Privacy

Who is responsible

The World Radar is a personal, non-commercial project operated from Spain. Its operator is the data controller for everything described here and can be reached at [email protected]. That address reaches a person, and it is the right one for any request under this policy.

If you never sign in

This is how most people use the site, and it asks nothing of you. There is no account, no profile and nothing that follows you between visits. Three things still happen, and all three are worth stating:

The legal basis for the logs is our legitimate interest in operating and protecting the service (Article 6(1)(f) GDPR). Nothing on this path profiles you, and no decision about you is made automatically.

If you create an account

An account is optional and unlocks nothing: the map, the reading profiles, the briefings and the probability readings are the same with or without one. It exists so there is a way back in later. The legal basis is the agreement between us — you asked for an account, and this is what providing it takes (Article 6(1)(b) GDPR).

What is stored

What is not stored

The sign-in link and the session token exist in readable form only in your mailbox and in your browser. What this server keeps is a SHA-256 digest, which cannot be turned back into a working key — so a copy of the database is not a way into anyone’s account.

Signing in with Google

Google sign-in is one of two ways in and it is never required. If you use it, this is exactly what is requested and what happens to it.

Those three are the whole request. The World Radar does not ask for and cannot read Gmail, Drive, Contacts, Calendar, Photos or any other Google service. It does not request offline access and holds no refresh token, so it cannot act on your behalf at Google after you have signed in.

The data received is used for one purpose: to create your account and recognise you when you come back. It is not used for advertising, not used to build a profile, not sold, not shared with anyone, and not read by a human. If Google reports that it has not verified the address, the sign-in is refused — an unverified address would let someone claim an account that belongs to another person.

You can revoke this app’s access at any time from your Google account permissions. That disconnects Google from your account here; it does not delete the account itself, which you can do on your account page.

Cookies

Two, both strictly necessary, both created only when you sign in. A visitor who never signs in is never given a cookie by this site, which is why there is no consent banner: strictly necessary cookies do not need one, and there are no others to ask about.

What your browser fetches from elsewhere

The map is assembled in your browser from sources we do not host. Those servers necessarily see your IP address, your user-agent and which tile you asked for. We send them nothing else: no identifier, no account, no referrer — this site withholds the referring page on every cross-origin request.

The last two are different in kind: nothing is fetched from X or Telegram until you open an event that cites one of them and ask for the embed. Until you do, your browser has not spoken to them.

Who else handles data for us

These are processors: they act on our instructions, under contract, to run the service.

The server itself is a virtual machine in Germany, and the database on it is the only place account data lives. It is not copied anywhere else, and no third party is given access to it.

Where data goes

Hosting is inside the European Economic Area. Some of the services above are based outside it and may process data — chiefly an IP address, and in Resend’s case the sign-in message — in other countries, including the United States. Each relies on the transfer safeguards it publishes, which for these providers are the European Commission’s standard contractual clauses and, where they are certified, the EU–US Data Privacy Framework. Their own policies are linked above.

How long anything is kept

Your rights

You have the right to access your data, to correct it, to have it erased, to restrict or object to its processing, and to receive it in a portable form. Two of those you can exercise yourself, immediately, without asking anyone:

For anything else, write to [email protected]. If you think your data has been handled wrongly you can also complain to the Spanish supervisory authority, the Agencia Española de Protección de Datos, or to the authority where you live.

Security

Traffic is encrypted end to end, at the network edge and again between the edge and this server. Sign-in links and session tokens are stored only as SHA-256 digests. A sign-in link works once and expires in fifteen minutes, and asking for a new one kills the old. The pages that render the map connect to the database with an account that cannot write to it. The editorial tools that publish content are not reachable from the internet at all.

None of that makes a system impossible to breach, and anyone who claims otherwise about theirs is selling something. If you find a weakness here, [email protected] is the address to tell us about it.

Children

This site is not directed at children. You must be at least 14 — the age of digital consent in Spain — to create an account, or older if the country you live in sets a higher age. The map itself asks nothing of anyone, but it reports armed conflict and is not written for children.

Changes

If this policy changes, the date at the top changes with it. A change that materially affects people with an account will be stated on this page before it takes effect. The terms of service are the other half of this document and change the same way.