Effective date: August 8, 2026
Publisher: Civil Radar
Privacy contact: https://docs.google.com/forms/d/e/1FAIpQLSdHrwZsKBc1d3d0L-9woI4dQqCx0Lhll3z9u5KX7xX_EuYRAg/viewform?usp=header
Civil Radar is a local-first Bluetooth Low Energy (BLE) awareness, calibration, mapping, and investigative-notebook application for Android. This policy explains what information the app accesses, where it is processed, how long it is retained, and the controls available to the user.
Summary
- Civil Radar does not require a Civil Radar account.
- Civil Radar does not contain advertising SDKs.
- Civil Radar does not sell personal or sensitive information.
- Civil Radar does not upload the user's BLE history, notes, emergency audio, Home Anchor, or evidence reports to a developer-operated server.
- Most application data is processed and stored locally on the user's Android device.
- The optional Google Map uses Google Maps Platform, which processes limited technical and map-usage data as described below.
- Optional Mesh mode sends session observations directly between user-paired receivers on the same local network.
- Evidence leaves the app only when the user deliberately invokes Android's share sheet and chooses a destination.
Information Civil Radar accesses
Nearby Bluetooth information
Civil Radar scans BLE advertisements visible to the user's device. Records may include a Bluetooth address or random address, advertised device name, manufacturer data, service identifiers, RSSI, transmitted-power information when advertised, PHY/channel-related information exposed by Android, first/last-seen times, observation counts, and estimated motion or fade state.
BLE identifiers can be randomized or rotated by transmitting devices. Civil Radar's labels and classifications are estimates and do not establish a person's identity, intent, precise position, speed, floor, vehicle status, or ownership.
Nearby Wi-Fi information
After site calibration, the optional anomaly layer compares visible Wi-Fi access-point identifiers (BSSID), network names when Android exposes them, signal strength, and first/last-seen timing against the locally stored origin baseline. Wi-Fi observations appear only in the Anomalies view. A solid diamond records a timing correlation when a locked BLE advertisement drops suddenly while an unmatched access point is visible. This does not identify a person, client device, owner, intent, or threat. Wi-Fi observations and the origin baseline remain local and are removed by Delete BLE History & Target Data or Delete All Data & Recordings.
Location and device sensors
When the user grants permission, Civil Radar uses receiver latitude, longitude, altitude, accuracy, speed/course, and available compass, orientation, pressure, temperature, and humidity sensors. These support Home Anchor detection, perimeter calibration, receiver orientation, local map display, and optional Mesh calculations.
The Home Anchor is stored locally as coordinates selected by the user. Android backup and device-transfer backup are disabled for Civil Radar.
Microphone and emergency audio
Civil Radar accesses the microphone only for a user-initiated Lockdown/Passive Sonar session after an in-app disclosure and Android permission. The app records local AAC audio and derives basic loudness/anomaly timestamps. It cannot identify a person, footsteps, lockpicking, broken glass, criminal intent, or a specific threat from sound.
Emergency audio is retained for 14 days by default. Expired recordings are removed when the scanning service starts and during a daily retention sweep. The user may delete all Lockdown audio immediately from Control → Privacy & Data Controls. Deleting audio during an active session stops microphone recording.
User-entered information
The user may enter tags, notes, investigative minutes, flags, floor observations, building/context descriptions, pairing overrides, and a local Last/Emergency Message. This information remains on the device until the user deletes the applicable category or chooses Delete All Data & Recordings.
Generated evidence exports
Civil Radar can create a local JSON report containing selected signal records, timestamps, receiver data, notes, flags, and acoustic-event summaries. Audio is not automatically attached. The app opens Android's share sheet only after user confirmation. Civil Radar does not control or delete copies that the user saves or sends outside the app.
Third-party processing
Google Maps Platform
The optional Map feature uses Google Maps SDK for Android. According to Google's current Maps SDK disclosure, the SDK may automatically collect request/device metadata, crash metrics and stack traces, IP address, a Maps SDK-specific pseudonymous identifier, and map interaction events such as panning or zooming. Google processes this information under Google's terms and privacy policy. Civil Radar does not use this information for advertising.
Google Privacy Policy: https://policies.google.com/privacy
Maps SDK data disclosure: https://developers.google.com/maps/documentation/android-sdk/play-data-disclosure
Local Mesh receivers
When the user explicitly creates or joins a Mesh session, Civil Radar sends AES-256-GCM encrypted and authenticated session observations—including receiver coordinates, BLE identifiers, timestamps, RSSI and transmitted-power estimates—to paired Civil Radar-compatible receivers on the same local network. The encryption key is derived from the secret contained in the pairing QR. Every trusted receiver holding that shared secret can decrypt session packets. No Civil Radar cloud relay is used. Users should keep pairing QRs private, use Mesh only on a trusted local network, and end the session when finished.
Retention
- Untagged and unsaved BLE records: normally removed after 24 hours.
- Tagged, flagged, manually locked, paired-overridden, floor-observed, or noted targets: retained until the applicable deletion control is used.
- Notebook notes and investigative minutes: retained until deleted.
- Acoustic-event summaries and emergency message: retained until deleted.
- Emergency/Lockdown audio: 14 days by default, or until deleted sooner.
- Generated export files inside Civil Radar's cache: retained until deleted by the user or cleared by Android.
- Copies exported to another application or storage location: controlled by that destination, not Civil Radar.
User controls and deletion
Open Control → Privacy & Data Controls to access:
- Delete Home Anchor
- Delete Notes & Minutes
- Delete BLE History & Target Data
- Delete Generated Exports
- Delete Lockdown Audio
- Danger — Delete All Data & Recordings
Delete All permanently removes local Home Anchor data, calibration, preferences, notes, BLE history, tags, flags, floor observations, emergency message, acoustic summaries, generated exports, and Lockdown audio. Active scanning can begin collecting new observations after deletion while the application is running.
Uninstalling Civil Radar also removes its app-specific local storage. Copies previously shared or exported must be deleted from their destination separately.
Permissions
Civil Radar may request Nearby Devices/Bluetooth, precise or approximate location, notifications, microphone, camera, network, and vibration access. Camera access is used for QR pairing. Microphone access is optional and used only for Lockdown audio. Permission access can be changed in Android Settings at any time, although denying a permission may disable the related feature.
Security
Civil Radar uses Android app-specific storage, disables Android backup for its app data, shows a persistent foreground notification while continuous scanning or Lockdown is active, and requires explicit user action before generating an evidence share. No method of storage or transmission is guaranteed to be completely secure.
Children
Civil Radar is not designed for children and should not be listed as targeting children in Google Play.
Safety limitations
Civil Radar is an awareness and documentation aid, not an emergency-response service, life-safety device, law-enforcement system, or proof that a person or vehicle is present. BLE and RSSI observations are affected by device behavior, walls, reflections, interference, antenna orientation, randomized addresses, and environmental conditions.
Changes
This policy may be updated when app behavior, dependencies, or legal requirements change. The effective date at the top of the page will be updated. Material changes should be reflected in the app and Google Play Data Safety declaration before release.
Contact
Privacy questions and deletion questions may be sent to: https://docs.google.com/forms/d/e/1FAIpQLSdHrwZsKBc1d3d0L-9woI4dQqCx0Lhll3z9u5KX7xX_EuYRAg/viewform?usp=header