Privacy
maqua.app is a public-information site. It has no accounts, no advertising and no tracking profiles. This page describes the small amount of data that does move, and who handles it.
Applies to maqua.app and its API.
In short
- No account is needed, and none can be created.
- No advertising, no ad networks, no cross-site tracking, no data sold or shared for marketing.
- The only personal data the site can ever store is an email address, and only if you ask for alerts and then confirm.
- Your location, if you choose to share it, stays in your browser. It is never transmitted to this site and never stored.
- No cookies are set for analytics or advertising.
This deployment has usage measurement switched off entirely. No analytics script is served.
Usage measurement
Nothing measures your use of this site. No analytics script is loaded and no page-view events are sent anywhere.
Independently of this, the hosting platform keeps ordinary server request logs — the kind every web server keeps — for a short period, for security and abuse prevention. These contain an IP address, which is personal data. They are not used to profile visitors and are not combined with anything else on this site.
Cookies and local storage
maqua.app sets no cookies for analytics, advertising or tracking. There is therefore no consent banner, because there is nothing to consent to.
- Appearance preference
- Choosing light, dark or “match device” stores a single value in your browser's local storage so the page does not flash the wrong theme on your next visit. It never leaves your device and can be cleared with your browser data.
- In-page data
- Readings fetched while you browse are held in memory for the life of the tab and are discarded when it closes.
Location
The map has an optional “find my location” control. It uses your browser's geolocation, which always asks your permission first and can be declined without losing any other feature.
Your coordinates are used only inside your browser, to centre the map and to work out which monitoring station is nearest. They are never sent to this site, never written to a database, and never included in a log.
Declining the prompt changes nothing else: every station is reachable from the map and from the list either way. Permission can be revoked at any time in your browser settings.
Email alerts
Alerts are not enabled on this deployment. No email address can be submitted, and none is stored.
What is stored, if you subscribe
- Your email address.
- The station and band you asked to be alerted about, and how often.
- Whether the address has been confirmed, and the times of subscription, confirmation and the most recent alert — needed to avoid sending the same alert twice.
The address is used for nothing but the alerts you asked for. There is no newsletter, no marketing, and it is never shared with or sold to anyone.
The legal basis is your consent, and consent can be withdrawn at any time. Every alert email carries a one-click unsubscribe link. Confirmation and unsubscribe links are signed so that nobody can subscribe or unsubscribe an address they do not control.
Services involved
maqua.app is deliberately thin, but a few third parties are involved in delivering it. Each is listed with what it actually sees. Where a service is not configured on this deployment, it processes nothing at all.
- Vercel — hosting
- Serves every page and API response, and therefore sees your IP address and request headers as any web host would. Also provides the optional analytics described above.
- Base map tiles — third-party tile service
- The map is drawn from tiles your browser requests directly from a tile provider, using OpenStreetMap data. Those requests reveal your IP address and which part of the map you are looking at to that provider, and they are subject to its own privacy policy rather than this one. Choosing the list view instead of the map avoids them entirely.
- Neon — PostgreSQL database (not configured)
- Not configured on this deployment. Nothing is written to a database, so no subscription or history exists to store.
- Resend — email delivery (not configured)
- Not configured on this deployment. No email is sent and no address is transmitted.
- Upstash — Redis cache (not configured)
- Not configured on this deployment. Caching falls back to the memory of the running server instance and nothing is written to an external store.
- OpenRouter — AI explanations (configured)
- Routes requests for plain-language explanations to a language model. What is sent is the air-quality figures already shown on the page — station, pollutant, concentration, band and time. Nothing that identifies you is included: no IP address, no email address, no location, no request history. Explanations are cached so that the same reading is not sent repeatedly.
- Environment and Resources Authority and the European Environment Agency
- The source of the measurements. Requests to the upstream feed are made by our server, on a schedule, and never by your browser — so your visit is not visible to either organisation.
How long things are kept
- Alert subscriptions
- Kept while the subscription is active. Removed when you unsubscribe. An unconfirmed subscription expires by itself if the confirmation link is never followed, and the pending record is deleted.
- Air-quality readings
- Public environmental measurements, not personal data. Retained to show history and trends.
- Server and error logs
- Short-lived, kept for operational and security purposes only.
- Caches
- Expire on their own, typically within minutes to an hour.
Your rights, and how to use them
Under the GDPR you can ask for access to your personal data, its correction or erasure, a restriction on its processing, a copy in a portable form, and you can object to processing. You can also complain to Malta's Information and Data Protection Commissioner.
In practice, the only personal data this site can hold is an email address you gave it for alerts, so most requests reduce to one action:
- Stop and delete: use the unsubscribe link in any alert email, or the Alerts page. Unsubscribing removes the subscription record, including the address.
- Anything else:raise an issue on the project's source repository, linked from the About page. Please do not include personal details in a public issue.
If you never subscribed to alerts, this site holds nothing about you to access or erase.
Children
The site is general public information and is safe for anyone to read. Alerts require an email address, and are not intended for children under the age at which they can give valid consent.
Changes to this page
This page describes how the software actually behaves, and the parts of it that describe optional services are generated from the running configuration. If the way data is handled changes, this page changes in the same release.
Air-quality data provided by Malta's Environment and Resources Authority (ERA), disseminated via the European Environment Agency (EEA). maqua.app is an independent project and is not operated by, affiliated with, or endorsed by ERA or the EEA.