Privacy Policy
Effective date: August 29, 2026
This Privacy Policy explains how OrbitDeck for iOS ("OrbitDeck," "the app," "we," "us") handles information. OrbitDeck is developed by Paul Stoetzer, N8HM ("the developer"). We are committed to protecting your privacy. In short: OrbitDeck does not collect, store, or transmit your personal information to the developer, and contains no advertising or third-party analytics or tracking.
The developer does not collect any personal information through OrbitDeck. OrbitDeck has no user accounts, no advertising, and no analytics or tracking SDKs. All of your settings, favorites, saved sites, and cached data are stored locally on your device.
OrbitDeck can use your device's location to set your observer station, which is required to compute satellite pass predictions, look angles, and related information. Location is used only on your device. It is not transmitted to the developer and is not shared with any third party. Providing location is optional — you may instead enter your station manually as latitude/longitude or as a Maidenhead grid square. You can enable or revoke Location access at any time in the iOS Settings app.
OrbitDeck can optionally connect to third-party amateur-radio services if you choose to enter credentials for them:
Any passwords or API keys you enter are stored in the device's secure iOS Keychain, not in the app's preferences, and are never sent to the developer. They are transmitted only to the corresponding service, over an encrypted connection, when you use that feature. Your use of those services is governed by their own privacy policies.
When you post an activation alert to hams.at, the details you enter — including your callsign, grid squares and observer position — are sent to hams.at and published as a public alert attributed to your callsign. OrbitDeck submits an alert only when you confirm it.
To function, OrbitDeck downloads publicly available data from the following services. These requests are made directly from your device to each service and necessarily include your device's IP address, which those services may process according to their own policies. OrbitDeck does not send them your personal information.
OrbitDeck identifies itself and rate-limits its requests in accordance with these services' usage policies.
If you use OrbitDeck's CAT (rig control) feature to Doppler-tune your transceiver, OrbitDeck communicates directly with your radio: over Bluetooth Low Energy to a BLE serial adapter, or over your local Wi-Fi network to an Icom network-capable radio. These connections are made only when you configure and connect a radio. They stay on your device and local network and are never sent to the developer. iOS requests Bluetooth and local-network permission the first time you connect. Any radio network password you enter is stored in the iOS Keychain.
The rotator control feature works the same way: it communicates directly with your antenna rotator over Bluetooth Low Energy to a BLE serial adapter, or over your local Wi-Fi network to a rotator daemon (such as rotctld or PstRotator). These connections are made only when you configure and connect a rotator, stay on your device and local network, and are never sent to the developer.
OrbitDeck's pass-recording, SSTV and FT4 features capture audio from a connected USB audio interface (which iOS treats as a microphone, so iOS requests microphone permission) or from a network-audio radio. Audio is captured only while you record or decode, is processed on your device, and is not sent to the developer. Recordings and decoded SSTV images are stored on your device; SSTV images are added to your photo library only when you explicitly export them (iOS requests add-only photo permission at that time.)
The QSO log is stored on your device. Uploading a QSO sends it only to the service you choose — LoTW (ARRL) or your own Cloudlog/Wavelog instance — and only when you tap upload. Your LoTW certificate is imported and kept on your device; its passphrase and any Cloudlog API key are stored in the iOS Keychain and are never sent to the developer.
OrbitDeck can optionally upload the FT4 stations it decodes through satellites to PSKReporter (pskreporter.info), a public reception-reporting network, so that they appear on its public map. This feature is off by default and is only active if you enable "Upload FT4 reception reports" in Settings. When enabled, each report is sent directly from your device to PSKReporter and includes your callsign and grid square, the decoded station's callsign and (if heard) grid square, the downlink frequency, signal report (SNR), mode, and time. This information is inherent to amateur-radio reception reporting and is published publicly by PSKReporter under its own policies. Nothing is sent to the developer. You can turn this off at any time in Settings.
OrbitDeck keeps an on-device diagnostic log (rig, audio, and network activity) to help troubleshoot problems. The log stays on your device and is never sent automatically. You may choose to share a log file with the developer — for example by email — when reporting an issue; only then does any log content leave your device, and only to the recipient you pick. You can disable logging or clear the logs at any time on the Diagnostics screen.
If you schedule a pass alarm, OrbitDeck uses local notifications delivered on your device. Notification permission is requested only when you first schedule an alarm. No notification data leaves your device.
OrbitDeck contains no third-party analytics, no advertising, and no tracking. We do not track you across apps or websites, and OrbitDeck does not use the Advertising Identifier (IDFA) or request App Tracking Transparency permission.
OrbitDeck is a utility for amateur-radio operators and is not directed to children. We do not knowingly collect personal information from anyone, including children under 13.
Because OrbitDeck stores its data only on your device and the developer maintains no servers or accounts, there is no personal data held by the developer to retain or delete. You can remove all of OrbitDeck's local data by deleting the app from your device.
Network connections made by OrbitDeck use standard encrypted transport (HTTPS/TLS). Credentials are stored in the iOS Keychain. No method of transmission or storage is completely secure, but OrbitDeck minimizes risk by keeping your data on your device.
We may update this Privacy Policy from time to time. Material changes will be reflected here with a new effective date.
If you have questions about this Privacy Policy or OrbitDeck's privacy practices, contact the developer at n8hm@arrl.net.