Privacy
SunsetCrew tells you when the sunset is worth going outside for. To do that it needs to know roughly where you are. This page explains exactly what that means, what leaves your phone, and what does not.
There is no account, no sign-up, no email address, and no password. We never learn your name. There is no advertising, and nothing inside the app that reports what you do to anyone. It keeps a record of your own evenings so it can tell whether it was right, and that record stays on your phone.
The first half of this page is written to be read. The reference sections at the foot cover retention, security, your rights, what happens if there is a breach, and how this page changes — all required, and all drier. Both halves describe the same thing.
How to read this page
Almost everything here describes SunsetCrew as it works today, at the version named above. It is deliberately specific, because a policy written in "may" and "certain information" tells you nothing and we would rather you could actually check us.
Being specific means this page changes when the app changes. Some day a feature will need something we do not collect now — a shared map of good spots, a forecast that learns from what people report, something we have not thought of. If that happens, this page will say so plainly, and the version and date at the top will change with it.
These are the promises that do not change with the version. They bind future releases, not just this one.
- We will not start collecting something new, or send anything to someone new, without telling you in the app before it happens — not in a list of changes you would have to go looking for, and not after the fact.
- Anything we collect will be the least that makes the feature work, and you will be able to say no to the feature and keep the app.
- You will always be able to delete what we hold, from inside the app, without asking anyone.
The first of those is the one that matters most. It is what makes the rest of this page trustworthy even though it will change: a specific description you can check today, and a commitment that you will hear about it from us first if it stops being true.
Two things can override the "we will tell you first" promise, and it is better to name them than to let you discover them.
- A court can compel us. If served with a valid subpoena, warrant or order, we have to comply, and some of those forbid telling you. What could actually be handed over is small: the address Apple gave us for reaching your phone, a rounded square of map about 2 km across, a time zone, a place name and a couple of settings. We will insist on proper legal process, push back on requests that are overbroad, hand over the narrowest thing that answers the request, and tell you unless we are forbidden to.
- SunsetCrew could be sold. If the app changes hands, what we hold about the phones we notify goes with it — a sunset app with no way to notify anyone is not the same app. If that happens, we will make these promises a condition of the sale, and the data moves only with the app itself, never separately. You will hear about it in the app before it completes — or as soon as we lawfully can, if someone else is running the sale, as a trustee would in an insolvency — with time to delete your data first.
Those are the only two exceptions. Neither is a route to doing quietly what the rest of this box forbids.
Who we are
SunsetCrew is made and operated by Drake Martinet, who is responsible for everything described on this page.
The short version
Your exact location is not sent anywhere. Before the app uses or sends any position, it rounds it off to a square on a map — about 2 km across for the place you watch from, and about 25 km across for the points we check out to the west. What travels is that square, not you. If some future feature ever needs to know more precisely where you are, the app will ask you first, and it will be your choice.
Location is read only while the app is open. SunsetCrew asks for "while using the app" permission and nothing more. When the app is closed it cannot see where you are — not because we choose not to look, but because it was never built with the ability.
If you turn on notifications, we keep one short note about your phone: the address Apple gives us to reach it, the rounded square, your time zone, the name of your place, how much notice you asked for, and which kind of evening you want to hear about. When any of that changes we write over the old note rather than keeping both, so there is no record of where you have been.
If you never turn on notifications, we hold nothing about you beyond the aggregate traffic counts any web service records. Subscribing to a calendar feed is the one other thing that reaches us regularly, and it has its own section below.
All of the above is true of the version named at the top of this page. The commitments in "How to read this page" are what carry forward.
What stays on your phone
All of this lives on your device and is not uploaded.
| What | Why it exists |
|---|---|
| The place you watch from — its name and coordinates | So the app knows whose sunset to describe |
| A record of each evening: the date, the place, the score we gave it and how good we said it would be, whether we notified you, which sentence we used, and your answer if you gave one | So the app can tell whether its forecasts were right, and avoid repeating itself |
| A copy of the weather forecasts it fetched recently | So opening the app twice in a row does not go and ask for the same numbers again |
| Your settings: how often to notify, how much notice, and how many times we have offered | So the app behaves the way you asked |
| A random number the app invents on your phone | Only so that two people in the same town do not read the identical sentence. It never leaves your phone and identifies nobody. When the server picks wording for a notification it uses a different number of its own, and never sees this one. |
On deleting the app. Removing SunsetCrew removes all of the above from your phone. If you use iCloud or encrypted local backups, a copy may persist inside that backup until it is overwritten or expires — which is true of every app's data and is under your control, not ours.
What leaves your phone
Getting a forecast
The app asks our server for the weather in four rounded squares: the one you are in, and three more out to the west, along the direction the sun will set. It sends nothing else — nothing that says which phone is asking, and nothing about you.
Alongside that the app asks one more question — what counts as a good evening around here? — which sends the same rounded square and today's date, and nothing else. What comes back is two numbers about the weather over that square, and every phone in it gets the same answer.
Our server keeps no log of who asked for what. Answers are held for 90 minutes and reused, filed under the square of map rather than under any person — so during that window it does show that somebody asked about a square, which is exactly what lets one question serve a whole town. It clears itself, and it leads back to no one. Cloudflare, which runs the server for us, keeps limited security and traffic information under its own policy; that is not ours to control, and it is not something we can look at to find out who asked what.
The server then rounds everything off a second time when it arrives, rather than trusting that the app did it. That is belt and braces: if a build of the app ever failed to round, or sent something finer by mistake, the server still cannot make use of it.
Turning on notifications
To send you a notification, Apple gives us an address that points at your phone — a device token, in Apple's language, and every app that can notify you has one. There is no way around it, and it is the one place where SunsetCrew knows that a particular phone exists. When you turn notifications on we send and keep:
- the device token Apple issued for reaching your phone
- the rounded square you are in — not where you actually are
- your time zone, so we know when evening is where you are
- the name of your place — "Encinitas, CA" — so a notification can say which place it is about. Usually vaguer than the square beside it, though not always; its only use is to appear on your own phone.
- how much notice you asked for
- whether you want every visible sunset or only the special ones
- the date we last messaged you, so we never message twice about one evening
One note per phone, written over each time. When any of it changes we replace what was there rather than adding a second entry. We can answer "where does this phone watch from now"; we cannot answer "where has it been". There is no history of your movements, because none is kept.
The two buttons on a notification. If you tap I'm going or Can't tonight, the app tells our server which one you chose, along with the address for your phone, your rounded square, and which evening it was about. The address is used only to check that a real phone sent it, and is discarded in the same breath — it is never written down beside your answer. What is kept is a count for that square on that evening: four phones here went out, and nothing that could say which four, or whether they were the same four as last night. Nothing about the tap is stored on your phone either.
Worth naming while SunsetCrew is small: in an area where only one or two people use the app, "how many went out" and "who went out" are briefly the same number. That stops being true as soon as more than a handful of people share a square, and it is the reason we keep these counts coarse rather than a reason not to have them.
We do not store your name, your email, the internet address your phone is connecting from, or any record of what you did in the app.
We hold no name, email or account, and nothing in that note is tied to a person we could identify. It is tied to a phone — and because that address stays with the phone over time, data protection law counts it as personal information even though we cannot put a name to it. We treat it that way too, which is what the rights section below is for.
Other companies involved
| Who | What they receive |
|---|---|
| Cloudflare — runs our server and stores the note about your phone | Web requests, as any host sees them. We keep no log of them; Cloudflare keeps limited security and traffic information under its own policy. |
| Open-Meteo — provides the weather | Only rounded, multi-kilometre squares of map, and only from our server. Your phone never talks to them at all, so they never see your phone or where it is connecting from. |
| Apple — delivers notifications | The address for your phone and the words of each notification. This is how notifications reach you in every iPhone app. |
| Your calendar provider, if you subscribe to a feed — Google, Apple, Microsoft, Fastmail or whoever you use | The link you subscribed to, which has the rounded square of map written into it. See below. |
Nobody in the first three rows receives anything from us they could sell advertising against, measure you with, or trade in. Some of them are large companies that do all three in other parts of their business; what matters is that none of them gets that kind of thing from SunsetCrew. The fourth row is different, and that is why it has its own section below: a calendar provider is your supplier rather than ours, you choose it, and what it does with a feed you subscribed to is between you and them. If anyone else ever joins the list — a new host, a service that helps us spot crashes, an advertiser, a feature that needs a company we do not use today — the app will tell you before it happens, rather than leaving you to notice a new name here on your own.
The calendar feed
If you subscribe to a SunsetCrew calendar, the link you subscribe to has the rounded square of map for that place written into it.
Your calendar provider fetches that link from its own servers, on its own schedule, indefinitely — that is how subscribed calendars work everywhere. So that provider sees the approximate area the feed is about, alongside whatever it already knows about your account, and may keep its own record of those requests. The feed also syncs to every device on your account, and the link travels inside exported calendar files and shared-calendar invitations.
The link says nothing about you and contains nothing that points at your phone. But it does reveal roughly where you watch sunsets, it lasts indefinitely, and it is handled by a company we have no relationship with. Treat it as you would any link that reveals your approximate location.
Deleting your data
- In the app: Settings → Delete my data. This erases everything our server holds about your phone and every evening stored on the phone itself, immediately. It is the fastest and most complete route, and it needs nothing from you but a tap. Your saved place stays, so the app keeps working.
- Turning notifications off erases what the server holds too, because we have no reason to keep anything once you have asked us to stop. That is true whether you switch them off inside the app, which takes effect there and then, or in iOS Settings, which takes effect the next time you open the app.
- Deleting the app removes everything held on your phone. Apple then tells us the phone can no longer be reached, and we erase what we hold the next time we try to message you. If that never happens, it goes on its own: we delete everything we hold about a phone twelve months after we last heard from it.
- Or write to us at hello@sunsetcrew.app and we will do it for you — though we hold no name or account, so you will need to tell us enough to find the right phone. The in-app controls accomplish the same thing and avoid that problem entirely, which is why they are listed first.
Children
SunsetCrew is not directed at children, and we do not knowingly collect information from them. Nothing in the app asks a person's age, name, or anything else about them. In the United States, COPPA requires parental consent before collecting personal information from a child under 13. If you believe a child has given us information, write to us — and because we hold no name or account, tell us enough to find the right phone, or use Delete my data on it, which needs no identification at all.
Purchases
SunsetCrew has no purchases of any kind. If paid features are added, this page will say so before they arrive, and it will say who handles the payment. If they are sold through Apple, which is what we would expect, your payment details go to Apple and never to us.
How long we keep things
| What | Kept for |
|---|---|
| Rounded coordinates sent to fetch a forecast | Not logged. The answer is held in a shared cache, keyed to the grid cell and not to you, for 90 minutes. |
| The notification row: token, cell, time zone, place name, notice, mode, last date messaged | Until you turn notifications off, delete your data, or delete the app — or automatically 12 months after we last heard from the device, whichever comes first. |
| The count of taps on a notification's two buttons | Kept beside the evening it belongs to, as a number attached to an area and not to any phone. Removed automatically about 120 days later, along with the rest of that evening's record. |
| Aggregate traffic and security data held by Cloudflare | Under Cloudflare's own retention policy. Not linked to you and not available to us as a per-person record. |
Turning it off is as easy as turning it on. Turning notifications off inside the app, or using Delete my data, removes the row there and then; turning them off in iOS Settings removes it the next time you open the app. You do not have to write to anyone.
Security
Everything travels over TLS. The database holding notification rows is reachable by our own server code and by the operator's Cloudflare account, which is protected by two-factor authentication. Cloudflare's dashboard and API can read and export any database on that account — that is true of every service built on it, and pretending otherwise would be the easiest claim on this page to disprove. What we have not done is build any further way in: there is no admin console for this data, no reporting tool, and no routine export.
Credentials — the weather API key and the Apple signing key — are held in Cloudflare's secret store, are not present in the app you download, and are not in our source code.
The data we do not take is itself the strongest security measure: there is no name, email, address or payment information to lose, and the location we hold is deliberately too coarse to identify a person or a building.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
If something goes wrong
If we discover a breach affecting personal data, we will assess it promptly and notify the people affected, and any authority the law requires us to tell, as quickly as the law requires. State breach-notification laws differ on the deadline and on who has to be told; we will meet whichever one applies.
Telling you has a practical problem worth naming: we hold no email addresses. There is no list to write to. So notice will come the way every other material change does — in the app, and on this page, prominently and promptly. That is not a workaround; it is the only channel that exists, and it is the same one the promises above rely on.
Your rights
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have not done either in the preceding twelve months. We do not process sensitive personal information for the purpose of inferring characteristics about anyone.
Residents of California, Virginia, Colorado, Connecticut, Texas and other states with comparable laws have rights to know, delete, correct and opt out. We will honour access and deletion requests from any resident of any state, whether or not we are technically covered by that state's law — there is little enough here that drawing lines would be pointless. You will not be treated differently for asking.
One honest limitation. Because we hold no account and no name, we usually cannot connect an emailed request to a particular row of data. We do not know which person any row belongs to — there is nothing to check a request against. The in-app controls avoid the problem entirely, because your phone already knows which row is yours, and Delete my data needs no identification at all.
Changes to this policy
This page will change, and that is expected. It describes a specific piece of software, and software gains features.
What will not change is how you find out. If we ever collect something new, send something to someone new, or use what we hold for a new purpose, the app will tell you before it happens — and, where the law requires consent, ask you. Corrections and clarifications get a new version and date at the top of this page.
A change to how the app works is not a licence to reinterpret what we already hold. Anything collected under an earlier version stays governed by the promises made when you gave it.