Privacy Policy
Last updated: July 25, 2026
WeatherPokes is operated by Co AI, Inc. This policy explains what data WeatherPokes and its service providers collect, how that data is used and shared, how long it is kept, and the choices available to you.
Data We Collect and How We Use It
- Anonymous account and device data: random owner and device identifiers, a hashed copy of the device credential, platform, timezone, notification preference state, and last-seen timestamps. We use this data to authenticate the device and operate your WeatherPokes account without asking for a name or email address.
- Location and saved places: when you choose Use My Location and grant permission, your device may provide precise or approximate coordinates depending on your system setting. We send those coordinates to the WeatherPokes service to return nearby weather and a place label. If you save a place, we store its name, coordinates, radius, order, and timezone. You can use manual place search instead of sharing your device location.
- Searches and WeatherPokes content: place-search text and any nearby coordinates are sent to the service to complete the search. We store the saved places and Pokes you create, including names, conditions, time windows, cooldowns, and notification limits, so the service can evaluate them.
- Notifications: if you enable notifications, we collect an Expo push token, platform, timezone, permission state, and delivery records. We use them to deliver matching Pokes, prevent duplicate sends, retire invalid tokens, and diagnose delivery failures.
- Service and diagnostic data: Cloudflare may process IP addresses, request URLs and metadata, response status, timing, and service errors for rate limiting, security, reliability, and troubleshooting. Request URLs can include place-search text or coordinates.
How We Share Data
We do not sell personal data, use it for advertising, or track you across other companies' apps or websites. We share data only with the service providers needed to operate WeatherPokes:
- Cloudflare: hosts the API and website and provides database, queue, rate-limiting, and operational logging services. Cloudflare processes the service data described above.
- Expo: provides build infrastructure and push-notification delivery. Expo receives push tokens and notification payloads when notifications are enabled.
- Open-Meteo: receives coordinates and weather-query settings needed to return forecast and air-quality data.
- Photon/Komoot and OpenStreetMap: receive place-search text and, when supplied, nearby or reverse-geocoding coordinates used to return place results.
- weather.gov/National Weather Service: receives location-based requests needed to return active United States weather alerts.
We require service providers that receive WeatherPokes user data to provide the same or equivalent protection described in this policy and required by applicable Apple rules and law, and to use the data only to provide, secure, and support their services for WeatherPokes.
Data Source Attribution
Weather data is provided by Open-Meteo.com. Place search and reverse geocoding use Photon/Komoot and OpenStreetMap data. United States weather alerts come from weather.gov and the National Weather Service.
Your Choices and Consent
- Location access is optional. You can decline it and search for places manually. You can change or revoke location access at any time in your device's system settings.
- Notifications are optional. You can decline them, turn individual Pokes off in the app, or change notification access in system settings.
- You can delete your anonymous account data in WeatherPokes under Settings by choosing Delete all WeatherPokes data.
Retention and Deletion
You can delete your WeatherPokes data from the app or request help through the delete-data page. Deletion removes the anonymous owner, devices, push tokens, saved places, Pokes, rule-evaluation failures, and notification delivery records from the primary service database.
Weather cache rows expire after about 10 minutes. Notification delivery records and disabled or invalid device tokens are removed after about 90 days. Rate-limit records are removed after about 2 days. Cloudflare Workers Logs are retained according to the Cloudflare plan retention window, currently up to 3 days on Workers Free or 7 days on Workers Paid. WeatherPokes does not configure Workers Logpush for v1.
Backups and provider operational records may persist for their normal retention period after primary database deletion.
Security
WeatherPokes uses HTTPS for network requests. The app stores its randomly generated anonymous device credential in iOS Keychain or Android encrypted storage, and the service stores only a cryptographic hash of the credential. We use access controls, input validation, rate limits, and owner-scoped database operations to reduce unauthorized access.
Contact
For privacy or support questions, email hi@mohamm.ad.