Privacy policy

Last updated .

In short

  • You can read every forecast without an account. Friction runs no analytics and no advertising, and sets no tracking cookies.
  • An account keeps your name, your email address, how you sign in, the crags you keep under Your crags, whether you want Alerts, and any access tokens you make.
  • Friction emails you only what you ask for: the link to verify your address, password resets, and the Alerts you switch on.
  • Your personal information never goes to the language model that writes local knowledge, and it is never sold.
  • Delete your account whenever you like (an account made with Google creates a password first), and everything it keeps goes with it.
  • Ask what Friction holds about you, or anything else, at [email protected].

Who is responsible

Friction follows South Africa’s Protection of Personal Information Act (POPIA). The responsible party decides why and how Friction uses personal information:

The information officer deals with requests and complaints about personal information:

Reading forecasts

Every area and crag page is open to anyone, without an account.

  • Your browser’s request passes through Cloudflare, which serves friction.co.za, to Friction’s server at Railway. Like any web server, they see your IP address, your browser and the address you asked for.
  • Friction keeps no history of what you read and builds no profile of you. It runs no analytics and no advertising, and its fonts come from its own server.
  • It sets the two cookies a site with forms needs, a session cookie and a CSRF cookie (see Cookies). Without an account the session holds nothing about you.
  • When many requests come from one IP address in a short time, Friction counts them, for an hour at most, to slow them down.

What an account keeps

An account is for keeping your own crags and Alerts, and for using Friction from your agents. It keeps:

Your name and email address
The name you give, the address Friction writes to, and when you verified it. A new address you ask for is kept beside it, and becomes your address only once you open the link Friction sends there.
Your password
Stored only as a one-way hash that cannot be turned back into it. An account made with Google starts with a random password that nobody knows, until you create your own.
Two-factor sign-in
If you turn it on, its secret and its recovery codes, encrypted.
Passkeys
For each one, its public key, the name you give it (Friction suggests your browser and device, such as Safari on iPhone), which passkey manager holds it, as your device reports it, and when it was last used. The private key, and your fingerprint or face, never reach Friction.
Google sign-in
If you choose Continue with Google, or connect Google on your security page, Google tells Friction your Google account’s ID, your email address, whether Google has verified it, and your name. Friction keeps the ID, to know you next time. It uses the address to find your account, or to make a new one, and the name for a new account, or for an account whose address was never verified, which your Google sign-in proves is yours. It keeps no picture, no contacts and no Google access token, and it cannot see into your Google account. Disconnect Google on your security page and the ID goes.
Staying signed in
A random token that keeps you signed in on one browser, when you tick Keep me signed in or sign in with Google (see Cookies).
Your crags
The crags you keep as Favourites, and for each one whether its Alerts are on.
Alerts
A record of each Alert email: the day, the crags and best windows it listed, the forecasts it read, and whether it was sent.
Access tokens
The name you give each access token (an account keeps ten at most), a hash of the token, and when it was last used. Friction shows you the token itself once, on the page after you make it, and keeps only its hash.
Dates
When the account was made and last changed.

Email

Friction sends three kinds of email, all through Resend, which delivers them and so handles your address and the message:

  • the link to verify your address, when you sign up or change it; it works for 60 minutes;
  • a link to reset your password, when you ask for one; it works for 60 minutes;
  • Alerts, only when you switch them on for a crag and your address is verified: at most one a day, after the evening forecast, listing each of your crags with a best window tomorrow. Every Alert has a link, and your mail app may show an Unsubscribe button, that switches all your Alerts off at once without signing in; your crags stay in your list.

There are no newsletters and no marketing. When you write to [email protected], Friction keeps your message and its reply for as long as it needs them to deal with what you asked.

Cookies

Friction sets only the cookies it needs to work, so it has nothing to ask you to accept:

friction-session
Keeps you signed in, and carries a form’s messages from one page to the next. It ends 2 hours after your last request.
XSRF-TOKEN
Proves that a form was sent from Friction’s own pages, against cross-site request forgery. It lasts as long as the session.
remember_web_…
Only when you tick Keep me signed in, or sign in with Google: keeps you signed in for up to 400 days, or until you sign out.
sidebar_state
For admins only: remembers whether the admin menu is folded. It lasts a week.

Cloudflare may set short-lived security cookies of its own, such as __cf_bm, to tell people from bots. Turnstile, Cloudflare’s check that you are a person, runs in your browser on three forms only: signing up, asking for a password reset link, and signing in after several failed attempts. To check its answer, Friction’s server sends Cloudflare your IP address with it.

Your browser’s session storage also keeps the state of pages you opened, such as where you had scrolled, so that Back returns you there. While you are signed in that copy is encrypted, and its key is thrown away when you sign out or delete your account. It never leaves your browser and is cleared when you close the tab.

Who else handles it

Friction runs on these services, under their terms for handling data:

Cloudflare
Serves friction.co.za and its pictures (stored in Cloudflare R2), so every request passes through it. It runs Turnstile on the account forms (see Cookies), and Cloudflare Access in front of staging.friction.co.za, the private test copy, which only invited testers can open.
Railway
Hosts Friction’s server and its database, where accounts are kept.
Resend
Delivers Friction’s email.
Google
Only when you use Continue with Google or connect Google to your account. Google’s own privacy policy covers your Google account.
OpenRouter
Carries Friction’s requests to the language model that writes the local-knowledge notes on crag pages. They hold weather, crag details and notes on the area, never anything about you: not your account, your crags, your Alerts or your tokens.
World Weather Online
Friction’s server asks it for forecasts by each area’s coordinates. Nothing about you is sent.

Friction does not sell, rent or trade personal information, and it shows no advertising.

Some of these services keep or handle data outside South Africa: Railway’s servers, Resend and Google among them, and Cloudflare runs worldwide. POPIA allows this when the receiver is bound to protect the information as well as POPIA does, or when it is needed to give you the service you asked for, and Friction uses them on those terms.

Why Friction uses it

  • To give you the account you asked for: signing in, Your crags, Alerts and access tokens.
  • To send Alerts, because you switched them on.
  • To keep Friction safe and working: bot checks, rate limits and logs.
  • To answer you when you write.

Friction never uses personal information for advertising, never makes decisions about you by machine, and never gives it to the language model.

How long it is kept

Your account, Your crags and passkeys
Until you delete the account, or ask Friction to. Deleting it removes it from the database at once, with your crags, your Alert records, your passkeys, your access tokens and any password reset link still waiting.
Access tokens
Until you revoke the token or delete the account.
Alert records
90 days.
Sessions
2 hours after your last request; with Keep me signed in, or after signing in with Google, up to 400 days.
Verification and password reset links
Each works for 60 minutes. The record of a reset link nobody used is deleted the night after it stops working.
Rate-limit counts
An hour at most. Failed sign-ins are also counted for a day, to know when to ask for Turnstile: against the IP address they came from and a scrambled form of the email address typed.
Logs
The server’s logs, which can hold an IP address and the address asked for, are kept by Railway for a short time to find faults, then deleted.
Backups
A copy of the database made for recovery can still hold a deleted account until that copy is deleted. Friction never restores one to bring an account back.
Your messages
As long as it takes to deal with what you asked.

Your rights

Under POPIA you may:

  • ask whether Friction holds personal information about you, and for a copy of it (most of it is on your account pages);
  • have it corrected, on your account pages or by asking Friction to;
  • have it deleted, by deleting your account (an account made with Google creates a password on its security page first) or by asking Friction to;
  • object to Friction using it, and take back your consent to Alerts at any time;
  • complain to the Information Regulator.

Write to the information officer at [email protected]. Friction may ask you to confirm a request from your account’s email address, answers within 30 days, and charges nothing.

The Information Regulator is at inforegulator.org.za.

Keeping it safe

Every page is served over HTTPS. Passwords and access tokens are stored only as hashes, and two-factor secrets are encrypted. Two-factor sign-in and passkeys are there for your account: use them. Pages you see signed in are marked so that no cache keeps them. Only the people who run Friction can reach its database. If personal information is ever reached by someone who should not have it, Friction will tell you and the Information Regulator, as POPIA requires.

Condition reports

Condition reports say what the rock was like at a crag at a time. Friction’s admins enter them, and each one records which admin entered it. A public report form may open later; this policy will say what it keeps, such as a name or an email address given with a report, before it does.

Children

Accounts are for people 18 and older. The forecasts need no account.

Changes to this policy

When this policy changes, the date at the top changes with it. When a change affects what an account keeps or why, Friction emails account holders before it takes effect. The terms of use cover the rest of using Friction.