Privacy & data handling
Last updated: 31 August 2026.
This product is built to need almost no personal data. There is exactly one thing it has ever collected about you: your email address, if you give it to sign up for occasional email updates about the product. Everything else below is a description of data that is not collected.
No accounts
There is no login, no user profile, no server-side "save my plan." The shareable URL is the save mechanism instead — see below for what that means for privacy. The email-updates signup never creates an account either: there is no password and nothing to log into.
Your starting location stays in your browser, with one exception
Whichever way you set a starting location — typing a place, dropping a pin, or "use my location" (browser geolocation) — the resulting coordinates are used only in your browser: how far a spot is from your start is worked out on your own device, and the app never sends your starting location to our server as data of its own.
The exception is a share link, which carries that location in the URL itself. Opening such a link sends the coordinates to our server inside the request for the page — unavoidably, because carrying the location is the whole point of the link. Being sent is not the same as being kept: the web server that answers that request does not write the location, or the address it came from, into its log. The next section says exactly what is logged, including the one place a share link's coordinates do briefly land.
What is sent to a server, and why
- Inspecting a spot sends that spot's coordinates — not your starting location — to our own server, which forwards them to MET Norway for the cloud forecast. The coordinates are rounded to about 0.1° first, so many nearby clicks share one cached answer.
- Typing a place name sends that search text to the same server, which forwards it to OpenStreetMap Nominatim to turn it into coordinates.
- Neither route logs requests against a user identity — there are no accounts, sessions, or cookies to tie a request to a person. What is cached is rounded coordinates and search text, shared across everyone, not per-person data.
- The web server that serves this site's pages logs no IP addresses and no URL query strings. Its access log keeps the time, the request method and path, the response status and size, and the browser's user-agent string — and nothing else.
- Your browser is told not to pass the page's address on. Every page here is served with a strict referrer policy, so when the page fetches a forecast, a place name, or the analytics script, it says which site the request came from and not which page you were on. A share link's coordinates are not attached to those requests.
One thing is still written down, and it is worth naming. Requests reach this site through a shared entry point inside our own infrastructure, and that layer keeps its own access log of the full address of each request. So a request that carries coordinates in its own address leaves them there: a forecast or place-name lookup for a spot, and a share link opened directly. Two things it does not do: it records no visitor IP address — at that point the only address in view is our own load balancer's, not yours — and nothing from it goes to anyone outside. It is also a rotating buffer rather than an archive: old lines fall away as new ones arrive, and it is cleared whenever that part of the infrastructure restarts. Changing it would mean upgrading that shared component for everything else running behind it — not a trade worth making for a log with no identity attached to it, so it is described here instead.
The site sits behind Cloudflare
Cloudflare serves this site to you and passes requests on to our own server. That is an ordinary setup, but it has a consequence worth saying out loud: the encrypted connection from your browser ends at Cloudflare, not at our server. So Cloudflare sees every request to this site, and your IP address with it — on every visit, whether or not you type anything in. This is a property of the connection itself, not of analytics or of any add-on product.
We get nothing back from Cloudflare about you: no analytics, no per-visitor reports, no profile, and it is never handed the email-updates list. What Cloudflare records at its edge, and how long it keeps it, is governed by Cloudflare's own policies rather than ours. It is a US company, so this is the one hop we cannot describe as EU-only, even though European visitors are normally served from its European locations. Their privacy policy is the place to check what they do; we cannot make promises on their behalf.
The shareable URL is data you choose to share
The share link encodes what you are looking at, and that can include your starting location and the spot and night on screen. If you set your home address as your starting location and then share that link (e.g. in a forum post), you are choosing to share that location with whoever opens it — the same tradeoff as sharing a Google or Apple Maps pin. Nothing forces you to set a precise home address; a nearby town or a dropped pin works just as well for the "how far is this spot" job.
Your email address, if you sign up for email updates
This is the only personal data this product has ever collected, and only from people who type it in themselves.
What is collected. Your email address, and nothing else. Specifically, the whole record kept about you is:
- the email address you typed,
- whether you have confirmed it,
- when you asked,
- when you confirmed.
No IP address is stored. No name, no location, no device information, no telescope, no anything else. There is no other field, because there is no other field on the form.
Why. Occasional updates about this product, written by me personally, a few times a year at most. That is the entire purpose. Being on this list is not the same as consenting to automated email. Nothing on this site emails you automatically. If that ever changes, being on this list would only mean you hear about it — enrolling would need a fresh, separate opt-in from you at that time. Your address is never used for a newsletter platform, product marketing beyond these updates, or anything else, and it is never sold, rented, shared, or handed to anyone for their own purposes.
Legal basis. Your consent (GDPR Art. 6(1)(a)), given when you submitted the form and confirmed by the step below.
Giving it was optional. No law and no contract required you to hand over your address, and it was never a condition of using anything here. The only consequence of not giving it was that you would not get the updates.
Confirmation is required, and nothing is stored before it. Submitting the form does not put you on the list — and it does not save your address either. Until you confirm, your address exists in exactly one place: inside the confirmation link in the email we just sent you, encrypted, and nowhere else. There is no "pending" list, because there is nothing to keep a pending list in. Only when you follow that link is your address written down at all. This exists so that nobody can put your address on the list by typing it into an open form, and so we can actually show that the person who owns the mailbox agreed.
How long it is kept.
- If you never confirm, nothing was ever stored. The confirmation link stops working after 14 days, and at that point your address is gone from our side entirely — not deleted on a schedule, but never written down in the first place. Ignoring the email is enough; you do not have to do anything.
- If you confirm, it is kept until you unsubscribe or ask for it to be deleted.
- If 12 months pass with no email sent to this list, every address on it will either be asked to confirm again or deleted. A list nobody has heard from in a year is a list of people who have forgotten they signed up, and that risk is what this clause protects against.
Who it comes from. Updates are sent from [email protected], a separate
address kept for exactly this purpose; replying to one reaches the same
person, via [email protected].
How to unsubscribe or be deleted. Every email we send to the list carries an unsubscribe link. One click, no login, no account, no reason needed. It deletes your address — it does not move it to a suppression list — and it takes effect immediately. You can also just email [email protected] and ask; same result.
The confirmation email is the exception, and deliberately so: at that point you are not on any list and there is nothing to unsubscribe from, so it tells you to ignore it instead. That is genuinely all you have to do.
No automated decisions, no profiling. Your address is not used to build a profile of you, to score or categorise you, or to make any decision about you automatically. It is a list of addresses to send an email to.
Your rights. You can ask what is held about you, ask for a copy of it in a portable form, ask for it to be corrected or erased, ask us to restrict or stop what we do with it, withdraw your consent at any time, and complain to a supervisory authority (in Estonia, the Andmekaitse Inspektsioon). Since the entire record is your own email address plus the four facts listed above, "what is held about you" is a short answer. Contact: [email protected].
Who holds it. Yury Kosharovskiy — one person in Estonia (EU), not a company. He builds and runs stars.2pm.ninja, and he is the data controller for your email address: he decides what happens to it, and he is the only person who can see the list. There is no team, so "we" on this page means him. If that ever changes — if a company is formed — this section will say so.
Contact him at [email protected] — the same address as everywhere else on this page, and one he reads himself.
Where it is held, and who else touches it. Your address is stored, and the confirmation and unsubscribe emails are sent, on hosting inside the European Union (Germany) — the same hosting that runs the rest of this site. The hosting provider acts only as a processor under a data processing agreement that covers this kind of data: it stores and transmits your address on our behalf and never uses it for anything of its own. Your address is not sent outside the European Economic Area, although the provider's affiliated companies and its support contractors outside the EEA may reach it while providing technical support, under the standard contractual clauses in that agreement. A copy of those clauses is available on request at [email protected]. Your address also passes through Cloudflare in transit — when you submitted the form, and whenever you follow a confirmation or unsubscribe link — for the reason described above; the list itself lives only on that hosting. No newsletter platform, mailing-list service, or email-marketing company is involved — there isn't one, and your address is never uploaded to one.
Analytics
This site uses privacy-friendly, cookieless analytics that we run ourselves. No cookies, no persistent identifiers, no cross-site tracking, no advertising network, and no personal data. The usage data is not sent to a third-party analytics company, and the tracker is served from this site's own domain.
What it records is aggregate and categorical: that a page was viewed, and that certain things happened in a session (a starting location was set, a spot was inspected, nights were compared, a share link was created or opened). What can be recorded is restricted to fixed, closed sets of values — no coordinates, place names, search text, error text, or free text of any kind, and never an email address. The tracker is also set to drop the query string from the address of the page you are on, so the coordinates a share link carries are not part of what it collects. Your email address, if you have given one, and your analytics activity are not linked; neither can be used to look up the other.
No cookies
Nothing in this product sets a cookie. That includes the email-updates signup: it stores nothing in your browser, and nothing about it persists after you close the tab. There is no cookie banner because there is nothing to consent to.