Privacy Policy

Applications and services published by Frost IT Solutions · Last updated 1 September 2026, 12:31 EDT

Scope of these applications. The software described here is built for internal use, development and testing by Frost IT Solutions. It is not sold, not distributed publicly, and has no user base beyond its own developers. In practice we are collecting data about ourselves, on our own devices, for our own diagnostics. This policy is published openly to meet Google's OAuth publishing requirements, and it describes what actually happens rather than what a template would say.

These applications carry no analytics, no advertising, no tracking and no third-party SDKs. They transmit nothing to Frost IT Solutions.

Per-application policies

This page is the umbrella policy covering all applications and this site. Each application also has its own page describing exactly what it does:

What the applications collect

BlueBRD is a Bluetooth scanner. While it is open and in the foreground it records radio observations that nearby devices are already broadcasting publicly:

TowerSS reads cellular network state — serving cell identity, band, and signal metrics — from the device's own radio.

NavSatCat reads raw satellite measurements from the device's own receiver, to characterise what the hardware can track.

Neither records the contents of any communication, and neither can. Advertisement and cell-identity data are broadcast in the clear by design and contain no message content.

Where that data goes

It is written to a file in the application's own private storage on the device. Nothing leaves the device automatically.

If a Google account is explicitly linked and upload is tapped, that file is sent to that account's own Google Drive, into a folder the application creates. It goes nowhere else. Frost IT Solutions operates no server for these applications, receives no copy, and has no access to the data.

Google account access

The Drive integration requests exactly one scope: https://www.googleapis.com/auth/drive.file.

That scope grants access only to files the application itself creates. It cannot read, list or modify anything else in the Drive — not documents, not photos, not files created by any other application. It is the narrowest scope that permits an upload, and it was chosen for that reason.

Use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google user data is never sold, never transferred to third parties, and never used for advertising.

The resulting authorisation token is stored on the device and used solely to upload that device's own log files. It can be revoked at any time at myaccount.google.com/permissions.

Location

Position is recorded only when the device has a satellite fix newer than thirty seconds, and only into the local log file. A stale fix is discarded rather than reused, so stationary sessions are left without position rather than stamped with a misleading one.

This website

This site sets no cookies and runs no analytics, no tag managers and no third-party scripts. Nothing is embedded from another domain.

Like any web server, the host records standard access logs when a page is requested. These typically include the requesting IP address, timestamp, the path requested, the HTTP status, the referring page and the browser's user agent string. This is ordinary server operation rather than a deliberate collection effort — the logs are used for diagnostics and are not analysed, profiled, combined with other data, or shared.

Retention and deletion

Log files live in the application's private storage until deleted. Uninstalling the application removes them. Anything uploaded to a Google Drive belongs to that account and is deleted the same way any other file is. Web server logs are rotated and discarded by the host on its own schedule.

Contact

privacy@