Legal
Attributions
The services, data sources, open-source libraries, fonts, and photography that power How's the Spot — kept open for licence compliance and general openness.
Last updated:
This page is provided for transparency. Nothing here constitutes legal advice; licence obligations should be reviewed against each upstream project's own terms.
1. External data & APIs
These are the services How's the Spot contacts at runtime to deliver forecasts, wildlife data, coastline geometry, tides, and approximate location. Each entry notes its licence where one applies.
DB-IP
IP geolocation, via the maxminddb reader against the City Lite .mmdb database. Used to derive an approximate country/region so the Service can surface nearby spots. Licence: CC BY 4.0 — attribution required. https://db-ip.com
Open-Meteo
Weather and marine forecasts (wind, swell, visibility, temperature, precipitation, UV). Free for non-commercial use; no API key required. We send location coordinates only. https://open-meteo.com
iNaturalist API
Wildlife species sightings near spots. We send location coordinates and a search radius only. Cached wildlife images carry their own attribution and licence. https://www.inaturalist.org
OpenStreetMap & the Overpass API
Coastline geometry (used to calculate the coastal shelter index) and the map tiles behind Spot maps. Licence: Open Database License (ODbL) — attribution required. https://www.openstreetmap.org/copyright · https://overpass-api.de
pyTMD + EOT20 / GOT5.5 tide models
Tide harmonic constituents powering tide times and heights. Underlying models are published by NASA, NOAA, and the EOT20 project; consumed via the pyTMD Python library. https://pytmd.readthedocs.io
2. Photography
Static photography on the homepage is freely licensed and reproduced here in accordance with each image's licence. Where derivatives (resized/cropped variants) are produced via the @nuxt/image pipeline, the share-alike terms of the original are respected.
| Image | Author | Licence | Source |
|---|---|---|---|
| Cape Range National Park and Ningaloo Reef from the air | Andrew Turner | CC BY-SA 4.0 | Wikimedia Commons |
| Coral Bay | Phil Whitehouse | CC BY 2.0 | Flickr |
| CoralBay | (WT-shared) Tensaibuta | CC BY-SA 1.0 | Wikimedia Commons |
Spot fallback pool
The spot-fallback photographs that fill the “Conditions right now” grid cards for spots without a image_url are drawn from Unsplash under the Unsplash License (free for commercial and non-commercial use; no attribution required, but credit appreciated).
3. External services
The infrastructure and third-party services How's the Spot depends on to run.
Resend
Transactional email delivery (password resets, notifications). https://resend.com
AWS S3 & DigitalOcean Spaces
S3-compatible object storage for user-uploaded images (avatars, spot photos, community report photos). https://www.digitalocean.com/products/spaces
Google OAuth 2.0
“Sign in with Google” via OpenID Connect (PKCE). We receive and store only the OpenID, email, and profile scope claims needed to create or link your account — never your Google access tokens.
ALTCHA
Privacy-friendly proof-of-work verification (CAPTCHA) and spam protection. https://altcha.org
DigitalOcean
Hosting: App Platform for the backend service and static frontend, plus Managed PostgreSQL 17 and Managed Valkey 8 (Redis-compatible) for the database and cache. https://www.digitalocean.com
4. Frameworks & libraries
How's the Spot is built on open-source software. The table below lists the major components and their licences; see each project's repository for the authoritative text.
| Project | Licence |
|---|---|
| Nuxt 4 | MIT |
| Vue 3 | MIT |
| TypeScript | Apache 2.0 |
| Tailwind CSS v4 | MIT |
| FastAPI | MIT |
| SQLAlchemy 2 | MIT |
| Pydantic v2 | MIT |
| Alembic | MIT |
| APScheduler | MIT |
| httpx | BSD-3-Clause |
| PostgreSQL | PostgreSQL License |
| PostGIS | GPLv2 |
| Redis / Valkey | BSD-3-Clause |
| Vitest | MIT |
| Playwright | Apache 2.0 |
| Heroicons | MIT |
| maxminddb (Python) | Apache 2.0 |
| Leaflet | BSD-2-Clause |
5. Fonts
How's the Spot self-hosts its typefaces — they are not loaded from a third-party font service. Both are released under the SIL Open Font License 1.1, which permits free use, redistribution, and modification with attribution.
- Inter — the interface / body sans-serif (variable). By Rasmus Andersson.
- Fraunces — the display serif used for headings and the wordmark. By Undercase Type.
6. A note on the DB-IP attribution
The DB-IP City Lite database is published under Creative Commons Attribution 4.0 (CC BY 4.0), which requires attribution “in a reasonable manner” — naming DB-IP and linking back to the source. DB-IP's own terms go a little further and ask that a visible link appear on any page that surfaces results derived from the database.
This Attributions page satisfies the CC BY 4.0 obligation by naming DB-IP, describing what we use it for, and linking to https://db-ip.com. The Service only ever surfaces approximate, region-level location context (we do not expose raw IP lookups), so a dedicated per-page footer link is not strictly required by the licence. A future enhancement may add one anyway, in the spirit of DB-IP's request.
This note is explanatory, not legal advice. For the authoritative terms, see the DB-IP licence at https://db-ip.com.
7. Questions & contact
If anything here looks incorrect or incomplete — a missing credit, a stale licence, a broken source link — please let us know. The fastest way is to open an issue on the project's GitHub repository. You can also reach the team at:
How's the Spot
Website: https://howsthespot.com
Legal & attributions: [email protected]
Privacy: [email protected]
See also our Privacy Policy and Terms of Service .