GoatHam

Privacy
policy

GoatHam for Android, iOS and Linux · package com.jcalado.goatham
Effective 17 September 2026. Applies to version 0·1·0 and later.

The short version. GoatHam has no account, no analytics, no advertising and no tracking of any kind. Your log and your position stay on your device. The only thing that leaves it is what you deliberately send to an amateur radio programme: a spot you post, and your callsign attached to the requests the app makes on your behalf.

Who is responsible

GoatHam is made and published by Joel Calado, an individual developer. For anything in this policy, write to apps@jcalado.com.

What stays on your device

All of it is held in the app's own private storage, which other apps cannot read. None of it is uploaded anywhere, and there is no server belonging to GoatHam for it to be uploaded to.

Uninstalling the app deletes all of it. There is no copy elsewhere, so export a backup first if you want to keep your log.

Your position never leaves the device

GoatHam asks for location permission so it can sort spots by distance, show you on the map, and tell you whether you are standing inside a reference's boundary. That is the whole of it.

Your coordinates are used on the device and written only to the device's own database. They are never put into a network request, never sent to the amateur radio programmes, never sent to the map tile server, and never sent to the developer. You can decline the permission and still use the app; you can also set your position by pinning a point on the map or typing a grid square, which needs no permission at all.

What does leave your device

Requests to the amateur radio programmes

To show you spots and reference details, the app fetches data from the programmes themselves:

These requests carry a User-Agent header naming the app, its version, a contact address, and your callsign once you have set one, in the form goatham/0.1.0 (mailto:apps@jcalado.com; op=YOURCALL). This is deliberate and it is the convention these services ask for: it lets the operator of a free, volunteer-run service attribute traffic to a real licensee instead of an anonymous client. Your amateur callsign is already a matter of public record with your national licensing authority. If you have not entered a callsign, the app sends op=anon.

Spots you post

When you self-spot, the app sends to that programme exactly what a spot consists of: your callsign, the reference you are activating, the frequency, the mode, and any comment you typed. Nothing else is attached. Your position is not included even when the app knows it. A spot is a public broadcast by design; that is the point of posting one.

Map tiles

Map tiles come from the OpenStreetMap Foundation at tile.openstreetmap.org. Tile requests reach their servers with your IP address, as any web request does, and are subject to the OSMF privacy policy. These requests deliberately omit your callsign: their usage policy wants one stable identity per application, so every GoatHam user sends the identical string.

Signing in to SOTA

SOTA is the one programme that needs an account before it will accept a spot. If you ever sign in, that happens in your system browser against SOTA's own sign-in service, and GoatHam never sees your password. The resulting tokens are kept in your device's keystore (Keychain on iOS, the Android keystore, libsecret on Linux). No part of this is offered in the current release.

Files you choose to share

Exporting or backing up your log hands an ADIF file to your operating system's own share sheet. Where it goes from there is your choice, and the app is not involved once you have picked a destination.

What the app does not do

Permissions, and why each one exists

Children

GoatHam is a tool for licensed amateur radio operators and is not directed at children. It collects nothing from anyone, children included.

Legal basis and your rights

For operators in the European Economic Area and the United Kingdom: the app stores your data on your own device under your own control, and the only transmission of personal data is the callsign you enter and the spots you choose to post, which is processed on the basis of your consent given by entering it and by pressing the button. You can withdraw it by clearing the callsign field or by not posting.

Because nothing is collected centrally, there is no account to access, correct, export or delete. Your right to erasure is satisfied by deleting the app's data or uninstalling it. Spots already posted are held by the programme you posted them to, and requests about those go to that programme.

Changes

If this policy changes, the effective date above changes with it and the revised text replaces this page. Material changes will be noted in the release notes of the version that introduces them.

Contact

apps@jcalado.com