Privacy at a glance
- SunnyDaysApp is a general-audience weather, map and outdoor-planning service.
- Precise device location is used only with permission and for features you request.
- Favorites and app preferences are stored locally on your device.
- SunnyDaysApp does not create a permanent personal location history.
- The iOS app does not request App Tracking Transparency permission or access the IDFA.
- Ad personalization and the Google publisher first-party identifier are disabled.
- The website currently uses no analytics, advertising cookies or marketing trackers.
1. Controller and contact
The person responsible for the processing described in this notice is:
Leon Loncaric
Roseggerstraße 25, Top 12
5020 Salzburg, Austria
Email: [email protected]
Telephone: +43 660 6251 481
Website: sunnydaysapp.app
SunnyDaysApp is currently operated by Leon Loncaric as an individual operator. It is not
operated by a registered company. No data protection officer has been appointed because
the current processing does not require one.
2. Data used by SunnyDaysApp
| Data |
Purpose |
Where it is handled |
| Device location and selected map points |
Show your position, find nearby places, display relevant weather/map areas and support a route you request. |
Primarily on your device. Map/tile requests reveal the viewed area to the relevant delivery provider. |
| Account and sign-in data |
Create and secure your account, sign you in, manage sessions and process account deletion. |
The SunnyDays API stores your Google provider identifier, email address, display name, verification state, account ID, hashed refresh tokens and entitlement state. Google processes the provider sign-in. |
| Reverse-geocoding coordinates |
Turn a selected coordinate into a readable city, street or place label. |
The app sends the coordinate to the SunnyDays API. The API requests the label from OpenStreetMap Nominatim and caches the response without linking it to an account, device or user IP address. |
| Map, weather and thumbnail requests |
Deliver satellite, vector, terrain, weather and place-preview content. |
SunnyDays infrastructure and the providers listed below receive IP address, request time, requested resource/tile and normal connection data. |
| Favorites, settings and consent choices |
Remember saved places, app preferences and privacy choices. |
Favorites and app settings are stored locally. Google UMP stores the consent state needed for advertising compliance. |
| Advertising and consent data |
Show non-personalized/limited ads, record consent choices, measure delivery, prevent fraud and keep ads reliable. |
Processed by Google AdMob and the Google User Messaging Platform as described in section 5. |
| Technical and security logs |
Operate the API/website, diagnose failures, prevent abuse and protect the service. |
Cloudflare, Hetzner, Bunny and SunnyDays server logs may contain IP address, timestamp, endpoint, status code and device/browser connection information. |
| Support communications |
Answer questions, investigate reported problems and handle privacy requests. |
Email content and any information you voluntarily send are handled through the published support mailbox. |
3. Location, maps, weather and routes
Location permission is optional. If granted, the app may access foreground location to
show your position, nearby outdoor places, relevant weather, and navigation or route context.
You can deny or withdraw permission in the Android or iOS settings and manually select a map
location instead, although some features may then be limited.
SunnyDaysApp does not use your location to build an advertising profile and does not maintain
a permanent personal movement history. Most interactive map and local route processing happens
on the device. If a server-based route feature is enabled and you request it, the necessary
start/end points and route options may be sent to the SunnyDays API solely to return that route.
A requested map tile represents a geographic area. Therefore, the API, CDN or imagery provider
delivering that tile can technically infer the area being viewed from the tile coordinates and
connection metadata. Weather source data from Meteoblue and DWD is collected by the SunnyDays
build system; individual user identities are not sent to those weather-data sources.
When the app needs a readable label for a location, it sends the selected coordinate to the
SunnyDays API. The API forwards that coordinate to OpenStreetMap Nominatim using the API server's
connection, not the user's direct connection. Nominatim therefore receives the requested coordinate
and server connection data, but SunnyDays does not send it your account ID, email address or device ID.
Cached provider responses are keyed by a one-way request hash and are not attached to a user profile.
4. Purposes and legal bases
- Requested app and website functions: performance of a contract or steps taken at your request (Article 6(1)(b) GDPR).
- Security, fraud prevention, essential logs and service reliability: legitimate interests in operating and protecting SunnyDaysApp (Article 6(1)(f) GDPR).
- Advertising consent and device storage where required: your consent (Article 6(1)(a) GDPR and applicable ePrivacy rules). You can withdraw it through Settings → Privacy choices.
- Answering messages and privacy requests: contract-related steps, legal obligations, or legitimate interests depending on the request.
- Required record keeping: compliance with legal obligations (Article 6(1)(c) GDPR).
5. Advertising, consent and identifiers
The free version of SunnyDaysApp uses Google AdMob. Before an ad request is permitted in a
region where consent or a privacy choice is required, the app uses Google’s User Messaging
Platform (UMP) to obtain or update that choice. Privacy choices can be opened again from the
app’s Settings screen.
SunnyDaysApp configures Google Mobile Ads for non-personalized publisher treatment and disables
Google’s publisher first-party identifier. On iOS, SunnyDaysApp does not request Apple’s App
Tracking Transparency permission and does not access the IDFA. On Android, the Google Mobile Ads
SDK may process advertising/device identifiers made available by Android or Google Play, subject
to device settings, consent signals and Google’s limited-ad behavior.
Google states that its Mobile Ads SDK may automatically process IP address (which can indicate
approximate location), ad and product interactions, diagnostic/performance information, and
device or account-related identifiers for advertising, analytics and fraud prevention. Even a
non-personalized or limited ad still requires technical delivery and anti-fraud processing.
6. Local storage, diagnostics and accounts
Favorites, app preferences, cached map/weather content and temporary route state may be stored
on your device. You can remove this information through app controls where available, by clearing
app storage, or by uninstalling the app. Locally stored diagnostics are disabled in the normal
production configuration and are not sent to an external analytics or crash-reporting provider.
Google account sign-in is available where enabled in the distributed app. Google provides a verified
provider identifier, email address, display name and verification claims to the SunnyDays API. The API
stores the account, entitlement state and hashed refresh-session records in PostgreSQL. Apple sign-in,
cloud synchronization and paid subscriptions are not active features at the date of this notice.
7. Website and communications
The SunnyDays website currently has no analytics service, advertising pixels, marketing cookies,
account portal or contact form. The web server and its infrastructure providers process ordinary
connection/security logs to deliver and protect the site. If you contact SunnyDays by email, the
message, your email address and any information you include are used to answer and document the request.
8. Providers, recipients and transfers
| Provider | Role in SunnyDaysApp |
| Hetzner | API, database and object-storage infrastructure in Germany/EU. |
| Bunny | Content delivery for map, weather and thumbnail assets. |
| Cloudflare | DNS, proxy, security and delivery protection for the public API/domain. |
| Google AdMob / UMP | Advertising, consent choices, measurement, diagnostics and fraud prevention. |
| OpenStreetMap Foundation / Nominatim | Reverse geocoding requested coordinates into readable place labels through the cached SunnyDays API proxy. |
| Esri ArcGIS Location Platform | Online World Imagery satellite tiles; requests disclose connection data and the viewed tile area to Esri. |
| Apple and Google | App distribution, platform permissions/settings and store-provided diagnostics under their own terms. |
Some providers may process data outside the EEA. Depending on the provider and destination,
transfers rely on an adequacy decision, the EU Standard Contractual Clauses, or another lawful
safeguard. Provider privacy information is available below.
9. Retention
- Local app data: until you delete it, clear app storage or uninstall the app.
- Consent records: until withdrawn, reset, no longer required, or renewed under applicable consent rules.
- Accounts: until you request deletion. The account is disabled and sessions are revoked immediately; primary account data is permanently purged after 30 days. Only a non-identifying purge receipt and anonymized audit event type/timestamp may remain.
- Reverse-geocoding cache: provider responses are normally fresh for 30 days and may be retained for up to a further 90 days for resilient service before automatic removal; they are not linked to an account.
- Technical/security logs: only for the rolling period reasonably needed for operations, abuse prevention, incident investigation and legal claims.
- Support and privacy correspondence: until the request is resolved and thereafter only as needed for evidence, legal duties or limitation periods.
- Backups: removed through the normal backup rotation after the corresponding live record is deleted.
Data may be retained longer when required by law, a legal claim, fraud/security investigation or an enforceable authority request.
10. Your rights
Subject to the conditions in the GDPR, you may request access, correction, deletion, restriction,
portability, or object to processing. Where processing is based on consent, you may withdraw that
consent at any time without affecting processing that was lawful before withdrawal. You may also
lodge a complaint with the Austrian Data Protection Authority.
11. Children and families
SunnyDaysApp is a general-audience weather and map service that can be useful to individuals and
families; it is not designed or marketed primarily as a children’s service. The app does not ask
for a date of birth. Parents and guardians should supervise a child’s use of location, maps,
account sign-in, external links and advertising. If SunnyDays becomes
aware that personal data was collected from a child contrary to applicable law, it will be deleted
or otherwise handled as required.
12. Security, changes and contact
SunnyDaysApp uses encrypted HTTPS connections, restricted production access, protected credentials,
backups and technical safeguards appropriate to the service. No internet service can guarantee
absolute security. This notice may be updated when features, providers or legal requirements change.
Material changes will be reflected by the date at the top and, where appropriate, an in-app notice.
Questions and privacy requests: [email protected]
or +43 660 6251 481.
Datenschutz auf einen Blick
- SunnyDaysApp ist ein Wetter-, Karten- und Outdoor-Planungsdienst für ein allgemeines Publikum.
- Der genaue Gerätestandort wird nur mit Berechtigung und für von Ihnen angeforderte Funktionen verwendet.
- Favoriten und App-Einstellungen werden lokal auf Ihrem Gerät gespeichert.
- SunnyDaysApp erstellt keinen dauerhaften persönlichen Standortverlauf.
- Die iOS-App fordert keine App-Tracking-Transparency-Berechtigung an und greift nicht auf die IDFA zu.
- Personalisierte Anzeigen und die Publisher-Erstanbieter-ID von Google sind deaktiviert.
- Die Website verwendet derzeit keine Analyse-, Werbe- oder Marketing-Tracker.
1. Verantwortlicher und Kontakt
Verantwortlich für die in dieser Erklärung beschriebene Verarbeitung ist:
Leon Loncaric
Roseggerstraße 25, Top 12
5020 Salzburg, Österreich
E-Mail: [email protected]
Telefon: +43 660 6251 481
Website: sunnydaysapp.app
SunnyDaysApp wird derzeit von Leon Loncaric als Einzelperson betrieben und nicht von einer
eingetragenen Gesellschaft. Ein Datenschutzbeauftragter wurde nicht bestellt, da die derzeitige
Verarbeitung keine Bestellung erfordert.
2. Von SunnyDaysApp verwendete Daten
| Daten | Zweck | Verarbeitung |
| Gerätestandort und ausgewählte Kartenpunkte | Position anzeigen, Orte in der Nähe finden, passende Wetter-/Kartenbereiche darstellen und angeforderte Routen unterstützen. | Vorwiegend auf Ihrem Gerät. Karten-/Kachelanfragen legen dem jeweiligen Anbieter das betrachtete Gebiet offen. |
| Konto- und Anmeldedaten | Konto erstellen und schützen, Anmeldung, Sitzungsverwaltung und Kontolöschung. | Die SunnyDays-API speichert Google-Anbieterkennung, E-Mail-Adresse, Anzeigenamen, Verifizierungsstatus, Konto-ID, gehashte Aktualisierungstoken und Berechtigungsstatus. Google verarbeitet die Anbieteranmeldung. |
| Koordinaten für Rückwärtsgeokodierung | Eine ausgewählte Koordinate in eine lesbare Stadt-, Straßen- oder Ortsbezeichnung umwandeln. | Die App sendet die Koordinate an die SunnyDays-API. Die API fragt OpenStreetMap Nominatim ab und speichert die Antwort zwischen, ohne sie mit Konto, Gerät oder Nutzer-IP-Adresse zu verknüpfen. |
| Karten-, Wetter- und Vorschaubildanfragen | Satelliten-, Vektor-, Gelände-, Wetter- und Ortsvorschauinhalte bereitstellen. | SunnyDays-Infrastruktur und die unten genannten Anbieter erhalten IP-Adresse, Anfragezeit, angeforderte Ressource/Kachel und übliche Verbindungsdaten. |
| Favoriten, Einstellungen und Einwilligungen | Gespeicherte Orte, App-Einstellungen und Datenschutzentscheidungen merken. | Favoriten und Einstellungen werden lokal gespeichert. Google UMP speichert den für Werbung erforderlichen Einwilligungsstatus. |
| Werbe- und Einwilligungsdaten | Nicht personalisierte/eingeschränkte Anzeigen, Einwilligungsverwaltung, Auslieferungsmessung, Betrugsprävention und Zuverlässigkeit. | Google AdMob und Google User Messaging Platform gemäß Abschnitt 5. |
| Technische und Sicherheitsprotokolle | API/Website betreiben, Fehler untersuchen, Missbrauch verhindern und den Dienst schützen. | Protokolle bei Cloudflare, Hetzner, Bunny und SunnyDays können IP-Adresse, Zeitstempel, Endpunkt, Statuscode und Geräte-/Browser-Verbindungsdaten enthalten. |
| Support-Kommunikation | Fragen beantworten, gemeldete Probleme untersuchen und Datenschutzanfragen bearbeiten. | E-Mail-Inhalt und freiwillig übermittelte Informationen werden über das veröffentlichte Support-Postfach bearbeitet. |
3. Standort, Karten, Wetter und Routen
Die Standortberechtigung ist freiwillig. Bei Erteilung kann die App den Standort im Vordergrund
verwenden, um Ihre Position, Orte in der Nähe, relevantes Wetter sowie Navigations- oder
Routenkontext anzuzeigen. Sie können die Berechtigung in Android oder iOS verweigern bzw. widerrufen
und stattdessen einen Kartenpunkt manuell wählen; einige Funktionen können dann eingeschränkt sein.
SunnyDaysApp verwendet Ihren Standort nicht zur Erstellung eines Werbeprofils und führt keinen
dauerhaften persönlichen Bewegungsverlauf. Die meisten Karten- und lokalen Routenberechnungen
erfolgen auf dem Gerät. Wird eine serverbasierte Routenfunktion aktiviert und von Ihnen genutzt,
können die erforderlichen Start-/Zielpunkte und Optionen ausschließlich zur Rückgabe dieser Route
an die SunnyDays-API gesendet werden.
Eine Kartenkachel entspricht einem geografischen Gebiet. API, CDN oder Bildanbieter können daher
anhand der Kachelkoordinaten und Verbindungsdaten technisch erkennen, welches Gebiet betrachtet wird.
Wetterquellen von Meteoblue und DWD werden vom SunnyDays-Buildsystem abgerufen; einzelne
Nutzeridentitäten werden nicht an diese Wetterdatenquellen übermittelt.
Benötigt die App eine lesbare Bezeichnung für einen Ort, sendet sie die ausgewählte Koordinate an
die SunnyDays-API. Die API leitet die Koordinate über die Serververbindung an OpenStreetMap Nominatim
weiter, nicht über die direkte Verbindung des Nutzers. Nominatim erhält daher Koordinate und
Serververbindungsdaten, aber keine Konto-ID, E-Mail-Adresse oder Geräte-ID. Zwischengespeicherte
Anbieterantworten verwenden einen Einweg-Hash der Anfrage und werden keinem Nutzerprofil zugeordnet.
4. Zwecke und Rechtsgrundlagen
- Angeforderte App- und Website-Funktionen: Vertragserfüllung bzw. vorvertragliche Maßnahmen auf Ihre Anfrage (Art. 6 Abs. 1 lit. b DSGVO).
- Sicherheit, Betrugsprävention, erforderliche Protokolle und Zuverlässigkeit: berechtigte Interessen am sicheren Betrieb von SunnyDaysApp (Art. 6 Abs. 1 lit. f DSGVO).
- Werbeeinwilligung und Gerätespeicherung, soweit erforderlich: Ihre Einwilligung (Art. 6 Abs. 1 lit. a DSGVO und anwendbare ePrivacy-Regeln). Widerruf über Einstellungen → Datenschutzoptionen.
- Nachrichten und Datenschutzanfragen: vertragliche Maßnahmen, rechtliche Pflichten oder berechtigte Interessen je nach Anfrage.
- Gesetzlich erforderliche Aufbewahrung: Erfüllung rechtlicher Verpflichtungen (Art. 6 Abs. 1 lit. c DSGVO).
5. Werbung, Einwilligung und Kennungen
Die kostenlose Version von SunnyDaysApp verwendet Google AdMob. Bevor in einer Region mit
Einwilligungs- oder Wahlpflicht eine Werbeanfrage zulässig ist, wird über Googles User Messaging
Platform (UMP) die erforderliche Entscheidung eingeholt oder aktualisiert. Die Datenschutzoptionen
können in den App-Einstellungen erneut geöffnet werden.
SunnyDaysApp konfiguriert Google Mobile Ads für nicht personalisierte Publisher-Behandlung und
deaktiviert Googles Publisher-Erstanbieter-ID. Unter iOS fordert SunnyDaysApp keine
App-Tracking-Transparency-Berechtigung an und greift nicht auf die IDFA zu. Unter Android kann das
Google Mobile Ads SDK von Android oder Google Play bereitgestellte Werbe-/Gerätekennungen gemäß
Geräteeinstellungen, Einwilligungssignalen und Googles eingeschränkter Anzeigenauslieferung verarbeiten.
Laut Google kann das Mobile Ads SDK automatisch IP-Adresse (mögliche ungefähre Standortbestimmung),
Anzeigen- und Produktinteraktionen, Diagnose-/Leistungsdaten sowie Geräte- oder kontobezogene Kennungen
für Werbung, Analyse und Betrugsprävention verarbeiten. Auch nicht personalisierte oder eingeschränkte
Werbung benötigt technische Auslieferungs- und Betrugspräventionsverarbeitung.
6. Lokale Speicherung, Diagnosen und Konten
Favoriten, App-Einstellungen, zwischengespeicherte Karten-/Wetterinhalte und temporärer Routenstatus
können auf Ihrem Gerät gespeichert werden. Sie können diese Daten über verfügbare App-Funktionen,
durch Löschen des App-Speichers oder durch Deinstallation entfernen. Lokale Diagnosen sind in der
normalen Produktionskonfiguration deaktiviert und werden nicht an einen externen Analyse- oder
Crash-Reporting-Anbieter gesendet.
Die Google-Kontoanmeldung ist dort verfügbar, wo sie in der verteilten App aktiviert ist. Google
übermittelt eine verifizierte Anbieterkennung, E-Mail-Adresse, Anzeigenamen und Verifizierungsangaben
an die SunnyDays-API. Die API speichert Konto, Berechtigungsstatus und gehashte Aktualisierungstoken
in PostgreSQL. Apple-Anmeldung, Cloud-Synchronisierung und kostenpflichtige Abonnements sind zum Datum
dieser Erklärung nicht aktiv.
7. Website und Kommunikation
Die SunnyDays-Website verwendet derzeit keinen Analysedienst, keine Werbepixel, Marketing-Cookies,
kein Kontoportal und kein Kontaktformular. Webserver und Infrastruktur-Anbieter verarbeiten übliche
Verbindungs-/Sicherheitsprotokolle zur Bereitstellung und zum Schutz der Website. Bei einer E-Mail
werden Nachricht, E-Mail-Adresse und freiwillige Angaben zur Beantwortung und Dokumentation verwendet.
8. Anbieter, Empfänger und Übermittlungen
| Anbieter | Rolle bei SunnyDaysApp |
| Hetzner | API-, Datenbank- und Objektspeicher-Infrastruktur in Deutschland/EU. |
| Bunny | Inhaltsauslieferung für Karten-, Wetter- und Vorschaudaten. |
| Cloudflare | DNS, Proxy, Sicherheit und Auslieferungsschutz für API und Domain. |
| Google AdMob / UMP | Werbung, Einwilligungsentscheidungen, Messung, Diagnosen und Betrugsprävention. |
| OpenStreetMap Foundation / Nominatim | Rückwärtsgeokodierung angeforderter Koordinaten in lesbare Ortsbezeichnungen über den zwischenspeichernden SunnyDays-API-Proxy. |
| Esri ArcGIS Location Platform | Online-Satellitenkacheln von World Imagery; Anfragen legen Esri Verbindungsdaten und betrachtetes Kachelgebiet offen. |
| Apple und Google | App-Vertrieb, Plattformberechtigungen/-einstellungen und Store-Diagnosen nach deren Bedingungen. |
Einige Anbieter können Daten außerhalb des EWR verarbeiten. Je nach Anbieter und Ziel beruht die
Übermittlung auf einem Angemessenheitsbeschluss, EU-Standardvertragsklauseln oder einer anderen
zulässigen Garantie. Weitere Informationen:
9. Speicherdauer
- Lokale App-Daten: bis zur Löschung, zum Löschen des App-Speichers oder zur Deinstallation.
- Einwilligungsdaten: bis zum Widerruf, Zurücksetzen, Wegfall der Erforderlichkeit oder einer notwendigen Erneuerung.
- Konten: bis zu Ihrer Löschanfrage. Das Konto wird sofort deaktiviert und alle Sitzungen werden widerrufen; die primären Kontodaten werden nach 30 Tagen endgültig gelöscht. Verbleiben können nur ein nicht personenbeziehbarer Löschbeleg sowie anonymisierte Audit-Ereignisart und Zeitstempel.
- Rückwärtsgeokodierungs-Cache: Anbieterantworten sind normalerweise 30 Tage aktuell und können für einen ausfallsicheren Betrieb bis zu weitere 90 Tage gespeichert werden, bevor sie automatisch entfernt werden; sie sind keinem Konto zugeordnet.
- Technische/Sicherheitsprotokolle: nur für den rollierenden Zeitraum, der für Betrieb, Missbrauchsprävention, Vorfalluntersuchung und Rechtsansprüche erforderlich ist.
- Support- und Datenschutzkorrespondenz: bis zur Erledigung, danach nur für Nachweise, Rechtspflichten oder Verjährungsfristen.
- Sicherungen: Entfernung im normalen Sicherungszyklus nach Löschung des entsprechenden Live-Datensatzes.
Eine längere Aufbewahrung erfolgt nur bei gesetzlicher Pflicht, Rechtsanspruch, Sicherheits-/Betrugsuntersuchung oder vollstreckbarer Behördenanordnung.
10. Ihre Rechte
Nach Maßgabe der DSGVO können Sie Auskunft, Berichtigung, Löschung, Einschränkung oder
Datenübertragbarkeit verlangen und der Verarbeitung widersprechen. Bei Einwilligung können Sie
diese jederzeit für die Zukunft widerrufen. Sie können außerdem Beschwerde bei der österreichischen
Datenschutzbehörde erheben.
11. Kinder und Familien
SunnyDaysApp ist ein Wetter- und Kartendienst für ein allgemeines Publikum, der für Einzelpersonen
und Familien nützlich sein kann; er ist nicht hauptsächlich als Kinderdienst gestaltet oder beworben.
Die App fragt kein Geburtsdatum ab. Eltern und Erziehungsberechtigte sollten die Nutzung von Standort,
Karten, Kontoanmeldung, externen Links und Werbung begleiten.
Werden entgegen anwendbarem Recht erhobene Daten eines Kindes bekannt, werden sie gelöscht oder
entsprechend den gesetzlichen Vorgaben behandelt.
12. Sicherheit, Änderungen und Kontakt
SunnyDaysApp verwendet verschlüsselte HTTPS-Verbindungen, eingeschränkte Produktionszugriffe,
geschützte Zugangsdaten, Sicherungen und angemessene technische Schutzmaßnahmen. Kein Internetdienst
kann absolute Sicherheit garantieren. Änderungen an Funktionen, Anbietern oder Rechtslage können eine
Aktualisierung bewirken. Wesentliche Änderungen werden durch das Datum oben und gegebenenfalls in der
App mitgeteilt.
Fragen und Datenschutzanfragen: [email protected]
oder +43 660 6251 481.