Legal
Privacy & disclaimer
Last updated 8 August 2026
The short version: no accounts, no data for sale, and — unless you turn on background push alerts — everything about you stays on your own device. Here's the full picture — what this app's guidance does and doesn't mean, and exactly what happens to your data.
Disclaimer
Not medical advice
UV Index gives general, population-level sun-safety guidance drawn from public health sources (WHO, the American Academy of Dermatology) and forecast data. It is not medical advice and isn't a substitute for a doctor or dermatologist. Burn-time estimates, reapplication timers, and skin-type guidance are approximations built from published dermatological research, not a personalized risk assessment. If you have a history of skin cancer, take photosensitizing medication, or have a skin condition, follow your clinician's guidance over this app's.
Data accuracy
The UV index shown is a forecast from MET Norway's public weather model, not a direct sensor reading at your exact location. Like any forecast, it can be wrong — cloud cover shifts faster than models update, and local conditions (haze, altitude, nearby reflective surfaces) aren't always captured. Treat it as a strong guide, not a guarantee, and trust your own judgement — or an official local warning — over the app if conditions look different.
No liability
This is an independent, open-source project, provided as-is and without warranty of any kind. To the fullest extent permitted by law, its author is not liable for sunburn, other harm, or any damages arising from reliance on the information it provides. Use your own judgement outdoors.
Who's behind this
UV Index is an independent project built and run by Raffaele Pizzari — no company, no data broker, no third party involved beyond the handful of services listed below, each doing exactly one job. For anything privacy-related — questions, requests, or just something that looks off — email:
[email protected]What we collect, and why
This is the actual GDPR detail: what data moves, where, on what legal basis, and for how long.
Location (GPS or a searched place)
When you allow location access or search for a place, your coordinates are sent to our server just long enough to ask MET Norway (for the UV reading), Open-Meteo Air Quality (for current air quality), and, for search, Open-Meteo or BigDataCloud — then discarded. We don't write it to a database or attach it to any identity. It's kept only on your own device, so the app can show your last reading if you reopen it offline.
Legal basis: Art. 6(1)(b) GDPR — necessary to do the specific thing you asked for.
Retention: none — it exists only for the duration of the request.
IP address
Our API routes briefly hold your IP address in memory to rate-limit requests, so the free tiers of the upstream weather APIs can't be exhausted by one visitor. It lives in server memory only, in a counter that resets every few minutes, and is never written to disk or a database.
Legal basis: Art. 6(1)(f) — legitimate interest in keeping the service available and within its providers' usage limits.
Retention: minutes, then automatically discarded.
Profile info you enter (name, skin type, infant toggle)
Stored entirely in your browser's local storage. It never leaves your device — there's no server-side database for it, so we couldn't see it, export it, or lose it in a breach even if we wanted to. Clearing your browser data deletes it for good.
Legal basis: not applicable — we don't process this data at all.
Anonymous usage analytics
We use Umami, a self-hosted, cookie-free analytics tool, to see aggregate numbers — how many people use the app, which pages get read. Umami sets no cookies and no persistent identifiers, and doesn't store your IP address or anything else that identifies you individually; any country-level stat it derives from IP is computed on the fly, and the address itself is discarded.
Legal basis: Art. 6(1)(f) — legitimate interest in basic, non-identifying usage statistics, using a tool chosen specifically because it doesn't need to track anyone.
Retention: aggregate counts only, kept for as long as they're useful; nothing in them identifies you.
Push subscription (only if you turn on background alerts)
Turning on either background alert — high UV, or the reapply reminder — hands us a push subscription: an endpoint and two encryption keys your browser generates itself, not tied to your name or any account. For the high-UV alert, we also store the place you want watched, so a background check can compare that place's UV every 15 minutes and send an alert on the rise past the threshold. For the reapply reminder, we store the profile name you typed into the app and the one time it's due — nothing else — and delete it automatically once it's sent, cancelled, or replaced by starting the timer again.
Legal basis: Art. 6(1)(a) GDPR — your explicit consent via the toggle, on top of your browser's own permission prompt. Withdraw it any time by turning the toggle off.
Retention: the high-UV watch lasts until you turn its toggle off or your browser reports the subscription expired; a reapply reminder deletes itself automatically once it's sent (usually within 2 hours) or you cancel the timer.
Who else sees a request
Getting you a UV reading means forwarding your coordinates to whichever of these does that specific job — nobody else.
- MET Norway — the UV forecast itself.
- Open-Meteo — turning a typed place name into coordinates.
- BigDataCloud — turning GPS coordinates into a place name.
- Open-Meteo Air Quality — the same air-quality reading shown in the app, for your coordinates.
- Umami, self-hosted on our own infrastructure — anonymous usage counts.
- Your browser's own push service (e.g. Google for Chrome, Mozilla for Firefox, Apple for Safari) — delivers the alert to your device if you've turned background alerts on. They see that a notification was sent, not its contents: Web Push payloads are encrypted end-to-end with keys your browser generates itself.
None of these receive anything that identifies you personally, and we don't share data with advertisers, data brokers, or anyone else. Some may process requests on infrastructure outside the EU/EEA; where that's the case, it's on them to secure it under their own compliance obligations (e.g. standard contractual clauses).
Your rights
Because so little personal data is processed server-side, most of these are already satisfied by design — but formally, under the GDPR, you have the right to:
- Access — know what data concerning you we process (as above, that's minimal and mostly nothing).
- Rectification — correct anything inaccurate. For your locally-stored profile, that's a Settings screen away.
- Erasure — ask us to delete data we hold. There's essentially nothing server-side to delete; for local data, clearing your browser storage does it instantly.
- Restriction & objection — object to or restrict processing based on legitimate interest (the IP rate-limiting and analytics above).
- Portability — receive data you provided in a portable format, where applicable.
- Complaint — lodge one with your local data protection authority; in Italy, that's the Garante per la protezione dei dati personali (garanteprivacy.it).
To exercise any of these, email:
[email protected]Children
The app's "infant" toggle exists purely to switch its sun-safety guidance — AAP/AAD recommendations are that infants under 6 months avoid direct sun entirely rather than rely on a burn-time budget. It isn't a data-collection feature, and like the rest of profile data, it's stored on-device only. We don't knowingly collect personal data from children beyond what any visitor's device already handles locally.
Changes to this page
If what this app collects or how it's used changes, this page changes with it — dated at the top, no silent rewrites of history since the source is public.
Contact
Questions, requests, or just something that looks wrong — email: