Signal Collector

Effective from 16 August 2026

Measured data
stays with you.

Signal Collector stores everything it measures in a database inside the phone. It has no accounts and no cloud storage. Measured data leaves only when you send it yourself — and then to a server you have entered yourself. Nothing you measure is ever sent to us or to anyone else.

This page describes version 0.10.0. A detailed list of every recorded field is in the data dictionary.

Who processes the data

The app is operated by Indigo Studio, which is also the controller of any personal data. The contact for questions and for exercising your rights is at the end of this page.

In practice you are the one holding the measured data: the app stores it only in your phone, and the operator has no access to it unless you send it to them yourself.

What the app measures

A measurement runs only when you start it with the Start button and ends with Stop. Every source can be switched off individually beforehand. The following is recorded:

  • Location. GPS and GNSS including satellite status, raw measurements, navigation messages and NMEA sentences. Location is the most sensitive item in the whole record — it describes where you have been.
  • Phone sensors. Accelerometer, gyroscope, magnetometer, barometer, light sensor, proximity and rotation vector.
  • Cellular network. Parameters and identifiers of nearby LTE, 5G, 3G and 2G cells, registration changes and signal strength.
  • SIM card. Slot number, operator name, MCC/MNC network code, roaming state and which card carries the data. Neither ICCID nor EID is recorded — they are permanent subscription numbers that outlive even a change of phone.
  • Wi-Fi. Identifiers and signal of nearby access points (SSID, BSSID), parameters of the current connection and any RTT/FTM ranges.
  • Bluetooth. Bluetooth Classic devices found nearby and the contents of BLE advertising packets around you.
  • Network context. Interface IP addresses, DNS servers, routes, MTU and connectivity changes.
  • Ambient noise. Only an indicative loudness in RMS and dBFS. No audio is stored or transmitted; the microphone samples are discarded once the single number has been computed, and nothing about what could be heard can be recovered from it.

The app does not collect your name, e-mail, phone number, contacts, photos or message contents, and holds no permission to reach them. It creates no user accounts. The only identifier it ever touches is the advertising ID, and only at the moment of a purchase — see third parties.

A record of the phone's surroundings may contain data about other people's devices and networks — the BSSID of someone's home Wi-Fi, say, or the address of someone's Bluetooth headphones. Treat an exported file as a sensitive document.

Where the data sits

Measured data is stored in an SQLite database inside the app's private storage. No other app on the phone can reach it. The data stays in the phone until you delete it yourself with Reset or uninstall the app — uninstalling removes the database and all settings.

Credentials for a server you may have data sent to are encrypted with a key held in the Android Keystore, that is, in the phone's hardware-backed storage. Cloud backup is disabled for the app (allowBackup=false), so neither the measured data nor the passwords end up in a Google backup.

When data leaves the phone

No measured data ever leaves automatically. There are exactly three ways out for it, and you start all of them:

  • Download or Share. An export to a TXT or GZIP file that you save into the phone or pass on through the system share sheet, wherever you choose.
  • Your own destination. The settings accept an S3, WebDAV or SFTP server to send the export to. It is your server or your cloud storage; the operator of the app knows nothing about it and no data passes through them. An address without HTTPS fails validation, and the SFTP server key fingerprint is verified on every upload.
  • Internet mapping and throughput measurement. These optional modules, off by default, transfer small test files to measure the real speed of the link. Only random padding is transferred, never measured data. See third parties.

One message that carries no measured data does leave on its own, and only if you buy the unlock: the purchase report described under third parties.

Third parties

The app contains no analytics, advertising, crash reporting or any other third-party SDK. Measured data is never shared with anyone. Two connections exist beyond the servers you enter yourself:

  • Cloudflare Speedtest (speed.cloudflare.com) acts as the far end for the test HTTPS transfers. Cloudflare sees what any web server sees: your IP address, the time and the size of the transfer. No measured data is sent to them. The module is off by default, and the settings accept your own endpoint in place of Cloudflare.
  • A purchase report. If you buy the unlock, the app sends one message to our own server: which product was bought, for how much, in which currency, the app and Android version, the language of the phone, and your device's advertising ID. We forward that to Meta so we can tell which advertisement led to a purchase. This happens at the moment of purchase and at no other time — if you never buy, your advertising ID never leaves the phone. Nothing about your measuring is ever included: not that a measurement started, not what it recorded, not where you were. The advertising ID can be reset or switched off entirely in Android settings, under Privacy, Ads.

The app is distributed through Google Play. As the store operator, Google processes installation data under its own policies, over which the operator of the app has no influence.

Permissions and why they are needed

The system asks for each sensitive permission only when you switch on a technology that needs it. Refusing one disables that source; the rest of the app carries on.

  • Precise location. Recording the location itself. Without this permission Android also withholds the identifiers of nearby Wi-Fi networks and cells.
  • Microphone. Computing ambient loudness. No audio is stored.
  • Nearby devices and Bluetooth. Discovering Bluetooth devices around you.
  • Phone state. SIM and operator details.
  • Foreground service. So the measurement continues with the screen locked and the system does not stop it. That is exactly why a persistent notification is shown while measuring — collection never runs hidden.
  • Notifications. Showing the state of the measurement, its duration and the record count.

Children

The app is meant for professional measurement work and is not directed at children under 16. The operator does not knowingly collect data about children; given that the data stays in the phone, they have no access with which to collect it.

Your rights

Under the GDPR you have the right of access, rectification, erasure, restriction of processing, portability and the right to object. With this app you exercise them in the phone itself, because we hold no copy of the data anywhere else:

  • Access and portability: the Download button hands over the complete measured data in a machine-readable text format.
  • Erasure: the Reset button deletes the measured data; uninstalling the app also deletes the settings and stored passwords.
  • Restriction of processing: every data source can be switched off individually before a measurement starts.

If you have sent us data yourself and want it deleted, write to the address below. You also have the right to lodge a complaint with a supervisory authority — in the Czech Republic, the Office for Personal Data Protection.

Changes to this policy

If the scope of processing changes, we will update this page and change the effective date at the top. Substantial changes will also be described in the release notes of the version concerned.

Contact

Send privacy questions to privacy@signalcollector.app.

Help: how to measure with the app →