ReconStar privacy notice
ReconStar is local-first and account-free. Astronomy calculations, the selected Free Sky Area, saved places and trips work on the device. Optional connected reports, Pro entitlement checks and sky alerts use a pseudonymous app installation rather than a name, email address or ReconStar account.
Last updated: 1 September 2026
1. Controller and scope
Controller and publisher: StarSpun Labs Ltd, company number 17372613, registered in England and Wales.
Registered office: Office 9267OC, 182-184 High Street North, Area 1/1, East Ham, London, E6 2JA, United Kingdom.
Published as: StarSpun Labs.
Privacy and support correspondence may be sent by post to the registered office above.
This notice covers the ReconStar app on iOS and Android, its connected service and this static support site. It distinguishes information kept only on the device from information received by StarSpun Labs or a service provider.
2. Privacy summary
- There is no ReconStar account, advertising, advertising identifier or cross-app tracking. ReconStar does not send personal information to an artificial-intelligence service.
- ReconStar does not request background location, contacts, photos, microphone or camera access.
- Foreground location, notifications and live sky-guidance sensors are requested only after the user chooses the relevant feature. On Android, foreground location permission is also required by the platform postcode/address lookup.
- The exact saved place stays on the device; connected features use a coarsened area as described below.
- ReconStar Pro is an optional monthly or annual auto-renewing subscription processed by the Apple App Store or Google Play. Genuine earlier Lifetime Pro purchases remain recognised; no new lifetime purchase is offered.
- This static support site sets no application cookies and contains no analytics tracker, script or form. Its web host may still process IP addresses and ordinary request logs for delivery and security.
3. Information kept on the device
- onboarding choices, interests, units, appearance and accessibility preferences, plus the Free Sky Area centre and the date on which it may next be changed;
- saved-place names, regions, exact coordinates and time zones, plus trip names and dates;
- alert preferences, monitored-place choices, local reminder schedules and local alert history;
- up to 32 cached connected reports, which are replaced as the cache fills;
- bounded app-open, viewed-report, positive or negative moment and prompted state used only to decide whether to offer a store-review prompt;
- a random installation identifier and secret in operating-system secure storage when connected features are used; and
- a local Pro entitlement cache containing store, product, status, expiry and verification information, but no payment-card details or store password.
If the user deliberately opens a named source, full map, public policy, terms or support link, the destination receives ordinary web connection information under its own privacy terms. ReconStar does not collect link-click analytics.
ReconStar may ask the operating system to offer a store rating or review after restrained on-device eligibility checks. ReconStar does not receive the response to that prompt. If the user submits a rating or review, Apple or Google processes it and may display it publicly or make it available to StarSpun Labs through its developer tools.
Local records remain until the user deletes them, clears app storage or uninstalls. On Android, ReconStar disables operating-system app backup. On iOS, eligible app data may be handled by an Apple device backup or transfer according to the user's Apple settings. ReconStar does not operate a cloud-save account.
4. Permissions, location and sensors
ReconStar asks for foreground location permission only after the user chooses a current-location or live-guidance action. It does not request background location. Offline city search and manual coordinates remain available without location permission.
Postcode and address search is available only in the installed iOS and Android apps and runs only after the user taps Find. Apple or Google platform location services may process the search text under their own privacy terms. ReconStar does not send that text to its connected service. If the user confirms the result, the returned exact point and the entered text as its local label are stored on the device; an unconfirmed search is not added to ReconStar's saved places. On Android, the operating system requires foreground location permission before this platform lookup can run.
Compass heading and device-motion readings are used only while live sky guidance is active. Those readings are processed on the device and are not stored or sent to the ReconStar connected service.
For connected reports, ReconStar rounds the selected latitude and longitude before assigning the location to a broad map square several kilometres across. The report request sends that area, the selected date and the language and regional setting — not the original device coordinate. Online aurora alerts send the broad area, coordinates rounded to two decimal places and the settings needed to evaluate the alert.
NASA night-light imagery is requested for a broad reference area centred on a two-decimal location. NASA Earthdata receives that coarsened map request and ordinary network metadata such as IP address, time, browser or app network information. Opening the full NASA Worldview map is a separate user action.
5. Pseudonymous connected-service records
A connected installation is pseudonymous, not anonymous: it has no ReconStar name or account, but its records are joined by a stable random installation ID and may be linked to that app installation.
| Record | Purpose |
|---|---|
| Installation ID; protected verification value derived from the client secret; iOS or Android platform; language and regional setting; time zone; created and updated times | Authenticate the installation, format reports and apply destination-local alert rules. |
| Coarse report area, requested date and language and regional setting | Return the requested weather and aurora report and operate a short-lived shared report cache. |
| Expo push token and token status | Deliver remote alerts that the user enables and stop delivery to disabled or invalid tokens. |
| Platform, store product and base plan, transaction ID, entitlement kind and status, auto-renew state, access or grace expiry, verification and next-check times, an HMAC proof hash, and an AES-GCM-encrypted Google purchase token or Apple StoreKit transaction proof needed for periodic re-verification | Verify Pro with Apple or Google and prevent an unpaid or expired installation from creating cost-bearing background monitoring. Raw proof is not written to logs. |
| Generated notification title and body; delivery reference; event type, key, date and stage; coarse cell; score; and a ReconStar deep link. The payload does not include a user's name, email or saved-place label. | Route the requested alert through Expo and the device push provider and open the corresponding ReconStar event when selected. |
| Aurora or clear-sky event type, coarse cell, two-decimal coordinates, destination time zone, threshold, quiet hours, active dates and maximum alerts per day | Evaluate only the remote subscription configured by the user. |
| Delivery reference, event and stage, score, scoring-method version, delivery status and time, provider reference or failure status | Prevent duplicates, enforce frequency limits, confirm delivery and diagnose failures. |
| Optional useful/not useful rating and optional reason | Evaluate alert timing and calibration. It is not used for advertising. |
| Shared alert-evaluation state: event type and key, coarse cell, destination time zone, stage, score, confidence, scoring inputs and source status. It contains no installation ID. | Detect a genuine alert-stage change and avoid duplicate or stale alerts. |
| IP address and ordinary request metadata handled by hosting and rate-limiting infrastructure | Route requests, limit abuse, protect the service and maintain security logs. The ReconStar application database does not store IP addresses. |
6. Providers and sharing
- Cloudflare hosts the connected service, database, cache, rate limiting and service monitoring.
- MET Norway may receive a coarse-cell centre from the connected service to return weather. It does not receive the ReconStar installation ID.
- NOAA Space Weather Prediction Center supplies global aurora model data; the connected service does not send it a user or installation location query.
- NASA Earthdata GIBS and Worldview provide night-light imagery for the coarsened area described above.
- Expo Push Service, Apple Push Notification service on iOS and Firebase Cloud Messaging on Android process push tokens, notification content and delivery information for enabled remote alerts.
- Apple processes App Store purchases, payment and store-account history on iOS. Google performs the corresponding role for Google Play on Android.
- Apple or Google platform location services process a postcode or address only after the user deliberately requests native lookup. The query and provider result are handled under the platform provider's own privacy terms; ReconStar's connected service does not receive the search text.
These providers may process information in countries outside the United Kingdom under their own terms and applicable international-transfer arrangements. See Sources and licences.
StarSpun Labs does not sell personal data or share it for third-party advertising or cross-app tracking. Information may also be disclosed when legally required or needed to establish, exercise or defend legal claims.
7. Pro subscriptions and entitlement checks
ReconStar Pro is an optional monthly or annual auto-renewing subscription. Apple processes iOS payments through the App Store and Google processes Android payments through Google Play. The app receives the store-supplied product, price and transaction status so it can purchase, unlock, manage and restore Pro. StarSpun Labs does not receive payment-card or bank details, the user's store password or the user's name or email from ReconStar.
To prevent an unpaid installation from creating cost-bearing background monitoring, the app sends its authenticated pseudonymous installation ID, platform, store product and base plan, store transaction ID, and the Google purchase token or Apple StoreKit transaction proof needed for verification. The ReconStar service asks Apple or Google to verify the purchase and stores the fields described in section 5. The store proof is encrypted at rest for periodic verification; it is not written to application logs. Background monitoring is enabled only while the server has a qualifying recently verified entitlement. A genuine earlier Lifetime Pro purchase is handled in the same way and remains recognised.
Deleting ReconStar data removes the local entitlement cache and its pseudonymous connected entitlement record, but does not cancel a subscription, erase store purchase history or create a refund. The user manages or cancels a subscription in the relevant store. Restore purchases can re-establish access through the same Apple App Store or Google Play account.
8. Purposes and UK lawful bases
- Requested reports, entitlement verification, alerts, deletion and purchase restoration: taking steps at the user's request and providing the app service.
- Authentication, rate limiting, duplicate prevention, availability and security: legitimate interests in operating and protecting the service.
- Optional alert usefulness feedback: legitimate interests in evaluating and improving alert calibration; providing feedback is optional.
- Support and purchase enquiries: contract where the request concerns the purchased service, and legitimate interests in supporting users and maintaining appropriate records.
- Restrained store-review prompting and developer-visible reviews: legitimate interests in receiving and responding to product feedback. The eligibility state remains on the device.
- Compliance, disputes and rights requests: legal obligations and legitimate interests in legal claims.
Operating-system permission is requested separately for location, motion and notifications. Refusing a permission leaves the relevant optional feature off.
9. Retention
ReconStar keeps different records for the periods described below:
- local records remain until they are deleted, app storage is cleared or the app is uninstalled;
- submitted store ratings and reviews are retained and controlled by Apple or Google under the relevant store policy; removing ReconStar data does not remove them;
- the connected report cache uses short freshness and stale-response windows; a validated public MET forecast response may be retained for up to 24 hours;
- alert-delivery and optional feedback records are automatically removed after 90 days;
- shared alert-evaluation state for a coarse area and destination time zone is removed after 30 days without evaluation and contains no installation identifier;
- an alert subscription is automatically removed 30 days after its end date;
- when a Pro entitlement reaches a terminal expired, refunded or revoked state, its remote monitoring and push association are removed promptly and its encrypted store proof is erased; terminal entitlement metadata and proof hash are retained for no more than 30 days; recoverable pending, paused, hold or billing-retry states may retain the encrypted proof only for re-verification and do not permit background monitoring;
- a pseudonymous installation, its push token and anything still linked to it are automatically removed after 365 days without connected use; opening a connected feature refreshes that activity date;
- aggregated daily service-usage totals are retained for up to 400 days and do not contain an installation identifier;
- deleting the installation also deletes its alert settings, delivery records and feedback; aggregated usage and public source-status records are not part of that personal deletion because they do not contain the installation ID; and
- sampled Cloudflare Worker invocation logs are retained for no more than seven days. Cloudflare D1 recovery history may retain a deleted database state for up to 30 days before it expires. Apple, Google, NASA, Expo and other providers apply their own service and security retention periods.
10. Choices and deletion
- Use offline city search or manual coordinates instead of current location or native postcode/address lookup.
- Keep connected reports and notifications off, or disable remote alerts.
- Use predictable local reminders without a remote alert subscription.
- Choose Settings > Delete my ReconStar data.
When the connected service confirms deletion, ReconStar deletes the pseudonymous installation and its linked push token, alert settings, delivery records and feedback. Local preferences, Free Sky Area, saved places, trips, reminders, alert history, report cache and local Pro record are also cleared.
If the connected service cannot confirm deletion, local content and report cache are cleared but the secure installation credential is retained so the user can retry. The app does not report remote deletion as complete unless it is confirmed. See the data-deletion guide.
Apple App Store and Google Play purchase history is controlled by the relevant store and is not erased by deleting ReconStar data.
11. Rights and complaints
Depending on the circumstances, UK data-protection law may give a person rights to access, correct, erase, restrict, object to or receive a copy of personal information held by StarSpun Labs, and to withdraw consent where consent is the basis used. These rights apply to information StarSpun Labs actually holds; local-only app records remain under the user's device control.
Because ReconStar has no account and deliberately does not hold a name or email against a registration, the device's installation credential is normally needed to authenticate remote deletion. StarSpun Labs must not disclose pseudonymous records to an unauthenticated requester.
Write to the registered office shown below to make a privacy request. A person may also complain directly to the UK Information Commissioner's Office.
12. Children, security and automated results
ReconStar is a general-audience astronomy-planning app and is not designed specifically for children. It has no child profile, social feature or ReconStar account. A parent or guardian contacting support should avoid sending unnecessary personal information.
Operating-system secure storage protects the installation secret, network requests use HTTPS, and the service stores only a protected verification value derived from the secret. Access to service accounts and logs is restricted to authorised people. No security measure can guarantee absolute protection.
Sky scores and alerts are planning aids, not decisions with legal or similarly significant effects. They include uncertainty and are not guarantees of weather, safety or visibility.
13. Changes and contact
We will update this notice when a material privacy practice changes, including if ReconStar adds an account, analytics or advertising, background location, precise remote location, cloud sync, another provider or another purpose.
Controller: StarSpun Labs Ltd, company number 17372613
Privacy correspondence: Office 9267OC, 182-184 High Street North, Area
1/1, East Ham, London, E6 2JA, United Kingdom