Direct product policy. This Privacy Policy applies only to Parcel (app.parcel.Parcel). It directly states the app’s data practices and is not an owner-site redirect or a portfolio-wide substitute.
Scope, controller, and contact
UNCOMMON WEATHER LLC, 1212 N Walker Ave Apt 207, Oklahoma City, OK 73103, United States, is responsible for the information described here. Contact team@uncommonweather.com for privacy questions, rights requests, or support.
Information Parcel handles
- Authentication identifiers and account data, including an anonymous lookup user ID, email address where provided, Sign in with Apple identifier, Supabase user ID, and session state
- Land-area geometry, parcel name, purpose, land-cover choice, calculated area, map search or selected location, monitoring state, and processing progress
- Satellite source identifiers, acquisition dates, cloud and valid-pixel measurements, derived vegetation and water indices, baseline and replay state, alert footprints, confidence state, and monitoring health
- Private generated evidence, including before, after, and difference images, monthly snapshots, and timelapse files associated with a selected parcel
- Push-notification token, notification environment and bundle identifier, optional alert-email preference, and alert-delivery state
- Apple purchase and RevenueCat subscription and entitlement metadata associated with an anonymous or signed-in app user identifier
- Privacy-minimal legal-choice evidence and request-audit metadata
- Operational network and security metadata processed by service providers
- Support correspondence and attachments the user deliberately sends to Uncommon Weather
Product-specific practices
Anonymous lookups, accounts, and authentication
Parcel can create a random anonymous Supabase identity so a person can check a limited number of spots without first providing an email address. That identity and its lookup records are not a promise of permanent storage or account recovery. Watching land, receiving account-linked alerts, and purchasing paid access require the durable account state shown in the app.
A user can sign in with Apple or a supported email one-time code. Supabase processes the authentication identifier, email address where provided, access and refresh tokens, and account user ID. Parcel does not receive an Apple ID password or email-account password.
Land boundaries, search, and device location
A boundary the user draws or selects, its calculated area, name, monitoring purpose, land-cover choice, and processing state are stored because they are the subject of the requested service. Those records can reveal an interest in a home, farm, forest, water body, work site, or other location and should be treated as sensitive even when ownership is not established.
Parcel requests precise device location only after the user chooses the location control and uses it to center the map. Parcel does not request background location and does not monitor the device's movement. Map search and map imagery are provided through Apple frameworks.
Satellite sources, derived observations, and evidence
The service searches public Copernicus Sentinel-2 catalog records through Element 84 Earth Search and reads source imagery from AWS Open Data for the selected land window. It records source scene identifiers, observation dates, cloud and validity measures, derived vegetation and water values, baseline state, possible-change state, alert footprints, and service health needed to build the report and continue monitoring.
When a qualifying change is confirmed, Parcel can generate private before, after, and difference images, snapshots, and a timelapse for the account. Generated media is stored in private service storage and made available through short-lived access URLs. A copy deliberately exported or shared remains with the selected recipient or service.
Push and email alerts
If notifications are enabled, Apple provides a device push token. Parcel stores that token with the account, app bundle, and development or production environment needed to route an alert through Apple Push Notification service. Delivery and device presentation remain controlled by Apple and device settings.
If the user enables email alerts, the account email address and alert content needed for that message can be sent to Resend. Parcel does not use push or email identifiers for advertising.
Purchases, entitlements, and legal choices
Apple processes App Store purchases and payment credentials. RevenueCat receives an anonymous app-user identifier and, after durable sign-in, the Supabase user identifier, plus limited app, device, transaction, purchase, subscription, and entitlement metadata needed to present offerings, restore purchases, provide aggregate subscription analytics, and determine server-authorized access. RevenueCat does not receive parcel geometry, satellite imagery, alert evidence, or location merely to verify an entitlement.
The Uncommon Weather legal-choice service receives signed, privacy-minimal evidence of an acceptance, decline, or withdrawal. It does not receive the Parcel account email, Supabase account ID, parcel geometry, satellite evidence, or alert content.
Retention, account deletion, and subscription cancellation
Account-backed parcel records and generated media remain while the account is active or as needed to provide the requested service. Operational records can remain for a limited period to retry work, investigate a failed run, prevent duplicate alerts, control abuse, secure the service, resolve a dispute, or satisfy legal obligations.
The in-app account-deletion flow removes account-owned private storage through the storage service, then removes the Supabase authentication user and user-owned database records. A completed deletion does not erase copies the user shared, Apple or RevenueCat transaction records, provider security records, or privacy-minimal legal-choice evidence. Deleting a Parcel account does not cancel an Apple subscription.
Service providers and disclosures
Apple provides iOS, App Store billing, and the Apple frameworks identified above. RevenueCat provides subscription-entitlement infrastructure. Supabase provides the separate legal-choice service and, where the product-specific sections say so, account, storage, synchronization, or server-function infrastructure. Cloudflare delivers and protects the public website. Other named providers process only the information needed for the selected function.
Ordinary connection metadata, such as IP address or IP-derived coarse region, user agent, request identifier, route, response status, and execution timing, is processed by network, security, hosting, storage, workflow, and server-function providers to deliver and protect a request. Some of it may be retained under provider security and operational schedules. Information may also be disclosed when required by valid legal process, to protect rights or safety, to investigate abuse or security incidents, or in a business transaction with legally required safeguards.
Uncommon Weather does not sell personal information, share it for cross-context behavioral advertising, serve third-party ads, or track users across unrelated products.
Retention and deletion
Product data follows the product-specific retention and deletion boundaries above. Copies deliberately exported, uploaded, or shared remain wherever the user, recipient, or selected service saved them. Support correspondence is retained while needed to handle the request and for reasonable operational, security, and legal purposes. Apple, RevenueCat, Supabase, OpenAI where applicable, and other independent providers retain records under their own policies and legal duties.
Legal-choice events and acceptance receipts are append-only evidence retained until the verified relationship ends plus seven years. Related challenge, key-registration, request-audit, signing-key incident, receipt-integrity, and retention-purge records follow their security and legal-claims schedules. Immutable legal evidence may be retained where needed to establish, exercise, or defend legal claims.
Security
The legal-choice system uses HTTPS, P-256 signatures, keyed pseudonyms, replay-resistant single-use challenges, strict product allowlists, rate limits, restricted service credentials, append-only evidence, and signed receipts. Apple security frameworks and the product-specific controls above protect other data where stated. No system is perfectly secure.
Choices and privacy rights
Users can decline, later withdraw to limited mode, review the current documents, or affirmatively accept from Legal & Privacy settings. Available product controls can manage permissions, delete or export product data, manage or restore purchases, and delete an account where applicable. Depending on location, rights may include access, correction, deletion, restriction, objection, appeal, withdrawal, or a regulator complaint.
A current affirmative acceptance takes effect after it is durably saved on the device. Main-app access remains available while signed-receipt delivery retries after a non-terminal network, Apple, or service outage. Widgets, Live Activities, and other extension surfaces that require a verifiable cross-process receipt may wait until the server-signed receipt is received and verified. An explicit terminal rejection of the exact saved acceptance causes the client to quarantine that failed record and return to the appropriate decision or limited-state screen.
Children and eligibility
Parcel is intended only for adults age 18 or older. The legal flow records only a broad adult age band and acceptor role, not a birth date.
Changes and related documents
Material changes receive a new immutable document version. Previously accepted users are asked to make one new choice for a materially changed family; continued use alone does not silently create acceptance. A stored decline or withdrawal remains limited without a recurring prompt. Read the Parcel Terms of Service and Parcel Product Schedule.
UNCOMMON WEATHER LLC
1212 N Walker Ave Apt 207
Oklahoma City, OK 73103
United States
team@uncommonweather.com