Privacy Policy

Last updated: 25 September 2026

Probably Weather is a free, advertising-supported weather application built and operated from South Africa. This policy explains, honestly and in plain language, what data the app handles, who it is shared with, and why — in line with the Protection of Personal Information Act 4 of 2013 (POPIA).

The short version

We keep data collection to the minimum needed to run a free, ad-supported weather app. We do not require an account, we do not ask for your name or email, we do not build a profile of you, and we never sell your data. We do use a privacy-friendly analytics tool and we show ads, both described below. The app sends your location to weather and mapping providers so it can show you a forecast. We also keep a short-lived copy of that forecast on our own server, filed by a rough 2 km area rather than by you, so that neighbours share one forecast instead of each fetching their own; those entries are deleted within 15 minutes. Like any website, our responses are also briefly cached by our host's delivery network, and our server counts requests per IP address to block abuse. Your IP address — as with any website — is seen by our host, our analytics tool, our ad partners, and a couple of supporting services. Everything that leaves your device is listed below.

Location data

To show you a forecast, the app needs a location. With your permission it uses your device's GPS coordinates (latitude and longitude), rounded before they leave your device: to about 2 km when the app asks for a forecast, and to four decimal places (about 10 m) when it looks up the name of your place. If instead you choose a place from the search box, its forecast is asked for on the same 2 km grid. If GPS is unavailable or you decline it, the app falls back to an approximate, city-level location (see "IP-based location" below). Your coordinates are sent to the weather and mapping providers listed below to fetch the forecast and a readable place name.

We keep a short-lived copy of the finished forecast on our own server, so that everyone opening the app in the same neighbourhood shares one set of provider calls instead of each triggering five. That copy is filed under a location cell of about 2 km: your coordinates are snapped to the nearest grid square to make the filing label, so your exact position is not part of the label. The forecast stored inside carries the coordinates it was fetched for, which are that grid point — about 2 km — not your position. These forecast entries are refreshed after 5 minutes and deleted automatically after 15 minutes. They are held in a Redis database operated by Upstash, which we use through our host, Vercel. There is no account, no name, no IP address and no device identifier in these entries, nor in the label they are filed under.

Separately from that, the responses our server sends are also cached by Vercel's content-delivery network — the ordinary way a website is served quickly. A cached response is stored against the exact web address that produced it, and because coordinates sit in those addresses, both the address and the stored response can contain them. The windows we ask for are: weather responses served for up to about 6 minutes before a refresh; place-name lookups up to about 40 minutes; and the share-preview card for a shared link up to 1 hour, after which the network may keep serving the stored card for up to a further 24 hours while it fetches a new one in the background (your own browser may also hold that card for 5 minutes). Two share addresses are worth naming separately. The preview image (/api/og) tidies its own address: when a request arrives carrying more decimal places than we use, our server redirects it to an address rounded to two decimals, and that redirect may be served from the cache for up to 24 hours — filed under the incoming address, which still carries the original, unrounded coordinates. The share page a recipient opens (/share) does no such rounding: it builds a small HTML page carrying the coordinates from the link exactly as they arrived, both in the preview tags and in the app link it forwards to, and your browser and the network may each hold that page for 5 minutes.

Those numbers describe how long a stored copy may be served before it is refreshed. They are not deletion times. Under the caching rules Vercel follows, once a copy is no longer "fresh" the network may go on serving it while it fetches a new one in the background, and when a copy is actually discarded is Vercel's own affair, on its own schedule. We have not verified when that happens and we do not claim a figure for it. The /api/locate response described below is marked private, so the network does not store it at all.

Some copies stay on your own device rather than on our servers, and they hold coordinates too. The app's service worker keeps recent forecast responses so it can still show you something when you go offline: it will serve such a copy only while it is under 3 hours old, deletes it once it is older than that, and keeps at most 60 of them. It also keeps up to 32 share-preview images, and those it will re-use whatever their age while it fetches a fresh one in the background. Separately, the app stores the last forecast for each place you have viewed in your browser's own database, labelled with that place's coordinates to three decimals, and reads one back only if it is under 30 minutes old. Browser storage also holds the random install identifier described under "Abuse protection". These device copies are replaced by fresher ones as you use the app — but "we stop showing it" is not the same as "it is gone": an entry goes when it is replaced, when you move away from that place, or when you clear this site's data in your browser or app settings, which removes all of them at once. None of it is sent to us.

Beyond the caches described here, we do not store your location in any account, profile, or database. Brief operational logs kept by our host may transiently contain technical request data, as they would for any website.

Abuse protection

To stop any single source of traffic from overwhelming the app, our server counts how many requests each IP address makes. Your IP address is used as the label on a counter — a tally of recent requests and nothing else — held in the same Upstash Redis database described above. These counters are not linked to your location, to your forecast, or to the forecast cache. Several parts of the app keep their own separate counter: the forecast, place search, the share-card renderer, and error reports. Each counter covers one of two window lengths — a minute or a day. The rate-limiting library we use sets a counter's expiry once, at the moment that counter is first created, to twice its own window: so a minute counter is dropped a little over two minutes after it was created, and a day counter about 48 hours after it was created. That is measured from when the counter was created, not from your most recent request. We use these counters only to decide whether to slow a request down, and we build no profile from them.

One more label is involved, and it is worth being plain about it. The app generates a random identifier once on your device — a random value from your browser's cryptographic generator, or random hex characters if that is unavailable — and keeps it in browser storage under pw_install. It is sent as an X-PW-Install header with forecast and place-name requests, and the server uses it, together with your IP address, as the label on a second set of abuse-protection counters (again one covering a minute and one covering a day). The reason is South African mobile networks: thousands of unrelated people share a single public address behind carrier-grade NAT, so a limit counted by address alone would lock strangers out over each other's traffic. Counting per install as well means your allowance is your own. This identifier is tied to no name, no account and no email address — we hold none of those — it is never shown to you, and it is not used to recognise you on any other website. It is not written into our logs beside your IP address; the two are put together only to label those counters, which expire on the schedule described above. If your browser blocks storage the identifier simply is not kept, and your requests fall back to the per-address limits. Clearing this site's data removes it, and the app then makes a fresh one.

Analytics

Probably Weather uses Vercel Web Analytics, a cookie-less, privacy-focused analytics tool provided by our host, Vercel Inc. It records anonymous, aggregated usage events (for example, page views and a one-off "app installed" event) together with coarse technical details derived from your request — an approximate country (from your IP address), device type, browser, and the referring page. It does not use cookies, does not track you across other websites, and does not identify you personally. See Vercel's privacy policy: vercel.com/legal/privacy-policy

Advertising

To keep Probably Weather free, the app is supported by advertising. When ads are shown, the network that serves them may collect and process technical data such as your IP address, device and browser information, the page you are on, and your interactions with the ads, and it may set its own cookies or use similar technologies. Each network's processing is governed by its own privacy policy:

Google AdSense (Google LLC): how Google uses information from sites that use its services · policies.google.com/privacy
Adsterra: adsterra.com/privacy-policy · Media.net: media.net/privacy-policy

Third-party vendors, Google among them, use cookies to serve ads based on your earlier visits to this site or to other sites. Google's advertising cookies let Google and its partners serve you ads based on your visits to this site and to other sites on the internet.

Advertising is being rolled out; depending on when you read this, you may not yet see ads in the app. We disclose it here in advance so this policy is accurate the moment ads go live. We do not share your saved locations or any data you enter with advertisers.

Your ad choice: ads picked for you, or general ads

When Google ads start, the app will ask you once whether Google may pick ads for you. Yes means Google may use cookies and similar identifiers to choose ads based on your earlier activity, such as visits to other sites. No means you still see ads, but they are not picked from your history; Google still uses cookies for frequency capping (how often you see the same ad) and aggregated ad reporting. Until you have chosen, no Google ad loads.

Your choice is kept only on your device, in browser storage, and is never sent to us. Once ads start, you can change it at any time under Settings → Ad choices. Clearing this site's data removes it, and the app asks again.

You can also turn off ads personalised by Google across sites in My Ad Center, Google's ad settings, and opt out of personalised advertising by many other vendors at aboutads.info/choices. Adsterra and Media.net describe their own opt-outs in the policies linked above.

Cookies

Probably Weather itself does not set tracking cookies, and our analytics tool is cookie-less. The advertising networks named above may set their own cookies or similar identifiers when ads are shown. Google, for example, lists advertising cookies such as __gads (lets a site show Google ads), IDE (shows Google ads on sites that are not Google's), DSID (applies a signed-in user's ad settings) and id (remembers that personalised ads are off); its full list is at policies.google.com/technologies/cookies. You can control cookies through your browser settings.

Saved locations and preferences

If you save locations (like "Home" or "Work") or change settings (temperature units, wind units, language), these are stored locally on your device only — in your browser's local storage or the Android app's local data. We never see or access them, and you can clear them at any time through your browser or app settings.

Weather providers

Your approximate latitude and longitude are sent to the following forecast sources, each governed by its own privacy policy:

Open-Meteo — open-meteo.com/en/terms

WeatherAPI.com — weatherapi.com/privacy.aspx

MET Norway (Norwegian Meteorological Institute) — met.no privacy policy

Pirate Weather (API access via Apiable) — docs.pirateweather.net · apiable.io privacy policy

Tomorrow.io — tomorrow.io/legal/product-privacy-policy

Location lookup (search and place names)

LocationIQ (operated by Unwired Labs) powers place search and place-name lookup. When you type in the search box, your search text is sent to LocationIQ to return matching places. When the app needs to turn coordinates into a readable place name (for example, "Strand, Western Cape"), your approximate latitude and longitude are sent to LocationIQ. Privacy policy: locationiq.com/privacy

IP-based location

When your device's GPS is unavailable, blocked, or too slow to answer, the app asks our own server for a rough location instead, at /api/locate on this same website. Our host, Vercel, works out an approximate city-level position from your IP address as the request arrives at its network, and our server hands that back to the app rounded to one decimal place — roughly 11 km, enough to pick the right city and no more. No third-party IP-lookup service is contacted, and your browser opens no connection to one. Vercel's privacy policy: vercel.com/legal/privacy-policy

Install QR code

On the "install" page, the app shows a QR code so you can open the site on your phone. The QR image is generated by goQR.me (api.qrserver.com). Your browser requests the image from that service, so it may see your IP address; the only data encoded in the QR code is the app's public install web address — nothing personal about you. Privacy policy: goqr.me/privacy-safety-security

Hosting and cross-border processing

The app is hosted on Vercel Inc. (United States). When you load the app, Vercel processes standard request metadata (your IP address, user-agent, and the URL you requested) to route the response — the same metadata any web host sees for any visit. Privacy policy: vercel.com/legal/privacy-policy. Because hosting, analytics, advertising, the forecast cache, and some providers are outside South Africa, the processing described here involves cross-border transfers of personal information under POPIA section 72; we rely on the recipients' own contractual and legal safeguards.

Children's privacy

Probably Weather is suitable for all ages. We do not knowingly collect personal information from children. Note that the third-party advertising networks above operate under their own policies; we have configured advertising for a general audience.

Your rights under POPIA

POPIA gives you the right to: confirm whether personal information about you is being processed, request access to it, request correction or deletion, object to processing, and lodge a complaint with the Information Regulator. We hold no account or profile to retrieve. What we do hold is described above: short-lived forecast entries filed by location cell, the delivery-network copies of our responses and share cards, and the per-IP request counters used for abuse protection. The forecast entries and the counters are deleted automatically on the schedules given there. For the delivery-network copies we can tell you how long they may be served before a refresh, but not when Vercel discards them — that is on its own schedule, and we have not verified it. Because your IP address and usage data are processed by the analytics, advertising, hosting, and provider services listed above, you may also exercise these rights directly with them under their policies. Write to us and we will help where we can.

Information Regulator (South Africa): inforegulator.org.za · POPIAComplaints.IR@justice.gov.za

Share links and the share preview

When you share weather using the in-app Share button, the link you send may include the coordinates of the location you were viewing, a language code, and a weather-condition tag used to pick the share-preview image. No personal information about you is encoded in the link. The optional city name in the share preview is the public place name (e.g. "Cape Town") — not your home address.

Changes to this policy

If we make changes, we'll update the date at the top of this page. Because we don't collect email addresses, we can't notify you directly, so please check back here from time to time.

Contact

Questions or concerns? Reach us at howzit@probablyweather.co.za

← Back to Probably Weather