Privacy and your data

What stays on your phone, what leaves it and when, and the permissions OpenSurvey3D asks for. No account, no analytics, no tracking.

On this page

OpenSurvey3D works without an account, and your survey data stays on your phone. Data leaves the phone in only a few cases, each of which you start yourself. This page lists them. For the website's own policy, see the privacy policy.

What stays on the phone

  • Projects, assets, coordinates, notes and attributes.
  • Photos, videos and 3D scans. Photos include the GNSS position in their EXIF data.
  • Raw receiver logs (NMEA).
  • Offline map areas, cached map tiles and built site models.
  • Your surveyor name, settings and saved NTRIP casters. The caster password is stored in the iOS Keychain.

Nothing is synced to a cloud service. There's no account, no analytics, no advertising, and nothing is used to track you across apps.

What leaves the phone, and when

Files you export

When you export or share a file, it goes wherever you send it with the iOS share sheet. That can be precise locations, photos with GPS in their EXIF, scans, and raw receiver logs if they're in a bundle. The app doesn't upload exports anywhere itself.

NTRIP corrections

When you connect to an NTRIP caster, the app sends your login and, periodically, your current position to that caster. Network (VRS) services need your position to compute corrections for where you are. Nothing is sent to a caster unless you configure one and tap Connect corrections.

Maps, terrain and imagery

To draw maps and build the 3D site model, the app downloads tiles:

  • Basemap tiles: from OpenFreeMap.
  • Elevation tiles: the public Terrarium dataset, hosted on Amazon S3.
  • Satellite imagery for 3D: from Esri World Imagery.

These requests reveal which map area you're viewing, as any map app's do, but they carry none of your survey data. Offline areas and built site models are reused without downloading again.

Problem reports

When you send a report with Report a problem, it goes to the developers' Firebase project on Google Cloud. The project is set up so the app can create a report but can't read one back, including its own. A report contains:

  • Always: what you typed, the kind of problem and the screen, and a summary of the app's state that you can read before sending: zone, asset count, fix type, receiver and corrections state, units, device model, iOS version and app version. It never includes coordinates, the project name, your surveyor name or the receiver's serial number.
  • Only if you fill them in: a class or crew name, and an email address for a reply. The email identifies you; leave it blank to stay anonymous.
  • Only if you switch them on: a screenshot, which shows your screen and so roughly where you are, and the receiver's recent NMEA, which is a record of your positions.

Nothing is sent until you tap Send. A report saved without a signal waits on the phone and is dropped after 14 days if it can't be sent. See Report a problem.

Permissions

iOS asks before the app can use each of these. Denying one leaves the rest of the app usable.

Permission Why it's asked
Location (while using the app) To show your position on the map and record it with each asset, so measurements have a position and an accuracy.
Camera To photograph assets and scan sites in 3D with the camera and LiDAR.
Microphone Only for sound in the video notes you record.
Local Network To connect to a GNSS receiver on its Wi-Fi hotspot or your local network, to stream positions and send corrections.

Bluetooth receivers are paired in iOS Settings → Bluetooth; the app connects to them as accessories.

Deleting data

Delete a project from the Projects tab to remove it and its data from the app. Settings → Clear map tile cache removes cached tiles and imagery, but keeps downloaded offline areas and built site models. Raw receiver logs for a project can be deleted from the Precision sheet.