🔒 Privacy Policy

Sensor Playground

Last Updated: July 25, 2026

✓ No Tracking · No Analytics
🛡️

Your Privacy is Our Priority

Sensor Playground talks only to your own sensor nodes on your local network or over Bluetooth. The app contains no analytics, tracking or advertising frameworks of any kind. The only connection to the internet is loading map tiles from OpenStreetMap — and only when you open the map view of a GPS sensor node. Nothing else leaves your device.

What This Means for You

📵

No Personal Data Collected

No accounts, names, IDFA / AAID or device fingerprints

🔐

No Analytics or Tracking

No Firebase, Crashlytics, Sentry, AdMob, Facebook SDK, AppsFlyer or Branch

🏠

Local Network & Bluetooth Only

Sensor readings travel directly between your device and your own sensor nodes

🗺️

One Transparent Internet Use

OpenStreetMap tiles for the GPS map view — nothing else

How the App Works

Sensor Playground is a cross-platform companion app for do-it-yourself sensor nodes (ESP32 and Raspberry Pi & co.) on iOS, Android, macOS, Windows and Linux. It discovers your sensor nodes and displays their live readings — temperature, humidity, pressure, air quality, CO₂, light, color, motion, distance, gestures, GPS position and more.

  • Your own hardware: the app only talks to sensor nodes you build and operate yourself
  • Local discovery: nodes are found via a UDP broadcast on your Wi-Fi network or via Bluetooth Low Energy scanning
  • Direct connections: readings are fetched over HTTPS, WebSocket or BLE directly from the node — there is no cloud in between
  • Works offline: everything except the optional GPS map works without any internet connection

Network Connections

The app contacts only the destinations listed below. There is no analytics endpoint, no crash reporting, no telemetry, no advertising network, no remote configuration service and no push-notification service.

  • Local network only — sensor communication: a UDP discovery broadcast on port 9133, HTTPS requests (self-signed certificates, accepted only for private LAN addresses) and WebSocket connections on port 9132 — all exclusively between your device and your own sensor nodes on the same Wi-Fi network (RFC 1918 addresses). Requests are authenticated with the API key you configured on your nodes. No sensor data leaves your local network.
  • Bluetooth Low Energy: as an alternative to Wi-Fi, the app can scan for and connect to your sensor nodes over BLE. This is a direct device-to-device connection; no internet is involved.
  • https://tile.openstreetmap.org — the only internet connection the app makes. When you open the map view of a GPS sensor node, map tiles are loaded from the OpenStreetMap tile servers operated by the OpenStreetMap Foundation. The request contains the tile coordinates of the map area shown (derived from the position your own GPS sensor reports), a user-agent string identifying the app (as required by the OSM tile usage policy) and your IP address (visible to any web server by virtue of TCP/IP). No account, no cookies and no personal identifiers are sent. The OpenStreetMap Foundation privacy policy applies to that service. If you never open the GPS map, the app never contacts the internet at all.

Data Storage

All data the app keeps is stored exclusively on your device:

  • App preferences (SharedPreferences): your chosen settings such as the discovery mode (Wi-Fi / Bluetooth), temperature unit (°C / °F) and UI preferences
  • Secure storage (iOS Keychain / Android EncryptedSharedPreferences): the API key you configured for your sensor nodes, the locally generated licence key, and the store-receipt fields returned by Apple / Google after the in-app purchase

Important: All of this data is stored exclusively on your device and is never transmitted to our servers or any third party. You can remove it at any time by uninstalling the app.

Permissions

The app requests only the permissions it needs for the features you use, grouped by platform:

iOS

  • Local network access: to discover sensor nodes on your Wi-Fi and read their live data
  • Bluetooth: to discover and read nearby sensor nodes over BLE
  • No camera, microphone, location, photos, contacts, calendar or HealthKit usage

macOS

  • App sandbox enabled
  • Network client / server: for UDP discovery and connections to your sensor nodes
  • Bluetooth: for BLE sensor nodes

Android

  • INTERNET, ACCESS_WIFI_STATE, CHANGE_WIFI_MULTICAST_STATE: discovering and reading sensor nodes on your local network (and OpenStreetMap tiles for the GPS map)
  • BLUETOOTH_SCAN (declared with neverForLocation), BLUETOOTH_CONNECT: BLE sensor nodes on Android 12+; the legacy Bluetooth and fine-location permissions are declared only for Android 11 and older, where the system required them for BLE scanning. The app never determines or stores your location — GPS coordinates shown in the app come from your sensor node's GPS receiver, not from your phone
  • com.android.vending.BILLING: Google Play Billing for the single in-app purchase

Windows / Linux

  • Standard network access for local discovery and sensor connections; no store services

In-App Purchase

The app is free to download and works with the majority of supported sensors without payment. A single one-time in-app purchase (StoreKit on iOS, Google Play Billing on Android) unlocks the licence-gated sensor types. When you complete the purchase, the receipt fields returned by the store are saved locally in secure storage and a licence key is generated on your device. Payment processing is handled entirely by Apple or Google according to their own privacy policies; the app itself never sees your payment information.

Third-Party Services

Sensor Playground relies on a small, explicit set of third-party services:

  • OpenStreetMap Foundation (tile.openstreetmap.org): map tiles for the GPS map view — only when you open it. Subject to the OSMF privacy policy.
  • Apple App Store / Google Play (StoreKit / Play Billing): for the in-app purchase. Subject to Apple's and Google's own privacy policies.

The app does not include Firebase, Sentry, Crashlytics, Google Analytics, Facebook SDK, AdMob, Branch, AppsFlyer, IDFA collection, or any other tracking, analytics or advertising framework.

Data Controller

The data controller responsible for this app is:

  • Company: ScienceSoft e.U.
  • Address: Oberzellergasse 12/13, 1030 Vienna, Austria
  • Commercial Register: FN 644834k
  • VAT ID: ATU60406778
  • Email: peter.sauer@flutterdev.at

Legal Basis for Processing

The limited processing the app performs — loading OpenStreetMap tiles when you open the GPS map view and locally storing the in-app-purchase receipt — is carried out under Article 6(1)(b) GDPR (performance of a contract / providing the feature you requested) and Article 6(1)(f) GDPR (legitimate interest in delivering that feature without collecting more than is necessary). The app does not collect or process personal data on our servers.

Website Tracking Disclosure

This privacy policy page is hosted on our website, which may use essential scripts for functionality (such as theme switching). Our website does not use analytics, advertising trackers, or third-party cookies. No personal data is collected through this website.

Children's Privacy

Our app does not collect personal data from anyone, including children. This applies to children under 13 (as defined by COPPA in the United States) and children under 14 (as defined by Austrian data protection law under the GDPR). The app has no user profile, no chat, no user-generated-content sharing, and no ad targeting.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Any changes will be reflected by updating the "Last Updated" date at the top of this policy. We encourage you to review this policy periodically.

Your Rights

Since we do not store any personal data on our servers, there is no profile to access, rectify, port or delete from our systems. All data the app keeps remains on your device under your complete control. You may also lodge a complaint with the supervisory authority listed below.

Contact Us

If you have any questions about this Privacy Policy or our privacy practices, please contact us:

Supervisory Authority

If you believe your data protection rights have been violated, you have the right to lodge a complaint with the competent supervisory authority:

  • Austrian Data Protection Authority (Österreichische Datenschutzbehörde)
  • Address: Barichgasse 40-42, 1030 Vienna, Austria
  • Website: www.dsb.gv.at

Compliance

This privacy policy complies with:

  • General Data Protection Regulation (GDPR)
  • California Consumer Privacy Act (CCPA)
  • Children's Online Privacy Protection Act (COPPA)
  • Google Play Store Privacy Requirements
  • Apple App Store Privacy Guidelines

CCPA Notice for California Residents: Under the CCPA, you have the right to know what personal information is collected, request deletion of your personal information, and opt out of the sale of your personal information. Since we do not collect, sell, or share any personal information, these rights are inherently fulfilled. We do not sell personal information as defined by the CCPA.

Our Commitment

At ScienceSoft e.U., we are committed to building software that respects your privacy. Sensor Playground keeps your sensor data on your own network, contains no tracking or advertising frameworks, and contacts the internet for exactly one thing — OpenStreetMap tiles for the GPS map — and only when you use that feature.