WLAN Geeks LLC ("we", "us", "our") develops PCAPAI Desktop ("the Software"). This Privacy Policy describes what data the Software collects, how it is used, and your choices.
The Software does not collect, transmit, or store:
We collect personal information (name, email address, company) and your IP address in exactly three situations, and nowhere else. Each one has its own section describing what and why: licensing, if you request or hold a paid licence (Section 4); downloading the Software, because the link goes to your email address (§9); and feedback, if you choose to give us a contact address (§10). Using the Free tier without downloading from our site and without sending feedback involves none of it.
The Software stores the following data on your local filesystem:
| Data | Location | Purpose |
|---|---|---|
| Settings | OS config directory | Your preferences (theme, columns, etc.) |
| Licence file and licence state | OS config directory | Your licence, its expiry, and your device label |
| API keys | OS keychain | Encrypted storage of AI provider API keys |
| Crash logs | OS log directory | Debugging information if the app crashes |
| Analysis files | User-chosen location | .pcapai files you save |
Paths: macOS: ~/Library/Application Support/pcapai/ · Linux: ~/.config/pcapai/ · Windows: %APPDATA%\pcapai\
Crash logs are written to disk only when the Software encounters an unexpected error. Before writing, the Software automatically redacts:
Crash logs are never transmitted automatically. You may choose to attach them to a support request voluntarily.
Anonymous usage analytics are enabled by default during the beta. To turn them off, open Settings › Security › Beta Diagnostics and clear Send opt-in aggregate diagnostics. It takes effect immediately — nothing further is sent from that moment, and you do not need to restart the Software.
When enabled, the Software sends to pcapai.app:
Analytics never include, whether enabled or not: packet contents, packet metadata, capture-derived values, file paths, filenames, display filters, IP addresses, MAC addresses, hostnames, SSIDs, BSSIDs, AI prompts, AI responses, API keys, licence keys, credentials, or authentication tokens.
Your network address is visible to our servers when your machine sends analytics, as it is with any network request. For analytics it is used only to rate-limit abuse, is stored only as a salted hash, and is never stored alongside the analytics data.
We delete analytics records with a cleanup that removes anything older than a set window — 180 days by default, and never more than 365. That cleanup is run by hand rather than on a schedule, so a record can outlive the window until the next run.
For licence binding, the Software computes a machine identifier (MID) by taking a SHA-256 hash of a hardware ID combined with a salt. This is a one-way hash — the original hardware identifier cannot be recovered from it, and the MID is not a serial number, a MAC address, or any other identifier that has meaning outside PCAPAI.
The MID is stored in your local licence file. It is transmitted when you request, activate, or renew a paid licence (§4), and when you use a feature that requires us to authorize your licence — for example the optional AFC feature (§5.5) or downloading an AI model your licence entitles you to. When it is transmitted, we may use it to: verify and enforce your licence; authorize, meter, and rate-limit access to services we provide; detect, investigate, and prevent fraud, abuse, and unauthorized sharing of licences; operate, secure, maintain, and improve those services; provide support at your request; and comply with legal obligations.
We do not sell it, do not use it for advertising, do not use it to build a profile of you or your activity, and do not disclose it to third parties except to service providers acting on our behalf under contract, or where required by law. If you use the Free tier and no feature that requires authorization, the MID never leaves your machine.
This section applies only if you request or hold a Standard or Pro licence. Free-tier use requires no account, no licence key, and no transmission of anything described here.
When you request a licence from within the Software, we receive and store:
We send a confirmation link to your email address; a request is not visible for approval until you click it. The IP address is stored with the request and used to detect and rate-limit abuse of the request form. Your email address is used to contact you about your request and to deliver your licence key.
When you activate a machine against a licence key, the Software sends:
We store one activation record per machine holding a seat: the machine identifier, device label, operating system, app version, when it was activated, and when it was last seen. This is what enforces the seat count, and it is what the Software shows you in its device list so you can identify a machine and release it.
Your licence file is a time-limited lease that the Software renews automatically in the background. A renewal sends your existing signed licence and your machine identifier; it updates the "last seen" time on your activation record. Viewing your device list and releasing a machine send the same signed licence, plus the machine identifier being released.
We do not receive, and cannot infer from any of this, what you were doing in the Software — only that a machine on your licence checked in.
The device label exists so that a row in your own device list is recognizable to you rather than being a bare hash. It defaults to your computer's hostname and is editable in the Software before it is first sent — so if your hostname says something you would rather not send, you can change it at the point of activation. It is shown only to you and to us, never to other users.
We retain your entitlement record — email, name, company, tier, seat count, term — for as long as your licence exists, and afterwards as a record of a licence having been issued. Activation records are retained while the seat is held and, once released, retained as a record that the machine was released. Licence requests are retained as a record that a request was made and how it was decided, including rejected ones.
We do not sell any of this, do not use it for advertising, and do not disclose it to third parties except to service providers acting on our behalf — our hosting and database provider (Cloudflare) and our transactional email provider (Resend) — or where required by law. To ask about, correct, or delete your licensing records, contact us at the address in §13; deleting them ends the licence, because the record is the licence.
The Software includes optional AI-powered analysis features (Network Analyst, General Assistant, Security Analyzer). These features are disabled by default and require you to:
When you use AI features, the Software sends to your configured AI provider:
The Software does not send:
When using local AI providers (Ollama, LM Studio), all data remains on your machine. No data is transmitted to any external service.
Data sent to third-party AI providers is subject to their respective privacy policies:
We have no control over how these providers handle your data.
PCAPAI is not a certified AFC system and is not approved or endorsed by the FCC, by any AFC system operator, or by any other regulatory body. The AFC feature is provided for laboratory, educational, modeling, and planning use — to illustrate what a certified AFC system might report. It is not an authorization to operate any radio transmitter and must not be relied upon to determine whether transmission is permitted. See the EULA §5 for the full terms.
AFC is an optional feature used for 6 GHz standard-power channel planning. It is off unless you use it.
What is sent, and to whom. When you make an AFC query, the Software sends your license envelope and the query's location and antenna parameters to pcapai.app. pcapai.app verifies the license, then forwards the spectrum query to the AFC operator. Your license and machine identifier are never forwarded to the AFC operator or any third party — they are used solely to authorize the request.
What we log. pcapai.app records the license identifier and the outcome of each request (allowed, denied, rate-limited) so the service can be operated and abusive access revoked. The license identifier is stored hashed. We do not log the location you queried. Coordinates are forwarded to the AFC operator to answer the query and are not retained by pcapai.app, do not appear in analytics or crash reports, and are not included in the diagnostics bundle.
Why a broker exists. The AFC operator's credential is held by pcapai.app rather than embedded in the Software. A credential shipped inside an application can be extracted by anyone who has the application, cannot be revoked for one user, and would expire for everyone at once.
Results are planning data. PCAPAI is a planning client, not a certified AFC device. AFC results are labelled as planning information and are not an authorization to operate real access points.
If you never use AFC, none of the above applies to you and nothing is sent.
The optional geolocation feature uses locally stored MaxMind GeoLite2 database files to resolve IP addresses to approximate geographic locations. No data is transmitted to MaxMind or any external service for this purpose. The databases are bundled with the application.
The Software includes network diagnostic tools (ping, traceroute, ARP lookup, DNS lookup, Wi-Fi scanner) that interact with your local network. These tools operate directly on your machine using standard operating system APIs. No data from these operations is transmitted to external services.
When you check for updates, the Software requests the PCAPAI update manifest from pcapai.app and may open the PCAPAI website. Standard web server logs may record your IP address — this is controlled by the web hosting provider.
This section is about our website, not the Software. It applies if you use the download form on pcapai.app. It does not apply if you got PCAPAI some other way.
The form asks for your email address, a beta access code, and which platform you want. We ask for the address because the download link is emailed to you rather than served from the page.
Your request is recorded in our hosting provider's key-value store. The pieces have different lifetimes, and one of them does not expire at all:
| Record | What it holds | Kept for |
|---|---|---|
| Your email record | Your address, when you first asked, when you last asked, how many times in total, which platforms and how many times each, and the IP address your most recent request came from | No expiry — kept until we delete it |
| Request entry | Your address and the platform you chose | 365 days |
| Download entry, written only if you actually use the link | Your address, the platform, the link token, the time, the IP address, and your browser's user-agent string | 365 days |
| Download link token | Your address and the platform | 24 hours |
| Abuse counters | Counts keyed to your IP address or your email address | 10 minutes to 24 hours |
We are stating the first row plainly because it is the one that surprises people: the email record has no expiry set. It persists until it is deleted by hand. The rest ages out on its own.
To send you the download link; to stop the form being abused, which is what the counters and the IP address are for; and to see how many people are trying the beta and on which platform.
We do not sell it, do not use it for advertising, and do not send marketing email to it — the only message we send from the form is your download link. We do not disclose it to third parties except to service providers acting on our behalf: our hosting and database provider (Cloudflare) and our transactional email provider (Resend). To ask about or delete your download record, contact us at the address in §13.
Sending feedback is voluntary. Nothing in this section happens unless you open the feedback form and submit it.
Your message, and the category you pick. A contact address, only if you type one — the field is optional, and leaving it blank still sends the feedback. Alongside it, the Software attaches the app version, release channel, operating system, CPU architecture, and the same anonymous install identifier described in §3.2, so that a report can be read in context.
Your network address is used to rate-limit the form and is stored only as a salted hash, as in §3.2. It is not stored with your feedback.
You may attach a screenshot. The Software never takes or attaches one on its own — an image is included only because you pasted or attached it, you are shown exactly what will be sent before you send it, and you can remove it.
Please look at it first. A screenshot of a packet analyzer can contain capture data — SSIDs, BSSIDs, MAC addresses, client and device names, IP addresses, hostnames, file names and paths. That is your data and possibly your customer's, and once you attach it we hold it. Nothing in the Software inspects or redacts an image you attach, so if you are unsure, crop it or do not attach it. The feedback is just as useful with the screenshot left off.
Feedback is stored in our database and is also copied into an issue in our private GitHub repository so that it can be tracked and acted on. That repository is not public: the copy is visible to us and to GitHub as our service provider, not to other users or to the internet. The copy carries the same fields, including the contact address if you gave one.
The database record is removed by the same cleanup described in §3.2 — 180 days by default, never more than 365, run by hand. The GitHub issue is not covered by that cleanup and remains until it is deleted by hand. To ask about or delete feedback you sent, contact us at the address in §13 and tell us roughly when you sent it.
The Software is not directed at children under the age of 13. We do not knowingly collect data from children.
We may update this Privacy Policy from time to time. Changes will be posted in the Software's documentation and on our website. Your continued use of the Software after changes constitutes acceptance.
For questions about this Privacy Policy, or to ask about, correct, or delete data we hold about you, contact: kevin@wlangeeks.com