Privacy Policy
Last updated: August 7, 2026
CQDX is operated by Hagale Technologies. This policy describes what we actually collect and do with it, written directly from how the system is built rather than boilerplate. If anything here is unclear, let us know.
What CQDX is
CQDX (cqdx.io / cqdx.app) is a DX spotting portal for amateur radio operators. Most of the site — live spots, rarity rankings, propagation predictions — is public data about radio activity and doesn't involve your personal information at all. This policy covers the parts that do: creating an account, logging QSOs, and anything else tied to you specifically.
What we collect
Account information
Email address and callsign (both required), and optionally your grid square. We use passwordless "magic link" login — we never ask for or store a password for your CQDX account. When you register we also store your minimum-age confirmation and the timestamp of the moment you made it, as the record of that attestation. It's kept for the same account-retention period as the rest of your account information, and it's deleted when you delete your account.
Authentication data
Session cookies, and if you enable them, passkey (WebAuthn) credentials. If you use CQDX's remote-rig features with Pancetta, we also store pairing/authorization tokens for that connection. Personal Access Tokens you generate for API access are stored as one-way hashes — we can't recover the token value after it's issued to you.
QSO logs and award tracking
If you log contacts or upload a log, we store the QSO details you provide: worked callsign, band, mode, signal reports, grid squares, and timestamps. This builds your "needed" list against DXCC entities and grid awards.
Third-party sync credentials (ClubLog / LoTW)
If you use the optional ClubLog or ARRL Logbook of the World (LoTW) sync features, you enter your credentials for those services directly into CQDX. We forward them over HTTPS to ClubLog's or ARRL's own API to fetch your confirmation status — we do not store these passwords. They exist only for the duration of that one request.
You can also tag your own confirmation records as coming from QRZ or eQSL; we don't contact those services on your behalf or handle any credentials for them.
Feedback submissions
If you use the feedback form, we receive your message, your callsign and email if you're logged in, and your IP address (used only for abuse prevention on that form).
Technical data
We log IP addresses transiently for rate limiting and abuse prevention across the API. We don't run analytics or advertising trackers of any kind — there's no Google Analytics, no ad pixels, nothing watching you browse.
Cookies
CQDX sets one cookie: a session cookie that keeps you logged in. It's strictly necessary for the site to function and isn't used for tracking or advertising. We don't use any third-party analytics or marketing cookies.
Who else sees your data
We use a small number of service providers to run CQDX. None of them can use your data for their own purposes — they process it only to provide their service to us.
| Provider | Purpose |
|---|---|
| Cloudflare | Hosting, database, storage, bot protection (Turnstile), and email forwarding |
| Resend | Sends login links and feedback notification emails |
| Fly.io | Runs the live spot ingest service (public spot data only) |
| ClubLog / ARRL LoTW | Only if you use the optional sync features — see above |
How long we keep data
Public spot data is aggregated and pruned on a rolling retention schedule — it doesn't accumulate indefinitely. Your account, QSO logs, and related data are kept for as long as your account exists. You can delete your account yourself at any time from your account page — deletion is immediate and permanent, and removes your account together with your QSO logs, awards progress, alerts, API tokens, passkeys, and paired devices. If you'd rather we handle it, email contact@cqdx.io.
Three records outlive deletion. None is included in your export or removed when you delete, and all three expire on their own:
- A deletion record, kept for 30 days. It holds your account identifier and the time you deleted, and nothing else. It exists so that sign-ins already issued to your other devices stop working immediately instead of staying valid until they expire — deleting it early would let a session outlive your account, so it is kept for the full lifetime of the longest-lived sign-in, then removed automatically.
- If a request of yours fails, a diagnostic record naming your account identifier is kept for 7 days so we can fix the fault. It is filed under the time of the fault and the name of the operation, not under your account, so it cannot be looked up from your account either.
- If a sign-in, passkey, or device-pairing attempt is still in progress, its working state names your account identifier for up to 10 minutes — usually only seconds. It is filed under a random identifier rather than under your account.
Your rights
Regardless of where you're located, you can access, export, correct, or delete your personal data at any time. Export and deletion are self-service on your account page, and your grid square is editable there. Callsign corrections need a uniqueness check, so email them to us. For anything else, email contact@cqdx.io. Amateur radio is an inherently international hobby, so this applies whether you're writing from the US, the EU, or anywhere else — we'll honor GDPR-style requests (access, rectification, erasure, restriction, portability, objection) the same way for everyone.
Children's privacy
CQDX isn't directed at children, but we recognize amateur radio has licensed operators of all ages, including minors. When you create an account we ask you to confirm you're at least 13 years old. We don't verify your age beyond that confirmation. If you're a parent or guardian and want to review or remove a minor's data, contact us at contact@cqdx.io.
Security
All traffic to CQDX is encrypted (HTTPS). We don't store passwords for your CQDX account. Personal Access Tokens are stored as one-way hashes. Third-party sync credentials (ClubLog/LoTW) are relayed, never stored. No secrets live in our source code.
Changes to this policy
If this policy changes materially, we'll update the date at the top of this page. Check back occasionally if you want to stay current.
Contact
Questions about this policy or your data: contact@cqdx.io or use the feedback form.