Privacy Policy
This draft says what QRVnet collects and what is public because it is amateur radio. It is not a promise of confidentiality for anything you transmit.
Account data we collect
We collect the account data you submit: callsign when you have one, name, email, postal address, password (stored as a slow hash, not as the password itself), other licences you add, links, grid square, affiliations, and a short bio. We store the terms version you accepted and the time you accepted it.
Licence material
If you upload a licence image or PDF, that file is private in Cloudflare R2. Moderators can open it to review the account. The intended retention is to delete the file 90 days after review. That retention is a target, not yet a guarantee that every copy is gone on day 91.
LoTW and logbook data
LoTW credentials are collected only with your consent, for a verification check and, if you opt in, for later logbook import. They are encrypted at rest. Do not send them if you do not want that. You can ask us to delete stored credentials. We do not write the password into ordinary logs.
Public licence data
We store FCC ULS public data locally: licensee name, address, and operator class, and the status and expiry we need to know whether a licence is active. The FCC publishes this. A copy in our database is still public-record material, kept so the service can run when the FCC download is slow.
Lookups
Callsign checks may query callook.info, HamDB, QRZ, and HamQTH, and our own copy of ULS. Those services see the callsign we ask about and see our request. QRZ and HamQTH are used for an email match only when we have an account with them and the ham has published an email there.
Messages and bulletins
Messages and bulletins on the store-and-forward network are public and are replicated to other nodes. They cannot be recalled once they have been gossiped. Treat every bundle as something another operator, and another server, will keep. The permanent log exists so a trustee can answer who injected a message.
If you use @qrv.riftly.cloud, we process the message content, headers, and attachments in order to deliver them into the mailbox and, when the rules allow, toward RF. Delivery to RF may expose a portion of that content on the air, where it is not private.
Audio
Voice audio is not recorded by the cloud by default. A repeater trustee might record locally under their own rules and their own notice. This policy does not cover a recorder we do not operate. Channel text chat in the browser client is ephemeral and is not the mailbox.
Logs
We keep operational logs and an audit log of moderator actions: who approved, suspended, or changed a role, and when. Logs are for abuse handling and debugging. They are not sold.
Processors
The service runs on Cloudflare: Workers, Durable Objects, D1, R2, and, when configured, email sending and routing. Cloudflare processes the data needed to host the service. We do not sell personal data.
Browser storage
The website stores your session token, theme, and repeater-sound mute preference in local storage on your device. The token is sent as a Bearer header. It is not a tracking cookie. There is no third-party analytics and no advertising script.
Deletion requests
Ask for deletion or correction at support@qrv.riftly.cloud (placeholder until a monitored mailbox is published). We can delete an account and stored credentials. We cannot promise deletion of a message that other nodes already store, or of a transmission that already went out on the air. Public ULS data may remain as a copy of the FCC file even after your account is gone.