Privacy Policy
Last updated: 19 August 2026
1. Who we are
Meteobreeze is operated by Without Limits Digital Ltd, a company registered in England and Wales (Companies House number 14197830). We are the data controller for personal data processed through this service.
To contact us about privacy matters, email support@meteobreeze.com.
2. Scope of this policy
This policy covers personal data collected when you visit meteobreeze.com (the "Site"), create an account, connect a weather station, join the waitlist, or otherwise interact with the Meteobreeze service.
3. Information we collect
Account data
When you create an account: name, email address, hashed password, and the date you registered.
Session data
Session tokens, your IP address at sign-in, and the User-Agent string of your browser. These are stored by Better Auth, the authentication library we use, and are retained for 30 days.
Station and weather data
Station name, location (latitude/longitude), timezone, and weather readings pushed from your devices. Weather readings are not personal data in most cases, but station location can indirectly identify you.
Notification logs
When we send email alerts, we log the fact of delivery (timestamp, alert type, recipient address). Logs are retained for 90 days.
Waitlist sign-ups
If you join our waitlist, we store your email address, an anonymised hash of your IP address (for rate-limiting only — the raw IP is never stored), and the date of sign-up. Waitlist data is retained for 2 years or until you ask us to remove it.
Launch-updates subscriptions
If you separately choose to receive product stories and launch news, we store your email address, the time and source of your consent, and the version of the consent wording shown to you. We keep a minimal record when you unsubscribe so we can honour your choice.
Waitlist invitations and Founding Station onboarding are operational messages. They do not depend on your choice to receive optional launch updates.
Technical and error data
We use Sentry for error monitoring. Sentry receives a pseudonymous user ID (a database-generated identifier, not your email) so we can correlate errors with accounts. Sentry's automatic PII collection (IP addresses, email addresses) is disabled.
4. How we collect it
- Directly from you when you register, configure a station, or join the waitlist.
- Automatically when your station software pushes data to our API.
- Automatically by our infrastructure (server logs, Sentry error events).
- Via Cloudflare Turnstile (invisible mode) when you submit the waitlist form for bot detection. Turnstile may collect device and signal data as described in the Cloudflare Turnstile Privacy Addendum.
5. How we use your data
| Purpose | Data used |
|---|---|
| Provide the service | Account, session, station and weather data |
| Send alert emails | Email address, notification log |
| Diagnose errors | Pseudonymous user ID, error events (Sentry) |
| Understand product usage | Pseudonymous user ID, named product events (PostHog) |
| Prevent abuse | IP hash (rate limiting on waitlist) |
| Send waitlist confirmation | Email address |
| Send opted-in launch updates | Email address and subscription preference |
| Display maps | Station lat/lon passed to Mapbox |
6. Lawful bases (UK GDPR)
- Contract — processing necessary to provide the service you've signed up for (account, station data, alerts).
- Legitimate interests — error monitoring with pseudonymous identifiers, server security logging, and privacy-minimising product analytics (PostHog).
- Consent — waitlist sign-up (you explicitly provide your email for an invitation) and separately opted-in launch updates.
7. Cookies
We set a session cookie to keep you logged in, and a analytics_consent cookie recording your analytics preference (see "8. Analytics" below). No third-party advertising cookies are used. Cloudflare may set a security cookie (__cf_bm) as part of bot protection. If you opt in to in-depth analytics, our analytics provider, PostHog, sets a cookie and/or local storage entry containing a randomly generated identifier used to recognise you across visits (see "8. Analytics" below).
8. Analytics
We use PostHog, hosted in the EU region, for privacy-minimising product analytics. Analytics capture is deliberately limited: automatic click/page tracking is off, we only send a small set of named events, and identified visitors are tagged with an internal, pseudonymous account ID — never your email address or other directly identifying profile data.
By default, analytics runs anonymously with a session-only identifier that does not persist across visits — we rely on our legitimate interests in understanding and improving the product as the lawful basis for this baseline processing, without requesting cookie consent, given how limited it is. You can opt in to a persistent, cross-visit identifier for deeper journey tracking via the cookie banner shown on your first visit, or at any time from Settings if you have an account; opting out clears the persistent identifier immediately. We honour Do Not Track browser signals for the baseline analytics above. We do not currently honour Global Privacy Control, as we do not meet the size thresholds under which it carries legal force for us.
Session replay (a recording of on-screen interactions for product troubleshooting) is supported by PostHog but is not currently enabled. If we enable it in future, it will be limited to a sampled subset of sessions for product investigation, will mask all text and input fields by default, and will exclude sign-in, account, billing, deletion and other sensitive pages. We will update this policy before turning it on.
Server access logs (request path, timestamp, response code) are retained for operational purposes only and are not shared.
9. Third-party processors
| Processor | Purpose | Data shared |
|---|---|---|
| Resend | Email delivery | Email address, email content |
| Sentry | Error monitoring | Pseudonymous user ID, stack traces |
| PostHog (EU region) | Product analytics | Pseudonymous user ID, named product events, environment tag — never email or station location |
| Mapbox | Map tiles | Station lat/lon in tile requests |
| Cloudflare | DDoS protection, DNS, Turnstile | IP address, request metadata |
10. International transfers
Our servers are located in the United Kingdom. Some processors transfer data to the United States:
- Sentry — transfers to the US under Standard Contractual Clauses (SCCs).
- Mapbox — transfers to the US under Standard Contractual Clauses.
- PostHog — data is ingested and stored in PostHog's EU region; we do not route analytics data through PostHog's US infrastructure.
- Resend — transfers to the US under UK Standard Contractual Clauses and the UK Addendum.
- Cloudflare — global edge network; transfers made under UK Standard Contractual Clauses and the UK Addendum.
11. Data retention
| Data type | Retention period |
|---|---|
| Account and station data | Until account deletion |
| Session data | 30 days |
| Notification logs | 90 days |
| Waitlist sign-ups | 2 years |
| Launch-updates subscriptions | Until you unsubscribe; a minimal consent and opt-out record is retained afterward |
| Server access logs | 90 days |
| Analytics events (PostHog) | Deleted, along with your analytics profile, when you delete your account |
12. Security
We use HTTPS for all connections. Passwords are hashed before storage. Session tokens are rotated. Error monitoring is configured with PII auto-capture disabled. No credit card data is processed or stored by us.
13. Your rights
Under UK GDPR you have the right to access, rectify, erase, or restrict processing of your personal data. You also have the right to data portability and to object to processing based on legitimate interests.
To exercise any of these rights, email us at support@meteobreeze.com. We will respond within one calendar month. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
14. Children's privacy
Meteobreeze is not directed at children under 13. We do not knowingly collect personal data from children. If you believe a child has provided us with their data, please contact us and we will delete it.
15. Changes to this policy
We may update this policy from time to time. Material changes will be indicated by an updated "Last updated" date at the top of this page. We will notify registered users of significant changes by email where required by law.