๐Ÿ›ก๏ธ

Data Safety Declaration

Everything WiFi Map declares in Google Play's Data safety section, reproduced here in full โ€” with the reasoning behind each answer.

๐Ÿ“… Last updated: September 5, 2026 ๐Ÿ“ฑ Android v1.0.0+ ๐Ÿ”— Mirrors the Play Console form

๐Ÿ›ก๏ธ At a glance

  • No account required. No name, email, phone number or social login is ever collected.
  • Data is encrypted in transit on every request the App makes.
  • You can request deletion of any server-side data at any time.
  • Most of what the App produces โ€” scans, history, vault, heatmaps โ€” never leaves your device, so it is not "collected" at all in Play's sense.
  • The community map is the one place data goes to our server, and only when you choose to contribute.

Why this page exists

Google Play requires every app to complete a Data safety form declaring what it collects, what it shares, and how it protects it. That form is rendered on the Play listing as a summary. It is necessarily compressed, and its categories do not always map cleanly onto what an app actually does.

This page is the uncompressed version: every answer we give in the Play Console, plus the reasoning. It exists so that the declaration can be checked against reality rather than taken on trust, and so that Play's summary and this site never disagree.

โ„น๏ธ

Google's guidance defines "collected" as data transmitted off the device. Data that is processed and stored only on your device is not collected, and is declared as such. Where that applies we say so explicitly rather than leaving it out, because "not collected" and "not touched" are different claims and we only make the one that is true.

The authoritative narrative account is the Privacy Policy. This page is the structured version of the same facts.

1 Summary of Declarations

Play questionOur answer
Does your app collect or share any of the required user data types?Yes
Is all of the user data collected by your app encrypted in transit?Yes
Do you provide a way for users to request that their data is deleted?Yes โ€” Data Deletion
Does your app allow users to create an account?No โ€” there are no accounts
Has your app's data collection been independently validated against a global security standard?No
Does your app contain user-generated content?Yes โ€” the community hotspot map
Does your app target children?No
Privacy policy URLwifimap.epsilondevelopers.xyz/privacy-policy.html

2 Data Collected

Collected means transmitted off your device. For each type we declare whether it is optional, why it is collected, and what happens to it.

2.1 Location

TypeCollectedOptionalPurpose
Precise locationYesYesApp functionality โ€” centring the map and stamping a contribution you choose to submit. Rounded to 5 decimal places before it is stored or sent.
Approximate locationYesNoAdvertising โ€” Google AdMob infers a coarse country/region from your IP address for ad delivery.

Note: precise location is used only while the Map tab is open, is requested at that moment rather than at first launch, and is never collected in the background. On Android 13 and above, scanning does not require it at all.

2.2 App activity

TypeCollectedOptionalPurpose
App interactionsYesYesAnalytics โ€” screen views, feature opens, session length. Collection follows your ad-consent choice; declining consent disables it.
Other user-generated contentYesYesApp functionality โ€” hotspot contributions, venue names, notes, votes and reports you submit to the community map.
Other actionsYesNoAdvertising โ€” ad impressions, clicks and completions, processed by AdMob.

2.3 App info and performance

TypeCollectedOptionalPurpose
Crash logsYesYesAnalytics โ€” diagnosing crashes. Collection follows your ad-consent choice; declining consent disables it.
DiagnosticsYesYesAnalytics โ€” performance and error diagnostics. Same control as above.
Other app performance dataYesYesAnalytics โ€” ad-serve outcomes and latency, used to tune frequency caps.

2.4 Device or other IDs

TypeCollectedOptionalPurpose
Device or other IDsYesNoAdvertising (Android Advertising ID, used by AdMob), analytics (a Google-generated app instance ID), and fraud prevention (our own randomly-generated install ID).
๐Ÿ†”

Our install ID is a random UUID generated on your device. It is not the Android ID, not the advertising ID, and is not derived from any hardware identifier. Google's guidance treats it as a device or other ID, so we declare it as one โ€” but it identifies an installation for rate-limiting and moderation, not a person or a handset.

2.5 Purchase history

TypeCollectedOptionalPurpose
Purchase historyYesNoApp functionality โ€” honouring your Remove Ads or Pro entitlement. Limited to purchase state, product ID and purchase token. Payment details are handled by Google and never reach us.

3 Data Shared With Third Parties

"Shared" in Play's sense means transferred to a third party. We declare the following, and nothing else.

Data typeShared withPurpose
Approximate locationGoogle AdMob (and mediation partners, ยง8)Advertising
Device or other IDs โ€” Advertising IDGoogle AdMob (and mediation partners)Advertising
App interactions and other actionsGoogle AdMobAdvertising
App interactions, crash logs, diagnosticsGoogle FirebaseAnalytics
Purchase historyGoogle Play BillingApp functionality
Map viewport requestsGoogle Maps SDKApp functionality

We do not sell personal data. We do not transfer data to data brokers. We do not share location data with anyone for the purpose of building a location dataset outside the App's own community map, and the map holds only rounded coordinates of venue networks, never a record of where any user has been.

โœ…

Community contributions go to our own server, not to a third party. Under Play's definitions that is collection rather than sharing, since we operate the infrastructure and Cloudflare acts as our processor.

4 Explicitly Not Collected

Every Play data type we declare "not collected", so that the absences are on the record too:

CategoryStatusNote
Name, email address, user IDs, address, phone numberNot collectedThere is no account and no sign-up. We never ask.
Race, ethnicity, political or religious beliefs, sexual orientationNot collectedNo feature touches these.
Payment card, bank account, credit scoreNot collectedGoogle Play handles all payment; we never see it.
Health and fitness dataNot collectedโ€”
Messages โ€” email, SMS, in-app messagesNot collectedNo such permission is declared.
Photos and videosNot collectedCamera is used only to decode a WiFi QR code in memory; no frame is stored or uploaded.
Audio โ€” voice, sound recordings, music filesNot collectedNo microphone permission.
Files and documentsNot collectedExports are written where you choose; nothing is read back.
Calendar eventsNot collectedโ€”
ContactsNot collectedโ€”
Web browsing historyNot collectedRouter Access opens a URL in your browser; we do not observe it.
Installed apps, app usage of other appsNot collectedNo QUERY_ALL_PACKAGES.
Search history within the appNot collectedMap searches and tool inputs are not logged by us.
Passwords stored in the vaultNot collectedEncrypted on-device only. Never transmitted, in any form, to anyone.
WiFi scan results and network detailsNot collectedProcessed on-device. Only what you deliberately contribute is sent.
LAN device discovery resultsNot collectedProbe traffic stays on your local network.
Speed test, heatmap and deep-scan historyNot collectedLocal database only, unless you attach a speed sample to a community hotspot.
Full BSSIDs / MAC addressesNot collectedThe server rejects a full MAC outright; only the vendor prefix is kept.

5 Security Practices

PracticeStatusDetail
Data encrypted in transitโœ… YesTLS on every request the App makes โ€” map tiles, contributions, speed tests, ads, billing, analytics.
Data encrypted at rest on-deviceโœ… Yes, for credentialsVault entries use AES-256-CTR with an HMAC-SHA256 tag, under a key held in Android's hardware-backed Keystore.
Data encrypted at rest on the serverโœ… Yes, for credentialsCommunity venue passphrases are stored encrypted and served per hotspot rather than embedded in public tiles.
Users can request deletionโœ… YesIn-app instant deletion, plus a web request route โ€” Data Deletion.
Account deletionn/aNo accounts exist to delete.
Committed to Play Families PolicyโŒ NoNot a children's app; not enrolled.
Independent security reviewโŒ NoNot validated against a global security standard. We say so rather than leaving it ambiguous.
Data minimisationโœ… YesCoordinates rounded on-device, full BSSIDs rejected server-side, no accounts, no persistent user profile.
โš ๏ธ

How the analytics control actually works. Analytics and crash-reporting collection are switched together, and are driven by the advertising consent choice you make in the Google-provided form โ€” not by a separate setting. Declining consent, or a consent state that cannot be resolved, disables both along with advertising. You can revisit the choice at Settings โ†’ Privacy โ†’ Ad privacy options. A standalone analytics switch is planned; this page will be updated when it ships.

6 Permissions Declared in the Manifest

PermissionProtection levelUsed for
INTERNETNormalSpeed tests, map tiles, ads, purchases, contributions
ACCESS_NETWORK_STATENormalDetecting connectivity and connection type
ACCESS_WIFI_STATENormalReading scan results and connected-network details
CHANGE_WIFI_STATENormalStarting a scan; handing a network to the system add-network sheet
NEARBY_WIFI_DEVICES
neverForLocation
Runtime (Android 13+)Scan results without location permission
ACCESS_FINE_LOCATIONRuntimeMap "my location"; scan results on Android 12 and below
ACCESS_COARSE_LOCATION
maxSdkVersion 32
RuntimeFallback for scan results on older releases
CAMERARuntimeWiFi QR code import only
com.google.android.gms.permission.AD_IDNormalAdvertising ID access for AdMob on Android 13+

Deliberately absent

The manifest declares no QUERY_ALL_PACKAGES, no accessibility service, no SYSTEM_ALERT_WINDOW, no ACCESS_BACKGROUND_LOCATION, no foreground service, no contacts, SMS, call-log, microphone or storage-scope permission. Each of those is either unnecessary for what the App does or carries a review and privacy cost we are not willing to impose.

7 Third-Party SDKs in the App

Play holds developers responsible for what their SDKs do. These are all of them that touch data:

SDKProviderData it handlesOptional
Google Mobile Ads (AdMob)GoogleAdvertising ID, IP, device info, ad eventsRemoved by purchase
User Messaging Platform (UMP)GoogleConsent choicesRequired where law applies
Firebase AnalyticsGoogleApp interactions, app instance IDYes โ€” follows ad consent
Firebase CrashlyticsGoogleCrash logs, device model, OS versionYes โ€” follows ad consent
Firebase Remote ConfigGoogleConfiguration fetch; no personal dataNo
Google Play BillingGooglePurchase state, product ID, purchase tokenOnly if you purchase
Google Maps SDK for AndroidGoogleMap viewport requestsMap tab only
Google Play ServicesGoogleUnderlying platform servicesNo

Every other package in the App โ€” the database layer, HTTP client, secure storage, QR scanner, charting, routing, state management โ€” is local-only and transmits nothing. The full list is on the Open Source Licenses page.

8 Ad Mediation Partners

AdMob mediation may be used to fill advertising inventory from additional networks. Where mediation is active, the participating network receives the same categories of advertising data described in Privacy Policy ยง9, under its own privacy policy and subject to the consent choice you made.

PartnerStatusPrivacy policy
Google AdMobActivepolicies.google.com/privacy โ†—
Meta Audience NetworkPlannedfacebook.com/about/privacy โ†—
AppLovinPlannedapplovin.com/privacy โ†—
Unity AdsPlannedunity.com/legal โ†—
Liftoff / VunglePlannedliftoff.io/privacy-policy โ†—

This table is kept current. A partner marked planned is not yet receiving any data. When one goes live we update this page and, if the change requires it, re-present the consent form rather than assuming your earlier choice covers it.

9 Target Audience & Content

DeclarationAnswer
Target age group13+ (18+ in India, per the DPDP Act)
Appeals to children?No
Enrolled in Designed for Families?No
Tagged for child-directed treatment in AdMob?No
Content ratingGeneral audience โ€” utility app, no objectionable content
Contains ads?Yes, in the free version
Contains in-app purchases?Yes โ€” two one-time, non-consumable products
Contains user-generated content?Yes โ€” the community hotspot map
UGC moderation in place?Yes โ€” see Community Guidelines ยง7
In-app reporting for UGC?Yes โ€” a Report control on every community entry

10 Terminology

Play's vocabulary is specific, and misreading it is how declarations end up wrong. For clarity:

Collected
Transmitted off your device. On-device processing is not collection.
Shared
Transferred to a third party. Transfer to our own infrastructure, or to a processor acting on our instructions, is collection rather than sharing.
Optional
You can use the App without it โ€” either because a toggle exists, or because declining a permission leaves the rest working.
Ephemeral processing
Accessed in memory and not retained beyond the request. Camera frames in the QR scanner work this way.
Service provider
A third party processing on our behalf, under contract. Cloudflare is one; Google, for advertising, is not โ€” it processes for its own purposes too.
โš ๏ธ

If you find any discrepancy between this page, the Play listing's Data safety summary, and what the App actually does, tell us. A mismatch is a defect and we will fix whichever side is wrong.

11 Contact

Publisher
Epsilon Developers
Operated by
Satyam Kushwaha & Anurag Mahajan
Country
India
Email
contact@epsilondevelopers.xyz

Spotted something that does not match?

If the app behaves differently from anything declared here, that is a bug in our declaration or in our code. Either way we want to know.

โœ‰๏ธ contact@epsilondevelopers.xyz