Privacy policy
Effective October 10, 2026
Nebula AI Labs LLC, 30 N Gould St, Ste N, Sheridan, Wyoming 82801-6317, United States, operates Aurora Lens and is the data controller responsible for your personal data. You can reach us directly at contact@nebulaailabs.com.
THE SHORT VERSION
Aurora Lens works without an account. Your photos and timelapses stay on your device in your Photos library; the app does not upload them, you retain full ownership and copyright, and we claim no intellectual property rights or license in them. If you enable aurora alerts, we store minimal technical parameters solely to deliver push notifications. In the European Union, European Economic Area, the United Kingdom, and Switzerland, the app asks for your explicit consent before collecting usage statistics or crash reports. We do not sell your personal data or share it for cross-context behavioral advertising.
WHAT THE APP DOES WITH DATA
- Camera, Photos, and Motion Sensors: The camera and motion sensors operate strictly on your device to capture timelapses and detect phone stability. The app does not upload imagery, video, or sensor telemetry. The app saves finished media to your device's Photos library using add-only permissions. If you use iCloud Photos, Apple synchronizes your media under your personal iCloud account settings.
- Forecasts and Area Names: When you grant location access, the app sends your location to our server each time it loads a forecast, the interactive globe, or the viewing guide. Version 2.0 sends a coarse grid square approximately 50 km across. From version 2.0.1 the app sends your exact coordinates instead, so the forecast matches the sky directly above you; our server rounds them to the same 50 km square to compute the answer. To display the general name of your area, the app queries Apple's geocoding service using the 50 km grid square (Apple receives your IP address as part of standard network requests). Our server processes your IP address solely to transmit the requested network response. (Legal Basis: Performance of a requested service, GDPR Art. 6(1)(b)).
- Cloud Cover: Cloud cover data is powered by Apple WeatherKit. The app transmits only the coarse 50 km grid square to Apple, not your exact coordinates. Apple receives your IP address as part of standard network communication and processes requests under the Apple Privacy Policy. The app displays the required Apple Weather attribution within forecast views. (Legal Basis: Performance of a requested service, GDPR Art. 6(1)(b)).
- Aurora Alerts: If you enable push alerts, we store your device push token, a one-way scrambled copy of a random install key, your 50 km grid square, time zone, system language, alert threshold preferences, device platform, app version and build identifier, installation source (TestFlight vs. App Store), and the timestamp of last contact. Notifications are dispatched via the Apple Push Notification service (APNs). To evaluate local cloud cover for triggered alert regions, our server queries MET Norway regarding the relevant grid square. (Legal Basis: Performance of a requested service, GDPR Art. 6(1)(b)).
- Usage Statistics and Crash Reports: In the European Union, European Economic Area, the United Kingdom, and Switzerland, the app requests prior consent and transmits no telemetry until you affirmatively opt in. If the app is initially opened via a notification, this prompt appears on the next time you open the app, and no data is transmitted in the interim. In other jurisdictions, diagnostic telemetry is enabled by default. You can change this at any time in Settings > Share usage and crash data (toggling this off disables both analytics and crash logging).
- When enabled, the app logs screens you open, crashes with the recent steps in the app, hardware model, operating system version, app version, and your alert and permission settings, under a random identifier kept on your phone. We have configured PostHog and Sentry not to store IP addresses. These records do not contain your name, email address, or push token, and we do not link them to your alert registration or your email.
- Usage analytics are processed by PostHog on servers located in the European Union.
- Crash logs and app-start signals are processed by Sentry on servers located in Germany; crash logs capture recent in-app steps without screenshots.
- iOS system freeze summaries remain on your device; we receive only aggregate freeze counts.
(Legal Basis: Consent under GDPR Art. 6(1)(a) where required by law; elsewhere, our legitimate interest in application stability and product maintenance under GDPR Art. 6(1)(f), subject to your right to opt out at any time).
- Mapping: Interactive maps are provided via Apple Maps, which processes map tiles and location data pursuant to Apple's Privacy Policy.
- Problem Reports: Selecting "Report a Problem" initiates an email draft addressed to our support inbox populated with your app version, device model, OS version, and system language. You may inspect or edit this information before sending.
OUR WEBSITE (AURORALENS.APP)
- Web Analytics: For visitors in the EU, EEA, UK, and Switzerland, Google Analytics runs only if you explicitly opt in via our consent banner (Legal Basis: Consent, GDPR Art. 6(1)(a)). When accepted, it sets cookies and transmits page views and clicks to Google LLC in the United States. In other regions, visits are counted without a banner. You may change your choice at any time via the "Cookie settings" link in the footer. Analytics is not used on our support page.
- App Store Attribution: Outbound clicks to the Apple App Store log the source link, interface language, and general destination city landing page without logging IP addresses.
- Email Alerts: When subscribing to web alerts, we record your email address, interface language, optional 50 km coarse location, and requested alert level. Subscriptions require double opt-in confirmation, and every automated email includes a direct unsubscribe link. Emails are dispatched via Resend. Subscriber records are maintained in our managed database at Neon. (Legal Basis: Consent, GDPR Art. 6(1)(a)).
- Customer Support: Inquiries submitted through our website support form store your message content, provided email address, and optional device/OS details. To prevent automated spam, we retain a one-way code derived from your network address for 24 hours. Messages are routed internally to our team via email and a private Slack channel. (Legal Basis: Legitimate interest in responding to inquiries and safeguarding web forms from malicious traffic, GDPR Art. 6(1)(f)).
- Hosting and Infrastructure: Our website is hosted on Vercel. Standard server logs (including client IP addresses) are retained for up to 1 day to maintain service integrity and security. (Legal Basis: Legitimate interest in network security, GDPR Art. 6(1)(f)).
IN-APP DATA DELETION AND SELF-SERVICE MANAGEMENT
Aurora Lens does not require user accounts. You can manage or delete your personal data directly without submitting a support ticket:
- Aurora Alerts: Toggle alerts off in Settings. The app then tells our server to delete your push token, grid square, and device record, and the server deletes them. If you revoke notification permission in iOS Settings, the app does the same the next time you open it. If that request does not get through, or if the app is uninstalled without disabling alerts, APNs invalidation signals cause our database to delete the record within 30 days.
- Email Alerts: Click the "Unsubscribe" link in any alert email to remove your email address and location from our database straight away.
- Usage and Crash Data: Disable "Share usage and crash data" in Settings. The app stops sending; records already held by PostHog and Sentry expire and are deleted after 30 days.
- Support Records: To request early deletion of support correspondence before the standard retention limit, email contact@nebulaailabs.com.
DATA RETENTION SCHEDULE
- Push Alert Registrations: Kept until disabled in-app, or up to 30 days after an uninstalled/invalid APNs token signal.
- Email Alert Records: Kept until you unsubscribe, then deleted straight away. Unconfirmed subscription requests are deleted after 7 days.
- Support Inquiries: Kept for up to 12 months; the anti-abuse code expires after 24 hours.
- Usage Statistics (PostHog): Deleted automatically after 30 days.
- Crash Diagnostics (Sentry): Deleted automatically after 30 days.
- Web Server Logs (Vercel): Kept for up to 1 day.
THIRD-PARTY PROCESSORS AND INTERNATIONAL TRANSFERS
We process data on infrastructure located in the United States and the European Union. Where we name a transfer mechanism below, we have checked it in the provider's own terms.
- Vercel Inc. (USA): Website hosting and server logs. Transfers from Europe use Standard Contractual Clauses.
- Neon (USA): Managed database for alerts, email sign-ups, and support messages. Neon's parent company, Databricks, is certified under the EU-U.S. Data Privacy Framework.
- Resend (USA): Email delivery. Transfers use Standard Contractual Clauses, and Resend is certified under the EU-U.S. Data Privacy Framework.
- Slack (USA): Internal support notifications. Transfers use Standard Contractual Clauses, and Slack is certified under the EU-U.S. Data Privacy Framework.
- PostHog (European Union): Usage analytics, if you share them. Hosted in the European Union.
- Sentry (Germany): Crash reports, if you share them. Hosted in the European Union.
- Google LLC (USA): Web analytics, if you accept in the banner.
- MET Norway (Norway): Cloud checks for alert areas.
Apple processes data independently under the Apple Privacy Policy for APNs notification transport, Apple Maps, and WeatherKit. Aurora Lens is an independent app developed by Nebula AI Labs LLC and is not sponsored by, endorsed by, or affiliated with Apple Inc., NOAA, or MET Norway.
YOUR RIGHTS (GDPR / UK DPA)
Subject to the data protection laws where you live (including the EU/EEA, UK, and Switzerland), you have the right to access, correct, port, or erase personal data we hold, to restrict or object to our processing, and to withdraw consent at any time. Usage data is stored under a random ID, not your name, so we may not be able to find yours. To exercise your rights, email contact@nebulaailabs.com. We respond to verified requests within 30 days. You also have the right to lodge a complaint with your national or regional Data Protection Authority.
CALIFORNIA PRIVACY RIGHTS (CCPA / CPRA)
California residents are entitled to these disclosures:
- Categories of Personal Information Collected: Identifiers (a random app ID, push token, IP address, and an email address if you give us one), location (a grid square about 50 km across; from app version 2.0.1, exact coordinates sent with a forecast request), and usage data (screens you open, crash reports, iPhone model and iOS version).
- Business Purposes: Providing forecast alerts, keeping the app stable, responding to inquiries, and preventing abuse.
- Sale / Sharing of Personal Information: We do not sell your personal information or share it for cross-context behavioral advertising.
- Sensitive Personal Information: We do not use or disclose sensitive personal information for anything other than providing the service you asked for.
- Consumer Rights: You may request access to, correction of, or deletion of your personal information, without discriminatory treatment, by contacting contact@nebulaailabs.com. We do not respond to Do Not Track signals because we do not track you across other sites.
CHILDREN'S PRIVACY
Aurora Lens does not ask for your age and does not knowingly collect personal data from children under 13 (or under 16 in applicable European jurisdictions). If you believe a minor has given us personal details through our website or support channels, contact us at contact@nebulaailabs.com and we will delete them.
AMENDMENTS
We may revise this Privacy Policy to reflect technical updates, legal changes, or operational changes. Updated versions will be published at this location with a revised effective date.
CONTACT
Data Controller: Nebula AI Labs LLC 30 N Gould St, Ste N Sheridan, WY 82801-6317 United States Email: contact@nebulaailabs.com