Privacy policy
Last updated: 7 September 2026.
Big Coat ("the app", "we", "us") sends you a personalised daily weather and outfit brief. This policy explains what we collect, why, and the choices you have. It is written for the UK GDPR regime, and applies equally where EU GDPR applies to you.
Who we are
The data controller is Purple Ohm Ltd, a company registered in England and Wales (company number 11643197), whose registered office is 1 Tennyson Close, Kenilworth, CV8 2TD, United Kingdom. For any privacy question, or to exercise your rights, contact privacy@tiktaktoe.co.uk.
What we collect
- Account — your email address (to sign you in and deliver briefs) and an optional display name (used only to greet you).
- Locations — the place(s) you ask us to forecast, stored as approximate coordinates. If you enter a postcode we send it to a lookup service to find those coordinates; we do not store the postcode itself.
- Daily routine — the times and labels of the moments you want the brief anchored to (e.g. a commute or a school run), plus your timezone and send times.
- Trips — if you ask for a trip or festival packing brief: where you're going, the dates, what you'll be doing there, the brief we wrote, and any changes you make to the packing checklist.
- Devices — a push notification token per device, so we can deliver the brief and update your home-screen widget.
- Subscription — your subscription status, store, and product, received from the app store via RevenueCat. We never see or store your card details.
- Sign-in codes and sessions — short-lived one-time codes and a signed session token so you stay logged in.
- Technical and security data — your IP address, held briefly as a request counter so we can rate-limit abuse of the sign-in and API endpoints. It is not linked to your account, not used to profile you, and expires within the hour.
We do not collect analytics profiles, advertising identifiers, or your contacts, and we do not sell your data or use it for advertising.
Why we use it, and our lawful basis
- To deliver the service you signed up for — generating and sending your briefs, running your widget, and keeping your preferences — on the basis of performing our contract with you (UK/EU GDPR Article 6(1)(b)).
- To sign you in, keep the service secure, and prevent abuse — on the basis of our legitimate interests (Article 6(1)(f)) in running a safe service.
- To take payment and manage your subscription — contract and our legal obligations (Article 6(1)(b) and (c)).
Your location and daily routine are personal to you. We treat them as sensitive in practice and minimise how far they travel — see "Who we share with".
Who we share with (sub-processors)
We use a small number of providers, and we minimise what each one receives:
- Cloudflare — hosting, database, and cache (where your data is stored).
- Open-Meteo — weather and air-quality data. Receives approximate coordinates — no name, email, or identity. If you ask for a trip brief it also receives the destination you typed, to turn it into coordinates. (Their data is credited under its licence in our terms — see Weather data and attribution.)
- Postcodes.io — turns a UK postcode you enter into coordinates. Receives the postcode only, at the moment you add a location.
- OpenRouter and the language-model provider — writes the wording of your brief. Receives the weather figures, the name of the place the brief is for, your display name, and the labels and times of your routine anchors (so the brief can say "before your 8:15 school run"), plus the destination, dates and activities of a trip when you ask for a trip brief — never your email address, your postcode, or any coordinates. This provider may process outside the UK and EEA — see International transfers below.
- QuickChart — renders the hourly weather chart image for the email. Receives the weather numbers and the labels of your routine anchors, which are drawn on the chart — no name, email, or location.
- Brevo — sends the emails (receives your email address and the brief content).
- Expo — delivers push notifications (receives a device token and the brief content).
- RevenueCat, the Apple App Store, and Google Play — process your subscription and payment (we receive only your subscription status).
How long we keep it
- Account data and preferences: for as long as your account exists.
- Generated briefs (cache): about 36 hours, then overwritten.
- Trip briefs and their packing checklists: until you delete the trip, or your account.
- One-time sign-in codes: 10 minutes.
- Sessions: up to 90 days, or until you sign out.
- Rate-limiting and fair-use counters: up to 24 hours.
- When you delete your account we erase your data immediately (see below). Our database provider keeps a point-in-time backup from which data could technically be restored for up to 30 days; we do not use it to reinstate deleted accounts, and it is overwritten on its normal cycle.
Your rights
Under UK/EU GDPR you can:
- Access and port your data — export everything we hold as JSON from the app (Settings → Your data), and save or send it wherever you like. You can also ask us.
- Correct it — edit your details and preferences in the app at any time.
- Delete it — delete your account in the app (Settings → Your data); this is immediate and permanent. You can also ask us. Deleting your account does not cancel a subscription — the stores handle that.
- Restrict or object to processing, and withdraw consent — pause briefs in the app, turn a delivery channel off (Settings → Delivery), or unsubscribe from email with one tap from any brief.
- Complain — to the Information Commissioner's Office (ICO) or your local data protection authority.
Email and notifications
Every brief email has a one-click unsubscribe link, and you can turn off email or push under Settings → Delivery, or pause everything, in the app. Sign-in code emails are transactional and are not marketing.
Children
The app is not directed at children and is intended for users aged 16 and over.
International transfers
Where a provider processes data outside the UK and EEA, that transfer is covered by appropriate safeguards such as the UK International Data Transfer Addendum or Standard Contractual Clauses.
Changes
We will update this policy as the app changes and revise the date above. Material changes will be notified in the app.
Home ·
About ·
Support ·
Contact ·
Privacy ·
Terms ·
Delete your account
|