WATCHTOWER

PRIVACY POLICY

Privacy Policy

Last updated 25 September 2026 · Effective for Watchtower version 1.0.0 and later

The short version: Watchtower has no servers, no accounts and no sign-in. Almost everything it does happens directly between your device and the public data provider you're asking about (weather, flights, markets, news, radio, and so on). We — Sleeping Giant Marketing — never see that traffic, don't run analytics or ad tracking, and don't sell or share your data, because there's no channel for it to reach us through. The sections below explain, provider by provider, what does leave your device and why.

1. Who we are

Watchtower is developed and published by Sleeping Giant Marketing Services (OPC) Private Limited, trading as Sleeping Giant Marketing ("Sleeping Giant Marketing", "we", "us"), based in Bhopal, India. This policy covers the Watchtower mobile app (iOS and Android, package/bundle ID com.watchtower.app) and this website. You can reach us any time at hello@sleepingiantmarketing.com.

Watchtower is a free OSINT (open-source intelligence) dashboard: a live globe of aircraft, ships, satellites and hazards, plus markets, news and radio for any country, drawn from dozens of public data providers. There are no ads, no in-app purchases, and no user accounts.

2. What we don't collect

We — the developer — do not operate a backend server for Watchtower, and we do not collect, log, or store any of the following, because there is nothing in the app that sends it to us:

The app contains no analytics SDK, no crash-reporting SDK, no advertising SDK, and no sign-in SDK.

3. Location

Location access is entirely optional and, on both iOS and Android, is requested only while the app is open in the foreground — Watchtower never requests background or "always" location.

What stays on your device: your precise GPS fix is used only locally — to centre the globe on you, to calculate which satellites are passing overhead, and to label items as "N km from you." It is not transmitted by us anywhere.

What is shared, and with whom: when a feature needs data near you, a coarse version of your location — rounded to about 0.1° (roughly 11 km), together with the name of your city, region and country — may be sent to the specific public provider that feature uses. This happens only when you use that feature. The providers this can apply to are:

FeatureProvider(s) that may receive your coarse location or region
Local weather & air qualityOpen-Meteo, MeteoAlarm (Europe)
Nearby aircraftadsb.lol, adsb.fi
Nearby earthquakesUSGS
Radio stations near youRadio Browser (radio-browser.info)
Regional / local newsGDELT, Global Voices, UN News
Country markets & economic dataWorld Bank (country code only)
AI features, if you've added a key and enabled location sharingyour chosen AI provider — see §4

Getting a location fix also uses your device's built-in geocoder to turn coordinates into place names — Apple's servers on iOS, or Google Play services on Android — the same way any map app would. This is handled by the operating system, not by us.

You can revoke location permission at any time from your device's system settings. Once revoked, Watchtower's features that use location simply fall back to a manually chosen country, or go without a "near you" view. Note that Watchtower currently keeps your last-known location saved on the device (see §6) even if you later revoke permission; it is just not sent anywhere further. If you want it fully cleared, clear the app's storage as described in §6.

4. AI features — bring your own key (BYOK)

Watchtower's AI features (explanations, briefings, and the "Ask" assistant) are entirely optional and are powered by your own account with a third-party AI provider — never a Watchtower-run AI service. You choose the provider and paste in your own API key.

Supported providers: Anthropic, OpenAI, Google Gemini, Groq, Mistral, and OpenRouter.

How it works:

If you disable an AI feature or never add a key, none of this applies — nothing AI-related is sent anywhere.

5. Your own API keys for data sources

Beyond AI, Watchtower lets you optionally add your own API keys or credentials to unlock extra data from certain providers (this is never required — the app works fully without any keys). Each credential is stored only in your device's secure storage and is sent only to the single provider it belongs to, never to us or to any other party:

CategoryProviders
Conflict & crisis dataACLED — this is the one credential that is personal data (your ACLED account email and password), sent only to ACLED's own login (acleddata.com) to obtain an access token
Financial & markets dataFRED, BLS, CoinGecko, CoinMarketCap, Finnhub, Alpha Vantage
Aviation, maritime & hazardsNASA FIRMS, AISStream
Sanctions & securityOpenSanctions, Cloudflare Radar
Government & patentsReliefWeb, USPTO
Messagingyour own Telegram bot token, if you choose to connect one

Any usage limits, fees, or terms tied to a key you provide are between you and that provider — see our Terms of Use.

6. What's stored on your device

Watchtower stores the following locally, using standard app storage (and, for credentials, your OS's encrypted secure storage). None of it is synced to us:

Clearing your data: you can remove individual items (a key, a feed, a hidden station) from within the app's own settings screens. To remove everything at once, clear the app's storage from your device's system settings, or uninstall the app — either immediately and permanently deletes all of the above, because it only ever existed on your device.

7. Background refresh

To have fresh data ready when you open the app, Watchtower periodically refreshes its data sources in the background (roughly every 15 minutes at minimum, scheduled by your device's operating system — not more often than the OS allows, and never while your device is low on battery or resources, per standard iOS/Android background task rules). This uses your last saved location if you've granted permission, the same way as if you'd opened the app. It does not show notifications, does not run AI features, and sends nothing to us.

8. Third-party SDKs bundled with the app

Watchtower's translation feature uses Google ML Kit to translate foreign-language headlines and identify their language, on-device where possible. Per Google's own disclosure for this SDK, using it can share certain diagnostic and usage data with Google — such as device and app information, a per-installation identifier, performance metrics, and (for translation) the source/target language pair — for Google's diagnostics and analytics. Google states this data is not passed to third parties. See Google's ML Kit data disclosure for details. The on-device translation models themselves download from Google's servers over Wi-Fi the first time you use a given language.

Until a language's on-device model has finished downloading, foreign-language headlines are translated using MyMemory, a third-party translation API — this sends the third-party headline text (never anything you personally typed) to MyMemory's servers. You can turn off auto-translation in the app's settings.

No other third-party SDK is bundled with Watchtower: there is no analytics, crash reporting, advertising, or sign-in SDK in the app.

9. Third-party content

Watchtower aggregates content from many independent public sources — news wires, Reddit/Lemmy communities, Bluesky and Telegram posts, government and scientific data feeds, and any RSS feed you add yourself. We do not write, verify, or moderate this content, and the opinions or claims in it belong to their original authors and publishers, not to us. See the full list of sources and their licences. If you see something in the app that's wrong, offensive, or that you believe infringes your rights, please tell us — see §11 and our Support page for how to report it.

10. Emails and reports you send

Some requests Watchtower makes to public data providers include a short "contact" line in the technical User-Agent header — hello@sleepingiantmarketing.com — so that a provider can reach us if a request from the app is causing them a problem. This is standard practice for API clients and is not tied to your personal identity.

The in-app Report button (on AI answers) opens a pre-filled email addressed to hello@sleepingiantmarketing.com in your own mail app — it does not send anything automatically. The draft includes the feature and AI provider used, the time, your device platform, and (depending on the feature) the question you asked or the item you were viewing, plus the AI's response, so we can look into it. You choose whether to send it, and you can edit or delete anything in the draft first.

11. How this maps to the app stores' privacy labels

For transparency, here's roughly how we've represented Watchtower in Google Play's Data Safety section and Apple's App Privacy ("nutrition label") details:

12. Children's privacy

Watchtower is not directed at children, and we do not knowingly collect personal information from children under 13 (or under 16 in the EEA/UK). If you believe a child has provided us personal information (for example, through a support email), contact us at hello@sleepingiantmarketing.com and we will address it.

13. Your rights

If you're in the EU, UK, or another jurisdiction with similar law (GDPR / UK GDPR)

Where we act as a data controller (chiefly: the minimal data in a message you send us), our legal basis is your consent (sending us an email) or our legitimate interest in operating and supporting the app. You have the right to request access to, correction of, or erasure of your personal data, to restrict or object to its processing, and to data portability. Because Watchtower stores your data on your own device rather than with us, the most direct way to exercise erasure is simply to clear the app's storage or uninstall it (§6). You also have the right to lodge a complaint with your local data protection authority (in the UK, the ICO).

If you're in California (CCPA / CPRA)

We do not sell or share personal information as those terms are defined under California law. We do not collect the kinds of identifiers, geolocation, or other personal information listed in the CCPA in any form we retain — data that touches third-party providers passes directly from your device to them, as described above. You may still contact us at hello@sleepingiantmarketing.com with any CCPA request and we will respond.

If you're in India (Digital Personal Data Protection Act, 2023)

Where we process personal data as a Data Fiduciary (for example, an email you send us), you have the right to access a summary of that data, seek correction or erasure, and file a grievance, as set out in the DPDP Act. Our Grievance Officer's contact details are in §16.

14. Security

All network requests Watchtower makes use encrypted connections (HTTPS or WSS). API keys and credentials you enter are stored using your operating system's dedicated secure storage (Keychain on iOS, an encrypted keystore-backed store on Android) rather than in plain text. Because we operate no server holding your data, there is no central database of user data for us to secure or that could be breached on our end — the security of data on your device depends on your device's own lock and encryption settings.

15. International data transfers

Because Watchtower has no backend, your device communicates directly with each public data provider or AI provider you use, which may be located in a different country than you. Each of those transfers, and any related safeguards, are governed by that provider's own privacy policy — see the Sources page for the full list.

16. Changes to this policy

We may update this Privacy Policy from time to time, for example as we add or change features. We'll update the "Last updated" date above when we do. If a change is significant — for instance, if we were ever to introduce our own server-side processing — we'll make that clear on this page and, where required by law, seek your consent again before it takes effect.

17. Contact & Grievance Officer

For any question about this policy or your data, contact us at hello@sleepingiantmarketing.com.

In accordance with India's Information Technology Rules and the Digital Personal Data Protection Act, 2023, our Grievance Officer is:

Kunal Bakshi
Sleeping Giant Marketing Services (OPC) Private Limited
Bhopal, Madhya Pradesh, India
hello@sleepingiantmarketing.com

We aim to acknowledge grievances within a reasonable time and resolve them as promptly as we can.