EasyBMS Privacy Policy
W2JKT Software LLC · Last updated 25 July 2026
EasyBMS is a battery-monitoring app that talks to your battery management systems (BMS), shunts, and chargers over Bluetooth, and optionally to monitoring servers you configure. This policy describes what the app and the servers collect, store, transmit, and never collect.
Part 1 — The EasyBMS app
1.1 Stored on your device
- Your live battery readings. Voltages, current, state-of-charge, per-cell millivolts, temperatures, and fault/MOSFET state that the app reads directly from your batteries over Bluetooth are held in memory only, shown on screen, and never written to your device's disk; they are lost when the app closes (as are the app's short in-memory diagnostic buffers). This is different when a monitoring server is involved: if your batteries are monitored through a server, the app streams your live battery telemetry to W2JKT Software LLC, where it is received and stored as a time-series — your pack and per-cell readings, faults, temperatures, MOSFET and balance state, your device names, and the devices' Bluetooth addresses (the full list is in Part 2, §2.3). Bluetooth-only monitoring with no server stays entirely on your device. Enabling APRS also broadcasts periodic telemetry summaries to a public network (§1.2).
- Your settings and per-battery configuration (poll interval, enabled radios, and each battery's name, capacity, chemistry, and chosen driver).
- Credentials, encrypted at rest. Server API keys, your APRS passcode, and per-device Victron keys are stored with Android's hardware-backed Keystore.
- Pinned server certificates and your notification rules.
- A capped rolling diagnostic log in the app's private storage. It never leaves the device on its own — only if you choose to send a bug report (§1.2).
1.2 Transmitted off your device
- Anonymous usage data — off by default (opt-in). The app asks once on first launch; if you opt in, about once per device per day it sends, over HTTPS: your phone model and Android version, the app version, a device count, and for each connected battery its type/model/firmware, a 4-digit short id, and Bluetooth name, plus a random per-install identifier (app-generated, not tied to your device). No battery readings are sent. This usage data is pseudonymous — it is keyed only to that random per-install id and cannot be linked to your account, license, or identity, so we cannot delete it on request. Turn it off in Settings → Usage Analytics.
- Battery analysis sync. If you use the cloud report/shadow-SOC/DCIR features, the app sends your license key and a short device id to fetch your analysis.
- Connections to monitoring servers you configure. The app streams those servers your live readings and authenticates with that server's API key. These connections require TLS; the app refuses to send your data in plaintext.
- Bug reports — only when you choose to send one. The diagnostic bundle contains your description, phone details, your settings (server API keys, APRS passcode, APRS callsign, server hostnames, and SMS recipient numbers are masked; device Victron keys are never included), a snapshot of each connected device including its Bluetooth address and current readings, recent Bluetooth/network traffic, and recent logs. Bug reports are investigated with the help of an AI assistant (Anthropic Claude), so their contents are processed by that third party.
- APRS — off by default, opt-in. If you enable it, your callsign and an aggregated battery summary are broadcast to the public amateur-radio APRS-IS network and archived indefinitely by third-party aggregators.
- Local-network broadcast — optional. An unencrypted reading broadcast on your local network only (never the internet).
- "View charts on the web" opens a link in your browser containing the device's short id, only when you tap it.
1.3 Never collected
EasyBMS does not collect your location, microphone/audio, contacts, camera/photos, an advertising ID, or your email/account identity beyond credentials you type in. It does not send your SMS messages to any EasyBMS server, and it keeps no on-device analytics database of your behavior.
Identifiers we use
A random per-install identifier (app-generated, not your device's hardware id) in usage data; Bluetooth device addresses to identify your batteries; your license key as your account credential; and your APRS callsign only if you enable APRS (which is public by design).
Part 2 — The EasyBMS servers
"Server" means the EasyBMS monitoring server ("easybmsd"), operated by W2JKT Software LLC, plus the cloud services it works with.
2.1 Account & contact information
Username, display name, email (and a secondary email), full name, company, phone number, full postal address, free-text notes, an account role, and a bcrypt-hashed dashboard password. Kept for the life of the account (hosted-cloud only).
2.2 Your device roster & configuration
For each battery/bridge: its full Bluetooth address, your chosen name, type/model, capacity, and owning bridge. Device pairing credentials (a Victron key and Bluetooth pairing PIN) are stored on the server so it can read those devices. Kept until you remove the device.
2.3 Battery telemetry (time-series)
Every reading your devices report is stored as a time-series (readings plus the device address, your name for it, and bridge), retained roughly 60 days uncompressed and up to ~180 days compressed, then deleted. Customer telemetry is stored in a private location and is reachable only over authenticated paths — the session-gated dashboard and the app's credentialed endpoints. It is not publicly readable. (Only W2JKT Software LLC's own demo account is intentionally published on the public site.)
2.4 Banks, rules & automation
Your battery groupings ("banks") and the notification/automation rules you define, kept until you delete them.
2.5 Reports & analysis
Server-side analyzers compute and store battery-health reports (cell drift, internal resistance/DCIR, cell health) derived from your telemetry.
2.6 Bug reports you submit
An intake record (your license id/username, uploader key, client IP, app version) and the diagnostic bundle itself (logs, device snapshots, phone details, and your settings with credentials and the items listed in §1.2 masked). Bug reports are processed by Anthropic Claude during triage and are retained as part of our records and the project's development history (they inform fixes). You consent to this when you choose to submit a report. The app can also show you a coarse processing status of reports you submitted (for example: received, under review, or fixed); that status is scoped to your account and exposes no other information.
2.7 Licensing & usage records
Each license validation records a hardware fingerprint (an irreversible hash), your license id, your IP address, the app version, and timestamps; self-service license requests also record the email you supply. The optional anonymous app usage data (§1.2) is stored in a usage database.
2.8 Operational logs
Day-rotated server logs containing device short-ids, device names, and a record of control commands you issue, plus standard web-server access logs.
2.9 Third-party sharing
Anthropic (Claude) processes bug-report contents during AI-assisted triage. APRS-IS (public) receives your callsign and aggregated summary if you enable APRS. We do not sell your data and use no advertising or analytics third parties.
2.10 Security & access
Data is encrypted in transit with TLS, passwords are bcrypt-hashed, and your data is scoped to your account. W2JKT Software LLC support personnel can access hosted data to provide support and triage bug reports. If we learn of a breach of security affecting your personal information, we will notify you and the relevant authorities as required by applicable law.
2.11 Terms-acceptance records
When you accept our Terms of Service & EULA and this policy in the app, we record the document versions you accepted and the time of acceptance, together with your account or a per-install id. We keep these records as evidence of the agreement, even if you later delete your data or account.
Deleting your data
You can delete the data we hold for you at any time, in two scopes:
- In the app. Use Delete my data to remove your off-device telemetry, device roster, rules, reports, and bug-report bundles while keeping your account active, or Delete my account to additionally remove your account and stop monitoring.
- On the web. Our public data-deletion form is at https://w2jkt.com/delete. This is the data-deletion URL for Google Play; submit your license key or account email and confirm via the link we send to your registered email.
A deletion request immediately purges that data even though it would otherwise be retained up to 180 days. The pseudonymous usage analytics described in §1.2 cannot be linked to your account, so it cannot be deleted by request. Records required for legal compliance (such as the terms-acceptance records in §2.11) are retained. You can also email requests or questions to easybms@w2jkt.com.
Your choices & contact
You can turn off usage data; APRS, local-network broadcast, and SMS alerts are off by default; bug reports are only sent when you choose. Uninstalling the app or clearing its data removes everything stored on your device, and you can delete your off-device data or your whole account at any time (see Deleting your data above). Questions or requests: easybms@w2jkt.com.
EasyBMS is not directed to children under 13, and we do not knowingly collect personal information from them.
We may update this policy; the "last updated" date above reflects the current version. If we make material changes, we will provide notice (for example, in the app or on this page).