Frost IT Solutions → BlueBRD → Privacy
BlueBRD — Privacy Policy
Wear OS Bluetooth scanning utility · Last updated 1 September 2026, 12:31 EDT
What this application is for. BlueBRD is built for internal use, development and testing by Frost IT Solutions. It is not sold, not distributed publicly, and has no user base beyond its own developers — the data it collects is our own, from our own devices. This policy is published openly to meet Google's OAuth publishing requirements.
BlueBRD contains no analytics, no advertising, no tracking and no third-party SDKs. It transmits nothing to Frost IT Solutions.
What BlueBRD collects
While open and in the foreground, it records radio observations that nearby devices are already broadcasting publicly:
- Bluetooth and Bluetooth LE addresses, device names and signal strength
- Advertised service identifiers and manufacturer data
- Device class, where a device reports one
- Addresses of devices already paired with the watch
- An approximate position, only while a recent satellite fix is available
It records nothing about the contents of any communication, and it cannot. Bluetooth advertisement data is broadcast in the clear by design and contains no message content.
Location
BlueBRD requests ACCESS_FINE_LOCATION and uses it to attach an
approximate position to observations, so that a walked route can be analysed
rather than a stationary pile of readings.
Position is recorded only when the device has a satellite fix newer than thirty seconds, and only into the local log file. A stale fix is discarded rather than reused, so stationary sessions are left without position rather than stamped with a misleading one.
Where the data goes
Observations are written to a CSV file in the application's own private storage on the watch. Nothing leaves the device automatically.
If a Google account is explicitly linked and upload is tapped, that CSV is sent to that account's own Google Drive, into a folder named BlueBRD which the application creates. It goes nowhere else. Frost IT Solutions operates no server for this application, receives no copy, and has no access to the data.
Google account access
The Drive integration requests exactly one scope:
https://www.googleapis.com/auth/drive.file.
That scope grants access only to files BlueBRD itself creates. It cannot read, list or modify anything else in the Drive — not documents, not photos, not files created by any other application. It is the narrowest scope that permits an upload, and it was chosen for that reason.
Use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google user data is never sold, never transferred to third parties, and never used for advertising.
Authorisation uses the OAuth device flow — the watch displays a short code which is approved on a separate device. The resulting token is stored on the watch and used solely to upload that watch's own log files. It can be revoked at any time at myaccount.google.com/permissions.
Retention and deletion
Log files live in the application's private storage until deleted. Uninstalling BlueBRD removes them. Anything uploaded to a Google Drive belongs to that account and is deleted the same way any other file is.