Privacy Policy
Who we are
Krona watch apps are developed and operated by Lord Skippy LLC, based in St. Petersburg, Florida, United States ("we", "us"). For anything in this policy, contact us at info@lordskippy.com.
The short version
What we collect, and why
| Data | Where it goes | Why | Kept for |
|---|---|---|---|
| Device location (coordinates, rounded on-device to ~1 km before transmission) | Sent from your watch or phone to our weather server over an encrypted connection (TLS). The server forwards the rounded coordinates to the weather data provider — Open-Meteo (Basic plan) or Apple Weather (Premium plan) — to obtain the forecast, and stores only a coarse geohash grid cell (~5 km Basic, ~1 km Premium) — not the coordinates. On the Custom plan, rounded coordinates go directly from your device to OpenWeatherMap with your own key and never reach our server (no caching or logging on our side at all). With your opt-in (see Background location), the App also reads your position while it is closed — at most about once an hour — and requests a fresh forecast when you have moved more than a few kilometres. | Showing the forecast for your location; noticing that you travelled so the widget and watch face stay current; caching so nearby users share one upstream request. | Grid cell in request statistics: up to 90 days. Forecast cache: up to 2 hours. Precise position: on your device only. |
| Anonymous Data ID (a random key your App creates on first use) and request statistics linked to it (timestamp, grid cell, cache status, response time, HTTP status) | Our server (hosted by DreamHost in the United States). | Service reliability, per-install rate limiting, abuse prevention, capacity planning, verifying premium entitlements. The Data ID is not linked to your name, email, device identity, or any advertising identifier — you can see it in the App under About. | Up to 90 days after last use — or deleted instantly on request at /delete-data. |
| IP addresses in standard web-server logs | Our hosting provider's ordinary access logs. | Security and troubleshooting (an inherent part of operating any web service). | Approximately 30 days. |
| Purchase information | Handled entirely by Google Play. We receive a purchase token confirming your entitlement — never your payment details, name, or address. | Unlocking premium features you paid for. | For as long as your entitlement is active, plus statutory record-keeping periods. |
| Settings and cached weather on your device | Stay on your watch/phone. Never uploaded. | The App working the way you configured it, including offline. | Until you clear the App's data or uninstall it. |
Background location — optional, off until you say yes
On first launch the App asks a plain question: should it update the weather in the background? If you choose "Update in the background" and grant Android's "Allow all the time" location permission, the App may read your position while it is closed — at most about once an hour, reusing the system's existing fix whenever possible — so that when you travel, the home-screen widget, the watch face and the ring refresh for where you actually are without you opening anything. The position is used exactly as in the foreground: rounded to ~1 km, sent only to request the local forecast, never stored server-side beyond the coarse grid cell, and never used for anything else.
If you choose "Only while using the app", everything still works — the App simply learns a new position only when you open it (weather itself still refreshes in the background for the last known place). You can change your mind anytime: in the App under Location → Background updates, or in Android's settings by setting Krona's location permission to "Allow all the time" or "While using the app".
What we do not do
No advertising, no ad identifiers, no analytics SDKs, no selling or renting of data, no cross-app tracking, no profiling, no accounts, no collection of names, email addresses, contacts, health data, or message content. The App requests exactly one sensitive permission: location — and its background variant only ever with your explicit opt-in, which you can withdraw at any time.
Third parties we rely on
- Open-Meteo (weather data, EU-based) — receives coordinates from our server to produce your forecast on the Basic plan. See the Open-Meteo terms. If our server is unreachable, the App may query Open-Meteo directly from your device as a fallback, in which case Open-Meteo receives your device's request (including IP address).
- Apple Weather / Apple Inc. (weather data, USA) — receives coordinates from our server to produce your forecast on the Premium plan (WeatherKit). See Apple Weather attribution and Apple's privacy policy.
- OpenWeatherMap (weather data) — on the Custom plan only, the App sends your coordinates directly from your device using your own API key; our server is never involved. See the OpenWeatherMap privacy policy.
- DreamHost (server hosting, USA) — processes all server-side data above on our behalf.
- Google Play / Google LLC — app distribution, billing, and (on the watch) the fused location service that supplies your position to the App. Governed by Google's privacy policy.
Legal bases (GDPR / UK GDPR)
Where the GDPR applies, we process location and request data to perform our contract with you (delivering the forecasts the App exists for, verifying purchases) and under our legitimate interest in operating a reliable, abuse-free service (statistics, logs). Background location is the one exception: it is processed only on the basis of your consent — the in-app opt-in plus Android's "Allow all the time" grant — and you can withdraw that consent at any time by changing the permission, with no loss of the App's core function.
International transfers
Our server is located in the United States. If you use the App from the EU/EEA, UK, or elsewhere, the request data described above is processed in the United States. We minimize what is transferred (grid cells, not coordinates; no identity data).
Your rights
Depending on where you live (EU/EEA, UK, California, and other jurisdictions), you may have the right to access, correct, delete, or export data about you, to object to or restrict processing, and to complain to your data-protection authority. One honest caveat: we cannot identify you in our data by name — the only link is the anonymous Data ID held by your App. That is also what makes your rights easy to exercise: access and deletion are self-service at /delete-data using the Data ID shown in the App under About. For anything else, email info@lordskippy.com and we will respond within 30 days. We never discriminate against you for exercising any right.
Data deletion
The App requires no account. To remove on-device data, uninstall the App or clear its storage. Server-side data (your anonymous Data ID and its request statistics) can be deleted instantly and self-service at krona.lordskippy.com/delete-data — your Data ID is shown in the App under About. Independently of any request, server-side data is deleted automatically after 90 days of inactivity. You may also email us at any time and we will delete it for you.
Children
The App is not directed at children under 13, and we do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it.
Security
All traffic between the App and our server uses TLS. Server credentials and upstream API keys are stored outside the web root with restricted access. No system is perfectly secure, but our best protection is structural: we simply don't hold data worth stealing.
Changes to this policy
If we change this policy, the new version will be posted here with an updated effective date. Material changes (for example, a new category of collected data) will additionally be announced in the App's store listing changelog.