Foothill Signal

Plain-language privacy policy

A quiet archive for a local-only fieldbook

This policy describes the shipped Foothill Signal Android app: an offline educational fieldbook with no account, network feature, analytics, advertising, sharing, or free-form personal-data entry.

An open glass archive beside a clearly separate operator boundary
Folio 01

Scope and operator

This policy covers the shipped Foothill Signal Android app. The product is proposed independent educational software associated with the package org.boisebackstheblue.foothillsignal; it is not an official organization, Boise Police Department, City of Boise, emergency-management, or 911 product. Final publisher and privacy-operator identity remain publisher-controlled information and must be confirmed before public release.

Two small local state tokens resting in an otherwise empty archive drawer
Folio 02

Data inventory

The app can store only field-card identifiers placed in one of two mutually exclusive sets: Practiced or Revisit. It also relies on ordinary operating-system and app-installation data outside the app's own content model. The app has no names, addresses, notes, photographs, call records, account profiles, scores, streaks, or shared submissions.

A closed input channel leading only to two simple local choice stones
Folio 03

Collection and processing

No personal-data form exists. When a user taps Practiced or Revisit, the app updates the matching local identifier set so the Local Trail can display that choice. Tapping the selected choice again clears it. This local behavior is the only app-authored data processing.

A private on-device drawer holding two restrained state markers
Folio 04

Local storage

Practiced and Revisit identifiers are stored in private Android app preferences on the device. They are not designed for synchronization, export, account recovery, or server backup. Android backup and device-transfer extraction are disabled in the app manifest and data-extraction rules.

An open permission gate with camera microphone location and contacts objects left unused
Folio 05

Permissions

The shipped app declares no runtime permissions. It does not request camera, microphone, contacts, phone, notification, Bluetooth, precise or approximate location, storage, calendar, sensor, or network permissions.

A self-contained archive island with no bridge to an external network
Folio 06

Network behavior

All one hundred field-card images and all educational copy are packaged inside the Android artifact. The app declares no internet permission and has no network feature, remote configuration, content download, browser view, upload, or dispatch connection.

A quiet local folio separated from empty third-party service pedestals
Folio 07

Third-party services

The shipped app contains no third-party service SDK for analytics, advertising, authentication, social sharing, crash reporting, maps, payments, messaging, cloud storage, or remote media. Standard Android and Jetpack libraries provide local application functionality.

Abstract tracking trails fading before reaching a sealed local enclosure
Folio 08

Analytics, ads, and tracking

The app has no analytics, advertising, behavioral profiling, cross-app tracking, attribution SDK, device-fingerprint feature, marketing pixel, telemetry upload, or personalized content feed. It does not create engagement scores or streaks.

An unused key beside an empty glass login arch and an accessible fieldbook
Folio 09

Accounts and authentication

No sign-up, sign-in, profile, password, email verification, social login, subscription, or identity credential is supported. Local Practiced and Revisit choices are not linked to an account and cannot be recovered from a service operated by the app.

A child and adult standing outside a protected garden enclosure with no data vessels
Folio 10

Children

Some educational cards are suitable for adult-guided family discussion or service learning, but the app does not ask a child to create an account, submit a name, share a location, take a photograph, contact another person, or document participants. Final child-directed store classification is a publisher-controlled decision.

Sealed sensitive-detail vessels positioned outside the open fieldbook workspace
Folio 11

Sensitive data

The app has no free-form notebook and is not designed to receive health information, emergency details, precise locations, addresses, phone numbers, private stories, reports about people, government identifiers, financial data, biometrics, or photographs. Exercises tell users to keep examples fictional or household-safe.

A sturdy local archive drawer protected by layered glass and limestone walls
Folio 12

Security

The narrow data model, no-network design, private app preferences, disabled backup, no exported data component, and release signing reduce exposure. No software can promise absolute security; device access, operating-system behavior, malware, and backups outside this app remain outside the app's control.

Local state tokens moving from a small drawer into a clear deletion basin
Folio 13

Retention and deletion

Local Practiced and Revisit identifiers remain until the user clears all local flags, toggles individual choices off, clears app data in Android settings, or uninstalls the app. Because no app service receives the identifiers, there is no server-side deletion request for this shipped build.

Two accessible local controls beside a clear-all path in the archive
Folio 14

User controls

Users may choose Practiced, choose Revisit, tap an active choice again to remove it, or use Clear all local flags in Local Trail. Android settings also provide standard app-data and uninstall controls. The app works without marking any card.

A self-contained fieldbook resting across several abstract geographic terraces
Folio 15

International use

The fieldbook's editorial context is Boise-area civic care and Idaho household readiness, while the shipped app has no server transfer or cross-border service. Users outside that context should rely on their own current local official emergency guidance and laws.

A sequence of dated-looking blank folios arranged as visible policy revisions
Folio 16

Policy changes

If a later app version changes its data behavior, permissions, services, or controls, its policy should be revised before distribution and the effective version should be communicated through the publisher's chosen release surface. This local artifact does not prove that a future policy is hosted or live.

A blank reply envelope beside an intentionally blank contact placeholder
Folio 17

Contact and questions

A verified public privacy contact has not been supplied for this proposed product. The publisher must add an accurate monitored contact and live policy location before public release. No address or contact detail is invented in this local website artifact.

An orderly shelf of source folios with a clear separation from editorial cards
Folio 18

Sources and attribution

Privacy statements are based on the locally inspected Android source, manifest, packaged resources, data-extraction rules, dependencies, and verified release behavior. Educational emergency topics should be checked against current official guidance; local build evidence does not establish public hosting, Play approval, organization approval, publisher authority, or rights clearance.