Gendarmerie Privacy

Dana Technologies · Updated 6 October 2026

Gendarmerie observes radio advertisements available through your phone's operating system and can record your own location with your permission. It does not establish device identity, threat, RF dose or medical safety.

Data on your device

Nearby radio observations, deliberately read NFC tag records, custom signatures, local settings and journey history are held locally by default. Gendarmerie's dashboard journey history is limited to 24 hours. Advanced Fieldwatch session logs and exports on Android may retain coordinates until you delete them; screen privacy mode does not redact those files. You choose whether to export or share them using your device's share sheet.

Native observation notifications

Unusual-observation alerts are optional native notifications generated on your device. They require your notification permission and apply evidence thresholds and cooldowns. Nearby observations are not sent to a remote push-notification server. Alerts do not prove malicious intent and depend on observations available during permitted scans.

Daily summary reminders

You can opt into a daily on-device reminder at a local time you choose, change that time, or turn it off. Notification permission is required. The reminder uses generic text; tapping it opens the dashboard and refreshes the summary from locally retained observations and journey data. Scheduling does not start extra radio scans or upload your summary. The operating system controls delivery timing, including battery restrictions.

Android advanced network tools

The inherited Android tools include catalogue downloads, advanced report/path online lookup and configurable TAK publication. Starting with Android 0.1.3, advanced online lookup defaults off, earlier inherited enabled settings are reset off, and a separate explanation and confirmation are required to enable it. Earlier builds inherited an enabled default. When enabled, advanced reports can send precise saved coordinates to the system reverse-geocoding provider. Initialization or session-path refresh with retained phone or aircraft paths can also request map tiles from OpenStreetMap without opening the advanced view. Disabling online lookup stops new requests and cancels app-owned pending tile/path work. Previously transmitted requests cannot be recalled; an already-started system geocoder request may finish at its provider. The main dashboard map has its own default-off online-map control. When you explicitly enable TAK publication, configured radio identifiers, observation or coordinate fields may be sent using unencrypted UDP to the receiver you choose and a local loopback receiver. Review those destinations and their privacy practices before enabling it. Catalogue requests expose ordinary network metadata to catalogue providers. These tools are separate from Gendarmerie's HTTPS cloud sharing service.

Optional voice alerts

Android watchlist voice alerts use your selected system TextToSpeech engine. Some engines or voices may use remote synthesis or diagnostics under their provider policies. The app cannot guarantee that this engine is offline. Turn voice alerts off to stop new speech requests.

Sign-in and optional live sharing

Apple or Google supplies a provider identifier after you sign in. The backend verifies your identity token and stores the provider identifier, account creation time and a hashed temporary session token. It does not request your contacts. Gendarmerie uses its own Google sign-in project and requests basic identity only. No Google contacts or Google location access is requested.

Only when you create a location-sharing link and enable updates does the app send location coordinates, accuracy and update time to Gendarmerie's Cloudflare backend. It stores your latest point, not your journey, plus the recipient label you enter for each link. Labels record your sharing intent; the app cannot identify actual recipients or people who forward a URL. Anyone with the link can view a recent location, and can forward the link. Persistent links remain active until you revoke them. Old points are hidden after five minutes and deleted during hourly cleanup once more than 24 hours old or no active links remain. Revoking the final active link removes its latest point immediately. Revoke-all removes all your sharing links and the latest cloud point together. The app pauses publication first and confirms removal only after a successful server response; an offline attempt cannot establish that removal succeeded. Previously copied locations and exported files cannot be recalled.

PIN protection and viewer activity

You may add a six-digit PIN to a sharing link. The app suggests a random PIN that you can edit. New-link share text includes the PIN separately from the URL, so anyone receiving the entire message has both. The backend stores a salted, secret-keyed verifier rather than the PIN. Attempts are limited; someone holding the URL can temporarily exhaust its unlock budget. Successful unlock creates short-lived access for that link only. The browser holds its access token in memory; revocation or expiry ends access.

Authorized visible viewers refresh the latest point and create a short activity lease. The owner app can use this to increase foreground update cadence while viewed and reduce it when idle. This records recent viewing activity, not viewer identity. Live freshness still depends on the owner phone's consent, permissions, connectivity and operating system. No uninterrupted background tracking is guaranteed.

Permissions and controls

Bluetooth, Wi-Fi-related location permission on Android, and your own location are requested for the features that need them. Scanning and location recording can be paused. Background behavior differs by platform. iOS optionally requests Always location permission for significant-change background updates. The operating system controls background cadence; stationary, offline or restricted phones may not supply fresh updates. Android uses an explicit foreground service when you enable scanning/location recording. Neither platform guarantees uninterrupted tracking. You can revoke links, delete cloud location, sign out and delete your cloud account. A separate local-location deletion control stops location recording and removes dashboard journey coordinates and NFC phone-position attachments. Android also removes phone-position attachments from current nearby-radio records. Advanced Android Fieldwatch session logs and exports are separate and need separate deletion. Local deletion does not revoke cloud links, and cloud revocation does not erase local history. Other local app data is removable through the app's settings or uninstall.

Optional local app access

You can require native biometric or device-credential authentication to access the app interface. Your operating system performs this check; Gendarmerie does not collect biometric templates. This interface lock is separate from provider sign-in and data encryption, and it does not revoke links or stop previously consented background sharing. Device-category preferences filter normal browsing while unusual and watched observations remain eligible; they do not prevent radio observations from being collected.

Google sign-in SDK disclosures

Optional Google sign-in delegates authentication to Google. The bundled iOS Google Sign-In SDK privacy manifest declares account/profile information (name, email and phone), coarse location, user and device identifiers, usage data and other data for authentication/functionality and, for some types, analytics. These SDK disclosures are included in our App Store privacy label; they do not mean Gendarmerie reads your contacts, collects biometric templates or uploads your local radio journal. Google may process sign-in and network metadata under its own privacy practices. Gendarmerie has no advertising or cross-app advertising tracking.

Service providers and security

Cloudflare operates the backend. Apple and Google operate sign-in. Native maps or opening an external map may send requests to their respective map providers. Location-link pages use no analytics or advertising trackers. Backend application observability is disabled; Cloudflare may process infrastructure logs under its own terms. Authentication rate limits store a hash of IP address temporarily, cleaned hourly. Access links are unguessable bearer links and must be treated as private.

Contact

Privacy, deletion and support requests: info@dana.technology. Include only the information necessary to identify your request; do not email location logs unless needed.

Gendarmerie · Support

Request Gendarmerie account deletion