Your device location, or a location you choose, may be used for local aurora chance, darkness, cloud, weather, Moon, horizon context, nearby viewing information and alert decisions.
Privacy policy
Aurora Beacon app privacy policy
A plain-English explanation of the personal information Aurora Beacon uses, why it is needed, who may process it and the choices available to you.
1. Who we are
Aurora Beacon is an aurora forecasting and observation service operated by Neil Thomas in the United Kingdom. In this policy, “Aurora Beacon”, “we”, “us” and “our” refer to the operator of the Aurora Beacon mobile app, website and supporting service.
For privacy questions, rights requests or data-protection complaints, use the Aurora Beacon support page.
2. What this policy covers
This policy covers the Aurora Beacon mobile app on iPhone and Android, the Aurora Beacon website, account and subscription services, aurora alerts, Community contributions and the backend services used to provide those features.
Scientific and environmental data used to create aurora forecasts is generally not personal data. This policy focuses on information that relates, or could reasonably be linked, to a user or device.
3. The information Aurora Beacon may use
A push-notification token, device/platform information and your alert preferences may be used to deliver aurora alerts to your device.
If you sign in, account identifiers and profile information may be used to keep your preferences, achievements, subscriptions and contributions linked to your account.
Subscription status, product identifiers, purchase-validation information and related transaction references may be processed so Plus access can be granted and restored. Payment-card details are handled by Apple or Google, not by Aurora Beacon.
Optional contributions may include the uploaded image, observation time, location/context, caption or notes, moderation status and contributor information needed to review and display the observation.
Basic screen or feature events, a device identifier, app version, platform details, request/error information and similar operational data may be used to diagnose faults, protect the service and improve reliability.
4. Location
Aurora visibility is highly location-dependent, so Aurora Beacon may ask for location permission to make Tonight, local weather and darkness checks, maps, viewing guidance and alerts relevant to where you are.
You can deny or change location permission in Aurora Beacon or in your device settings. Some local features will be less useful without it. Exact device locations are not displayed publicly. Community locations shown to other users are intended to be rounded, moderated or otherwise made less precise.
5. Notifications and alerts
If you enable notifications, Aurora Beacon uses a push token and your alert settings to send time-sensitive aurora notifications. Notification permission can be changed in iOS or Android settings, and alert types or sensitivity can be changed inside Aurora Beacon.
Turning notifications off stops the device from receiving alerts, but some technical token or preference records may remain temporarily until they are cleaned up, invalidated or no longer needed for service operation.
6. Accounts, sign-in and profile information
If you choose to sign in, Aurora Beacon may receive an account identifier and profile information needed to create or maintain your Aurora Beacon account. Sign-in may be provided through Apple or Google.
Account data can be used to keep preferences, Observer Passport progress, achievements, Community contributions and subscription entitlement associated with you across sessions or devices. Signing out removes the active session from that device; it does not by itself delete the server-side account.
7. Subscriptions and payments
Paid subscriptions are purchased through the Apple App Store or Google Play. Apple or Google handles the payment method. Aurora Beacon may receive and store product, entitlement, renewal, expiry, cancellation and transaction-reference information needed to verify a purchase and provide Plus features.
Apple and Google have their own privacy policies and act independently for payment processing and store-account data.
8. Community photos and public contributions
Uploading a Community observation is optional. Aurora Beacon processes the photo and the observation details needed to review, moderate, manage and, if approved, display the contribution. Automated checks may assist moderation, but contributions are reviewed before public publication.
Your own observations can be reviewed and deleted through the app where that control is available. Public Community display is designed not to expose an exact private device position.
If Aurora Beacon offers a separate choice allowing a contribution to be reused on Aurora Beacon social-media channels, that permission is recorded separately from normal in-app Community publication. Declining that optional permission does not prevent normal Community use where you have submitted the observation for that purpose.
9. Automated processing and AI-assisted review
Aurora Beacon uses automated calculations to produce forecasts, local viewing guidance and alert decisions. These outputs are informational and do not make decisions that have legal or similarly significant effects on you.
Automated or AI-assisted checks may support Community photo moderation or explanatory app features. They are treated as supporting evidence rather than an unquestionable decision, and Community photos are not made public solely because an automated check approves them.
10. Why we use personal information
Depending on the feature and circumstances, Aurora Beacon relies on one or more of the following lawful bases:
- Contract — where processing is needed to provide an account, subscription or feature you have requested.
- Legitimate interests — to operate a secure and reliable service, prevent abuse, diagnose faults and improve Aurora Beacon, where those interests are not overridden by your rights.
- Consent — where we ask for a separate optional permission for a specific use, such as separate social-media reuse of a Community contribution. You can withdraw that consent for future use.
- Legal obligation — where information must be retained or disclosed to comply with applicable law, accounting, tax, dispute or regulatory requirements.
Device permissions such as location and notifications give you technical control over access on your phone. A device permission is not necessarily the same thing as the legal basis used under data-protection law.
11. Who may process information
We do not sell personal data. Information may be processed by service providers where needed to run Aurora Beacon, including:
- cloud hosting, database, security, content-delivery and infrastructure providers;
- Apple and Google for platform sign-in, app distribution, subscriptions and payment processing;
- Firebase Cloud Messaging / Google services used to deliver push notifications;
- Mapbox and other mapping services used to display maps and geographic context;
- weather or location-related service providers where a local forecast requires a geographic query; and
- professional advisers, regulators or law-enforcement bodies where disclosure is legally required.
Scientific data providers such as space-weather and geomagnetic organisations generally provide data to Aurora Beacon; they are not given your Aurora Beacon account profile simply because their scientific data is used in the app.
12. International processing
Some platform and technology providers operate internationally. This means personal information may be processed outside the United Kingdom. Where data-protection law requires safeguards for an international transfer, we use the safeguards applicable to the provider and transfer, such as an adequacy arrangement or appropriate contractual protections.
13. How long information is kept
We keep personal information only for as long as it is reasonably needed for the purpose for which it was collected, for service security, or to meet legal obligations. The exact period varies by category:
- Account and profile data — normally while the account is active, then for the limited period needed to complete deletion, protect the service, resolve disputes or meet legal obligations.
- Push tokens and alert preferences — while needed to provide notifications, until invalid, disabled, deleted or no longer operationally required.
- Community contributions — while you keep the contribution in Aurora Beacon, subject to moderation, deletion, backup and legal requirements.
- Usage, diagnostic and security records — for a limited operational period based on the need to diagnose faults, investigate incidents, prevent abuse and understand service reliability.
- Subscription and transaction records — for as long as needed to provide entitlement, handle disputes and comply with accounting, tax or other legal requirements.
- Consent records — for as long as reasonably needed to record what you agreed to, when you agreed, and any later withdrawal.
Backups may retain deleted information for a limited additional period until normal backup rotation removes it.
14. Security
Aurora Beacon uses technical and organisational measures intended to protect information against unauthorised access, loss, misuse or alteration. These include encrypted network connections, restricted administrative access, separation between public and private operational services, service monitoring and controlled production infrastructure.
No internet service can guarantee absolute security. If we become aware of a personal-data breach, we will assess and handle it in accordance with applicable legal requirements.
15. Your choices and privacy rights
Depending on the circumstances and applicable law, you may have rights to ask for access to your personal information, correction, deletion, restriction, portability, or to object to certain processing. Where processing is based on consent, you may withdraw that consent for future processing.
Inside Aurora Beacon you can also control location permission, notifications and alert settings, review account/profile information, and manage your own Community observations where those controls are provided.
To delete your Aurora Beacon account or request deletion of specific personal data, see Delete your Aurora Beacon account. To exercise another legal privacy right or raise a data-protection complaint, use the support route. We may need enough information to verify your identity and locate the relevant account or contribution before acting on a request.
16. Website privacy
The Aurora Beacon website may generate ordinary server, security and content-delivery logs containing information such as IP address, request time, requested URL, browser/user-agent information and security signals. Cloudflare is used to help deliver and protect the public website.
The website does not currently use behavioural advertising or third-party advertising SDKs. If website analytics, marketing cookies or similar tracking are added later, this policy and any required consent controls will be updated before those tools are used.
17. Complaints
Please contact Aurora Beacon first if you have a concern about how your personal information has been handled so we have an opportunity to investigate and respond.
If you remain dissatisfied, you may also complain to the UK Information Commissioner’s Office (ICO). Information about making a complaint is available from ico.org.uk.
18. Changes to this policy
We may update this policy when Aurora Beacon features, service providers, legal requirements or data practices change. The “last updated” date at the top of this page will be changed when a material revision is published.
19. Contact
Data controller: Neil Thomas, Aurora Beacon, United Kingdom.
Privacy enquiries, rights requests and data-protection complaints should be made through the Aurora Beacon support page.