Privacy policy
Last updated .
In short
- You can read every forecast without an account. Friction runs no analytics and no advertising, and sets no tracking cookies.
- An account keeps your name, your email address, how you sign in, the crags you keep under Your crags, whether you want Alerts, and any access tokens you make.
- Friction emails you only what you ask for: the link to verify your address, password resets, and the Alerts you switch on.
- Your personal information never goes to the language model that writes local knowledge, and it is never sold.
- Delete your account whenever you like (an account made with Google creates a password first), and everything it keeps goes with it.
- Ask what Friction holds about you, or anything else, at [email protected].
Who is responsible
Friction follows South Africa’s Protection of Personal Information Act (POPIA). The responsible party decides why and how Friction uses personal information:
- [email protected]
The information officer deals with requests and complaints about personal information:
- [email protected]
Reading forecasts
Every area and crag page is open to anyone, without an account.
- Your browser’s request passes through Cloudflare, which serves friction.co.za, to Friction’s server at Railway. Like any web server, they see your IP address, your browser and the address you asked for.
- Friction keeps no history of what you read and builds no profile of you. It runs no analytics and no advertising, and its fonts come from its own server.
- It sets the two cookies a site with forms needs, a session cookie and a CSRF cookie (see Cookies). Without an account the session holds nothing about you.
- When many requests come from one IP address in a short time, Friction counts them, for an hour at most, to slow them down.
What an account keeps
An account is for keeping your own crags and Alerts, and for using Friction from your agents. It keeps:
- Your name and email address
- The name you give, the address Friction writes to, and when you verified it. A new address you ask for is kept beside it, and becomes your address only once you open the link Friction sends there.
- Your password
- Stored only as a one-way hash that cannot be turned back into it. An account made with Google starts with a random password that nobody knows, until you create your own.
- Two-factor sign-in
- If you turn it on, its secret and its recovery codes, encrypted.
- Passkeys
- For each one, its public key, the name you give it (Friction suggests your browser and device, such as Safari on iPhone), which passkey manager holds it, as your device reports it, and when it was last used. The private key, and your fingerprint or face, never reach Friction.
- Google sign-in
- If you choose Continue with Google, or connect Google on your security page, Google tells Friction your Google account’s ID, your email address, whether Google has verified it, and your name. Friction keeps the ID, to know you next time. It uses the address to find your account, or to make a new one, and the name for a new account, or for an account whose address was never verified, which your Google sign-in proves is yours. It keeps no picture, no contacts and no Google access token, and it cannot see into your Google account. Disconnect Google on your security page and the ID goes.
- Staying signed in
- A random token that keeps you signed in on one browser, when you tick Keep me signed in or sign in with Google (see Cookies).
- Your crags
- The crags you keep as Favourites, and for each one whether its Alerts are on.
- Alerts
- A record of each Alert email: the day, the crags and best windows it listed, the forecasts it read, and whether it was sent.
- Access tokens
- The name you give each access token (an account keeps ten at most), a hash of the token, and when it was last used. Friction shows you the token itself once, on the page after you make it, and keeps only its hash.
- Dates
- When the account was made and last changed.
Friction sends three kinds of email, all through Resend, which delivers them and so handles your address and the message:
- the link to verify your address, when you sign up or change it; it works for 60 minutes;
- a link to reset your password, when you ask for one; it works for 60 minutes;
- Alerts, only when you switch them on for a crag and your address is verified: at most one a day, after the evening forecast, listing each of your crags with a best window tomorrow. Every Alert has a link, and your mail app may show an Unsubscribe button, that switches all your Alerts off at once without signing in; your crags stay in your list.
There are no newsletters and no marketing. When you write to [email protected], Friction keeps your message and its reply for as long as it needs them to deal with what you asked.
Who else handles it
Friction runs on these services, under their terms for handling data:
- Cloudflare
- Serves friction.co.za and its pictures (stored in Cloudflare R2), so every request passes through it. It runs Turnstile on the account forms (see Cookies), and Cloudflare Access in front of staging.friction.co.za, the private test copy, which only invited testers can open.
- Railway
- Hosts Friction’s server and its database, where accounts are kept.
- Resend
- Delivers Friction’s email.
- Only when you use Continue with Google or connect Google to your account. Google’s own privacy policy covers your Google account.
- OpenRouter
- Carries Friction’s requests to the language model that writes the local-knowledge notes on crag pages. They hold weather, crag details and notes on the area, never anything about you: not your account, your crags, your Alerts or your tokens.
- World Weather Online
- Friction’s server asks it for forecasts by each area’s coordinates. Nothing about you is sent.
Friction does not sell, rent or trade personal information, and it shows no advertising.
Some of these services keep or handle data outside South Africa: Railway’s servers, Resend and Google among them, and Cloudflare runs worldwide. POPIA allows this when the receiver is bound to protect the information as well as POPIA does, or when it is needed to give you the service you asked for, and Friction uses them on those terms.
Why Friction uses it
- To give you the account you asked for: signing in, Your crags, Alerts and access tokens.
- To send Alerts, because you switched them on.
- To keep Friction safe and working: bot checks, rate limits and logs.
- To answer you when you write.
Friction never uses personal information for advertising, never makes decisions about you by machine, and never gives it to the language model.
How long it is kept
- Your account, Your crags and passkeys
- Until you delete the account, or ask Friction to. Deleting it removes it from the database at once, with your crags, your Alert records, your passkeys, your access tokens and any password reset link still waiting.
- Access tokens
- Until you revoke the token or delete the account.
- Alert records
- 90 days.
- Sessions
- 2 hours after your last request; with Keep me signed in, or after signing in with Google, up to 400 days.
- Verification and password reset links
- Each works for 60 minutes. The record of a reset link nobody used is deleted the night after it stops working.
- Rate-limit counts
- An hour at most. Failed sign-ins are also counted for a day, to know when to ask for Turnstile: against the IP address they came from and a scrambled form of the email address typed.
- Logs
- The server’s logs, which can hold an IP address and the address asked for, are kept by Railway for a short time to find faults, then deleted.
- Backups
- A copy of the database made for recovery can still hold a deleted account until that copy is deleted. Friction never restores one to bring an account back.
- Your messages
- As long as it takes to deal with what you asked.
Your rights
Under POPIA you may:
- ask whether Friction holds personal information about you, and for a copy of it (most of it is on your account pages);
- have it corrected, on your account pages or by asking Friction to;
- have it deleted, by deleting your account (an account made with Google creates a password on its security page first) or by asking Friction to;
- object to Friction using it, and take back your consent to Alerts at any time;
- complain to the Information Regulator.
Write to the information officer at [email protected]. Friction may ask you to confirm a request from your account’s email address, answers within 30 days, and charges nothing.
The Information Regulator is at inforegulator.org.za.
Keeping it safe
Every page is served over HTTPS. Passwords and access tokens are stored only as hashes, and two-factor secrets are encrypted. Two-factor sign-in and passkeys are there for your account: use them. Pages you see signed in are marked so that no cache keeps them. Only the people who run Friction can reach its database. If personal information is ever reached by someone who should not have it, Friction will tell you and the Information Regulator, as POPIA requires.
Condition reports
Condition reports say what the rock was like at a crag at a time. Friction’s admins enter them, and each one records which admin entered it. A public report form may open later; this policy will say what it keeps, such as a name or an email address given with a report, before it does.
Children
Accounts are for people 18 and older. The forecasts need no account.
Changes to this policy
When this policy changes, the date at the top changes with it. When a change affects what an account keeps or why, Friction emails account holders before it takes effect. The terms of use cover the rest of using Friction.