Privacy Policy

Last updated: August 23, 2026

This policy describes how Stormdrop Lamp LLC (“Stormdrop,” “we,” “us,” or “our”) collects, uses, discloses, and retains information when you use our website, launch list, mobile application, and connected lamp (collectively, the “Service”).

Information We Collect

Information you provide

  • Account and sign-in information: Firebase Authentication processes your email address, account identifier, and login credentials. If you use Google or Apple sign-in, we receive the profile information that provider makes available, such as your name and email address.
  • Launch list and optional research: If you join, we collect your name, email address, optional interest selection, consent record, signup button and landing page, referring page, and campaign parameters included in the link. On a research landing page, we may also record the experiment, copy, creative, and offer version shown; the displayed price and shipping treatment; whether the interest was for yourself, a gift, or undecided; optional occasion, general place category, and setup-environment selections; and separate optional consent to one short research follow-up. We do not ask for an exact ZIP code in this launch-list research.
  • Lamp configuration and content: We store account-associated lamp names, local IP addresses, U.S. ZIP codes, scenes, colors, brightness and alert preferences, and other control settings.
  • Wi-Fi credentials: During provisioning, the app sends the network name and password directly to the lamp over Bluetooth. Stormdrop's servers do not store them; the lamp retains them so it can join the network.
  • Support communications: We receive information you include in a support message and diagnostics you choose to provide.

Information collected automatically

  • App and mobile-device diagnostics: Firebase services may process IP address, installation/session identifiers, operating-system and device details, crash reports, stack traces, performance information, and diagnostic keys used to identify an affected lamp or workflow.
  • Lamp heartbeat: A connected lamp periodically sends its Wi-Fi MAC address (used as a device identifier), firmware version, selected ZIP code, and last-seen time to our AWS service.
  • Weather data: We process the selected ZIP code, derived coordinates, provider result, alert result, condition, and temperature to choose the lamp display. On August 10, 2026, the production backend stopped creating new provider-derived weather-history records and stopped writing provider- or device-valued weather details to application logs. Older app versions may still save a weather, temperature, or location snapshot with account-associated device settings in Firestore until those versions are replaced.
  • Controlled remote pilot: For an enrolled lamp, we process the Firebase user ID, lamp identifier, ownership/enrollment state, certificate state, and remote settings needed to authenticate and route requests.
  • Website analytics: If you allow analytics, Google Analytics processes page visits, referral/campaign information, browser/device details, approximate location derived from IP address, and non-identifying experiment-view, button-click, form-start, and launch-list conversion events. Advertising signals and personalization are disabled. You can change the choice using the Analytics choices control.

How We Use Information

  • Provide, operate, secure, and maintain the Service.
  • Manage accounts, lamp ownership, provisioning, control, updates, and support.
  • Retrieve weather for the selected ZIP and apply Stormdrop's weather logic.
  • Save settings and scenes; diagnose failures; and measure reliability.
  • Deliver requested launch-list messages, measure consented outreach, analyze offer and message interest, and conduct a separately consented short research follow-up.
  • Comply with legal obligations and protect users, Stormdrop, and the Service.

How We Disclose Information

We do not sell personal information and do not share it for third-party targeted advertising. We disclose information to service providers only as needed for these functions:

  • Google Firebase and Google sign-in: authentication, Firestore storage, Crashlytics, and related app/session operation.
  • Apple sign-in: Apple account authentication when selected.
  • Amazon Web Services: API/weather processing, lamp heartbeat, retained weather-history records awaiting their existing expiration, controlled remote ownership and enrollment, IoT messaging, operational logs, secrets, and private firmware delivery.
  • Apple WeatherKit: receives derived coordinates for current conditions and short forecast lookahead used only to select cache duration.
  • OpenWeather: receives the ZIP and derived coordinates for geocoding and fallback current conditions.
  • National Weather Service: receives derived coordinates for active-alert lookup. We do not send these weather providers your Stormdrop account ID or lamp identifier.
  • Netlify and Resend: website hosting, launch-list forms, and requested email delivery.
  • Google Analytics: consented website measurement with advertising personalization disabled.

We may also disclose information when required by law, reasonably needed to protect rights or safety, or as part of a business transaction subject to applicable law and notice requirements.

Retention

  • Lamp-heartbeat records expire 90 days after the last heartbeat; an active lamp refreshes that period.
  • A completed automated deletion permanently retains a minimal pseudonymous hashed-UID record and immutable Firestore lock solely to prevent account recreation. For each exactly linked lamp, it also retains a hashed-device heartbeat-suppression record; that lamp keeps weather service but loses fleet/remote last-seen status, including after transfer, until a possession-authorized clear path exists.
  • The production backend stopped adding new provider-derived weather-history records on August 10, 2026. Existing records remain subject to their existing 30-day expiration; this change did not manually delete them.
  • Legacy Firestore weather, temperature, and provider-location snapshots remain with the associated per-user lamp record until that record or account data is deleted through the automated workflow or a verified request. The current signed pilot app stops new snapshot writes and ignores existing snapshot fields; installing it does not delete retained values.
  • Short-lived enrollment sessions expire automatically. Ownership records remain until release, transfer, decommissioning, or an approved deletion action.
  • Account settings and scenes remain while the account is active or until an implemented deletion workflow or verified request addresses them, subject to permitted or required retention.
  • Launch-list records remain until a verified deletion request. Unsubscribing changes mailing status and retains the minimal suppression data needed to honor the opt-out; it does not by itself delete the original submission.

Security and Local-Network Limits

We use administrative, technical, and organizational safeguards we believe are reasonable for the nature of the information. No transmission or storage method is completely secure. Cloud traffic uses encrypted connections, but portions of lamp provisioning and local control use Bluetooth or local HTTP and are not all end-to-end encrypted. Set up and control the lamp from a trusted local environment.

Account and Data Deletion

The current signed pilot app and production backend provide a fail-closed Delete Account workflow. After identity reauthentication, it locks the account against recreation, removes account-linked backend ownership/enrollment records and Firestore settings, scenes, and legacy snapshots, revokes Apple authorization when applicable, then deletes Firebase Authentication last. If availability or cleanup cannot be confirmed, sign-in remains active so deletion can be retried safely.

A completed deletion deliberately retains the minimal immutable Firestore lock and pseudonymous hashed account anti-recreation record described above. For each exactly linked lamp, it also retains a hashed-device heartbeat-suppression record. It does not factory-reset a lamp, erase Wi-Fi stored on it, or remove a separately collected launch-list record. Older app builds do not contain the complete automated sequence.

If automated deletion is unavailable, fails to complete, or is not present in your installed app, follow the steps on our public account-deletion request page or email support@stormdroplamp.com from the account address. A verified request can address retained Firestore settings, scenes, and legacy weather snapshots along with other account-linked records. Identify any lamps and say whether a separate launch-list subscription should be included. We may verify the request and retain limited records when permitted or required for security, fraud prevention, legal, tax, support, or opt-out compliance; we will explain an applicable exception.

Unsubscribing from launch-list email stops future marketing messages; it does not delete an app account and does not by itself request deletion of all launch-list information. Conversely, deleting an app account does not automatically delete a separately collected launch-list record. Request launch-list deletion separately or ask us to include it with the account request. A minimal suppression record may remain so an opt-out continues to be honored.

Your Choices and Rights

You may update lamp settings in the app, unsubscribe from marketing email by replying “Unsubscribe” or using any unsubscribe link provided, change website analytics consent on the site, and request access, correction, or deletion by contacting us. Additional rights may apply where you live.

Children's Privacy

The Service is a general-audience product and is not directed to children under 13. We do not knowingly collect personal information from children under 13. Contact us if you believe a child provided information.

Changes and Contact

We may update this policy as the Service and legal requirements change. We will post the revised date and provide additional notice when required.

Questions or privacy requests: support@stormdroplamp.com.