The fine print

Privacy & legal

Everything worth knowing about what data leaves your phone, the services involved when you use network features, what's legal to receive, and whose shoulders this project stands on.

Terms of use

By downloading or using SondeFox, you agree to these terms. SondeFox does not transmit radio-frequency signals; it is a receive-side field aid, not an aviation, navigation, emergency, or safety-of-life service. You remain responsible for obeying local radio, access, driving, and recovery laws and for making safe decisions in the field.

SondeFox includes optional Google Maps features and content. By using SondeFox, you agree to be bound by Google's Terms of Service. Your use of Google Maps features and content is also subject to the then-current Google Maps End User Additional Terms of Service and Google Privacy Policy.

No warranty

SondeFox is provided as-is, without any warranty, not even the implied warranties of merchantability or fitness for a particular purpose.

Licensing

SondeFox is distributed free of charge to invited beta testers, and there is no plan to charge for the app. The licensing terms for the public release, including how and where source code will be published, are still being finalized and will be announced before launch.

SondeFox owes a real debt to published specifications and permissively licensed work across the radiosonde and SDR communities (see the acknowledgements below). Third-party provenance, immutable versions, licenses, and redistribution terms are recorded in the project's reviewed third-party inventory.

Privacy policy

Last updated: August 26, 2026.

Short version

No ads, no accounts, and no SondeFox analytics or tracking. Signal processing and telemetry decoding happen on your phone. SondeFox sends decoded telemetry to SondeHub or SondeFox only through the opt-in upload and capture features described below. Online maps and SondeHub reading features send request, viewport or location, and SDK usage data as described below. SondeFox-controlled uploads of your own position are off by default.

The app

  • No SondeFox analytics, ads, or accounts. The app contains no SondeFox analytics or advertising SDK, requires no sign-up, and does not send decoded telemetry to SondeFox unless you explicitly use a developer-capture upload.
  • Location and sensors: location and orientation data support on-device chase guidance and the compass pointer. When native 3D is enabled, SondeFox also provides geographic coordinates to the Maps 3D SDK: the current phone fix can be added as the chase-vehicle marker and used as the Chase Car camera center, while sonde positions, tracks, and landing predictions are added as markers and overlays. In normal operation Google may receive latitude/longitude coordinates and request or usage data, as described in the Google Maps Platform Terms. Android location permission can be revoked at any time; the SondeHub and SondeFox uploads described below remain separately opt-in.
  • SondeHub, reading: the Saved Flights screen fetches and refreshes exact flight history, and the optional landing-prediction setting polls SondeHub's predictor for eligible radiosonde targets during a running local chase. If you enable Auto-update for a saved flight, Android may make its exact-history refresh requests in the background about every 15 minutes, subject to the Wi-Fi-only or cellular network policy you selected. From v0.14.8 onward, while the chase screen is open SondeFox also live-follows saved flights over up to six read-only MQTT-over-WSS connections to SondeHub (three before v0.14.9; one per followed flight, the flight on screen first), subscribed only to those flights’ exact serial or callsign topics; the connections respect the same network policy, are bounded by an aggregate reconnect limit, stop when the app leaves the foreground, and upload nothing. SondeHub receives ordinary request metadata for these connections, including your IP address and a random per-connection client identifier. The current SondeFox source configuration enables the SondeHub Live source in both production releases (from v0.14.7 onward) and the separately installed SondeFox Test debug build; older installed production builds do not expose it. SondeHub Live is an explicit per-activation opt-in: after you select it, review its disclosure, and choose network access, broad 2D map views request one bounded active-sonde snapshot without sending the map center, while closer 2D views send the viewed map center and search radius; from v0.14.9 onward either view then opens live subscriptions for up to sixty-four selected exact sondes, and before v0.14.9 only the closer views opened subscriptions, for up to twenty-four. Native 3D currently does not estimate or send its viewport for SondeHub Live discovery. SondeHub receives ordinary request metadata, including your IP address, and a random per-activation client identifier. SondeFox sends no user-account identifier; the session is receive-only, never uploads telemetry or your position, and is not restored or run in the background. From v0.14.9 onward you can also long-press a sonde on the chase screen to fetch that flight’s published path from SondeHub and draw it on your map; this is a single request you initiate, it follows the same network policy, nothing is stored, and the fetched positions are drawn only and are never uploaded anywhere.
  • SondeHub, writing: strictly opt-in; see the table below.
  • MapLibre 2D map: when you're online, the chase map fetches styles and tiles from its configured providers; like any web request, a provider sees standard request metadata such as your IP address and which map areas you request. Supported 2D content may be cached on-device for field continuity.
  • Google Maps APIs: the optional native 3D map uses the Maps 3D SDK for Android and requests online Google map content for the area you view; SondeFox does not implement an offline store for that Google content. Google's current SDK disclosure says the SDK automatically collects request metadata, including device and operating-system details, SDK build and version, the number of results returned, and an Internal Usage Attribution Identifier; it also collects stack traces and crash metrics, IP address, and a Maps 3D SDK-specific pseudonymous identifier. Depending on map use, it collects interaction events such as panning and zooming. Google states that the Internal Usage Attribution Identifier is not used to identify the user or for advertising attribution. SondeFox uses Google Maps APIs, and this Privacy Policy incorporates the Google Privacy Policy by reference.

SondeHub uploads: all opt-in

Everything you upload to SondeHub joins a public telemetry stream and may be redistributed by SondeHub and downstream projects. The in-app opt-in flow says the same thing before you enable anything.

Telemetry upload is also gated per sonde type: a type is published only once its decode has been validated against SondeHub's own multi-station data. RS41 and DFM17 are cleared today; every other type decodes locally and is held from upload.

SondeHub upload choices, defaults, and transmitted fields
Upload Default What it contains
Sonde telemetry Off opt-in + callsign required The sonde's position and telemetry, your callsign, and your radio and antenna metadata. When the phone has a recent GPS fix, each record also includes your receiver's own position as uploader_position, which SondeHub uses for range rings and reception statistics. This is part of the telemetry opt-in itself; the position toggles below do not affect it.
Station position Off separate opt-in Your station's position, callsign, SondeFox software name and version, configured radio and antenna metadata, your configured contact email (or a non-personal placeholder when it is blank), and a mobile flag set to false. The position is published to the public SondeHub map. This upload has its own toggle, independent of telemetry upload.
Chase-car position Off separate opt-in The same listener document—effective position (GPS by default; manual if station upload is enabled and manual coordinates are selected), callsign, SondeFox software name and version, configured radio and antenna metadata, and your configured contact email (or a non-personal placeholder when it is blank)—with the mobile flag set to true so it appears as a chase station on the SondeHub map.
Recovery report Only when you report a recovery; requires the telemetry opt-in and a callsign The sonde's serial, recovery coordinates including altitude, your callsign or reporter name, recovered/not-found status, notes, SondeFox as the recovery-software identifier, and a planned-status flag (currently false). A report opened from sonde details can use the phone's current GPS fix when available; the dialog shows latitude and longitude before you confirm the one-off report.

The user-controlled paths that can transmit your own position as application data are telemetry upload through uploader_position, station-position upload, chase-car upload, a manually confirmed recovery report when it uses the phone's current GPS fix, and the two developer capture tools. SondeHub developer capture records exact uploader_position, callsign, reception details, and raw payload and diagnostic fields. The separate field-debug capture uploads radio IQ, spectrum, decoded sonde telemetry, diagnostics, and the app's own log; when Android location is active, that log can contain exact phone GPS fixes. Both capture tools send to SondeFox's private server at debug.sondefox.com, not to SondeHub. A separately initiated SondeHub validator dry-run control exists for development, but it is held in v0.14.0 and sends nothing. These features remain off until you enable, start, or confirm them. Online maps separately disclose the requested area and provider or SDK data described above.

Pending field-debug bundles are retained in app-private storage for up to seven days and deleted after successful upload. A SondeHub developer capture may remain pending until it uploads, subject to a 512 MiB backlog ceiling. The private debug server is configured to delete completed objects after 30 days and abort unfinished multipart uploads after seven days.

This website

  • Static pages only. No cookies, no trackers, no analytics, no third-party scripts or fonts.
  • Hosting: the site is served through Cloudflare, which, like any host, sees standard request logs (IP address, user agent, requested URL) as part of serving and protecting the site. We add nothing on top.
  • Email: if you write to [email protected], your message is handled like ordinary email and used only to respond and to run the beta program.

Reception legality & field safety

Radiosonde telemetry in the 400–406 MHz band is unencrypted and broadcast as part of the public meteorological service. Receiving it is legal in most jurisdictions. SondeFox does not transmit radio-frequency signals; its separately described network features communicate over the internet only when their own conditions are met.

Check your local law

Legality of reception is the norm, not a guarantee. Rules vary by country, and uploading telemetry or operating radio equipment may have separate local requirements. Know your regulations before you go further than listening.

  • Never make an RF transmission without authorization. SondeFox has no RF transmit function; do not use other equipment to transmit unless you hold the appropriate license.
  • Never trespass to recover a sonde. Get the landowner's permission first, and let a recovery go rather than take a risk. A dead RS41 in a field is not worth a confrontation, an injury, or a fine.
  • Chirp monitor: authorized signals only. The experimental chirp-spread-spectrum (CSS) monitor is off by default and scoped strictly to signals you're authorized to receive: your own devices, amateur-radio telemetry under your license, and ISM-band experiments. It performs PHY-level bit recovery only: no key extraction, no payload decryption, no private-network interception.

Acknowledgements

SondeFox exists because the radiosonde and SDR communities did the hard work first, in the open. Our sincere thanks to:

  • Published radiosonde standards and independent measurements: the public evidence that makes interoperable, independently implemented decoders possible.
  • Project Horus and SondeHub: the open community tools and public telemetry network that make radiosonde tracking and chasing a shared, worldwide effort.
  • Airspy and RTL-SDR communities: the documented receiver ecosystems and permissive upstreams that enable direct USB reception on Android.
  • sdr-fox: the reviewed, permissively licensed companion driver used for SondeFox's RTL-SDR path.
  • MapLibre: the open map renderer behind the keyless 2D chase map and supported offline continuity.

Full third-party provenance, immutable versions, licenses, and redistribution terms are maintained in the project's reviewed third-party inventory. Each beta APK ships the required distributable license and notice files for its included third-party material.

Trademarks

Vaisala, Graw, Meteomodem, Intermet, Meisei, and other manufacturer names are trademarks of their respective owners, used here solely to identify the radiosonde models SondeFox can decode or plans to decode. Airspy is a trademark of its owner. Android, Google Maps, and Google Earth are trademarks of Google LLC. SondeHub is an independent community project.

SondeFox is an independent project and is not affiliated with, endorsed by, or sponsored by any of the organizations or projects named above.


Questions about this policy or anything else on this page? Write to [email protected].