Privacy Policy
Last updated: 24 Jul 2026
This is an English translation for your convenience. The German version at vfrwetter.com/privacy.html is the legally binding text.
Protecting your personal data matters to us. This app processes personal data only to the extent required to provide the requested functionality. There are no user accounts, no advertising, and no tracking or analytics services. VFR Wetter consists of the Android app and a dedicated backend service (Cloud Run) that secures and forwards key-protected weather requests on the app's behalf.
Controller
See Legal Notice.
What data is processed?
- Location data (GPS or network location): to determine location-based weather and flight-weather data and to center the map.
- ICAO codes or selected airports: to query METAR, TAF and airport information.
- Map viewport and zoom level: to load the required map and weather data.
- Favorites, recently used airports and language setting: solely for the convenient use of the app.
- Device integrity attestation (Play Integrity/Firebase App Check): to secure backend requests against abuse, see below.
- Purchase status or Play purchase token: to verify an active VFR Wetter Pro subscription, see "Subscription and payment".
Purpose and legal basis
Processing occurs exclusively to provide the app functions you have requested and to provide the subscription. The legal basis is Art. 6(1)(b) GDPR (performance of a contract, including for the subscription) and Art. 6(1)(f) GDPR based on our legitimate interest in a technically functional, abuse-protected and secure app.
Recipients and third parties
Our own backend service (Cloud Run): For OpenWeatherMap, AVWX, EUMETView (EUMETSAT satellite imagery), MeteoGate/EUMETNET OPERA (Europe-wide radar precipitation rates), the Deutscher Wetterdienst (DWD) precipitation radar and lightning map tiles, as well as all Open-Meteo requests (forecast, ICON upper winds, air quality, marine, and – depending on location – the high-resolution regional models KNMI/DMI HARMONIE, Météo-France/GeoSphere AROME, MeteoSwiss ICON-CH1/CH2 and ItaliaMeteo ICON-2I), the request first passes through our own backend service operated on Google Cloud before reaching the respective provider. MeteoAlarm (Europe-wide official weather warnings as a fallback when no DWD warning is available) also runs through this backend service, as do – depending on location – current official ground observations from GeoSphere Austria (Austria), MeteoSwiss SwissMetNet (Switzerland), ARSO (Slovenia), DMI (Denmark), DHMZ (Croatia), KMI/IRM (Belgium), KNMI (Netherlands), Météo-France (France), AEMET (Spain), SMHI (Sweden), FMI (Finland), MET Norway Frost (Norway) and the Met Office (United Kingdom). This transmits location or coordinate data as well as the request parameters. The service does not store permanent user profiles, only holding responses briefly in an in-memory cache.
Directly called services: The following providers are queried directly from the app without going through our own backend service:
- Bright Sky – DWD-adjacent current observations, short-term forecast and official DWD weather warnings for the location
- Aviation Weather Center (NOAA, AviationWeather.gov) – METAR/TAF fallback
- OurAirports – airport master data (~19,000 airports, mostly offline from the app's database)
- MapTiler / CARTO / OpenStreetMap – map tiles for the radar map
Other services:
- Google Play Services – location determination
- Firebase App Check / Google Play Integrity – device and app integrity verification for backend requests
- Google Play Billing – subscription handling and purchase-status verification
Some of these services may process personal data on servers outside the European Union, in particular in the USA. The respective providers' own privacy terms apply.
Local storage
Favorites, recently used airports, language setting, offline weather cache and app settings are stored locally on your device. The most recently verified subscription status is held locally for a maximum of 24 hours as an offline grace period; after that, the app re-checks the purchase status against Google Play. This data is not transmitted to the app provider and can be removed at any time by clearing the app's data or uninstalling the app.
Optionally, and disabled by default, you can enable change notifications per favorite. When this feature is switched on, the app uses Android's own WorkManager to check the weather at your favorites in the background at sparing intervals – via the same weather services already listed above. No additional recipients are contacted; the feature can be switched off again at any time in the app.
Route evaluations are additionally stored locally as an offline package for a maximum of 7 days so they remain available without a connection. The shareable briefing PDF is generated locally exclusively from data already loaded, and is only passed to an app of your choice, under your control, if you actively use the share function.
Permissions
- Location (precise or approximate): for location-based weather queries. Without granting it, ICAO search remains usable.
- Internet and network access: to fetch weather, map and airport data and to communicate with our own backend service.
Device integrity (Firebase App Check)
So that the backend service cannot be misused by other apps or automated requests, the app verifies a device/app integrity token via Firebase App Check (based on Google Play Integrity) with every key-protected request. This transmits device and app signals to Google; no profiling for advertising purposes takes place. Without a valid token, the backend service rejects the request.
Subscription and payment (Google Play Billing)
VFR Wetter is a subscription app with a seven-day free trial. Afterwards, the "VFR Wetter Pro" subscription continues via Google Play Billing unless cancelled beforehand. The app checks the purchase status against Google Play on every launch and whenever you return to the app; a locally verified state is valid for at most 24 hours as an offline grace period. For server-side verification, the app transmits the Google Play purchase token to our own backend service, which verifies it against the actual subscription status via the Android Publisher API. Payment data (e.g. payment method, billing address) runs exclusively through Google Play; neither the app nor the backend service receives or stores this payment data.
Your rights
You have the rights under Art. 15 to 21 GDPR, in particular to access, rectification, erasure, restriction of processing and objection. The app provider itself does not store any permanent personal user profiles server-side; these rights therefore primarily concern the third-party providers used (including Google Play Billing) and the data stored locally on your device.
If you have questions about privacy, you can reach out anytime to the contact listed in the Legal Notice.