Heliocast · Legal
Privacy Policy
Heliocast tells you whether you can see the aurora tonight. It does that without asking who you are: there is no account, no login, no ads, and no tracking or analytics SDK. Your sightings journal, photos and settings stay on your device. This policy explains the small amount of information the app does handle, mainly your approximate location, and, if you turn on Pro alerts, a push token, why we handle it, and the choices you have.
01Who we are
Heliocast ("the app," "we," "us," or "our") is developed and operated by Ingenio Productions. This policy covers the Heliocast mobile application, the Heliocast API that serves it, and this website. It does not cover third-party services that have their own privacy policies, which we identify below.
02The short version
- There are no accounts and no logins. You open the app and it works.
- No ads, no ad SDKs, no advertising identifiers, no analytics or crash-reporting SDK.
- Your sightings journal, photos, alert rules and settings stay on your device. We never upload them.
- Your location is used to answer "can you see it tonight", and is rounded to roughly a kilometre before it reaches our server.
- We only store something about your device on our server if you turn on Pro alerts: a push token and your alert preferences.
- Purchases are processed by Apple or Google and managed for us by RevenueCat. We never see your payment details.
- We do not sell or share your personal information for advertising.
03Information we handle
Information you provide
Heliocast does not ask you to create an account or supply personal details to use it. You give us information directly only when you choose to: setting a home location, or contacting us for support, in which case we receive whatever you include in your message.
Location
Aurora visibility is local, it depends on your latitude, how dark it is where you are, and whether the sky above you is clouded. With your permission, the app uses your device's location (or a home location you set manually) to compute darkness, moon phase, cloud cover and your visibility score.
- Coordinates are rounded to two decimal places (roughly a kilometre) before being sent to our API for a cloud-cover or darkness lookup.
- These lookups are not stored against you - our server fetches the weather, returns it, and caches it by rounded coordinate, not by device.
- If you enable Pro alerts, your rounded coordinates are stored with your alert subscription, because the server needs them to check the sky above you before waking you up.
- You can decline the location permission entirely. The app still works; it just answers in general terms rather than for your exact spot.
Anonymous app identity
To call the parts of our API that are reserved for paying users, the app signs in anonymously with Firebase Authentication. This produces a random identifier for the app installation, not for you. It is not tied to a name, email, phone or profile, it is not used to track you across apps or websites, and it exists so we can (a) confirm a request came from a genuine copy of the app and (b) check whether that installation holds a Pro subscription. It is shown in Settings as your "Device ID" so support can help you.
Alerts (Pro)
If you turn on aurora alerts, we store the following on our server for as long as the alert is active:
- the push token issued to your device by Apple (APNs) or Google (FCM);
- your alert preferences - Kp threshold, cloud-aware on/off, quiet hours and your time zone, and which channels you chose;
- your rounded coordinates, so cloud-aware alerts can be evaluated for your sky;
- a timestamp of the last alert sent, which is how the cooldown works;
Your journal, photos and settings
Sightings you log, the rating, your notes, the captured conditions, and any photo you attach, are stored on your device only. Photos are downscaled on-device and never leave it. The same is true of your alert rules, home location and app preferences. We have no copy of any of it and no way to read it.
Server logs
Like any web service, our API and this website record ordinary request logs - IP address, timestamp, requested path, user agent, generated by our hosting providers (Google Cloud Run and Cloudflare). We use them to keep the service running, diagnose faults, and prevent abuse. They are retained for a short period and are not used to build a profile of you.
No advertising or attribution identifiers. No contacts, calendar, microphone or health data. No browsing history. No behavioural analytics. No payment card details, those are handled entirely by Apple or Google and are never seen by us.
04How we use information
- To answer the question - compute darkness, cloud cover, moon phase and your visibility score for where you are.
- To send the alerts you asked for - evaluate your thresholds against live NOAA data and deliver a push at the right moment.
- To confirm entitlement - check whether an installation holds a Pro subscription before unlocking paid features.
- To keep the service reliable and secure - diagnose failures, enforce rate limits, and prevent abuse of the alert system.
- To support you - respond to questions and requests you send us.
We do not use your information for advertising, profiling or automated decision-making, and we do not combine it with data bought from third parties.
05Third-party services we use
We rely on a short list of providers to run Heliocast. They process information on our behalf and only for the purposes described here. Each operates under its own privacy policy.
Review these providers' practices in their policies: Apple, Google, RevenueCat, Cloudflare and OpenWeatherMap and MET Norway.
Heliocast reads public feeds from NOAA SWPC, NASA (SDO, DONKI), NASA/ESA SOHO, GOES, DSCOVR, the Kyoto WDC and USGS. Our server fetches and caches that data; nothing about you is ever sent to those agencies.
07Data retention & deletion
- On-device data (journal, photos, rules, settings) stays until you delete it or uninstall the app. There is no cloud copy for us to keep.
- Alert subscriptions are kept while the alert is active. Turning alerts off in the app deletes the subscription, token, preferences and coordinates, from our store. Tokens that the platform reports as permanently invalid are removed automatically.
- Server logs are retained for a short period under our hosting providers' default retention, then discarded.
- Purchase records are retained by Apple, Google and RevenueCat under their own policies, as required for billing and tax purposes.
If your device's operating system includes app data in your personal iCloud or Google Drive backup, that backup is operated by Apple or Google under your control and your device settings, we do not operate it or receive a copy.
08Security
All traffic between the app and our API is encrypted in transit (HTTPS). Requests to paid endpoints must carry a short-lived, cryptographically signed identity token that our server verifies against Google's public keys, there is no secret key hidden in the app to steal. Alert subscriptions are stored in Google Cloud Firestore under Google's security infrastructure. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
09Children's privacy
Heliocast is a general-audience science and travel-planning app and is not directed to children under 13 (or the equivalent minimum age in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.
10Your choices and rights
- Location. Grant, deny or revoke the permission at any time in your device settings; the app degrades gracefully without it.
- Notifications. Turn alerts off in the app (which deletes the subscription) or revoke the notification permission in your device settings.
- Your journal. Delete individual sightings in the app, or uninstall to remove everything local.
- Access, correction or deletion. Email us with the Device ID shown in Settings and we will locate, export or delete anything we hold that is associated with it.
Depending on where you live (for example, the EEA or UK under the GDPR, or California under the CCPA/CPRA), you may have additional rights, to access, port, correct or delete your information, to object to or restrict certain processing, and not to be discriminated against for exercising them. Where the GDPR applies, our legal bases are: performance of a contract (delivering the features and alerts you requested), your consent (location, notifications), and our legitimate interests (keeping the service secure and working). We do not sell or "share" personal information as those terms are defined under California law. To exercise any right, contact us below; we will respond consistent with applicable law.
11International users
Heliocast is operated from the United States, and our service providers may process information in the United States and other countries. If you use the app from outside the United States, you understand that your information may be transferred to, stored and processed in countries whose data-protection laws may differ from those in your country.
12Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above, and for material changes we will give more prominent notice in the app or by other appropriate means. Continuing to use Heliocast after an update means you accept the revised policy.
13Contact us
Questions about this policy, or want to exercise a privacy right? Get in touch: