Privacy Policy

Naola ("we", "our", "the app") is a weather application. We are committed to protecting your privacy. This policy explains what data we collect, why, and how it is handled.

1. Data We Collect

1.1 Location Data

When you grant location permission, the app accesses your device's geographic coordinates (latitude and longitude) to fetch weather data for your area. Location data is:

You can deny location permission and manually search for a city instead. You can revoke location permission at any time through your device settings.

1.2 IP Address

For rate limiting purposes, we store a one-way cryptographic hash (SHA-256) of your IP address. The original IP address cannot be recovered from this hash. Hashed IP records are automatically deleted after 7 days.

1.3 Feedback Messages

If you submit feedback through the app, we store the message text and your app language. Feedback is fully anonymous — no email, name, or identifying information is attached.

1.4 Subscription Data

If you make an in-app purchase, RevenueCat (the service that processes our subscriptions) receives your numeric Naola account id — the id of the anonymous device account if you never signed up — together with your platform (iOS/Android) and the store's purchase receipt. We store your subscription status against that account id. Your name and email address are never sent to RevenueCat.

1.5 Local Storage

The app stores the following on your device only:

This data never leaves your device and is cleared when you uninstall the app.

1.6 Ad Impressions and Clicks

Free-tier users see one small ad card at the bottom of the main weather screen. We do not use any third-party ad network. All ads are served from our own backend and contain no tracking pixels, cookies, or third-party scripts.

The only data we store related to ads is:

The schema has no foreign key, IP, timestamp, or any other field that could link an ad impression or click back to an individual user. It is technically impossible to reconstruct which user saw or clicked any given ad, even with full database access.

Ads do not read device advertising identifiers (IDFA, GAID), do not set cookies, and do not share any data with third parties.

Affiliate Links

Some ads contain affiliate links (e.g. Amazon Associates). These URLs include an affiliate tag that identifies Naola as the referral source. Naola does not pass any user data through these links — no device ID, no IP address, no session token, and no identifier of any kind.

However, once you tap an affiliate link and leave the app, the destination merchant (e.g. Amazon) operates under their own privacy policy. The merchant may use cookies or other mechanisms on their site to attribute the visit to the affiliate tag. This is standard affiliate program behavior and is outside Naola's control.

If you prefer not to be tracked by the merchant, you can choose not to tap the ad, or clear your browser cookies after visiting the merchant's site.

Advanced subscribers do not see any ads and no ad-related data is recorded for them.

1.7 Account Data

You don't need to sign up to use Naola. On first launch, the Android and iOS apps create an anonymous device account: a numeric id, a placeholder address that no one can receive mail at (…@device.naola.invalid), and a hash of a random secret kept in your device's keystore. It contains no personal data. It exists so that a subscription bought on that device is recognised without asking for your email.

Signing up with an email address, Apple or Google is optional. You need it only to move a subscription between Android and iOS. The web version never creates accounts: to use Advanced on the web, you generate an activation code in the mobile app.

What we store for an account:

The web version does not have a registration form. To use Advanced on the web you generate an activation code in the mobile app (Settings → Account → Activate Naola on the web) and paste it at naola.net/activate. The web cannot create new accounts or new subscriptions on its own.

Sessions are managed via JSON Web Tokens (JWTs) signed with HMAC-SHA256, valid for 30 days. Each JWT is bound to the device identifier of its slot.

1.8 Browser Cookies (Website and Web App)

The Naola website (naola.net) and web app (naola.net/app) use only these cookies, both strictly necessary:

Under GDPR/ePrivacy, strictly-necessary cookies do not require prior consent. The lang cookie is set either when you choose a language in the footer, or when the site detects your browser's Accept-Language header and redirects you to the matching language for the first time.

Our analytics sets no cookies (see Section 1.9). You can clear cookies at any time in your browser settings. The Android and iOS apps don't use browser cookies.

1.9 Website Analytics

To understand how many people visit naola.net and the web app, and which pages they use, we run Matomo, an open-source analytics tool, on our own server in the European Union. No other company receives this data. The Android and iOS apps contain no analytics at all.

This is analytics, not tracking:

What Matomo records: the pages you view, the site that linked you here, your browser, operating system, screen size and language, and an approximate country. Individual visits are deleted after 6 months; after that we keep only totals, such as monthly page views.

The legal basis is our legitimate interest in knowing how the site is used (GDPR Art. 6(1)(f)). To opt out, turn on "Do Not Track" or Global Privacy Control in your browser: Matomo then doesn't load at all.

2. Data We Do Not Collect

3. Third-Party Services

To provide weather data, your coordinates are sent to the following services during each weather request:

a Available with Naola Advanced.

For in-app purchases:

For email:

Each service has its own privacy policy linked above. We encourage you to review them.

Our website analytics (Section 1.9) runs on our own server, so no analytics company receives your data.

4. Data Retention

5. Data Processing Location

Naola's database is held under Cloudflare's European Union jurisdiction — a binding restriction, fixed when the database was created, that keeps every account, subscription and feedback record we store inside the EU and prevents it from being relocated elsewhere. Our backend runs on Cloudflare Workers, a globally distributed network, so a request may first be handled at the edge location nearest you before it reaches that database. Location coordinates are processed in memory only and are never written to our database.

6. Children's Privacy

Naola does not knowingly collect data from children under 13. The app does not require an account and collects no personal information.

7. Your Rights

Under GDPR (Articles 15, 17, and 20) and similar regulations, you have the right to access, delete, and port your data. Naola provides these as self-service actions, so you don't need to email support or wait on a manual process — though email remains an option if you can't use the app.

Export your data (Art. 15 and 20)

In the mobile app: Settings → Account → Export my data. You'll get a JSON file containing every row we have linked to your account (profile, OAuth links, subscription entitlements, activation-code metadata). The export is in a structured, machine-readable format for portability to other services.

On the web: once Naola is activated in your browser, Settings → Account → Export my data in the web app at naola.net/app. If you can't use the app, email support@naola.app.

Delete your account (Art. 17)

In the mobile app: Settings → Account → Delete my account. A two-step confirmation removes every user-linked row from our database (profile, OAuth links, activation codes, subscription entitlements, webhook event history).

On the web: naola.net/delete-account, with an activation code from the mobile app; the deletion is immediate and permanent. If you can't use the app, email support@naola.app from the address on your account and we will erase it within 30 days.

Important — subscriptions are billed by Apple and Google, not by us. Deleting your Naola account does not cancel your App Store or Google Play subscription. Before deleting, go to Settings → [your name] → Subscriptions on iPhone, or Google Play → Payments & subscriptions → Subscriptions on Android, and cancel Naola Advanced, otherwise you will continue to be charged at renewal. We remove our entitlement record immediately so the app stops treating you as Advanced, but the billing relationship stays with the store until you cancel there.

Other rights

For objection to processing, rectification of data, complaint to a supervisory authority, or any other GDPR-related question not covered by the self-service options, email support@naola.app.

8. Changes to This Policy

We may update this policy from time to time. Changes will be posted on this page with an updated date. Continued use of the app after changes constitutes acceptance.

9. Contact

For privacy-related questions or data requests, contact us at: support@naola.app