SimpleFT8

FT8 receiver, transmitter, logger

Privacy Policy

Last updated · September 7, 2026
Overview

SimpleFT8 is designed with privacy as a core principle. Radio operation and the local logbook work without an account. External community and logbook services are separate, clearly labelled opt-ins. Apple services may be contacted for UTC clock sync and to check App Store product and purchase status.

Permissions Used

Microphone — required to receive FT8 audio from your radio. Audio is processed locally to decode FT8 messages. Captured audio is never recorded, stored, or transmitted.

System Audio Capture (macOS only) — optional. Lets you decode FT8 audio played by another app (SDR software, WebSDR in a browser) without a virtual audio cable. Uses Apple's ScreenCaptureKit; granting Screen Recording is required by Apple for any app that captures system audio.

Location (one-shot) — optional. The "Use GPS" button in Settings reads your location once to fill in your Maidenhead grid locator. Triggered only when you tap the button.

File Access (User-Selected) — used for ADIF import/export and native logbook backup/restore through Apple's system file picker. The app only reads or writes the file you select.

Data Stored Locally

Your QSO log is stored in the app's local container on your device. Logbook records leave the device only when you explicitly export a file or opt into QRZ Logbook transfer or private iCloud sync.

Community Services — Default Off

The community services below are off by default. The app also uses SNTP queries to time.apple.com for accurate UTC, and Apple may be contacted to load or verify App Store purchases.

In Settings → Community there are two independent opt-in toggles:

Share decodes with PSK Reporter opt-in
When on, decoded callsigns + grids + signal reports are forwarded to PSK Reporter (a long-running ham-community reception-report database) via our proxy at simpleft8.strangeloop.nl. We proxy rather than letting the app hit PSK Reporter directly so we can rate-limit a misconfigured client and stop it from flooding the upstream. When on, we also fetch reception reports for your callsign every five minutes so the map can show who heard you.

Show me on the SimpleFT8 online map opt-in
When on, the app posts your callsign + Maidenhead grid to our backend every 2–4 minutes so other SimpleFT8 users can see you on the "online now" layer of the map. We store nothing beyond callsign, grid, last-seen timestamp, and a per-install device identifier (used internally for rate limiting). Entries that haven't pinged in 15 minutes drop off the map.

Each toggle gates its own periodic task. You can have either on without the other.

Logbook Services — Opt-In

QRZ Logbook direct transfer Pro · opt-in
When you save a QRZ Logbook API key, it is stored in Apple's Keychain. A manual upload, or automatic upload if you enable it, sends the QSO as an ADIF record together with that API key directly to https://logbook.qrz.com/api. This traffic does not pass through the SimpleFT8 backend.

Private iCloud log sync Pro · opt-in
When enabled, QSO records, modification timestamps, and deletion markers are synchronized through Apple's CloudKit private database for container iCloud.nl.strangeloop.SimpleFT8. Apple associates this private data with your iCloud account. The SimpleFT8 backend cannot see it.

ADIF import/export and native backup/restore remain local, manual features and do not require Pro.

Device Attestation

On iOS, opting into a community feature starts an Apple App Attest handshake with our backend. App Attest provides hardware-backed verification of the app installation. The macOS app uses an application credential instead; it does not use App Attest.

For attested installations, we store the public key, a per-install device identifier, and a request counter used to reject replays. These authentication records do not include your Apple Account identity or payment information.

Audit Logs

Our backend keeps a per-request log (path, status code, IP, device identifier, app version, platform, timing) so we can spot a misbehaving client or service abuse. These logs are not exposed via the API, are not shared with third parties, and contain no message content — just request metadata. Used for anomaly detection only.

Children's Privacy

SimpleFT8 is not directed at children. It has no advertising, analytics, or social account. All community and logbook integrations are off by default.

Third-Party Services
  • PSK Reporter (pskreporter.info) — only contacted via our proxy and only when you've opted in. They receive your decoded-stations list, your callsign, your grid, your contact email (if you set one), and your antenna info (if set).
  • QRZ Logbook (logbook.qrz.com) — contacted directly only when you configure QRZ transfer and upload. QRZ receives your API key and the selected QSO data as an ADIF record.
  • Apple iCloud / CloudKit — used only when you enable private iCloud log sync. Apple stores the synchronized logbook data in your private iCloud database.
  • Apple App Store / StoreKit — used to load, purchase, restore, and verify the lifetime SimpleFT8 Pro entitlement. Apple handles payment information; SimpleFT8 does not receive it.
  • Apple SNTP (time.apple.com) — used for UTC clock sync. No data sent beyond the SNTP packet itself.
  • simpleft8.strangeloop.nl — operated by Strangeloop Software, hosted in Germany.
Data Retention
  • Local QSO log: kept until you delete the app.
  • Private iCloud log: kept in your iCloud account until you delete the records or otherwise remove the data through Apple.
  • QRZ Logbook records: governed by QRZ's own policy and your QRZ account settings.
  • Server-side presence pings: dropped after 15 minutes.
  • Server-side audit logs: retained at operator discretion. Email us to request deletion of rows tied to your device identifier.
  • PSK Reporter retention: governed by PSK Reporter's own policy.
Your Rights (EU / UK GDPR)

Email simpleft8@strangeloop.nl to:

  • Request a copy of every audit-log row associated with your device identifier.
  • Request deletion of every row associated with your device identifier.
  • Withdraw consent from SimpleFT8 community processing — turn both Community toggles off; the app stops sending new community data and presence records expire.
  • Stop QRZ or iCloud transfers by disabling those logbook integrations. Existing copies held by QRZ or Apple remain subject to their account controls and policies.
Contact

Questions about this privacy policy: simpleft8@strangeloop.nl

Changes

Any changes to this policy will be reflected in app updates with an updated "Last updated" date.

← Back to Support