1. Scope and controller
UNCOMMON WEATHER LLC, 1212 N Walker Ave Apt 207, Oklahoma City, OK 73103, United States, is responsible for the limited information described here. Contact team@uncommonweather.com. This policy applies to the covered Uncommon Weather iOS and iPadOS apps, Chrome extensions, legal-acceptance ledger, and Legal Center identified in the current manifest and Product Schedules.
2. Data that stays local
Product records described in each Product Schedule generally remain on the device, in the Chrome profile, in Apple services such as iCloud or CloudKit where a schedule expressly identifies them, or in files you explicitly export. Uncommon Weather does not receive Screen Time selections, calculations, reflections, proof media, ownership records, calendar contents, precise location, browsing history, page contents, session cookies, notes, flashcards, invoices, extracted styles, estimates, timestamps, or reports merely because you use a product.
3. Legal choices and acceptance evidence
When you accept, decline, or later withdraw acceptance to use limited mode, the product records that choice locally and queues a signed, privacy-minimal event for Supabase. The product’s local queue also tracks delivery and synchronization status. The Edge function transiently receives the random local installation ID as a field of the signed request. Apart from validating that signed-request binding, it uses the ID solely to derive a domain-separated keyed HMAC. The ledger stores that HMAC as the installation identifier and a one-way hash of the signed evidence; it does not retain the raw installation ID or include it in the stable idempotency fingerprint. Supabase stores: random request, event, and receipt IDs; the installation pseudonym; bundle or extension ID and environment; app or extension version/build; document and assent-statement versions and SHA-256 hashes; the choice (accepted, declined, or withdrawn to limited mode); broad age band and acceptor role for accepted choices; device and server timestamps; locale; source; a per-installation sequence number; online or offline decision status; proof or key type; evidence and idempotency hashes; receipt signing-key ID and signature; and, when applicable, a linked or superseded acceptance receipt ID. For configured Apple products only, the Edge function transiently receives the RevenueCat app user identifier as a field of the signed acceptance request. Apart from validating that signed-request binding, it uses the identifier solely to derive a separate domain-separated keyed HMAC. The ledger and receipt store that HMAC as the RevenueCat pseudonym and a one-way hash of the signed evidence; they do not retain the raw identifier or include it in the stable idempotency fingerprint.
To authenticate requests and prevent replay, the Edge function transiently receives a challenge value, raw evidence-key ID, device signature or App Attest assertion, and, for App Attest registration, the attestation object. The security ledger stores: the challenge ID; installation and evidence-key HMACs; bundle or extension ID; environment and purpose; a SHA-256 nonce hash; public key; proof or key type; attestation environment; counters and security-status timestamps; SHA-256 hashes of the attestation receipt and signed evidence; and request-audit route, status code, and timestamp. It does not retain the raw challenge, raw evidence-key ID, raw attestation receipt or object, App Attest assertion, or device signature. The Edge application code does not write request bodies or raw identifiers to its request-status audit log.
Historical signing-key incident and receipt-repair integrity records may store receipt and attestation IDs, document family, involved signing-key IDs and public keys, incident or repair reason, aggregate forensic counts, SHA-256 hashes of the immutable receipt and repair payload, repair signature, and timestamps. These integrity records do not add raw installation IDs or product content. Declining and withdrawing do not collect a name, email, or reason. The saved current choice prevents repeated prompts for the same document family; a new prompt appears only when no current-family choice exists or a materially new family is published.
Apple products use App Attest when available and a device signing-key fallback; Chrome products use a non-extractable P-256 WebCrypto key stored in IndexedDB. We do not place your name, email, birth date, IP address, Gumroad key, product content, browsing activity, calculation, reflection, proof media, precise location, or raw purchase receipt in the ledger receipt. Network and hosting providers may process ordinary connection and execution metadata, including IP address, request route, response status, and timing, to deliver, operate, and secure requests.
A local decline or withdrawal takes effect immediately; if delivery is unavailable, its ordered event remains queued. After you affirm acceptance, the product saves the current choice locally as verification pending and keeps ordinary product operation in limited mode. Full product access begins only after the current signed server receipt is returned and its signature and document binding verify. Evidence recorded while the device is online must reach the ledger within one hour; evidence recorded while the product has genuinely detected an offline state may be queued for up to seven days. If the applicable window expires before verification, the product does not silently re-date or reuse the evidence and requires a fresh affirmative choice.
4. Licensing and billing
Apple processes App Store purchases and payment credentials. RevenueCat receives App Store transaction and entitlement information needed to present offerings and determine paid access; Uncommon Weather does not receive full card details. When you activate or re-check a paid Chrome license, the extension sends the license key and fixed Gumroad product ID to Gumroad’s verification endpoint. Gumroad returns limited purchase, refund, dispute, subscription, and entitlement information used to determine access.
5. Service providers and disclosure
Apple provides iOS, iPadOS, App Store billing, and optional iCloud or CloudKit services. RevenueCat provides subscription-entitlement infrastructure for paid Apple apps. Gumroad handles Chrome checkout, receipts, taxes, refunds, customer records, subscriptions, and license verification. Supabase hosts the legal ledger in the United States. Google provides Chrome and the Chrome Web Store. We may disclose narrowly necessary information to providers under contract, to comply with valid legal process, protect rights or safety, investigate fraud/security incidents, or complete a business transaction with required safeguards and consent.
Uncommon Weather does not sell personal information, share it for cross-context behavioral advertising, serve third-party ads, or track users across unrelated products.
6. Chrome Web Store Limited Use
The use of information received from Chrome APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Data accessed for a product’s disclosed single purpose is not used for advertising, lending, or unrelated profiling.
7. Retention
Local product data remains until you delete it, uninstall, clear local storage, leave a shared record, or use an available product deletion control. Apple, RevenueCat, Gumroad, Google, and other providers retain records under their policies and legal duties. Legal-choice events, acceptance receipts, and related receipt-repair integrity evidence are append-only during active retention and are retained until the verified relationship end plus seven years. Challenges, key-registration and security state, request-status audit entries, relationship-end records, signing-key incident records, and retention-purge audit entries are retained under security, integrity, operational, and legal-claims schedules and may be kept with related evidence where necessary. Encrypted backups follow the schedule applicable to the record category.
8. Security
We use HTTPS, P-256 signatures, keyed pseudonyms, rate limits, replay-resistant challenges, strict origin allowlists, forced row-level security, append-only evidence, restricted service credentials, and signed receipts. No system is perfectly secure. Keep exported backups and license keys private.
9. Choices and rights
You may decline updated terms or later switch to limited mode from Legal & Privacy settings. The product saves that current choice, updates the ledger when online, and stops asking again for the same document family. You may later review the documents and accept again. You may also use available export/delete or leave-sharing tools, manage or restore subscriptions, deactivate a Chrome license locally, request support, and exercise applicable privacy rights. Depending on location, rights may include access, correction, deletion, restriction, objection, appeal, withdrawal, or regulator complaint. Immutable legal evidence may be retained where needed to establish, exercise, or defend legal claims.
10. Children
Products are not directed to children under 13. Users aged 13 through 17 require parent or guardian acceptance unless a Product Schedule requires adulthood. We record only a broad age band and role, not a birth date.
11. Changes and contact
Material policy changes receive a new immutable version and new acceptance. Non-material clarifications may update the live explanatory page without changing previously archived evidence.
UNCOMMON WEATHER LLC
1212 N Walker Ave Apt 207
Oklahoma City, OK 73103
United States
team@uncommonweather.com
