Privacy Policy

This Privacy Policy describes how 22 Degrees North LLC, a Wyoming limited liability company doing business as WeatherWindow.AI ("we," "us," or "our"), collects, uses, and shares information about you and your rights over it.

1. Information We Collect

When you use WeatherWindow.AI we collect and store the categories below. Most are collected only through the signed-in application; where a category applies instead to our public marketing website, it is marked as such:

What we do not collect. Except as expressly described above, WeatherWindow.AI does not collect:

2. How We Use Your Data

3. Legal Basis for Processing (GDPR Article 6)

If you are located in the European Economic Area, we process your personal data on the following legal bases:

Data / Processing ActivityLegal Basis
Account data, vessel profile, route and passage data (including a single current position you submit with an en-route briefing request), passage analysis reports and en-route briefing reports — used to provide the ServicePerformance of a contract (Art. 6(1)(b) GDPR)
Passage analysis reports and AI Input — reviewed internally to diagnose and improve AI output quality, analyze costs, and improve how the Service assembles AI requestsLegitimate interests (Art. 6(1)(f) GDPR) — improving the accuracy and safety of AI-generated analysis
Bug reports voluntarily submitted by youPerformance of a contract / legitimate interests (responding to your support request)
Waitlist / early-access email, your consent record, and the limited technical context submitted with the waitlist form (marketing website) — used to email you about the launch of the ServiceConsent (Art. 6(1)(a) GDPR) — you provide this email and affirmatively opt in by ticking the waitlist consent box; you may withdraw your consent at any time (see Section 6), which does not affect the lawfulness of processing carried out before withdrawal
IP address and interaction signals processed by our bot-protection provider to confirm that a waitlist submission comes from a human — the IP address is transmitted for this check and is not stored in the waitlist recordLegitimate interests (Art. 6(1)(f) GDPR; Recital 49) — protecting our systems and the waitlist against automated abuse, spam, and fraudulent submissions
Website analytics data collected on our public marketing website (marketing website only), including the cookies and the identifier described in Section 9 — used to measure how our marketing pages and published guides are readConsent (Art. 6(1)(a) GDPR) and Art. 5(3) ePrivacy Directive as implemented in your country; withdrawable at any time (Section 9).
IP addresses, request metadata, and rate-limit counters — rate-limiting and abuse preventionLegitimate interests (Art. 6(1)(f) GDPR; Recital 49) — preventing fraudulent account creation, denial-of-service attacks, and abuse of API rate limits. We have assessed this processing as proportionate to the risk; the 90-day retention period is necessary to identify and respond to abuse patterns that may develop over multiple weeks, a purpose recognised as a legitimate security interest under Recital 49; the data is not used for any other purpose and is not used to profile individual users.
Legal-acknowledgment records (consent-gate timestamp, IP at acceptance, User-Agent, document SHA-256 hashes, entry-path sentinel) — evidencing your informed acceptance of the disclosure modal, Terms of Service, and Privacy PolicyPerformance of a contract (Art. 6(1)(b) GDPR) and legitimate interests (Art. 6(1)(f) GDPR) — evidencing acceptance of the terms and preserving that evidence for the establishment, exercise, or defence of legal claims.
Disclosure of stored voyage data to maritime Search and Rescue authorities in a life-safety emergencyVital interests (Art. 6(1)(d) GDPR) — protecting the life of you or another person

Providing your email address and the vessel, route, and passage inputs described in Section 1 is necessary to enter into and perform our contract with you: without them we cannot create your account or generate the analyses you request. Accepting the pre-access disclosure modal and the Terms of Service, and acknowledging this Privacy Policy — together with the legal-acknowledgment record the Service creates when you do — is likewise a condition of using the Service. Every other category of information that you yourself supply under Section 1 is voluntary. Information the Service records automatically when you use it (such as the IP addresses and legal-acknowledgment records described in Section 1) is processed on the bases stated in the table above.

4. Data Storage and Security

All user data is stored with a US-based cloud database provider. Data is encrypted in transit and at rest.

The application is hosted on a US-based cloud platform. AI analysis is performed by a third-party AI provider via API. Your passage data (routes, vessel details, weather conditions) is transmitted to our AI provider to generate the analysis. Your username and email address are not transmitted to the AI provider. As set forth in Section 2 of our Terms of Service, the GO / CAUTION / NO-GO assessment (and any other assessment or recommendation label displayed by the Service) is advisory only, and the master and operator of the vessel remain solely responsible for all navigation, routing, and departure decisions. See Your Rights (Section 6) for information about your rights regarding automated processing.

Automated processing — transparency disclosure. The Service uses automated processing of weather forecasts, vessel-profile inputs, and route inputs to generate informational outputs, including a color-coded passage indicator. The logic combines third-party weather model data with vessel-profile parameters you provide. These outputs are advisory information for the vessel operator's consideration. The vessel operator is the sole decision-maker for all navigation, departure-timing, and route-selection decisions, and the Service does not make any decision concerning you. Because the Service does not make decisions concerning you, the outputs are not a decision within the meaning of Article 22 GDPR. If you have questions about the processing, contact [email protected].

Payment information. Payment card details (full card number, CVV, expiration) are transmitted directly from your browser to Stripe, our payment processor. We do not see, store, or have access to your full payment card number at any point. We receive only the billing identifiers (last four digits, card brand, billing zip code, Stripe customer ID) necessary to administer your subscription.

Scope of coordinate processing. The Service's processing of latitude and longitude coordinates is limited to the passage-planning, route-computation, and en-route briefing purposes described in Section 2. The Service does not use these coordinates to profile your residence, infer your absence from a location, identify a marina or slip you keep your vessel at, infer travel patterns beyond the individual passage analysis or en-route briefing you request, or perform any other inference outside the scope of the requested analysis or briefing. A current position captured for an en-route briefing is used to generate that briefing and, as described in Section 2, may be reviewed internally as part of the stored AI Input to verify, maintain, and improve the quality and safety of the Service's AI output; it is not used to build a track history, to monitor your passage, or to evaluate your position against any route except within the briefing you requested. If you use the optional "use my current location" button or request an en-route briefing, you may limit our use of those device-derived readings; see Section 6.

All data we hold is stored and processed in the United States. If you access WeatherWindow.AI from outside the United States, your personal data will be transferred to and processed in the United States. One exception applies, and it concerns our marketing website only: the website analytics data described in Sections 1 and 9 is processed by our analytics provider on that provider's own global infrastructure, which may include countries other than the United States. That data is subject to the transfer safeguards described in the paragraph below, and where we ask for your consent it is not collected at all unless you give it.

If you are located in the European Economic Area, United Kingdom, or Switzerland, your personal data is collected directly by us in the United States and processed there. Where we subsequently transfer your personal data to our U.S.-based sub-processors — including our cloud authentication and database provider, cloud hosting provider, AI analysis provider, transactional email provider, the two website-analytics providers described in Sections 7 and 9, and the bot-protection and marketing-website hosting providers described in Section 7 — each such sub-processor receives your personal data under one of the following transfer safeguards: (a) the sub-processor is self-certified under the EU–US Data Privacy Framework (DPF), the UK Extension to the DPF, and the Swiss–US Data Privacy Framework, as applicable, and has committed to the DPF Principles, including notice, choice, accountability for onward transfer, security, data integrity and purpose limitation, access, and recourse, enforcement, and liability — Google LLC, which provides the cookie-based website analytics described in Sections 7 and 9, receives marketing-website analytics data under this safeguard, and we identify it by name so that you can verify its certification for yourself and so that any consent you give under Section 9 is an informed one; or (b) where the sub-processor is not DPF-certified, it receives your personal data under Standard Contractual Clauses (Art. 46(2)(c) GDPR) — together with the UK International Data Transfer Addendum and the Swiss-law-adapted form of the clauses, where applicable — together with our assessment of the transfer. You may verify the DPF certification status of any DPF-certified sub-processor on the official DPF List at dataprivacyframework.gov/list. If a sub-processor's DPF certification lapses or is withdrawn, we will transition that transfer to the safeguard described in (b) and update this Policy accordingly.

5. Data Retention

6. Your Rights (GDPR / CCPA / CPRA)

You may request deletion of your stored data at any time from the Account page inside the app using the Delete All Account Data button. This deletes your vessel profile, sail configuration, route history, settings, passage analysis reports, and en-route briefing reports. Deletion of your vessel profile includes all stored vessel specifications, polar performance data, and sail configuration that WeatherWindow.AI holds in its own systems. Copies held by our AI analysis provider are subject to the contractual deletion terms described in Section 7; you do not need to make a separate request to that provider. The Delete All Account Data button deletes all stored account data but does not delete your login account. To close your account entirely you have two options. You may use the Close Account Permanently button on the same Account page, which takes effect immediately and cannot be undone: it cancels any active subscription (no refund is issued for the unused portion of the current billing period), deletes the stored data listed above, and permanently deletes your email address and authentication record from our authentication provider. Alternatively — or if you would like assistance — you may request account closure by emailing [email protected]; emailed account-closure and full-erasure requests are processed within 30 days of receipt. One category of records survives deletion and account closure: the legal-acknowledgment records described in Section 5 are retained for the period, and for the sole evidentiary purposes, stated there — for EEA, UK, and Swiss residents on the Article 17(3) basis described in Section 5; for California residents as permitted by Cal. Civ. Code §§ 1798.105(d) and 1798.145(a)(5); and for residents of other U.S. states under the analogous statutory exceptions of their state's privacy law. Where we act on a deletion or erasure request but retain these records, our response to your request will say so and will identify the exception relied upon (for California residents, as required by 11 C.C.R. § 7022(f)).

If you are located in the European Economic Area, you have rights under the GDPR including: the right of access (Article 15), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), data portability (Article 20), objection (Article 21), and rights related to automated decision-making and profiling (Article 22). Where we process your data based on legitimate interests (see the Legal Basis for Processing section), you may object to that processing by contacting us at [email protected]; we will assess your objection and respond within 30 days. You also have the right to lodge a complaint with the data protection supervisory authority in the EU member state where you live or work, or where an alleged infringement occurred. A list of EEA supervisory authorities is available from the European Data Protection Board at edpb.europa.eu. If you are located in the United Kingdom, you may also lodge a complaint with the Information Commissioner's Office at ico.org.uk.

If you are a California resident, you have rights under CCPA/CPRA including: the right to know what personal information we collect, use, disclose, and sell; the right to correct inaccurate personal information; the right to delete your personal information; the right to limit the use of sensitive personal information; and the right to opt out of the sale or sharing of your personal information (we do not sell or share your data). If you use the optional "use my current location" feature, or request an en-route briefing that captures your current position, each such device geolocation reading is sensitive personal information under Cal. Civ. Code § 1798.140(w). We use each device-location reading only for performing the services you request with it and to verify, maintain, and improve the quality and safety of the Service (Cal. Civ. Code § 1798.121(a); Cal. Code Regs. tit. 11, § 7027(m)), and for no other purpose. To limit our use of sensitive personal information or exercise any other CCPA/CPRA right, email [email protected]. We will honor verifiable requests within 45 days. You may designate an authorized agent to submit rights requests on your behalf. We will not discriminate against you for exercising any of these rights. The legal-acknowledgment records described in Section 5 survive deletion as stated in the first paragraph of this Section.

Residents of other U.S. states. If you reside in a state with a comprehensive consumer privacy law (including Virginia, Colorado, Connecticut, Texas, Oregon, Montana, Delaware, New Jersey, New Hampshire, and others as enacted), you may have rights to access, correct, delete, and obtain a portable copy of your personal data, and to opt out of targeted advertising, sale, and certain profiling (we do not engage in any of those three activities). To exercise these rights, email [email protected]. If we decline to act on your request, you may appeal our decision by replying to our response with the word "Appeal"; we will respond to your appeal within the period required by your state's law (generally 45–60 days) and, if the appeal is denied, will provide a method to contact your state Attorney General.

To exercise any of the rights described above, contact us at [email protected]. We will respond to verifiable requests within the timeframes required by applicable law (45 days for CCPA/CPRA requests, 30 days for GDPR requests, with extensions where permitted and required notice given).

The signed-in Service does not send marketing or promotional emails, and creating an account does not enroll you in any marketing list. The one exception is our pre-launch waitlist: if you asked to be notified about the launch by submitting the waitlist form on our marketing website and ticking the consent box, we will email you about the launch on the basis of that affirmative opt-in consent, as described in Sections 1 and 3. Every such email includes a one-click unsubscribe link, and you may withdraw your consent at any time — by using that link or by emailing [email protected] — which will stop the emails and, on request, delete your waitlist entry. Withdrawing consent does not affect the lawfulness of any processing carried out before withdrawal, and does not affect transactional or service-related messages necessary to operate an account you separately create. If we introduce any broader marketing or promotional email program in the future, we will again request your affirmative opt-in consent before sending such communications, and all such emails will include a one-click unsubscribe link in compliance with the CAN-SPAM Act and, where applicable, Canada's Anti-Spam Legislation (CASL).

7. Third-Party Service Providers

We do not sell your data to any third party. We do not share your data with advertising networks or data brokers. Our two website-analytics providers are engaged as our processors and service providers only, under data-processing terms that limit their use of what they receive to providing the measurement service to us, and with every setting that would let a provider use that data for its own products or services switched off; neither receives your account, vessel, route, or passage data; see Section 9.

We share your data only with the categories of service providers necessary to operate the Service. Each provider is contractually bound to process your data only as directed and to maintain appropriate security standards. All vessel, route, and passage data you enter is private to your account; WeatherWindow.AI has no user-to-user sharing features, and your data is never visible to other users.

Public weather, forecast, and geographic data sources. The Service retrieves forecast data server-side from public and commercial meteorological data sources, which may include the U.S. National Weather Service / National Hurricane Center (NHC), the Tropical Analysis and Forecast Branch (TAFB), NOAA-operated forecast models, and international weather agency forecasts. The Service also queries a public geographic place-name (reverse-geocoding) service server-side to display approximate town- or area-level names for coordinates shown in the Service — for example, to label a waypoint or an unnamed shelter; these queries transmit only the coordinates and a zoom level. These are sources of forecast and geographic data; they are not service providers acting on our behalf. They do not receive your identity, account information, IP address, or any user identifier: all such queries are made server-side by us and transmit only the coordinates and parameters needed to retrieve the requested data, without anything linking those coordinates to you.

8. Legal Process, Safety, and Emergency Disclosure

We may disclose your data — including stored voyage data such as departure position, destination, planned route, vessel profile, passage analysis reports, and en-route briefing reports — when required or permitted by law, including in response to:

Search and Rescue. At the request of the United States Coast Guard or other governmental maritime Search and Rescue (SAR) authorities in connection with a maritime emergency or distress situation involving a user or their vessel, we may share stored voyage data — including, where one exists, the most recent single position submitted with an en-route briefing request — without waiting for formal legal process. This exception applies only to governmental SAR authorities acting in an official emergency response capacity; it does not extend to private salvage companies, towing services, insurers, or other commercial maritime entities. Our willingness to cooperate with SAR authorities upon their request is a passive responsiveness to lawful emergency inquiries; it is not a representation that WeatherWindow.AI monitors users for distress, alerts SAR authorities when users may be in distress, or otherwise participates in any user's safety plan. The Service does not provide and does not monitor for distress signaling, and no user should rely on WeatherWindow.AI as any part of their safety-of-life-at-sea coverage.

Where feasible and legally permissible, we will notify you before producing your data in response to legal process (this notice commitment does not apply to emergency SAR disclosures described above).

9. Cookies and Local Storage

Two surfaces, two different answers. This Policy covers both the signed-in WeatherWindow.AI application and our public marketing website at weatherwindow.ai, and they are not instrumented in the same way. The signed-in WeatherWindow.AI application uses no third-party analytics of any kind. There is no analytics tag, no advertising cookie, no advertising network, and no third-party tracking cookie anywhere in the application; the only cookie it sets is the session cookie described immediately below. Our marketing website is measured, and since August 2026 that measurement includes a cookie-based analytics tool. Everything in this Section about cookie-based analytics concerns the marketing website only.

In the signed-in application. We use a single HttpOnly session cookie (wwai_session) to authenticate you after login. We also use your browser's localStorage to store data between sessions, including your vessel profile, passage waypoints, sail and reefing configuration, fuel settings, custom polar file, form preferences, and cached weather forecast data (which remains subject to the NOT FOR NAVIGATION labelling shown in the Service). This localStorage data is stored only on your device and is not transmitted to our servers independently of your normal use of the Service. These uses are strictly necessary to provide a service you have requested, or store a preference at your direction, so they do not require consent under the EU ePrivacy Directive and equivalent laws.

Cookieless measurement on our marketing website. Our marketing website also uses Cloudflare Web Analytics, a cookieless measurement tool that sets no cookie, never stores or reads a cookie or other identifier on your device, and reports only aggregate page-view and page-performance metrics (see Section 7); we treat it as not requiring consent under the ePrivacy Directive. It runs on every visit, is unaffected by the choice described below, and is not present in the signed-in application.

Cookie-based analytics on our marketing website. Since August 2026 our marketing website also uses Google Analytics 4, provided by Google LLC, so that we can see how our homepage and our published guides and articles are actually read — which pages people finish, which they abandon, how far down an article they get, and which links they follow. That is how we decide what to write next. Unlike the cookieless measurement above, this one does store cookies on your device and does recognise a repeat visit as a return by the same browser. It runs only on the marketing website. We do not sell or share your personal information. We do not use advertising cookies, advertising networks, remarketing, or cross-site tracking, and we have not enabled any advertising feature of our analytics provider's service. Marketing-website measurement is not connected to your account, vessel, route, or passage data, and no such measurement runs in the signed-in application. We have not enabled the settings that would allow the provider to use what it collects for its own products and services, and we do not fingerprint your device. Section 1 lists exactly what is collected, Section 7 describes the provider, and Section 4 describes how the data is protected when it leaves the country you are in.

The cookies and stored items involved.

Cookie or stored itemWhat it doesHow long it lasts
wwai_session
(signed-in application)
Keeps you signed in after login. HttpOnly, so page scripts cannot read it. Strictly necessary — the Service cannot be provided without it.The duration of your signed-in session.
localStorage
(signed-in application)
Stores your vessel profile, waypoints, sail and reefing configuration, fuel settings, polar file, preferences, and cached forecast data on your own device so they persist between sessions. Not a cookie; never transmitted to us independently of your use of the Service.Until you clear it, or clear your browser storage.
_ga
(marketing website only)
Set by Google Analytics 4. Holds the randomly generated identifier that allows a repeat visit to be recognised as a return by the same browser rather than counted as a new visitor. Set only where this measurement is permitted — see below.Up to 2 years, measured from your most recent visit; each visit refreshes it. Removed if you withdraw your consent.
_ga_ followed by our property identifier
(marketing website only)
Set by Google Analytics 4. Holds the state of your current visit — for example when it began — so that a series of page views is counted as one visit rather than several. Set only where this measurement is permitted.Up to 2 years, measured from your most recent visit; each visit refreshes it. Removed if you withdraw your consent.
ww_consent_v1
(marketing website only, browser storage)
Remembers whether you accepted or declined the cookie-based analytics, where we asked you, so that we do not ask you again on every page and every visit. Stored on your device only; we hold no copy of it. Strictly necessary in order to honour your choice, and set whichever way you choose — including when you decline.Until you change your choice or clear browser storage. An acceptance is re-asked after twelve months; a decline is permanent and is not re-asked.

Where we ask before setting analytics cookies, and where we do not. Before the cookie-based analytics tool is permitted to load at all, we apply a default position that depends on the territory you are visiting from. Your browser's country is resolved for that purpose alone; it is not stored as part of any record about you.

How to change your mind, where we asked you. If you are visiting from the European Economic Area, the United Kingdom, or Switzerland — or from somewhere we could not determine, which we treat the same way — your choice is reversible at any time. Every page of our marketing website carries a Cookie preferences link in its footer, alongside a standing line telling you whether the measurement is currently on or off for your browser. The link reopens the notice so that you can accept or decline. Declining withdraws your consent, stops the measurement, and removes the analytics cookies from your device. Withdrawing is as easy as giving consent, costs you nothing, and does not limit your access to any page, guide, or part of the Service; nor does it affect the lawfulness of any measurement carried out before you withdrew.

How to switch it off everywhere else, including the United States. You can stop the measurement at any time, by two means that work whatever we do and that we cannot override. You may delete or block these cookies through your browser's own settings. You may also install the analytics provider's opt-out browser add-on, available at tools.google.com/dlpage/gaoptout, which prevents the measurement on every website you visit rather than only ours. How that provider uses data from sites that use its measurement tools is described at google.com/policies/privacy/partners. Our marketing website does not respond to browser "Do Not Track" signals, for which there is no accepted standard. No other party collects personally identifiable information about your activity on our website over time or across other websites. Neither of these choices affects the session cookie or the localStorage described above, both of which are strictly necessary to provide the Service.

If this changes again. If we later introduce any measurement or other technology that stores or reads a cookie or other identifier on your device, or that follows you across visits or across websites, beyond what this Section describes, we will update this Policy and give notice of the change under Section 11 before it takes effect. We will ask for your consent first wherever consent is required by the law of the territory you are in; everywhere else we will disclose it in this Section and give you a way to refuse it.

10. Children's Privacy

The Service is not directed at, and may not be used by, anyone under 18, and we do not knowingly collect personal data from anyone under 18 (including children under 13 within the meaning of the Children's Online Privacy Protection Act (COPPA)). If we learn we have collected such data we will delete it promptly; contact [email protected] if you believe a minor has provided data.

11. Changes to This Policy

We may update this policy as the service evolves. We will update the effective date at the top of this page whenever changes are made. Non-material changes — such as clarifying language, correcting typographical errors, or adding information about a new service provider who processes data in the same way as an existing provider — will be reflected in an updated effective date with no advance notice.

For material changes — including new data uses, new categories of data collected, changes to data retention periods, changes to how we share data, or changes that affect your rights — we will provide at least 14 days' advance notice through two channels: (1) by email to the address associated with your account, and (2) by a notice displayed prominently within the Service (for example, a banner or modal when you next log in). Where a material change affects visitors to our public marketing website who do not hold an account — a change to the measurement described in Section 9, for example — we will additionally give notice on the marketing website itself before the change takes effect, so that the people affected by it are told about it on the surface where it applies. If you do not agree to the updated policy, you may request account closure before the effective date by contacting us at [email protected]. Continued use of the Service after the effective date constitutes acceptance of the updated policy.

For users located in the European Economic Area: where a material change affects the legal basis for processing, the scope of data processed, or your rights under the GDPR, we will provide additional information as required by applicable law and, where required, seek fresh consent before the change takes effect.

Prior versions of this Policy are available on request to [email protected].

12. Contact

For privacy questions, data subject rights requests, data deletion requests, or account closure, contact us at [email protected]. We aim to respond to all privacy-related inquiries within 30 days of receipt. Requests sent to [email protected] are handled through the same channel.

We have not appointed a formal Data Protection Officer (DPO) under Article 37 of the GDPR. If you are unsatisfied with our response to a privacy inquiry, you have the right to contact your local data protection supervisory authority directly. See Section 6 for supervisory authority contact information.

13. EU Representative

We have not yet designated a representative in the EU or UK under Article 27 GDPR / UK GDPR. Until a designation is published here, EEA and UK residents may direct GDPR inquiries, rights requests, and supervisory-authority referrals to [email protected], which we handle within the Section 6 timeframes.