Legal
Privacy Policy — Incog Radio
Last updated: 13 August 2026 · Effective for the web app, PWA, and store builds that load incog.mnlabs.uk
1. Who we are (data controller)
Incog Radio is operated by MN Labs Ltd (“we”, “us”, “our”), a company registered in England and Wales (Company No. 17267178).
Contact (privacy & support): michael@mnlabs.uk · mnlabs.uk · Support page
For UK GDPR purposes, MN Labs Ltd is the data controller for personal data processed in connection with hosted (online) features of Incog Radio.
2. What Incog Radio is
A private push-to-talk service for small crews. It offers:
- Online rooms — invited channels hosted by us (voice + short text).
- Local boat / field mode — device-to-device or local-network connection (QR or pin). Not Marine VHF and not public radio spectrum.
There is no traditional login account (no email/password signup) for core use. You choose a callsign on the device.
3. Data we process
- Callsign / display name — chosen by you; stored on your device and, for online rooms, on our server with the room membership.
- Device / app key — a random identifier stored locally so your device can rejoin rooms you created or joined (not a password).
- Room metadata — room name, invite code, membership list, short text messages, timestamps for online rooms.
- Technical logs — IP address, timestamps, basic request/error logs for security, abuse prevention, and reliability of the hosted service.
- Microphone audio — used only while you use push-to-talk to send live voice. We do not sell recordings. Online mode sends media between peers (WebRTC). Local field mode keeps media between your devices.
- Camera — optional; only if you scan a QR code to join. Frames are processed on-device to read the code and are not stored as a photo library on our servers.
4. Permissions (mobile / browser)
- Microphone — required for push-to-talk.
- Camera — only for optional QR join in local boat mode.
- Network — online rooms and updates; local mode may use local network / peer connectivity.
You can revoke permissions in system settings; voice/QR features will not work without them.
5. Why we process data (purposes & legal bases)
- Provide the service you request (create/join rooms, PTT, messaging) — UK GDPR: contract / steps prior to contract.
- Security, abuse prevention, and reliability (logs, rate limits) — legitimate interests.
- Legal obligations if we must respond to lawful requests — legal obligation.
6. Who can see your data
- Other members of a room you join can see your callsign, messages you send, and hear your PTT audio while you transmit.
- MN Labs operates the online hosting and may access server data as needed to run and secure the service (not for ads).
- We do not sell personal data or run third-party advertising trackers in the core app experience.
7. Sharing with service providers
Online features run on infrastructure we control or rent (e.g. hosting / server providers in the course of operating incog.mnlabs.uk). Voice in online mode uses peer-to-peer WebRTC where possible; network routing may involve standard internet infrastructure. We do not use your content for advertising.
If you install from Google Play or the App Store, those platforms process install and account data under their own policies (separate from this policy).
8. International transfers
We aim to host the service in a way suitable for a UK operator. If any processing occurs outside the UK, we take appropriate steps required by UK data protection law. Contact us if you need more detail for a specific transfer.
9. Retention
- Online rooms — typically expire after about 7 days (unless reconfigured); associated membership and messages are removed with the room.
- Server logs — kept only as long as needed for security and operations, then deleted or aggregated.
- On your device — callsign, local keys, and recent room list until you clear site/app data or remove the app.
- Local boat sessions — live on participating devices for the session; not stored as a permanent server archive by us.
10. Your rights (UK GDPR)
Where applicable, you may request:
- Access to personal data we hold about you
- Correction of inaccurate data
- Deletion or restriction
- Objection to processing based on legitimate interests
- Data portability where technically feasible
Email michael@mnlabs.uk. You may also complain to the ICO (UK supervisory authority).
11. Deleting your data
- On device: clear site data / app storage, or uninstall the app.
- Online rooms: leave the room; rooms auto-expire (see retention). For deletion of specific hosted data, email us with your callsign and room code if known.
Because there is no email login, we may need enough detail to locate server-side records safely.
12. Children
Incog Radio is not directed at children under 13. Do not use the service if you are under 13. We do not knowingly collect data from children under 13.
13. Security
We use HTTPS for the hosted site and standard security practices for the server. No method of transmission or storage is 100% secure; use room codes carefully and only invite people you trust.
14. Safety notice (not a privacy right, but important)
Incog Radio is not a substitute for Marine VHF, 999 / emergency services, coastguard, or licensed safety radio. Use official channels for distress and navigational safety.
15. Changes to this policy
We may update this policy. The “Last updated” date at the top will change when we do. Continued use after an update means you accept the revised policy.