Privacy Policy

QuakeSignal is designed to collect only the information required to provide location-aware earthquake notifications.

QuakeSignal · Effective 12 August 2026

Data we process

If you enable notifications, the service stores the APNs device token, app locale, selected earthquake sources, magnitude threshold, alert preferences (including the exact alert-sound identifier and a test-alert preference), alert radius, optional selected-city label, registration timestamps, and one approximate coordinate on a 0.1° grid. That coordinate is derived from either the selected city's coordinate or the current device location; neither an exact GPS fix nor an unrounded selected-city coordinate is sent. To prevent fraudulent subscription changes, the service also stores an opaque Apple App Attest key identifier, public verification key, attestation receipt, monotonic assertion counter, and integrity timestamps; newer Apple proofs may additionally carry the app build version and distribution category. The app does not require an account, name, email address, contacts, photos, or advertising identifier.

How data is used

Subscription data is used only to decide whether an earthquake event matches your preferences and to send the requested Apple Push Notification. Location is not used for advertising, profiling, or sale.

Storage and deletion

Subscription settings and the associated App Attest integrity record are stored in Cloudflare D1. Removing notification registration from the app deletes the matching device registration, even when this launch has no APNs token, if an existing App Attest key can prove it owns that subscription. A new key cannot claim a legacy subscription with an empty request. After reinstall or device restore, a fresh Apple attestation plus the exact APNs token may safely rebind that one token and retire its old key record; assertions and tokenless requests cannot transfer another key's subscription. If it was the last registration using an App Attest key, that associated verifier, receipt, and assertion-counter record is deleted. A reviewed production training test creates a separate token-free claim containing only the opaque App Attest key ID and UTC timestamps; it is retained for at most 14 days to enforce one production training attempt per key per UTC day. Its optional fixed-delay check also creates one private scheduler record containing only that opaque App Attest key ID, a due time, and an at-most-once attempted state; it contains no APNs token, request body, proof, preferences, location, or earthquake payload. That temporary record is deleted after its one scheduled attempt or cancellation; an alarm more than 30 seconds late is deleted without delivery. Each App Attest challenge expires in no more than five minutes and expired records are removed by routine cleanup. A daily retention job purges registrations that are not refreshed for 90 days with their orphaned integrity records. Sanitized delivery-failure token hashes are retained for at most 14 days for reliability investigations. Disabling notifications or location access stops new collection but does not reliably send a deletion request, so use the in-app removal control when possible.

Third-party services

The app fetches earthquake information directly from the Wolfx Open API. Cloudflare is used only to store notification subscriptions, verify Apple App Attest proofs, watch upstream alerts, and request delivery through Apple Push Notification service. Their handling of network metadata is governed by their own policies. The App Attest private key never leaves your device.

Safety notice

QuakeSignal is not an official government warning platform. Data and notifications can be delayed, incomplete, or inaccurate. Follow official announcements and local emergency instructions.

Contact

For privacy, safety, or support questions, open an issue in the QuakeSignal GitHub repository.