Last updated August 24, 2026
Account: your email address, display name, and handle. You can sign in with a password or with a one-time emailed code. Passwords are handled and stored by our authentication provider (Supabase), hashed — never by us in plain text, and never visible to us.
Device location:with your permission and only while you use the app, SunnySky reads a precise latitude and longitude to show local conditions, alerts, maps, and nearby activity, and when you ask it to plan a weather-aware route. Those coordinates leave your device when needed for the weather, map, place-name, and routing services listed below. The numeric coordinates stored with reports and asks are snapped to a ~5 km grid cell. A location label is also stored; if a place name cannot be found, that label may be a coordinate rounded to two decimal places. Push context uses a coarser ~20 km cell, and optional presence shares a place name rather than coordinates. You can use SunnySky with a manually chosen city instead.
Website location estimate: when you visit sunnyweather.co, its host, Vercel, may derive an approximate city and coordinates from your IP address to localize the live weather example. SunnySky sends that estimate to Open-Meteo and uses its coarse ~20 km grid cell to look up a recent forecast receipt in Supabase. This does not use your device's GPS or location permission and is not linked to a SunnySky account.
Content you post: condition reports, asks, answers, confirmations, photos you attach, and your follow lists.
Device:a push-notification token if you enable notifications, and — so alerts can reach the right area — a coarse ~20 km grid cell, never your exact position.
Preferences: units, activities, pinned readings and card order are stored with your account so the app looks the same on a new phone. Your active location, manual override, last GPS fix, and whether you have finished setup stay on the device. Places you choose to follow and locations used for custom alert rules are stored with your account so those features can work across sessions and while the app is closed.
Diagnostics: the native app sends crash diagnostics and samples performance traces through Sentry. These may include the error and code location, technical app and device details, and a request URL used during a failed or slow operation. A weather request URL can contain coordinates. SunnySky does not deliberately attach your name, email, handle, or other account profile to these reports and does not use them for advertising or profiling. Sentry receives the IP address used to send the report.
Links you share: weather cards and wall-display links that you choose to share encode a location rounded to two decimal places or as a six-character geohash. Anyone with the link can infer the shared area, and a weather-card page may display its rounded coordinates. Share only locations you intend to disclose.
To run the product: showing your reports to nearby users per your visibility choice, answering asks, notifying you of answers and activity at places you follow, and enforcing community rules. We do not sell your data or use it for advertising.
Sunnyweather.co is hosted by Vercel, which processes ordinary web request information such as your IP address and may supply the approximate city and coordinates used for the website location estimate described above. Account and community data is stored with Supabase (Postgres, authentication, file storage, and Edge Functions). For current conditions, forecasts, alerts, air quality, pollen, marine weather, and river context, a precise or slightly rounded latitude and longitude is sent to Open-Meteo, MET Norway, the US National Weather Service, Apple WeatherKit, Pirate Weather, OpenWeather, Google Weather, and Google Pollen. Nearby observation and climate searches send a location-derived search area to the US Aviation Weather Center, NOAA/NCEI, ACIS, and USGS. NOAA tide and buoy feeds receive a station identifier selected by the app rather than your coordinates.
Open-Meteo, Apple WeatherKit, Pirate Weather, OpenWeather, Google Weather, and Google Pollen are reached through SunnySky's Supabase functions. Signed-in requests carry your authentication to Supabase, but Supabase does not forward your SunnySky account details to those upstream providers; they receive our server's IP address rather than yours. MET Norway, the National Weather Service, the Aviation Weather Center, NOAA/NCEI, ACIS, and USGS may be contacted directly and therefore receive your device IP address. All of these requests use HTTPS. On native devices, the operating system's place-name service may reverse-geocode a coordinate; when that is unavailable, SunnySky sends the coordinate through Supabase to OpenStreetMap's Nominatim service.
If you use route planning, the chosen origin and destination are sent to Apple Maps through MapKit on iOS, or to SunnySky's authenticated Supabase function and then Google Routes on Android and the web. Sample points along the resulting route are sent to Open-Meteo and, in the United States, the National Weather Service to check weather and alerts along the drive. SunnySky authenticates the Google route request to enforce an abuse limit; Apple and Google do not receive your SunnySky account details.
Opening or moving the map requests tiles identified by map-grid coordinates from CARTO, RainViewer, the Iowa Environmental Mesonet, and NASA GIBS, depending on the layers shown. Those services receive your IP address and can infer the area visible on the map even though the tile request does not contain your account information.
Delete your account any time in Profile → Delete Account. This permanently removes your account, reports, asks, follows, photos, and tokens. Deleting an individual report removes it from SunnySky and requests deletion of its attached photos without deleting your account. Shared weather cache entries use rounded coordinates and expire within two days. On Android and the web, a route response containing sampled points along the requested road may also be cached in Supabase for up to two days; it is not joined to your profile, although the route itself can reveal the chosen area. A pseudonymous route-request counter keyed to your account ID may remain for up to two days after account deletion for abuse prevention; it contains no route or location.
SunnySky is not directed at children under 13.
The Sunny Weather Company · support@sunnyweather.co