Privacy

SunsetCrew · Version 1.0 · Effective September 11, 2026

SunsetCrew tells you when the sunset is worth going outside for. To do that it needs to know roughly where you are. This page explains exactly what that means, what leaves your phone, and what does not.

There is no account, no sign-up, no email address, and no password. We never learn your name. There is no advertising, and nothing inside the app that reports what you do to anyone. It keeps a record of your own evenings so it can tell whether it was right, and that record stays on your phone.

The first half of this page is written to be read. The reference sections at the foot cover retention, security, your rights, what happens if there is a breach, and how this page changes — all required, and all drier. Both halves describe the same thing.

How to read this page

Almost everything here describes SunsetCrew as it works today, at the version named above. It is deliberately specific, because a policy written in "may" and "certain information" tells you nothing and we would rather you could actually check us.

Being specific means this page changes when the app changes. Some day a feature will need something we do not collect now — a shared map of good spots, a forecast that learns from what people report, something we have not thought of. If that happens, this page will say so plainly, and the version and date at the top will change with it.

These are the promises that do not change with the version. They bind future releases, not just this one.

The first of those is the one that matters most. It is what makes the rest of this page trustworthy even though it will change: a specific description you can check today, and a commitment that you will hear about it from us first if it stops being true.

Two things can override the "we will tell you first" promise, and it is better to name them than to let you discover them.

Those are the only two exceptions. Neither is a route to doing quietly what the rest of this box forbids.

Who we are

SunsetCrew is made and operated by Drake Martinet, who is responsible for everything described on this page.

hello@sunsetcrew.app

The short version

Your exact location is not sent anywhere. Before the app uses or sends any position, it rounds it off to a square on a map — about 2 km across for the place you watch from, and about 25 km across for the points we check out to the west. What travels is that square, not you. If some future feature ever needs to know more precisely where you are, the app will ask you first, and it will be your choice.

Location is read only while the app is open. SunsetCrew asks for "while using the app" permission and nothing more. When the app is closed it cannot see where you are — not because we choose not to look, but because it was never built with the ability.

If you turn on notifications, we keep one short note about your phone: the address Apple gives us to reach it, the rounded square, your time zone, the name of your place, how much notice you asked for, and which kind of evening you want to hear about. When any of that changes we write over the old note rather than keeping both, so there is no record of where you have been.

If you never turn on notifications, we hold nothing about you beyond the aggregate traffic counts any web service records. Subscribing to a calendar feed is the one other thing that reaches us regularly, and it has its own section below.

All of the above is true of the version named at the top of this page. The commitments in "How to read this page" are what carry forward.

What stays on your phone

All of this lives on your device and is not uploaded.

WhatWhy it exists
The place you watch from — its name and coordinatesSo the app knows whose sunset to describe
A record of each evening: the date, the place, the score we gave it and how good we said it would be, whether we notified you, which sentence we used, and your answer if you gave oneSo the app can tell whether its forecasts were right, and avoid repeating itself
A copy of the weather forecasts it fetched recentlySo opening the app twice in a row does not go and ask for the same numbers again
Your settings: how often to notify, how much notice, and how many times we have offeredSo the app behaves the way you asked
A random number the app invents on your phoneOnly so that two people in the same town do not read the identical sentence. It never leaves your phone and identifies nobody. When the server picks wording for a notification it uses a different number of its own, and never sees this one.

On deleting the app. Removing SunsetCrew removes all of the above from your phone. If you use iCloud or encrypted local backups, a copy may persist inside that backup until it is overwritten or expires — which is true of every app's data and is under your control, not ours.

What leaves your phone

Getting a forecast

The app asks our server for the weather in four rounded squares: the one you are in, and three more out to the west, along the direction the sun will set. It sends nothing else — nothing that says which phone is asking, and nothing about you.

Alongside that the app asks one more question — what counts as a good evening around here? — which sends the same rounded square and today's date, and nothing else. What comes back is two numbers about the weather over that square, and every phone in it gets the same answer.

Our server keeps no log of who asked for what. Answers are held for 90 minutes and reused, filed under the square of map rather than under any person — so during that window it does show that somebody asked about a square, which is exactly what lets one question serve a whole town. It clears itself, and it leads back to no one. Cloudflare, which runs the server for us, keeps limited security and traffic information under its own policy; that is not ours to control, and it is not something we can look at to find out who asked what.

The server then rounds everything off a second time when it arrives, rather than trusting that the app did it. That is belt and braces: if a build of the app ever failed to round, or sent something finer by mistake, the server still cannot make use of it.

Turning on notifications

To send you a notification, Apple gives us an address that points at your phone — a device token, in Apple's language, and every app that can notify you has one. There is no way around it, and it is the one place where SunsetCrew knows that a particular phone exists. When you turn notifications on we send and keep:

One note per phone, written over each time. When any of it changes we replace what was there rather than adding a second entry. We can answer "where does this phone watch from now"; we cannot answer "where has it been". There is no history of your movements, because none is kept.

The two buttons on a notification. If you tap I'm going or Can't tonight, the app tells our server which one you chose, along with the address for your phone, your rounded square, and which evening it was about. The address is used only to check that a real phone sent it, and is discarded in the same breath — it is never written down beside your answer. What is kept is a count for that square on that evening: four phones here went out, and nothing that could say which four, or whether they were the same four as last night. Nothing about the tap is stored on your phone either.

Worth naming while SunsetCrew is small: in an area where only one or two people use the app, "how many went out" and "who went out" are briefly the same number. That stops being true as soon as more than a handful of people share a square, and it is the reason we keep these counts coarse rather than a reason not to have them.

We do not store your name, your email, the internet address your phone is connecting from, or any record of what you did in the app.

We hold no name, email or account, and nothing in that note is tied to a person we could identify. It is tied to a phone — and because that address stays with the phone over time, data protection law counts it as personal information even though we cannot put a name to it. We treat it that way too, which is what the rights section below is for.

Other companies involved

WhoWhat they receive
Cloudflare — runs our server and stores the note about your phoneWeb requests, as any host sees them. We keep no log of them; Cloudflare keeps limited security and traffic information under its own policy.
Open-Meteo — provides the weatherOnly rounded, multi-kilometre squares of map, and only from our server. Your phone never talks to them at all, so they never see your phone or where it is connecting from.
Apple — delivers notificationsThe address for your phone and the words of each notification. This is how notifications reach you in every iPhone app.
Your calendar provider, if you subscribe to a feed — Google, Apple, Microsoft, Fastmail or whoever you useThe link you subscribed to, which has the rounded square of map written into it. See below.

Nobody in the first three rows receives anything from us they could sell advertising against, measure you with, or trade in. Some of them are large companies that do all three in other parts of their business; what matters is that none of them gets that kind of thing from SunsetCrew. The fourth row is different, and that is why it has its own section below: a calendar provider is your supplier rather than ours, you choose it, and what it does with a feed you subscribed to is between you and them. If anyone else ever joins the list — a new host, a service that helps us spot crashes, an advertiser, a feature that needs a company we do not use today — the app will tell you before it happens, rather than leaving you to notice a new name here on your own.

The calendar feed

If you subscribe to a SunsetCrew calendar, the link you subscribe to has the rounded square of map for that place written into it.

Your calendar provider fetches that link from its own servers, on its own schedule, indefinitely — that is how subscribed calendars work everywhere. So that provider sees the approximate area the feed is about, alongside whatever it already knows about your account, and may keep its own record of those requests. The feed also syncs to every device on your account, and the link travels inside exported calendar files and shared-calendar invitations.

The link says nothing about you and contains nothing that points at your phone. But it does reveal roughly where you watch sunsets, it lasts indefinitely, and it is handled by a company we have no relationship with. Treat it as you would any link that reveals your approximate location.

Deleting your data

Children

SunsetCrew is not directed at children, and we do not knowingly collect information from them. Nothing in the app asks a person's age, name, or anything else about them. In the United States, COPPA requires parental consent before collecting personal information from a child under 13. If you believe a child has given us information, write to us — and because we hold no name or account, tell us enough to find the right phone, or use Delete my data on it, which needs no identification at all.

Purchases

SunsetCrew has no purchases of any kind. If paid features are added, this page will say so before they arrive, and it will say who handles the payment. If they are sold through Apple, which is what we would expect, your payment details go to Apple and never to us.

How long we keep things

WhatKept for
Rounded coordinates sent to fetch a forecast Not logged. The answer is held in a shared cache, keyed to the grid cell and not to you, for 90 minutes.
The notification row: token, cell, time zone, place name, notice, mode, last date messaged Until you turn notifications off, delete your data, or delete the app — or automatically 12 months after we last heard from the device, whichever comes first.
The count of taps on a notification's two buttons Kept beside the evening it belongs to, as a number attached to an area and not to any phone. Removed automatically about 120 days later, along with the rest of that evening's record.
Aggregate traffic and security data held by Cloudflare Under Cloudflare's own retention policy. Not linked to you and not available to us as a per-person record.

Turning it off is as easy as turning it on. Turning notifications off inside the app, or using Delete my data, removes the row there and then; turning them off in iOS Settings removes it the next time you open the app. You do not have to write to anyone.

Security

Everything travels over TLS. The database holding notification rows is reachable by our own server code and by the operator's Cloudflare account, which is protected by two-factor authentication. Cloudflare's dashboard and API can read and export any database on that account — that is true of every service built on it, and pretending otherwise would be the easiest claim on this page to disprove. What we have not done is build any further way in: there is no admin console for this data, no reporting tool, and no routine export.

Credentials — the weather API key and the Apple signing key — are held in Cloudflare's secret store, are not present in the app you download, and are not in our source code.

The data we do not take is itself the strongest security measure: there is no name, email, address or payment information to lose, and the location we hold is deliberately too coarse to identify a person or a building.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

If something goes wrong

If we discover a breach affecting personal data, we will assess it promptly and notify the people affected, and any authority the law requires us to tell, as quickly as the law requires. State breach-notification laws differ on the deadline and on who has to be told; we will meet whichever one applies.

Telling you has a practical problem worth naming: we hold no email addresses. There is no list to write to. So notice will come the way every other material change does — in the app, and on this page, prominently and promptly. That is not a workaround; it is the only channel that exists, and it is the same one the promises above rely on.

Your rights

We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have not done either in the preceding twelve months. We do not process sensitive personal information for the purpose of inferring characteristics about anyone.

Residents of California, Virginia, Colorado, Connecticut, Texas and other states with comparable laws have rights to know, delete, correct and opt out. We will honour access and deletion requests from any resident of any state, whether or not we are technically covered by that state's law — there is little enough here that drawing lines would be pointless. You will not be treated differently for asking.

One honest limitation. Because we hold no account and no name, we usually cannot connect an emailed request to a particular row of data. We do not know which person any row belongs to — there is nothing to check a request against. The in-app controls avoid the problem entirely, because your phone already knows which row is yours, and Delete my data needs no identification at all.

Changes to this policy

This page will change, and that is expected. It describes a specific piece of software, and software gains features.

What will not change is how you find out. If we ever collect something new, send something to someone new, or use what we hold for a new purpose, the app will tell you before it happens — and, where the law requires consent, ask you. Corrections and clarifications get a new version and date at the top of this page.

A change to how the app works is not a licence to reinterpret what we already hold. Anything collected under an earlier version stays governed by the promises made when you gave it.