top of page

Privacy policy — Weasley Clock

Weasley Clock shows where your family are as hands on a clock face. This policy explains
what the app does with information, and it is short because the app does very little.

The short version: **your location never leaves your phone.** Your phone works out for
itself which of *your own* saved places you are at, and sends nothing but the name of
that place. There is no account, no email address and no password, because there is
nothing to attach one to.

---

What we do not collect

Plainly, so there is no doubt:

- **We never receive your location.** No coordinates, no map positions, no routes, no
  history. Not approximate, not precise, not once.
- **We do not know who you are.** There is no account, no sign-up, no email address, no
  phone number, no name and no password anywhere on our service.
- **We have no advertising, no analytics, and no third-party trackers** of any kind.
- **We do not sell, rent or share anything with anyone.** There is nothing to sell.

What your phone keeps to itself

All of this stays on your device and is never uploaded:
| **The places you pin** | Their coordinates and radius, so your phone can tell when you arrive |
| **Your name** | Typed by you, and shared only inside an invite code you hand to someone |
| **Everyone's names** | What *you* call the people on your clock |
| **Your clock's appearance** | Face, hands, colours, lettering |
| **A photo you choose as a backdrop** | If you set one; it is never uploaded |
| **Places you keep visiting** | Rounded to about 100 metres, so the app can offer to add them. Capped, dropped after a month, never uploaded |
| **A diagnostics log** | Off unless you turn it on. Contains no coordinates, no place names and no contact names |

What is sent to our service

When you arrive somewhere you have pinned, your phone sends a small message:

- **A number identifying which of your places it is.** Not where that place is — just
  "the one you called Home".
- **When you arrived.**
- **An identifier for your device**, derived from a cryptographic key your phone
  generates and keeps. It is not linked to you, your phone number, your email or any
  account, and it cannot be traced back to you by us or anyone else.

That message is about forty bytes and is sent roughly eight times a day. It is signed by
your phone so nobody can send one pretending to be you.

We also hold, only for as long as you use the app:

- **Who you have agreed to share with**, as a list of those device identifiers.
- **A push notification token**, so we can ask your phone to check for updates.
- **Your profile photo, if you set one** — see below.

 

Your photo

If you add a photo, it is **encrypted on your phone before it is uploaded**, separately
for each person you share with. We store the encrypted result and cannot open it. Only
the people you have shared with hold a key that can.

 

What other people can see

Only the people you have approved, and only:

- Which of your places you are at, or *Away* if you are somewhere you have not named
- How long ago we last heard from your phone
- Your photo, if you set one, and the name they gave you

They cannot see where any of your places actually are, anywhere you have not named, or
anywhere you have been in the past.

**You can pause at any time**, for everyone or for one person. While paused your hand
simply says nothing — exactly as it would if your phone were switched off. Nobody is
told that you paused.

 

Permissions the app asks for

- **Location, set to "Always"** — required. The whole app is noticing when you arrive
  somewhere while it is closed. Your phone does that work itself; the location is not
  sent anywhere.
- **Physical activity** *(Android, optional)* — used only to notice when you have stopped
  moving, so the app knows a place check is worth doing. Declining changes nothing except
  that your clock may update a little later.
- **Camera** *(optional)* — only to scan a friend's invite code. Nothing is recorded and
  no image leaves your phone.

Children

A parent can set up the app on a child's phone from their own device, in person. A device
can never put itself into child mode. We collect nothing additional for a child device,
because we collect nothing identifying for any device.

 

How long we keep things

Your device record lives on our service while you use the app. If you stop using it, the
record stops being updated and its last place code is all that remains.

**To delete everything, use the delete option in the app.** It removes your device
record, every sharing link in both directions, and your encrypted photo. Because we hold
nothing that identifies you, we cannot delete your data on request by email — there is no
way for us to tell which record is yours. The app is the only thing that can prove it.

> **Note for this draft:** the in-app delete is not built yet — see `docs/DEFERRED.md`.
> This paragraph must be true before the app is published, and both stores require it.

 Where the data lives

On Microsoft Azure, in the United Kingdom. Everything is encrypted in transit.

Changes

If this policy changes we will update the date at the top and note it in the app's
release notes. Material changes will be shown in the app.

Contact

Allenbirdcam@gmail.com

Because there are no accounts, please include what you are asking about rather than
"my account" — we will not be able to look you up.

bottom of page