Legal

Privacy Policy

Last updated: June 2026

Who we are

Auroracast (auroracast.co.uk) is a free aurora forecasting and community service for the UK. The site is operated by a private individual, not a company.

What data we collect

User accounts

If you create an account, we store: your email address, a hashed (bcrypt) version of your password — never the password itself — your chosen display name, username, and optionally a bio, website URL, and avatar image. Your email address is never shown publicly. Your username and display name are public.

We also ask for your date of birth when you sign up. This is used only to confirm you meet our minimum age of 16; it is stored against your account, is never shown publicly, and is not used for any other purpose. See our Child Safety statement for more.

Signing in with Google

If you choose "Continue with Google", Google sends us your name, email address, and profile picture so we can create or sign you into your account. We do not receive your Google password or any other information from your Google account. Your use of Google sign-in is also governed by Google's own privacy policy.

Email alerts

If you subscribe to email aurora alerts, we store your email address and your chosen Hp30 threshold. We use this solely to send alerts when aurora activity reaches your threshold. Each alert email contains an unsubscribe link that permanently removes your address from our database. We do not use your email for marketing or share it with any third party.

Session cookie

When you log in, we set an aurora_session httpOnly cookie containing a signed session token. This cookie is used only to authenticate your requests to the site. It cannot be read by JavaScript and expires after 30 days or when you log out. See our Cookie Policy for full details.

Community content

Posts you publish to the community wall, reactions you give, and comments you write are stored in our database and — unless set to friends-only — are publicly visible. Your display name and avatar are shown alongside your posts. Do not include sensitive personal information in community posts.

Aurora sighting reports

If you submit a sighting report, we store: your optional display name, the coordinates of the sighting, your description, intensity rating, the time of the sighting, and any photo you upload. Sightings are public. Do not include personal information in your description that you would not wish to be public.

Private messages

Messages sent between users are stored in our database and are only accessible to the sender and recipient. We do not read private messages except where required by law or to investigate a serious abuse report.

Location data

The Sky Tonight page and Find Clear Skies feature may request your device's GPS location via the browser Geolocation API. Your coordinates are sent to our server to fetch local weather, cloud cover, and ISS pass data. We do not store your location permanently or associate it with your account. Coordinates are cached for up to 30 minutes to reduce external API calls.

Push notification subscriptions

If you enable browser push alerts, your browser generates a push subscription endpoint. We store this to deliver notifications. It is not linked to your account identity. You can unsubscribe at any time from Settings, which deletes the subscription from our database immediately.

Server logs

Our web server records standard access logs (IP address, browser type, pages visited, timestamps). These are used solely for diagnosing errors and are retained for a maximum of 30 days.

What we do not collect

  • We do not use advertising or tracking cookies
  • We do not use Google Analytics or any third-party analytics service
  • We do not sell or share personal data with third parties
  • We do not store passwords in plain text — only bcrypt hashes

Third-party services

Auroracast fetches data from the following external services. Most are server-side only and your browser never contacts them directly:

  • GFZ Potsdam — Hp30 geomagnetic index (server-side only)
  • NOAA Space Weather Prediction Center — solar wind and CME data (server-side only)
  • Open-Meteo — weather and cloud cover data (server-side only)
  • Nominatim / OpenStreetMap — place name search when you set your location (your browser contacts this service directly)
  • Esri / ArcGIS Online — satellite map tiles for the aurora globe (your browser contacts this service directly)
  • wheretheiss.at — ISS position data (server-side only)

Data retention

  • User accounts: retained until you delete your account or request deletion
  • Email alert subscriptions: retained until you unsubscribe via the link in any alert email
  • Session cookies: expire after 30 days or on logout
  • Community posts: retained until you delete them or request removal
  • Sighting reports: retained indefinitely as part of the community record; contact us to request removal
  • Private messages: retained until deleted by both parties or on account deletion
  • Push subscriptions: retained until you unsubscribe or the browser subscription expires
  • Weather / location cache: purged automatically after 30 minutes
  • Server logs: purged after 30 days

Your rights

Under UK GDPR you have the right to access, correct, or delete personal data we hold about you. To delete your account and associated data, go to Settings → Delete Account. To request removal of a specific sighting or post, or for any other privacy enquiry, contact us at the address below.

Contact

For privacy questions: admin@auroracast.co.uk

Terms of Use →Cookie Policy →