Privacy
policy
The short version. GoatHam has no account, no analytics, no advertising and no tracking of any kind. Your log and your position stay on your device. The only thing that leaves it is what you deliberately send to an amateur radio programme: a spot you post, and your callsign attached to the requests the app makes on your behalf.
Who is responsible
GoatHam is made and published by Joel Calado, an individual developer. For anything in this policy, write to apps@jcalado.com.
What stays on your device
All of it is held in the app's own private storage, which other apps cannot read. None of it is uploaded anywhere, and there is no server belonging to GoatHam for it to be uploaded to.
- Your log. Every contact you record: callsign, time, band, mode, signal reports, references credited and your own notes.
- Your settings. Your callsign, your chosen position, starred references, filters, alert rules and language.
- Downloaded reference lists. The parks, summits and towers you fetch for offline use, and cached responses from the programme feeds.
- Your position. See the separate section below.
Uninstalling the app deletes all of it. There is no copy elsewhere, so export a backup first if you want to keep your log.
Your position never leaves the device
GoatHam asks for location permission so it can sort spots by distance, show you on the map, and tell you whether you are standing inside a reference's boundary. That is the whole of it.
Your coordinates are used on the device and written only to the device's own database. They are never put into a network request, never sent to the amateur radio programmes, never sent to the map tile server, and never sent to the developer. You can decline the permission and still use the app; you can also set your position by pinning a point on the map or typing a grid square, which needs no permission at all.
What does leave your device
Requests to the amateur radio programmes
To show you spots and reference details, the app fetches data from the programmes themselves:
- POTA, at
api.pota.appandpota.app - SOTA, at
api-db2.sota.org.uk,sso.sota.org.ukandstorage.sota.org.uk - WWFF, at
wwff.coandspots.wwff.co - TOTA, at
wwtota.comandrozhledny.eu
These requests carry a User-Agent header naming the app, its
version, a contact address, and your callsign once you have set one,
in the form goatham/0.1.0 (mailto:apps@jcalado.com; op=YOURCALL).
This is deliberate and it is the convention these services ask for: it
lets the operator of a free, volunteer-run service attribute traffic to a
real licensee instead of an anonymous client. Your amateur callsign is
already a matter of public record with your national licensing authority.
If you have not entered a callsign, the app sends op=anon.
Spots you post
When you self-spot, the app sends to that programme exactly what a spot consists of: your callsign, the reference you are activating, the frequency, the mode, and any comment you typed. Nothing else is attached. Your position is not included even when the app knows it. A spot is a public broadcast by design; that is the point of posting one.
Map tiles
Map tiles come from the OpenStreetMap Foundation at
tile.openstreetmap.org. Tile requests reach their servers with
your IP address, as any web request does, and are subject to the
OSMF privacy policy.
These requests deliberately omit your callsign: their usage policy
wants one stable identity per application, so every GoatHam user sends the
identical string.
Signing in to SOTA
SOTA is the one programme that needs an account before it will accept a spot. If you ever sign in, that happens in your system browser against SOTA's own sign-in service, and GoatHam never sees your password. The resulting tokens are kept in your device's keystore (Keychain on iOS, the Android keystore, libsecret on Linux). No part of this is offered in the current release.
Files you choose to share
Exporting or backing up your log hands an ADIF file to your operating system's own share sheet. Where it goes from there is your choice, and the app is not involved once you have picked a destination.
What the app does not do
- No analytics, telemetry or usage measurement of any kind.
- No crash or diagnostic reporting to the developer.
- No advertising, no ad identifiers, no advertising networks.
- No third party tracking or profiling SDKs. The app bundles none, and the full list of its libraries is public in the source.
- No account, no sign-up, no email address, no contacts, no photos, no microphone, no camera.
- No selling or sharing of personal information. There is nothing collected to sell.
Permissions, and why each one exists
- Internet. Fetching spots, reference data and map tiles, and posting spots you choose to post.
- Location, fine and coarse. Distance to references, your marker on the map, and the boundary check. Optional, and never transmitted.
- Notifications. Alerting you when a spot matches a rule you wrote. Notifications are generated on the device. There is no push service and no server sending them.
Children
GoatHam is a tool for licensed amateur radio operators and is not directed at children. It collects nothing from anyone, children included.
Legal basis and your rights
For operators in the European Economic Area and the United Kingdom: the app stores your data on your own device under your own control, and the only transmission of personal data is the callsign you enter and the spots you choose to post, which is processed on the basis of your consent given by entering it and by pressing the button. You can withdraw it by clearing the callsign field or by not posting.
Because nothing is collected centrally, there is no account to access, correct, export or delete. Your right to erasure is satisfied by deleting the app's data or uninstalling it. Spots already posted are held by the programme you posted them to, and requests about those go to that programme.
Changes
If this policy changes, the effective date above changes with it and the revised text replaces this page. Material changes will be noted in the release notes of the version that introduces them.