Privacy Policy

Last updated: August 8, 2026
The short version: Heliosinger does not sell personal data, show ads, or track people across other companies' apps and websites. The website makes sound in your browser. The iPhone and Android apps use installation identifiers and network services to load space-weather data, support purchases, and—when configured—deliver alerts. The iPhone app also sends limited product events and Apple MetricKit diagnostics.

What this policy covers

Website data

The website synthesizes audio in your browser. It stores audio and display settings, notification settings, recent space-weather event history, and similar preferences in browser localStorage. Its service worker may cache the app shell and other static files, but not API responses. This local information is not an account and is removed according to your browser's storage controls.

The website currently sends ambient display settings to a compatibility API endpoint when they change. The endpoint validates and returns those settings but does not store the request body. Ordinary web and API requests still expose network metadata such as IP address, user agent, requested path, request identifier, status, and timing to Heliosinger's Cloudflare-hosted infrastructure and its security and operational logs.

A production build may include Cloudflare Web Analytics when its site token is configured. That service measures aggregate page and performance information; Heliosinger does not use it for cross-site advertising profiles. The site also loads fonts from Google and an App Store badge from Apple, so a visitor's browser may send those providers ordinary request metadata under their own policies.

Installation identity & API security

The native apps generate a random Heliosinger installation ID. It is not an Apple ID, Google account, email address, IDFA, Android Advertising ID, or identifier Heliosinger can use across other apps. Requests may include the installation ID, app/platform version, time zone, and ordinary network metadata.

The apps also create an installation secret used to authenticate changes to that installation's server registration. The raw secret is kept in the iPhone Keychain or encrypted using the Android Keystore. It is sent to the Heliosinger API over HTTPS when needed; the server stores a one-way SHA-256 hash rather than the raw secret.

Alerts & push notifications

If an installation is registered for alerts, Heliosinger stores its installation ID, push token, platform, app version, time zone, alert switches and thresholds, quiet hours, and related preferences. Notification-delivery records contain the installation ID, event identifier, delivery status or reason, and time.

Alert payloads and tokens pass through Apple APNs or Google FCM for delivery. The dispatcher retains provider response status for operations. A legacy delivery path may use Expo for older token formats; current native apps use APNs or FCM.

Purchases

Heliosinger+ is a one-time purchase handled by the store for the platform.

iPhone product events & diagnostics

The iPhone app sends a limited product-event stream to Heliosinger's backend. Each event contains the installation ID, time, a short event name, and limited properties. Current events cover onboarding, first playback, upgrade-sheet triggers, purchase completion, capture start, background-audio stops, app backgrounding, and store-loading failures. These events do not contain recorded audio or the space-weather values being viewed. Pending events may be buffered in the app's local preferences until upload.

The iPhone app also uploads Apple MetricKit metric and diagnostic payloads with its installation ID and app version. Depending on what Apple reports for an installation, those payloads can contain crash, hang, launch, memory, disk-write, and performance diagnostics. The Android app does not currently include Heliosinger analytics, Firebase Analytics, Crashlytics, or Firebase Performance Monitoring.

Data kept on the device

Both native apps cache public space-weather frames and settings locally. The iPhone app also stores alert settings, listening history and streaks, timer and display choices, and an app-group snapshot for its widget. Current StoreKit entitlement is resolved from StoreKit rather than a Heliosinger purchase-entitlement cache. Android stores app preferences and encrypts its FCM token and installation secret; its backup rules exclude these credentials.

The iPhone Capture & Share feature creates a temporary video file on the device from app visuals and generated audio. It does not use microphone input. Heliosinger does not upload that file to its backend. A file leaves the device only when the user chooses a destination in Apple's share sheet or saves it to Photos, in which case the selected destination's terms and privacy policy apply.

How the data is used

What Heliosinger does not do

Heliosinger does use service SDKs and processors needed for the product: Firebase Cloud Messaging and Google Play Billing on Android, Apple StoreKit/APNs/MetricKit on iPhone, and Cloudflare hosting, database, logging, security, and optional Web Analytics services.

Space-weather sources

Heliosinger's servers obtain public scientific data from NOAA services. The iPhone app can contact a NOAA solar-wind feed directly as a fallback, in which case NOAA receives ordinary request metadata. See the credits page for data sources and attributions.

Support communications

If you choose to email support, we receive the email address, message, attachments, and troubleshooting or transaction details you include, such as platform, OS/app version, or a Google Play order number. This information is handled through our email provider and used to respond, investigate the request, process a deletion request, and protect purchase and service integrity. Do not send a push token, raw Play purchase token, or installation secret. Support records are kept as needed to handle the request and related transaction, security, and legal obligations while the exact schedule is under review; you can ask us to delete a support conversation subject to those limits.

Retention & deletion

Turning off Storm alerts asks the backend to remove the current device registration. On Android, the app also asks FCM to delete its token, but FCM can create a new Firebase installation token later while automatic initialization remains enabled; that alone does not create a Heliosinger alert registration. Deleting an app or clearing browser storage stops future local use but does not by itself guarantee immediate deletion of records already received by Heliosinger or a platform provider.

There is no Heliosinger user account or self-service data portal. To request deletion of server records associated with an installation, email [email protected] and include enough information for us to locate the installation if available. We will explain what can be matched and deleted and what, if anything, must be retained for security, transaction, or legal reasons. Because the released apps do not currently expose a reliable copyable installation ID in every build, support may need to work with you to identify the relevant record.

Children's privacy

Heliosinger is not directed to children under 13. We do not knowingly collect information from a child beyond the product and operational data described in this policy. If you believe a child has provided information that should be removed, contact us.

Security

Data is transmitted over HTTPS. Cloudflare hosts the backend and D1 databases and provides network-security controls. Installation secrets are encrypted at rest on the device and only a one-way hash is stored by Heliosinger's server. No method of storage or transmission can be guaranteed completely secure.

Changes

If this policy changes materially, we will update the "Last updated" date. Whether an additional in-app or website notice is required will depend on the change and applicable platform or legal requirements.

Contact

Questions or deletion requests: [email protected].