Privacy Policy

Effective September 6, 2026

Joseph Iannazzone built the QRV app as a free app with in-app purchases. This service is provided by Joseph Iannazzone at no cost and is intended for use as is. This page informs visitors regarding my policies with the collection, use, and disclosure of personal information for anyone who uses my service. It covers QRV on iPhone, iPad, Mac, Apple Watch, and Android.

Information Collection and Use

Free features. Band plans, references, and calculators work entirely on your device and need no network at all. Callsign lookups and logbook features go straight from your device to the service you chose — QRZ, HamQTH, or your own self-hosted Wavelog — and never pass through QRV's servers; your credentials for them are stored on your own device, in the Keychain on Apple devices and in storage protected by the Android Keystore on Android, and are sent only to those services.

Band conditions, live spots, and POTA and SOTA activations work differently: QRV's server fetches them from PSK Reporter, HamQSL, POTA, and SOTA on your behalf and caches them, so that thousands of apps don't hammer those services individually. Your app talks to QRV's server, not to them. For live spots that means your grid square reaches QRV's server as part of the request — see below for exactly what is kept.

What QRV's servers hold for you. QRV has no sign-in: no email address, no password, no name, and no account system. What it has is a random identifier, and a record attached to it. On Apple devices that record is created the first time you turn on notifications; on Android it is created the first time you open the app, so that your devices can find each other. It holds a push notification token for your device — issued by Apple's Push Notification service (APNs) or by Firebase Cloud Messaging (FCM) — your app version, and your device's language, and then whatever else you have asked QRV to keep for you: your alert settings, and on Android your synced favorites, frequency memories and preferences. That record holds no location at all unless you turn on notifications — the live spots request described above carries your grid square to the server, but it is not stored against you or against this record. The identifier itself contains no personal information and isn't tied to your name or email; on Apple devices it is generated on your device and carried between your devices through your own iCloud account, and on Android it is issued by QRV's server and carried to a replacement phone through Google Block Store. Nothing in the record identifies you unless you put your own callsign into it.

Premium notification features (live spots, and band, DXCC, callsign, DXpedition, and lightning alerts) need QRV's servers to store more than that, so they can deliver push notifications to your device:

  • An approximate location, as a Maidenhead grid square — never your precise GPS coordinates. Band, DXCC, callsign, and DXpedition alerts use a 4-character grid square (roughly 100 km across). Lightning alerts, which have to know whether a storm is close to your station, use a 6-character grid square (roughly 5 km across) together with the alert radius you choose
  • The alert criteria you configure — which bands, callsigns, DXCC entities, or DXpeditions you want to be notified about
  • A cryptographic hash of your recovery code, if you have generated one to link your devices. The code itself is never stored and cannot be read back from QRV's servers

How long this is kept depends on what it is. A device that goes unused and holds no active alert configuration is removed from our servers automatically after 180 days. Your synced favorites, frequency memories and preferences are kept until you delete them — deliberately, so that a recovery code can restore them to a new phone however long you have been away.

Delivering a push notification requires the platform's own push service, so QRV hands each notification to Apple (APNs) for Apple devices, or to Google (FCM) for Android devices, and they deliver it to you. Apple or Google therefore see your device's push token and the short text of the notification — a callsign and a band, a DXCC entity, or, for a lightning alert, an approximate distance from your station. They do not receive your grid square, your alert configuration, or your credentials, and they process what they do receive under their own privacy policies. QRV sends your data to no other third party for its own purposes, with the single exception of the maps component described below.

Settings and sync. On Android, your favorites, your saved frequency memories — including the names and notes you give them — and a small set of preferences — your callsign, your unit and clock choices, and which lookup service you prefer — are stored on QRV's servers, so that they follow you between your devices. They are held against the random identifier described above, not against a name, an email, or a sign-in, and they are never shared with anyone. You can turn this off at any time in Settings, under Identity, and delete what has already been stored. On Apple devices this sync happens inside your own iCloud account instead, using Apple's infrastructure, and QRV's servers never see it.

Everything else — your other app settings and preferences — stays on your device. On Apple devices it is backed up through your own iCloud account; on Android, if you have Android Auto Backup enabled, Android backs it up to your own Google account, and QRV uses Google Block Store so that a replacement phone can pick up where the old one left off. The start date of your free trial travels the same way — through iCloud on Apple devices, through Block Store on Android — so that reinstalling the app doesn't hand you a second trial. That data moves through Apple's or Google's infrastructure, inside your own account, and QRV's servers never see it.

Maps on Android. The grid square map is drawn by Google's Maps SDK, which is built into the Android app. Google receives what that SDK sends it directly: crash and performance data, device and request information, your IP address, an identifier for the app on your device that is not tied to you, and — because the map can be panned and zoomed — the fact that you interacted with it. Google uses this to run and improve its own services, under its own privacy policy. None of it passes through QRV's servers. This is the one place in QRV where data reaches a third party for that third party's own purposes rather than to perform a service for you.

What QRV doesn't do: QRV adds no analytics, crash-reporting, advertising, or tracking tools of its own, it has no advertising identifier, and I don't sell or share your data. Apart from the Maps SDK described above, the only third parties QRV sends anything to are the push services, and only to deliver notifications. On Android, the operating system reports crashes and performance data to Google Play on its own, if you have allowed it to; I see those in aggregate in the Play Console and they are not tied to you. Purchases are handled directly by the platform's store — Apple's StoreKit on Apple devices, Google Play Billing on Android — so QRV never sees your payment information. IP addresses are used transiently to rate-limit API abuse and aren't stored in our database; server logs are capped and roll off automatically rather than being retained long-term. When the app asks the server which stations are being heard near you, that request isn't recorded against you or your device, but the server does keep a running count of how many requests came from each grid square — an aggregate with nobody attached to it, which ages out after fifteen days.

If you delete the app, your locally stored data is deleted in the manner dictated by your device. If you purchase QRV Premium, data indicating your purchase status is written to your device's local storage. If you restore a purchase, your device contacts Apple's or Google's servers to authenticate the previous transaction.

Deleting Your Data

You can delete any alert you have configured from inside the app, one at a time or all at once. It stops working immediately. A copy is kept in an internal log for 30 days — you can't see or restore it from the app — so that a large accidental or malicious deletion can be spotted. After 30 days it is erased for good. Turning notifications off unregisters your device and stops every push immediately.

On Android, Settings → Identity → Delete synced data removes your synced favorites, frequency memories and preferences from QRV's servers. Nothing on your own device changes — and, exactly as iCloud behaves, another device of yours that is still syncing will put its copy back, so turn sync off there first if you want the deletion to stick.

If you would like everything QRV holds for you removed — including the random identifier that keeps your devices in sync and the hash of any recovery code — email me at [email protected] and I will take care of it. Deleting your data does not cancel or refund anything: your purchase still exists with Apple or Google, and restoring it rebuilds your Premium access, so this is not a way to lose what you paid for.

Links to Other Sites

This service may contain links to other sites. If you click on a third-party link, you will be directed to that site. These external sites are not operated by me. I advise you to review the privacy policy of any website you visit. I have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.

Changes to This Privacy Policy

I may update this privacy policy from time to time. You are advised to review this page periodically for any changes. Changes are effective when posted on this page.

Revised September 6, 2026, for cross-device sync on Android: your favorites, frequency memories and some preferences are now stored on QRV's servers rather than only on your device, the record QRV keeps for you is created when you first open the app rather than only when you turn on notifications, the Google Maps SDK's own data collection is described, and the sections on what is kept and how to delete it have been rewritten to match. The previous version was effective August 10, 2026.

Revised August 10, 2026, for the release of QRV on Android: the push, credential-storage, backup, and payment services each platform uses are now named individually, the grid-square precision each alert type uses is stated exactly, and how to delete your data has its own section. The previous version was effective July 29, 2026.

Contact

If you have any questions or suggestions about this privacy policy, contact me at [email protected].