HOOKSCAN← Back to HookScan

Legal

Privacy policy

Effective August 14, 2026

Who operates HookScan

HookScan is a Welcome to the Chase project. Welcome to the Chase operates HookScan and is responsible for the practices described in this policy. This wording identifies the project and does not represent Welcome to the Chase as an incorporated company or registered nonprofit.

Permissions and chosen features

HookScan uses location, camera, and photo-library access only after permission is granted and only for features the user chooses. Location supports map positioning, nearby radar selection, saved places, forecasts, and location-relevant weather information. Camera and selected photographs support Cloud ID and the scrapbook.

Weather questions and Cloud ID

Weather questions, selected weather context, and Cloud ID photographs may be sent over encrypted HTTPS to the HookScan backend when hosted features are enabled. HookScan does not sell personal data and does not use this information for cross-app tracking.

Optional accounts and syncing

Live radar and official weather information remain available without an account. When account features are enabled, HookScan stores the user's name, email address, mobile phone number, an unreadable salted password hash, email-verification status, acceptance of the account privacy notice, timestamps, and security or session records.

Signed-in users may privately sync selected display preferences, map-layer choices, saved radar sites, and an explicitly saved Home location across supported HookScan devices. HookScan does not sync a device's current GPS position, APNs token, local AI-server address, radar files, or photo library through account settings. Contact information and synced settings are private and do not appear on public weather reports.

Unverified accounts expire after 24 hours. Verification and reset codes expire after 10 minutes, and signed-in sessions expire after 30 days without use. Active account and synced-setting records remain until the user deletes the account. Users can permanently delete their account, synced settings, and active sessions inside Settings.

Sign in with Apple

On supported Apple devices, users may choose Sign in with Apple. HookScan receives an Apple-signed account identifier and verified email address, which may be an Apple private-relay address. HookScan never receives the Apple ID password or device passcode. The identifier remains with the HookScan account until that account is deleted.

Email delivery

When Resend is configured, it processes the destination email address and a one-time-code message only after the user requests verification or password recovery. HookScan does not send Resend a phone number, password, or password hash and does not retain a reusable plain-text verification code.

Alerts and location monitoring

Device tokens, notification preferences, and locations a user explicitly chooses to monitor may be stored after remote alerts are enabled. A saved alert point changes only when the user runs setup again. HookScan never substitutes the selected radar tower when no notification location is chosen.

If Follow My Location is separately enabled with Always location access, the latest precise background-alert coordinate and observation time are used to route official warnings. The ordinary map blue-dot cache is never used for that upload. A Follow My Location coordinate stops matching alerts after 24 hours unless refreshed. Registrations expire after 90 days unless refreshed, and a notification-delivery identifier may remain for up to seven days to prevent duplicates.

App authenticity

On supported Apple devices, HookScan may use Apple App Attest to help verify that notification registrations originate from a genuine copy of the app. The backend may retain the public key, receipt, environment, and assertion counter for up to 400 days after the latest successful verification. HookScan does not receive the user's Apple ID or device passcode through App Attest.

Reports and public layers

Signed-in users may choose to submit a community road report. HookScan sends the selected category, precise GPS coordinate, location accuracy, heading or speed when available, and report time. Public responses include only the category, coordinate, and time. They do not expose the reporter's name, email, phone number, or account identifier. Reports expire automatically within 45 minutes to four hours depending on category.

The optional Storm Chasers layer shows only creator-approved profiles and feeds. A chaser location is public only when that creator explicitly enables sharing. HookScan does not infer or scrape a creator's private location.

Weather providers and widgets

HookScan obtains public weather information from NOAA and related government or university services. Those providers may receive ordinary network information such as an IP address and request metadata under their own policies. Radar and forecast widgets store the latest app-rendered radar snapshot or forecast summary in HookScan's private platform container for display by the matching widget.

Contact

Privacy questions for Welcome to the Chase and HookScan can be sent to hookscanadmin@hookscan.net.