Privacy Policy
Effective 10 July 2026
This Privacy Policy explains how Flying River Ltd collects, uses, stores and discloses personal data in connection with the YANL Android application and the yanl.net web platform, together referred to as the “Service”.
Who we are
Flying River Ltd is the controller responsible for the personal data described in this Privacy Policy.
Our registered office is:
Flying River Ltd
71–75 Shelton Street
Covent Garden
London
WC2H 9JQ
United Kingdom
For privacy questions, requests or complaints, contact us at team@yanl.net.
The short version
- The app records network, device and location measurements only while a recording you start is running.
- Recordings remain on your device unless you choose to upload them or initiate a function that requires communication with a test server.
- Recordings may contain personal or sensitive information, including precise locations and identifiers relating to networks and nearby devices. Review them before uploading.
- Uploads made without an account are not intentionally linked to a name, email address or YANL account, but their contents may still identify a person, place or device.
- We do not sell measurement data, license it to mobile operators or data brokers, or use it for advertising.
- We use service providers to host, secure and operate YANL.
- Map and place-name features may involve sending map or coordinate information to Google.
- Uploads without an account are normally deleted seven days after upload.
- Saved sessions are retained until the expiry date displayed for the session, followed by any stated grace period.
- Optional first-party app analytics can be disabled in Settings.
- Organisation administrators may be able to access and manage information within organisation workspaces.
- Sessions are private by default. You can share one with a view-only link, and anyone who has that link can open it without signing in.
- Share links hide precise location and Wi-Fi names by default. You can choose to include them.
- You can delete sessions and your account and can contact team@yanl.net about your data-protection rights.
1. Information recorded on your device
When you start a recording session, the app may record measurements approximately once per second.
The information recorded may include the following.
Mobile network measurements
This may include:
- signal strength and quality measurements, including RSRP, RSRQ, SINR and similar values;
- network technology, including 2G, 3G, 4G and 5G;
- band and frequency information;
- serving and neighbouring cell identifiers, including PCI, EARFCN, Cell ID and TAC;
- carrier or network name;
- whether mobile data is flowing at each moment, in which direction, and whether the radio connection has gone dormant; and
- network events such as handovers, drops and loss of service.
These are readings about the connection itself, taken about once per second while a recording runs. The app does not record web addresses, the names of sites or apps you use, or the contents of anything you send or receive.
Wi-Fi measurements
This may include:
- the signal strength and technical parameters of your connection;
- the SSID and BSSID of the network to which you are connected; and
- identifiers and signal information relating to access points visible during permitted scans.
Bluetooth measurements
This may include identifiers and signal-strength information relating to paired or nearby Bluetooth devices that Android makes available to the app.
Location
The app may record precise location information, including GPS coordinates, so that measurements can be placed on a map.
Android may also require location permissions before allowing Wi-Fi, Bluetooth or cell-scanning functionality.
Device and performance information
This may include:
- device manufacturer and model;
- Android version;
- app version;
- battery level and battery use;
- CPU and memory use;
- screen state;
- power-management state, including whether the device has entered deep idle (doze) or battery-saver mode;
- how long it is since the device last moved a meaningful amount of network traffic; and
- data-traffic counters.
Test results
Where you run a supported speed or performance test, the app may record:
- the test server used;
- throughput measurements;
- latency or timing information;
- protocol and transport statistics;
- technical errors or completion status; and
- information necessary to operate, secure and limit access to the test service.
Running a test may require your device to communicate with YANL-operated or approved test infrastructure. Those systems may receive ordinary connection data, including your IP address, request time, protocol information and test parameters.
Notes
The app records notes or labels that you choose to enter during a session.
Local storage
Recordings are written to files stored in a location available to the app or selected by you, depending on the device and Android version.
The app does not need to collect your name, email address or contacts in order to make a local recording.
The app does not intentionally make network measurements in the background when no recording is running.
Measurement data does not leave your phone unless:
- you choose to upload a recording;
- you initiate a function that requires communication with a test server;
- you load online maps or place-name features; or
- limited optional usage information is sent as described in section 6.
You are responsible for reviewing recordings before uploading them. Recordings may contain precise locations, network identifiers, nearby-device identifiers, notes or other information relating to you or other people.
2. Information relating to other people
Recordings may contain information relating to people other than the person making the recording or upload.
This may include:
- identifiers of nearby access points or devices;
- network information;
- locations;
- information about a shared or workplace network; or
- information entered in notes.
We normally receive this information from the person who makes or uploads the recording rather than directly from the other people concerned.
We use it only for the purposes described in this Privacy Policy.
Users must not record or upload information unlawfully and should remove information that is not reasonably necessary for their diagnostic purpose.
3. What happens when you upload
Uploading is initiated by you.
An upload may contain:
- recorded log files;
- parsed measurement data;
- app version;
- device model;
- file metadata;
- a file checksum;
- notes;
- location data; and
- other information contained in the recording.
Uploads are transmitted using encrypted connections and stored using encryption at rest where supported by the relevant infrastructure.
Uploads without an account
You may upload a recording without creating an account.
We do not intentionally associate that upload with a name, email address or YANL account.
We assign the upload a random reference and access code. We store a cryptographic hash of the access code rather than the access code itself.
Although an upload is not associated with an account, its contents may still constitute personal data. For example, it may contain location data, device and network identifiers, timestamps, notes or information capable of being linked to a person, device, home or workplace.
Uploads without an account, including uploaded files and parsed data, are scheduled for deletion seven days after upload.
Limited technical or security information may remain temporarily in logs or backups as explained in section 13.
Saved sessions
If you sign in and save a session, it is associated with your internal YANL account identifier.
Saved sessions follow the retention period applying to your plan. The expiry date should be displayed for each session.
An expired session may remain available or listed for a limited grace period so that you can renew or restore it, where that feature is offered. The applicable grace period will be displayed in the Service or on the Pricing page.
After the relevant retention and grace periods, the session is scheduled for permanent deletion from active systems.
Deleting and un-saving sessions
You may delete or un-save sessions through the Service where that functionality is available.
Deletion from active systems may not immediately remove copies from routine backups. Backup copies are deleted or overwritten according to the backup cycle described in section 13.
4. Sharing sessions
Sessions are private by default. Nothing is shared until you press Share and confirm.
Only the signed-in owner of a session can create a share link. The link is view-only: a recipient can look at the session, but cannot delete it, rename it, change how long it is kept, or share it onward from your account. You can share a whole session, or only a trimmed range of one.
A share link is a bearer link. Anyone who has it can open the session without signing in, inside or outside your organisation, so treat the link as being as sensitive as the session itself.
What a share link hides by default. Precise location and Wi-Fi names are hidden unless you choose to include them. With this setting on, coordinates are rounded to roughly 110 metres, and Wi-Fi network names and hardware identifiers (SSID, BSSID and MAC addresses) are masked for the recipient. You always see your own session in full. The choice is offered every time you share, and it is on by default.
How long a share link works. A share link has no separate expiry of its own. It stops working when the underlying session expires or is deleted: normally seven days after upload for uploads made without an account, or the expiry date shown for a saved session.
Ending access. Deleting the session immediately breaks every share link to it, and that is how you end access to a session you have shared. There is no control for switching off an individual link while keeping the session.
The link the app gives you is not a share link. The View on Web link shown by the Android app after an upload contains your own access code, and it opens the session in full, with nothing hidden. It is meant for opening your own recording on your own screen. If you forward it to someone else, they see the session exactly as you do, including precise locations and Wi-Fi names. To send a session to another person, open it on the web and use Share, which creates a separate view-only link with the protections described above.
When you create or use a share link:
- we process the session and access information to make the session available;
- recipients may view, copy, download or otherwise record information shown to them;
- we may record limited access information for security and abuse prevention; and
- access continues until the underlying session expires or is deleted.
You are responsible for reviewing the session before sharing it and ensuring that you have permission to disclose its contents.
Share links are not suitable for passwords, credentials, trade secrets, highly sensitive personal information or other information prohibited by the Terms of Service.
We cannot control what a recipient does with information after accessing it.
5. Maps and place names
YANL may use Google services to provide maps or general place names.
When map content is loaded, your browser or device may communicate directly with Google. Google may receive technical information such as:
- your IP address;
- browser or device information;
- the requested map area; and
- other information ordinarily included in a web or app request.
To generate a general place label, such as the town or area associated with a session, YANL may calculate an average coordinate for the session and send that coordinate to Google’s geocoding service.
We do not intentionally include your YANL account identifier or the full underlying recording in that geocoding request.
Google may nevertheless process the coordinate and ordinary connection information in accordance with its own terms and privacy information.
The returned town, locality or area name may be stored with the session for the same retention period as the session.
6. Optional first-party usage analytics
With the relevant setting enabled, the app may send us limited usage information to help us identify software problems and understand how the app performs across different types of device.
This information may include:
- app-open events;
- a broad recording-duration range, such as 5–15 minutes, rather than the exact recording duration;
- device model;
- Android version;
- app version; and
- a randomly generated installation identifier.
The installation identifier:
- is generated by the app;
- is not an advertising identifier;
- is not intended to be a permanent hardware identifier;
- is not intentionally associated with your YANL account, recordings or precise location; and
- can be reset through the app where that functionality is available.
Our servers and infrastructure providers may also process ordinary connection information, including IP address, request time and technical headers, for delivery, security and troubleshooting.
Analytics events are not intended to contain the contents of a recording.
Where technically supported, analytics events are sent while the app is idle rather than while an active recording is running.
Optional usage analytics are retained for up to 180 days.
You can disable this processing in Settings → Analytics. Disabling analytics does not prevent you from using the app’s core diagnostic functions.
On the web, we may use cookieless or limited performance measurement to understand page-load performance and identify technical problems. Further information about browser storage and similar technologies is provided in section 11.
7. Accounts, authentication and preferences
Creating a web account is optional unless a particular feature or plan requires one.
Accounts may be invite-only during private beta.
Authentication
Sign-in is provided through Clerk or another authentication provider identified in the Service.
The authentication provider may process:
- your email address;
- authentication credentials or tokens;
- OAuth identity information;
- sign-in times;
- IP address;
- device or browser information; and
- security or fraud-prevention information.
Our main application database is designed to use an internal account identifier rather than storing your email address as the primary account reference.
However, our systems, logs, support records or providers may process email addresses or other identity information where necessary to operate accounts, provide support, secure the Service or comply with law.
Preferences
We may store preferences and settings against your account, including:
- workspace layouts;
- display preferences;
- saved-session settings;
- plan information; and
- other account configuration.
Waiting list and invitations
If you join a waiting list, request an invitation or ask to be contacted about access, we may collect:
- your name;
- email address;
- organisation;
- role;
- reason for interest; and
- related correspondence.
We use this information to manage access, communicate with you about availability and administer the private beta.
Account deletion
Deleting your account removes your sign-in identity and closes your YANL account.
Unless the deletion flow clearly tells you otherwise, deleting your account does not necessarily cause every existing upload to be deleted immediately.
You should delete any saved sessions that you want removed before deleting your account, unless the account-deletion process expressly offers to delete all associated sessions.
Sessions not immediately deleted may continue to follow their displayed retention and expiry periods.
We disassociate retained security records from your account where reasonably possible. We may retain limited records where necessary for security, fraud prevention, legal compliance or the establishment or defence of legal claims.
8. Organisation accounts and administrators
Where an account or workspace is controlled by an organisation, authorised administrators may be able to:
- add, suspend or remove users;
- manage subscriptions;
- configure workspace settings;
- view, export, share or delete sessions;
- change retention settings;
- manage access permissions; and
- view information about activity within the organisation account.
The organisation may be a separate controller of personal data processed through its workspace.
You should contact the relevant organisation if you have questions about its use of your personal data or the actions of its administrators.
Where Flying River Ltd processes personal data on behalf of an organisation as its processor, the applicable Data Processing Addendum governs that processing.
9. Payments
Paid-plan payments may be processed by Stripe or another payment provider identified at checkout.
The payment provider may collect and process:
- name;
- billing address;
- email address;
- card or payment details;
- transaction information;
- fraud-prevention information; and
- subscription status.
We do not receive or store complete payment-card details.
We may receive limited billing information from the payment provider, such as:
- customer or subscription reference;
- payment status;
- plan;
- invoice information;
- card type or last digits; and
- billing country.
Payment providers may act as separate controllers for some of their processing. Their own privacy information applies to that processing.
10. How we use personal data and our legal bases
The lawful basis depends on the information and the purpose for which we use it.
Providing recordings, uploads and diagnostic functions
We process measurements, locations, device information, notes and uploaded content to provide functions that you request.
Our usual lawful basis is performance of our contract with you.
Operating test services
We process test parameters, IP addresses, protocol information, timestamps and test results to provide requested tests, manage capacity, prevent misuse and secure our infrastructure.
Our lawful bases are performance of our contract and our legitimate interests in operating and protecting the Service.
Operating accounts and saved sessions
We process account identifiers, preferences, plan information and session information to provide and administer your account.
Our usual lawful basis is performance of our contract with you.
Operating organisation workspaces
We process user, administrator, workspace and activity information to provide organisation-account functionality.
Our lawful basis may be performance of our contract with the relevant user or organisation and our legitimate interests in operating and securing the workspace.
Managing waiting-list and beta access
We process contact information and correspondence to manage invitations and communicate about access.
Our lawful basis may be taking steps at your request before entering into a contract or our legitimate interests in managing the private beta.
Payments and subscriptions
We process subscription, transaction and limited billing information to administer paid plans.
Our lawful bases are performance of our contract and compliance with legal obligations.
Optional usage analytics
We process limited usage and device information to maintain and improve the app.
Our lawful basis is our legitimate interests in maintaining, troubleshooting and improving the Service.
Where applicable law requires consent for storage of or access to information on your device, we rely on consent for that activity.
Security and abuse prevention
We process IP addresses, access records, account information, request information and security events to protect users and the Service, enforce usage limits and investigate misuse.
Our lawful basis is our legitimate interests in protecting users, systems, infrastructure and legal rights.
Support and correspondence
We process contact details, account information, session information and correspondence to answer questions, provide support and resolve complaints.
Our lawful bases may include performance of our contract, compliance with legal obligations and our legitimate interests in providing support and resolving disputes.
Legal obligations and claims
We may process relevant account, payment, security and correspondence information to:
- comply with law;
- respond to lawful requests;
- maintain required business records; and
- establish, exercise or defend legal claims.
Our lawful bases are compliance with legal obligations and our legitimate interests in protecting our legal rights.
Android permissions
Android permissions control whether the app can access particular device capabilities.
Granting an operating-system permission does not mean that we will use the resulting information for purposes not described in this Privacy Policy.
11. Cookies, browser storage and similar technologies
The web platform may use cookies, local storage or similar technologies where necessary to:
- keep you signed in;
- protect account security;
- remember preferences;
- operate payment or account functions;
- prevent abuse; and
- measure basic performance.
Where a technology is not strictly necessary, we will seek consent where required by law.
The documentation site may be largely static, but hosting and security providers may still process ordinary request information through edge, access or security logs.
12. Service providers and other recipients
We use service providers to help operate, host, secure and support the Service.
Our own authorised staff may also access and manage account, subscription and session data where reasonably necessary to operate and secure the Service, administer accounts and billing, provide support, and investigate misuse. Staff access is limited to what is reasonably necessary and is subject to access controls.
Depending on the service and information involved, a provider may act as our processor, as a separate controller or in another role recognised by data-protection law.
Providers acting as our processors are required to handle personal data in accordance with contractual terms appropriate to their role.
Current providers may include:
| Provider | Purpose |
|---|---|
| Cloudflare | DNS, network security, proxy services and object storage |
| DigitalOcean | API, application, server or test-service hosting |
| Neon | Database hosting for parsed metrics, events and account-related records |
| Vercel | Web application and documentation hosting and performance measurement |
| Clerk | Account authentication and sign-in |
| Stripe | Payment and subscription processing |
| Map display and geocoding or place-name functions |
The precise providers and technical architecture may change as the Service develops.
We do not sell measurement data, license it to mobile operators or data brokers, or disclose it for advertising.
We may disclose personal data:
- to providers where necessary to operate the Service;
- to organisation administrators where the relevant account or session belongs to an organisation workspace;
- to people with whom you choose to share a session;
- to professional advisers, including lawyers, accountants and insurers;
- to regulators, courts, law-enforcement bodies or public authorities where required or permitted by law;
- where reasonably necessary to investigate fraud, security threats or misuse;
- to protect the rights, property or safety of users, Flying River Ltd or another person; or
- in connection with a financing, restructuring, merger, acquisition, sale of assets or similar business transaction.
Where a recipient acts as a separate controller, its own privacy information applies to its use of personal data.
13. Retention
We retain personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy.
Normal retention periods are as follows:
| Data | Normal retention |
|---|---|
| Recordings stored only on your phone | Controlled by you and normally retained until you delete them, remove the app or the device removes the files |
| Uploads without an account | Seven days after upload |
| Saved sessions | Until the expiry date shown for the session, followed by any grace period shown in the Service or on the Pricing page |
| Share-link access information | For as long as reasonably necessary to operate the link, protect the Service and investigate misuse |
| Test-server and infrastructure logs | For as long as reasonably necessary for capacity management, security, abuse prevention and incident investigation |
| Account record and preferences | Until account deletion, followed by the period reasonably required to complete deletion from active systems |
| Organisation workspace information | Until removed by the organisation, closure of the workspace or expiry under the applicable plan, subject to legal and security retention |
| Optional usage analytics | Up to 180 days |
| Payment and transaction records | For the period required by tax, accounting and other applicable law |
| Waiting-list and invitation information | Until access is granted, the waiting list is closed or the information is no longer required, subject to any legal or dispute-related retention |
| Support correspondence | For as long as reasonably required to resolve the request and deal with related complaints or legal claims |
| Security and access logs | For as long as reasonably necessary for security, abuse prevention, incident investigation and legal claims |
Information removed from active systems may remain temporarily in routine backups until the relevant backup is overwritten or deleted.
We may retain information for longer where necessary to:
- comply with law;
- respond to a dispute;
- investigate fraud, misuse or a security incident;
- enforce our agreements; or
- establish, exercise or defend legal claims.
When information is no longer required, we delete it or render it anonymous so that it can no longer reasonably be linked to an identifiable person.
14. International transfers
Some providers may process personal data in countries outside the United Kingdom.
Where personal data is transferred to a country that is not covered by UK adequacy regulations, we use an approved transfer mechanism where required.
This may include:
- the UK International Data Transfer Agreement;
- the UK Addendum to the European Commission’s standard contractual clauses;
- another approved contractual safeguard; or
- a legally recognised exception.
You may contact us for further information about safeguards relevant to a particular provider or transfer.
15. Security
We use technical and organisational measures intended to protect personal data.
These may include:
- encrypted network connections using TLS;
- encryption at rest where supported by the relevant infrastructure;
- access controls;
- restricted administrative access;
- hashed upload access codes;
- logging and security monitoring;
- separation of account identifiers from some application data;
- deletion and retention controls; and
- provider security arrangements.
Share links and upload references may permit access to a session by anyone who possesses the relevant token, code or link.
You are responsible for protecting those links and codes and for sharing them only with people you trust.
No system is completely secure. You should not upload information prohibited by the Terms of Service or rely on YANL as the only copy of important information.
Report suspected security problems to team@yanl.net.
16. Your rights
Depending on the circumstances and the lawful basis for processing, you may have the right to:
- request access to your personal data;
- request correction of inaccurate or incomplete personal data;
- request deletion of your personal data;
- request restriction of processing;
- object to processing based on legitimate interests;
- receive certain personal data in a structured, commonly used and machine-readable format;
- withdraw consent at any time where processing is based on consent; and
- complain to a data-protection supervisory authority.
These rights are subject to legal conditions and exceptions. Exercising a right does not always require us to delete or provide every item of information.
You can delete sessions and your account through the Service where those functions are available.
For organisation-account information, you may also need to contact the organisation that controls the relevant workspace.
For other requests, contact team@yanl.net.
We may need to verify your identity before completing a request. We will not ask for more information than is reasonably necessary for verification.
In the United Kingdom, you may complain to the Information Commissioner’s Office.
If you live in the European Economic Area, you may also be entitled to complain to the supervisory authority in the country where you live or work.
17. Automated processing
YANL may automatically calculate, classify, correlate or summarise diagnostic measurements.
Automated outputs may include:
- derived measurements;
- classifications;
- summaries;
- warnings;
- comparisons;
- visualisations; and
- suggested areas for investigation.
These functions are intended to provide technical information.
We do not use personal data to make decisions about you that are based solely on automated processing and produce legal or similarly significant effects, unless we tell you otherwise and provide the information required by law.
Where an external artificial-intelligence or machine-learning provider is used to process personal data, we will update this Privacy Policy or provide an appropriate notice explaining the provider, purpose and relevant data use.
18. Children
YANL is intended only for people aged 18 or over.
You must not create an account, upload a recording or use the Service if you are under 18.
We do not knowingly collect personal data directly from children through the Service.
If you believe that a child has provided personal data to us, contact team@yanl.net so that we can investigate and take appropriate action.
19. Changes to this Privacy Policy
We may update this Privacy Policy to reflect changes to:
- the Service;
- our providers or technical architecture;
- the information we process;
- our legal obligations; or
- our business operations.
We will publish the updated policy with a revised effective date.
Where a change is material, we will take reasonable steps to bring it to your attention through the Service, by email or by another appropriate method.
20. Contact
For privacy questions, corrections, requests or complaints, contact:
Flying River Ltd
71–75 Shelton Street
Covent Garden
London
WC2H 9JQ
United Kingdom
Email: team@yanl.net