Privacy Policy

Version 1.3 · Effective date: Apr 1, 2026 · Last updated: Sep 9, 2026

1. Who We Are

Wildflyer B.V. ("Wildflyer", "we", "us", or "our") provides a wildfire intelligence platform for fire services and emergency management organisations. Our products include Wildflyer Analyst (a web application), Wildflyer FieldKit (a native mobile app for iOS and Android), and Wildflyer FireWeather (a free fire-weather app for iOS, Android and the web, with an optional account and optional paid plans).

Data Controller:

Wildflyer B.V.

Kapteynstraat 1, Suite 140

2201 BB Noordwijk, The Netherlands

Email: daan@wildflyer.co

KvK (Chamber of Commerce): 91830192

This Privacy Policy explains how we collect, use, store, and protect personal data when you use our products or visit our website. It applies to all users of Wildflyer Analyst, Wildflyer FieldKit, Wildflyer FireWeather, wildflyer.co and fire-weather.com.

2. What Data We Collect

Sections 2 to 11 describe Wildflyer Analyst and Wildflyer FieldKit, which are used by organisations and require an account. Wildflyer FireWeather works without an account and collects far less; if that is the app you are using, section 12 covers it in full and is written to stand on its own.

2.1 Account Data

When you create an account or are invited by your organisation, we collect your name, email address, and organisation affiliation. We use email-based one-time password (OTP) authentication — we do not store traditional passwords.

2.2 Usage Data

We collect information about how you interact with our products, including pages visited, features used, and timestamps. This helps us improve the platform. Web analytics are processed using Umami, which is self-hosted on our own EU infrastructure — no data is sent to third parties for analytics purposes.

2.3 Device and Technical Data

We collect IP addresses, browser/device type, operating system, and screen resolution. On the FieldKit mobile app, we additionally collect device identifiers for push notification delivery and basic device telemetry for map rendering (via Mapbox).

2.4 Location Data

Wildflyer FieldKit may request access to your device's location. This is used to show your position on the incident map and to enable location-aware features like nearby incident alerts. Location data is shared with your team members within the app when you are on an active incident. You can disable location access in your device settings at any time.

2.5 Camera and Media

FieldKit may request access to your device's camera and photo library to allow you to capture and upload incident photos and videos. These media files may contain embedded metadata such as GPS coordinates (EXIF data) and timestamps. Uploaded media is stored on our servers and shared with members of your organisation who have access to the relevant incident.

2.6 Push Notifications

FieldKit uses push notifications to deliver incident alerts and team communications. We use Expo Push Service as a relay and Apple Push Notification service (APNs) for iOS delivery. Push notification tokens are device-level identifiers and are not linked to your personal identity by the relay services. Notification payloads are encrypted in transit. You can disable push notifications in your device settings.

2.7 Incident and Operational Data

Data you enter into the platform — incident reports, perimeter drawings, team assignments, weather observations, photos, and other operational content — is stored and processed to provide our services. This data may contain personal information about emergency personnel or members of the public involved in incidents.

2.8 Payment Data

If your organisation subscribes to a paid plan, payment processing is handled by Stripe. We store your billing contact details (name, email, billing address) but do not store or have access to credit card numbers or bank account details — these are handled entirely by Stripe.

2.9 Error and Crash Data

We use Sentry (hosted in the EU, Germany) to monitor errors and performance issues across both Analyst and FieldKit. When an error occurs, Sentry may collect your user ID, email, display name, IP address, device information, and technical stack traces. This data is used exclusively for debugging and improving platform stability.

3. Why We Process Your Data (Legal Basis)

We process personal data under the following legal bases as defined in the GDPR:

  • Performance of a contract (Art. 6(1)(b)) — to provide and maintain our platform services as agreed with your organisation
  • Legitimate interests (Art. 6(1)(f)) — to improve our products, ensure platform security, prevent fraud, and provide customer support
  • Consent (Art. 6(1)(a)) — for optional features such as push notifications and location sharing, which you can withdraw at any time through your device settings
  • Legal obligation (Art. 6(1)(c)) — where required by law, for example tax and accounting records related to billing

4. How We Use Your Data

We use the data we collect to:

  • Provide, operate, and maintain the Wildflyer platform (Analyst and FieldKit)
  • Authenticate your identity and manage your account
  • Deliver notifications, alerts, and incident communications
  • Process payments and manage subscriptions
  • Monitor and fix errors, crashes, and performance issues
  • Improve our products based on usage patterns (using self-hosted analytics)
  • Respond to your support requests
  • Comply with legal obligations

We do not sell your personal data. We do not use your data for advertising. We do not use your data to train machine learning models.

5. Who We Share Data With

We share personal data only with trusted third-party service providers (sub-processors) who help us deliver our platform. Each sub-processor is bound by a Data Processing Agreement and processes data only on our instructions.

A complete, up-to-date list of our sub-processors — including what data each processes, their legal entity, and their data residency location — is maintained in our List of Data Processors.

Key sub-processors include:

  • Hetzner (Germany) — infrastructure hosting and data storage
  • Vercel (global CDN) — static web app delivery
  • Stripe (US/EU) — payment processing for organisation subscriptions and for FireWeather plans bought on the web
  • Brevo (France) — transactional email delivery
  • Sentry (Germany) — error tracking and performance monitoring
  • Mapbox (US) — native map rendering in FieldKit and FireWeather
  • Open-Meteo (Germany) — weather forecasts and place search in FireWeather
  • MapTiler (Switzerland) — map tiles and geocoding in Analyst
  • Expo (US) — mobile app infrastructure and push notification relay
  • Apple and Google (US) — push notification delivery to phones, and payment processing for purchases made inside the FireWeather app
  • RevenueCat (US) — verification of in-app purchases in FireWeather, where a plan is sold inside the app
  • Bunny.net (Slovenia/EU) — video streaming and CDN

We may also share data if required by law, regulation, or court order.

6. Where We Store Your Data

Your data is primarily stored and processed within the European Union, specifically in Germany (Hetzner data centers in Falkenstein and Nuremberg).

Some sub-processors are based in the United States (Stripe, Mapbox, Expo, Vercel, Apple, Google, RevenueCat). Where data is transferred outside the EEA, we ensure appropriate safeguards are in place as required by GDPR, including the EU-US Data Privacy Framework, Standard Contractual Clauses (SCCs), or adequacy decisions.

For details on each sub-processor's data residency, see our List of Data Processors.

7. How We Protect Your Data

We implement appropriate technical and organisational measures to protect your data, including:

  • Encryption of data in transit (TLS 1.3) and at rest (AES-256)
  • Role-based access control and multi-factor authentication
  • Regular security assessments and vulnerability testing
  • ISO 27001-certified data centres (Hetzner)
  • Daily encrypted backups with 90-day retention
  • 24/7 system monitoring and alerting
  • Employee training on data protection

For full details, see the Technical and Organisational Measures appendix in our Data Processing Agreement.

8. How Long We Keep Your Data

We retain your personal data for as long as your account or your organisation's subscription is active. When an account or subscription is terminated:

  • Your organisation has 60 days to export all data
  • After the export period, personal data is deleted from active systems
  • Backup copies are deleted or anonymised within 90 days
  • Billing records may be retained for up to 7 years as required by Dutch tax law

9. Your Rights

Under the GDPR, you have the following rights regarding your personal data:

  • Access — request a copy of the personal data we hold about you
  • Rectification — ask us to correct inaccurate or incomplete data
  • Erasure — ask us to delete your personal data (subject to legal retention requirements)
  • Restriction — ask us to limit how we process your data
  • Portability — receive your data in a structured, machine-readable format
  • Objection — object to processing based on legitimate interests
  • Withdraw consent — for processing based on consent, such as push notifications or location sharing

To exercise any of these rights, contact us at daan@wildflyer.co. We will respond within 30 days.

If you are not satisfied with our response, you have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl.

10. Cookies and Tracking

Our website and web applications — including fire-weather.com once you sign in — use minimal cookies required for functionality:

  • Session cookies — to keep you logged in during your session
  • Security cookies — for CSRF protection and rate limiting

We do not use third-party advertising cookies or tracking pixels. Our web analytics (Umami) are self-hosted and do not use cookies — they collect anonymous, aggregated usage data only.

11. FieldKit Mobile App — Additional Disclosures

This section provides additional information specific to the Wildflyer FieldKit mobile app, as required by Apple and Google's app store policies.

11.1 Data Collected by FieldKit

Data TypePurposeShared with Third Parties?Optional?
Name and emailAccount authentication, team identificationBrevo (email delivery), Sentry (error context)Required
Precise locationShow position on incident map, location-aware alertsMapbox (map tile requests contain approximate location)Optional (device permission)
Photos and videosIncident documentationHetzner Object Storage (hosting)Optional (device permission)
Push notification tokensDelivering incident alertsExpo Push Service, Apple APNsOptional (device permission)
Device info, IP addressError tracking, performance monitoringSentry (EU, Germany)Required
Device telemetryMap renderingMapboxRequired for map features

11.2 Offline Data Storage

FieldKit stores some data locally on your device for offline functionality. This includes cached incident data, map tiles, and queued actions that sync when connectivity is restored. This local data is protected by your device's native security (passcode, biometrics) and is cleared when you log out of the app.

11.3 Third-Party SDKs

FieldKit includes the following third-party SDKs:

  • Mapbox Maps SDK — for 3D map rendering and terrain visualisation. Mapbox may collect anonymised telemetry data (which can be disabled). See Mapbox Privacy Policy.
  • Sentry SDK — for crash reporting and error tracking. Data is sent to Sentry's EU (Germany) data centre. See Sentry Privacy Policy.
  • Expo SDK — for push notifications and over-the-air updates. See Expo Privacy Policy.

12. FireWeather App — Additional Disclosures

This section applies to Wildflyer FireWeather, our fire-weather app for iOS, Android and the web (fire-weather.com). It is a separate product from Analyst and FieldKit, it is free to use, and it collects markedly less than either of them. It is written to be read on its own, and where it says something different from sections 2 to 11, this section is the one that applies to FireWeather.

An account is optional. You can open the app, look up any place, read its forecast, use the map and switch on a fire-weather alert without signing in and without telling us who you are. Signing in — with your email address and a one-time code — is needed for two things only: to save places so that they follow you between devices and survive a reinstall, and to buy or redeem a paid plan. Section 12.7 describes what an account stores. Sections 12.1 to 12.6 describe what happens whether or not you have one.

12.1 What Stays on Your Device

Your settings (language, units, light or dark), the place you last looked at, the places you have saved, a copy of the last forecast so the app opens offline, and — once you switch on an alert — a random identifier for this device, are all stored on your phone or in your browser. Without an account, none of this is transmitted, with one exception: the place attached to an alert you switch on, which we must keep in order to send that alert (12.6). With an account, your saved places are additionally kept on our servers so they can be restored on another device (12.7). Deleting the app removes everything stored on the device.

12.2 Data Collected by FireWeather

Data TypePurposeShared with Third Parties?Optional?
Location (precise or approximate)Fetching the forecast for where you are, and naming the place you are atOpen-Meteo (Germany) — coordinates appear in the forecast request; Mapbox (US) — map tile requests reveal the area shown, and a reverse-geocoding request turns your coordinates into a place nameOptional — you can search for a place instead and never grant the permission
Place searchesFinding a place by nameOpen-Meteo (Germany) — geocoding. Nothing is retained by usOptional (only when you search)
Account — your email address, the display name shown in the app (taken from the part of your email address before the @ unless you change it), the language you use the app in, the date you signed up, and a record of each sign-in (date, method, internet protocol (IP) address and the browser or device string)Signing you in, keeping your saved places and plan across devices, and noticing an account being used from somewhere unexpectedBrevo (France) delivers the one-time code email. Nothing elseOptional — only if you sign in
Saved places — the coordinates and name of each place you bookmark, in your orderRestoring your places on another device or after a reinstallNo — stored on our own EU infrastructure, attached to your accountOnly with an account. Removing a place removes it from our servers too
Alert subscription — a random identifier for this device, the coordinates and name of the place you chose, its time zone, which alert, how often, at what hour, and your languageSending the fire-weather alert you asked for, at the right hour, in the right language, and not twiceStored on our own EU infrastructure. When an alert is sent, the notification text and the place it is about pass through the push services in the next rowOptional — only if you switch an alert on. Deleted when you switch it off
Push notification token (phone) or push subscription (browser)Delivering the alert to your phone or browserExpo Push Service (US) as relay; Apple Push Notification service or Google Firebase Cloud Messaging for phones; your browser vendor's push service (Apple, Google or Mozilla) for browsersOptional — only if you switch an alert on
Plan and payment data — see 12.8Selling a paid plan and honouring it on every device you sign in onStripe (US/EU) for purchases made on the web; Apple or Google for purchases made inside the appOptional — only if you buy or redeem a plan
Anonymous usage eventsUnderstanding whether the app is useful and whether people returnNo — our analytics are self-hosted on our own EU infrastructureRequired
Crash and error reportsFixing crashesSentry (EU, Germany)Required

We do not collect your phone number, contacts, photos, files, calendar or health data through FireWeather, and we never read your location in the background. We do not use advertising identifiers. The app contains no ads and no advertising SDKs. We never see or store a card number — payment details are entered on Stripe's, Apple's or Google's pages, not ours.

12.3 Location — What Actually Happens To It

To show you the weather somewhere, that place's coordinates have to reach the service that produces the forecast. FireWeather sends them to Open-Meteo, in the request itself, and receives weather back. Nothing identifying travels with them: no account, no device identifier, no history. For browsing the forecast, we do not store your location on our servers — in that path there is no server of ours at all, whether or not you are signed in.

A place's coordinates reach our servers in exactly two cases: the place attached to an alert you switched on (12.6), and the places you bookmark while signed in (12.7). Both are places you chose deliberately, not a trail of where your phone has been. The position of your device itself is never stored by us.

If you grant the location permission, it applies while you are using the app only. FireWeather never requests background location and cannot read your position when it is closed. An alert does not change this — it is sent from our servers on a schedule, using the place you picked, and does not read your phone's position.

12.4 Analytics — Measuring Without Identifying Anyone

We want to know whether people find the app useful. Measuring that normally requires an identifier that follows you, and we decided not to have one. Instead:

  • Every measurement is computed on your device and coarsened before it is sent. Where a conventional analytics system would send "user 4f2a opened the app on 12 September, day 23 of their use", we send "someone opened the app; they are in the 21+ days bucket and have used it on 14+ distinct days". Those buckets are all we ever receive.
  • No identifier is attached — no account, no advertising id, no cookie. Signing in does not change this. Your account id is never attached to an analytics event; the analytics code drops any identifier by name before an event leaves your device, and a sign-in is recorded as "somebody signed in, from this screen", never who. The alerts identifier described in 12.6 is not attached either. We cannot join an account or an alert subscription to anyone's usage.
  • Anything that could carry a coordinate, a search term or a place name is removed before the event leaves your device, as a safety net independent of what any individual screen sends.
  • Our analytics are Umami, self-hosted on our own infrastructure in the EU. No third-party analytics or advertising company receives anything.

12.5 Crash Reports

We use Sentry (hosted in the EU, Germany) to be told when the app crashes. Because the app fetches forecasts by putting coordinates in a URL, a default crash reporter would ship your exact location to a third party. FireWeather removes coordinates from crash data in three independent places — from breadcrumbs, from the crash event itself, and by switching off the SDK's network breadcrumbs entirely — so that a crash report cannot carry your position even when the crash happened inside a network request. Unlike Analyst and FieldKit (2.9), a FireWeather crash report carries no user id, no email address and no IP address; it names the country the place was in, the app language, and the technical state of the screen, and nothing about you.

12.6 Fire-Weather Alerts

Alerts are off until you switch one on, and the app never asks for notification permission at launch or on opening the alerts screen — only at the moment you turn an alert on. You do not need an account for them.

When you switch one on, your phone or browser generates a random identifier — 122 random bits, minted on the device, not derived from anything about you, your device or your Apple or Google account — and stores it in the app's own storage. We keep one row per alert you enable, containing:

  • that random identifier, and a push notification token for your phone (or, in a browser, the browser's push subscription);
  • the coordinates and name of the place you chose for the alert, and its time zone;
  • which alert it is, how often you want it, the hour of day you asked to hear about it, and which language to write it in;
  • the date we last sent it, so an hour that runs twice does not notify you twice;
  • if you are signed in on that device, a link to your account, so that the deletion actions in 12.9 can find it.

That is the entire record. There is no history of what we sent you. The identifier is not your device's advertising id or any identifier shared with other apps — it exists only inside FireWeather and only for this purpose. When an alert goes out, the notification — its text, and the place and date it is about, so the app can open on them — is handed to the push services named in 12.2 for delivery.

How it is deleted. Turning an alert off deletes that row immediately and completely — turn off every alert and nothing about your device remains. Deleting the app removes the identifier from your phone, and because our notification relay tells us when a token belongs to an app that no longer exists, we delete the row when that happens. As a backstop, any subscription whose app has not been seen for 90 days is deleted automatically. If you are signed in, Delete my FireWeather data (12.9) removes every alert attached to your account and to that device at once.

Alerts in a browser. The web version asks your browser for notification permission and keeps the same record. At the time of writing, browser alerts are not yet being sent — the alerts screen says so — and the subscription is stored so that they can start without you having to set them up again. It is deleted in the same ways.

12.7 Your Account

Signing in. You enter your email address and we send you a six-digit code, which is valid for ten minutes and is discarded once used or expired. There is no password. The code email is delivered by Brevo (France), our email provider. An account is created the first time you sign in.

What an account stores. Your email address; a display name, which we take from the part of your email address before the @ unless you change it; the language you use the app in; when the account was created; and a record of each sign-in with its date, the method used, the IP address it came from and the browser or device string. Those sign-in records exist for security — they are how an account being used from somewhere unexpected could be noticed — and they are the only place our servers keep your IP address. Attached to the account are the places you save (12.2) and any alert you switch on while signed in (12.6), and, if you buy or redeem a plan, the plan record described in 12.8.

Staying signed in. A signed-in session is kept in a cookie in your browser, or in the secure storage of your phone. It expires after seven days without use, and signing out ends it. Signing out does not delete anything: your saved places stay on the device and on our servers, and your alerts keep working.

One account across our products. If you already have a Wildflyer Analyst or FieldKit account under the same email address, signing in to FireWeather uses that same account. What you do in those products is covered by sections 2 to 11; a FireWeather-only account is a member of no organisation and is not visible in them.

Why we may process it (legal basis). Your account, saved places and plan are processed to provide the service you asked for (Article 6(1)(b) of the General Data Protection Regulation (GDPR), performance of a contract). Sign-in records are kept in our legitimate interest in keeping accounts secure (Article 6(1)(f)). Alerts, and reading your device's location, happen only with your consent, which you withdraw by switching the alert off or revoking the permission (Article 6(1)(a)). Billing records are kept because tax law requires it (Article 6(1)(c)).

How long. Everything above is kept for as long as your account exists and is deleted with it (12.9). Where a session cookie is used, section 10 applies.

12.8 Paid Plans and Payments

FireWeather is free, and the free version stays free. Optional paid plans add capacity, such as more saved places and more alerted places. A plan is attached to your account, which is why buying one requires signing in. What we keep for a plan is small: which plan, when it started, when it renews or ends, and where it came from — a purchase, or a gift or licence code.

Buying on the web. Purchases made on fire-weather.com are processed by Stripe. Stripe receives your email address, your country and, where needed to calculate tax, your billing address, together with your card or other payment details, which you enter on Stripe's pages and which never reach our servers. Stripe calculates and applies value-added tax. We store a reference to your Stripe customer record and the status of your subscription, so the app can show your plan and so a missed notification from Stripe can be corrected. Invoices and receipts are issued by Stripe; you can manage or cancel a subscription through the billing portal Stripe provides, reached from the account screen. See the Stripe Privacy Policy.

Buying inside the app. Where a plan is offered inside the iOS or Android app, the purchase is made through Apple's App Store or Google Play. Apple or Google handle the payment and hold your payment details; we never receive them. What we receive is a record of the purchase — which plan, when it started and when it renews or ends, and an anonymised transaction reference — which we attach to your account so the plan works on every device you sign in on. We use RevenueCat (US) to receive and verify those purchase records from Apple and Google. Refunds and cancellations for in-app purchases are handled by Apple or Google under their terms.

Gift and licence codes. A code is redeemed against your account on the web. We record which code was used, by which account and when. If someone gave you the code, they can see that it was used, but never your email address.

How long. Plan records are kept for as long as your account exists. Billing records — the invoices Stripe issues and our record of the sale — are kept for up to seven years after the purchase, as Dutch tax law requires, and survive account deletion; they are kept for that purpose only.

12.9 Deleting Your Data, and Your Rights

If you have never signed in and never switched on an alert, FireWeather holds no account and no identifier for you, so there is no personal data of ours to look up, correct, export or delete — nothing links any record to you. To remove everything the app has kept, delete the app: the saved places and settings live on your device and go with it.

If you have switched on an alert without an account, the record described in 12.6 exists until you delete it. You can do that yourself at any moment, without contacting us: turn the alert off in the app, or delete the app. We hold nothing that would let us find that record from your name or email address, so self-service deletion in the app is the complete route.

If you have an account, two actions are built into the app, under Settings → Account, on every platform including the web at fire-weather.com — so you can use them without having the app installed:

  • Delete my FireWeather data removes, immediately and permanently, every saved place and every alert attached to your account and to the device you are using. Your account stays, so you can sign in again later with an empty slate.
  • Delete my account ends the account. For a FireWeather account — one that is not a member of any organisation in Analyst or FieldKit — this is an immediate, permanent, hard delete: the account, its email address, its sign-in records, its sessions, its saved places, its alerts and its plan records are all removed in a single step, and you are signed out. There is no grace period and no way to undo it. If the same account is also a member of an organisation, the app instead sends an erasure request to our privacy team, because your entries in that organisation's incident records cannot be removed automatically; we complete the request within 30 days and confirm it to you by email.

Deleted data is gone from our active systems at once and from backups within 90 days (section 8). Billing records are the one exception, for the reason and the period given in 12.8. Your other rights under the GDPR — access, correction, portability, restriction and objection — are as described in section 9, and the address to write to is the same.

If you believe we hold personal data about you despite the above, contact daan@wildflyer.co and we will investigate and respond within 30 days.

12.10 Third-Party Services in FireWeather

  • Hetzner (Germany) — hosts our servers and database, which is where accounts, saved places, alert subscriptions and plan records live.
  • Open-Meteo (Germany) — weather forecasts and place search. Receives coordinates and search terms, directly from your device. See the Open-Meteo terms.
  • Mapbox (US) — map rendering and turning your coordinates into a place name. The Mapbox telemetry in the phone app is switched off. See the Mapbox Privacy Policy.
  • Brevo (France) — delivers the sign-in code email, and the confirmation email if you request erasure. See the Brevo Privacy Policy.
  • Sentry (EU, Germany) — crash reporting. See the Sentry Privacy Policy.
  • Expo (US) — app builds, over-the-air updates, and the push notification relay for alerts. If you enable an alert on a phone, Expo receives your push token and the notification in order to deliver it. See the Expo Privacy Policy.
  • Apple and Google (US) — the operating-system notification services that deliver an alert to your phone (Apple Push Notification service, Google Firebase Cloud Messaging), and, for purchases made inside the app, the payment processing of the App Store and Google Play. Mozilla plays the notification role for Firefox on the web.
  • Stripe (US/EU) — payment processing for purchases made on the web. See the Stripe Privacy Policy.
  • RevenueCat (US) — receives and verifies in-app purchase records from Apple and Google, where a plan is sold inside the app. See the RevenueCat Privacy Policy.

Our analytics (Umami) run on our own servers and are not a third party. The complete list, with what each processor receives, is the List of Data Processors linked in section 5.

13. Children's Privacy

Analyst and FieldKit are professional tools for fire services and emergency management organisations. FireWeather is publicly available but is built for, and aimed at, an adult audience. None of our products is directed at children under the age of 16, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will promptly delete it.

14. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our products, practices, or legal requirements. When we make material changes, we will notify affected users by email and update the "Last updated" date at the top of this page. We encourage you to review this policy periodically.

15. Contact Us

If you have any questions about this Privacy Policy, your personal data, or wish to exercise your rights, please contact:

Wildflyer B.V.

Kapteynstraat 1, Suite 140

2201 BB Noordwijk, The Netherlands

Email: daan@wildflyer.co

Phone: +31 6 460 710 67

Related Documents

Version 1.3 — September 2026