Skip to main content

Legal

Attributions

The services, data sources, open-source libraries, fonts, and photography that power How's the Spot, kept open for licence compliance and general openness.

Last updated:

1. External data & APIs

These are the services How's the Spot contacts at runtime to deliver forecasts, wildlife data, coastline geometry, tides, and approximate location. Each entry notes its licence where one applies.

DB-IP

IP geolocation, via the maxminddb reader against the City Lite .mmdb database. Used to derive an approximate country/region so the Service can surface nearby spots. Licence: CC BY 4.0, attribution required. https://db-ip.com

Open-Meteo

Weather and marine forecasts (wind, swell, visibility, temperature, precipitation, UV). Free for non-commercial use; no API key required. We send location coordinates only. https://open-meteo.com

iNaturalist API

Wildlife species sightings near spots. We send location coordinates and a search radius only. Cached wildlife images carry their own attribution and licence. https://www.inaturalist.org

OpenStreetMap & the Overpass API

Coastline geometry (used to calculate the coastal shelter index) and the map tiles behind Spot maps. Licence: Open Database License (ODbL), attribution required. https://www.openstreetmap.org/copyright · https://overpass-api.de

pyTMD + EOT20 / GOT5.5 tide models

Tide harmonic constituents powering tide times and heights. Underlying models are published by NASA, NOAA, and the EOT20 project; consumed via the pyTMD Python library. https://pytmd.readthedocs.io

2. Photography

Static photography on the homepage is freely licensed and reproduced here in accordance with each image's licence. Where derivatives (resized/cropped variants) are produced via the @nuxt/image pipeline, the share-alike terms of the original are respected.

Licensed landing-page photographs: title, author, licence, and source.
Image Author Licence Source
Cape Range National Park and Ningaloo Reef from the air Andrew Turner CC BY-SA 4.0 Wikimedia Commons
Coral Bay Phil Whitehouse CC BY 2.0 Flickr
CoralBay (WT-shared) Tensaibuta CC BY-SA 1.0 Wikimedia Commons

Spot fallback pool

The spot-fallback photographs that fill the “Conditions right now” grid cards for spots without a image_url are drawn from Unsplash under the Unsplash License (free for commercial and non-commercial use; no attribution required, but credit appreciated).

3. External services

The infrastructure and third-party services How's the Spot depends on to run.

Resend

Transactional email delivery (password resets, notifications). https://resend.com

AWS S3 & DigitalOcean Spaces

S3-compatible object storage for user-uploaded images (avatars, spot photos, community report photos). https://www.digitalocean.com/products/spaces

Google OAuth 2.0

“Sign in with Google” via OpenID Connect (PKCE). We receive and store only the OpenID, email, and profile scope claims needed to create or link your account. Your Google access tokens are never stored.

ALTCHA

Privacy-friendly proof-of-work verification (CAPTCHA) and spam protection. https://altcha.org

DigitalOcean

Hosting: App Platform for the backend service and static frontend, plus Managed PostgreSQL 17 and Managed Valkey 8 (Redis-compatible) for the database and cache. https://www.digitalocean.com

4. Frameworks & libraries

How's the Spot is built on open-source software. The table below lists the major components and their licences; see each project's repository for the authoritative text.

Open-source frameworks and libraries used by How's the Spot, with their licences.
Project Licence
Nuxt 4 MIT
Vue 3 MIT
TypeScript Apache 2.0
Tailwind CSS v4 MIT
FastAPI MIT
SQLAlchemy 2 MIT
Pydantic v2 MIT
Alembic MIT
APScheduler MIT
httpx BSD-3-Clause
PostgreSQL PostgreSQL License
PostGIS GPLv2
Redis / Valkey BSD-3-Clause
Vitest MIT
Playwright Apache 2.0
Heroicons MIT
maxminddb (Python) Apache 2.0
Leaflet BSD-2-Clause

5. Fonts

How's the Spot self-hosts its typefaces: they are not loaded from a third-party font service. Both are released under the SIL Open Font License 1.1, which permits free use, redistribution, and modification with attribution.

  • Sora: the display typeface used for headlines, spot names and data numerals (variable). By Jonathan Barnbrook. Licensed under the SIL Open Font License.
  • Manrope: the interface / body sans-serif (variable). By Mikhail Sharanda.
  • IBM Plex Mono: the data voice — labels, measurements and meta text (400/500/600). By Mike Abbink and the IBM Plex team. Licensed under the SIL Open Font License.

6. A note on the DB-IP attribution

The DB-IP City Lite database is published under Creative Commons Attribution 4.0 (CC BY 4.0), which requires attribution “in a reasonable manner”: naming DB-IP and linking back to the source. DB-IP's own terms go a little further and ask that a visible link appear on any page that surfaces results derived from the database.

This Attributions page satisfies the CC BY 4.0 obligation by naming DB-IP, describing what we use it for, and linking to https://db-ip.com. The Service only ever surfaces approximate, region-level location context (we do not expose raw IP lookups), so a dedicated per-page footer link is not strictly required by the licence. A future enhancement may add one anyway, in the spirit of DB-IP's request.

We do not store or share your precise location from DB-IP lookups, and we never sell data. The database only ever powers an approximate, region-level “nearby spots” hint.

For the authoritative terms, see the DB-IP licence at https://db-ip.com.

7. Questions & contact

If anything here looks incorrect or incomplete (a missing credit, a stale licence, a broken source link), please let us know. The fastest way is to open an issue on the project's GitHub repository. You can also reach the team through the support form:

How's the Spot

Website: https://howsthespot.com

Contact: Support form — legal, privacy, and attribution enquiries all land in the same queue.

See also our Privacy Policy and Terms of Service .