Towerilo - Cell Tower Map

Privacy

Privacy policy

What this app collects, why it collects it, and what you can ask us to delete.

This policy explains what Towerilo - Cell Tower Map ("Towerilo", "we") handles when you explore cellular tower and antenna-site records, save places, use the AI guide, subscribe or write to support. It covers what leaves your device, why, who receives it, how long it is kept and how to delete it. Towerilo is published under the developer name shown on its App Store and Google Play listings. Questions, access requests and deletion requests go through the support page.

What Towerilo does and does not do

Towerilo shows sourced records: where public registries and OpenStreetMap say towers, masts and antenna sites are, with the source, licence and date of each record. Where a regulator publishes coverage data, it shows that as reported coverage, never as a measurement. A grounded AI guide explains records and answers questions from them.

Towerilo does not measure or read your live signal, and it never claims signal strength or speed. It has no account or sign-up, shows no ads and does not track you across other apps or websites. Personal information is not sold or used for advertising.

Your anonymous identity

  • On first launch the app signs in to Firebase Authentication anonymously. It never asks for a name, e-mail address, phone number or password.
  • The app creates a random installation identifier and a signing key kept in your device's secure storage (Keychain or Secure Enclave on iOS, Keystore on Android). The private key never leaves the device.
  • Each request to our service carries a Firebase sign-in token, an App Check attestation (Apple App Attest or DeviceCheck on iOS, Play Integrity on Android) and a signature made with your device key. This shows the request comes from the genuine app on that installation and protects the service from abuse and replay.
  • Our service stores the installation identifier, the anonymous Firebase user identifier, the public key, the platform (iOS or Android), the app version and first and last seen times. It is an identifier for an installation, not for you by name.

Location

  • Towerilo asks for location only while the app is open, and only after an in-app explanation. You can refuse: search and browsing work without it. It never uses background location.
  • Your exact position stays on your device for distances, bearings, range rings and the compass.
  • To load records, the app sends the map cells (tiles roughly 3 to 4 km across) covering the area you are viewing, or the bounding box of the visible map. When a request needs a point, such as a nearby list, reported coverage or an AI question, the app sends coordinates rounded to three decimals, about 110 metres.
  • Opening a site or place in your Maps app, or sharing it, hands its coordinates to the app you choose.
  • Towerilo never sends your coordinates to Firebase Analytics. If you turn Analytics on, Google itself derives an approximate location (such as country, region or city) from your device's IP address; see Optional analytics and crash reports.

Search, maps and phone details

  • Place search text is sent to our service only when you submit a search, with no autocomplete. Our service forwards the text to an open geocoder, Nominatim run by the OpenStreetMap Foundation, or Photon as fallback, so those services see the text and our server, not your device. Search text is not stored with your identity.
  • Map tiles, styles and fonts are downloaded by your device directly from OpenFreeMap, or from VersaTiles if OpenFreeMap is unavailable. Their operators see your device's IP address and the tiles you request, which reveal the area you view. See the OpenFreeMap privacy policy.
  • The "This phone" card reads your connection type and cellular generation on the device. It is not sent to us.

Saved places and history stay on your device

Saved places, their names, notes and record snapshots, recent searches, Guide history and your settings are stored only on your device. We have no copy. Removing the app or using Delete my data erases them. Notes and names leave the device only if you choose a Guide feature that includes them, for example comparing places.

The AI guide

  • When you run a Guide feature, the app sends our service the feature name, the text you type (a question, situation or symptoms), rounded coordinates, record identifiers and, for comparisons and change digests, the names and optional notes of the saved places you pick. The app never sends model instructions.
  • Our service writes the prompt itself: its own fixed rules, a pack of sourced records and computed values (distances, bearings, counts) from its own database, and your typed text marked as data, never as instructions. It sends the prompt to an AI model service through our own AI gateway, checks the answer against those records before showing it, and falls back to a fixed template if the check fails.
  • Before location, a photo or your voice is used, the app shows what is sent and to whom, and asks you to confirm. You can withdraw each choice in Settings.
  • A photo or screenshot you choose, and a voice recording of up to 60 seconds, is processed in memory to answer that request and is not stored by us. A recording is converted to text, which appears in the app.
  • To enforce fair-use limits we record counts of AI runs per installation and per purchase. These usage records hold no question and no answer.
  • Every answer has a Report control. A report sends an opaque report reference, the reason you pick and an optional note of up to 400 characters, kept for our review.
  • The AI service processes your request under its own terms. Do not enter information you do not want processed there. AI answers can be wrong and never establish live signal or guaranteed coverage. You can use the map without the AI guide.

What the AI service receives and keeps

What the AI gateway and the model service behind it receive:

  • The prompt described above: sourced site records, computed values and the text you typed for that request, such as a question, a situation, symptoms, an operator name, notes on your readings and, for a comparison, the names and notes of the places you pick.
  • A location only if you allowed location sharing: the coordinates or map area you send, rounded to about 110 metres (three decimals), and values computed from them, such as distances and bearings. Without that choice the app sends none and our service refuses a request that carries one. Asking about a single record sends no location of yours.
  • A photo or screenshot only when you choose one and allowed photo sharing. Our service removes location and camera details from the picture before it goes on.
  • A voice recording only after you allowed voice sharing. The AI service turns it into text and our service returns that text to the app.
  • No identifier of yours is added. The request carries no installation identifier, Firebase user identifier, name, e-mail address or purchase detail. It is sent from our servers under Towerilo's own service credentials, so the AI service sees our server and not your device or IP address.
  • An address you type in the address check is looked up by our service through the geocoder (Nominatim, or Photon as fallback), as for search. Only the resulting point, rounded, is used, and the address text is not passed to the AI service.

What is kept:

  • Towerilo keeps no copy of your typed text, coordinates, photo, recording, prompt or answer. Our servers hold them in memory while the request runs; they are not written to our database or our logs. Guide history on your device, which you can clear or switch off, keeps your own copy of an answer.
  • For each AI run we store a usage record tied to your installation: which feature ran, when, how long it took, whether it succeeded, the model name, how many records the answer drew on and the codes of any check that failed. It holds none of the content above. Usage records are removed after 400 days, or sooner when you delete your data.
  • A report you send is stored with the same run details, the reason you picked and your optional note, until you delete your data.
  • The AI gateway and the model service process the request to write the answer. How long they keep a request while doing so is set by them under their own terms, not by Towerilo, and this policy does not state a period for it. Towerilo does not sell this data or use it for advertising.

Subscriptions and purchases

  • Access to Towerilo's features is a subscription bought through Apple or Google, who handle payment and never share your card details with us. Onboarding, purchase, restore, support, privacy choices and data deletion work without a subscription.
  • To grant access, the app sends a purchase proof to our service, which checks it with Apple's App Store Server API or the Google Play Developer API. We store a hashed purchase reference and an encrypted copy of the store's own reference (used only to re-check the purchase with Apple or Google), the product, platform, status and expiry and verification times, linked to your installation. If you restored the same purchase on another device, the purchase record stays for that installation until it is deleted too.
  • Deleting your data does not cancel a subscription. Cancel or manage it in Settings under Manage subscription, or in your Apple or Google account subscriptions.

Feedback, data-problem reports and support

  • Feedback and data-problem reports you send from the app contain your message of up to 600 characters, the record concerned for a data problem, and a contact detail only if you type one. They are stored with your installation identifier.
  • Diagnostics (app version, platform, OS version and last error code) are added only if you tick the option.
  • The support page form collects the name, e-mail address, subject and message you type. It is delivered to us by e-mail and used only to answer you. Do not send passwords or payment details.
  • You can ask us to delete a support message through the support page.

Optional analytics and crash reports

Firebase Analytics and Crashlytics are off until you turn them on in Settings, and you can turn them off again there. When on, Analytics receives anonymous counts of actions, such as finishing onboarding, submitting a search, opening a record or using a Guide feature. These events never contain text you typed, coordinates, record identifiers or tokens. Along with them, Analytics collects standard details by itself: a random app-instance identifier (not your advertising identifier), the app version, OS version and device model, and an approximate location, such as country, region or city, that Google derives from your device's IP address. Towerilo does not send your coordinates to Analytics, and none of this is collected while Analytics is off. Crashlytics receives crash traces with the device model, OS version and app version. Google processes this under its own terms; see Firebase privacy. Towerilo does not use the advertising identifier.

Who receives data

  • Google (Firebase Authentication and App Check, plus Analytics and Crashlytics if you opt in, where Analytics also derives an approximate location from your IP address) and Apple (App Attest and purchase verification).
  • Cloudflare, which relays traffic to towerilo.site, including our API, the AI gateway and the onboarding and paywall screens the app loads from it.
  • The servers we operate, which run our API and database.
  • OpenFreeMap and VersaTiles (map tiles) and Nominatim and Photon (search and the address check).
  • The AI gateway and the model service behind it (Guide): the prompt and any location, photo or recording you allowed, as described under What the AI service receives and keeps.

Providers may process data in other countries under their own safeguards. We do not sell or share personal information for advertising.

How long we keep it

  • Installation record and entitlement: until you delete your data in the app.
  • Feedback, data-problem reports and AI reports tied to your installation: until you delete your data in the app.
  • AI usage records (which feature ran and how it ended, never its content): 400 days, or until you delete your data in the app if that comes first.
  • Guide requests and answers (typed text, coordinates, photos, recordings, prompts): not stored by Towerilo. How long the AI gateway and the model service keep a request while processing it is governed by their own terms, and this policy does not state a period for it.
  • Request-security records: replay guards for 10 minutes, rate counters for a few hours and usage-allowance counters for about 3 days.
  • Support messages: kept to answer you, and deleted on request.
  • After a deletion we keep a minimal record that the installation identifier is retired, so it cannot be registered again. For 30 days it also holds the user identifier and public key so a deletion retried after a lost connection can be verified, then those two values are erased.
  • Local data on your device stays until you delete it or remove the app.

Your choices and deleting your data

  • In Settings, choose Delete my data. It deletes the server records of your installation, asks Firebase to delete your anonymous Firebase user, turns off analytics and crash reporting, resets the analytics identifier and erases places, caches, preferences and Guide history on the device. It stays available without a subscription. If a step fails, the app keeps the request so you can retry, and does not report it as done.
  • If you cannot open the app, send a deletion request through the support page. Name the app, say you want your data deleted, and add any details that help identify your installation. Because Towerilo has no accounts, we can only remove records we can tie to your installation. A support form receipt confirms we received the request, not that deletion is complete.
  • Data already sent to Firebase Analytics or Crashlytics stays with Google under its retention settings.
  • We hold no copy of Guide requests, so there is nothing of them to delete on our side. What the AI gateway and the model service hold while processing a request is under their own terms, and we cannot recall it.
  • Turn location, camera, microphone and photo access on or off at any time in your device settings, and AI consent in Settings.
  • You can also ask about access, correction or other privacy rights through the support page.

Where the records come from

Records keep their own provenance in the app. Sources and licences:

  • OpenStreetMap: contains data © OpenStreetMap contributors, available under the Open Database License. See the OpenStreetMap copyright page.
  • FCC Antenna Structure Registration: public records of the U.S. Federal Communications Commission, public domain. Not endorsed by the FCC.
  • ANFR (France), Observatoire 2G, 3G, 4G, 5G: Licence Ouverte 2.0. Regrouped and normalized by Towerilo.
  • ISED (Canada), Spectrum Management System Authorization Data Extract: contains information licensed under the Open Government Licence - Canada.
  • BAKOM (Switzerland), mobile phone base stations, via opendata.swiss: open use, source mandatory.
  • ACCC (Australia), Mobile Infrastructure Report data release, reported coverage: CC BY 2.5 AU.
  • ARCEP (France), Mon Réseau Mobile, reported coverage: Licence Ouverte.
  • Maps: © OpenStreetMap contributors, OpenMapTiles data, served by OpenFreeMap or VersaTiles.

Public records are incomplete and can be out of date. Reported coverage is modeled by operators for the regulator, outdoors, and is not measured.

Changes

If we change how Towerilo handles data, we update this page before the change takes effect. Terms of use are on the terms page.