Legal
Privacy Policy
The short version
- We collect what ShackOS needs to work: your account, your log, your station, and the security records any online service keeps.
- We do not sell your personal information, show ads, or use advertising or third-party analytics trackers.
- Elmer, the AI assistant, is optional. If you never open him, nothing about you is sent to the AI provider. When you do, your data is not used to train AI.
- Connections to other services, such as QRZ.com, only happen when you set them up or use them.
- You can export your log at any time and delete your account yourself from Settings.
Contents
- Who we are
- What we collect
- How we use it, and why
- Elmer and AI
- Who we share it with
- Where it is processed
- How long we keep it
- Your choices and rights
- Cookies and browser storage
- Security
- Children
- Other operators’ information
- The contact form
- Changes to this policy
- How to reach us
1. Who we are
ShackOS is run by Chris Hawk (callsign W7CWH), an individual in Phoenix, Arizona, United States. In this policy “ShackOS”, “we”, “us” and “our” mean Chris Hawk operating ShackOS. For the purposes of data protection law, he is the controller of the personal information described here.
You can reach us through the contact form or at [email protected]. We have not appointed a data protection officer; privacy questions come to the same place.
2. What we collect
Information you give us
- Account: your callsign, name, email address and password. Your password is stored only as a one-way bcrypt hash; we cannot read it. Optionally your license class and a note to the administrator when you register. We record when you accepted these terms and which version.
- Station profile: your grid square, time zone, elevation and display preferences (theme, units, time format, accessibility settings).
- Equipment: radios, antennas (including height and direction) and accessories, with any notes you add; and, if you use radio control, the connection settings for your radio.
- Logbook: the contacts you log or import, including the other station’s callsign, and if you record them, their name, location, grid square, signal reports, notes and comments.
- POTA and SOTA: activations, scheduled activations, spots you post, and park notes you write.
- Rolodex: contacts you save, with any details you add, which may include another person’s phone number or email address.
- Dashboard: your card layout and anything you type in the Scratch Pad.
- Elmer conversations: what you ask Elmer and his replies (see section 4).
- Voice recordings are not kept. If you talk to Elmer, the recording is converted to text on our server and discarded; only the text is kept, as part of the conversation.
- Support and feedback: support tickets, the Help assistant conversation if you attach it to a ticket, beta feedback, and contact-form messages.
- Credentials for other services you choose to connect, such as your QRZ.com username and password, QRZ logbook API keys and HamQTH login. Passwords and keys are encrypted in our database (AES-256-GCM); your HamQTH username is stored unencrypted.
- AllStar (early access): your node numbers and settings, the commands you send, alert settings, a log of who was heard on your nodes (the node number or callsign of each station that transmitted through them, and when), and from the ShackOS agent on your node: its hostname, operating system, software versions, network addresses, and CPU, memory and disk use. Live audio passes through our server to reach you and is not recorded.
- Off-air transcription (in testing, limited accounts): received audio sent for speech-to-text (see section 4). Recordings you make are kept in your browser and never uploaded.
Information collected automatically
- Security records: the IP address and browser details (user agent) of each sign-in and each signed-in session, failed sign-in counts, and a log of security-relevant actions such as registration, password changes, account deletion and administrator actions.
- Usage records (first-party only): while ShackOS is open and visible, a heartbeat once a minute (so we can see how long people use it); which pages and features you open; and how the Elmer panel is used (for example, that it was opened and how long a question was, never the draft text).
- Error reports: when something fails, the error, the page or request involved and your callsign. Passwords and tokens are removed before an error is recorded.
- Web server logs: the IP address, address requested, referring page and user agent of each request.
- Performance statistics: response times per type of request, with no user or IP address attached.
Information from other sources
- Public callbook data from Callook and HamDB when you look up a callsign, including during registration (name, location, grid and license class of the station looked up). These results are cached and shared between users, with email and street addresses removed first. Results from your own QRZ.com or HamQTH login are kept in server memory for up to 10 minutes, for you only, and are never cached in our database or shown to anyone else.
- FCC license records (US only, from the FCC’s license database via Callook): the grant date and license class for your callsign, stored with your account and used for overall statistics about our users’ experience; and the same data for callsigns you ask Elmer about.
- Public spotting networks: PSK Reporter reception reports, POTA spots, and DX cluster spots. These are public by design and may include your callsign if you are on the air.
We do not ask for and do not knowingly collect sensitive categories of information, such as health, financial or government ID information. We do not collect your precise location from your device; your location in ShackOS is the grid square you enter.
3. How we use it, and why
Data protection laws such as the GDPR require a legal basis for each use. Ours are: contract (needed to provide the service you signed up for), legitimate interests (our reasonable interests, balanced against yours, which you can object to), consent, and legal obligation.
| What we do | Data used | Legal basis |
|---|---|---|
| Run your account, logbook, dashboard, forecast, POTA tools and the other features you use | Account, station, equipment, log, settings | Contract |
| Answer your questions through Elmer, when you use him | The data listed in section 4 | Contract (you asked) |
| Connect to services you set up, such as QRZ logbook sync | Your credentials for that service and the data it needs | Contract (your instruction) |
| Send account emails: confirmation, sign-in codes, password resets, approval and security notices, replies to support | Email address, callsign, name | Contract |
| Keep accounts and the service secure; detect and stop abuse; investigate problems | Security records, error reports, web server logs | Legitimate interests (security) |
| Understand which features are used and where Elmer gets things wrong, to improve ShackOS | Usage records, Elmer question text and ratings, feedback | Legitimate interests (improving the service). You can object. |
| Measure and improve forecast accuracy | Anonymous forecasts bucketed to a 4-character grid square, compared against public PSK Reporter reports. No callsign, account or IP address. | Legitimate interests (anonymous research) |
| Answer contact-form messages | What you send us | Legitimate interests (replying to you) |
| Meet legal requirements and enforce our Terms | Whatever the requirement covers | Legal obligation; legitimate interests |
We do not:
- sell your personal information, or share it for targeted advertising;
- use advertising, social-media or third-party analytics trackers;
- use your data to train any AI model, or allow our AI provider to;
- make decisions about you by automated means that have legal or similarly significant effects.
Your callsign, email address and a password are required to create an account; without them we cannot provide ShackOS. Everything else is optional, though some features need it (the forecast needs your grid square, for example).
4. Elmer and AI
Elmer is an optional AI assistant inside ShackOS. ShackOS also has a Help assistant on the Help page. Both use Claude, a model made by Anthropic, PBC, through Anthropic’s commercial API. Anthropic processes this data on our behalf as our service provider.
When anything is sent
Nothing about you is sent to Anthropic until you open Elmer: his panel, the Elmer card if you add it to your dashboard, or the Help assistant. Opening Elmer prepares a greeting and suggested questions for you, and each question you ask sends a request. If you never open him, no information about you reaches the AI provider.
What is sent to Elmer
- your callsign, license class, grid square, time zone and local time;
- your radios, antennas and accessories, including notes you wrote on them;
- a summary of your log (totals, bands, modes, countries, busiest hours) and your eight most recent contacts (the other station’s callsign, country, band and mode);
- current band conditions and space weather for your location, recent band activity, and any POTA activation in progress with your POTA totals;
- if you use AllStar early access, your nodes, the callsigns of nodes connected to them and who was heard on them recently; if you use radio control, your radio’s current frequency, band and mode;
- your recent messages in the conversation (up to eight), and the results of any lookups Elmer makes to answer you, such as FCC license data for a callsign you ask about.
ShackOS does not send your name, email address, password or credentials for other services. Anything you type into a message is sent as written, so please do not include passwords or other sensitive information.
Talking to Elmer
Where voice is turned on for your account, you can talk to Elmer and hear him answer. Your browser asks for permission to use the microphone, and the microphone is on only while you are talking to him (after you press Talk, or in hands-free conversation while Elmer is listening). Your recording goes to ShackOS’s own server, is turned into text there, and is discarded when that request ends: it is never stored and never sent to Anthropic or anyone else. The text then goes to Elmer like a typed message. His spoken replies are made on our server from his written reply. Your voice settings (whether replies are read aloud, which voice) are stored with your account.
The Help assistant sends only the messages in that Help conversation, with no account details.
What Anthropic does with it
- No training. Under Anthropic’s commercial terms, Anthropic does not use what we send, or Elmer’s replies, to train its models.
- Retention. Anthropic deletes API inputs and outputs within 30 days. If a request is flagged as violating Anthropic’s usage policy, Anthropic may keep it for up to two years, and its safety classification for up to seven.
- See Anthropic’s Privacy Center and Commercial Terms.
What ShackOS keeps
- Your conversation: the last ten messages, so the chat is there when you return. Clear chat in the Elmer menu deletes it.
- Question records: the text of each question (up to 2,000 characters), its topic, response time, and any thumbs-up or thumbs-down you give, for twelve months. The administrator can read these to find where Elmer is wrong. They are deleted with your account.
- Summary reports: the administrator can ask Claude to summarise overall usage. Only counts and percentages are sent, never callsigns or question text.
Off-air transcription (in testing)
A small number of accounts are testing live transcription of received audio. When it is on, audio is sent to Deepgram for live speech-to-text, with Deepgram’s model improvement program switched off, so Deepgram keeps the audio only as long as it takes to process it; and short clips may be sent to Replicate (running OpenAI’s open-source Whisper model) for a more accurate second pass, which Replicate deletes automatically about an hour later. Received audio can contain other operators’ voices and callsigns; amateur transmissions are public by nature. This section will be updated before transcription is offered to everyone.
AI output
Elmer’s answers are generated by AI and can be wrong. They are not professional advice. See section 8 of the Terms of Service.
5. Who we share it with
We share personal information only with the service providers that run ShackOS, with services you choose to connect, and where the law requires it. Our service providers may use it only to provide their service to us.
| Provider | What it receives | Why |
|---|---|---|
| DigitalOcean (United States) | All data stored by ShackOS | Hosts our server and database |
| Cloudflare | All traffic to our sites, including your IP address | Network delivery and protection against attacks; Turnstile on the contact form |
| Anthropic | The data in section 4, when you use Elmer or the Help assistant | Elmer and the Help assistant |
| Brevo | Your email address and the content of account emails (including sign-in codes); contact-form messages; administrator notices that include a new user’s callsign, name, email and registration note, and error alerts that include the callsign involved | Sending email |
| Microsoft OneDrive | Encrypted copies of our database backups. They are encrypted on our server before upload, and Microsoft does not hold the key. | Off-site backup |
| Deepgram and Replicate | Received audio, only for accounts testing transcription | Speech-to-text |
| Service | What it receives | Why |
|---|---|---|
| OpenFreeMap, Esri, Amazon Web Services | Your IP address and the map area you are viewing | Map tiles, satellite imagery and terrain for the maps |
| QRZ.com and HamQTH | Your IP address | Photos shown in callsign lookup results |
| Cloudflare Turnstile (contact page only) | Your IP address, browser details and signals about how the page is used | Telling people from bots. See Cloudflare’s Turnstile privacy addendum. |
| Service | What it receives | When |
|---|---|---|
| QRZ.com | Your QRZ username and password, and the callsign you look up; your QRZ logbook key and the contacts being synced | When you look up a call with QRZ configured, or sync your QRZ logbook: when you push or pull, and, if you turn on QRZ live sync, automatically as you log and edit contacts |
| HamQTH | Your HamQTH login and the callsign you look up | When you look up a call with HamQTH configured |
| Callook | The callsign being looked up | Lookups of US calls (including Elmer’s), ADIF import, the registration form, and FCC license data for user statistics |
| HamDB | The callsign being looked up | Lookups of US and Canadian calls that Callook does not answer |
| Parks on the Air | Spots you post, including your callsign as spotter; POTA publishes spots publicly | When you spot yourself or another station |
| PSK Reporter | The callsign whose reports you ask for | Signal map queries |
| Open-Meteo | The coordinates of your grid square, with no account or callsign | Weather data for the VHF/UHF ducting forecast |
| AllStarLink | Node numbers | Node status, for AllStar users |
| Your own webhook | AllStar alert events | Only if you set one up |
When you use a connected service, its own terms and privacy policy apply to what it receives. Other services ShackOS reads from, such as NOAA, HamQSL and the DX clusters, receive nothing about you.
Other sharing
- Other ShackOS users can see park notes you write, with your callsign and name.
- Legal requirements: we may disclose information if the law requires it, such as a valid court order, or to protect the safety, rights or property of our users, the public or ShackOS.
- If ShackOS changes hands: if ShackOS is transferred to another operator, your information would go with it, under this policy; we would tell you first and you could delete your account.
6. Where it is processed
ShackOS is run from the United States, and our server is in a DigitalOcean data centre in the United States. If you use ShackOS from outside the US, your information is transferred to and processed in the US, where data protection law may differ from yours and where it may be accessible to US courts, law enforcement and national security authorities. Our providers that handle personal data on our behalf, including DigitalOcean, Cloudflare and Anthropic, commit to safeguards such as the EU Standard Contractual Clauses in their data processing terms.
7. How long we keep it
We keep information only as long as it is useful for the purpose it was collected for. The automatic deletions below run every hour.
| Information | How long |
|---|---|
| Account, station, equipment, logbook, settings, Rolodex, activations, AllStar settings | Until you delete your account |
| Elmer conversation | The last ten messages, until you clear the chat or delete your account |
| Elmer question records | 12 months, or until you delete your account |
| Sign-in history (IP address, browser) | 12 months, or until you delete your account |
| Signed-in sessions (IP address, browser) | Until the session expires (at most 90 days), then 1 to 7 days |
| Usage heartbeats | 12 months, or until you delete your account |
| Pages and features opened | 120 days, or until you delete your account |
| Elmer panel usage | 120 days, or until you delete your account |
| Performance statistics (no user or IP) | 7 days |
| Error reports | 90 days, or until you delete your account |
| Support tickets | 24 months, or until you delete your account |
| Beta feedback | Until you delete your account |
| Security log (registration, password changes, deletions, administrator actions) | 24 months. Kept after account deletion as a security record, with your email address removed. |
| AllStar command history, node logs and who was heard | 90 days (commands) and 30 days (logs and who was heard) |
| Web server logs | A rolling log of fixed size (30 MB); the oldest entries are overwritten as new ones arrive |
| Contact-form messages | Not stored in ShackOS. Kept in our mailbox for up to 24 months after the conversation ends. |
| Anonymous forecast-accuracy records (4-character grid square only) | 730 days |
| PSK Reporter reports | 2 hours, in memory only |
| Backups | Nightly backups for 7 days; a copy taken before each software update, keeping the latest ten; encrypted off-site copies for 30 days |
| Data held by Anthropic for Elmer | Up to 30 days (see section 4) |
When you delete your account, we delete straight away your account and everything linked to it above, including your log, equipment, settings, Elmer conversation and question records, support tickets, feedback, usage records and error reports. What remains is the security log entries about your account, which include your callsign and IP address but not your email address, for the period above; your callsign in the shared cache of public callbook lookups if someone looked you up; and copies in backups, which are overwritten on the schedule above. A park note you wrote is deleted with your account.
8. Your choices and rights
Things you can do yourself, any time
- See and correct your account, station, equipment and log in the app.
- Export your log as an ADIF file from the Log page, and each POTA activation from POTA.
- Clear your Elmer conversation from the Elmer menu, or simply never open Elmer.
- Disconnect QRZ.com or HamQTH by removing your credentials in Settings.
- Delete your account in Settings.
Things you can ask us for
Depending on where you live, you may have the right to: get a copy of the personal information we hold about you (including in a portable format); correct it; delete it; restrict or object to how we use it, including the usage and Elmer quality records we keep on the basis of legitimate interests; and withdraw consent where we rely on it. We honour these requests from everyone, wherever they live.
Send requests through the contact form (choose “Privacy or data request”) or to [email protected]. We will acknowledge your request within 30 days and respond within one month, or tell you within that month if we need longer (up to two further months for complex requests). We may ask you to confirm your identity, usually by replying from the email address on your account. We will not treat you differently for exercising your rights.
Complaints
If you are unhappy with how we have handled your information, please tell us first and we will try to put it right. In the European Economic Area you may also complain to the data protection authority where you live or work; in the United Kingdom, to the Information Commissioner’s Office (ico.org.uk); in Canada, to the Office of the Privacy Commissioner of Canada.
California and other US states
We do not sell or share personal information as those terms are defined in California law, and we do not process sensitive personal information to infer characteristics about you. Do Not Track and Global Privacy Control: ShackOS does not track you across other websites and does not allow third parties to do so through ShackOS, so these browser signals do not change how we handle your information. The third-party services in section 5 receive your IP address as part of delivering their service and are governed by their own policies.
9. Cookies and browser storage
ShackOS uses only storage it needs to work. There are no advertising or analytics cookies.
- Sign-in cookie (
shackos_rt): keeps you signed in. It cannot be read by scripts, is only sent to our sign-in endpoint, and lasts for the browser session, or up to 90 days if you tick “Remember me”. - Session storage in your browser tab: a short-lived access token (15 minutes) and the day’s Elmer greeting.
- Local storage on your device: your theme (so the sign-in page can use it), your profile if you chose “Remember me”, and preferences such as map style, logging defaults, audio levels and which notices you have dismissed.
- IndexedDB and the offline cache on your device: POTA and SOTA contacts waiting to sync, park information for offline use, and the app itself so it opens quickly. Unsynced contacts stay on the device after you sign out so they are never lost; clear your browser’s site data to remove them.
- Cloudflare, which delivers our sites, may set cookies needed for security and bot protection.
This site, shackos.net, sets no cookies of its own. The contact page loads Cloudflare Turnstile.
10. Security
We protect your information with measures including: encrypted connections (HTTPS) everywhere; passwords stored only as bcrypt hashes; short-lived sign-in tokens with a refresh cookie scripts cannot read; optional two-step sign-in by emailed code; account lockout and rate limits against password guessing; encryption of the credentials you give us for other services; encryption of off-site backups; and administrator functions limited to administrator accounts, checked on every request.
No system is perfectly secure. Use a password you do not use anywhere else, and turn on two-step sign-in in Settings. If a breach affects your personal information, we will tell you, and the authorities where the law requires, without unreasonable delay.
To run and secure the service, the administrator can see account details, sign-in history, support tickets, feedback, error reports and Elmer question records (the text of questions, not Elmer’s replies). There is no administrator screen for reading your logbook entries or your Elmer conversation, and nobody can see your password.
11. Children
ShackOS is for licensed amateur radio operators aged 13 or older. It is not directed at children under 13, and we do not knowingly collect personal information from them. If you are 13 to 17, a parent or guardian must agree to our Terms and this policy with you. If you live in a country that sets a higher age for consenting to online services, the same applies up to that age.
If we learn that we hold information from a child under 13, we will delete the account and its information. If you are a parent or guardian and believe your child under 13 has an account, please contact us.
12. Other operators’ information
Your log and Rolodex hold information about other people: callsigns and, if you add them, names, locations and contact details. Much of this is shared publicly in amateur radio, but you are responsible for having a right to record what you add. If you are an operator whose details appear in ShackOS and you have a concern, contact us and we will help.
13. The contact form
The contact form on shackos.net collects your name or callsign, email address, the topic and your message, and emails them to us through Brevo so we can reply. They are not stored in the ShackOS database, not added to any mailing list and not shared with anyone else. We keep contact emails for up to 24 months after the conversation ends. To prevent spam, the form uses Cloudflare Turnstile, which processes your IP address, browser details and similar signals (see Cloudflare’s Turnstile privacy addendum), and we use your IP address briefly to limit how many messages one connection can send. Our legal basis is our legitimate interest in answering you.
14. Changes to this policy
We will update this policy when ShackOS changes. The effective date at the top always shows the current version. For a significant change, we will email you before it takes effect. We will not start using information we already hold in a materially different way without telling you first, and where the law requires it, asking for your consent.
15. How to reach us
Chris Hawk, W7CWH · Phoenix, Arizona, USA · [email protected] · contact form.