BLE Radar is an Android app that scans for nearby Bluetooth Low Energy (BLE) devices and converts that into three things: a live coverage map, a non-monetary reward for the phone carrying it, and, only if you explicitly ask for either, a named impact certificate or a public profile page. It also reads WiFi network density, your movement mode, cellular signal quality, magnetic field, atmospheric pressure, artificial night light, and deliberate ambient noise levels. Each is explained below. This page explains what data that involves, in plain terms.
There are two exceptions, both optional: if you specifically turn on the optional impact certificate feature in Settings, your email (and name, if you provide one) is stored and shared with our fulfillment partner. Separately, the public BLE Radar landing page lets you choose to submit a Gmail address to request access to a Google Play Closed Test. Nothing about your name or email is collected any other way. Both actions are opt-in, see "Google Play test-access requests" and "Certificates and public profiles" below for exactly what that means.
Legacy live-map correction, 2026-08-13: installed app builds currently include latitude and longitude in an older anonymous-density compatibility block. The server now ignores those two values, stores only the signed H3 cell from the same request, and places the live marker at that hexagon's centre. The next app build removes the two fields entirely. A restricted historical file still contains older live-density points received before this correction. It is not publicly accessible, is not connected to rewards or a public profile, and no new precise points are being added to it. It will be purged only after the owner approves that irreversible deletion.
891fa41a40bffff), your GPS location is converted
to a ~150m-wide hexagon on your phone before anything is sent. We know roughly which
hexagon you were in, never your exact coordinates.This feature is optional and applies only to a Bluetooth device you deliberately claim. A claim requires a strong nearby signal in the app, or the owner-only page can accept an address printed on an object already in the owner's possession. The raw Bluetooth address is sent once when claiming and is not stored. The server stores a per-device HMAC value that cannot be turned back into the address. Participating phones download only the HMAC matching material, compare advertisements on the phone, and send nothing unless a registered device actually matches.
A match sends the reporting phone's exact latitude and longitude, signal strength, time and pseudonymous node ID. This exact position is necessary to locate the claimed object and is stored in that object's private sighting history. It is visible only to the owner of that object. The owner can distinguish sightings made by their own phone from sightings made by the network, and can see how many different nodes corroborated a sighting, but never another node's identity.
Bike Guard is off until the owner arms it. Arming stores an exact parked position, a movement radius and whether the local disappearance warning is enabled. A matching sighting beyond that radius creates a private alert containing the latest exact position, distance, direction, time, signal and a confidence score based on independent reporting nodes. The score is evidence quality, not proof that theft occurred and not a count of people. An armed device is marked urgent in the anonymous watchlist so a matching phone can report it immediately, but other nodes receive no owner, label, parked position or history.
The HITWAY inspector connects directly from the owner's phone to a nearby bike and displays the BLE services and characteristics the bike itself exposes. It reads only readable characteristics and can listen to the bike's notification channel. Enabling that listener changes only the standard Bluetooth notification descriptor and never sends a proprietary control command. Raw GATT values, services, characteristics and bike controls are not sent to BLE Radar. Proprietary battery, lock or trip values will not be labelled until the real protocol has been verified.
An owner may optionally connect a separate GPS source. BLE Radar stores a one-way hash of its ingest token and the latest exact latitude, longitude, accuracy, speed and time that source sends. The token is shown once and can be revoked by disconnecting the source. This data is private to the device owner, is never used for mining or rewards, and is never mixed into the public map.
Magnetic and pressure sensing run alongside mining when the phone has the required sensors and a usable location fix. Night light and noise do not run passively. You must open their instrument screen and start each reading yourself. The microphone permission is requested only when you choose to take a noise reading, never at app start. None of the four physical field readings contributes to your reward: they describe the state of a place rather than a new BLE device or WiFi network discovered there, and rewarding deliberate measurements would encourage fabricated data.
Every sensing layer has its own Settings switch and all seven start enabled. Switching a layer off makes the app omit that layer from uploads and stop its sensor where Android permits. A sensor-matched cause keeps its required layer enabled while selected. The server records only the pseudonymous node, H3 hex, layer name, timestamps, and sample count needed to prove active participation and coverage. Participation can unlock eligibility, but never creates a reward.
The separate Traffic flow switch also starts enabled. It contributes only anonymous, bounded vehicle-speed samples under the conditions above. Traffic flow does not unlock a cause and never changes mining credits or payouts.
Every Field Guide note is a deterministic explanation shipped with BLE Radar. It works without an AI model and uses fixed, reviewed rules for measurement meaning, thresholds and limitations. Inside the Android app, you may optionally download the Gemma 4 E2B model, approximately 2.59 GB, from its public Hugging Face repository. The app shows the size, source and Apache 2.0 licence and requires explicit confirmation before downloading. The download can be paused, resumed and removed, and its cryptographic SHA-256 checksum is verified before the model can run. Android may continue the optional download as an Android foreground task with a persistent progress notification, so you do not need to keep the Atlas screen open.
The model file, temporary download, model cache and conversation exist only in the app's private storage on your phone. Questions and answers are processed on the phone and are not sent to BLE Radar, Google, Hugging Face or any other server. Conversations are not saved. Closing the guide discards the conversation, and removing the model deletes both its completed and partial download. The model receives only the guide topic, displayed aggregate value, fixed field note and text you type. It cannot access the internet, live server data, your location, microphone, camera, contacts or files.
Optional safety report: after Atlas has answered, you can choose Report last reply, select a reason and review the exact question and reply before sending. Only after that separate confirmation does BLE Radar receive the selected question, selected reply, guide topic, app language, app version and your pseudonymous node ID. Exact location, map history, sensor readings, model file and the rest of the conversation are not included. These reports are used only to investigate incorrect, unsafe or inappropriate Atlas output. They are private to the BLE Radar owner, are never sold or used for rewards, and are retained for up to 12 months for safety review before deletion. Choosing not to report keeps the conversation entirely on your phone.
AI wording can still be wrong. The labelled verified field note remains authoritative, and the model is constrained to explain it rather than replace sensor validation or invent health, safety, people-count, traffic or environmental claims.
Atlas can read an answer aloud with an offline speech voice already installed on Android. If no offline voice is available, the app does not fall back to a network voice. The public website can also ask the browser to read a deterministic Field Guide note aloud. Browser speech may be local or network-backed depending on the browser, operating system and selected voice; BLE Radar does not send that text to a speech service itself.
Explorer can show optional map context from independent public sources: Safecast radiation measurements, OpenStreetMap road-limit tags, Vlaams Verkeerscentrum road events, IRCELINE Belgian outdoor air-quality stations, and grouped public shared-bike availability from permitted GBFS feeds. These are not BLE Radar measurements and are labelled with their source and update time on the map. They never enter your node record, coverage, rewards, causes, impact, or anything sold through BLE Radar.
To protect your map privacy, BLE Radar fetches these sources from its server through shared, short-lived caches. A map visitor's exact viewport is not sent to IRCELINE or Vlaams Verkeerscentrum. The Flanders and IRCELINE feeds are re-used under their published open-data licences, with source attribution in the map.
For postcode and district surveys and live-map coverage missions, the browser converts the real cached OpenStreetMap administrative polygon into resolution-9 H3 cells. The public server response counts how many of those cells carry an accepted measurement for each layer. A live mission also receives the anonymous measured cell identifiers so it can colour completed and unfinished hexes. It never receives the contributing node identities. Bluetooth, WiFi and cellular require 90 percent coverage; magnetic and pressure require 80 percent; deliberate night light and noise require 60 percent. Larger areas represented by coarse cells can be surveyed but cannot claim an unlock, because boundary-edge descendants would not be exact enough.
The activity layer uses a separate short-window count designed for this purpose. During one scan window, the phone holds the BLE addresses it sees only in memory long enough to count distinct radios. It sends the resulting number, never an address, hash, device name, manufacturer record, or fingerprint, then clears the in-memory set. A rotating Bluetooth private address can still make one radio look new in a later window, which is one reason this layer is never labelled as a headcount.
The server stores that count with the H3 hex, minute, and pseudonymous contributing node for up to 35 days. The node association is used internally only to state sample and contributor confidence. Public map and API responses contain the current aggregate count, comparison with that hex's usual level when enough history exists, freshness, sample count, and number of contributing phones. They never contain a node identity. A person may carry several radios, a fixed device may remain when no person is present, and many Android phones do not advertise continuously, so the only claim this layer makes is the honest one: how much nearby radio activity participating phones actually measured. Retaining this aggregate activity sample does not itself change rewards, causes, or impact.
Discovery Pulse is an optional 30-second dashboard game. While it is open, the mining upload adds only a true/false active marker. After the server has accepted a normal BLE or WiFi mining batch and calculated its ordinary credits, it may return a short-lived, single-use claim token. The token contains no device address, location, radio identity or readable node identity. A successful tap submits that token through the same signed node connection.
The first five verified catches per server day add a 25% bonus to the ordinary credits of the accepted batch. Later verified catches can increase the game score but add no bonus. The server, not the phone, fixes the amount, rejects expired or replayed tokens and enforces the daily cap. The bonus never creates a reading and never changes Bluetooth range, novelty or movement rules.
The public Pulse leaderboard shows only a randomly assigned alias and verified catch count for today, the last seven days and all time. It never publishes node keys, recovery keys, device details, credits, chosen cause, H3 cells, routes or timestamps. Internally, the pseudonymous node link is retained so one real batch can count once and the owner can see their own score.
Two categories of nearby device get an individual marker on the live map instead of folding into the anonymous count, both for a specific, consent-based reason, not because it's technically easy:
Everything else detected in a scan, including Apple, Google Fast Pair, and every other BLE-emitting device, is folded into the anonymous count only, with no address, brand, or manufacturer ID ever transmitted.
Businesses can query or purchase aggregate coverage statistics for an area, for example, "how many distinct BLE devices were seen in this map hexagon in the last 24 hours," the aggregate WiFi count, average cellular quality, magnetic field and anomaly averages, current sea-level pressure and trend, artificial-light lux averages, and approximate ambient-noise levels. These are aggregate properties of a map hexagon and are also visible through the public Explorer and public aggregate API. That is the only level of detail ever exposed externally. No individual node ID, device, network name, precise coordinate, audio, or person is identifiable in anything shown, sold, or exported. Internally, we track which pseudonymous node contributed to which hexagon so we can calculate rewards fairly, but that internal record is never included in anything shown or sold to a third party.
Walking or cycling through new areas earns the best rate, since that's the core, sustainable use of the app. Driving earns a reduced rate, this is deliberate: a car naturally passes far more BLE devices and WiFi networks per minute than someone on foot, so without a correction driving would out-earn walking despite covering the same ground less carefully. Your phone's detected movement mode adjusts the multiplier accordingly; it does not add a new location signal beyond the H3 hex tile already described above.
Unlike BLE devices and WiFi networks, a cellular signal reading isn't something new you "discovered" on a given scan, it's just how good the one connection your phone already has happens to be right now. There's nothing to count or dedupe, so it was never plugged into the reward formula at all: it exists purely to build a public coverage-quality map (see "What businesses can buy" below), and your mining rate is exactly the same whether your signal is full bars or none.
The live map (this page) can show your real-time position as a violet dot and, since 2026-08-11, the current air quality right where you are. Both use your browser's own Geolocation API directly, your exact coordinates never pass through our server at all for either feature. The air quality number comes from a free third-party service (Open-Meteo): your browser sends your coordinates straight to them and gets a number back, the same way it would if you opened a weather app. We never see or store that location, and it has no connection whatsoever to your node, your rewards, or the H3 hex tile your phone reports while mining, this is a separate, optional, informational layer on the map only.
The Explorer and live map coverage mission let you look up a place and see what this network has actually sensed inside it. Two things are worth being precise about.
The place name you type never reaches our server. Your browser sends it directly to Photon, a free open-source geocoder built on OpenStreetMap data, and gets coordinates back, the same arrangement as the air-quality lookup above. We never see what you searched for. The ⌖ button uses your browser's own Geolocation API to survey where you are, and those coordinates go to that same geocoder (only to give the area a human name), never to us.
What our server receives is a set of H3 cell identifiers, not coordinates. Your browser converts the area into the same hexagon grid the whole network already runs on, and asks us only "what has been recorded in these hexes." The answer is aggregate: hex counts, signal densities, and how many nodes have passed through, never which nodes, and never anyone's position, exactly the same limits as tapping a single hexagon on the map.
The Explorer can also show real public radiation measurements from Safecast. This is an external reference overlay, clearly labelled as Safecast and licensed CC0. It is never treated as a BLE Radar measurement and never affects coverage, credits, cause eligibility, rewards, impact, or enterprise data.
When the radiation switch is on and the map is sufficiently zoomed in, your browser sends the visible map rectangle and zoom level to our server in a POST body. This is necessary to ask for only the measurements visible on screen. The rectangle is not placed in the URL or nginx access log, is not tied to a node or portal session, and is not kept as a visitor record. Our server expands it to a shared geographic grid, caches the resulting public measurements for one hour, and sends only that expanded rectangle to Safecast. Safecast sees our server's request and IP address, not yours. If you used the location button, the visible rectangle can still describe the area around you, so you can switch the radiation layer off at any time. Switching it off clears those points and stops new viewport requests.
The Explorer can optionally draw legal road limits that volunteers have mapped in OpenStreetMap. This is a reference overlay, separate from BLE Radar's anonymous road-area speed samples. A missing mapped limit is shown as missing, never guessed from how fast a phone travelled. It does not affect coverage, credits, causes, rewards, impact, or enterprise data.
When the Road limits switch is on and the map is sufficiently zoomed in, the browser sends the visible map rectangle and zoom level to our server in a POST body. The rectangle is not put in the URL or kept as a visitor record. Our server expands it to a shared grid, caches the public road data for one day, and requests it from OpenStreetMap's public Overpass service. That service sees our server request, not your IP address. Switch the layer off to clear it and stop new requests.
Added 13 August 2026, and named here before it went live, because a privacy policy that catches up afterwards is not a policy.
The public pages of this site load Rybbit, an open-source, privacy-first analytics tool, so we can see which pages people actually read and whether the app is being found. We chose it specifically because this project promises that nothing identifying about you is stored, and that promise had to survive the analytics decision.
What it does not do: it sets no cookies, writes nothing to your browser's storage, uses no persistent identifier, and does not track you across other websites. Your IP address is anonymised by default and is not stored in a form that identifies you. There is no consent banner because there is nothing to consent to: no personal data is collected.
What it does record: aggregate, per-visit facts. Which page was viewed, the referring site, a coarse country or region, and general device type such as mobile or desktop. Nothing that ties two visits together as the same person, and nothing connected to your node, your recovery key, your rewards, or anything your phone has measured. Analytics and node data are entirely separate and are never joined.
Where it is not used: the owner's own administrative pages, any session recognised as the owner's, the ingest endpoint, and the JSON APIs. Pages viewed inside the Android app are ordinary web pages, so they are counted the same way. The app itself sends no analytics of any kind: the only thing it ever transmits is the aggregate measurement data described above.
If you would rather not be counted at all, any tracker blocker will stop it, and nothing on this site depends on it working.
The network owner has a private launch checklist for Google Play. It stores task status, notes the owner chooses to write, completion times and a short change history. The owner-node session is checked before any tracker data is read or changed. The tracker is never public, indexed, included in analytics, connected to measurements or rewards, or shared with Google automatically. Its notes must never contain passwords, recovery keys or private signing material. The operational record is kept until the launch is complete or the owner removes it.
The public BLE Radar landing page may offer a voluntary form for a person to request access to an invitation-only Google Play test. If you submit a Gmail address there, the page sends that address directly to the BLE Radar owner by email so they can decide whether to add it to the Google Play tester list. The address is not added to a newsletter, sold, used for advertising, linked to a node, sent to the mapping backend, or shared with any party other than Google Play when the owner adds it as a tester. The owner keeps the request only as long as needed to handle access and will delete it on request.
Rewards are never tokens, points, or cash. They're progress toward a planet-impact cause you choose (trees, ocean cleanup, carbon capture, clean water, or animal welfare). All five are wired to a real fulfillment provider, 1ClickImpact, and become real once your progress crosses a whole unit. This is live and has been since 2026-08-09 for trees, ocean cleanup and carbon capture, and since 2026-08-13 for water and animals, which are delivered as direct donations of one real US dollar per unit. No cause is progress-only any more.
Turning this on in Settings sends your email (and name, if you give one) to 1ClickImpact so they can email you a personal certificate, the same kind of certificate showing your name, a real unit count, and a QR code, each time a real unit funded by your mining gets fulfilled in your name specifically, instead of anonymously alongside everyone else's. Your email/name are stored on our server only to pass to 1ClickImpact at fulfillment time, and appear in nothing else, not the live map, not the public profile below, not any data sold to a business. Turn it back off at any time in Settings and both fields are deleted immediately, no support request needed. This does not change what happens to progress you've already had fulfilled anonymously before turning it on.
Turning this on gives you a shareable link (a random code, not your recovery key and not usable to access your account) showing a display name you choose (or "Anonymous node" if you skip it) and your real verified impact totals, trees planted, ocean cleanup funded, and so on. It never shows which map hexagons you've covered or any location data: with a small number of real users, a specific person's coverage history is effectively a map of their commute and home, so that data never leaves the server for this feature regardless of what you opt into. Turn it off at any time and the link stops resolving immediately.
Scanning only runs while the app is in the foreground or, if you've explicitly enabled "keep mining after closing app" in Settings, as a visible foreground service with an always-on notification, never hidden. Uninstalling the app stops all data collection immediately. Your pseudonymous node ID and everything tied to it can be abandoned at any time simply by not using that recovery key again; nothing links it back to you personally in the first place. If you turned on a certificate email or a public profile, both can be switched off independently at any time in Settings, each removes its data immediately and has no effect on the other.
Questions about this policy: reach out via sevinhub.com.