Summary
The short version
- We collect nothing. The developer of PTTdroid operates no account system and receives no data from the app — no usage statistics, no crash reports, no device identifiers.
- Your settings never leave your device, except the ones that have to be sent to the relay in order to connect to it.
- Your audio is not recorded. It is captured while you hold the button, sent live to the relay, passed on to the other radios on your channel, and then it is gone. Nothing writes it to disk.
- You choose the relay. It can be a server you run, or this device itself. If you leave the app on its shipped default, it connects to a relay this project operates — see Which relay you are talking to.
- There are no third parties. No advertising, no analytics SDKs, no Google Play services, no trackers of any kind.
On device
What is stored
on your device
PTTdroid keeps its settings in the app's own private storage, which no other app can read and which the operating system removes when you uninstall. Nothing here is uploaded anywhere by the app.
| What | Why it is kept |
|---|---|
| Relay address and port | So the app knows what to connect to. Only used when you connect. |
| Channel number | The channel you were last on, 1 to 99. |
| Display name | Shown to the other radios on your channel while you hold the floor. Defaults to Anon. |
| Access token | The relay's shared secret, if it has one. Sent as a request header when connecting. |
| Certificate fingerprint | The SHA-256 of the relay's certificate, if you pinned one. |
| Theme, floating-button position and toggles | Interface preferences. |
In flight
What is sent
to the relay
Connecting to a relay means sending it what it needs to place you on a channel, and nothing else. There is no registration step and no profile.
- Your display name and channel number, as part of the connection address. Because they are in the address rather than in the body, a relay — and any proxy in front of it — will normally record them in its ordinary connection logs.
- The access token, if you set one, as a request header. It is never put in the address, so it does not land in logs the way the name does.
- Audio, only while you are holding the talk button and only after the relay has granted you the floor. It is raw 16 kHz mono PCM, streamed as it is captured.
- Two control messages: a request for the floor when you press, and a release when you let go.
- Your IP address, unavoidably, as with anything you connect to over a network.
In the other direction the app receives audio from whoever holds the floor, that person's display name, and a count of how many radios are on the channel.
The relay
Which relay you
are talking to
Everything you say passes through a relay, so which one you use is the whole privacy story. There are three cases, and the app tells you which one is in force under Settings → Relay, including the exact address it will dial.
A relay you run — Settings → Relay → Custom
Point the app at your own copy of ptt-server and no one else is in the path. That server keeps no database and stores no audio and no messages; the only file it writes is its own TLS certificate fingerprint. It does print ordinary operational logs — a session identifier, the display name, the channel number, and when each radio joined, left, took the floor or released it — to its console. Those logs are yours, on your machine, under whatever retention you give them.
This device — Settings → Hands-free → Host a relay on this device
On Android and desktop, the app can be the relay itself, and other people on the same Wi-Fi connect to it. Nothing then leaves the local network at all. This on-device relay serves plaintext only, so treat it as being as private as the network it runs on.
The shipped default — Settings → Relay → Default
So that a fresh install can be tried without setting up a server first, PTTdroid ships
pointing at a relay this project operates, over an encrypted wss://
connection. If you leave the app on Default, your audio and your display name pass
through a machine we run. It runs the same ptt-server code as above,
so it stores no audio and no messages and keeps no database — but its console logs, which
record display names and channel activity, are held by the hosting provider under that
provider's retention, and we do not control how long that is.
Whichever you pick, turn on Encrypted connection where the relay supports
it. Over wss:// the app will also pin the relay's exact certificate if you paste
its fingerprint, which is a stricter guarantee than the usual certificate-authority check.
Permissions
What the app
asks for
| Permission | What it is for |
|---|---|
RECORD_AUDIO | Capturing your voice while you hold the talk button. Nothing is captured at any other time. |
INTERNET | Connecting to the relay. |
FOREGROUND_SERVICEFOREGROUND_SERVICE_MICROPHONE | Keeping the channel open while the app is in the background or the screen is off. Android requires a visible, ongoing notification for this, which is the one you can talk from. |
POST_NOTIFICATIONS | Showing that ongoing notification. |
MODIFY_AUDIO_SETTINGS | Routing playback for a two-way call, so incoming audio behaves like a radio rather than like music. |
SYSTEM_ALERT_WINDOW | The optional floating talk button that sits over other apps. Leave the feature off and the app never asks for it; everything else works without it. |
PTTdroid asks for no location, no contacts, no camera, no storage and no phone-state access, and it has no way to read anything else on your device.
Third parties
Nobody else
is involved
There is no advertising, no analytics, no crash reporting, no attribution and no A/B testing in this app, and it does not use Google Play services or any other Google SDK. It contains no third-party SDK that reports anything anywhere, and no data is shared with any third party, because none is collected to share.
That is not only a policy. The whole source tree is public and every release is built from a tagged commit, so what the app does can be checked rather than taken on trust, whichever way you installed it.
We do not sell, rent or share any data, because we do not have any to sell, rent or share.
Your choices
Deleting your data
- Everything the app holds is on your device. Uninstalling PTTdroid, or clearing its storage in the system settings, removes all of it — settings, display name, access token and all.
- There is no server-side account to delete, because there is no account. A relay holds a live session only while you are connected, and it is discarded the moment you disconnect.
- To have a relay's logs deleted, ask whoever runs it. If that is you, it is your machine. If it is the shipped default, write to us and we will remove what we can — but do note the caution above about using it for anything sensitive.
Children
Age
PTTdroid is a general-purpose tool for groups who run their own network infrastructure. It is not directed at children, it has no content of its own, and it knowingly collects nothing from anybody, children included.
Changes
Changes to
this policy
If this policy changes, the date at the top of the page changes with it, and the change itself appears in the project's public history — this page lives in the same repository as the app, so every revision of it is a commit anyone can read. Material changes will also be noted in the release notes for the version that introduces them.
Contact
Getting in touch
Questions about this policy, or about anything the app does with data, go to the public issue tracker: github.com/devapro/ptt-client-android/issues.
If you would rather not ask in public — including asking for something to be removed from the default relay's logs — contact the maintainer through github.com/devapro.