The Spread Maps Request an invite

Privacy

The Spread is a small, independent weather site. This page describes exactly what it stores, because a short honest answer is more useful than a long one written by a lawyer for a company with more to hide.

The short version

  • No advertising, no advertising networks, and nothing is sold or shared with anyone.
  • No third-party analytics service. No Google Analytics, no tracking pixels, no external fonts or scripts — every page loads only from this site.
  • An account is optional and is only an email address plus your preferences. No password is ever stored — sign-in is a one-time email link.
  • Your IP address is not stored in anything this site writes down — not in the usage log, not in the server's own technical log, not in the backups.
  • You can see everything held about this browser, download it, or delete it, without asking anyone.
  • You can turn measurement on or off below, and it takes effect immediately. In the EU, the EEA and the UK it is off unless you turn it on.

The cookie

One cookie, wxvid, holding a random string that means nothing outside this site. It expires a year after it is set, and it does two jobs:

  • Remembering your things — the places you save and the dates you watch are attached to it. Without it the site would forget them the moment you closed the tab.
  • Counting how the site is used — so we can tell whether people who arrive actually find what they came for.

Turning measurement off below stops the second job and leaves the first alone, so declining never costs you your saved places. If you decline before saving anything, no id is created at all.

In the EU, the EEA and the UK, the second job is off unless you switch it on. Nothing is counted and no id is created for reading — saving a place or watching a date still works, because that is something you asked for. Everywhere else, measurement is on until you turn it off. Which one applies is decided by the country your network provider reports, and you can change it below either way.

A second cookie, wxdnt, exists once you have made that choice — it holds a single character recording which way, and nothing else.

A third, wxmode, exists only if you switch the forecast discussion between plain language and forecaster language. It holds one of those two words, nothing else. It records nothing about you, so it is unaffected by the choice below.

A fourth, wxunits, exists only if you switch the site between °F and °C. It holds one of two words, nothing else. Until you touch that switch there is no cookie at all: we start from the country your network provider reports — the same signal named above, read fresh each time and never written down — and show °C everywhere except the United States. Functional, like wxmode, so the measurement choice below does not affect it.

A fifth, wxsess, exists only if you sign in to an account. It holds a random string that means "this browser is signed in" — the string itself is meaningless, and what it unlocks is stored on our server in scrambled form, so even our own backups never contain a value that could be replayed. It expires after 90 days, or immediately when you sign out. Functional, like wxmode: it exists because you asked to be signed in, and it is unaffected by the measurement choice below.

Separately from cookies, three things are kept in your browser's own local storage. None of them ever leaves it — our server is not told and cannot read any of them — and clearing your browsing data removes all three.

  • theme — one word, if you switch the site between light and dark.
  • wxmodel — the name of the model you last picked on a forecast chart, so the chart opens on it next time instead of forgetting. One short word, the same for every place you look at.
  • changesSeen:… — one marker per place whose “what changed” list you have opened, so the badge can tell you what is new since last time. The coordinates of that place are part of the marker's name, which makes this the one place a location you looked at is written down at all. It is written down on your device, by your browser, and nowhere else.

What the usage log actually contains

One line per page view, plus a line for a few of the things you can do on a page, with:

  • the time, and the random id above;
  • which kind of page — “a forecast page”, “a watch page” — not which place. A forecast for specific coordinates is recorded as /forecast and nothing more;
  • the name of the site you arrived from, if any — reddit.com, not the full address of the page you were reading;
  • when you save a place or watch a date, that you did so, along with the place name and the date you chose;
  • on a forecast, Model Lab, model-accuracy, location, maps or national page, how long the page was actually in front of you. It counts only while the page is visible and you are doing something — a tab left open in the background, or one you walked away from, adds nothing;
  • on a forecast or Model Lab page, which forecast model you singled out if you picked one — “ECMWF”, “GFS”. Which model, not which place.

Those last two are the only things on this list your browser has to tell us; everything else we can see for ourselves because we served the page. They are switched off by the same choice below as everything else.

They answer two different questions, and the second one is worth naming. On the forecast, Model Lab, maps and national pages, how long you stayed tells us whether the thing on the page is worth its keep — a map nobody looks at for more than a moment is a map we should draw differently or not at all. On the model-accuracy, location, maps and national pages, which anyone can read without signing in, it does a second job as well: it is the only way we can tell a person from an automated crawler — most of what reaches those pages is software, and a crawler that describes itself as a browser is otherwise indistinguishable from you. We would rather ask your browser this one question than do what a tracking service would do to answer it: we run no analytics service, load no third-party script, and do not fingerprint your browser or look at your IP address. If you would rather not answer it, the switch below turns it off along with everything else.

It deliberately does not contain your IP address, the full web address you came from, the coordinates or place names you searched for, or anything you typed.

Where measurement is off by default, there is no such line and no id — but the site does add one to a tally of pages served that day. That tally is a single number per day, with no id, no page and no time beyond the date, and it exists so we can tell whether anyone is reading from those countries at all.

If your browser sends a Global Privacy Control signal, the same applies: nothing is recorded about your visit and no id is created, and the site adds one to a tally of the same shape — a single number per day, with no id, no page and no time beyond the date. Without it, a reader who asks not to be counted and a reader who never came look identical to us. We would rather know that people are arriving than know anything about them.

Log files and those tallies are kept for 25 months and then deleted.

Our web server keeps its own technical log of requests — which page, which result, how long it took. It records no address and no identifier: where a visitor's IP address would go, it writes a one-way code that changes every time the server restarts, so a burst of requests can be recognised as one source without anyone being able to work out whose. It does not record the coordinates you looked at or the link you were sent.

Places you save and dates you watch

These are the things you deliberately ask the site to remember. They are kept against the id above — or against your account, if you have signed in on this browser:

  • Saved places — the name and coordinates of each place, and when you last looked at it. Removed if you do not come back for 180 days.
  • Watched dates — the place, the date, anything you chose to be alerted about, and the short label you typed, if you typed one. A watch is removed 90 days after its date has passed, whether or not you touch it.
  • The share link for a watch is a random code. Anyone who has the link can see that watch, which is what makes it shareable — it is not tied to you and does not identify you.

You can see everything held against this browser, and download a copy, on what this browser has stored.

Accounts, if you make one

An account is optional — everything above works without one. If you create one, on the account page, this is the complete list of what it adds:

  • Your email address, and when the account was created. It is used to send the sign-in links you request, and — only if you switch it on — the email updates described below. It is never sold, shared for advertising, or used for anything this page does not name.
  • Your preferences — which discussion register you read, and whether you read the site in °F or °C. Both are the same two values described above as cookies; the account holds a copy so that signing in on a new device carries them over. Your theme is not among them: it never leaves your browser.
  • Your saved places and watched dates, which move from the browser to the account the first time you sign in on it, and belong to the account from then on. That is what makes them appear on your phone and your laptop alike. They are the same information described above — only the thing they are attached to changes.
  • Whether you asked for email updates. Off by default; nothing is sent to you except the sign-in links you request, until you turn it on.

There is no password: sign-in works by emailing you a link that is valid once, for 15 minutes.

Deleting the account, on the same page, is immediate and self-service: the address, the preferences, the saved places and watched dates attached to it, any pending sign-in links and every signed-in session are removed from the live site in one step. The backups caveat below applies to accounts the same as everything else.

Other companies involved

  • Cloudflare sits in front of this site as its network and, during the beta, its sign-in gate. Like any network provider it handles your requests, including your IP address, in order to deliver the page. It also tells our server which country a request came from, which is how the rule above is applied.
  • DigitalOcean hosts the server the site runs on, in the United States, and takes periodic whole-server images as a disaster-recovery measure.
  • Backblaze stores the nightly backup described below. It is encrypted before it leaves our server, so Backblaze holds a file it cannot read.
  • Resend delivers the account emails — sign-in links, and any updates you switch on. It is given the address it is delivering to, which is what delivery means, and nothing else about you. If you never make an account, Resend never hears about you at all.
  • Anthropic provides the language model that writes the forecast discussions, from numbers our server has already calculated. Nothing about you is sent with them — not your id, not your address, nothing that came from your browser.
  • Weather data comes from Open-Meteo and the National Weather Service. Our server fetches it — your browser never contacts them, so they never see you.

All of them are in the United States, so if you are reading from elsewhere your request is handled there.

Backups, and what deleting does not reach

The site's data is copied to an encrypted nightly backup, kept on a thinning schedule that reaches back about a year. This matters for one honest reason: deleting something here does not reach the copies already made. If you clear this browser's id, it is gone from the live site immediately and stops being used for anything — but a backup taken last month still contains what was there last month, until it ages out on its own. Backups are only ever used to restore the site after a failure, and never to bring back something someone deleted.

Your rights

Wherever you live, you can do all of this yourself, right now, without asking us or proving who you are:

  • See what is held — everything, on what this browser has stored.
  • Take a copy — the same information as a downloadable file, from that page.
  • Delete it — “Forget this browser” below clears the id and detaches everything from it; deleting an account, on the account page, removes the email and everything with it just as immediately.
  • Turn measurement off — below, effective immediately, and it never costs you your saved places.

It works this way because the id is stored so that scripts cannot read it, which means you cannot read it either — so what this browser holds could not be looked up from an email even if you asked us to, and a request form would be a promise we could not keep. Your browser proves who it is by simply being your browser, and a signed-in account proves itself the same way. The one thing an email can identify is the account that carries it — which is why the account page lets you delete that yourself, no request needed.

If you are in the EU, the EEA or the UK you also have the right to object to or restrict what we do, to ask us to correct something, and to complain to your national data protection authority. The lawful basis is your consent for measurement — which is why it is off until you switch it on — and our legitimate interest in keeping the site running and secure for the rest.

Your choices

Measurement is currently on.

Who runs this, and when this changed

The Spread is operated by Jonathan Griffin, who decides what is collected and why — the “data controller”, if you are reading this against a checklist.

This notice was last changed on 2026-09-03. When it changes again, this date changes with it and the change is listed in the site's release notes; if a future change means collecting something materially new, it will be announced on the site before it starts rather than quietly appearing here.

Where this stands

The Spread is in a closed beta and is not a life-safety service. This notice describes the site as it is built today; if that changes, this page changes with it.Questions: hello@spreadwx.com.