Privacy Policy
Last updated: 29 August 2026
Who we are
QSO One is made by Francesco Catena, based in Ohio, United States. You can reach us at [email protected] or by post at 46 Shopping Plaza, Unit #5015, Chagrin Falls, OH 44022.
We decide what data QSO One collects and what happens to it, which makes us the data controller under the GDPR and UK GDPR.
What we collect, and why
Your account. When you sign up we store your email address, your callsign, and optionally your name and license class. We need these to give you an account and to know that you are a licensed operator. We also use your email address to send you occasional updates about QSO One, such as new features, new platforms and release notes. Every one of those has an unsubscribe link, and unsubscribing does not affect your account.
Network credentials, only if you turn on syncing. QSO One can save the usernames and passwords you use for AllStarLink, EchoLink, BrandMeister, TGIF and similar networks, so that signing in on a second device restores them. This is off unless you turn it on. Passwords are encrypted before they are stored, each account with its own key.
Connection diagnostics. While the app is running it reports which network you are connected to, what you are connected to on it, your app version and platform, and by default your account and callsign. We use this to tell whether an update has broken connections for people, and to help you when you write in with a problem. Our reason for collecting it is our legitimate interest in keeping the app working for everyone, including the many people who never report a problem. You can turn off the account and callsign part in the app under Settings, and we ask you when you first install it. Connection activity is still recorded without you attached to it.
Bug reports. When you send a bug report it includes your app's log file, your callsign and email, your app and device version, and network details including IP addresses and information about who your app was connected to. We use it to diagnose the problem you reported.
Your position, only if you turn it on. On Android, QSO One can share your location over M17 so you appear on the map. This is off unless you switch it on, and you can switch it off at any time.
Password reset requests. When someone asks to reset a password on this website, we record the email address that was entered, the IP address the request came from, and the time. We use this to limit how often a reset email can be sent and to see whether an address is being targeted, so people are not spammed with reset emails they did not ask for. We keep these records for 30 days and then delete them.
Server logs. Our hosting and database providers keep short term technical logs that include IP addresses, in the ordinary course of running a website.
What we do not do
We do not use advertising. We do not use third party analytics or tracking scripts on this website. We do not use an advertising identifier. We do not sell your data or share it with anyone for their own marketing.
Who else receives your data
We use these companies to run QSO One. They only process data on our instructions.
- Supabase, for our database and sign-in
- Netlify, for hosting this website and its server functions
- Cloudflare, for file storage
- Resend, for sending email
- Google, only if you choose to sign in with a Google account
All of them are in the United States, which is where our servers are. If you are in the EU or UK, that means your data is stored outside your country.
How long we keep things
- Your account data, for as long as you have an account
- Connection diagnostics, 90 days
- Bug reports, 90 days, or 30 days once we have marked them resolved
- Password reset request logs, 30 days
- Payment records, for as long as tax law requires us to keep them
Deleting your account
You can delete your account from the app, from qso1.net/account-deletion (which works even if you no longer have the app), or by emailing [email protected]. Deleting removes your profile, your callsign, your saved credentials, your favorites, your diagnostics, your bug reports, and your sign-in. It is not a deactivation and it cannot be undone.
Two things survive. If you have ever paid us, the payment record stays because tax law requires it, but it is no longer connected to you. If you have submitted something to the net directory, the entry stays for everyone else's benefit, without your name on it.
Your rights
If you are in the EU or the UK, you have the right to ask us for a copy of your data, to correct it, to delete it, to restrict what we do with it, to receive it in a portable form, and to object to our use of it.
You have the right to object to our use of your connection diagnostics. Because we rely on legitimate interests for that, you can tell us to stop at any time, and you can also switch off the identifiable part yourself in the app.
Email [email protected] to exercise any of these. We will respond within one month.
You also have the right to complain to a data protection authority. In the EU that is the authority in the country where you live. In the UK it is the Information Commissioner's Office at ico.org.uk.
Security
Passwords for other networks are encrypted before storage, and each account has its own encryption key. Everything travels over an encrypted connection.
Two things you should know. As the developer, we can access the data stored on our servers, including diagnostics and, technically, stored credentials. And EchoLink's own protocol sends passwords without encryption, which is how EchoLink works everywhere and is not something QSO One can change.
Changes
If we change this policy we will update the date at the top.