Privacy policy

What data we collect

SolarStormAlert has no accounts, email addresses, passwords, or payment data. When you visit the dashboard, the server issues an anonymous, opaque session token. No personally identifiable information is collected at any point.

Session token

A 256-bit cryptographically random token is generated server-side on your first visit and transmitted to your browser as an HttpOnly, Secure, SameSite=Strict cookie named ssa_session. The token is stored as a SHA-256 hash — the raw token is never persisted. The session has no expiry. Clearing your browser cookies removes it.

The session token carries no personal data. It is used solely to gate access to the dashboard API and to enable future server-side revocation if required. The raw token value is never logged, emailed, or shared with any third party.

Analytics

This site uses PostHog EU analytics, loaded only after consent, with data processed in the EU. No personally identifiable information is collected. Do Not Track is honored — if your browser sends DNT:1, no analytics are loaded.

If you decline analytics, no PostHog library is loaded and no analytics requests are made. Your choice is stored in your browser's localStorage under the key ph_consent so the consent banner does not reappear on return visits.

Cookies in use

Sub-processors

We use the following third-party processors:

  • PostHog (PostHog Inc., EU Cloud) — consent-gated analytics. Data is processed in the EU; see the Analytics section above.
  • Resend (Plus Five Five, Inc., San Francisco, USA) — transactional email delivery for the email-alerts feature, currently in preparation. When you subscribe to alerts, Resend processes your email address and the message content in the United States. This processing is governed by a signed Data Processing Agreement incorporating the EU Standard Contractual Clauses; Resend is certified under the EU-U.S. Data Privacy Framework. Alert emails are sent from the isolated subdomain alerts.solarstormalert.com. Subscriber data held by Resend is deleted within 90 days of account termination.

Your rights

Under GDPR and applicable data-protection law you have the right to access, rectify, erase, restrict, or object to processing of personal data, and the right to data portability. Given the anonymous model — no account, no email, no name — there is typically no personal data linked to a real-world identity. Your session token is opaque and non-identifying.

To exercise any of these rights, email [email protected].

Data export and deletion

To request export or deletion of any data associated with your session, email [email protected]. Because the session token is anonymous and hashed at rest, there is typically little to export. You can also delete your session immediately by clearing the ssa_session cookie in your browser settings.

Data controller

SolarStormAlert (Lars Meier)
[email protected]

Policy last updated

2026-07-27