Privacy Policy
Last updated: 9 October 2026
1. Controller and contact
The controller responsible for Mork is Gian Piero Mosetti. For support or privacy requests, email support@morkapp.net.
2. Local information and permissions
Mork uses location to provide forecasts, alerts, maps and sky information for relevant places. Where supported, you can choose a place manually instead of using your device location. iOS controls location permission; you can change it in Settings.
Calendar contents are processed locally through Apple EventKit to display, create and edit events. Photos selected for widget backgrounds are processed and stored locally. Mork does not upload calendar contents or selected photos to its backend. iOS or your calendar/photo provider may independently synchronize information under your settings and their own policies.
Preferences, widget configurations and cached feature data are stored locally, including in the iOS App Group shared by the app and its extensions. System permissions can be withdrawn in iOS Settings. This may limit the corresponding feature.
3. Weather and other online services
Weather requests can leave your device even when remote notifications are disabled. The app sends selected location coordinates directly to Apple WeatherKit, Rainbow Weather and Open-Meteo for weather and air-quality information. Apple geocoding and mapping services support place lookup and map features. Direct connections also expose technical network information such as your IP address to the provider.
Mork obtains European alert feeds from MeteoAlarm/EUMETNET; astronomy information from Astronomiamo, the U.S. Naval Observatory, NASA Astronomy Picture of the Day and the public Astronomy Calendar; and earthquake data from USGS. The global NASA, USGS, USNO and astronomy calendar requests do not include your device’s location. Sky visibility calculations also use weather and local settings.
Open-Meteo’s privacy notice states that its free API logs may contain IP addresses and geographic coordinates and are deleted after 90 days. This is provider-side processing and is separate from Mork’s own registration retention.
4. Optional remote notifications
Remote notifications are disabled by default. When enabled, the app sends the Mork backend its APNs push token, a random installation identifier, app bundle identifier, selected city and coordinates, country code when available, additional saved forecast places, language, time zone, notification categories, weather and earthquake thresholds, and notification sound choice. The backend adds operational information such as an update timestamp and the APNs delivery environment.
The registration does not send your device name, device model, operating-system version, calendar contents, photos or advertising identifiers. Mork has no user accounts, advertising or analytics integration, as confirmed by the operator.
Cloudflare Workers and Workers KV process and store the registration to generate requested alerts. For localized weather and Live Activity updates, the Worker sends coordinates and relevant language/country parameters to WeatherKit. APNs receives the delivery token and the notification or activity-update payload.
5. Live Activities
Starting a weather Live Activity can register it for remote updates independently of the remote-notification setting. Registration includes a Live Activity token and identifier, installation identifier, bundle identifier, APNs environment, selected place and coordinates, language and time zone. Mork Sky Live Activities in Mork are updated locally.
When you end a weather Live Activity through the app’s end controls, the app requests removal of its server registration. Removal depends on the request reaching the server; closing an activity through another route must not be assumed to trigger that request. The expiry described below provides an additional limit.
6. Purposes and processing bases
Information is processed to provide requested weather and calendar features, send enabled alerts, update weather Live Activities, prevent duplicate notifications, operate the service securely and respond to support or privacy requests. It is not used by Mork for advertising, commercial profiling, marketing, selling personal data or cross-app advertising tracking.
We process information necessary to deliver the app features and remote updates you request on the basis of performance of the service (Article 6(1)(b) GDPR). We rely on our legitimate interests in maintaining a reliable and secure service and responding to support enquiries (Article 6(1)(f)), subject to your rights and interests. Where consent is required for a particular processing activity, it is requested separately and may be withdrawn. Device permissions and notification settings control access and feature activation; they do not replace the legal basis for server-side processing.
7. Retention and deletion
- Push device registrations: expire 90 days after the most recent server write that sets their expiry. Registration or renewal by the app resets this period. Legacy-record migration and a correction to the APNs delivery environment can also reset it. The period is therefore not strictly measured only from the last app launch.
- Disabling remote notifications in Mork: sends an unregister request. On successful processing the Worker deletes the device registration. If the request fails, the app retains its token so removal can be retried on a later launch. Changing only iOS notification settings or uninstalling the app does not guarantee immediate backend deletion.
- Weather Live Activity registrations: expire 12 hours after a write that sets the expiry. Identical registration requests do not extend it; changed registrations or APNs environment corrections can reset it. Successful explicit removal or certain invalid-token responses can delete it earlier.
- Duplicate-notification markers: expire after 36 hours for weather, NASA and sky notifications and 7 days for earthquakes. Temporary weather-delivery reservations expire after 5 minutes. Unregistering a device does not immediately delete these separate markers.
- Invalid push tokens: removed after applicable invalid-token or unregistered responses from Apple.
Support correspondence is retained while needed to handle your enquiry, related follow-up or applicable legal obligations. You may request its deletion. Technical records processed by hosting and service providers follow their applicable retention arrangements and do not necessarily share the device-registration expiry. The app’s backend does not maintain an additional application-level diagnostic log store in its KV registry.
8. Hosting and international processing
Mork’s backend is hosted on Cloudflare Workers and Workers KV. This website is hosted on Cloudflare Pages; support email is handled with iCloud Mail. Provider infrastructure may process information outside your country or outside the European Economic Area.
Cloudflare publishes a Customer Data Processing Addendum that provides for standard contractual clauses and additional safeguards for relevant restricted transfers. Information about relevant transfer safeguards can be requested at support@morkapp.net.
9. Website and support
This website has no analytics, advertising scripts, cookies, local storage, embedded third-party content or external fonts. Hosting providers may still process network and security information. Links to external sites are subject to those sites’ practices.
If you contact support, Mork receives your email address and whatever you include in the message. Please avoid sending unnecessary personal calendar information, precise locations or other sensitive details.
10. Security
The app uses HTTPS for online requests. Worker administrative endpoints require an administrative bearer secret; the iOS registration and removal code does not embed that secret. Ordinary registration endpoints use payload validation, and removal of a device registration checks the supplied installation identifier against its stored record. No transmission or storage system can be guaranteed to be completely secure.
11. Your rights
Where applicable, you may request access, correction, deletion, restriction, portability or object to processing. You can withdraw consent without affecting earlier lawful processing. Contact support@morkapp.net to exercise these rights. Because Mork has no user accounts, limited technical information may be needed to locate a registration securely.
You can complain to a competent supervisory authority, including the Spanish Data Protection Agency (AEPD) or the authority in your country of residence.
12. Children and changes
Mork does not use children’s data for advertising or commercial profiling. Optional location and remote-update features involve the processing described in this policy regardless of the user’s age. This statement does not imply that Mork collects no information when used by a child.
This policy will be updated when features or processing practices change. The revision date appears at the top of this page.