🔒 Privacy Policy
Sensor Playground
Last Updated: July 25, 2026
Your Privacy is Our Priority
Sensor Playground talks only to your own sensor nodes on your local network or over Bluetooth. The app contains no analytics, tracking or advertising frameworks of any kind. The only connection to the internet is loading map tiles from OpenStreetMap — and only when you open the map view of a GPS sensor node. Nothing else leaves your device.
What This Means for You
No Personal Data Collected
No accounts, names, IDFA / AAID or device fingerprints
No Analytics or Tracking
No Firebase, Crashlytics, Sentry, AdMob, Facebook SDK, AppsFlyer or Branch
Local Network & Bluetooth Only
Sensor readings travel directly between your device and your own sensor nodes
One Transparent Internet Use
OpenStreetMap tiles for the GPS map view — nothing else
How the App Works
Sensor Playground is a cross-platform companion app for do-it-yourself sensor nodes (ESP32 and Raspberry Pi & co.) on iOS, Android, macOS, Windows and Linux. It discovers your sensor nodes and displays their live readings — temperature, humidity, pressure, air quality, CO₂, light, color, motion, distance, gestures, GPS position and more.
- Your own hardware: the app only talks to sensor nodes you build and operate yourself
- Local discovery: nodes are found via a UDP broadcast on your Wi-Fi network or via Bluetooth Low Energy scanning
- Direct connections: readings are fetched over HTTPS, WebSocket or BLE directly from the node — there is no cloud in between
- Works offline: everything except the optional GPS map works without any internet connection
Network Connections
The app contacts only the destinations listed below. There is no analytics endpoint, no crash reporting, no telemetry, no advertising network, no remote configuration service and no push-notification service.
- Local network only — sensor communication: a UDP discovery broadcast on port 9133, HTTPS requests (self-signed certificates, accepted only for private LAN addresses) and WebSocket connections on port 9132 — all exclusively between your device and your own sensor nodes on the same Wi-Fi network (RFC 1918 addresses). Requests are authenticated with the API key you configured on your nodes. No sensor data leaves your local network.
- Bluetooth Low Energy: as an alternative to Wi-Fi, the app can scan for and connect to your sensor nodes over BLE. This is a direct device-to-device connection; no internet is involved.
-
https://tile.openstreetmap.org— the only internet connection the app makes. When you open the map view of a GPS sensor node, map tiles are loaded from the OpenStreetMap tile servers operated by the OpenStreetMap Foundation. The request contains the tile coordinates of the map area shown (derived from the position your own GPS sensor reports), a user-agent string identifying the app (as required by the OSM tile usage policy) and your IP address (visible to any web server by virtue of TCP/IP). No account, no cookies and no personal identifiers are sent. The OpenStreetMap Foundation privacy policy applies to that service. If you never open the GPS map, the app never contacts the internet at all.
Data Storage
All data the app keeps is stored exclusively on your device:
- App preferences (
SharedPreferences): your chosen settings such as the discovery mode (Wi-Fi / Bluetooth), temperature unit (°C / °F) and UI preferences - Secure storage (iOS Keychain / Android EncryptedSharedPreferences): the API key you configured for your sensor nodes, the locally generated licence key, and the store-receipt fields returned by Apple / Google after the in-app purchase
Important: All of this data is stored exclusively on your device and is never transmitted to our servers or any third party. You can remove it at any time by uninstalling the app.
Permissions
The app requests only the permissions it needs for the features you use, grouped by platform:
iOS
- Local network access: to discover sensor nodes on your Wi-Fi and read their live data
- Bluetooth: to discover and read nearby sensor nodes over BLE
- No camera, microphone, location, photos, contacts, calendar or HealthKit usage
macOS
- App sandbox enabled
- Network client / server: for UDP discovery and connections to your sensor nodes
- Bluetooth: for BLE sensor nodes
Android
INTERNET,ACCESS_WIFI_STATE,CHANGE_WIFI_MULTICAST_STATE: discovering and reading sensor nodes on your local network (and OpenStreetMap tiles for the GPS map)BLUETOOTH_SCAN(declared withneverForLocation),BLUETOOTH_CONNECT: BLE sensor nodes on Android 12+; the legacy Bluetooth and fine-location permissions are declared only for Android 11 and older, where the system required them for BLE scanning. The app never determines or stores your location — GPS coordinates shown in the app come from your sensor node's GPS receiver, not from your phonecom.android.vending.BILLING: Google Play Billing for the single in-app purchase
Windows / Linux
- Standard network access for local discovery and sensor connections; no store services
In-App Purchase
The app is free to download and works with the majority of supported sensors without payment. A single one-time in-app purchase (StoreKit on iOS, Google Play Billing on Android) unlocks the licence-gated sensor types. When you complete the purchase, the receipt fields returned by the store are saved locally in secure storage and a licence key is generated on your device. Payment processing is handled entirely by Apple or Google according to their own privacy policies; the app itself never sees your payment information.
Third-Party Services
Sensor Playground relies on a small, explicit set of third-party services:
- OpenStreetMap Foundation (
tile.openstreetmap.org): map tiles for the GPS map view — only when you open it. Subject to the OSMF privacy policy. - Apple App Store / Google Play (StoreKit / Play Billing): for the in-app purchase. Subject to Apple's and Google's own privacy policies.
The app does not include Firebase, Sentry, Crashlytics, Google Analytics, Facebook SDK, AdMob, Branch, AppsFlyer, IDFA collection, or any other tracking, analytics or advertising framework.
Data Controller
The data controller responsible for this app is:
- Company: ScienceSoft e.U.
- Address: Oberzellergasse 12/13, 1030 Vienna, Austria
- Commercial Register: FN 644834k
- VAT ID: ATU60406778
- Email: peter.sauer@flutterdev.at
Legal Basis for Processing
The limited processing the app performs — loading OpenStreetMap tiles when you open the GPS map view and locally storing the in-app-purchase receipt — is carried out under Article 6(1)(b) GDPR (performance of a contract / providing the feature you requested) and Article 6(1)(f) GDPR (legitimate interest in delivering that feature without collecting more than is necessary). The app does not collect or process personal data on our servers.
Website Tracking Disclosure
This privacy policy page is hosted on our website, which may use essential scripts for functionality (such as theme switching). Our website does not use analytics, advertising trackers, or third-party cookies. No personal data is collected through this website.
Children's Privacy
Our app does not collect personal data from anyone, including children. This applies to children under 13 (as defined by COPPA in the United States) and children under 14 (as defined by Austrian data protection law under the GDPR). The app has no user profile, no chat, no user-generated-content sharing, and no ad targeting.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Any changes will be reflected by updating the "Last Updated" date at the top of this policy. We encourage you to review this policy periodically.
Your Rights
Since we do not store any personal data on our servers, there is no profile to access, rectify, port or delete from our systems. All data the app keeps remains on your device under your complete control. You may also lodge a complaint with the supervisory authority listed below.
Contact Us
If you have any questions about this Privacy Policy or our privacy practices, please contact us:
- Company: ScienceSoft e.U.
- Address: Oberzellergasse 12/13, 1030 Vienna, Austria
- Email: peter.sauer@flutterdev.at
Supervisory Authority
If you believe your data protection rights have been violated, you have the right to lodge a complaint with the competent supervisory authority:
- Austrian Data Protection Authority (Österreichische Datenschutzbehörde)
- Address: Barichgasse 40-42, 1030 Vienna, Austria
- Website: www.dsb.gv.at
Compliance
This privacy policy complies with:
- General Data Protection Regulation (GDPR)
- California Consumer Privacy Act (CCPA)
- Children's Online Privacy Protection Act (COPPA)
- Google Play Store Privacy Requirements
- Apple App Store Privacy Guidelines
CCPA Notice for California Residents: Under the CCPA, you have the right to know what personal information is collected, request deletion of your personal information, and opt out of the sale of your personal information. Since we do not collect, sell, or share any personal information, these rights are inherently fulfilled. We do not sell personal information as defined by the CCPA.
Our Commitment
At ScienceSoft e.U., we are committed to building software that respects your privacy. Sensor Playground keeps your sensor data on your own network, contains no tracking or advertising frameworks, and contacts the internet for exactly one thing — OpenStreetMap tiles for the GPS map — and only when you use that feature.