Privacy policy

Clear by design.

AirLocal uses only the data needed to find and deliver useful air-quality readings. There is no account, advertising, cross-app tracking, or data-broker integration.

Effective July 31, 2026
AirLocal for iPhone
Hyperstatic LLC

The short version

This policy explains how Hyperstatic LLC handles information when you use AirLocal, its widgets, notifications, Shortcuts, and related cloud services.

No user accountAirLocal does not ask for your name, email address, or Apple ID to use the app.
No tracking or adsThere are no advertising SDKs, tracking domains, or cross-app profiles.
Location stays localExact phone coordinates are used on the iPhone and are not sent to AirLocal's backend.
Deletion is built inYou can delete AirLocal cloud data from Settings without contacting us.

If you email support, we receive the address, message, and attachments you choose to send. That support conversation is separate from normal app use.

How location works

With your permission, AirLocal uses the iPhone's location to identify nearby public air-quality sources. The phone performs the nearby choice locally. Exact latitude and longitude are not sent to the AirLocal backend.

To retrieve public data, the app may send canonical map tile identifiers and public PurpleAir or AirNow station identifiers. These requests describe the data being viewed, not a precise phone-location history.

If you enable an alert that follows your location, iOS provides low-power significant location changes to the app. The phone chooses the new public sensor locally and sends only that chosen sensor identifier to the backend.

Location permission is your choice.

You can change AirLocal's location permission in iOS Settings. Some automatic Nearby features will be limited when location is unavailable.

Information stored on your iPhone

Saved sensors
Sensor identifiers, placement, the active sensor, and the last working local-network address are stored in app preferences until you remove them.
Local readings
AirLocal keeps up to 24 hours of one-minute sensor readings in protected app storage for charts and trends.
Private read keys
Keys for private PurpleAir sensors are kept in the device Keychain using a ThisDeviceOnly protection class until the sensor is unlinked.
Widgets and Shortcuts
Protected App Group files hold the latest snapshots and limited credentials needed by the app, widget, and Shortcut to coordinate.
Public caches
Map tiles, nearby summaries, and public history are cached for speed and honest fallback when a provider is temporarily unavailable.
Preferences
Appearance, public favorites, Home focus, and map choices are retained until changed or the app's data is removed.

A small allowlist of preferences may sync through Apple's iCloud key-value service when iCloud is available. It can include appearance, public favorites, and public map display choices. Exact location, map viewport, saved sensors, local addresses, credentials, alerts, and reading history are excluded from this sync.

Information sent to AirLocal's backend

Cloud features use a random anonymous installation identity. It is not an email address, Apple ID, advertising identifier, or user account.

Session details
The random installation identifier, app version and build, locale, and timezone establish and protect an anonymous session.
Public-data requests
Canonical map tile identifiers and public sensor or station identifiers retrieve viewed-region data, favorites, readings, and history.
Notifications
An APNs device token is registered only after notification permission exists and at least one alert is enabled. Alert payloads can include the provider, public sensor identifier, event type, AQI when applicable, and observation time.
Private sensor requests
A private read key is normally forwarded over TLS only for the request and kept in backend memory. It is not placed in shared public caches.
Private remote alerts
If you explicitly enable reliable remote monitoring for a private sensor, the backend stores an AES-GCM encrypted copy of its read key until you remove the rule or stop remote monitoring.

The backend also stores public source catalogs and caches, anonymous alert state, request-usage controls, and operational cost records. Public PurpleAir and AirNow records are observations published by those providers; they are not a history of your phone's location.

Services AirLocal relies on

  • Apple: iOS location permission, Keychain, iCloud preference sync when available, WidgetKit, Shortcuts, and Apple Push Notification service.
  • PurpleAir: public air-quality observations and, when you link one, access to your supported PurpleAir sensor.
  • AirNow: public monitoring-station observations and reporting-area forecasts.
  • Hetzner: infrastructure hosting AirLocal's backend and its protected operational data.

These providers process information under their own terms and privacy practices. AirLocal does not sell personal information or share it for targeted advertising.

Your controls and deletion

Delete AirLocal cloud data

In AirLocal, open Stations → Settings → Privacy & cloud data and choose Delete cloud data. This revokes the current cloud session and deletes that installation's notification destination, alert rules and events, encrypted private-alert credentials, and request-usage buckets.

Deletion leaves a one-way hash tombstone for the deleted random installation identifier. This prevents an old token or replayed identifier from recreating the erased installation; it cannot be used to recover the original identifier.

Remove device-held sensor data

Cloud deletion does not erase saved sensors, local reading history, or private read keys from the iPhone. Use Forget this sensor in Settings to remove a saved sensor, its local history, and its device-held read key.

Permissions

You can change location, local-network, and notification permissions in iOS Settings. You can also disable or delete individual alerts inside AirLocal.

Security and diagnostics

AirLocal uses TLS for backend traffic, device Keychain protections for private sensor keys, signed anonymous sessions, encrypted storage for explicitly enabled private-alert credentials, and restricted operational logging.

AirLocal's prepared support diagnostics include the app and iOS versions, appearance, saved-sensor count, and active connection state. They exclude exact location, network addresses, sensor names and identifiers, and credentials.

No system can promise absolute security. If you believe you found a security or privacy issue, contact us so we can investigate.

Changes and contact

We may update this policy when AirLocal's features or data practices change. The effective date at the top will be revised, and material changes will be reflected here before they apply.

Questions, deletion problems, or privacy concerns can be sent to [email protected].

AirLocal is provided by Hyperstatic LLC.

Last updated July 31, 2026