Privacy Policy — UberSDR Mobile
The UberSDR app for phones and tablets · Last updated 13 August 2026
In short: UberSDR does not have accounts, does not contain advertising, analytics, tracking or crash-reporting components, and its developer operates no server that collects personal information from you. Your list of saved receivers, your settings and any receiver passwords stay on your device. The app is a client for radio receivers run by other people: when you connect to one, that receiver's operator sees your connection in the way any website operator sees a visitor.
1. Who this policy is from
This policy covers the UberSDR mobile application ("the app"), published by the UberSDR project (MadPsy), ubersdr.org. The app is the mobile client for the open-source UberSDR software; its source code is at github.com/madpsy/ka9q_ubersdr, and everything described below can be checked there. The same policy applies to every version of the app, whichever store or platform it was installed from.
It does not cover the individual UberSDR receivers you choose to connect to. Those are run by independent operators — radio amateurs, clubs and enthusiasts — on their own equipment, under their own terms. See section 4.2.
2. No account, no profile, no tracking
- There is no sign-up, no login and no user account for the app itself.
- The app contains no advertising, no analytics, no attribution or measurement SDK, no crash reporter and no third-party tracking libraries. Its only dependencies are the Capacitor runtime and its preferences plugin, both of which run entirely on the device.
- No advertising identifier, device identifier or persistent user identifier is read, generated or transmitted. The app does not track you across other apps or websites, and does not ask for permission to do so.
- No personal information is sold, rented or shared for advertising.
3. What is stored on your device
All of the following is written to the app's private storage on your device. None of it is uploaded to the developer.
| What | Why |
|---|---|
| Your saved receivers — a label, hostname/address, port, public identifier and whether you chose to accept a self-signed certificate for it | So the list you built is there next time, and a link or a search does not have to be repeated |
| Chooser preferences — the tab you were last on, the sort order, and an optional "home" position (latitude/longitude) if you set one | To show receivers in a useful order and to work out how far away they are. Distances are calculated on the device |
| Receiver access passwords, where a receiver requires one and you ask the app to remember it | So it is not typed every time. Each one is encrypted using the operating system's secure key store, with a key that never leaves the device, and is sent only to the receiver it belongs to |
| The radio interface's own settings — panel layout, audio, filters, bookmarks, notification choices, and the display name you type if you use a receiver's chat | Ordinary browser localStorage belonging to the bundled
web interface, kept per receiver |
The app does not read your contacts, calendar, photos, files, call history, messages or installed-app list, and has no permission to do so.
Device backup
The app's storage is included in the standard device backup provided by your platform if you have that turned on — iCloud Backup or Google backup, as applicable. Those backups are held by Apple or Google under their terms rather than ours, and you can exclude the app in your device's backup settings.
4. What leaves your device, and to whom
4.1 The UberSDR directory (instances.ubersdr.org)
To show the list of public receivers, the app makes ordinary HTTPS requests to the project's directory service:
/api/instances— the public list of receivers and current band conditions. Nothing about you or your device is sent with it./api/instances/<id>— the address of one receiver, when you follow anubersdr://connectlink./api/myip— asked at most once per app run, and only if you have not set a home position manually. It returns an approximate location derived from your IP address so that "distance to receiver" can be shown. The result is used on the device; the app does not send your location to the directory, and it never asks the operating system for your precise location.
As with any HTTPS request, the directory necessarily receives your IP address and the app's identifying User-Agent string in order to reply. These may appear in ordinary server logs kept for operating the service and preventing abuse. They are not used to build a profile of you, are not linked to an identity, and are not shared with advertisers.
4.2 Receivers you connect to
Choosing a receiver opens a direct connection from your device to that receiver's server. The operator of that server can see, as any web server can, your IP address, the app's User-Agent, and what you do on their receiver — frequencies and modes you tune, how long you listen, and anything you type into that receiver's chat or logbook features. Many UberSDR receivers show a list of current listeners, and some keep statistics or require a password.
These operators are independent third parties. The developer of this app does not receive, collect or have access to that information, and each operator's own terms and privacy practices apply. Connect only to receivers you are content to be seen by.
4.3 Your local network
The "LAN" tab sends a standard multicast DNS service query
(_ubersdr._tcp) over your local network to find receivers on it. The
query and its replies stay on your network; no information about your network is
sent anywhere else. On platforms that require your consent for local network
access, the app asks the first time you use that feature, and the rest of the app
works without it.
4.4 Other services used by features you choose to open
The bundled radio interface includes optional features that fetch from third parties when — and only when — you use them:
- Maps. Map tiles are loaded from OpenStreetMap
(
tile.openstreetmap.org) when a map is displayed. - News panel. Amateur-radio news headlines are relayed
through
api.rss2json.com. - Callsign links. Tapping a callsign link opens
qrz.comin your browser. - Callsign and operator lookups shown inside a receiver's panels are performed by that receiver's server, not by the app.
Requests to these services carry your IP address to them in the normal way. Their own privacy policies apply.
5. Permissions the app asks for
The app asks for as little as the platform allows, and asks at the moment the feature is used rather than at launch. Nothing here is requested when you first open the app.
| Permission | Why it is needed |
|---|---|
| Network access | To reach the directory and the receivers you select |
| Notifications | The playback notification you stop the receiver from, and the alerts the radio interface raises (your callsign mentioned in chat, a recorder warning, and similar). Asked for when audio starts or when you enable an alert. The app works without it |
| Background audio | To keep a receiver playing, and its lock-screen controls working, while the screen is off or another app is in front. Active only while a receiver is open |
| Local network access | Only for finding receivers on your own network from the "LAN" tab, on platforms that ask |
The app requests no precise or background location, no microphone, no camera, no contacts, no photo library, no health or fitness data, no Bluetooth and no tracking permission.
6. Security
- Traffic to the directory uses HTTPS. Traffic to a receiver uses whatever that receiver offers — many run HTTPS, and receivers on a home network often use plain HTTP or a self-signed certificate.
- If a receiver presents a certificate that cannot be verified, the app says so and connects only if you explicitly choose to trust that receiver. That choice is remembered for that receiver alone.
- Saved receiver passwords are encrypted with a key held in the platform's secure key store — the iOS Keychain or the Android Keystore — hardware backed where the device provides it, and readable only by this app.
- The radio interface is bundled inside the app rather than downloaded, and is served to the receiver view over a loopback connection on the device itself.
7. Retention and deletion
Because the developer holds no data about you, there is nothing to request deletion of from us. Data held on your device is under your control:
- Deleting a receiver from the saved list removes its entry and any password stored for it.
- Your device's app settings offer a way to clear the app's stored data.
- Uninstalling the app removes it all. If device backup is enabled, also remove the app's backup in your iCloud or Google account settings.
Any logs kept by the directory service or by an individual receiver operator are subject to their own retention practices; contact the relevant operator about those.
8. Children
The app is a general-audience amateur-radio tool. It is not directed at children, and it does not knowingly collect personal information from anyone, including children under 13 (or the equivalent age in your jurisdiction).
9. Your rights
Data-protection law — including the UK GDPR and EU GDPR, and the CCPA in California — gives you rights of access, correction, deletion, portability and objection over personal data held about you. The developer of this app holds no such data, so those rights are satisfied in practice by your control of the device as described in section 7. If you believe otherwise, contact us using the details below and we will respond.
10. Changes to this policy
If the app's behaviour changes in a way that affects this policy, the policy is updated and the date at the top changes with it. Previous versions are visible in the project's public source history.
11. Contact
Questions about this policy or about the app:
- Website: ubersdr.org
- Issues: github.com/madpsy/ka9q_ubersdr/issues