Jahtiradio privacy policy
Updated 1 October 2026. The Finnish version (tietosuojaseloste) is the primary text. The app’s Finnish interface names the same settings “Tekstitä puheeni” and “Lähetä akkutilastot ja virheraportit”.
Jahtiradio is a push-to-talk radio for hunting parties. This policy explains what data the app and its server process, why, and for how long. The app has no user accounts, no ads and no ad tracking. The app sends technical error reports and battery statistics only if you allow it. We never sell your data.
Controller
Latentti Oy
Business ID: 3183704-9
Taimenkuja 7, 01490 Vantaa, Finland
Email: info@latentti.fi – use this address for privacy questions, requests and reports of offensive content.
In short
- A hunt's content is taken out of use and deleted at 04:00 Finnish time. The cloud provider's backups keep deleted data for at most 30 more days.
- There is no account. The app only asks for the name your hunting party knows you by.
- A hunt leader can set up a hunting party that lasts from day to day and under which the day's hunts are created. For a hunting party we keep its name, its ID, the hunt leaders' names and device identifiers and the season details.
- Your location is sent to the hunt only when you send an emergency alert and have allowed location access.
- When you create or join a hunt, the server uses your location to check whether you are near the hunt's creator, so that someone trying random codes cannot get in. Other members never see this location. A joiner's location is not stored, and the creator's location is deleted with the hunt at 04:00.
- The microphone is on only while you talk.
- On iPhone, Apple's notification service wakes the app when someone talks or sends an emergency alert. The identifiers needed for this are deleted from the server when you leave the hunt or the hunt ends.
- The server counts anonymous statistics on how the service is used, such as the number of hunts and transmissions. They contain no names, codes, device identifiers or content.
- On first launch the app asks whether it may send technical error reports and battery statistics. Nothing is sent before you answer, and sending is off by default. The reports and statistics contain no device identifier, name, hunt or location. You can change your choice in the settings.
- Speech to everyone in the hunt is machine-transcribed by Cloudflare's AI service. The app tells you about transcription on first launch. You can turn off transcription of your own speech in the settings. Private talk is never transcribed.
What we process
Your name. You type it when you first open the app. Other members of the hunt see it next to your talk, messages and in the member list. The name is required to use the service, because your hunting party recognises the speaker by it.
Device identifier. On first launch the app creates a random identifier. It contains no serial number or other hardware data. The server uses it to recognise you as a member of the hunt, and the apps of other members of the hunt can see it. On iPhone the identifier is kept in the keychain, so it survives deleting and reinstalling the app.
Hunt data. Hunt code, hunt name, creation and end time, and when members joined or left. If a member approved your join, the message stream also shows that member's name.
Voice. While you hold the talk button, your voice is relayed to the hunt. The server stores each transmission as an audio clip so it can be replayed. Private talk is stored the same way, but only the speaker and the recipient can hear it. If your phone has no coverage, your speech is first saved on the phone and sent when the connection returns.
Machine transcription. Speech to everyone in the hunt is converted to text automatically. The audio clip is sent to Cloudflare's AI service for transcription, together with a hunting vocabulary and the names of the members of the hunt to improve accuracy. The resulting text is stored in the hunt's message stream. If a member of the hunt reads messages in another language, transcripts and typed messages are translated for them by the same AI service. Translations are stored in the hunt and deleted with it. Private talk is not transcribed. The app tells you about transcription on first launch. You can turn off transcription of your own speech in the settings.
You can turn off transcription of your own speech. The settings have the option “Transcribe my speech”, which is on by default. When you turn it off, your speech to the hunt is not sent to the AI service, and no text or translation is made of it. Others still hear your speech and can replay it as before, and the message stream shows “no transcript” next to it. The option does not affect whether you see transcripts of other members' speech. It applies to speech that reaches the server after you change it. The apps of the other members of the hunt receive whether transcription of your own speech is on and in which language you read messages.
Typed messages and reactions. Messages you type to the hunt. When you react to a message (👍, 🎉 or 👀), the server stores the reaction with your name next to that message. Members of the hunt can see who reacted. Reactions are removed together with the hunt.
Emergency alert. An emergency alert contains your name, device identifier and the time. If it was sent late from a place without coverage, it also carries a delay flag and the original time. If you have allowed location access, the phone's precise location and its accuracy in metres are attached. All members of the hunt see the location.
Wake-up identifiers (iPhone). When an iPhone joins a hunt, the app joins Apple's Push to Talk service. Apple gives the app a Push to Talk identifier and a notification identifier, and the app sends them to the hunt's server. The server stores them with your entry in the member list. When someone starts talking or sends an emergency alert while your app is in the background or offline, the server asks Apple's push notification service (APNs) to wake the app. The request contains the identifier and the name of the speaker or of the alert's sender. No voice, text or location is sent to Apple. The Android app sends no identifiers.
Location. The app reads the phone's location in three situations:
- when you create or join a hunt – the server measures the distance to the hunt's creator (see *Protecting the hunt from outsiders*)
- when you send an emergency alert – the location is sent to the hunt with the alert
- when you open an emergency alert you received – the app works out the distance and direction to the sender. This reading stays on the phone and is not sent anywhere.
If the phone cannot get a fresh reading within a few seconds, the app uses the phone's last known location, which may be older than the moment of sending. An alert sent without coverage is delivered later with the location from the moment you pressed the button. The app does not track your location in the background.
If you open the location of an emergency alert you received on a map, the app hands the coordinates to your phone’s map app, for example Google Maps or Apple Maps. The map app processes them under its own terms.
Protecting the hunt from outsiders. When you create a hunt, the app sends the phone's location and its accuracy to the server if you have allowed location access. The server stores the creator's location with the hunt and uses it only to measure how far joiners are. When you join a hunt, the app sends your own location in the same way. The server calculates the distance to the creator and does not store, log or show your location to anyone. If you are within about 30 kilometres of the creator, you get in at once.
If you join from further away or your location is unknown, the hunt's members get a join request. It shows your name and whether the joiner is far away or the location is unknown. The request is stored in the hunt. Any member can approve or reject it. A request expires after ten minutes.
Removing a member. Any member of the hunt can remove another member from the hunt. The server stores the removed device identifier and the name of the member who removed it, so that the same phone cannot rejoin the same hunt. The message stream keeps a note of the removal. The removed member is told who removed them.
Hunting party and season. A hunt leader can set up a hunting party and invite other hunt leaders to it with an invite code. The server stores the party's name, a random party ID, its creation time, the founder's device identifier and when the party was last used. For each hunt leader it stores the device identifier, role and joining time. Each hunt leader also has a hunt leader key, a random identifier tied to their device identifier. For the party the server also stores the number of hunt leader seats, when the trial period started, until when the party's season is valid, and whether the party takes part in a pilot. No names of hunt members, voice, messages or locations are stored with the party. An invite code is valid for seven days and works once. The server stores from whose device the code was created and who used it. A hunt leader’s seat can have two devices, for example a phone and a tablet. For each device the server stores the device key ID, the platform (iOS or Android) and the time it was added. The second device is added with a code that is valid for 15 minutes and works once. The device details are deleted with the hunt leader’s seat or with the party. The owner of a party can transfer ownership to another hunt leader. The hunt leader’s seat also stores the name the hunt leader uses in Jahtiradio. The name is shown to the other hunt leaders of the same party and is deleted with the seat or with the party.
Purchases and invoicing. Jahtiradio is free for now. A season cannot yet be bought in the app or by invoice, and club codes cannot be redeemed. This section explains what data is processed once the season fee is introduced.
If you buy a Jahtiradio season in the app, Apple (App Store) or Google (Google Play) handles the payment. We do not receive your card details, name or email address. The app sends the receipt signed by the store to the server, which checks it. For each purchase we store the product, store, transaction identifier, purchase time, end of the season, storefront, price and currency. For a Google Play purchase we also store a hash of the purchase token so that the purchase can be restored.
A club can also buy a season by invoice. For the invoice we process the payer’s name, address, email address and business ID and the invoice details. A club that has paid the invoice receives a redeem code, which a hunt leader redeems for the party on a web page. The server stores the redeem code, the invoice reference and the party the code was redeemed for.
Reports of offensive content. If you report a member from the app, your phone's email app opens a message with the member's name and the hunt code. We process the report and the related email to look into the matter. Blocking a member happens only on your own phone and sends nothing to the server.
IP address and technical data. The server uses your IP address and device identifier to prevent abuse by limiting how many requests can come from one source per minute. The service's technical log records request and error data for troubleshooting. With every request the app states its version and whether it is the Android or the iPhone app, so that the server can ask you to update an outdated version. The session token contains your name and the hunt code and may appear in the log as part of a request address.
Battery statistics. While you are in a hunt, the app measures the phone's battery use. When you leave the hunt or it ends, the app sends a summary to the server: phone manufacturer and model, operating system and app version, battery level at the start, at the end and every hour, charging periods, drain in percent per hour, screen-on time and the audio route used (speaker, earpiece, wired, Bluetooth or silent). It also covers the app's own CPU time, data volume, talk time and the number of transmissions received. An iPhone also sends Apple MetricKit's daily summary of the app's energy use. The app starts using MetricKit only after you have allowed sending.
The summary contains no device identifier, name, hunt code or name, and no location. The server does not store your IP address with the statistics, and the summary is not linked to you or your hunt. We use the statistics to reduce the app's battery use on different phone models. The app asks for permission before the first sending, and sending is off by default. You can change your choice in the settings under “Send battery statistics and error reports”. You see your own figures in the hunt history and the settings; they stay on the phone.
Usage statistics. The server counts anonymous figures from its own events so that we can size the service and follow its costs and reliability. The statistics count, for example, hunts started, members, transmissions, messages, emergency alerts, transcriptions and translations. They also include the length of talk, the time of day and weekday, the language and duration of transcriptions and translations, the app's platform and version, and the country from which a hunt is joined. The statistics contain no names, hunt or hunting party codes, device identifiers, IP addresses, locations, or the content of talk or messages. The events of one hunt are linked by a random identifier that is unrelated to the hunt code and is deleted with the hunt at 04:00. A hunting party appears only as a hash that cannot be linked to the party without the server's secret key and that changes every hunting year. It is used to count how many hunting parties come back to the service. Because no single user can be identified from the statistics, we cannot pick out one person's data from them.
Error reports. If the app crashes or a technical error occurs, the app sends an error report to the Sentry service. On iPhone a report can also concern the app freezing. The report contains the app and operating system version, the phone model, the type of error and where in the program code it occurred (stack trace), technical error codes, the audio route in use and counts related to the error. The app does not send Sentry any information about app use, only errors. The server also sends reports of its own errors to Sentry.
An error report contains no name, device identifier, hunt code, voice, transcripts, messages or location. The hunt code is removed from the report before it is sent. Sentry does not store your IP address. We use the reports to find and fix faults that stop the app from working. The app sends error reports only if you have allowed them. The app asks about this on first launch, and sending is off by default. You can change your choice in the settings under “Send battery statistics and error reports”.
We do not collect your contacts, phone number, email address, photos or other data on your phone beyond the battery statistics and error reports above. We see your email address only if you email us.
Purposes and legal bases
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Talk to everyone in the hunt, private talk, replay and message stream | name, device identifier, hunt data, voice, messages | contract: the service you ask for (Art. 6(1)(b)) |
| Hunting party, hunt leader invites, trial and season | party name, hunt leaders' names, device identifiers, platforms, roles and joining times, season details | contract: the service the hunt leader asks for (Art. 6(1)(b)) |
| Checking purchases and keeping purchase records (once the season fee is in use) | purchase records, redeem codes and invoice references | contract (Art. 6(1)(b)); keeping them: legitimate interest in handling refunds and complaints (Art. 6(1)(f)) |
| Invoicing clubs and bookkeeping (once the season fee is in use) | payer’s name, address, email address and business ID, invoice details | contract (Art. 6(1)(b)) and the obligation under the Finnish Accounting Act (Art. 6(1)(c)) |
| Machine transcription | voice to everyone in the hunt, member names | contract: transcription is part of the service (Art. 6(1)(b)). The app tells you about transcription on first launch, and transcription of your own speech can be turned off in the settings. |
| Protecting the hunt from outsiders: distance check, join requests and removing members | creator's location, joiner's location (only to calculate the distance), name, device identifier | contract: a protected hunt is part of the service (Art. 6(1)(b)). You can choose not to give a location; a member then approves the join. |
| Emergency alert and its location | name, device identifier, precise location | contract: a feature you start by pressing SOS (Art. 6(1)(b)). You can block location use in the phone's settings. |
| Waking the app for talk and emergency alerts (iPhone) | Push to Talk identifier, notification identifier, name of the speaker or sender | contract: the radio works on the lock screen too (Art. 6(1)(b)) |
| Handling reports | report content, email address | legitimate interest: security of the service and misuse (Art. 6(1)(f)) |
| Abuse prevention and troubleshooting | IP address, device identifier, app version, technical log | legitimate interest: security and reliability (Art. 6(1)(f)) |
| Reducing battery use | battery statistics: phone model, versions, battery level and drain, the app's technical usage | consent (Art. 6(1)(a); section 205 of the Finnish Act on Electronic Communications Services). You can withdraw consent in the settings. |
| Sizing, cost monitoring and development of the service: usage statistics | anonymous counts of service events, app platform and version, country, a hunting party hash that changes every hunting year | legitimate interest: sizing and developing the service (Art. 6(1)(f)) |
| Finding and fixing faults: the app’s error reports | app and operating system version, phone model, error type and stack trace, technical error codes, audio route, counts | consent (Art. 6(1)(a); section 205 of the Finnish Act on Electronic Communications Services). You can withdraw consent in the settings. |
| Finding and fixing faults: the server’s error reports | the server’s error type, stack trace and technical error codes | legitimate interest: keeping the service working (Art. 6(1)(f)) |
Data is not used for marketing, profiling or automated decision-making.
Who processes the data
The server runs on Cloudflare, Inc.'s cloud platform. Cloudflare processes hunt content on our behalf under a data processing agreement and does not use the content to train AI models. Cloudflare may also process technical service data, such as traffic and billing data, as its own controller for security and abuse prevention.
- Hunt content (voice, transcripts, messages, emergency alerts and the member list) is stored in the European Union.
- The list of hunt codes is stored in a Western European data centre.
- Hunting party data, purchase records and redeem codes are stored in the same Western European data centre.
- Battery statistics are stored in Cloudflare's Analytics Engine service.
- Usage statistics are stored in the Analytics Engine service, and their daily summaries in the same Western European data centre as the hunting party data.
- Transcription, battery statistics, usage statistics and the technical log may be processed in a Cloudflare data centre outside the EU. Such transfers rely on Cloudflare's data processing terms and the EU Standard Contractual Clauses included in them.
Error reports are processed on our behalf by Functional Software, Inc. (Sentry) under a data processing agreement. The reports are stored in Sentry’s EU region in Frankfurt. If Sentry accesses the reports from the United States, for example for technical support, the transfer relies on the EU Standard Contractual Clauses included in the data processing agreement.
iPhone wake-ups and emergency notifications go through Apple Inc.'s push notification service (APNs). Apple receives the identifier of the wake-up request and the name of the speaker or of the alert's sender, and processes them under its own terms, also outside the EU.
On Android, the location is read with the Google Play services location provider when it is available on the phone. Google processes location service data under its own terms.
Once the season fee is in use, season purchases are handled by Apple (App Store) and Google (Google Play) under their own terms. Club invoices and bookkeeping are handled in an accounting and invoicing service that processes the data on our behalf.
Other members of the hunt receive the hunt's voice, transcripts, messages and emergency alerts on their phones. We do not disclose data to anyone else unless the law requires it.
Retention
On the server. A hunt ends the next time the clock reaches 04:00 Finnish time. The server then takes out of use all its voice clips, transcripts, messages, emergency alerts, member list and hunt data, together with the creator's location, join requests, the list of removed devices and the iPhones' wake-up identifiers. Your wake-up identifiers are deleted as soon as you leave the hunt or are removed from it. The cloud provider's backups keep deleted data for at most 30 more days, after which it is gone for good. We do not restore deleted hunts. If you leave earlier, what you already sent stays in the hunt until it ends. The technical log is deleted within seven days. Battery statistics are kept for three months. Usage statistics events are kept for three months and the daily summaries calculated from them for 24 months. Error reports are kept in Sentry for at most 90 days. An unsent battery summary is deleted from the phone after seven days. We delete report emails once the matter has been handled.
Hunting party and purchases. A hunting party's data is kept until the last hunt leader leaves the party or its owner deletes it. A party is also deleted if it has not been used for 24 months and has no valid season. The data of a party taking part in a pilot is kept for the duration of the pilot agreement. A hunt leader key is deleted at the latest 30 days after the hunt leader has left the party or the party has been deleted. Invite codes are deleted one day after they expire. Purchase records and redeem codes are kept for three years after the purchase or after the code was created. When a party is deleted, the link to it is removed from the purchase records. Invoices and other accounting records are kept for six years from the end of the year in which the financial period ended, as the Finnish Accounting Act requires.
On your phone. The hunt's message stream and unsent speech stay on your phone until the hunt has ended and you next open the app, or until you join another hunt. The list of past hunts (hunt code, name, date, member count and battery use) stays until you clear it in Settings or delete the app. Your name, device identifier, the members you blocked and your settings stay until you delete the app. App data is not copied to the phone's cloud backup.
Phone permissions
| Permission | Used for |
|---|---|
| Microphone | talking to everyone in the hunt, only while the talk button is held |
| Notifications | emergency alerts (also while the app is in the background), private talk and the end of the hunt |
| Location | the distance check when creating or joining a hunt, the location of an emergency alert when sending, and the distance to an alert you received |
| Background use (Android) | the radio keeps working while the screen is locked |
| Display over other apps (Android) | the floating talk button, only if you turn it on in the settings |
The app detects when a call comes in or you are on a call, and silences the radio for the duration of the call. The app does not read call details such as the phone number, and the call state is not stored or sent.
You can revoke permissions at any time in the phone's settings. Without the microphone you can still listen and type. If you do not allow location, emergency alerts are sent without a location, your joins wait for a member's approval, and everyone who joins a hunt you created needs a member's approval.
Your rights
You have the right to know what data we process about you and to get a copy. You can ask us to correct, delete or restrict processing of your data, and you can object to processing based on legitimate interest. You also have the right to receive the data you provided in a machine-readable format and to transfer it to another service. You can block location use in the phone's settings.
As there are no accounts, we can find your data only by hunt code and your name, so include them in your request. Hunt data is deleted at 04:00 in any case. If you want it deleted sooner, email us and we will delete the hunt. We find a hunting party's data by the party's name and delete the party on request.
If you believe your data is processed unlawfully, you can complain to the Finnish Data Protection Ombudsman (tietosuoja.fi) or the supervisory authority where you live.
Children and security
Users of Jahtiradio must be at least 13 years old. We do not knowingly process the data of children under 13.
Connections between the phone and the server are encrypted (HTTPS and secure WebSocket). A hunt can be joined only with its code, and the server limits code guessing. Someone joining from further away or without a location must also be approved by a member of the hunt. Share your hunt code only with your own hunting party.
Changes
If this policy changes, we update this page and the date at the top.