Privacy Policy - HazeFacet

Effective date: 2026-07-16

1) Who we are

HazeFacet is provided by Saifullah Ahad. Contact us at www.saifullah.ai@gmail.com or visit saifullah.ai.

2) What HazeFacet does

HazeFacet compares walking and cycling route alternatives and departure windows using public route geometry and hourly modeled air-quality fields. Results retain evidence timestamps, source availability, coverage, and missing fields.

Important: Results are relative modeled estimates, not personal exposure measurements, medical advice, official alerts, emergency guidance, or a guarantee. HazeFacet is not a medical device and does not diagnose, treat, cure, or prevent any medical condition. Follow local authorities and qualified health professionals when those sources are needed.

3) Information processed for a comparison

When you search for a place or request a comparison, HazeFacet sends the following over HTTPS to the developer-operated HazeFacet service on Cloudflare:

The app does not request device location permission and does not read GPS location. You choose places by typing and reviewing search matches.

4) HazeFacet service and public data providers

The HazeFacet service transiently combines responses from OpenStreetMap Nominatim for place search, routing.openstreetmap.de for mode-specific route geometry, and Open-Meteo for hourly air-quality and weather fields. These providers and Cloudflare may process ordinary network metadata under their own privacy terms.

The service does not create accounts, persist route histories, or log request bodies. It uses short-lived hashed network identifiers for abuse prevention and rate limiting; those counters expire after approximately 60 seconds. It may temporarily cache normalized public place results and coarse public environmental responses to reduce repeated upstream requests. Personalized route requests are not cached by the service.

5) Information stored on your device

HazeFacet may keep the following in Android private app storage:

Android backup is disabled for the app. HazeFacet has no advertising, analytics, crash-reporting, account, authentication, payment, or cross-app tracking SDK.

6) Permissions and background refresh

INTERNET is used for place and route-evidence requests. ACCESS_NETWORK_STATE supports connection-aware behavior and cached fallback. On Android 13 and later, optional POST_NOTIFICATIONS access is requested only if you choose a scheduled watch; denial leaves manual watches and the rest of the app usable.

Scheduled watches use Android WorkManager with a network constraint. WorkManager adds normal wake-lock and restart-receiver permissions so an enabled schedule can finish and be restored after a device restart. HazeFacet does not start a foreground service. A refresh occurs only for a watch you enable, and you can delete that watch to cancel its work.

7) PDF export and feedback

If you export an evidence brief, Android asks you to choose the destination. The resulting PDF is then retained and controlled by that destination or document provider, not by HazeFacet.

The Send feedback action opens your chosen email app with the HazeFacet support address. HazeFacet does not transmit the message itself. Any email you choose to send is handled by your email provider and the developer's email provider under their respective terms.

8) Sharing, sale, and advertising

We do not sell personal data or use it for advertising. The limited data described above is sent only to Cloudflare and the named public providers as needed to perform place search, routing, modeled-evidence comparison, security, and rate limiting.

9) Retention, deletion, and controls

Each saved watch keeps its 24 most recent snapshots and automatically removes older watch snapshots. Remaining local watches and snapshots stay on your device until you delete a watch, use Sources - Delete all local data, clear HazeFacet storage in Android Settings, or uninstall the app. Deleting all local data removes saved watches, snapshots, schedules, and refresh history from the app. Exported PDFs are separate files and must be deleted from their chosen destination.

Transient service requests end after the response. The short-lived rate-limit counters and public-data caches expire automatically as described above. Upstream providers set their own server-log retention.

10) Security

Network requests use HTTPS encryption in transit, and local data is held in Android private app storage. No method of storage or transmission is completely risk-free.

11) Children's privacy

HazeFacet is a general-audience route information utility and is not directed to children under 13. We do not knowingly collect personal information from children.

12) International processing

Cloudflare and the named public providers may process requests and network metadata in countries outside your own. HazeFacet's developer does not receive upstream provider server logs.

13) Changes to this policy

We may update this policy when the app, its providers, or legal requirements change. The latest version will remain at privacy.saifullah.ai/HazeFacet.html with a revised effective date.

14) Contact

Privacy questions or requests: www.saifullah.ai@gmail.com
Saifullah Ahad, Dhaka, Bangladesh