Aurora ExplorerContact us ↗Norsk

AURORA EXPLORER

Privacy policy

Privacy policy for the Aurora Explorer app and Aurora Developer website. Updated 28 September 2026. Applies to production version 1.3.0 and later versions with the same data practices.

Controller and contact

A Steinhaug (Norwegian organisation number 938 460 035) is the controller for Aurora Explorer. Aurora Developer is the public-facing name. Send privacy questions and requests to kontakt@auroradeveloper.no.

Audience

Aurora Explorer is intended for adults and young people seeking places to view the northern lights. It is not specifically directed at children.

Location and place selection

When you grant location permission and ask the app to find the nearest place, the app calculates distances to registered aurora places on your phone. If a curated place is within 50 km, it selects that place without sending your GPS coordinates as part of that selection. Otherwise, the app may send the coordinates to our backend to calculate weather, light and aurora conditions for “My location”. Ordinary lookups are not stored in the custom followed-place table or weather history, but the web server access log may contain the requested address and coordinates as described below.

Place searches in the Android app go to our backend, which first searches a local database of place names from the Norwegian Mapping Authority. If there are no local matches, the search text may be forwarded to that authority's place-name service. When you open a result, its name and coordinates are sent to our backend to calculate local conditions. If you follow a searched place or “My location”, the backend stores its name and the centre of an approximate 5 km geographic cell to calculate alerts. The place remains active for alert calculations for 60 days after the last follow request. This is a shared place record, not a list of the users following it. Expiry of the active period does not mean physical deletion; the place record itself currently has no fixed deletion deadline. The map tile provider receives requests for the area displayed on the map and can therefore see which geographic area is being viewed.

Usage data and service operation

Usage statistics are optional and off by default in the production version, including for existing installations. If you enable them in Settings, the app creates a random installation ID and sends it with some API requests. The server stores the ID and the times of first and latest contact to count participating installations. You can turn this off at any time. New reporting stops, though requests already sent may finish. Turning it off queues a deletion request. After successful delivery, the record is deleted from the active database. If offline, the app retries while it runs and at the next launch. Uninstalling before delivery may remove the queue; the regular 90-day cleanup then applies. A hash of the deleted ID is kept to prevent delayed requests from recreating the record; this suppression list currently has no fixed expiry. Database backups may retain earlier records for up to 14 days. Older app versions may continue to send an ID automatically until updated. This is a pseudonymous identifier, not necessarily anonymous data. No user account is required.

Server access logs may contain IP address, time, requested address, client information and response status. We use these for operation, troubleshooting and security. The backend and active database are hosted with Hetzner in Finland. Administrative access is restricted.

A cleanup job deletes installation records when the last contact is more than 90 days old. Backend data-collection logs are deleted after 30 days; these are separate from web server access logs. Nginx is configured for daily log rotation and retains 14 rotated files as well as the active log. Empty logs are not rotated, so under low traffic older files may remain longer than 14 days, assuming the scheduled rotation runs normally. Configured database backups are retained for 14 days. We no longer create new manual database copies on a PC; existing manual copies are scheduled to be deleted no later than 14 days after creation.

Push notifications

You can follow multiple places and control Android notifications separately. We use Google's Firebase Cloud Messaging (FCM) for delivery. FCM processes installation identifiers and message tokens. Subscriptions connect an app installation to the places you follow. Automatic FCM registration is off by default and activates when you follow places. Followed-place choices are also stored on your phone. For a searched place, our backend stores its name and an approximate 5 km cell. The place remains active for alert calculations for 60 days after the last follow request, with retention as described under “Location and place selection”. The exact selected coordinate is not used in this notification table.

You can remove followed places in the app or turn off notifications in Android. Turning off their display in Android does not itself delete Firebase data. When no places are followed, the app requests deletion of its FCM token and Firebase installation ID, retrying after network errors. According to Firebase, the installation ID remains until an API deletion request is made; removal from live systems and backups can take up to 180 days after that request. The active period for a custom place cell on our backend expires even if the app is uninstalled or the place is unfollowed.

Ads, consent and affiliate links

The production version of Aurora Explorer displays Google AdMob ads. Development and test builds may use test ads. Both test and production ads involve contact with Google. Ads may not appear if your privacy choices or ad availability do not permit them.

The Google Mobile Ads SDK may process IP address, advertising and other device identifiers, ad interactions and diagnostic data for advertising, analytics and fraud prevention. IP address may be used to estimate approximate location. The app uses Google's User Messaging Platform (UMP) to obtain and manage privacy choices where required. The ad SDK is initialised after UMP permits ad requests.

Where privacy choices are required, you can reopen them in Settings. You can refuse consent to personalised advertising. Which ads, if any, may appear without such consent depends on Google's configuration and permitted purposes.

The app and website may show clearly labelled affiliate links. If you choose to open one, you leave our service for the partner's website. The partner then receives ordinary web information such as your IP address and referral information, including any tracking parameters in the link. We may earn a commission if you book. The partner is responsible for its subsequent processing after you leave our service.

Maps and other external services

Map tiles are loaded from OpenStreetMap. In the Android app, the Leaflet map library is loaded from unpkg. These services may receive your IP address and other information carried by web requests. Weather and aurora data reach the app through our backend; map and advertising services are separate external connections.

In the password-protected Web Lite version, Leaflet is served locally. OpenStreetMap tiles load when you open the map. If you search for a place name on that map, your browser sends the query directly to the Norwegian Mapping Authority's place-name service; it may receive the search text and your IP address. Forecasts are loaded through a read-only connection to our backend. Web Lite does not offer following places.

When you choose directions, Google Maps or another map app opens. The destination coordinates are passed to the selected service. Your current location, if used, is then handled according to that map app’s own permissions and privacy terms; Aurora Explorer does not start navigation or background tracking on its own.

Website and email

The public homepage at auroraexplorer.no (also available at auroradeveloper.no) uses locally stored images and stylesheets and has no separate analytics or advertising SDK. It may show labelled affiliate links as described above. Web Lite requires HTTP Basic authentication and does not use a user account with us; your browser may remember the login during the session. Visits to our pages may be recorded in server access logs as described above. If you email us, we process your address and message to respond. Do not send passwords or sensitive information. We delete correspondence no later than 12 months after a matter is closed. Material needed for legal obligations or specific legal claims may be kept longer for as long as necessary.

Local storage

The app stores choices such as language, selected places, coordinates of followed searched places, notification settings, cached data and images on your phone. You can remove local app data through Android settings. This does not automatically delete server logs or data processed by other providers. Some settings may be included in Android backups.

The public site stores your language choice in your browser's local storage (aurora-language); Web Lite may store its own language choice (aurora-web-language). These are device settings, not analytics or advertising cookies. You can remove them through your browser settings.

Legal bases and your rights

Optional usage statistics rely on the consent you give when enabling them; you can withdraw it in Settings without losing other app functions. Necessary operation and security, responses to enquiries and the suppression record preventing deleted statistics from being recreated rely on legitimate interests under GDPR Article 6(1)(f). Our interests are providing and protecting the service, helping users and respecting deletion choices. Optional notifications, place searches and location use rely on consent under Article 6(1)(a); withdraw it by unfollowing places or removing location permission. Withdrawal does not affect processing that was lawful before it. Consent is used where required for advertising and can be withdrawn for future processing.

You can contact us to request access, correction, deletion, restriction and other applicable rights. You can object where processing relies on legitimate interests. We may need enough information to find data associated with your installation, but will not request more than necessary. You can complain to the Norwegian Data Protection Authority (Datatilsynet).

Google and map providers may process data outside the EEA. Google describes use of the EU-US Data Privacy Framework for covered US recipients and standard contractual clauses where needed. Section 10 of the Firebase terms governs transfers of customer data, including standard contractual clauses where applicable. OpenStreetMap delivers tiles through a global network and unpkg uses Cloudflare, so processing locations may vary. Provider information and transfer details are linked below. Contact us for information about safeguards and copies of applicable terms. See Google's transfer information.

Information about services

Additional provider information

← Back to the homepage