Effective from 4 September 2026
Privacy
Measured data
stays with you.
Signal Collector stores everything it measures in a database inside the phone. It has no accounts and no cloud storage. Measured data leaves only when you send it yourself — and then to a server you have entered yourself. Nothing you measure reaches us unless you type in the credentials to our demo server, and what lands there stays unlisted, deletes itself on a timer, and is published only if you say so.
This page describes version 1.5.0. A detailed list of every recorded field is in the data dictionary.
Set for paper: no colour fills, no navigation. The same dialog saves it as a PDF.
Who processes the data
The app is operated by Indigo Studio, which is also the controller of any personal data. The contact for questions and for exercising your rights is at the end of this page.
In practice you are the one holding the measured data: the app stores it only in your phone, and the operator has no access to it unless you send it to them yourself.
What the app measures
A measurement runs only when you start it with the Start button and ends with Stop. Every source can be switched off individually beforehand. The following is recorded:
- Location. GPS and GNSS including satellite status, raw measurements, navigation messages and NMEA sentences. Location is the most sensitive item in the whole record — it describes where you have been.
- Phone sensors. Accelerometer, gyroscope, magnetometer, barometer, light sensor, proximity and rotation vector.
- Cellular network. Parameters and identifiers of nearby LTE, 5G, 3G and 2G cells, registration changes and signal strength.
- SIM card. Slot number, operator name, MCC/MNC network code, roaming state and which card carries the data. Neither ICCID nor EID is recorded — they are permanent subscription numbers that outlive even a change of phone.
- Wi-Fi. Identifiers and signal of nearby access points (SSID, BSSID), parameters of the current connection and any RTT/FTM ranges.
- Bluetooth. Bluetooth Classic devices found nearby and the contents of BLE advertising packets around you. Where such a packet is a reading broadcast in a publicly described format — a thermometer, a hygrometer, an air-quality meter — the reading is also written down as a named value in SI units. Nothing is paired with and nothing is connected to. The app only listens.
- Network context. Interface IP addresses, DNS servers, routes, MTU and connectivity changes.
- Ambient noise. Only an indicative loudness in RMS and dBFS. The noise source stores no audio. The microphone samples are discarded once the single number has been computed, and nothing about what could be heard can be recovered from it. A voice note at a survey point is a different thing entirely, and it is described below.
- Sound probe. A tool you start by hand, in which one phone beeps and another listens, so that you can tell where sound carries in a building. While it listens, the app measures the loudness, the brightness of the sound and the level of three known tones in windows of about a tenth of a second, and writes those numbers into the loose notebook. The sound probe stores no audio either — the recording buffer is overwritten again and again and never leaves the app. It does keep more numbers than the noise source does, so what it writes down is a rough sketch of a sound rather than only its loudness. Speech cannot be reconstructed from it, but it can tell a spoken sentence apart from a door slamming. It describes how sound carries through a place, not what was said in it.
- Photos and voice notes at a survey point. Only when you take them. A point you mark can carry a photo taken through the app's own viewfinder, or a recording of up to ten minutes that you start and stop yourself. Both are made by you, inside the app: the camera opens only on that screen, the recording only after you press record, and neither runs during an ordinary measurement. A photo is what stood in front of the lens and a recording is what could be heard while it ran — treat both as the sensitive documents they are.
The app does not collect your name, e-mail, phone number, contacts, message contents or the photos in your gallery, and holds no permission to reach them. The photos and recordings it does hold are only the ones you take at a survey point. It reads nothing from the phone's own gallery and writes nothing into it. It creates no user accounts. It touches no device identifier at all — not even the advertising ID.
A record of the phone's surroundings may contain data about other people's devices and networks — the BSSID of someone's home Wi-Fi, say, or the address of someone's Bluetooth headphones. Treat an exported file as a sensitive document.
Where the data sits
Measured data is stored in an SQLite database inside the app's private storage. No other app on the phone can reach it. The data stays in the phone until you delete it yourself with Reset or uninstall the app — uninstalling removes the database and all settings.
Photos and voice notes taken at a survey point sit in the same private storage, as ordinary files beside the database. They are not written into the phone's gallery and no other app passes them through — the app carries its own viewfinder precisely so that a photo never travels through anything else. Reset deletes them together with the measurements.
Credentials for a server you may have data sent to are encrypted with a key held in the Android Keystore, that is, in the phone's hardware-backed storage. Cloud backup is disabled for the app (allowBackup=false), so neither the measured data nor the passwords end up in a Google backup.
When data leaves the phone
No measured data ever leaves automatically. There are exactly four ways out for it, and you start all of them:
- Download or Share. An export to a TXT or GZIP file that you save into the phone or pass on through the system share sheet, wherever you choose. A measurement that carries photos or voice notes leaves as a single
tar.gzinstead, with the media in amedia/folder next to the text — an export is the one and only way they get out of the app. - Your own destination. The settings accept an S3, WebDAV or SFTP server to send the export to. It is normally your server or your cloud storage, and then the operator of the app knows nothing about it and no data passes through them. The one destination we run ourselves is the demo server, and it too only ever receives what you send it after entering its credentials yourself. An unencrypted address is accepted only towards your own network, with a warning beneath the field, and the SFTP server key fingerprint is verified on every upload.
- A slice from the record browser. The browser can hand an excerpt of the rows you filtered to another app as text, with a header saying which measurement and which filter it came from. It is the same share sheet as an export, only smaller — and it goes nowhere until you pick the app it goes to.
- Internet mapping and throughput measurement. These optional modules, off by default, transfer small test files to measure the real speed of the link. Only random padding is transferred, never measured data. See third parties.
After a paid unlock, the app sends its Google Play purchase token to signalcollector.app once so the purchase can receive its included gift code. The server verifies the token with Google Play, stores only its SHA-256 fingerprint and assigns one unused Play promo code. No measured data, name, e-mail or device identifier goes with it.
A settings backup is not one of those four either, and it carries no measured data — but it can carry passwords. You write it yourself, from the settings menu, and choose whether the server and Wi-Fi passwords go into it. Those leave only after a fingerprint, a face or the screen lock confirms it is you. The file is readable text, so a backup with passwords in it is kept the way the passwords themselves are kept. The licence and the free hour never travel in it.
Feedback sent from inside the app is not one of those four, and not automatic either: the app hands the text, the app version, the Android version, the phone model and any pictures you attached to your own mail app, where you read it over and press send yourself. No measured data goes with it unless you attach it.
The demo server
Sending to a server assumes you have one. So that the feature can be tried without owning one, we run a demo server at signalcollector.app/demo. It is one of the destinations above and nothing else: the app does not know it exists, nothing points at it by default, and it receives a measurement only after you enter its credentials yourself or drop a file on the page yourself.
For measurements sent there, we are the controller — the same as any other server operator you would have chosen. Concretely:
- What we hold. The exported file exactly as your phone sent it, plus the facts from its header — duration, number of records, distance walked, phone model, which sources were recording. No account, no name, no e‑mail, no device identifier.
- How long. Thirty days, and sooner if the demo runs out of space: the oldest unpublished measurements are deleted first, without asking. Do not send anything you would mind losing.
- Who can see it. Nobody but the people you give the link to. Every upload is unlisted, its address is unguessable, and the page is kept out of search engines.
- Publication needs your word first. Nothing appears in the public log unless you press the button that says so, on the page of that one measurement, after you have seen what is in it. Your consent puts it in a queue, and a person here still reviews it before it goes out.
- You can take it back. Withdraw the consent or delete the measurement at any time, using the key you were given when you uploaded it. We can also remove any published measurement at any time.
- Photos and voice notes are never published, whatever you allow. A measurement bundle with media has no preview and stays unlisted.
Worth knowing before you press publish: a measurement is not only signal strength. It carries a GPS track, the names and addresses (BSSIDs) of the Wi‑Fi networks around you, the addresses of nearby Bluetooth devices and cell identifiers — that is, facts about places and equipment that are not yours. The preview on the site never draws those identifiers, but the file itself, which a published measurement offers for download, does contain them. That is why publishing takes two steps and why we look at each one.
Third parties
The app contains no analytics, advertising, attribution or crash-reporting SDK. The complete list of libraries it is built from is below. We share measured data with no one. The only measurements that ever become public are the ones you explicitly allow us to show on the demo page. Two connections exist beyond the servers you enter yourself:
- Cloudflare Speedtest (
speed.cloudflare.com) acts as the far end for the test HTTPS transfers. Cloudflare sees what any web server sees: your IP address, the time and the size of the transfer. No measured data is sent to them. The module is off by default, and the settings accept your own endpoint in place of Cloudflare. - Gift-code verification (
signalcollector.app) receives the Google Play purchase token after a paid unlock, verifies it with Google and returns one promo code. The full token is not stored — only its SHA-256 fingerprint remains so repeated requests return the same code.
The voice note on this website is recorded by the browser and stays in it. The page has no address to send it to and no server behind the key: the finished recording either goes into the system share sheet, from which you pick your own mail app, or is saved as a file that you attach to a mail yourself. The microphone opens when you press the key and closes the moment you stop. Nothing is recorded before that.
This website counts its visits with Cloudflare Web Analytics. The script sets no cookies, uses no browser storage and builds no device fingerprint. It reports the page, the referring site, the browser family and the country derived from the IP address, which Cloudflare does not store. There is nothing to consent to and nothing to opt out of, and an ad blocker simply stops it.
The app is distributed through Google Play. As the store operator, Google processes installation data under its own policies, over which the operator of the app has no influence.
What foreign code is in the app
An app is rarely written from end to end by the people who publish it. Here is every library this one is built from, and the list is the whole of it:
- AndroidX and Jetpack Compose — the interface. Google, open source.
- Room — the database the measured data sits in. Google, open source.
- The Kotlin runtime — the language the app is written in. JetBrains, open source.
- Google Play Billing — the one-off purchase that unlocks the full version. The store requires it for anything sold through it.
- JSch — the SSH client behind the SFTP upload. It runs only when you have entered an SFTP server yourself. Open source.
Not one of them is there to collect anything. The app carries no analytics, advertising, attribution or crash-reporting library, and none will be added. A library like that is foreign code running in the same process and with the same permissions as the rest of the app, and it takes its instructions from a server that is not ours. In an app whose whole point is that your measurements stay in the phone, that is a bad trade at any price.
Every library sits at an exact version number written into the source, and comes from Google's Maven repository or from Maven Central. Nothing updates on its own: what is in the app changes only when we change that number and publish a new version — and a version that changes what leaves the phone says so in its release notes.
One piece is not ours to pin, and we would rather say so than claim a guarantee we cannot give. Google Play services — which the billing library reaches through the system — live in the phone, are updated by Google independently of our releases, and can load parts of themselves into any app that uses them, this one included. That is the price of selling through the store. The promise above is about what we put into the app, not about what Google ships into the phone.
Permissions and why they are needed
The system asks for each sensitive permission only when you switch on a technology that needs it. Refusing one disables that source and the rest of the app carries on.
- Precise location. Recording the location itself. Without this permission Android also withholds the identifiers of nearby Wi-Fi networks and cells.
- Microphone. Computing ambient loudness, where no audio is stored, listening for the sound probe when you start it, where no audio is stored either, and recording a voice note at a survey point when you start one — that recording is kept as a file until you delete it.
- Camera. Taking a photo at a survey point through the app's own viewfinder. It opens only on that screen and never during an ordinary measurement.
- Fingerprint, face or screen lock. Confirming it is you before passwords are taken out of a settings backup, or put back from one.
- Nearby devices and Bluetooth. Discovering Bluetooth devices around you.
- Phone state. SIM and operator details.
- Foreground service. So the measurement continues with the screen locked and the system does not stop it. That is exactly why a persistent notification is shown while measuring — collection never runs hidden.
- Notifications. Showing the state of the measurement, its duration and the record count.
Children
The app is meant for professional measurement work and is not directed at children under 16. The operator does not knowingly collect data about children, and given that the data stays in the phone, they have no access with which to collect it.
Your rights
Under the GDPR you have the right of access, rectification, erasure, restriction of processing, portability and the right to object. With this app you exercise them in the phone itself, because we hold no copy of the data anywhere else:
- Access and portability: the Download button hands over the complete measured data in a machine-readable text format.
- Erasure: the Reset button deletes the measured data, including the photos and voice notes taken at survey points. Uninstalling the app also deletes the settings and stored passwords.
- Restriction of processing: every data source can be switched off individually before a measurement starts.
If you have sent us data yourself and want it deleted, write to the address below. You also have the right to lodge a complaint with a supervisory authority — in the Czech Republic, the Office for Personal Data Protection.
Changes to this policy
If the scope of processing changes, we will update this page and change the effective date at the top. Substantial changes will also be described in the release notes of the version concerned.
Contact
Send privacy questions to privacy@signalcollector.app.