Privacy policy for the Aurora Explorer app and Aurora Developer website. Updated 9 October 2026. Applies to production version 1.3.0 and later versions with the same data practices.
Controller and contact
A Steinhaug (Norwegian organisation number 938 460 035) is the controller for Aurora Explorer. Aurora Developer is the public-facing name. Send privacy questions and requests to kontakt@auroradeveloper.no.
Audience
Aurora Explorer is intended for adults and young people seeking places to view the northern lights. It is not specifically directed at children.
Location and place selection
When you grant location permission and ask the app to find the nearest place, the app calculates distances to registered aurora places on your phone. If a curated place is within 50 km, it selects that place without sending your GPS coordinates as part of that selection. Otherwise, the app may send the coordinates to our backend to calculate weather, light and aurora conditions for “My location”. Location permission is optional; you can select a place manually and use the app without it. For local weather forecasts, our backend may forward the coordinates to the Norwegian Meteorological Institute (MET). Although rounded to four decimal places, they are still considered precise location. Ordinary lookups are not stored in the custom followed-place table or weather history, but the web server access log may contain the requested address and coordinates as described below.
Place searches in the Android app go to our backend, which first searches a local database of place names from the Norwegian Mapping Authority. If there are no local matches, the search text may be forwarded to that authority's place-name service. When you open a result, its name and coordinates are sent to our backend to calculate local conditions. If you follow a searched place or “My location”, the backend stores its name and the centre of an approximate 5 km geographic cell to calculate alerts. The place remains active for alert calculations for 60 days after the last follow request. This is a shared place record, not a list of the users following it. Expiry of the active period does not mean physical deletion; the place record itself currently has no fixed deletion deadline. The map tile provider receives requests for the area displayed on the map and can therefore see which geographic area is being viewed.
Usage data and service operation
Usage statistics are optional and off by default in the production version, including for existing installations. If you enable them in Settings, the app creates a random installation ID and sends it with some API requests. The server stores the ID and the times of first and latest contact to count participating installations. You can turn this off at any time. New reporting stops, though requests already sent may finish. Turning it off queues a deletion request. After successful delivery, the record is deleted from the active database. If offline, the app retries while it runs and at the next launch. Uninstalling before delivery may remove the queue; the regular 90-day cleanup then applies. A hash of the deleted ID is kept to prevent delayed requests from recreating the record; this suppression list currently has no fixed expiry. Database backups may retain earlier records for up to 14 days. Older app versions may continue to send an ID automatically until updated. This is a pseudonymous identifier, not necessarily anonymous data. No user account is required.
Server access logs may contain IP address, time, requested address, client information and response status. We use these for operation, troubleshooting and security. The backend and active database are hosted with Hetzner in Finland. Administrative access is restricted.
A cleanup job deletes installation records when the last contact is more than 90 days old. Backend data-collection logs are deleted after 30 days; these are separate from web server access logs. Nginx is configured for daily log rotation and retains 14 rotated files as well as the active log. Empty logs are not rotated, so under low traffic older files may remain longer than 14 days, assuming the scheduled rotation runs normally. Configured database backups are retained for 14 days. We no longer create new manual database copies on a PC; existing manual copies are scheduled to be deleted no later than 14 days after creation.
In app versions offering the separate Google Analytics setting, this optional feature is off by default. You can agree or decline on first launch and change your choice in Settings. We retrieve aggregated Google Analytics reports into our access-restricted administration dashboard to understand app usage; this does not enable additional browser tracking. If enabled, Google Analytics for Firebase processes app openings, sessions, pages used, app/device information, approximate location derived by Google from masked IP addresses, and a pseudonymous app-instance identifier to help us understand app usage. Our page events do not contain search text, place names or GPS coordinates. Analytics advertising-ID collection and advertising personalisation are disabled. This consent is separate from our own backend usage statistics and advertising choices. Turning the setting off stops future Analytics collection and resets the local Analytics identifier; it does not automatically erase earlier data held by Google. Contact us about deletion requests. Google may process data outside the EEA under the safeguards described below. See https://firebase.google.com/support/privacy/ and https://policies.google.com/privacy . Event and user retention is set to two months without resetting on new activity; most aggregated standard reports are not affected.
Push notifications
You can follow multiple places and control Android notifications separately. We use Google's Firebase Cloud Messaging (FCM) for delivery. FCM processes installation identifiers and message tokens. Subscriptions connect an app installation to the places you follow. Automatic FCM registration is off by default and activates when you follow places. Followed-place choices are also stored on your phone. For a searched place, our backend stores its name and an approximate 5 km cell. The place remains active for alert calculations for 60 days after the last follow request, with retention as described under “Location and place selection”. The exact selected coordinate is not used in this notification table.
You can remove followed places in the app or turn off notifications in Android. Turning off their display in Android does not itself delete Firebase data. When no places are followed, the app requests deletion of its FCM token and Firebase installation ID, retrying after network errors. According to Firebase, the installation ID remains until an API deletion request is made; removal from live systems and backups can take up to 180 days after that request. The active period for a custom place cell on our backend expires even if the app is uninstalled or the place is unfollowed.
Ads, consent and affiliate links
The production version of Aurora Explorer displays Google AdMob ads. Development and test builds may use test ads. Both test and production ads involve contact with Google. Ads may not appear if your privacy choices or ad availability do not permit them.
The Google Mobile Ads SDK may process IP address, advertising and other device identifiers, ad interactions and diagnostic data for advertising, analytics and fraud prevention. IP address may be used to estimate approximate location. The app uses Google's User Messaging Platform (UMP) to obtain and manage privacy choices where required. The ad SDK is initialised after UMP permits ad requests.
Where privacy choices are required, you can reopen them in Settings. You can refuse consent to personalised advertising. Which ads, if any, may appear without such consent depends on Google's configuration and permitted purposes.
The app and website may show clearly labelled affiliate links. If you choose to open one, you leave our service for the partner's website. The partner then receives ordinary web information such as your IP address and referral information, including any tracking parameters in the link. We may earn a commission if you book. The partner is responsible for its subsequent processing after you leave our service.
Maps and other external services
Map tiles are loaded from OpenStreetMap. In the Android app, the Leaflet map library is loaded from unpkg. These services may receive your IP address and other information carried by web requests. Weather and aurora data reach the app through our backend; map and advertising services are separate external connections.
In the password-protected Web Lite version, Leaflet is served locally. OpenStreetMap tiles load when you open the map. If you search for a place name on that map, your browser sends the query directly to the Norwegian Mapping Authority's place-name service; it may receive the search text and your IP address. Forecasts are loaded through a read-only connection to our backend. Web Lite does not offer following places.
When you choose directions, Google Maps or another map app opens. The destination coordinates are passed to the selected service. Your current location, if used, is then handled according to that map app’s own permissions and privacy terms; Aurora Explorer does not start navigation or background tracking on its own.
Website and email
The public homepage at auroraexplorer.no (also available at auroradeveloper.no) uses locally stored images and stylesheets and has no separate analytics or advertising SDK. It may show labelled affiliate links as described above. Web Lite requires HTTP Basic authentication and does not use a user account with us; your browser may remember the login during the session. Visits to our pages may be recorded in server access logs as described above. If you email us, we process your address and message to respond. Do not send passwords or sensitive information. We delete correspondence no later than 12 months after a matter is closed. Material needed for legal obligations or specific legal claims may be kept longer for as long as necessary.
Local storage
The app stores choices such as language, selected places, coordinates of followed searched places, notification settings, cached data and images on your phone. You can remove local app data through Android settings. This does not automatically delete server logs or data processed by other providers. Some settings may be included in Android backups.
The public site stores your language choice in your browser's local storage (aurora-language); Web Lite may store its own language choice (aurora-web-language). These are device settings, not analytics or advertising cookies. You can remove them through your browser settings.
Legal bases and your rights
Optional usage statistics rely on the consent you give when enabling them; you can withdraw it in Settings without losing other app functions. Necessary operation and security, responses to enquiries and the suppression record preventing deleted statistics from being recreated rely on legitimate interests under GDPR Article 6(1)(f). Our interests are providing and protecting the service, helping users and respecting deletion choices. Optional notifications, place searches and location use rely on consent under Article 6(1)(a); withdraw it by unfollowing places or removing location permission. Withdrawal does not affect processing that was lawful before it. Consent is used where required for advertising and can be withdrawn for future processing.
You can contact us to request access, correction, deletion, restriction and other applicable rights. You can object where processing relies on legitimate interests. We may need enough information to find data associated with your installation, but will not request more than necessary. You can complain to the Norwegian Data Protection Authority (Datatilsynet).
Google and map providers may process data outside the EEA. Google describes use of the EU-US Data Privacy Framework for covered US recipients and standard contractual clauses where needed. Section 10 of the Firebase terms governs transfers of customer data, including standard contractual clauses where applicable. OpenStreetMap delivers tiles through a global network and unpkg uses Cloudflare, so processing locations may vary. Provider information and transfer details are linked below. Contact us for information about safeguards and copies of applicable terms. See Google's transfer information.
Information about services
- Google Mobile Ads: developers.google.com/admob/android/privacy/play-data-disclosure
- Google privacy: policies.google.com/privacy
- Firebase privacy: firebase.google.com/support/privacy
- Norwegian Mapping Authority place-name API: kartverket.no/api-og-data/stedsnavndata
- OpenStreetMap privacy: osmfoundation.org/wiki/Privacy_Policy
- Norwegian Data Protection Authority: datatilsynet.no
Additional provider information
Customer support
When you submit a request from the app or website, we store your email address, subject, message, selected language, app or form version and case reference in our backend to handle the request and reply. On submission, the website stores a random support identifier in your browser (aurora-support-installation) to limit abuse. You can remove it in your browser settings. The message content is not saved in browser local storage. The support identifier is stored on the server as a hash to limit abuse and duplicate submissions. The form does not send GPS coordinates or automatic logs. Do not include passwords, payment details or sensitive information. Sending a request is optional and independent of analytics consent.
Only authorised administrators can access requests. We process these details to provide support and prevent abuse, based on our legitimate interest in helping users (GDPR Article 6(1)(f)). Closed support cases are automatically deleted 180 days after their last closure or change. Daily cleanup may add up to one day. Open cases remain until handled. Requests are included in regular server backups. Contact kontakt@auroradeveloper.no for access or deletion.
Account and Premium
In versions offering Premium, you can optionally create an account with email and password. Firebase Authentication handles sign-in and email verification. Our backend uses an account ID and its hash to associate and verify your Google Play subscription. We store an encrypted purchase token, plan, subscription state, expiry and verification times. Google Play handles payment; we do not receive card numbers. This system does not link location, searches or followed places to your Premium account.
Account and subscription data are used to fulfil the account and Premium agreement (GDPR Article 6(1)(b)). Security and refund handling rely on our legitimate interest in protecting the service and handling payment enquiries (Article 6(1)(f)). Refund notifications are stored encrypted with the order ID, optional account-ID hash, reason, time and processing status, and checked against Google. This system does not send location or additional usage evidence to Google for refund cases.
You can delete your account in the app under Menu → Aurora Explorer Premium → Delete account, with fresh password confirmation, or request deletion on our website. The login and account links to purchase tokens are removed. Deletion does not cancel a Google Play subscription and may prevent restoring Premium. Premium security events are retained for 90 days. Completed refund and support cases are deleted after 180 days from their last processing or closure. Unresolved cases remain until handled. Encrypted refund tokens are removed after a confirmed response or Google-confirmed refund. Daily cleanup may add up to one day. These are operational records, not accounting documents. Regular server backups are retained for up to 14 days. Google has its own rules for payment and Firebase data. Other installation data are handled as described above.