Last updated: October 4, 2026

Privacy what we keep, and for how long

This Privacy Policy describes how Leone Ventures srl ("we", "us", or "the Company") collects, uses, and protects personal data when you visit and use calamity.live ("the Platform"). The Platform is a real-time global disaster monitoring dashboard that aggregates publicly available data from governmental and scientific sources.

We are committed to protecting your privacy in accordance with the EU General Data Protection Regulation (GDPR — Regulation 2016/679), the Italian Privacy Code (D.Lgs. 196/2003 as amended by D.Lgs. 101/2018), and all applicable data protection legislation.

1.Data Controller (Titolare del Trattamento)

2.Data We Process

Calamity.live is designed with a privacy-first approach. We do not use tracking cookies, analytics cookies, or profiling technologies. The personal data we process is limited to the following:

2.1 Navigation Data

  • IP address — processed server-side for rate limiting and abuse prevention. Access logs can contain client IP addresses, request paths, response status and duration. Logs exclude cookies, authorization headers and query strings; reset tokens, unsubscribe codes and watch-room identifiers are redacted from the paths and from the referring page.

2.2 Contact Form Data

  • The contact form sends nothing to our servers: it opens your own email application with a message addressed to info@leone-ventures.com. What you then send us — your name, email address and message content — is used solely to respond to your inquiry.

2.3 API Keys (by Arrangement)

  • The read API is open: it needs no key and no registration. Where a key is issued by arrangement, we store the email address it was issued to and a hashed copy of the key in our own database, on our own server in Germany. No payment is taken on the Platform today.

2.4 Accounts and voluntary notifications

Accounts store your email address, password hash, sessions, saved areas and delivery preferences. A push subscription stores the browser endpoint and encryption keys needed for delivery. Email watch rules use separate confirmation and unsubscribe links. A watch rule stores the address, the place, the distance and the hazards chosen and, only if you answer it, the one optional question asked after confirmation (whether the place is where you live, where family lives, a property, a destination or curiosity). Saving an account does not subscribe its email address to alerts. Account deletion removes its sessions, saved areas and push subscriptions; independently confirmed email watches can be stopped using their unsubscribe link. Account emails (confirmation, password reset) and alert emails are delivered through Resend, an email delivery service. Push notifications travel through the push service of your browser's maker (for example Google, Mozilla or Apple), which receives an encrypted message it cannot read.

2.5 Aggregate service counters

We retain daily totals of area saves and deletions, push registration and revocation, email confirmations, account deletions, save failures, openings of saved-area and watch pages, and voluntary push-test outcomes for up to 90 days. These best-effort request counters contain no user identifier, email, IP address, URL, private coordinates or device fingerprint. They do not count unique people, establish individual return visits or confirm that a notification was read.

We process personal data under the following legal bases as defined by Art. 6 GDPR:

DataLegal BasisReference
IP address (rate limiting)Legitimate interestArt. 6(1)(f)
Contact form dataConsentArt. 6(1)(a)
API key recordsContract performanceArt. 6(1)(b)
Account, saved areas and alertsContract performanceArt. 6(1)(b)
Push subscriptionConsent (your browser's permission)Art. 6(1)(a)

Where processing is based on legitimate interest (security, rate limiting, and spam prevention), we have assessed that these interests do not override your fundamental rights and freedoms, given the minimal nature of the data collected and the absence of profiling.

4.Processing Methods

Personal data is processed using automated means with appropriate security measures to prevent unauthorized access, disclosure, modification, or destruction. Data is transmitted over encrypted connections (HTTPS/TLS). We do not perform automated decision-making or profiling as defined by Art. 22 GDPR.

5.Data Retention

  • Access logs — restricted to operations, rotated at 50 MB with up to five rolled files and a seven-day age limit. A current log file can remain until rotation; documented incident evidence may be retained separately for investigation.
  • Sessions — a signed-in session lasts up to 90 days and is renewed while you use the Platform; signing out or deleting your account ends it.
  • Accounts — kept until you delete your account.
  • Emails you send us — retained for as long as necessary to respond to your inquiry, and no longer than 12 months.
  • API key records — kept while the key is in use.
  • Display preferences — stored in your browser (localStorage) and never sent to our servers, except the monitoring place you ask observations for (Section 7).

6.Your Rights

Under GDPR (Articles 15–22), you have the following rights regarding your personal data:

  • Right of access (Art. 15) — obtain confirmation of whether your data is being processed and receive a copy.
  • Right to rectification (Art. 16) — correct inaccurate personal data.
  • Right to erasure (Art. 17) — request deletion of your personal data ("right to be forgotten").
  • Right to restriction (Art. 18) — restrict processing under certain conditions.
  • Right to data portability (Art. 20) — receive your data in a structured, commonly used, machine-readable format.
  • Right to object (Art. 21) — object to processing based on legitimate interest at any time.
  • Right to withdraw consent (Art. 7(3)) — where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, please contact us at info@leone-ventures.com. We will respond within 30 days of receiving your request.

7.Cookies and Local Storage

Calamity.live does not use tracking cookies, analytics cookies, or any form of profiling cookies. The only client-side storage we use is:

  • Technical account and language cookies maintain your signed-in session and language choice. We do not operate an anonymous online-presence counter.
  • Display and monitoring preferences (localStorage) — your map style and area, the latest event list (so the map can show it at once) and your selected monitoring place can be remembered in your browser. The selected location is sent to our API when you request its observations. Account areas are saved separately when you explicitly save them.

No third-party service on the Platform sets cookies. Your browser loads the globe imagery, the map label fonts and, if you switch it on, the precipitation radar directly from their providers, which see your IP address (see Section 8 below).

8.Third-Party Services

The Platform integrates the following third-party services. Data may be transferred to servers located outside the EU/EEA, with appropriate safeguards in place (Standard Contractual Clauses or adequacy decisions):

Hetzner Online GmbH

Hosts the Platform on a server in Germany (EU): our database, the access logs and the service counters described above are kept there. See Hetzner Privacy Policy.

Resend

Delivers account and alert emails. It receives the recipient's email address and the message. See Resend Privacy Policy.

Browser push services

If you allow notifications, they are delivered by the push service of your browser's maker (for example Google, Mozilla or Apple). The message is encrypted for your browser: the push service delivers it without being able to read it.

NASA GIBS, OpenMapTiles and MapLibre

Your browser loads the globe imagery from NASA's GIBS service and the map label fonts from fonts.openmaptiles.org and demotiles.maplibre.org. These servers see your IP address, as any web server does; we send them nothing else. See NASA Privacy Policy.

RainViewer

Only if you switch on the precipitation layer of the map, your browser loads the radar images from RainViewer, which sees your IP address. See RainViewer Privacy Policy.

Stripe (Planned)

Not active today. If paid plans start, Stripe will handle all payment data (card numbers, billing address) directly; we will never receive or store card details. See Stripe Privacy Policy.

9.Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. Any changes will be posted on this page with an updated "Last updated" date. We encourage you to review this page periodically. Material changes will be communicated through a visible notice on the Platform.

10.Contact and Complaints

For any questions, concerns, or requests related to this Privacy Policy or the processing of your personal data, please contact us:

If you believe that the processing of your personal data violates applicable data protection law, you have the right to lodge a complaint with the Italian Data Protection Authority: