Privacy
Privacy
What each tool sends, what it keeps, whether anyone else is involved, and what clears it. Every tool is listed, including the ones with nothing to report — an entry left out would mean nothing was checked, and that is not something this page should ever mean.
For where dalMap’s evidence comes from and how far it can be trusted, read Sources and limits and the map’s Data sources and terms . Those pages are about the evidence; this one is about your data.
What every tool shares
These are true of every entry below, so a tool entry describes only what it adds. “No third party” in an entry means none beyond the ones named here.
- dalMap has no accounts and no signed-in state. What it knows about you is what you entered in My station and which layers you switched on. A callsign there is a preference that makes selected tools useful; it is not authentication or a claim of callsign ownership.
- Your callsign, your grid, and your layer choices travel with every page you open. They are kept in your browser for 30 days, renewed each visit, and they are what lets a tool answer for where you are. Clear My station removes the callsign and grid; Delete saved cookie, in About, removes everything saved for this browser.
- Only a coarse grid is used. Tools work from the four-character square, not a precise position. Where a tool passes that square, or an area around it, to someone else, its entry says so and names who receives it.
- A precise browser location never leaves the page. If you allow your browser to locate you, dalMap reduces the result to the same four-character square and keeps the precise position for the page you have open, to draw where you are.
- Opening the map fetches map tiles. That happens on every visit, whichever tool you use, and it is the reason OpenStreetMap is named below.
- dalMap submits nothing on your behalf. It is not a spotting, reporting, or logging endpoint: it publishes no spot, report, or log entry for you, and no tool transmits, tunes, or keys a radio.
Who else is involved, on every visit
You cannot judge a privacy effect without knowing who is on the other end of it, so the three parties every visit involves are named here rather than left to the entries.
- OpenStreetMap serves the basemap. Your browser fetches those tiles from them directly, so they see your network address and roughly which part of the world you are looking at. They receive nothing else about you.
- Sentry, run by Functional Software, Inc., receives dalMap’s error reports and anything you write in Share feedback. What is in a report, what is removed from it before it is sent, and what is kept are in Errors and feedback.
- Grafana Cloud receives dalMap’s complete operational log, described in Errors and feedback.
Tools
Beacon
Sends nothing. Keeps nothing. No third party. Nothing to clear.
PSK
Sends your coarse grid to PSK Reporter, which is how it can return recent reports involving your square; My reports narrows that to your exact callsign. Keeps nothing of yours — the reports it brings back are other stations’ submissions, and they leave the map after 20 minutes. PSK Reporter is the third party. Turning the layer off stops it, and Clear My station removes the square it was scoped to.
WSPR
Sends your coarse grid to WSPR.live to find recent paths involving it; My reports narrows that to your exact callsign. Keeps nothing of yours; pins leave the map after 15 minutes. WSPR.live is the third party. Turning the layer off stops it, and Clear My station removes the square it was scoped to.
DX Cluster
Sends nothing. Keeps nothing. No third party. Nothing to clear.
xOTA
Sends nothing. Keeps nothing. No third party. Nothing to clear.
APRS
Sends your coarse grid and your callsign to APRS-IS: the grid is what limits the feed to roughly 250 km around you, and the callsign identifies a receive-only connection and is what lets messages addressed to you reach you. Keeps nothing of yours; a message addressed to you waits five minutes as a dismissible pop-up. APRS-IS is the third party. Turning the layer off stops it, and Clear My station removes both.
APRS movement trails
Sends nothing beyond the APRS connection above, which it draws from. Keeps nothing. No third party beyond APRS-IS. Nothing to clear.
Repeater
Sends nothing beyond the APRS connection above, which it draws from. Keeps nothing. No third party beyond APRS-IS. Nothing to clear.
Earthquakes
Sends nothing. Keeps nothing. No third party. Nothing to clear.
Tropical cyclones
Sends nothing. Keeps nothing. No third party. Nothing to clear.
APRS weather
Sends nothing beyond the APRS connection above, which it draws from. Keeps nothing. No third party beyond APRS-IS. Nothing to clear.
Official observations
Sends the area around your coarse grid to the NOAA Aviation Weather Center, to ask for the airport observations inside it; the buoy observations in the same layer are selected after they arrive, so nothing of yours reaches NOAA’s National Data Buoy Center. Keeps nothing of yours. The Aviation Weather Center is the third party. Turning the layer off stops it, and Clear My station removes the square it was scoped to.
Satellite positions
Sends the satellite you select to SatNOGS Network, to ask how many stations received it in the last 24 hours; nothing about you is included. Keeps nothing of yours — the result is cached by satellite for five minutes and shared with everyone viewing it. SatNOGS Network is the third party. Nothing to clear.
My reports
Sends your exact callsign, with your coarse grid, to PSK Reporter and WSPR.live — that is what “reports involving me” asks them for, and it is more than the grid those layers send on their own. Keeps nothing of yours. PSK Reporter and WSPR.live are the third parties. Returning the scope to your grid stops it, and Clear My station removes the callsign.
Space weather
Sends nothing. Keeps nothing. No third party. Nothing to clear.
Path Planner
Sends nothing. Keeps nothing. No third party. Nothing to clear. The route, bearings, and planning context are worked out in your browser from your saved grid and the target you picked, and neither endpoint goes anywhere. A planning origin you set instead of your saved grid is held as a grid square for the open page only: it does not change My station, and closing the page ends it. Choosing that target with Find on map is a lookup, and has its own entry.
Signal paths
Sends nothing. Keeps nothing. No third party. Nothing to clear.
Band reach
Sends nothing of its own — it summarizes the PSK and WSPR evidence those layers have already brought in, so what they send applies. Keeps nothing of yours; the summary may weigh evidence up to 30 minutes old. No third party beyond PSK Reporter and WSPR.live. Nothing to clear. A Path Planner planning origin changes only where the direction summary is drawn from, in your browser.
Terrain clearance
Sends the path you select: the terrain tiles it crosses are fetched from the public Copernicus surface model, so the area of that path is visible to the service distributing it. The path starts at the center of your saved grid square, or at a planning origin you set for this browser session instead. Your callsign is not part of that request. Keeps nothing of yours. The Copernicus DEM distribution is the third party. Nothing to clear.
Beam headings
Sends nothing. Keeps nothing. No third party. Nothing to clear.
Grayline & blackout
Sends nothing. Keeps nothing. No third party. Nothing to clear.
D absorption
Sends nothing. Keeps nothing. No third party. Nothing to clear.
F layer
Sends nothing. Keeps nothing. No third party. Nothing to clear.
Auroral
Sends nothing. Keeps nothing. No third party. Nothing to clear.
NVIS
Sends nothing. Keeps nothing. No third party. Nothing to clear.
Tropo potential
Sends nothing. Keeps nothing. No third party. Nothing to clear.
Satellite lightning
Sends the part of the map you are looking at, so the flashes and counts match your view; it goes no further than dalMap. If you save your own EUMETSAT key on Data sources, the consumer key and secret you paste in are sent once to be checked with EUMETSAT, then kept only in a cookie in your own browser, never on dalMap’s server; this map then asks EUMETSAT directly with your credentials, but only when this dalMap’s own shared credential is not already supplying that coverage. Keeps nothing else. No third party beyond EUMETSAT for that request. Forget key on Data sources clears your saved credentials; there is nothing else to clear.
Satellite fire detections
Sends the area around your coarse grid to NASA FIRMS, to ask which detections fall inside it. If you save your own NASA Earthdata key on Data sources, that request goes to FIRMS using your key instead of this dalMap’s shared one; the key you paste in is sent once to be checked with FIRMS, then kept only in a cookie in your own browser, never on dalMap’s server. Keeps the shared answer for 15 minutes, labeled by the square it covers, so the same area is not asked for repeatedly; the detections in it are NASA’s rather than yours, and the square is the only part that came from you. Your own saved key is not kept anywhere but that browser cookie. NASA FIRMS and Upstash, which holds the shared answer, are the third parties. Turning the layer off stops it, Clear My station removes the square it was scoped to, and Forget key on Data sources removes your saved key.
NWS alerts
Sends the center of your coarse grid to the U.S. National Weather Service, to ask which alerts are active there. Keeps nothing of yours. The National Weather Service is the third party. Turning the layer off stops it, and Clear My station removes the square it was scoped to.
Tsunami alerts
Sends nothing. Keeps nothing. No third party. Nothing to clear.
Tornado reports
Sends nothing. Keeps nothing. No third party. Nothing to clear.
Plan satellite passes
Sends nothing. Keeps nothing. No third party. Nothing to clear. Passes, look angles, and Doppler are calculated in your browser from your saved grid and published satellite data. A pass you export to your calendar is a file your browser writes, and it includes your grid — where it goes after that is your calendar’s business rather than dalMap’s.
Satellite tracks
Sends nothing. Keeps nothing. No third party. Nothing to clear.
Satellite footprint
Sends nothing. Keeps nothing. No third party. Nothing to clear.
Moon & EME
Sends nothing. Keeps nothing. No third party. Nothing to clear.
Solar eclipse
Sends nothing. Keeps nothing. No third party. Nothing to clear.
Meteor showers
Sends nothing. Keeps nothing. No third party. Nothing to clear.
Worked log
Sends nothing: the ADIF file you choose is read in your browser and never uploaded, and no part of it enters a request, a report, or dalMap’s own records. Keeps a reduced private index — worked callsigns, bands, grids, and reference numbers — in your browser; the raw records are discarded once they have been read. No third party. Forget imported log clears it.
CQ WW candidate map
Sends nothing — it compares DX Cluster activity already on the map against the index Worked log keeps in your browser. Keeps nothing of its own. No third party. Cleared with the imported log.
Earth city lights
Sends your map view to NASA: your browser fetches the night-light tiles from NASA EOSDIS GIBS directly while the layer is on, so they see your network address and which area you are looking at. Keeps nothing. NASA EOSDIS GIBS is the third party. Turning the layer off stops it, and nothing is left behind to clear.
Radio references
Sends nothing. Keeps nothing. No third party. Nothing to clear.
Maidenhead grid
Sends nothing. Keeps nothing. No third party. Nothing to clear.
Time zones
Sends nothing. Keeps nothing. No third party. Nothing to clear.
Frequency Privileges
Sends your station callsign to HamDB when it is a United States callsign, the same way Find on map does — see that entry — to read the license class HamDB publishes for it. Keeps the same 24-hour Upstash entry Find on map keeps; this does not add a second one. HamDB is the third party. Clear My station, or Delete saved lookup on the map’s Data sources page, removes it, the same as Find on map. The frequency table itself is bundled with dalMap rather than fetched, and marks no row when your callsign has no class on file.
Alerts & watches
Sends nothing: a watch is matched in your browser against activity already on the map, and it never becomes a spot, a subscription, or a change to what dalMap requests. Keeps the watches you create in your browser until you remove them; whether one has already alerted lasts while the page is open. No third party. Removing the watch clears it.
Beyond the tools
My station
Sends your callsign and grid to dalMap with every page, which is what the tools above are scoped by; entering a callsign also looks it up, which has its own entry. Keeps them in your browser for 30 days, renewed each visit, alongside the layers, filters, units, and watch choices you have set. No third party. Clear My station removes the callsign and grid, and Delete saved cookie in About removes the whole set.
Find on map
Sends nothing when the map can answer. What you type is matched against the reports already on your map first, and against the beacon sites that ship with dalMap, and neither leaves your browser. Sends the callsign you look up — usually someone else’s — to HamDB, and to QRZ when HamDB has no published grid for it, only when nothing on the map answers and what you typed is a callsign; an airport identifier, a buoy number, or an award reference is never sent to either. Keeps the resulting grid for 24 hours, and the fact that there was no result for one hour, so the same callsign is not asked for repeatedly; that entry is held by Upstash rather than in your browser. HamDB, QRZ, and Upstash are the third parties. Delete saved lookup, on the map’s Data sources page, removes the entry for your saved callsign; clearing the result removes what is on the map. None of them changes what HamDB or QRZ holds.
Approximate location
Sends nothing unless you ask for it. When you do, the network address your request arrives from goes to IPWHOIS.IO and comes back as a four-character square; the address, the coordinates behind it, and the city are discarded rather than stored. Keeps only that square, with the rest of My station. IPWHOIS.IO is the third party. Clear My station removes it. An address-derived square can be wrong or drift, so it is orientation rather than a station location.
Share map
Sends nothing. Keeps nothing. No third party. Nothing to clear. A shared link carries public map state — where the map is, which layers are on — and not your callsign, your grid, imported logs, watches, or other private preferences. Whoever you send it to is the only person who has it, and nothing about you is in it.
Appearance
Sends nothing. Keeps your light, dark, or automatic choice in your browser until you change it. No third party. Choosing another appearance replaces it.
Errors and feedback
Sends an automatic report when dalMap runs into an error it recognizes, and whatever you write in Share feedback when you choose to send it, both to Sentry. Sends timing for about one visit in ten and a profile of the server answering those, also to Sentry, plus a running total of visits and requests. Sends dalMap’s complete operational log — including what a narrower note here used to cover, when an outside source fails or the server turns a request down — to Grafana Cloud instead. Keeps nothing in your browser. Sentry, run by Functional Software, Inc., and Grafana Cloud are the third parties. Nothing to clear here: what has been sent is held under each party’s own retention rather than dalMap’s.
An automatic report, when dalMap runs into an error it recognizes. You are not asked, and it happens whether or not you noticed anything. Every report is reduced before it leaves: the text of the error itself is replaced with a fixed phrase, so the words a fault produced are not carried; addresses lose everything after the page path, which is where Share map keeps map state; and any value labeled as a callsign, grid, coordinate, latitude, longitude, network address, token, email, or password is removed, as are request headers and cookies. What is left describes where in the product something went wrong, not what you were doing or who you are.
Share feedback, when you choose it. It sends what you write, and a name or email address only if you decide to enter one — neither is required, and no screenshot is taken or attached. Because the automatic report above carries so little, what you type is the part that says what actually happened; the same reason applies to leaving private station details, exact location, and credentials out of it.
A location that neither of them sends. Sentry works out a country and a city from the network address a report reaches them on, and keeps it beside the record. That applies to both of the things above, whatever dalMap removed first, and it is added once the report is already with them — so dalMap cannot take it back off. Removing it is a request to Sentry, the same as removing the report itself.
Timing, for one visit in ten. About a tenth of the time, dalMap also times what it is doing — how long a page took to open, how long a request to its own server took — and sends that to Sentry as well. It is measured in both places: in your browser as you move between views, and on the server as it answers. Addresses in it are cut at the page path, the same as in a report, so what arrives is how long a named step took rather than what you asked for. Which tenth is chosen at random, not by who you are.
A profile of the server, while it is answering. For those same sampled requests, Sentry receives which function the server was running and where. It is a measurement of dalMap’s own code, taken on dalMap’s own machine. Nothing from your browser is in it, and nothing about you: it exists to find the slow part of a page, and it can only see the server’s side of one.
dalMap’s own operational log, complete, sent to Grafana Cloud. Every line the server writes about what it is doing — not a curated note about one kind of failure — goes to Grafana Cloud. That is broader than what reached a third party here before: it can include your callsign or grid, when a line already names one in describing a station-scoped request or activity generated on its behalf. It still excludes cookies, headers, a raw network address, the contents of a request, and everything after the page path in an address, the same as everywhere else on this page. This is not cleared by anything on this page; it is dalMap’s own operating record, the same as an error report, rather than something kept about your device.
A running count of feed failures and refused requests, still to Sentry. When one of the outside sources dalMap reads from fails, or dalMap’s own server turns a request down, Sentry counts it — how many refusals of a given kind in the last hour, how often a particular source is failing — without receiving each one as its own note the way it used to: the same reason, the same status, and the same source name, but counted rather than listed. A count is the one shape that answers “is this getting worse”, which is what the alerting it exists for asks.
A count of visits and requests. Sentry receives a running total of how many browser sessions were started and how many requests the server served, and how many of each ended in an error, so a release that is going wrong can be told apart from one that is not. It is a total against the release and nothing else — not a list, not who, not which pages. Yours is not distinguishable within it.