PRIVACY POLICY
Effective Date: September 15, 2026
1. Two Kinds of People in This Policy
Most privacy policies describe one relationship: the company and its users. This Service has two, and being straight about the second matters more than the first.
- You, our user. We hold very little about you: an email address, the settings and saved items you create, and your subscription status.
- People heard on the radio. Public-safety transmissions routinely concern members of the public; names, addresses, vehicle descriptions, and medical details, spoken by responders about people who are not our users and have not agreed to anything. Section 6 is about them.
2. Information We Hold About You
- Account information. Your email address, and sign-in data held by Amazon Cognito. Your password goes to Cognito over an encrypted connection; we never see or store it.
- Two-factor settings. If you turn on two-factor sign-in, the authenticator secret is held by Amazon Cognito. We never see it.
- Which legal documents you accepted. The version numbers of these Terms and this Policy that you agreed to, so we can show you exactly what you accepted.
- Access and subscription status. Whether your account has been approved, and whether it has a Premium subscription. Payment details are handled by Apple or Google; we never receive or store them.
- Things you save.
- Scan lists: named sets of channels you choose to listen to.
- Keyword alerts: the channel and/or keyword each alert watches.
- Saved clips: copies of individual calls you chose to keep, and any note you added. Saved clips are private to your account.
- Messages you send us. Feedback you send from the Help page, together with your account email (so we can reply), your account ID, and the page you came from. Emails you send us for help, and anything you include in them.
- Listener count. While the scanner is open, it sends a heartbeat so the Service can show how many people are listening. The heartbeat records your account ID and the time, not what you are listening to, stops counting 90 seconds after the scanner closes, and is then deleted automatically.
- Technical data. Like any website, our hosting receives standard request data such as your IP address, browser, and device type, which may appear in short-term operational logs.
We do not record your listening history, which calls you played, which channels you had selected, or for how long. We do not collect location data, contacts, or biometric data.
3. How We Use It
To operate the Service, sign you in, apply your plan, keep the things you save, manage account access, communicate with you about your account (for example, verification codes and password resets), keep the Service secure, and meet legal obligations.
We do not sell your personal information, and we do not use it for targeted advertising.
4. Browser Storage and Cookies
The Service does not currently set cookies. It uses your browser's local storage, which stays on your device, for:
- your sign-in session, so you stay signed in;
- your channel selection, so the scanner remembers what you chose;
- the scan list you last used.
These are strictly necessary for the Service to work as you set it up, and none are used for advertising or cross-site tracking. Signing out removes the session; clearing your browser's site data removes all of them.
The website loads its fonts from Google Fonts, so your browser contacts Google's servers, which receive your IP address.
If we introduce analytics or advertising, those use non-essential cookies or similar technologies, and we will ask for your consent before using them and give you a way to change your mind.
5. Retention
Call audio, and everything derived from it, is kept for a short, fixed window and then deleted automatically:
- Free accounts can replay the last 2 days.
- Premium accounts can replay the last 14 days.
- After 14 days, call audio and its record, including any transcript and extracted details (section 6), are deleted for everyone.
These limits are deliberate. They cap what can ever be requested, breached, or subpoenaed, and they are as much a privacy protection for the people heard in the audio as they are a cost control for us.
Saved clips are the exception. A clip is a copy of a call that an account holder chose to keep, and it is kept until they delete it (or delete their account), outside the normal 14-day expiry. Only that account can play it.
Downloads leave our control. Some accounts can download calls and saved clips as audio files. A downloaded file is stored on that person's device, where our retention limits and takedowns (section 6) cannot reach it. We keep a record of which account downloaded which call.
Account information is kept while your account exists and removed when you delete it, except where we must keep records for legal or accounting reasons.
6. People Heard in Transmissions
We receive transmissions broadcast in the clear over public airwaves. We do not decrypt anything, and encrypted talkgroups never reach the Service.
Even so, unencrypted public-safety traffic can contain sensitive information about identifiable people. We limit that exposure by:
- keeping audio only for the short windows in section 5;
- not building profiles of individuals from call content;
- limiting transcription and search to a small set of channels and a small group of accounts we select (below);
- honouring takedown requests (below).
Transcription and search (experimental). For a selected set of dispatch channels only, calls are converted to text by speech-recognition software (Whisper) running on equipment we operate — audio is not sent to a third-party transcription or AI service. The text is then scanned automatically for:
- the type of incident (for example, "crash" or "fire");
- keywords; and
- spoken street addresses and intersections, which are matched to map locations using public street data.
This information is available only to a limited group of accounts we select for testing, who can search calls by keyword and location. It is not available to the public. Transcripts and extracted details are machine-generated, often wrong, and are deleted together with the call when its retention window ends. Other channels are not transcribed, and ordinary accounts cannot search call content.
Takedown requests. If you are a person concerned in a transmission and you want the recording removed, email privacy@winnebagowaves.com with enough detail to locate the call — the approximate date, time, and agency. We will remove the audio, its record, and any transcript ahead of normal expiry, and remove saved clips of that call. We cannot remove copies someone has already downloaded. You do not need an account, and you do not need to explain why.
7. Who We Share Information With
We share personal information only with service providers that operate the Service for us, each for that purpose alone:
- Amazon Web Services — hosting, storage, sign-in (Amazon Cognito), and sending account emails such as verification codes (Amazon Cognito and Amazon SES).
- Apple (App Store) and Google (Google Play) — subscriptions bought in our apps. Their own privacy policies govern those purchases.
- Discord — private channels that only we can see receive:
- a notice when someone signs up, with their email address and account ID, so we know when someone joins and can manage their account's access; and
- feedback sent from the Help page, with the sender's email, account ID, and the page they came from.
- Google Workspace — our email, including help requests you send us.
- Google Fonts — loads the website's fonts, and so receives visitors' IP addresses (section 4).
- Advertising providers, if and when we introduce ads — only with your consent where the law requires it, and never on Premium accounts.
We may disclose information where legally required. We will not volunteer user records to law enforcement absent valid legal process.
8. Security
Audio is stored in private, encrypted storage that is not publicly reachable; playback and download links are individually signed and expire within minutes. Two-factor sign-in is available for every account. Access to production systems is restricted and authenticated.
No system is perfectly secure, and we cannot guarantee absolute security.
9. Your Rights
Depending on where you live, you may have the right to access, correct, delete, or export your personal information, to opt out of sale or sharing (we do not sell), and to withdraw consent.
From your account page you can, at any time and without asking us:
- download your data — your account details, accepted document versions, two-factor status, scan lists, keyword alerts, and saved clips; and
- permanently delete your account — which also deletes your scan lists, alerts, and saved clips (including their audio copies).
For anything else, email privacy@winnebagowaves.com.
Deleting your account does not delete call recordings that other listeners can still replay: those are public-safety broadcasts rather than data belonging to your account, and they expire on their own schedule. To have a specific recording removed, use the takedown route in section 6.
10. Children
The Service is not directed to children under 13, and we do not knowingly collect their personal information. Account holders must be 18 or older.
11. Changes
We may update this policy. Each version is kept and identified by version number, and the version you accepted remains available to you. Material changes require your acceptance before you continue using the Service.
12. Contact
Version 1.2 · current