Hamblin Weather Privacy Policy
Last updated: September 3, 2026
Hamblin Weather LLC ("Hamblin Weather") provides weather conditions and forecasts, active National Weather Service alerts, Hamblin Weather editorial coverage, links to live coverage and videos, and optional push notifications. This policy describes the current Android app and its supporting services. Hamblin Weather is independent of the National Weather Service and is not a government agency.
Privacy contact: hamblinweather@gmail.com
Service territory: United States only
Audience: General audience; the app is not directed to children under 13
Information the app uses
Selected forecast location
The app needs a selected U.S. forecast point for location-specific weather and alerts. You can search by city or ZIP code without granting device location permission. Search text is sent to Open-Meteo's geocoding service to return matching places. Hamblin Weather does not retain a search-history list in its backend.
If you tap Use My Location, the app requests foreground location permission and obtains one balanced-accuracy location while that action is running. This optional reading may qualify as precise location under platform disclosures. Device reverse geocoding may be used to display a place name. Selected coordinates are rounded to three decimal places before local storage and weather requests. Broader place, state, and official forecast-area information may qualify as approximate location.
Hamblin Weather does not request background location, continuously track the device, or build movement history. The selected point remains on the device until you select another place, clear app data, or uninstall. It is sent to National Weather Service systems to request forecast and active-alert data.
Official alert targeting
If you enable automatic Official NWS Alerts, the app sends Firebase a minimized target containing the rounded selected point, a two-letter state, and structured NWS county, forecast-zone, and fire-weather-zone identifiers. The backend uses this information to match supported warnings, watches, and advisories to the selected area. It does not receive a continuous location feed.
Changing location replaces the target after official forecast-area data loads. Turning the Official NWS master switch off removes the active backend target while preserving your individual product choices on the device. Turning all notifications off clears the active push token and target from the subscription.
Optional push notifications
If you enable notifications, the app and backend use:
- a random installation identifier;
- a Firebase anonymous-authentication UID used as an installation credential, not a named consumer account;
- an Expo push token and underlying device-delivery identifier;
- platform, app version, and whether the installation is a development build;
- your manual-category, Official NWS master, and individual official-product choices; and
- registration, update, send, provider-ticket, and provider-receipt status timestamps.
Manual Hamblin Weather notifications are sent only through the authenticated admin system. Automatic Official NWS notifications are generated by a scheduled backend poller from supported NWS data and stored choices. Delivery cannot be guaranteed because it depends on network access, device settings, Firebase/FCM, Expo Push Service, operating-system behavior, and provider availability.
The consumer app does not require an email/password account or public profile. The anonymous UID is not intended to identify a real person. Notification-open behavior is not used for advertising or behavioral profiles.
How information is used
Information is used to provide requested weather and content, remember settings, operate optional push delivery, match enabled official alerts to the selected area, prevent duplicates, reconcile provider errors, remove dead tokens, secure and rate-limit backend operations, diagnose outages, control service cost, and apply the retention rules below.
Service providers and public data sources
Current systems include:
- Google Firebase and Google Cloud for anonymous authentication, public content/configuration, Functions, Firestore, Hosting, managed secrets, operational logs, FCM delivery, and related infrastructure;
- Expo/EAS and Expo Push Service for app builds/credentials and push delivery;
- U.S. National Weather Service for official weather, forecast-area discovery, and alert data;
- Open-Meteo for city/ZIP location search; and
- YouTube for the public Hamblin Weather playlist, thumbnails, and user-opened watch pages.
Providers may process IP address, request headers, device/network metadata, and other information needed to deliver and secure their services under their own policies. App-controlled network requests use HTTPS/TLS. These operational transfers are not described as a sale of information.
Retention and deletion
- Active notification installation records remain while notifications are enabled and the installation is recently active.
- Active installations not seen for 180 days are automatically deactivated. Inactive subscription records are deleted after 30 days.
- Disabling all notifications or receiving a dead-token result clears the active backend push token and official-alert target and releases token ownership.
- Private notification history and delivery records are deleted after 90 days in bounded cleanup batches.
- Expired callable rate-limit records are deleted after one day. Inactive automatic-alert state is deleted after seven days.
- The app attempts to delete its anonymous Firebase Auth user after full notification opt-out. This is best effort; an identifier without an active token or target may remain in managed authentication, security logs, or backups until provider cleanup.
- Local location, settings, and installation data remain until changed, app data is cleared, or the app is uninstalled. Android cloud backup is disabled by application configuration.
- City/ZIP searches are operational and ephemeral to Hamblin Weather unless a result is saved as the selected location. Provider request logs may follow provider policy.
- Service-provider logs, security records, backups, and push queues may use provider-specific retention.
To request privacy assistance, access, or deletion, email hamblinweather@gmail.com. Hamblin Weather aims to respond within 30 days unless applicable law requires otherwise. Because ordinary consumers do not maintain named accounts, some records may be associated only with an anonymous installation identifier. Hamblin Weather may be unable to locate or connect an anonymous record to a person unless the requester provides enough information to identify the corresponding installation.
Information not intentionally collected
The current consumer app does not intentionally collect names, personal email addresses, phone numbers, postal addresses, contacts, advertising identifiers, payment or financial information, photos, videos, audio recordings, microphone data, files/documents, health information, continuous/background location, movement history, installed-app inventory, or browsing history. It includes no advertising SDK, behavioral analytics SDK, or Crashlytics SDK.
The app has no user-upload feature. Firebase Storage is not provisioned for consumer content. Private Cloud Functions deployment buckets contain backend artifacts, not consumer uploads. Public media is loaded from administrator-approved HTTPS links or the fixed public Hamblin Weather YouTube source.
Android 1.0 has no paid subscription, free trial, in-app purchase, recurring billing, payment collection, paywall, or cancellation flow. References to a notification "subscription" mean free push-delivery settings. No user-facing AI feature currently requires an AI-use disclosure.
Internal administrators use separate Firebase email/password authentication. The distributed consumer app contains no admin sign-in or content-management interface.
Sale, advertising, and sharing
Hamblin Weather does not currently sell personal information or use it for targeted advertising. Firebase/Google and Expo process operational data for the services described above. NWS and Open-Meteo receive weather-related requests, and YouTube receives ordinary network requests when the app loads public playlist data or thumbnails or when you open a video.
Your controls
- Search by city/ZIP instead of granting device location.
- Deny or revoke foreground location in Android Settings and continue using a manually selected location.
- Change the selected forecast location at any time.
- Enable or disable manual categories, the Official NWS master switch, and each supported official alert type.
- Disable all notifications in the app or revoke notification permission in Android Settings.
- Clear app storage or uninstall to remove locally stored selections and identifiers.
- Contact hamblinweather@gmail.com with privacy, access, or deletion requests.
Security
Hamblin Weather uses access controls, server-side authorization, private Firestore collections, bounded and rate-limited operations, managed secrets, HTTPS/TLS, restricted push credentials, data minimization, dead-token handling, and scheduled retention cleanup. Access and dependencies are periodically reviewed. No security measure can guarantee absolute security.
Children, availability, and changes
Hamblin Weather is intended for a general audience and is not directed to children under 13. The initial public Android release is offered in the United States only.
This policy will be reviewed when the app adds analytics, advertising, accounts, payments, new permissions, new providers, new data types, different notification behavior, or different retention. The Last updated date will change when this policy changes, and material changes may also be communicated through the Hamblin Weather website or app.
