Privacy Policy

Effective October 1, 2026 · v2.1

The short version

  • Layer Weather is a weather and outfit app from Monsoro, LLC.
  • We collect an account, location, content you create, subscription status, a push token if you allow notifications, and optional usage events. Each category below says why.
  • We do not sell personal information, and we do not share it for cross-context behavioral advertising.
  • Delete your account in Settings → Danger zone → Delete account, or email support@monsoro.co.
  • Layer Weather is a general-audience app and is not directed to children under 13.

Layer Weather is published by Monsoro, LLC, a South Carolina limited liability company and the parent holding company. This Privacy Policy explains what personal data we collect, how we use it, and your rights regarding it.

1. Information We Collect

Each category below matches how the apps use the data and how the iOS privacy manifest labels it. Purposes are App Functionality unless the category says Analytics. None of these categories is used for tracking.

Email address. App Functionality. We collect the email you use to create an account, sign in, and receive account or notification email you opt into. Sign in with Apple may hide the email, in which case we receive the address Apple provides.

Name. App Functionality. We collect the display name you enter, or the name Apple or Google shares when you use those sign-in buttons.

Precise location. App Functionality. We collect coordinates so we can fetch a forecast, an outfit, and alerts for the city you are using. On iOS, a When In Use fix uses hundred-meter accuracy. Your profile stores the last latitude and longitude.

Coarse location. App Functionality. We collect the city name you type or that we resolve from a fix, and, if you turn on Always on iOS, significant location changes of about 5 kilometers at kilometer accuracy.

Product interaction. Analytics. When the Settings analytics toggle is on, we store app, paywall, outfit, and sign-in events in our database. After you sign in, an event can include your account id. You can turn this off in Settings. There is no third-party analytics SDK.

Purchase history. App Functionality. We store Layer Weather Pro subscription status for the monthly or annual plan, including whether a free trial is in effect, which store billed it, and when the current period ends. The price is the price shown by the store at purchase. This policy does not set a price. We do not collect a card number.

Device ID. App Functionality. When you allow notifications, we store an Apple Push Notification service device token on iOS, or a Firebase Cloud Messaging registration token on Android, on your profile. The token is used to deliver those notifications. It is not an advertising identifier.

Other user content. App Functionality. We store thermal calibration, wardrobe and style presets, commute times, outfit feedback, packing lists, and notification settings that you create.

Calendar. If you opt in on iOS, the app reads today's calendar on the device to infer a style hint such as a meeting or a workout. Event titles and details are not sent to our servers, and calendar is not a collected data type. Android does not read the device calendar.

Crash diagnostics. On iOS, MetricKit writes crash and hang reports on the device. The app does not upload them, and crash data is not a collected data type. There is no third-party crash-reporting SDK.

2. Location

The one free city may be your phone's location or a city you type. Additional saved cities are a Pro feature.

iOS asks for When In Use location to fetch weather and outfit recommendations. Foreground fixes use hundred-meter accuracy, which is precise enough to identify a neighborhood. If you turn on Always in Settings, the app can also watch for significant location changes of about 5 kilometers so weather can refresh after you travel. That monitor uses kilometer accuracy. Continuous background GPS is off: the iOS app does not declare the location background mode, and background location updates stay off unless that mode is present.

Android asks for fine, coarse, and background location. The fix it requests uses balanced-power accuracy, on the order of a city block. That call is a current-location read. The Android app does not register an ongoing background location update, even though Settings can request the background permission.

Widgets, Apple Watch complications, and Live Activities do not take a new GPS fix. They show a snapshot the main app already saved. On iOS that snapshot includes the city name and coordinates in the shared app group. Android home-screen widgets use the saved city name.

Your profile stores the last city, latitude, and longitude. Those coordinates refresh forecasts, weather alerts, and email digests, and they are sent to the forecast and map providers in section 4. They are removed when the profile is deleted.

3. Sale and Sharing

We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not use personal information to track you across other companies' apps or websites.

We do send some categories to the processors in section 4 so they can perform a service for us, such as a forecast, a map, email delivery, or subscription status. That service use is not a sale and is not cross-context behavioral advertising.

4. Third-Party Processors

These processors are in the current iOS app, Android app, or backend. Each has its own privacy policy. This list says what we actually send.

  • Supabase hosts authentication, the database, and edge functions. It receives your email, a password hash, display name, Apple or Google sign-in identifier, profile (city, latitude, longitude, push token, and subscription status), calibration, wardrobe, packing trips, outfit feedback, and analytics events when that toggle is on. An Apple refresh token, if we stored one, is revoked and deleted when the account is deleted.
  • Apple provides Sign in with Apple (the name and email you choose to share, and an Apple user identifier), WeatherKit (coordinates), App Store billing (the purchase), Apple Push Notification service (the device token and the notification), and MapKit (map requests for the radar, and the place name for a spot you tap on it). MetricKit diagnostics stay on the device and are not sent to Apple by us.
  • Google provides Sign in with Google (the Google Sign-In SDK on iOS, and Credential Manager with the Google Identity library on Android), which receives the Google account you pick. Google Weather, Geocoding, and Places receive a coordinate or a city query. Air Quality, Pollen, and those map tiles receive coordinates or a map tile request. Play Billing and the Google Play Developer API receive the purchase token so we can validate Pro. Firebase Cloud Messaging receives the Android registration token and the notification.
  • Open-Meteo receives coordinates for forecasts and for the air-quality API, including a pollen fallback.
  • Rainbow receives coordinates for minute-by-minute precipitation nowcasts, including a spot you tap on the radar map, and radar map tile requests relayed by our servers.
  • Vercel hosts layerweather.com and relays iOS radar map tile requests to Rainbow. Those requests identify a map tile, not your account.
  • On Android, RainViewer receives radar map tile requests. Those requests identify a map tile, not your account.
  • The National Weather Service and NOAA receive a U.S. location for forecasts and alerts. NOAA SWDI receives an area for lightning observations.
  • U.S. EPA AirNow receives a U.S. location for air-quality observations.
  • NASA FIRMS receives map tile bounds for wildfire detection on the radar map.
  • OpenFreeMap receives Android radar basemap tile requests. MapLibre draws that map on the device.
  • RevenueCat receives an app user id and the App Store or Play purchase so it can report subscription status. It does not receive your wardrobe or packing lists.
  • Resend receives the email address and the message when we send account, digest, alert, or subscription email you are set up to receive.
  • Google Gemini writes optional packing notes and share images. A packing prompt can include the destination, trip dates, the daily forecast, thermal calibration thresholds, wardrobe item names, and the packing list. A share-image prompt can include garment names, the weather condition, a feels-like temperature, style preferences, and a vibe. Those prompts do not include your account email.

If Google geocoding is unavailable, iOS falls back to Apple's on-device geocoder and Android falls back to the platform geocoder. Those fallbacks stay on the device.

Two backend functions are in the repository and are not called by the shipping apps. Google Solar is not requested (the iOS solar card returns no data). Rainbow fire detection is not requested (wildfire maps use NASA FIRMS). This version does not bill new purchases through Stripe or a website checkout.

5. Data Retention

Account data is kept until you delete the account. That includes the sign-in, profile, calibration, outfit feedback, wardrobes, and packing trips. The saved city, latitude, longitude, push token, and subscription-status fields on the profile are removed with the profile.

The iOS forecast snapshot is stored on the device and discarded after 12 hours. iOS radar tiles use the device HTTP cache. On-device crash reports stay on the phone until the system removes them or you delete the app.

Analytics events are kept after account deletion with the account id cleared. This policy does not state a purge period for those rows, for Android forecast data kept only for the app session, or for server and function logs, because those periods are not set in the product code. Subscription records held by Apple, Google, or RevenueCat after we delete the profile follow their policies. We do not set those periods.

6. Account and Data Deletion

After you sign in, you can delete the account in the app. A guest session does not show this control.

On iOS: Settings → Danger zone → Delete account, then confirm "Delete your account permanently?".

On Android: Settings → Danger zone → Delete account, then confirm Delete account. The section title is shown in capitals.

Deletion removes the sign-in immediately. Profile, calibration, outfit feedback, wardrobes, and packing trips are removed with it. If Sign in with Apple was used, we also revoke that sign-in. You can email support@monsoro.co and ask us to delete the account instead.

7. Data Security

We transmit data over HTTPS/TLS. The authentication provider stores passwords as hashes, not as plaintext. Database rules limit a signed-in account to its own rows. These are reasonable safeguards. No method of transmission or storage is perfectly secure, and we do not promise that unauthorized access will never happen.

8. Children's Privacy

Layer Weather is a general-audience app. It is not directed to children under 13 (or under 16 in the EU). We do not knowingly collect personal information from children under 13. A parent who believes a child provided personal information can contact support@monsoro.co to have it deleted.

9. Your Rights

You can update preferences in Settings, delete your account under Danger zone, or email support@monsoro.co. That email is the contact method for the requests below.

If you live in California, the CCPA and CPRA give you the right to know, delete, and correct personal information, and to opt out of the sale or sharing of personal information. Virginia, Colorado, Connecticut, and other US states with similar laws give you comparable rights to access, delete, and correct personal information, and to opt out of sale or targeted advertising. We do not sell personal information and we do not share it for cross-context behavioral advertising, so there is no sale or share to opt out of. We will not discriminate against you for exercising these rights.

We respond to a verifiable US state privacy request within 45 days. Where the statute allows an extension, we may take one further period of up to 45 days and will tell you if we do.

If the GDPR or the UK GDPR applies, you can request access, rectification, erasure, restriction, and portability, and you can object to processing. You can also complain to a supervisory authority or to the UK Information Commissioner's Office. We respond within one month. Where the law allows it, we may extend that period by up to two further months for a complex request, and we will tell you if we do.

We have not published a shorter internal response promise than those statutory clocks.

10. Changes to This Policy

We may update this policy. Material changes are noted in the app or by email, and we update the effective date and the version at the top. Continued use after the new effective date means you accept the updated policy.

11. Contact Us

Monsoro, LLC, 1726 Gold Hill Rd Unit #564, Fort Mill, SC 29708. Questions and privacy requests: support@monsoro.co