Bowcast privacy policy

Effective August 15, 2026

Bowcast estimates the chance of seeing a rainbow around you. It is built to know as little about you as possible.

Location

Bowcast uses your approximate location to compute estimated rainbow chances for the area around you. On the website and in the packaged apps, coordinates rounded to about 1 km go to Bowcast's shared forecast API. Bowcast then requests weather data for those coordinates from the providers listed below, without your name or an account identifier. If you deny location access, you can search for a place instead. The search text goes through Bowcast's place-search API to the geocoding provider, and only the selected place's coordinates are used for its forecast.

Rainbow alerts

If you turn on alerts, we store two things on our server: your device's push token and coordinates rounded to two decimal places, so we can send alerts for your area. Turning alerts off requests deletion from our server. The app confirms the disabled state only after that request succeeds. We send alerts through Google Firebase Cloud Messaging and Apple Push Notification service, which process the delivery. Registrations that have not refreshed for 180 days are removed automatically.

Optional account-free rainbow reports

If you choose to report whether you saw a rainbow, Bowcast sends the yes or no result, the observation time, relevant forecast values, and a coarse location to our server. Coordinates are rounded to two decimal places before transmission and storage. The stored report contains no name, email address, push token, advertising identifier, raw IP address, or exact location.

We keep these de-identified, account-free reports so we can study forecast performance and periodically calibrate the estimated chance. Coarse coordinates may be used to balance reports from different areas, group reports from the same weather event, and test the calibration on held-out regions. Location is not used as a predictive model input and is not included in published model files. Each report has a random report ID so a network retry does not create a duplicate. The report service uses the request address to form a short-lived, salted rate-limit bucket. Bowcast does not add the raw address to the report or application log fields. Hosting providers may process network metadata under their own terms.

Reports do not change the forecast immediately. Bowcast trains candidates in batches. Automated evaluation cannot publish a model: adoption requires explicit review in addition to minimum data-coverage and held-out performance checks. Sending a report is optional.

If you choose to share a sighting, Bowcast generates the share card on your device. Native apps keep it in a temporary cache only while the system share sheet is open, then delete it. The app you select receives the card, share text, and Bowcast link under that app's own privacy terms.

Anonymous website measurements

The website and installed web app count five product events so we can understand whether the core forecast flow is useful: forecast loaded, forecast window opened, alert enabled, share started, and sighting reported. Each event can be counted at most once per open page. The React Native app does not currently send these product measurements.

The measurement contains only the event name and a broad surface label: web, installed web app, iOS, Android, or unknown. It does not contain a coordinate, place name, URL, referrer, account, device identifier, user agent, advertising identifier, or persistent analytics cookie. Bowcast stores daily aggregate counters for 90 days. Global Privacy Control and Do Not Track disable these measurements.

Website traffic counts

The bowcast.app website uses Vercel Web Analytics to count page views. It is served from bowcast.app itself, sets no cookie, and writes nothing to your browser's storage. It records the page path, referring site, country, device type, and browser. It does not record your IP address, and it does not build a profile or follow you to other sites.

To count a repeat view without an identifier, Vercel derives a hash from the incoming request and re-salts it every 24 hours, so the value cannot connect your visits from one day to the next. Global Privacy Control and Do Not Track disable these counts, the same as the product measurements above. The packaged iOS and Android apps do not load this script at all.

What we do not do

Service providers

Advertising

Bowcast currently shows no ads. Advertising files may be prepared for a future release, but they are not loaded by public pages. This policy will be updated before ads are activated, and Bowcast will use any consent flow required for that release.

Data deletion and contact

A successful alert-disable request removes your push registration. A failed request leaves alerts visibly enabled so you can retry; stale registrations expire after 180 days. Local settings and unsent reports are deleted when you remove the app. Reports contain no direct account or device identifier. You can ask us to delete a report if you kept its report ID. A deleted report is excluded when the next model candidate is trained; an already published aggregate calibration is replaced only after a new candidate passes the safety checks. For any request or question, contact i@shamseddin.net. If you email us, your mail provider and ours process your address and message for support; they are not added to forecast, alert, or sighting records.


Back to Bowcast