← Home

Privacy Policy

For the GDF Connect application for Android and iPhone, published by Fitz Systems LLC.

Last updated 25 September 2026

The short version

GDF Connect is a workforce app for security guard agencies. It is an employee monitoring tool: while a guard is clocked in to a shift it records their location continuously, and it lets the guard record body-cam video when they choose to. On Android, Google Play may warn you about this when you install it. That warning is accurate, and this page is the explanation it points to.

Nobody signs up for GDF Connect on their own. Your agency’s administrator creates your account, and your agency runs the server that holds your data. Fitz Systems LLC writes and publishes the app but does not operate a central database of guard locations or recordings.

The app has no advertising, no analytics, no crash reporting and no third-party trackers. It does not track anyone who is not clocked in. It does no face recognition and no automated analysis of footage. Nothing is sold or shared for advertising, ever.

Who runs what

Two different parties are involved, and it matters which one you are dealing with.

Your agency
Runs its own server. Everything the app collects is sent to that server and is held there, under the agency’s control. The agency decides who gets an account, what its staff are told, and how its records are handled. For anything about your data — seeing it, correcting it, or deleting it — the agency is the one to ask.
Fitz Systems LLC
Writes and publishes the app. We do not have access to any agency’s server and we do not receive the locations, recordings, reports or messages the app produces. The one thing the app sends to us is described under “Third-party services” below: a one-time lookup of your organization code so the app can find your agency’s server.

Data we collect

The app has two kinds of user, and the app treats them very differently.

From guards

If you are a guard, the app collects the following and sends it to your agency’s server:

From clients

If you are a client — a property owner or manager who logs in to see what is happening at your own sites — the app holds your account details (name, email address and phone number), any messages you send to the agency or its guards, any map markers you place on your own properties, and a push notification token for your phone. Clients are not location-tracked and are not recorded.

What the app does not collect

Location tracking

When you clock in, the app starts following your position and keeps doing so for the length of the shift, including while the screen is off. On Android this runs as a foreground service with a persistent notification the whole time, so you can always see that tracking is on. On iPhone, the system shows its own location indicator while the app is using your location. When you clock out, tracking stops and no further positions are taken.

Your location is also used at clock-in itself: a site can have a geofence, and the app checks that you are inside it before it lets you clock in there.

Your track is visible to your agency’s administrators and supervisors, and — while you are on an active shift at a client’s site — to that client. See “Who can see what”.

Body-cam recording

The body cam is not always on. It records only when you press START, and it stops when you press STOP. It is meant for a specific incident or altercation, and a recording is typically a few minutes long. Nothing records automatically, and the app does not switch the camera on by itself.

While it is recording, the video and audio stream live to your agency’s server so a supervisor can watch. A local copy is also saved on the phone and uploaded afterward, so the agency gets a full-quality clip even if the live connection was poor.

People who are not users

A body-cam recording captures whoever is present — members of the public, visitors, the other party in an altercation. Those people are not users of the app, have no account, and have not agreed to anything on this page. Their image and voice end up in the recording all the same, and that recording is held by the agency and can be viewed by the people listed under “Who can see what”. Anyone who believes they appear in a recording should contact the agency whose guard made it.

The app does nothing to identify the people in a recording. There is no face detection, no face recognition, and no automated analysis of the footage. A recording is a video file and nothing more.

Who can see what

Agency administrators and supervisors
Everything: every guard’s live location and patrol history, every body-cam stream and clip, all incident reports, messages and checkpoint scans, and all account details.
Clients
Only what happened at their own sites: the guard’s live location while on an active shift there, the patrol history for that site, incident reports and daily activity reports for that site, and body-cam footage recorded at that property. Guards should understand this plainly: while you are working at a client’s site, your location trace and any body-cam footage you record there are visible to that client, who is your agency’s customer and not your employer.
Guards
Their own data. A guard cannot see another guard’s location, body-cam feed or recordings.

How long data is kept

These are the retention periods the server is configured with. They apply on the agency’s server, which the agency controls.

Live-streamed body-cam recordings
7 days.
Uploaded full-quality body-cam clips
30 days.
GPS tracks, full resolution
90 days.
GPS tracks, reduced resolution
After 90 days the track is thinned to fewer points and kept in that reduced form until it is 2 years old, then deleted.
Voice message clips
The same window as patrol tracks.
Login session
A sign-in lasts 12 hours, after which you sign in again.
Incident reports and their attachments
These are business records and are kept by the agency for as long as it keeps its other records. They are not deleted on a timer.
Account details
Kept while the account exists. When an account is deactivated, its details stay with the agency’s employment records rather than being deleted.

Permissions and what they are for

Android and iPhone name and group these differently, but the reasons are the same. Items marked “Android only” have no equivalent on iPhone.

Location (precise and approximate)
Shift tracking, as described above, and the geofence check at clock-in. On Android the app asks for location while in use only and does not request background location. On iPhone the app needs location to keep working while the screen is off during a shift; it still only uses location between clock-in and clock-out.
Camera
The body cam, photos and video for incident reports, and scanning QR checkpoint codes.
Microphone
Body-cam audio, hold-to-talk voice messages, and audio attachments on incident reports. The microphone is only live while one of those is in progress.
NFC
Tapping the phone on an NFC checkpoint tag to record a scan.
Notifications
Shift alerts, messages from staff, and lone-worker check-in prompts. Also the persistent notification that shows while shift tracking or the body cam is running.
Foreground service (location, camera, microphone) — Android only
Lets shift tracking and body-cam recording keep running while the screen is off or you are in another app. This is what puts the persistent notification on screen.
Ignore battery optimizations — Android only
Stops Android from killing location tracking partway through a long shift to save power. Without this, tracks develop gaps.
Vibrate — Android only
Haptic feedback for alerts and successful scans.
Internet and network state
Talking to your agency’s server, and noticing when the connection drops so buffered data can be sent when it returns.

Third-party services

Google Firebase Cloud Messaging
Delivers push notifications. Google issues a token for your phone and relays the notifications through its service; on iPhone, Firebase hands them to Apple’s push service for the last step. The notification payloads are kept minimal; the content itself lives on the agency’s server.
Map imagery
Maps in the app use public-domain aerial photography from the US Department of Agriculture’s NAIP program, served by the USGS National Map. There is no commercial mapping provider, and no location data is sent to any map vendor — the app only fetches image tiles.
The Fitz Systems organization-code directory
The first time the app runs, it asks for your organization code and looks it up at fitz-systems.com to find your agency’s server address. That lookup carries the code and nothing else — not your name, login or location — and the directory does not keep a record of who looked up which code.

Everything else the app does, it does against your agency’s own server.

Recording laws vary by state

The app can be downloaded anywhere in the United States, and the rules on recording audio and video are different from state to state. Some states require only one party to a conversation to consent to recording; others require everyone. Some states also have their own rules on notifying employees about workplace monitoring.

Each agency is responsible for complying with the law where it operates, and for telling its staff how the app is used. Fitz Systems does not decide when the body cam is used, and nothing on this page should be read as a statement that any particular recording is lawful.

Deleting your data

There is no delete-my-account button in the app. Your account was issued by your employer, and the records the app produces — shift tracks, incident reports, recordings — are your employer’s business records, which an employee cannot remove on their own.

To request deletion, ask your agency. Its administrators can deactivate your account so it can no longer sign in. Because a guard’s shifts, hours and reports are employment and payroll records, an agency will generally keep them after an account is deactivated, for as long as employment, tax and other laws require, rather than delete them. Location tracks, body-cam footage and voice clips still expire on the schedule under “How long data is kept”. Clients should likewise ask the agency that gave them their login.

For questions about the app itself — what it collects, how it works, or this policy — contact Fitz Systems at the address below. We can explain how the app behaves, but we cannot delete data from a server we do not operate, and we cannot discuss an account with anyone but the agency that owns it.

Data stored on your device

The app keeps your login session, buffered positions waiting to upload, body-cam clips waiting to upload, and its settings in its own private storage on the phone. Other apps cannot read it, on either platform. Uninstalling GDF Connect removes all of it from the phone; it does not remove anything already sent to the agency’s server.

Children

GDF Connect is an employment tool for licensed security staff and their agencies. It is for adults only. Accounts are created by an agency administrator, and we do not knowingly collect information from anyone under 18.

Changes to this policy

If this policy changes, the updated version will be posted at this address with a new date at the top. Material changes will also be noted in the app’s store listings.

Contact

Questions about this policy or about the app: dev@fitz-systems.com

For anything about your own account or your own data, start with your agency — it holds the data, and we can only discuss an account with the agency that owns it.

Fitz Systems LLC · Cave Creek, Arizona, United States