Legal

Mobile app privacy

X-Radius Operator is the phone and tablet client an internet provider's own staff use to run their network. This page is the privacy policy for that app: what it sends, where it sends it, what stays on the handset, and what it never asks for.

App record

Application
X-Radius Operator
Android package
com.app.xradius
Apple bundle
com.app.xradius
Platforms
Android, iOS
Policy version
1.0
Effective

This policy covers the operator app only. The subscriber app and the web portals are covered by the site and platform privacy policy.

The short version

Six things worth knowing before you read the rest

  • 01

    The app talks to your provider's system, not to ours

    Sign in and every screen after it go to the server your own internet provider runs. We do not receive a copy.

    Where data goes

  • 02

    No analytics, no advertising, no tracking

    The app carries no analytics product, no advertising network, no crash-reporting service and no social login. There is no advertising identifier in the build.

    What the app never does

  • 03

    Your sign-in is held by the operating system, not by the app

    Tokens live in the Android keystore and the iOS keychain, marked so they never leave the handset and never sync to iCloud.

    What stays on the device

  • 04

    Every permission is asked for at the moment it is used

    Camera, Bluetooth, photos and biometrics are requested by the screen that needs them, and the app keeps working when you decline.

    The permission ledger

  • 05

    Scans and fingerprints are read on the device and stay there

    A QR frame is decoded in memory and discarded. A fingerprint or face is checked by the operating system, which tells the app yes or no and nothing else.

  • 06

    The app remembers your password unless you turn that off

    It is saved to the device keystore when you sign in, so the account switcher can resume without a retype. The switch that stops it is in Accounts, and signing out and forgetting the account deletes it.

    Deleting your data

The data path

Two hops, and one that is not there

The app makes exactly two kinds of outbound connection. The first asks a directory host which server belongs to your licence code. Everything after that goes to that server.

How data leaves the app On first run the app sends only a licence code to the X-Radius directory host and receives the address of the provider's server. Every signed-in request after that goes to the provider's server. No path leads to an analytics, advertising or third-party service. Your device the app X-Radius directory first run only — licence code Your provider's server everything you do after signing in

There is no third path. No analytics service, no advertising network, no crash reporter, no other company.