# Privacy Policy **Last updated:** September 9, 2026 ## Overview HTCommander ("the App") is a local-first amateur radio application. Its core radio-control and decoding features operate on your device. The App does not include advertising, user tracking, or usage analytics, and the HTCommander project does not sell personal information. Cloud and server integrations are disabled by default on a new installation. They do not connect until you enable or configure the relevant feature. Features that can transmit radio signals and features that share location are also disabled by default. Some functions make network requests when you explicitly use them, such as viewing online map tiles, searching an online directory, downloading data or speech models, importing a channel from a website, or checking for application, firmware, or database updates. ## Information Stored on Your Device Depending on the features you use, the App may store the following locally: - Your call sign, station ID, radio settings, and application preferences - Channels, contacts, messages, mail, attachments, packet captures, and downloaded map or radio data - Location information received from a connected radio, serial GPS, device location service, or a location entered manually - Credentials and API tokens that you provide for optional services - Diagnostic and crash logs generated by the App This information remains under your control on your device unless you enable an integration, connect to another system, transmit it by radio, export it, or choose to share it. Storage protection depends on the platform and feature. Where supported, designated secrets may be stored using the operating system's native secure-storage facility. ## Permissions The App may request access to Bluetooth, nearby devices, the microphone, notifications, location, files, or local-network services. These permissions are used only to provide features you select, such as connecting to a radio, processing audio, showing your position, opening or saving files, receiving notifications, or running a local server. You can manage these permissions in your operating system settings. Granting a device permission does not by itself enable an optional cloud or server integration. ## Optional Cloud and Server Features The following integrations require you to enable, configure, or actively use them: - **APRS-IS:** When enabled, the App connects to the configured APRS-IS server and sends the call sign, station ID, application identifier, authentication passcode, filters, and APRS packets needed to provide the service. APRS traffic may include message content, telemetry, and location information. - **APRS push notifications:** When enabled on a supported mobile platform, the App registers with `aprs.meshcentral.com`. Registration includes the call sign and station ID, an APRS-derived authentication value, and an Apple Push Notification service (APNs) or Firebase Cloud Messaging (FCM) device token. The service processes messages and limited profile information needed to deliver notifications and message backlog. Apple, Google, and Firebase may also process notification metadata under their own policies. - **APRS.fi:** When you provide an API key and use message backfill or testing, the App sends the API key and requested call sign or query information to APRS.fi. - **RepeaterBook:** When you provide an API token and perform a search, the App sends the token and search parameters, which may include a location or region, to RepeaterBook. - **Online maps:** When you view or download online maps, the App requests map tiles from OpenStreetMap infrastructure. Tile coordinates reveal the geographic area being viewed, and the provider receives normal network metadata such as your IP address. - **Winlink, EchoLink, AllStarLink, and proxy services:** When you configure and use these services, the App sends the identifiers, credentials, messages, attachments, audio, and connection information required by the selected service or gateway. - **Home Assistant and MQTT:** When enabled, the App connects to the server you configure and exchanges the radio state, events, credentials, and commands needed for that integration. - **Local web and AGWPE servers:** When enabled, the App listens for network connections on your device. Connected clients may access radio controls, audio, packets, and other information exposed by those protocols. These servers are disabled by default and should be enabled only on trusted networks. - **Aircraft, satellite, callsign, model, firmware, and application data:** When you enable the relevant feature or request an update or download, the App contacts the configured server or public data provider. Requests normally include the requested resource and standard network metadata. Location may be sent when it is part of a search or server URL you selected. - **Web imports and external links:** When you import from a website or open an external link, that website receives the request and standard browser or network metadata. Radio transmissions are public by nature and may contain your call sign, message content, telemetry, or location. They can be received, recorded, relayed, and published by other stations and internet gateways. The privacy practices of amateur-radio networks and independently operated servers are outside the HTCommander project's control. ## Diagnostics and Crash Reports The App does not automatically upload analytics, crash reports, or diagnostic logs to the HTCommander project. Diagnostic and crash logs are stored locally. They are shared only when you choose to copy, export, or submit them. Review logs before sharing because they may contain call signs, server addresses, radio activity, or other operational information. ## Data Sharing and Third Parties The HTCommander project does not sell personal information and does not share information for advertising or cross-service tracking. Information is sent to third parties only when needed for a feature you enable or an action you request. Third-party and community-operated services have their own privacy, security, logging, and retention practices. The HTCommander project does not control those services. Before enabling an integration, review the policies of its operator. Standard network metadata, including your IP address, may be visible to every server you contact. ## Your Choices and Data Retention You can keep cloud and server integrations inactive by leaving them disabled, which is the default. You can later disable an integration, remove its credentials, revoke device permissions, clear App data using your operating system, or uninstall the App. Locally stored information remains until you delete it, clear the App's data, or uninstall the App, subject to operating-system backup behavior. Disabling a service stops future use by the App apart from any request needed to disconnect or unregister. It may not delete information already transmitted to a radio network, server, push provider, backup, or third party. Retention and deletion of that information are governed by the receiving operator. ## Children's Privacy The App is not directed to children under 13, and the HTCommander project does not knowingly collect personal information from children. Optional third-party services may impose their own age requirements. ## Security We take reasonable measures to keep App data local and limit network activity to enabled features and requested actions. No storage or transmission method is completely secure. Protect your device, radio, credentials, exported files, and any local servers you enable. ## Changes to This Policy We may update this Privacy Policy from time to time. Any changes will be posted in this file with an updated revision date. ## Contact For questions about this Privacy Policy, open an issue in the [HTCommander GitHub repository](https://github.com/Ylianst/HTCommander/issues). Do not include passwords, API tokens, private messages, precise locations, or other sensitive information in a public issue.