Privacy and retention policy

Last changed 2026-09-13

QNN HQ is operated by the San Diego Amateur Radio Council (SANDARC) for amateur radio clubs to run their on-air nets. This page says what we store about you, who can see it, how long we keep it, and how to have it removed. Contact for anything on this page: [email protected].

If you make an account: your username, email address, a hashed password (we never store the password itself), when you signed up, when you agreed to this policy, and when you last signed in, your callsign, your FCC Registration Number (FRN) and licence status and class as reported by the FCC licence database, the licensee name from that record, your Maidenhead grid square (a location about 5 km across, chosen by you), your time-format choice, and your notification choices.

If you turn on a second factor: the authenticator secret, encrypted under the site's key, and hashed recovery codes. If you add a passkey: its public key, credential id, the nickname you gave it, and when it was last used. Neither lets us sign in as you.

If a club seats you as a member: your role in that club (club admin, net control operator, viewer, or member), any officer title the club gives you, and when you were seated.

If you are on a club's roster: your callsign, name, licence class, and, if the club recorded them, an email address and phone number, plus your position in roll-call order and which nets you asked to be reminded about.

When you check into a net: your callsign, the name and licence class the net control operator recorded or looked up, your operating mode (mobile, portable, and so on), whether you had traffic, and any location (QTH), signal report, comment or club-defined field the operator typed, with the time it was logged. Corrections and voids are kept as a record rather than erased.

If you follow a club: which club and when.

If you link a Discord account: your Discord user id and username, and when you linked it. We ask Discord for nothing else.

If you post in a club's forum: your posts, when they were written, edited or removed, and which threads you subscribed to. A post a moderator removes is hidden from the page, but its text stays on the record and in the club's audit trail.

If a club invites you: the email address the invitation went to, the role offered, who sent it, and whether it was accepted, revoked or undeliverable.

If you request something: roster opt-in requests (callsign, name, email, phone, licence class), join requests raised by net control, and callsign-change requests (old and new callsign, the FCC lookup result, any note the deciding admin wrote).

Club records: a club's contact email, grid square, description, and whatever it chooses to publish on its public pages: an about text, founding year, website, meeting information, a public email address, a mailing address, and its officers.

Audit trail: clubs keep a record of who changed what: seating, role changes and removals, officer changes, roster edits and merges, check-ins logged and edited, session cancellations, club settings, invitations, CSV exports, callsign-change decisions, forum moderation, and announcements. These entries hold the before-and-after values, which can include a roster row's name, email and phone, a check-in's full details, and a removed post's text. SANDARC records who is granted or loses a staff role; other staff actions are written to the server log, not to an audit trail.

Anyone, without an account:

Club admins, net control operators and viewers: the club's roster (callsign, name, licence class), every net's check-in history, live check-ins during a net, attendance statistics, the club's forum and announcements. Club admins and net control operators additionally see roster email addresses and phone numbers. Members (the list-only role) see the forum and announcements.

Club admins: the members list (callsign, role, title), the callsigns and names of the club's followers, pending callsign-change requests from members, and the audit trail. They can download a net's or a session's check-in log as a CSV file.

You: your own check-in history across every club, your roster links, your callsign history, your second-factor and passkey settings, and your notification settings.

SANDARC staff: everything above for every club, plus usernames and invitation email addresses, through an administrative console. Staff do not run nets and do not read club data for any purpose other than operating the service and responding to requests.

We do not sell data, run advertising, or use analytics trackers.

We set a session cookie when you sign in, a CSRF token that protects forms, and a short-lived cookie that carries a one-time status message. Public pages set no cookie of ours at all. Your theme (light or dark) is kept only in your browser's local storage and never sent to us; your clock format (12 or 24-hour) is saved on your profile and mirrored to local storage for public pages. Cloudflare may set its own cookie (section 5). There are no advertising or analytics cookies.

Passwords are hashed. Connections use TLS. Each club's data is isolated from every other club's at the database level (row-level security). Sign-in attempts are throttled, and you can add a second factor or a passkey to your account. Only SANDARC staff have administrative access.

Amateur radio licences are issued without a minimum age. The service does not ask for age and treats every licensee alike. If a parent or guardian wants a minor's data removed, email [email protected].

We note the date of the last change at the top of this page.