1. Scope
This policy explains how DarkScout processes data when you use the DarkScout iOS app and website.
2. Information We Process
- Location data you choose to provide, including saved observing spots and exact or approximate locations attached to community shots and observing events.
- Saved spots, planner data, app preferences, and optional horizon profiles you create.
- Community content, including your display name and handle, photos, captions, event details, join requests, attendance state, event chat messages, announcements, safety reports, and the versions and timestamps of event participation documents you accept.
- An account identifier used for sync. If you link Sign in with Apple for event participation, Apple may also provide your name and email address according to the choices you make in Apple’s sign-in flow.
- Subscription and entitlement status provided through Apple.
- Limited product-interaction analytics made from categorical events, such as opening a feature or completing a comparison. DarkScout does not place free-form text, coordinates, email addresses, or auth tokens in these analytics events.
- Operational and diagnostic information needed to secure and maintain the service.
- If you enable Share usage analytics at startup or in Settings, Google Analytics for Firebase receives categorical feature events, app and device information, SDK diagnostics, session and purchase events, an app-instance identifier, and an approximate region derived from your network connection. This optional collection is off by default.
- In versions with crash reporting, the separate Share crash reports choice allows Firebase Crashlytics to receive technical crash reports, stack traces, app and operating-system versions, device information, and SDK-generated installation/session identifiers. It is off until you opt in. We do not add account identifiers, names, emails, coordinates, photos, or messages to crash reports.
3. Why We Process It
- Compute night scores, visibility, and best windows.
- Sync your data and personalize planner, map, widget, and notification experiences.
- Provide community sharing, nearby-event discovery, join requests, hosting, reminders, and event chat.
- Support account, subscription, moderation, and safety features.
- Secure, maintain, and improve the service.
4. Community Location Privacy
An event’s public map marker uses an approximate location. Its exact meeting location and access instructions are available only to eligible event participants and hosts. Exact event-location records are marked to expire after the event. A community shot can use an exact, approximate, or hidden location chosen by its author.
Spots that were already part of Community discovery in earlier DarkScout versions may remain discoverable. Newly saved spots are private by default and appear in Community discovery only after their owner enables Community visibility. Discovery returns either a name snapshot from an approved exact-location Community Shot or a neutral localized label, coordinates rounded to three decimal places, its time zone, and day-level timestamps. It does not include the owner’s account identifier, mutable private spot name, or horizon profile; it excludes your own spots and respects blocks in either direction. Owners can disable Community visibility from Spot Detail at any time.
5. Service Providers and Monetization
We do not sell personal data. We use Apple for purchases and Sign in with Apple, Supabase for authentication, database, realtime chat, and media storage, and infrastructure providers to operate the app and website.
With your optional consent, we use Google Analytics for Firebase to understand app usage and improve DarkScout. We do not send your DarkScout account identifier, name, email, coordinates, photos, messages, or other personal content to Firebase Analytics. Its app-instance identifier distinguishes installations; it is not your DarkScout account identifier. Advertising storage, advertising user data, personalized advertising, advertising identifiers (IDFA), vendor identifiers (IDFV), and ad-network registration are disabled. Google may process analytics data outside your country under its applicable data-processing terms. See Firebase privacy information.
Firebase Crashlytics helps us diagnose crashes when you separately enable crash reporting. If you also enable usage analytics, reports may include the categorical Analytics events leading up to a crash. Existing analytics consent does not automatically enable crash reporting. Both choices can be changed independently in Settings and neither is required to use the app.
When DarkScout requests a forecast, the selected coordinates are sent through DarkScout’s authenticated Supabase weather service and then to Open-Meteo so it can return local weather conditions. DarkScout applies access controls, strict request validation, and short-lived shared response caching; Open-Meteo processes the weather request under its own service and privacy terms.
DarkScout does not embed a third-party advertising SDK, display in-app ads, or request App Tracking Transparency permission. Optional DarkScout Pro features are funded through Apple in-app subscriptions; Community shots and the core Community events experience remain available without ads.
Horizon profiles remain associated with your account and are not exposed through community spot listings.
6. Retention and Deletion
Data is kept only as long as needed for the features above, safety and moderation, service operation, and legal obligations. Published community content and event records remain until removed, expired under their feature rules, or deleted with the account. You can delete your account and associated server data from app Settings.
Protected event meeting details are cleared after their configured post-event safety window. Event chat is normally removed after 90 days. An open safety or moderation report, or a legal preservation obligation, may extend those periods for the affected records. Revoked push-device registrations and completed notification delivery records are removed on shorter operational schedules.
To prevent an Apple purchase from being fraudulently claimed by another account, DarkScout retains a private, pseudonymous binding between the App Store environment and original transaction identifier and the former account identifier after account deletion. This anti-replay record is not used to restore deleted content, contact you, or advertise to you.
Turning off Share usage analytics stops further optional Firebase collection and clears analytics data stored locally on this device, including its analytics app-instance identifier. Account deletion also turns this option off. This does not automatically erase reports already processed by Google; they are subject to the analytics property's configured retention period. Contact us for privacy requests concerning previously collected data.
Crashlytics automatic upload is disabled. Reports are sent at a subsequent launch only when crash reporting was allowed for the previous session and is still allowed. While the SDK is running, it may store crash reports locally even if reporting is disabled. A session that included a withdrawal is not eligible for upload, even if reporting is re-enabled in that session. Ineligible unsent reports are discarded the next time Firebase starts. Reports already transmitted are not recalled. Account deletion turns off crash reporting as well as analytics. Device-local consent records retain the category, choice, timestamp, notice version, and app version; they are not sent as analytics events.
7. Your Controls
- Disable location and notifications in iOS Settings.
- Disable app notifications in DarkScout Settings.
- Enable or withdraw optional Firebase usage analytics and crash reporting independently in DarkScout Settings at any time.
- Choose exact, approximate, or hidden location when sharing a community shot.
- Show or hide each saved spot from Community discovery in that spot's details.
- Leave events, remove your content where available, report content, or block another community member.
- Export a portable JSON copy of your DarkScout account data from app Settings.
- Delete your account from within the app.
8. Website Analytics
The DarkScout website uses Vercel Web Analytics to understand aggregate page usage. Website requests may also produce standard infrastructure logs such as IP address, browser information, requested page, and timestamp.
9. Children
DarkScout is not intended for children under 13. Joining or hosting an in-person Community observing event is limited to people who declare that they are 18 or older.
10. Changes
We may update this policy. The date at the top shows the latest revision.
11. Contact
For privacy requests, contact sebastianmraz@gmail.com.