Privacy Policy

Last updated: April 2, 2026

1. Introduction

This Privacy Policy describes how Foxxception LLC (β€œwe,” β€œus,” or β€œour”) collects, uses, and protects information when you use the WeatherLens API and website at weatherlens.dev (the β€œService”).

2. Information We Collect

Account Information

When you create an account, we collect your email address and a password (stored as a bcrypt hash β€” we never store your plaintext password).

API Usage Data

We log API requests to enforce rate limits and provide usage statistics. Logs include: timestamp, API key identifier, endpoint called, and the coordinates queried. We do not log your IP address in API usage records.

Payment Information

Payments are processed by Stripe. We do not store your credit card number, expiration date, or CVC. We receive only a Stripe customer ID and subscription status.

Automatically Collected Data

When you visit our website, our hosting provider (Vercel) may collect standard web server logs including IP address, browser type, and pages visited. We do not use third-party analytics or tracking scripts.

3. How We Use Your Information

  • Provide the Service β€” Authenticate requests, enforce rate limits, deliver weather data.
  • Billing β€” Process payments, manage subscriptions, send invoices via Stripe.
  • Service communications β€” Send account-related emails (password resets, billing receipts, terms updates).
  • Improve the Service β€” Analyze aggregate usage patterns to improve API performance and reliability.

We do not sell, rent, or share your personal information with third parties for marketing purposes. We will never send you marketing emails.

4. Data Retention

  • Account data β€” Retained while your account is active. Deleted upon request.
  • API usage logs β€” Retained for up to 90 days for usage statistics, then aggregated and anonymized.
  • Payment records β€” Retained as required by applicable tax and financial regulations.

5. Data Security

We protect your data using industry-standard measures:

  • All connections are encrypted via TLS (HTTPS).
  • API keys are stored as SHA-256 hashes β€” the plaintext key is shown only once at creation.
  • Passwords are hashed with bcrypt.
  • Database connections use SSL.
  • Environment secrets are stored in Vercel's encrypted environment variable system.

6. Cookies

We use a single session cookie (wl_session) for authentication when you log in to the dashboard. This cookie is HttpOnly, SameSite=Lax, and contains only a session identifier. We do not use tracking cookies, advertising cookies, or third-party cookies.

7. Third-Party Services

ServicePurposePrivacy Policy
StripePayment processingstripe.com/privacy
VercelWebsite hostingvercel.com/legal/privacy-policy
NeonDatabase hostingneon.tech/privacy

8. Your Rights

You have the right to:

  • Access your account data and usage statistics via the dashboard or API.
  • Correct your account information at any time.
  • Delete your account and associated data by contacting us.
  • Export your usage data via the /usage API endpoint.

To exercise any of these rights, email support@foxxception.com.

9. Children's Privacy

The Service is not directed to individuals under the age of 13. We do not knowingly collect personal information from children. If you believe we have collected data from a child, contact us immediately.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or a prominent notice on the website. Continued use of the Service after changes constitutes acceptance.

11. Contact

For privacy-related inquiries: legal@foxxception.com

For general support: support@foxxception.com

Foxxception LLC β€” www.foxxception.com