This page has been updated A newer version of Invisible Atlas's site is live. Reload to get it.

Invisible Atlas (formerly BLE Radar), Privacy Policy

Last updated 2026-09-25. This describes exactly what the app and backend do, not a generic template.

Name change, 2026-09-18. BLE Radar is now called Invisible Atlas. Only the displayed name changed. The app package (com.sevinhub.bleradar), the servers, the data handling described below, and your existing node, credits and badges are all unchanged, and nothing needs reinstalling. The Google Play listing may still show the old name until the store update is published.

Invisible Atlas is an Android app that scans for nearby Bluetooth Low Energy (BLE) devices and converts that into three things: a live coverage map, a non-monetary reward for the phone carrying it, and, only if you explicitly ask for either, a named impact certificate or a public profile page. It also reads WiFi density and frequency-family counts, your movement mode, cellular signal and serving radio band, GNSS navigation-sky quality, magnetic field, atmospheric pressure, artificial night light, and deliberate ambient noise levels. Each is explained below. This page explains what data that involves, in plain terms.

What we never collect by default

Never sent unless you opt in

There are two exceptions, both optional: if you specifically turn on the optional impact certificate feature in Settings, your email (and name, if you provide one) is stored and shared with our fulfillment partner. Separately, the public Invisible Atlas landing page lets you choose to submit a Gmail address to request access to a Google Play Closed Test. Nothing about your name or email is collected any other way. Both actions are opt-in, see "Google Play test-access requests" and "Certificates and public profiles" below for exactly what that means.

Legacy live-map correction, 2026-08-13: installed app builds currently include latitude and longitude in an older anonymous-density compatibility block. The server now ignores those two values, stores only the signed H3 cell from the same request, and places the live marker at that hexagon's centre. The next app build removes the two fields entirely. A restricted historical file still contains older live-density points received before this correction. It is not publicly accessible, is not connected to rewards or a public profile, and no new precise points are being added to it. It will be purged only after the owner approves that irreversible deletion.

What we do collect, and why

Sent to our server

The Android home screen keeps the last successfully submitted night-light and sound numbers locally on that phone so their instrument cards can show the most recent real reading. This small local display cache contains no audio, coordinate, route, network identity or nearby-device identifier. It is removed when the app data is cleared or the app is uninstalled.

Privacy Sweep for nearby tracking tags

Privacy Sweep is a manual Android safety instrument for checking a car, room, bicycle or personal belongings. It listens for Bluetooth advertisement formats used by Apple Find My and AirTag, Google Find Hub, Samsung SmartThings Find, Tile, Chipolo and Pebblebee. A protocol match means only that a compatible signal was observed nearby. It does not prove that a device is unwanted, moving with you or separated from its owner.

The sweep, its raw Bluetooth addresses, signal samples and matching all stay on the phone. They are never uploaded, added to the public map, used for mining or rewards, linked to a node, or sent to analytics. During a sweep, the app turns an address into a locally keyed one-way identifier so repeat readings can be grouped without displaying or saving the raw address. Marking a signal as your own stores only that local keyed identifier in app-private preferences. Rotating Bluetooth addresses can therefore appear as a new signal later. The most recent aggregate summary contains counts only and is automatically erased after 24 hours. Clearing app data or uninstalling removes the local key, allowlist and summary.

Tracker Watch

Tracker Watch is the background counterpart to Privacy Sweep, added in version 2.4.0. While BLE Radar is scanning, it notes which nearby Bluetooth advertisements match a known finding-network protocol, and warns you if the same one is recorded in several different places over time, which means it travelled with you.

All of it stays on your phone and none of it is ever sent to us. It reuses the existing local novelty database, which already stores a truncated one-way hash of a Bluetooth address, the approximate H3 cell it was seen in, and a timestamp, and which is automatically erased after 24 hours. The only thing added for Tracker Watch is a label saying whether an advertisement matched a tracker protocol. No raw Bluetooth address is stored, no tracker identity, place or warning is uploaded, none of it is linked to your node, and no account is involved. Marking a tracker as your own records that same local hash in the same local database so it is not reported again. Clearing app data or uninstalling removes everything.

A warning means a tracker moved with you. It is not proof that anybody is following you, and the app does not say so: a tracker may belong to a partner, a friend, or a vehicle you travel in. Apple Find My devices also change their Bluetooth address roughly once a day, so this can only cover a tracker that followed you within that window. Tracker Watch can be switched off in the app, and it only runs while scanning is on with the Bluetooth layer enabled.

Each sweep mode applies a different local signal-strength, repetition, freshness and observation-time gate. Only the strongest repeated tracker-like signal that passes the chosen mode's gate is shown in the centred focus halo and live signal graph. Other qualifying signals are listed anonymously outside the focus zone. A 0 to 100 relative signal score is calculated on the phone from recent Bluetooth signal readings. It is not distance in metres. An optional local sound remains silent below 90 and becomes more urgent as the relative score approaches 100.

While Privacy Sweep is visible, the app may use the phone's current location accuracy and orientation sensors to draw the phone-centred marker and heading. The displayed halo does not claim a measured direction or coordinate for a Bluetooth device. Live coordinates, location accuracy, heading and raw sensor vectors are not stored, uploaded, added to the public atlas or included in an export. The optional Share action is initiated by the user and creates a text summary without Bluetooth addresses, raw identifiers or location.

Tracker Investigator can make a temporary direct Bluetooth connection to a focused accessory and check whether it exposes the documented Detecting Unwanted Location Trackers (DULT) non-owner service. Only fields actually returned by that service, such as manufacturer, model, category, firmware or capabilities, are displayed. A request to play the accessory's sound is sent only after you press the button and only when the documented service is available. The app does not treat an encrypted identifier as a readable serial number and does not invent a result when a command or field is unsupported.

Completed tracker encounters can be retained for up to seven days in Android encrypted app-private storage. Each record contains a locally keyed one-way signal identifier, the observed tracker family, sweep mode, first and last observation time, strongest relative score and number of sightings. It contains no coordinate or raw Bluetooth address. Expired records are removed automatically. An evidence summary leaves the phone only when you explicitly use Android's Share action, and excludes raw addresses, identifiers and locations.

The Combined Signal Console uses real phone sensors only. Its magnetic graph compares the live magnetic field magnitude with a slowly adapting local baseline. Metal, magnets and electronics can all change that reading, so it is not labelled as tracker detection. Its optional sound graph opens the microphone only after you press Start, immediately reduces each short audio frame to an uncalibrated numeric level, and keeps no audio. The reusable audio buffer is overwritten continuously and nothing from this sound meter is uploaded or added to the atlas. UWB distance or direction is never shown unless Android and a compatible ranged accessory provide a genuine ranging result.

Room and Hotel Privacy Inspection can run a 30-second Android network-service discovery scan on the WiFi network you joined. Advertised service names and types such as RTSP, ONVIF, HTTP, HTTPS, casting, home accessory and printing are held in memory while that screen is open and are not uploaded, stored or labelled automatically as cameras. Its lens-reflection view uses a live rear-camera preview and optional flashlight. Frames are not captured, analysed, stored or transmitted. The user visually inspects a reflection, and the app does not claim automatic hidden-camera detection.

My things and Bike Guard

This feature is optional and applies only to a Bluetooth device you deliberately claim. A claim requires the app to verify that the Bluetooth address printed on the device, box or manual exactly matches the address you selected or entered. This label check is evidence that you can access the label, not legal proof of ownership. The app uses a bundled text-recognition model on the phone. The camera image, automatically cropped label region and recognized text are kept only in volatile app memory or temporary app-private cache, are not added to the gallery, backup, logs or analytics, are never uploaded, and are erased when the check finishes or is cancelled.

The nearby-device list shows only consistently strong signals and refreshes visually at most once every seven seconds. Radio strength cannot establish an exact distance because antennas, walls and device orientation affect it, so the app describes candidates as very close rather than claiming a measured number of metres. Unclaimed nearby devices stay on the phone and are never sent to BLE Radar. For reward deduplication, the phone keeps truncated one-way hashes of BLE and WiFi radio addresses together with the observed H3 hex for 24 hours, then deletes them. These local hashes are never uploaded, do not contain names or locations more precise than that hex, and are used only to prevent the same radio in the same place from earning repeatedly. Many phones and watches rotate Bluetooth addresses, and a printed WiFi address may differ from the address used for Bluetooth, so those devices may not be verifiable or findable.

After an exact local label match, the raw Bluetooth address is sent once in the signed claim and is not stored. The server stores a per-device HMAC value instead of the address. Participating phones are given the matching key for each claimed device so they can compare advertisements locally, and we want to be plain about what that means: a Bluetooth address is a short value, so somebody running a modified copy of the app could work backwards from the material they are given to recover the address of a claimed device, though not its owner, its label, or where it has been. The Recovery Network described above was built to replace this approach, because it hands participating phones nothing at all. Participating phones download only the HMAC matching material, compare advertisements on the phone, and send nothing unless a registered device actually matches. Each registered node can open only its own claimed-device map and history. Making the feature available to registered nodes does not make any device, location or history public.

A match sends the reporting phone's exact latitude and longitude, signal strength, time and pseudonymous node ID. This exact position is necessary to locate the claimed object and is stored in that object's private sighting history. It is visible only to the owner of that object. The owner can distinguish sightings made by their own phone from sightings made by the network, and can see how many different nodes corroborated a sighting, but never another node's identity.

Bike Guard is off until the owner arms it. Arming stores an exact parked position, a movement radius and whether the local disappearance warning is enabled. A matching sighting beyond that radius creates a private alert containing the latest exact position, distance, direction, time, signal and a confidence score based on independent reporting nodes. The score is evidence quality, not proof that theft occurred and not a count of people. An armed device is marked urgent in the anonymous watchlist so a matching phone can report it immediately, but other nodes receive no owner, label, parked position or history.

The former bike telemetry inspector was removed on 2026-09-07. Invisible Atlas no longer connects to a bike's Bluetooth services and never reads or sends any of its characteristics.

An owner may optionally connect a separate GPS source. Invisible Atlas stores a one-way hash of its ingest token and the latest exact latitude, longitude, accuracy, speed and time that source sends. The token is shown once and can be revoked by disconnecting the source. This data is private to the device owner, is never used for mining or rewards, and is never mixed into the public map.

Recovery Network

The Recovery Network is separate from My things and is off until you turn it on. It lets a beacon you own be found by other phones running Invisible Atlas, without this service ever learning where anything is.

A recovery beacon advertises a public key that changes every fifteen minutes. A phone that has joined the network and hears one is not given any list of things to watch for and does not look anything up. It encrypts its own latitude, longitude, accuracy and the time directly to the key it just heard, and sends that sealed result along with a one-way hash of the same key. Only the holder of the beacon's master secret can open it, and that secret stays on the owner's phone and is never sent to us. Invisible Atlas cannot read a position stored this way, cannot tell which beacon a report belongs to, and cannot link two reports as coming from the same beacon, because the key and its hash both change every fifteen minutes.

We do not record which phone handed in a report. Your node identity is checked so that only a phone that agreed to take part can contribute, and is then discarded instead of stored. Nothing on our side connects you to anything you helped find.

To look for your own beacon, your phone regenerates the keys that beacon would have advertised, hashes them, and asks whether anything exists under those hashes. Being able to ask is itself the proof that the beacon is yours, because only your phone can produce those hashes. The answer comes back sealed and is opened on your phone.

What you agree to by turning this on: while the app is scanning, your phone will report sealed sightings of recovery beacons it hears, using your location at that moment. You can turn it off at any time in the app, which stops all further contribution. Turning it off does not delete sealed reports already handed in, because nothing on our side identifies them as yours. They expire on the schedule below.

A report is evidence that a beacon was heard near a place, not proof of where an object is. Anyone can transmit a public key they chose, so a single report should not be treated as fact.

Passive sensors and readings you deliberately start

GNSS sky, magnetic and pressure sensing run alongside mining when the phone has the required sensors and a usable location fix. Night light and noise do not run passively. You must open their instrument screen and start each reading yourself. The microphone permission is requested only when you choose to take a noise reading, never at app start. None of the four physical field readings contributes to your reward: they describe the state of a place rather than a new BLE device or WiFi network discovered there, and rewarding deliberate measurements would encourage fabricated data.

Walk mode in the browser (iPhone and other browsers)

Added 2026-09-24. contribute.php lets people without the Android app contribute from a browser. A browser cannot scan Bluetooth or WiFi, so walk mode measures only two things, and only while the page is open, you have pressed Start and the screen is on: ambient noise levels from the microphone (the same numeric Leq, L90 and L10 levels described above, never audio) and your position, which is turned into its resolution-9 H3 hex (about 170 m across) inside your browser. We receive the hex, the GPS accuracy in metres, an approximate speed to tell walking from driving, and the noise levels. We do not receive or store your exact coordinates or your route. Stopping the walk closes the microphone and location immediately.

Because a browser node has no radios to discover, the rule above is different for it: a hex you have not been credited for in the last 12 hours, measured with a valid noise reading while walking or cycling, earns a small, capped amount toward your chosen impact pack. Revisits, drives and hexes without a noise reading earn nothing, and there is a daily limit per node. A browser node is an ordinary node identified by a random recovery key created on our server and shown to you once; you are signed in with a session cookie on this site. Anyone holding the recovery key can use the node, so keep it private.

Every sensing category has its own Settings switch and all eight start enabled. WiFi and cellular spectrum views follow their parent WiFi and cellular switches. Switching a category off makes the app omit that layer from uploads and stop its sensor where Android permits. A sensor-matched cause keeps its required layer enabled while selected. The server records only the pseudonymous node, H3 hex, layer name, timestamps, and sample count needed to prove active participation and coverage. Participation can unlock eligibility, but never creates a reward.

The separate Traffic flow switch also starts enabled. It contributes only anonymous, bounded vehicle-speed samples under the conditions above. Traffic flow does not unlock a cause and never changes mining credits or payouts.

Private Guide and its optional local AI model

Every Field Guide note is a deterministic explanation shipped with Invisible Atlas. It works without an AI model and uses fixed, reviewed rules for measurement meaning, thresholds and limitations. Inside the Android app, you may optionally download the Gemma 4 E2B model, approximately 2.59 GB, from its public Hugging Face repository. The app shows the size, source and Apache 2.0 licence and requires explicit confirmation before downloading. The download can be paused, resumed and removed, and its cryptographic SHA-256 checksum is verified before the model can run. Android may continue the optional download as an Android foreground task with a persistent progress notification, so you do not need to keep the Atlas screen open.

The model file, temporary download, model cache and conversation exist only in the app's private storage on your phone. Questions and answers are processed on the phone and are not sent to BLE Radar, Google, Hugging Face or any other server. Conversations are not saved. Closing the guide discards the conversation, and removing the model deletes both its completed and partial download. The model receives only the guide topic, displayed aggregate value, fixed field note and text you type. It cannot access the internet, live server data, your location, microphone, camera, contacts or files.

Optional safety report: after Atlas has answered, you can choose Report last reply, select a reason and review the exact question and reply before sending. Only after that separate confirmation does Invisible Atlas receive the selected question, selected reply, guide topic, app language, app version and your pseudonymous node ID. Exact location, map history, sensor readings, model file and the rest of the conversation are not included. These reports are used only to investigate incorrect, unsafe or inappropriate Atlas output. They are private to the Invisible Atlas owner, are never sold or used for rewards, and are retained for up to 12 months for safety review before deletion. Choosing not to report keeps the conversation entirely on your phone.

AI wording can still be wrong. The labelled verified field note remains authoritative, and the model is constrained to explain it rather than replace sensor validation or invent health, safety, people-count, traffic or environmental claims.

Atlas can read an answer aloud with an offline speech voice already installed on Android. If no offline voice is available, the app does not fall back to a network voice. The public website can also ask the browser to read a deterministic Field Guide note aloud. Browser speech may be local or network-backed depending on the browser, operating system and selected voice; Invisible Atlas does not send that text to a speech service itself.

External reference layers

Explorer can show optional map context from independent public sources: Safecast radiation measurements, OpenStreetMap road-limit tags, Vlaams Verkeerscentrum road events, IRCELINE Belgian outdoor air-quality stations, and grouped public shared-bike availability from permitted GBFS feeds. These are not Invisible Atlas measurements and are labelled with their source and update time on the map. They never enter your node record, coverage, rewards, causes, impact, or anything sold through Invisible Atlas.

To protect your map privacy, Invisible Atlas fetches these sources from its server through shared, short-lived caches. A map visitor's exact viewport is not sent to IRCELINE or Vlaams Verkeerscentrum. The Flanders and IRCELINE feeds are re-used under their published open-data licences, with source attribution in the map.

Explorer basemap

The Explorer uses standard map tiles from OpenStreetMap as its geographic background. Your browser requests only the tiles needed for the map area and zoom level you are currently viewing. OpenStreetMap's tile service therefore receives your IP address, ordinary browser request information and the requested tile coordinates, as it would if you viewed its own map. Invisible Atlas does not attach a node ID, account, sensor reading, search text or reward information to those requests. Normal browser caching is respected, and Invisible Atlas does not prefetch areas or offer offline tile downloads.

Coverage Run: map, imagery, routing and address search

Added 2026-09-20. Coverage Run (the tilted, heading-up guidance page at /run.php) is drawn from vector map tiles served by OpenFreeMap (tiles.openfreemap.org), with the two colour styles hosted on our own server. The optional aerial view loads the most recent winter orthophoto mosaic of Flanders and Brussels from Digitaal Vlaanderen's public WMTS service (geo.api.vlaanderen.be), re-used under its "Modellicentie voor gratis hergebruik" with the credit "Bron: Luchtopnamen Digitaal Vlaanderen" shown on the map. Both services see what any tile server sees when you view a map: your IP address, ordinary browser request information and the coordinates of the tiles on screen. Nothing else is attached, and the aerial view is off until you switch it on.

Routing runs on our own server (an OSRM instance for Belgium that is not reachable from outside the server). Each time you press Route me, or the page recalculates after you took another street, your browser sends the position it will route from together with the target cells to api_route.php; that request is answered and not stored beyond the ordinary web-server log, which keeps no query parameters for that endpoint. Your position is never sent to any third party for routing, and Coverage Run does not upload a track: cells are marked measured only when the app on your phone reports them through the normal upload path described above. Our routing server holds road data for Belgium permanently and, since 2026-09-20, builds other areas on demand: the first time a signed-in node presses Route me outside a covered area, the server derives the region (a country, or a state or district where the map data is split that way) from the position in that request, records the region's name, when it was first requested, when it was last used and how many times, downloads that region's OpenStreetMap data and builds routing for it. The position is not kept, and regions unused for 60 days are removed.

About this place, added 2026-09-25. The "look" card can open a short description of a mapped place: the Wikipedia summary and picture, and facts from Wikidata (year built, architect, style, height, heritage status), each with its source and licence shown. When you tap About, your phone sends our server the place's name and its mapped point as it appears in OpenStreetMap, rounded to about 10 metres; it does not send your own position. Our server asks Wikipedia and Wikidata for that place and keeps the answer for 30 days, so those services see our server's address and the place, never you. Nothing about which places you looked up is recorded beyond that cache. Reading the text aloud uses your phone's own voice and sends nothing anywhere. The page draws your position on the route line when it is within a few metres of it; that is a display convenience, never a measurement, and the badge "on route" says when it is happening. Spoken instructions, if you switch them on, use your phone's own offline voice and send nothing anywhere.

The address search in Coverage Run sends the text you type directly from your browser to Photon (photon.komoot.io), the same OpenStreetMap geocoder Check my street uses, together with your position rounded to two decimals, about a kilometre, so that nearby results rank first. Your exact position is not sent. Your own picked cells and view preferences (theme, aerial view, voice) are kept only in your browser's local storage.

Coverage Run: the "look" hints

Added 2026-09-20. While following a route, Coverage Run can show one line saying what is worth a glance nearby, and speak it if you switched voice on. Every hint names its source and none is invented: places mapped in OpenStreetMap, read from the map tiles already on your phone with no request; gems from the public Rare Gems list; sunset and sunrise, computed on the phone; passes of the International Space Station, computed on the phone from the CelesTrak orbital elements our server already relays; nearby aircraft from our relay of adsb.lol, where the request carries only your position rounded to a tenth of a degree (about 10 km) and the server rounds it again to a half degree; and the NOAA Kp index through the same relay, with no position at all. Nothing about which hints you saw is recorded.

Rare Gems: photographs of places, stored elsewhere

Added 2026-09-20. Rare Gems (/gems.php) is a public gallery of photographs of places worth finding, posted by nodes that have contributed readings in at least 25 hexagons. This server stores no photographs. When you post one, your phone first re-encodes the image, which removes every embedded detail (GPS position, time, camera make, model and serial number), then uploads it directly to Cloudinary, the photo host, using a one-time signature from our server; the file never passes through us. Cloudinary therefore receives the image, your IP address and ordinary browser request information, and serves the picture to everyone who views the page. What our server keeps is the host's identifier for the picture, its pixel size, your title and caption, the kind (nature or city), an optional viewing direction you choose from eight compass points, your node's public key as the poster, and the location as an H3 cell only: your phone converts the spot you chose into a hexagon about 174 metres across (or, if you mark the place as fragile, an area about 1.2 kilometres across) before anything is sent, and the exact point is never transmitted or stored. Gems show the poster's chosen public name or the same stable pseudonym as the community wall. Posting earns nothing: no credit, badge, multiplier or reward of any kind. Any eligible node can report a gem; three reports hide it pending review, and the owner can hide or delete any gem, which also deletes the photo at the host. You can remove your own gem at any time, which deletes it at the host too. Nothing about who viewed a gem is recorded beyond the ordinary web-server log.

Google Play in-app updates

The Google Play edition can ask the Play Store whether a newer eligible Invisible Atlas version is available. Google Play processes device metadata, the installed app version and the list of installed modules or asset packs to determine update availability and expected download size. Google states that this information is encrypted, is not transferred to third parties and is deleted after a fixed retention period. Invisible Atlas does not receive or store that update-check metadata on its own server.

Ordinary releases use Google's flexible update screen so the download can continue while the app is used. A critical Play release, or one left unavailable on the device for seven days, can use Google's immediate update screen. Sideload installations do not invoke the Google Play update API; they keep the existing signed APK update path described by the app.

Administrative-area coverage unlocks

For postcode and district surveys and live-map coverage missions, the browser converts the real cached OpenStreetMap administrative polygon into resolution-9 H3 cells. The public server response counts how many of those cells carry an accepted measurement for each layer. A live mission also receives the anonymous measured cell identifiers so it can colour completed and unfinished hexes. It never receives the contributing node identities. Bluetooth, WiFi and cellular require 90 percent coverage; magnetic and pressure require 80 percent; deliberate night light and noise require 60 percent. Larger areas represented by coarse cells can be surveyed but cannot claim an unlock, because boundary-edge descendants would not be exact enough.

Nearby-device activity, not a people count

The activity layer uses a separate short-window count designed for this purpose. During one scan window, the phone holds the BLE addresses it sees only in memory long enough to count distinct radios. It sends the resulting number, never an address, hash, device name, manufacturer record, or fingerprint, then clears the in-memory set. A rotating Bluetooth private address can still make one radio look new in a later window, which is one reason this layer is never labelled as a headcount.

The server stores that count with the H3 hex, minute, and pseudonymous contributing node for up to 35 days. The node association is used internally only to state sample and contributor confidence. Public map and API responses contain the current aggregate count, comparison with that hex's usual level when enough history exists, freshness, sample count, and number of contributing phones. They never contain a node identity. A person may carry several radios, a fixed device may remain when no person is present, and many Android phones do not advertise continuously, so the only claim this layer makes is the honest one: how much nearby radio activity participating phones actually measured. Retaining this aggregate activity sample does not itself change rewards, causes, or impact.

Signal Lock daily bonus and anonymous board

Signal Lock, called Discovery Pulse in older app versions, is an optional 30-second radar game. While it is open, the mining upload adds only a true/false active marker. After the server has accepted a normal BLE or WiFi mining batch and calculated its ordinary credits, it may return a short-lived, single-use claim token. The token contains no device address, location, radio identity or readable node identity. A successful radar lock submits that token through the same signed node connection. The glowing marker uses a symbolic screen position and is never a measured bearing or distance. The phone stores only the local day and number of armed plays so the three-play local limit survives an app restart. A 30-second wait that never receives a real accepted target does not consume a play.

The first three verified catches per server day add a 25% bonus to the ordinary credits of the accepted batch. Later verified catches can increase the game score but add no bonus. The server, not the phone, fixes the amount, rejects expired or replayed tokens and enforces the daily cap. The bonus never creates a reading and never changes Bluetooth range, novelty or movement rules.

The public Signal Lock leaderboard shows only a randomly assigned alias and verified catch count for today, the last seven days and all time. It never publishes node keys, recovery keys, device details, credits, chosen cause, H3 cells, routes or timestamps. Internally, the pseudonymous node link is retained so one real batch can count once and the owner can see their own score.

Notifications sent to your phone

From version 2.4.4 the app can receive notifications while it is closed, using Google's Firebase Cloud Messaging. To make that possible your phone generates a delivery address, called a registration token, and the app sends it to us so we know where to deliver. The token identifies an app installation, not you: it is generated by Google, it changes on its own, it is meaningless to anyone else, and it is deleted when you uninstall the app or turn notifications off.

What travels in a notification is a short title, a short message, and a page inside our own site to open. Nothing else. No measurements, no location, no node key and no account details are ever put into a pushed message, because a notification passes through Google's servers on the way to your phone and is readable by anyone glancing at your lock screen.

The messages themselves are the same ones already shown in the app and on the website: a badge you earned, a certificate that completed, a reply on the community wall, an eSIM reward, or a message from us about your own node. Nothing new is created for push. It is a doorbell for something already waiting for you, capped so no phone is notified more than a handful of times a day, and you can switch it off in your phone's notification settings at any time.

Area notifications, added 2026-09-18. One kind of message is now chosen by where your node last measured: a "hot zone" tells you that readings in a nearby area count for more for a limited time, because that area is thin on the map. Deciding who receives it uses the last map hexagon your node reported, which is an area of roughly 174 metres that we already hold for coverage, and it is used only to decide whether to send you that message. Your position is never included in the message, never shared with the notification service beyond the words on your screen, and the area itself is public information already visible on the coverage map. If you would rather not receive these, switching notifications off in your phone's settings stops them along with the rest.

App version, language, and one setup report

From version 2.4.0 the app sends its own version number and your phone's language tag with its requests, and records them against your node when it first registers. Both were already stored once a node started scanning; recording them at registration means a node that never scans can still be attributed to a version and a language, which is how a broken release or a bad translation gets found.

Once per install, roughly a minute and a half after first launch, the app also sends a single short report describing its own configuration: whether the location, Bluetooth and notification permissions were granted, denied or unavailable, whether the background scanning service actually started, and whether a first upload was attempted. It is sent once, the first report per node is kept and later ones are ignored.

This is not behavioural analytics and will not become any. It contains no screens, no timings, no sequence of actions, and nothing describing what you looked at or tapped. It exists for one reason: most installs register and never scan, and from our side a refused permission, a background service blocked by the phone manufacturer, and somebody who simply closed the app all look identical, so there is no way to know which problem to fix.

Two deliberate exceptions

Two categories of nearby device get an individual marker on the live map instead of folding into the anonymous count, both for a specific, consent-based reason, not because it's technically easy:

Everything else detected in a scan, including Apple, Google Fast Pair, and every other BLE-emitting device, is folded into the anonymous count only, with no address, brand, or manufacturer ID ever transmitted.

What businesses can buy

Businesses can query or purchase aggregate coverage statistics for an area, for example, "how many distinct BLE devices were seen in this map hexagon in the last 24 hours," the aggregate WiFi count and anonymous band mix, average cellular quality and serving-band measurements, GNSS sky summaries, magnetic field and anomaly averages, current sea-level pressure and trend, artificial-light lux averages, and approximate ambient-noise levels. These are aggregate properties of a map hexagon and are also visible through the public Explorer and public aggregate API. That is the only level of detail ever exposed externally. No individual node ID, device, network name, precise coordinate, audio, or person is identifiable in anything shown, sold, or exported. Internally, we track which pseudonymous node contributed to which hexagon so we can calculate rewards fairly, but that internal record is never included in anything shown or sold to a third party.

Why movement mode affects your reward

Walking or cycling through new areas earns the best rate, since that's the core, sustainable use of the app. Driving earns a reduced rate, this is deliberate: a car naturally passes far more BLE devices and WiFi networks per minute than someone on foot, so without a correction driving would out-earn walking despite covering the same ground less carefully. Your phone's detected movement mode adjusts the multiplier accordingly; it does not add a new location signal beyond the H3 hex tile already described above.

Why passive cellular signal is never rewarded

Unlike BLE devices and WiFi networks, a cellular signal reading isn't something new you "discovered" on a given scan, it's just how good the one connection your phone already has happens to be right now. There's nothing to count or dedupe, so it was never plugged into the reward formula at all: it exists purely to build a public coverage-quality map (see "What businesses can buy" below), and your mining rate is exactly the same whether your signal is full bars or none. Signal Rewards use only the separate speed test that a user deliberately starts.

The live map's "you are here" dot and local air quality

The live map (this page) can show your real-time position as a violet dot and, since 2026-08-11, the current air quality right where you are. Both use your browser's own Geolocation API directly, your exact coordinates never pass through our server at all for either feature. The air quality number comes from a free third-party service (Open-Meteo): your browser sends your coordinates straight to them and gets a number back, the same way it would if you opened a weather app. We never see or store that location, and it has no connection whatsoever to your node, your rewards, or the H3 hex tile your phone reports while mining, this is a separate, optional, informational layer on the map only.

The invisible world card

A public profile also has a generated picture (profile.php?slug=...&card=1) that anyone with the profile link can see or download. It shows the same numbers the profile shows under the owner's own opt-ins, the provider-confirmed units, the owner's invite code, and a "sensing fingerprint": how many hexes the node measured per layer. It never draws a map, a coordinate or a tile position. Turning the public profile off removes the card.

Invites: plant a tree together

Every node can share an invite link carrying an eight-character code. A new node registered with that code is bound to the inviting node once, at registration, and the code is stored with the new node. When the invited node has earned its first 100 credits of accepted, verified uploads, the network queues one real tree for the invited node and one for the inviter through the normal owner-run fulfilment, subject to the same monthly caps as every other unit. The inviter sees only an anonymous label, the join date and the credit progress of each invited node, never its location, version, email or key. There is no money, no points and no bonus at signup.

Hex pages and city reports

Any measured hex has a public page (stats.php?hex=...) with the same aggregate values the Explorer shows: when it was first and last measured, how many phones passed through it, its successful uploads, the layers measured there with their readings, and how many real units the phones that measured it have caused across all their mapping. No node identity, route or exact observation time appears. "Follow this hex" stores a bookmark in your own browser only; nothing is sent to us. City reports (stats.php?city=...) are totals over hexes whose place name resolves to that city, are lower bounds, and expose nothing per phone.

Anonymous node ranking

Network Stats lists nodes ranked by lifetime activity credits, with the number of distinct hexes each measured, its successful uploads, the date it joined and the real provider-fulfilled units bought on its behalf. A node appears as Node plus four characters derived from a one-way hash of its key, which cannot be turned back into the key and is not shown anywhere else. No location, version, email or route is shown. If you chose a display name in My Node under Public profile, that name appears instead and links to the public profile you already opted into; remove the profile there and the ranking falls back to the anonymous label at the next refresh.

Searching an area on the maps

The Explorer and live map coverage mission let you look up a place and see what this network has actually sensed inside it. Two things are worth being precise about.

The place name you type never reaches our server. Your browser sends it directly to Photon, a free open-source geocoder built on OpenStreetMap data, and gets coordinates back, the same arrangement as the air-quality lookup above. We never see what you searched for. The ⌖ button uses your browser's own Geolocation API to survey where you are, and those coordinates go to that same geocoder (only to give the area a human name), never to us.

What our server receives is a set of H3 cell identifiers, not coordinates. Your browser converts the area into the same hexagon grid the whole network already runs on, and asks us only "what has been recorded in these hexes." The answer is aggregate: hex counts, signal densities, and how many nodes have passed through, never which nodes, and never anyone's position, exactly the same limits as tapping a single hexagon on the map.

The Explorer's Safecast radiation reference

The Explorer can also show real public radiation measurements from Safecast. This is an external reference overlay, clearly labelled as Safecast and licensed CC0. It is never treated as a Invisible Atlas measurement and never affects coverage, credits, cause eligibility, rewards, impact, or enterprise data.

When the radiation switch is on and the map is sufficiently zoomed in, your browser sends the visible map rectangle and zoom level to our server in a POST body. This is necessary to ask for only the measurements visible on screen. The rectangle is not placed in the URL or nginx access log, is not tied to a node or portal session, and is not kept as a visitor record. Our server expands it to a shared geographic grid, caches the resulting public measurements for one hour, and sends only that expanded rectangle to Safecast. Safecast sees our server's request and IP address, not yours. If you used the location button, the visible rectangle can still describe the area around you, so you can switch the radiation layer off at any time. Switching it off clears those points and stops new viewport requests.

The Explorer's OpenStreetMap road-limit reference

The Explorer can optionally draw legal road limits that volunteers have mapped in OpenStreetMap. This is a reference overlay, separate from Invisible Atlas's anonymous road-area speed samples. A missing mapped limit is shown as missing, never guessed from how fast a phone travelled. It does not affect coverage, credits, causes, rewards, impact, or enterprise data.

When the Road limits switch is on and the map is sufficiently zoomed in, the browser sends the visible map rectangle and zoom level to our server in a POST body. The rectangle is not put in the URL or kept as a visitor record. Our server expands it to a shared grid, caches the public road data for one day, and requests it from OpenStreetMap's public Overpass service. That service sees our server request, not your IP address. Switch the layer off to clear it and stop new requests.

Website analytics

Added 13 August 2026, and named here before it went live, because a privacy policy that catches up afterwards is not a policy.

The public pages of this site load Rybbit, an open-source, privacy-first analytics tool, so we can see which pages people actually read and whether the app is being found. We chose it specifically because this project promises that nothing identifying about you is stored, and that promise had to survive the analytics decision.

What it does not do: it sets no cookies, writes nothing to your browser's storage, uses no persistent identifier, and does not track you across other websites. Your IP address is anonymised by default and is not stored in a form that identifies you. There is no consent banner because there is nothing to consent to: no personal data is collected.

What it does record: aggregate, per-visit facts. Which page was viewed, the referring site, a coarse country or region, and general device type such as mobile or desktop. Nothing that ties two visits together as the same person, and nothing connected to your node, your recovery key, your rewards, or anything your phone has measured. Analytics and node data are entirely separate and are never joined.

Where it is not used: the owner's own administrative pages, any session recognised as the owner's, the ingest endpoint, and the JSON APIs. Pages viewed inside the Android app are ordinary web pages, so they are counted the same way. The app itself sends no analytics of any kind: the only thing it ever transmits is the aggregate measurement data described above.

If you would rather not be counted at all, any tracker blocker will stop it, and nothing on this site depends on it working.

Owner-only Google Play launch tracker

The network owner has a private launch checklist for Google Play. It stores task status, notes the owner chooses to write, completion times and a short change history. The owner-node session is checked before any tracker data is read or changed. The tracker is never public, indexed, included in analytics, connected to measurements or rewards, or shared with Google automatically. Its notes must never contain passwords, recovery keys or private signing material. The operational record is kept until the launch is complete or the owner removes it.

Google Play test-access requests

The public Invisible Atlas landing page may offer a voluntary form for a person to request access to an invitation-only Google Play test. If you submit a Gmail address there, the page sends that address directly to the Invisible Atlas owner by email so they can decide whether to add it to the Google Play tester list. The address is not added to a newsletter, sold, used for advertising, linked to a node, sent to the mapping backend, or shared with any party other than Google Play when the owner adds it as a tester. The owner keeps the request only as long as needed to handle access and will delete it on request.

How long we keep things

Rewards

Rewards are never tokens, points, or cash. They're progress toward a planet-impact cause you choose (trees, ocean cleanup, coral restoration, carbon capture, or clean water). All five are wired to a real fulfillment provider, 1ClickImpact, and become real once your progress crosses a whole unit. This is live and has been since 2026-08-09 for trees, ocean cleanup and carbon capture, and since 2026-08-13 for clean water, which is delivered as a direct donation of one real US dollar per unit. Animal Welfare was available from 2026-08-13 to 2026-09-02. Its historical progress and completed impact remain visible in the audit, but it is no longer available for future selection. No current cause is progress-only.

Coral Restoration joined the Ocean choices on 2026-09-01. One completed unit funds one coral fragment through 1ClickImpact's restore-coral programme. It uses the provider's exact Basic-plan price of $2.50, represented as 2,500 Invisible Atlas credits. The provider may assign fulfilled fragments to one of its available reef projects. A programme location is not the user's phone location.

Signal Rewards are separate from credits and environmental impact. Accepted signed cellular speed tests can unlock a one-time 1 GB eSIM at 1,000 daily-unique node-and-hex tests, 3 GB at 2,500 and 5 GB at 4,000. Passive scanning does not increase this progress. Redemption is optional. Before ordering, the user chooses the country where the data will be used. Invisible Atlas sends Airalo only the selected package and an order description, never the Invisible Atlas node ID, H3 history, phone number, recovery key or exact location. Airalo returns the eSIM installation details, which Invisible Atlas stores with the pseudonymous node so the user can reopen them. Loading the QR image or using a direct installation link connects the device to an Airalo-controlled HTTPS service, which receives normal connection information such as the IP address and browser details. Sandbox orders are always labelled as tests and do not create an installable eSIM. No live order is placed until the partner account is approved and live mode is explicitly configured.

Certificates and public profiles (both fully opt-in, both off by default)

Impact certificate, opt-in

Turning this on in Settings sends your email (and name, if you give one) to 1ClickImpact so they can email you a personal certificate, the same kind of certificate showing your name, a real unit count, and a QR code, each time a real unit funded by your mining gets fulfilled in your name specifically, instead of anonymously alongside everyone else's. Your email/name are stored on our server only to pass to 1ClickImpact at fulfillment time, and appear in nothing else, not the live map, not the public profile below, not any data sold to a business. Turn it back off at any time in Settings and both fields are deleted immediately, no support request needed. This does not change what happens to progress you've already had fulfilled anonymously before turning it on. The Android app periodically checks Invisible Atlas's signed node-status endpoint for newly provider-confirmed impact and certificates so it can show a phone notification. While mining is active this check normally happens within about 20 seconds; otherwise Android schedules it no more often than every 15 minutes and may delay it further for battery or network conditions. The check reads our stored fulfilment record only. It does not call 1ClickImpact, trigger a donation, expose the certificate publicly or create a new device identifier. The first check stores a local baseline so an update never replays notifications for every older certificate.

For a fulfilment attributed to your node in Invisible Atlas's private audit, Invisible Atlas can also store a filtered copy of the provider's lifecycle: impact and donation timestamps, quantity, assigned partner, project ID and programme location, scheduled or completed date, cancellation state, and HTTPS links for its certificate, project map or evidence when supplied. Provider metadata is deliberately not copied into this lifecycle view. The project location belongs to the environmental programme. It is never your phone location and is never presented as the exact position of an individual tree.

This lifecycle is never refreshed automatically. Only the owner can press the explicit sync control on the private Fulfillment page, and each press is capped and states how many provider API calls it may make. The app, portal, public profile, certificate page and every display path read only Invisible Atlas's stored copy and cannot contact 1ClickImpact. Your private journey is available only after recovery-key login or through the app's signed node request. Turning off certificates deletes your current email and name, stops future named fulfilments and hides the journey view. An older anonymous fulfilment may still appear in this private view because BLE Radar's own audit records which node funded it. It remains clearly labelled anonymous and cannot be converted into a named certificate. The identity-free lifecycle snapshot remains with the permanent fulfilment audit record so completed impact is not rewritten or silently lost.

The owner may also cache the provider's public project name, description, partner, country, programme coordinates and HTTPS project-image links with one explicit Projects API request. Project images load from images.1clickimpact.com only when they approach the visible page, using no-referrer requests. The image host receives normal connection information such as your IP address and browser details, but Invisible Atlas sends it no node ID, recovery key or phone location.

A provider project-map link is displayed only inside a Google Maps iframe. The iframe has no source and makes no request to Google until you press Show project map. At that point Google receives the normal connection information needed to serve the map, such as your IP address and browser details. Hiding the map removes the iframe source. Invisible Atlas does not send your node, phone location, recovery key or journey identity to Google.

Public profile, opt-in

Turning this on gives you a shareable link (a random code, not your recovery key and not usable to access your account) showing a display name you choose (or "Anonymous node" if you skip it) and your real verified impact totals, trees planted, ocean cleanup funded, and so on. It never shows which map hexagons you've covered or any location data: with a small number of real users, a specific person's coverage history is effectively a map of their commute and home, so that data never leaves the server for this feature regardless of what you opt into. Turn it off at any time and the link stops resolving immediately.

Check my street, Records, Heartbeat and Open data (added 2026-09-08)

Four public pages under Network Stats read the same aggregate tables as every other public page. Nothing new is collected from the app for them. Check my street sends the text you type from your browser directly to Photon (photon.komoot.io, an OpenStreetMap geocoder run by Komoot); our server never receives your text, only the ids of up to 19 hexes around the chosen point, and stores nothing about the request beyond the ordinary web-server log. The "Use my location" button reads your position once inside your browser and is subject to your browser's permission prompt. Records shows measured extremes with sample floors and never a single reading. Heartbeat shows hourly counts of accepted uploads worldwide and shows phone counts under five as "fewer than 5". Open data (CC BY-NC-SA 4.0) publishes one row per H3 resolution-6 cell (about 36 square kilometres) with counts and dates only, omits cells with fewer than 5 measured hexes, and contains no exact hex, no reading, no device identity and no route. Badges and the RSS feed are rendered from those same counts.

The 3D Earth, the Explorer and the Live Map can show "Earth today", NASA's daily satellite photograph of the planet. Those image tiles load in your browser directly from NASA's Global Imagery Browse Services (gibs.earthdata.nasa.gov), exactly like the OpenStreetMap street tiles do, so NASA's servers see the same thing any map tile server sees: your IP address and which parts of the world you look at. Nothing about you or your measurements is sent to NASA. The day/night line on those maps is computed in your browser from the Sun's position and is astronomy, not a measurement. You can switch Earth today off on each map. Since the evening of 2026-09-08 those tiles are fetched once by our server and served from it, so your browser no longer contacts NASA at all; the same server-side cache holds last night's real city lights from the same satellite, and NOAA's space-weather feeds (the Kp index and the aurora forecast oval), refreshed every five minutes, are relayed the same way, as are NASA's Earth Observatory Natural Event Tracker (EONET, the list of storms, fires, volcanoes and other events NASA records) and four more NASA daily layers (snow cover, sea ice, dust and smoke, sea surface temperature). None of these carry anything about you or your measurements; they are public data about the planet and the Sun, and Invisible Atlas does not detect or predict any event itself. The optional sky layers on the 3D Earth relay, through the same server cache, aircraft transponder broadcasts (adsb.lol), satellite orbital elements (CelesTrak) and earthquake records (USGS); the aircraft request carries only the rounded centre of the view, never your position, and satellite positions are computed in your browser.

Since 2026-09-09 the same public sources can be read for one point: the "Earth around this hex" section in the Explorer, the tap-to-read on the 3D Earth, and the optional context block in the Enterprise data (night-light brightness, snow, haze, sea temperature, sea ice, the Kp index and counts of nearby earthquakes and natural events for a cell). The point sent to our server is the hex centre or a tap on the planet, rounded to about a kilometre, never your own position, and no upstream provider is contacted per request: everything is read from the server-side cache. Those values are NASA, NOAA and USGS data about the planet, never Invisible Atlas measurement, and they are never sold on their own; in the Enterprise data they sit next to our aggregate rows with a credit line. Nothing from these providers is kept as history: the NASA tiles are kept for two days, the aircraft snapshots for one hour, the rest as single files that are overwritten.

Your control

Scanning only runs while the app is in the foreground or, if you've explicitly enabled "keep mining after closing app" in Settings, as a visible foreground service with an always-on notification, never hidden. Uninstalling the app stops all data collection immediately. Your pseudonymous node ID and everything tied to it can be abandoned at any time simply by not using that recovery key again; nothing links it back to you personally in the first place. If you turned on a certificate email or a public profile, both can be switched off independently at any time in Settings, each removes its data immediately and has no effect on the other.

Contact

Questions about this policy: reach out via sevinhub.com.