Privacy policy
1. Who is responsible
Igor GunRigaer Str. 89
10247 Berlin, Germany
Email: support@metevio.de
Data-protection officer: —
2. In short
- You can use Metevio without an account. Then your places and plans are kept only on your device; for the forecast, the app sends our server the coordinates of the place you plan for, which the server does not keep.
- With an account, your plans and places are stored on our server so that we can check the forecast and send notifications, and so that your devices stay in step.
- Metevio never reads your device's location. It works with places you choose by name.
- No advertising, no selling of data, no tracking across other apps or websites.
- You can delete your account, and all data tied to it, in the app at any time.
3. Visiting this website
This website sets no cookies, runs no scripts and loads nothing from other servers. When you open a page, our web server receives your IP address, the time, the address requested and the browser's identification, and records them in a short-lived server log to deliver the page and to keep the service secure. Legal basis: our legitimate interest in a secure and working website (Art. 6(1)(f) GDPR). Retention: see section 13.
4. Using the app without an account
Without an account, the places and activities you create, your settings and the downloaded forecast are stored only on your device, in the app's own storage. We do not receive them. The app still contacts the weather service described in section 8.
5. Your account
An account is optional. It is needed for synchronisation between devices and for push notifications. You can create one in three ways; we store the following for each.
- Email and password. Your email address, the name you enter, and a salted one-way hash of the password (we cannot read your password). To confirm the address we send an eight-digit code by email; a pending registration, including the address, is deleted when the code expires. The same applies to password reset.
- Sign in with Google. Google tells us your Google account identifier and email address, and your name if you have shared it.
- Sign in with Apple. Apple tells us your Apple account identifier, an authorisation token, and — if you allow it — your name and your email address or the private relay address Apple makes for you.
Your session is kept on your device in the system's protected storage (iOS Keychain, Android Keystore-backed storage) as a short-lived access token and a longer-lived refresh token; the server keeps a hashed copy of the refresh token. Legal basis: performing the contract you enter by creating an account (Art. 6(1)(b) GDPR).
6. Plans and synchronisation
When you are signed in, the app sends the following to our server and keeps it there: your places (name, coordinates, country, time zone), your activities (type, time, repetition, whether notifications are on, the place) and their conditions, your notification settings, and a change log so that your other devices can catch up. Deleted items are kept as markers so that other devices learn of the deletion, and removed with the account. The server also stores, for each occurrence of an activity, the latest verdict and a summary of the forecast behind it, so that it can tell when the verdict changes.
The places you enter are settlements you choose by name; Metevio never learns where you are. Legal basis: performing the contract (Art. 6(1)(b) GDPR).
7. Push notifications
If you allow notifications, your device gives the app a push token. We store the token, the platform (iOS or Android) and your device's language so that we can send notifications in your language. Notifications are sent through Google Firebase Cloud Messaging (Android) and Apple's push service (iOS). A notification contains the activity name, the place name, the time and the verdict, so it is visible to those services while in transit and, on your lock screen, to anyone who sees your phone. Legal basis: performing the contract (Art. 6(1)(b) GDPR); you can turn notifications off in the app and in the system settings, and signing out removes the token from our server. If a session merely expires, the token stays linked to your account, so notifications keep arriving until you sign out or sign in with another account.
8. Weather data and place search
Forecasts come from Open-Meteo.com, fetched by our server — the app itself never asks Open-Meteo for a forecast. The app sends our server the coordinates and the time zone of the place you plan for, with or without an account; the server uses them only to find the forecast for that area, does not store them and does not log them, and asks Open-Meteo for the centre of a grid cell of about 11 × 7 km, never your exact place. When you search for a place, the app sends the text you type and the app language directly to Open-Meteo's place-search service, which reveals your IP address to Open-Meteo, as any internet request does. Legal basis: performing the contract, and for the forecast in the app without an account your request to use the feature (Art. 6(1)(b) GDPR).
9. Security and operating logs
To protect accounts against guessing of passwords and codes, the server records sign-in and registration attempts with the IP address and the time and limits how often they may be made. Our servers also keep operating logs (IP address, time, the function called, the account identifier and error messages) to find and fix faults and to defend against abuse. We do not write the content of your plans to these logs. Legal basis: our legitimate interest in the security and stability of the service (Art. 6(1)(f) GDPR). Retention: see section 13.
10. Analytics and app diagnostics
Metevio uses Firebase Analytics (Google) to keep the app working and to improve it. It records only a few technical events: app start, sign-up and sign-in (with the method used) and — when synchronisation fails — the kind of failure and the phase in which it happened, so that we can find and fix faults. The events contain no email address, name, plans, places or other account data. The SDK adds an app-instance identifier, which tells installations apart without identifying a person, and technical data: device model, operating system and app version, language and a coarse region derived from the IP address. We do not use this for advertising and do not link it to your account.
Legal basis: our legitimate interest in a stable, improving app (Art. 6(1)(f) GDPR). You can object at any time by writing to support@metevio.de.
Crash reports. When the app crashes or runs into an unexpected error, it sends a crash report to Firebase Crashlytics (Google): the error and the place in the app's code where it happened, the device model, operating system and app version, free memory and storage, the time, and an installation identifier that Crashlytics creates for the app. The report contains no email address, name, plans, places or other account data, and we do not link it to your account. We use it only to find and fix faults. Legal basis: our legitimate interest in an app that works (Art. 6(1)(f) GDPR). You can object at any time by writing to support@metevio.de. Crash reports are kept for 90 days and then deleted.
11. Recipients
| Recipient | Data | Purpose |
|---|---|---|
| Hetzner Online GmbH (hosting), Germany (Nuremberg) | All data described above | Runs the server (processor) |
| Open-Meteo.com | From our server: the centre of a ~11 × 7 km grid cell. From the app: place-search text and IP address | Forecast and place search |
| Google (Firebase Cloud Messaging) | Push token and notification content | Delivering notifications to Android (processor) |
| Apple (push service) | Push token and notification content | Delivering notifications to iOS |
| Google / Apple | Sign-in data as described in section 5 | Only if you sign in with them |
| Resend | Your email address and the verification code | Sending registration and reset emails (processor) |
| Google (Firebase Analytics) | A few app events, app-instance identifier, device and app data — no account data | Keeping the app stable and improving it |
| Google (Firebase Crashlytics) | Crash reports: the error, device and app data, an installation identifier — no account data | Finding and fixing faults (processor) |
We do not sell data and do not share it for advertising. We disclose data to authorities only where the law requires.
12. Transfers outside the EU/EEA
Google and Apple are companies based in the United States. They rely on the EU–US Data Privacy Framework where they are certified, and on standard contractual clauses otherwise. Our server is located in Germany (Nuremberg).
13. How long we keep data
- Account and plans: until you delete the account.
- Sessions: the access token is valid for about ten minutes; a session ends when you sign out or when its refresh token expires, 90 days after it was last used.
- Sign-in attempt records (with IP address): 2 days.
- Operating logs and web-server logs: 30 days.
- Crash reports (Firebase Crashlytics): kept for 90 days, then deleted.
- Backups: up to 7 days after deletion.
14. Your rights
You have the right to access, rectification, erasure, restriction of processing, data portability and to object to processing based on legitimate interests (Art. 15–21 GDPR), and to withdraw a consent at any time. Write to support@metevio.de. You can also lodge a complaint with a supervisory authority; ours is: Berliner Beauftragte für Datenschutz und Informationsfreiheit.
15. Deleting your data
Open Account → Delete account in the app: this removes your account, every sign-in method, all plans, places, settings and push tokens from our server, and the data on that device. If you no longer have the app, see how to request deletion. Deleting your account within the app does not delete data held by Google or Apple under their own terms.
16. Children
Metevio is not directed at children under 16. Do not create an account if you are younger.
17. Changes to this policy
If we change how we handle data, we update this page and its date, and inform you in the app where the change is significant.
