Privacy Policy
Last updated: October 3, 2026
Revised October 1, 2026: Section 1.9 explains the website's analytics, which set no cookies and store no IP address; Section 1.8 lists the session cookie the web app sets when you activate it; Section 3 names Brevo, which sends our emails.
Naola ("we", "our", "the app") is a weather application. We are committed to protecting your privacy. This policy explains what data we collect, why, and how it is handled.
1. Data We Collect
1.1 Location Data
When you grant location permission, the app accesses your device's geographic coordinates (latitude and longitude) to fetch weather data for your area. Location data is:
- Stored locally on your device (in app storage) so we can remember your selected location between sessions.
- Sent to our backend server per request to retrieve weather data. It is processed in memory and not stored in raw form. For accuracy tracking, anonymized coordinates (rounded to approximately 1 km precision) and city names are stored — these are shared geographic reference points and are not linked to any user, IP address, or device.
- Forwarded to third-party weather providers (see Section 3) to obtain forecasts. Each provider receives your coordinates only for the duration of the API call.
You can deny location permission and manually search for a city instead. You can revoke location permission at any time through your device settings.
1.2 IP Address
For rate limiting purposes, we store a one-way cryptographic hash (SHA-256) of your IP address. The original IP address cannot be recovered from this hash. Hashed IP records are automatically deleted after 7 days.
1.3 Feedback Messages
If you submit feedback through the app, we store the message text and your app language. Feedback is fully anonymous — no email, name, or identifying information is attached.
1.4 Subscription Data
If you make an in-app purchase, RevenueCat (the service that processes our subscriptions) receives your numeric Naola account id — the id of the anonymous device account if you never signed up — together with your platform (iOS/Android) and the store's purchase receipt. We store your subscription status against that account id. Your name and email address are never sent to RevenueCat.
1.5 Local Storage
The app stores the following on your device only:
- Your selected location (coordinates and city name)
- Language preference
- Whether you have completed the intro
- Widget location configurations
This data never leaves your device and is cleared when you uninstall the app.
1.6 Ad Impressions and Clicks
Free-tier users see one small ad card at the bottom of the main weather screen. We do not use any third-party ad network. All ads are served from our own backend and contain no tracking pixels, cookies, or third-party scripts.
The only data we store related to ads is:
- An impression counter — a single integer per ad row, incremented each time the backend serves that ad. Not linked to any user, device, or session.
- A click counter — a single integer per ad row, incremented each time the backend receives a click report. Not linked to any user, device, or session.
The schema has no foreign key, IP, timestamp, or any other field that could link an ad impression or click back to an individual user. It is technically impossible to reconstruct which user saw or clicked any given ad, even with full database access.
Ads do not read device advertising identifiers (IDFA, GAID), do not set cookies, and do not share any data with third parties.
Affiliate Links
Some ads contain affiliate links (e.g. Amazon Associates). These URLs include an affiliate tag that identifies Naola as the referral source. Naola does not pass any user data through these links — no device ID, no IP address, no session token, and no identifier of any kind.
However, once you tap an affiliate link and leave the app, the destination merchant (e.g. Amazon) operates under their own privacy policy. The merchant may use cookies or other mechanisms on their site to attribute the visit to the affiliate tag. This is standard affiliate program behavior and is outside Naola's control.
If you prefer not to be tracked by the merchant, you can choose not to tap the ad, or clear your browser cookies after visiting the merchant's site.
Advanced subscribers do not see any ads and no ad-related data is recorded for them.
1.7 Account Data
You don't need to sign up to use Naola. On first launch, the Android and iOS apps create an anonymous device account: a numeric id, a placeholder address that no one can receive mail at (…@device.naola.invalid), and a hash of a random secret kept in your device's keystore. It contains no personal data. It exists so that a subscription bought on that device is recognised without asking for your email.
Signing up with an email address, Apple or Google is optional. You need it only to move a subscription between Android and iOS. The web version never creates accounts: to use Advanced on the web, you generate an activation code in the mobile app.
What we store for an account:
- Email address — only if you sign up (a device account has just the placeholder). Stored lowercased so we can match the same account across devices. Some users sign in with Apple's private-relay email; in that case we only ever see the relay address, never the underlying email.
- Password hash (only if you set a password) — hashed with PBKDF2 (100,000 iterations, SHA-256, random per-user salt). Users who sign in with Apple or Google never set a password.
- Pending sign-up — when you sign up with email, your address and password hash wait in a pending record until you type the 6-digit code we email you. The code is valid for 15 minutes; a sign-up that is never confirmed is deleted within a day. We create the account only once the code is confirmed.
- OAuth provider links (Apple / Google subject IDs) — only if you signed in with one of those providers.
- Session device identifiers — an opaque UUID for each of two session slots: one phone and one browser. A subscription can be used on one phone and one browser at the same time. Signing in on a second phone (or a second browser) signs the first one out after a short grace window.
- Activation codes — short-lived
NA-XXXX-XXXXcodes (10-minute, single-use) minted in the mobile app to unlock Advanced on the web. We store the code, who minted it, when, and whether it's been redeemed. - Account creation timestamp
The web version does not have a registration form. To use Advanced on the web you generate an activation code in the mobile app (Settings → Account → Activate Naola on the web) and paste it at naola.net/activate. The web cannot create new accounts or new subscriptions on its own.
Sessions are managed via JSON Web Tokens (JWTs) signed with HMAC-SHA256, valid for 30 days. Each JWT is bound to the device identifier of its slot.
1.8 Browser Cookies (Website and Web App)
The Naola website (naola.net) and web app (naola.net/app) use only these cookies, both strictly necessary:
lang— stores your language preference (e.g.fr,ja) so later visits load the site in your language without detecting it again. One-year lifetime,SameSite=Lax,Secure. Contains only the language code (for examplefrorpt-BR).session— set only if you activate Naola on the web with a code. It keeps you signed in to the web app. 30-day lifetime,HttpOnly,Secure,SameSite=Strict, so scripts on the page can't read it. Signing out or deleting your account removes it.
Under GDPR/ePrivacy, strictly-necessary cookies do not require prior consent. The lang cookie is set either when you choose a language in the footer, or when the site detects your browser's Accept-Language header and redirects you to the matching language for the first time.
Our analytics sets no cookies (see Section 1.9). You can clear cookies at any time in your browser settings. The Android and iOS apps don't use browser cookies.
1.9 Website Analytics
To understand how many people visit naola.net and the web app, and which pages they use, we run Matomo, an open-source analytics tool, on our own server in the European Union. No other company receives this data. The Android and iOS apps contain no analytics at all.
This is analytics, not tracking:
- No cookies. Matomo runs in its cookie-free mode and stores nothing on your device.
- Your IP address is not stored. Your browser has to send it to reach our server, but Matomo shortens it to its first block (for example 81.0.0.0) before saving anything.
- No recognition over time or across sites. Page views are grouped into a visit using a code that changes every 24 hours, so one day's visit can't be linked to the next, or to other websites.
- No sensitive pages or links. Analytics doesn't run on the password-reset, activation and account-deletion pages, and never records anything after a "?" in a web address, where codes and links go.
- Nothing is sold, shared or used for advertising.
What Matomo records: the pages you view, the site that linked you here, your browser, operating system, screen size and language, and an approximate country. Individual visits are deleted after 6 months; after that we keep only totals, such as monthly page views.
The legal basis is our legitimate interest in knowing how the site is used (GDPR Art. 6(1)(f)). To opt out, turn on "Do Not Track" or Global Privacy Control in your browser: Matomo then doesn't load at all.
2. Data We Do Not Collect
- No sign-up required on Android, iOS, or the web — the mobile apps create only an anonymous device account (see Section 1.7)
- No email addresses, unless you choose to sign up (optional — see Section 1.7)
- No names or other personal identifiers
- No tracking: the mobile apps contain no analytics, and the website's analytics sets no cookies and stores no IP address (see Section 1.9)
- No advertising identifiers (IDFA, GAID)
- No third-party ad networks or SDKs
- No tracking cookies (only the strictly-necessary
langandsessioncookies — see Section 1.8) - No crash reporting or telemetry
- No link between ad impressions/clicks and any user or device
3. Third-Party Services
To provide weather data, your coordinates are sent to the following services during each weather request:
- Open-Meteo — weather data
- OpenWeather — weather data and location search
- Apple Weather — weather data and weather alerts
- WeatherAPI.coma — weather data
- Visual Crossinga — weather data
- Googlea — weather data
a Available with Naola Advanced.
For in-app purchases:
- RevenueCat — subscription management
For email:
- Brevo — sends the emails we send you (sign-up confirmation codes and password-reset links) and forwards feedback you send from the app to our support inbox. It receives the recipient's email address and the message content.
Each service has its own privacy policy linked above. We encourage you to review them.
Our website analytics (Section 1.9) runs on our own server, so no analytics company receives your data.
4. Data Retention
| Data | Retention |
|---|---|
| Hashed IP (rate limiting) | 7 days (auto-deleted) |
| API usage counts | 7 days (auto-deleted) |
| Feedback messages | Until manually deleted by us |
| Subscription records | Duration of subscription + reasonable period after |
| Location coordinates (raw) | Not stored on servers (processed in memory only) |
| Location aggregates (accuracy tracking) | Indefinite (anonymized, not linked to users) |
| Local device data | Until you uninstall the app |
| Account data (the anonymous device account; email and password hash only if you sign up) | Until you delete your account |
| JWT session tokens | 30 days from issuance (then expire automatically) |
| Ad impression/click counters | Indefinite (aggregate only, no user link) |
lang cookie (website) | 1 year (browser-stored; clearable at any time) |
session cookie (web app, only after activation) | 30 days, or until you sign out |
| Website analytics: individual visits (Matomo) | 6 months, then only aggregated totals |
| IP address in website analytics | Not stored (shortened to its first block before saving) |
5. Data Processing Location
Naola's database is held under Cloudflare's European Union jurisdiction — a binding restriction, fixed when the database was created, that keeps every account, subscription and feedback record we store inside the EU and prevents it from being relocated elsewhere. Our backend runs on Cloudflare Workers, a globally distributed network, so a request may first be handled at the edge location nearest you before it reaches that database. Location coordinates are processed in memory only and are never written to our database.
6. Children's Privacy
Naola does not knowingly collect data from children under 13. The app does not require an account and collects no personal information.
7. Your Rights
Under GDPR (Articles 15, 17, and 20) and similar regulations, you have the right to access, delete, and port your data. Naola provides these as self-service actions, so you don't need to email support or wait on a manual process — though email remains an option if you can't use the app.
Export your data (Art. 15 and 20)
In the mobile app: Settings → Account → Export my data. You'll get a JSON file containing every row we have linked to your account (profile, OAuth links, subscription entitlements, activation-code metadata). The export is in a structured, machine-readable format for portability to other services.
On the web: once Naola is activated in your browser, Settings → Account → Export my data in the web app at naola.net/app. If you can't use the app, email support@naola.app.
Delete your account (Art. 17)
In the mobile app: Settings → Account → Delete my account. A two-step confirmation removes every user-linked row from our database (profile, OAuth links, activation codes, subscription entitlements, webhook event history).
On the web: naola.net/delete-account, with an activation code from the mobile app; the deletion is immediate and permanent. If you can't use the app, email support@naola.app from the address on your account and we will erase it within 30 days.
Important — subscriptions are billed by Apple and Google, not by us. Deleting your Naola account does not cancel your App Store or Google Play subscription. Before deleting, go to Settings → [your name] → Subscriptions on iPhone, or Google Play → Payments & subscriptions → Subscriptions on Android, and cancel Naola Advanced, otherwise you will continue to be charged at renewal. We remove our entitlement record immediately so the app stops treating you as Advanced, but the billing relationship stays with the store until you cancel there.
Other rights
For objection to processing, rectification of data, complaint to a supervisory authority, or any other GDPR-related question not covered by the self-service options, email support@naola.app.
8. Changes to This Policy
We may update this policy from time to time. Changes will be posted on this page with an updated date. Continued use of the app after changes constitutes acceptance.
9. Contact
For privacy-related questions or data requests, contact us at: support@naola.app
This translation is provided for convenience. The English version is the authoritative legal text; in case of any discrepancy, the English version prevails.