explanations — when the feature is enabled. Every narrative sends an anonymous device identifier, generated time and timezone, activity label, and prompt version, plus facts specific to that narrative: forecast period, current risk and status, safe-window guidance, next lower-risk window if any, unsafe blocks, and dominant hazards for the 3-Day Summary and “Should I Go?”; the specific hazard or factor, its value, and threshold context for hazard education; and the previous and current risk assessments and changed factors for forecast-change explanations. The backend validates generated text against Storm Window’s deterministic forecast facts before display. It does not send saved-location names, plan titles, user notes, precise GPS, custom activity profile details, or personal profile settings. You can turn off server-generated Advisor narratives in Storm Window Settings.
On-device notifications. If you choose to enable imminent hazard alerts or Pro+ proactive Safety Alerts, Storm Window asks iOS for notification permission and schedules local notifications from the relevant cached forecast — the active location for imminent hazard, saved-location caches for Pro+ Safety Alerts, or a pinned plan’s own cached forecast for Plan forecast changed alerts. These local alerts are computed and scheduled on your device unless a specific backend delivery path is enabled.
Pro+ backend safety alerts. If you opt in to Pro+ backend safety alerts, Storm Window sends SiPhy’s backend limited alert-registration data: an anonymous device identifier, subscription tier, enabled alert categories and hazard drivers, coarsened forecast grid location, location display name, and an activity profile selection for each activity you watch there — if a location is watched for more than one activity, the backend registers one such entry per watched activity so it can evaluate each one, but still combines them into a single alert rather than sending one per activity. The app rounds coordinates on device to a 0.1 degree grid, roughly 11 km, before sending the registration. The backend uses this data only to evaluate and deliver opted-in safety alerts. Precise GPS is not sent to or stored by SiPhy for these alerts.
Push notification delivery. Push notifications are delivered through OneSignal, a third-party push service. To deliver them, OneSignal registers a push subscription for your device and receives a push token, standard technical and delivery information, and the notification payload. OneSignal may also receive basic tags such as platform, subscription tier, and enabled notification categories. OneSignal does not receive your saved-location list, activity profile settings, personal profile settings, or precise GPS location. You can turn off individual categories in the app, or disable notifications for Storm Window entirely in iOS Settings, at any time.
Plans. Storm Window Pro+ lets you pin a future start time, end time, place, and activity, including planned commitments beyond the normal 72-hour home view. A pinned plan’s location and its forecast are stored on your device the same way saved locations are, independent of your saved locations list, and are used to show you that plan’s forecast and, if enabled, a Plan forecast changed alert as forecast data becomes available. Backend Plan monitoring is limited to Pro+ alert paths you enable; tutorial sample Plans are local-only fixtures and are not registered for backend monitoring. Plan titles, user notes, and saved plan details are not sent to OpenAI for Advisor narratives.
Subscriptions. Storm Window Pro and Pro+ purchases are handled by Apple’s in-app purchase system. The app uses RevenueCat to validate receipts, restore purchases, and mirror whether the pro or pro_plus entitlement is active. RevenueCat receives purchase and entitlement data needed to provide that service; it does not need your Storm Window location or forecast cache.
Information sent off device
To turn a location into a forecast, the app sends approximate geographic coordinates (and, for text searches, the place name or ZIP you enter) to weather and place-name services. To draw focused weather maps, the app sends the viewed map area, weather layer, selected product time, and sampled map context to NOAA/NWS services as needed. Pro Flow sends the viewed map area, grid size, and forecast hour to SiPhy’s backend so it can fetch NOAA HRRR wind vectors. Pro+ backend safety alerts, Plan monitoring, and backend Live Activity updates use coarsened coordinates rounded on device to a 0.1 degree grid, roughly 11 km, or a derived forecast-grid-cell identifier. Server-generated Advisor narratives use the limited forecast facts described above. Storm Window does not send your name, contacts, precise GPS, personal profile settings, full Outdoor Session state, or any account information, because the app has none.
- Apple MapKit — converts place names to coordinates and coordinates to a display name (e.g., “Tampa, FL”). Governed by Apple’s Privacy Policy.
- Open-Meteo — provides the hourly storm, heat-index, wind-chill, UV, air-quality, and marine forecast data. See the Open-Meteo terms.
- U.S. National Weather Service / NOAA — provides thunderstorm-probability data for U.S. locations, focused nowCOAST map imagery for radar, lightning activity density, wind speed, wind direction, and gust context, NOAA Digital Weather/NDFD sampled wind context for sparse Wind Map arrows, and HRRR U/V wind-vector data used by Pro Flow. See the NWS privacy policy.
- RevenueCat — validates in-app purchases and subscription entitlements for Storm Window Pro and Pro+. See the RevenueCat privacy policy.
- SiPhy backend — evaluates opted-in Pro+ backend safety alerts, fetches NOAA HRRR wind grids for Pro Flow, and, when enabled, brokers Pro+ server-generated Advisor narratives using the limited data described above. It is operated by SiPhy and is separate from OneSignal.
- OpenAI — generates Pro+ Advisor narrative text — the 3-Day Summary, hourly rating explanations, hazard education cards, “Should I Go?” recommendations, and forecast-change explanations — from limited forecast facts when server-generated Advisor narratives are enabled. It does not receive precise GPS, saved-location names, plan titles, user notes, custom activity profile details, or personal profile settings. See the OpenAI privacy policy.
- OneSignal — delivers push notifications if you opt in. It receives a push token, notification payload, basic tags, and standard delivery information as described above — not your saved-location list, activity profile settings, personal profile settings, or precise GPS location. See the OneSignal privacy policy.
The weather and place-name providers receive only the coordinates, search text, or viewed map area needed to return a forecast, map image, or wind context for that area; RevenueCat and OneSignal receive only what is needed to provide subscriptions and notifications, respectively. SiPhy’s backend receives only the data needed for opted-in Pro+ backend safety alerts, Plan monitoring, backend Live Activity updates, Pro Flow wind-grid requests, and enabled Pro+ server-generated Advisor narratives. Backend alert, Plan, and Live Activity location registrations use coarsened grid locations, not precise GPS. We do not control, and are not responsible for, the independent data practices of third-party services; please review their policies.
What we do not do
- We do not require an account or collect your name, email, contacts, or address book.
- We do not send or store precise GPS location, full forecast caches, custom activity profile details, personal profile settings, route history, plan titles, or user notes on SiPhy servers. Backend alert, Plan, and Live Activity location registrations use coarsened grid locations. Backend Live Activity support stores only limited Outdoor Session metadata needed to update or end the active Live Activity.
- We do not sell or share your information.
- We do not use advertising, ad networks, or cross-app/cross-site tracking technologies. Aside from OneSignal’s standard push-delivery data (only if you opt in to notifications) and RevenueCat’s purchase validation, we do not use analytics or crash-tracking SDKs.
- We do not track you across apps or websites.
Data retention and your choices
- On-device data: Your cached location, forecast, saved locations, activity settings, and personal profile settings remain on your device until you change or reset them within the app, or delete the app.
- Backend alert data: If you opt in to Pro+ backend safety alerts, limited alert-registration data remains on SiPhy’s backend while the alert feature is enabled. Turning off those alerts, removing the location, or losing Pro+ access causes the app to unregister or update that backend registration.
- Server Advisor data: If server-generated Advisor narratives are enabled, SiPhy’s backend may temporarily cache accepted narratives by forecast fingerprint and prompt version to reduce repeat OpenAI calls. The backend records aggregate operational metrics such as request counts, acceptance counts, rejection reasons, latency, and estimated cost. It does not store raw prompts, generated Advisor text, precise GPS, plan titles, user notes, custom activity profile details, or personal profile settings as persistent user records.
- Location permission: You can grant or revoke location access at any time in the device’s Settings. Revoking it does not stop the app from working — you can still search by place name or ZIP.
- Deletion: Deleting Storm Window removes all locally stored data associated with the app.
Children’s privacy
Storm Window is a general-audience app and is not directed to children under 13. We do not knowingly collect personal information from children.
International users
The weather services above may process requests on servers located in the United States or elsewhere. By using the app to request a forecast, you understand that approximate location coordinates are transmitted to those services to fulfill your request.
Changes to this policy
We may update this policy from time to time. Material changes will be posted at StormWindow.SiPhy.com with an updated effective date.
Contact
Questions about this policy? Contact SiPhy LLC at support@StormWindow.SiPhy.com.