Privacy policy
In short
- We collect what the service needs to work: your name and email, your team, the addresses and properties your team looks up, and the records of what was done with them.
- We do not sell or rent personal data, and we do not share it with data brokers, advertisers or anyone else for their own purposes.
- There is no advertising, no analytics service, no tracking pixel and no third-party script on any page. The only cookies are the ones that keep you signed in.
- An address leaves our system for one reason: to be located. The services that receive it are listed below, with what each one sees. Everything else, including the compiled weather archive, the map, the reports and the PDFs, is produced on our own systems.
- You can see, correct and delete what we hold from your settings, and you can write to us about anything this policy does not cover.
What we collect
Your account
Your name, your email address and a password, which is stored only as a one-way hash. If you turn on two-factor authentication we store the secret and your recovery codes, encrypted. If you register a passkey we store its public key and the name you gave it; the private key never leaves your device. We record when your email address was verified and when you last signed in.
Your team
The team's name, its plan, its members and their roles, the email addresses of people invited to join it, the time zone it works in and its notification preferences. API tokens are stored as a one-way hash with the name you gave the token, its abilities and when it was last used; the token itself is shown once and never kept.
Addresses and properties
The service is about places, so most of what it holds is addresses. For every report: the address, its coordinates, the window and radius searched, and the name of the person or firm the report is for and the reference they gave, if you entered them. For every watched property: the address, the label, notes and tags your team adds, and any contacts your team records against it (a name, a role, a company, a phone number, an email address). For every territory: the area and its name. The storm days we find near a watched property are recorded against it so the team can see what has happened since.
Where your team enters details of a person who is not a member of the team (an owner, an insured, an adjuster, counsel), your team is responsible for having a lawful reason to hold them and for removing them when that reason ends. We process them only to show them back to your team.
Alerts
For territory alerts and the weekly digest, which need no account: the email address given, the states and places chosen, the thresholds set, when the address was confirmed, what was sent and when, and whether it has unsubscribed. For a team's alert rules: the rule, the members who receive it, and any webhook, Slack or Discord address configured, stored encrypted.
Credits and usage
A ledger of credits issued to and spent by your team: when, by whom, and for which report. The ledger records the address a credit was spent on so that the charge remains explicable after the report is deleted. We keep a count of map fetches and image requests per team per day so allowances can be enforced.
Technical records
A signed-in session records your IP address and your browser's user-agent string, and is removed when the session ends or expires. Rate limits for the public tools, the map and the API are counted per signed-in user or, for visitors, per IP address, in a short-lived cache that holds nothing else. Our web server keeps ordinary access logs. We do not build a history of your IP addresses or your activity.
Correspondence
If you write to us, we keep the correspondence for as long as it takes to deal with it and for a reasonable period afterwards.
What we do not collect
- Payment card details. We do not receive or store card numbers. When a payment processor is introduced it will handle card details under its own terms, and this policy will be updated to name it.
- Analytics. No analytics service, no page-view tracking, no session recording, no heat maps.
- Advertising identifiers. No ad network, no pixel, no conversion tracking, no retargeting.
- Device location. We never ask your browser or your phone where you are. The only locations we hold are the addresses you type.
- Third-party scripts. Every script, style and font on every page is served from our own domain.
- Data about you from anyone else. We do not buy, enrich or append information about our users from other sources.
How we use it
- To provide the service: locate an address, compile the record around it, render the map and the report, deliver alerts, enforce the plan your team chose.
- To keep the service secure: sign you in, verify your email, rate-limit abuse, detect compromised accounts.
- To send transactional email: verification, password reset, invitations, alerts you subscribed to, and notices about your account or these terms. We send no marketing email.
- To support you when you write to us.
- To meet our legal obligations and to establish or defend a legal claim.
We do not use personal data to train models, to profile the people named in your team's records, or for any purpose not listed here. The weather archive, the free reference pages and the data series are compiled from the public federal record, not from anything our users enter.
Visitors and the free tools
The free pages and tools need no account. An address typed into the date-of-loss finder, the wind lookup or the front page is located in the same way as an address in a report, and the result of locating it is cached on our systems as reference data (an address is the same place for everybody), not tied to you. An address typed on the front page is held in your browser session only until you register, so the report you started is waiting for you. The wind lookup puts the address in the page's URL so that the result can be bookmarked; that URL appears in our server's access log like any other.
Subscribing to territory alerts asks for an email address and confirms it by sending a link; nothing is sent until the link is opened, and an unconfirmed address is not written to after 72 hours. Every alert carries a link that stops them, and mail clients that support one-click unsubscribe can use it without opening a page.
Who receives data
We do not sell personal data and we do not share it with anyone for their own use. The parties below receive data from us because the service cannot work without them. The list is generated from the services this installation has switched on, so it reflects what the software does today rather than what it might be configured to do.
Services that locate or picture an address
| Service | What it receives | Why |
|---|---|---|
| United States Census Bureau geocoder | The street address being looked up. | Resolving an address to coordinates and a county, which is how the record is searched around it. |
| Google Places | The partial address as it is typed into an address field, and where a page has one, the area the page is about. | Completing an address as it is typed. Sent from our server, not from your browser; Google does not see your IP address. |
| Google Geocoding | The coordinates of a point chosen on the map. | Naming the address under a point a reader chose on the map. |
| The coordinates of a property a report or a watched address is about. | A photograph of the property and an aerial view for the report. Fetched once, then kept by us, so the provider is not asked again when the report is re-opened. Not fetched at all on a plan that does not include imagery. | |
| Google Street View | The coordinates of a property a report or a watched address is about. | A photograph of the property and an aerial view for the report. Fetched once, then kept by us, so the provider is not asked again when the report is re-opened. Not fetched at all on a plan that does not include imagery. |
| Esri World Imagery | The coordinates of a property a report or a watched address is about. | A photograph of the property and an aerial view for the report. Fetched once, then kept by us, so the provider is not asked again when the report is re-opened. Not fetched at all on a plan that does not include imagery. |
| Open-Meteo | The coordinates a report is about, and the date window. | Hourly weather for the address over the window of the report. |
| National Weather Service API | The coordinates a report is about, rounded to roughly ten metres. | Finding the observing stations nearest the address. |
These requests are made by our server. None of them carries your name, your email address, your team or your IP address, and none of them is made for a report that has already been located and pictured.
Map tiles your browser fetches
The storm map is drawn by your browser from tiles. The storm data, the style and the warnings come from our own domain; the basemap and the radar underneath come from the hosts below, which your browser fetches directly and which therefore see your IP address and the squares of the map you are looking at, as any website's images would. They do not receive the address you searched for or anything about your account.
| Host | What it receives | Why |
|---|---|---|
| tile.openstreetmap.org | Your IP address and the squares of the map in view. | The street basemap under the storm map. |
| server.arcgisonline.com | Your IP address and the squares of the map in view. | The satellite basemap under the storm map. |
| mesonet.agron.iastate.edu | Your IP address and the squares of the map in view. | Radar imagery drawn over the storm map, live and archived. |
The public weather record
The archive is compiled from public sources: NOAA Storm Events, NOAA Radar (SWDI), National Weather Service, NWS Damage Surveys, NWS Damage Survey Points, IEM Local Storm Reports, NWS Warning Polygons, SPC Storm Reports, FEMA Disasters, CoCoRaHS Hail Reports, NOAA RTMA Wind Analysis, NOAA HRRR Wind Analysis, NOAA MRMS Radar Mosaic . These sources are asked for areas, counties, dates and national grids. They never receive an address, an account or anything about a person, and the archive is shared by every user because a storm belongs to nobody.
Channels you configure
If your team configures a webhook, a Slack channel or a Discord channel for alerts, we send alerts there on your instruction. Those alerts name the property and its address. What that service does with them is governed by your agreement with it, not by this policy.
Everyone else
We disclose personal data beyond the above only when the law requires it (a subpoena, a court order, a lawful request from an authority), when it is necessary to protect the rights or safety of a person or of the service, or to a successor if the service changes hands, in which case this policy continues to apply to it. Where the law allows, we will tell you before we comply with a request for your data.
Who can see your data
Your team. Every member of your team can see the team's reports, properties, territories and alert rules, according to their role. A report belongs to the team, not to the member who ran it. Data is isolated by team; no other customer can see it.
Our staff. A small number of staff can open any account to support it, to enforce the terms, to investigate abuse or to correct a billing problem. What they can see is what you can: the team, its members, its reports (including reports the team has deleted, for the retention period below) and its credit ledger. Staff access is not used to read your records for any other reason.
What is public
The verification page. Every compiled report carries a fingerprint and a verification link, so that anyone holding a copy can confirm it is unaltered. That page shows the city and state, the window and radius, the counts of records by kind, the date compiled, and, if they were entered, the name of the recipient and the reference. It never shows the street address, the coordinates, the team, or any individual record. A link is reachable only by the long identifier printed on the report.
The free pages. Hail history by city, wind history, storm days and the data series are compiled entirely from the public federal record. Nothing our users enter contributes to them.
How long we keep it
- Your account and your team's records are kept for as long as the account exists.
- Deleting your account removes it at once, along with your passkeys and your memberships. If you own a team, deleting your account deletes the team and everything in it: reports, properties, contacts, territories, alert rules, tokens and the ledger. Where you were a member rather than the owner, the team's records stay with the team and your name is detached from them.
- Deleted reports are held for 30 days so a mistaken deletion can be undone on request, then removed.
- Backups of our database are kept for 30 days and then overwritten, so a deleted record leaves the backups within that period.
- The credit ledger is kept for as long as the team exists, as a financial record. It names the address a credit was spent on, which survives the deletion of the report.
- Alert subscriptions that have unsubscribed are kept, marked as such, so that an address that asked not to be written to is not written to again. Write to us to have one removed entirely.
- Delivery records of alerts are kept for as long as the team exists, so a team can see what was sent and where.
- Located addresses and photographs are kept as reference data: an address is the same place for everybody, and a report must be able to show the same photograph years later. They are not linked to an account.
- Sessions are removed when they expire. Rate-limit counters expire within minutes. Server logs are kept on our own systems for ordinary operations and are not shared.
How we protect it
- Every connection is encrypted in transit.
- Passwords and API tokens are stored as one-way hashes. Two-factor secrets, recovery codes and webhook addresses are stored encrypted.
- Two-factor authentication and passkeys are available to every account, and a sensitive change in your settings asks for your password again.
- Every record is scoped to a team, and every action that reads or changes one is authorised against that team on every request.
- Reports, PDFs and photographs are stored on our own systems, not on a public bucket, and are served only to the team that owns them.
- The public API authenticates every request, limits its rate and honours the abilities a token was issued with.
No system is perfectly secure. If we learn of a breach affecting your data we will tell you without undue delay and tell the authorities the law requires us to.
Your rights and choices
You do not need to invoke a statute to exercise these; they are available to everyone.
- Access and correction. Your profile, security settings, team, properties and reports are all editable in the service. Anything you cannot see there, ask us for.
- Deletion. Delete your account from your settings. Delete a report, a property or a contact from its page. Ask us to remove anything the service does not let you remove yourself.
- Portability. Reports export as PDF on the plans that include it, and the API returns your team's reports and records as JSON. Ask us for a copy of anything else.
- Email. Every alert carries an unsubscribe link. The only email you cannot switch off is the email about your account itself (verification, password reset, a notice of a change to these terms).
- Objection and restriction. Tell us if you object to a use of your data described here and we will consider it; we may need to close the account if the objection makes the service impossible to provide.
- No sale, no sharing for advertising. We do not sell or share personal data as those words are used in United States state privacy laws, so there is nothing to opt out of. We honour browser Global Privacy Control signals in any case, by doing nothing different: there is no tracking to switch off.
- No discrimination. Exercising a right does not change the service you receive.
To make a request, write to legal@titanweather.com from the email address on your account, or from the address that subscribed to alerts. We may ask you to confirm it is you before acting. We answer within thirty days. If you are in the European Economic Area, the United Kingdom or another place whose law gives you a right to complain to a supervisory authority, you may; we would rather you wrote to us first.
Where data is held
The service runs on servers in the United States, and that is where your data is stored and processed. If you use the service from elsewhere, you are sending your data to the United States. The services that locate an address, listed above, are operated from the United States; the hosts your browser fetches map tiles from are operated by their owners and may be served from elsewhere.
Children
The service is for professional use by adults. We do not knowingly collect data from anyone under eighteen. If you believe a child has given us data, write to us and we will remove it.
Changes to this policy
We may revise this policy. The date at the top is the date the current text took effect. When a change affects what we collect, who receives it or how long we keep it, we will email account owners and alert subscribers before it takes effect. A part of this policy, the list of services that receive data, is generated from the software's configuration and changes when that does; it is always current.
Contact
Titan Weather is the controller of the personal data described here. Write to legal@titanweather.com about this policy, a request under it, or anything it does not cover.