The short version
GDF Connect is a workforce app for security guard agencies. It is an employee monitoring tool: while a guard is clocked in to a shift it records their location continuously, and it lets the guard record body-cam video when they choose to. On Android, Google Play may warn you about this when you install it. That warning is accurate, and this page is the explanation it points to.
Nobody signs up for GDF Connect on their own. Your agency’s administrator creates your account, and your agency runs the server that holds your data. Fitz Systems LLC writes and publishes the app but does not operate a central database of guard locations or recordings.
The app has no advertising, no analytics, no crash reporting and no third-party trackers. It does not track anyone who is not clocked in. It does no face recognition and no automated analysis of footage. Nothing is sold or shared for advertising, ever.
Who runs what
Two different parties are involved, and it matters which one you are dealing with.
- Your agency
- Runs its own server. Everything the app collects is sent to that server and is held there, under the agency’s control. The agency decides who gets an account, what its staff are told, and how its records are handled. For anything about your data — seeing it, correcting it, or deleting it — the agency is the one to ask.
- Fitz Systems LLC
- Writes and publishes the app. We do not have access to any agency’s server and we do not receive the locations, recordings, reports or messages the app produces. The one thing the app sends to us is described under “Third-party services” below: a one-time lookup of your organization code so the app can find your agency’s server.
Data we collect
The app has two kinds of user, and the app treats them very differently.
From guards
If you are a guard, the app collects the following and sends it to your agency’s server:
- Your precise location, continuously, while you are clocked in. The app samples your position about every 25 seconds and uploads it about every 60 seconds. If you have no signal, positions are buffered on the phone and sent when the connection returns. See “Location tracking” below.
- Body-cam video and audio, only when you press START, and only until you press STOP. See “Body-cam recording” below.
- Incident reports you write, with any photos, video or audio you attach to them.
- Messages between you and your agency’s staff, and with the clients of the sites you work: text messages and hold-to-talk voice messages.
- Checkpoint scans. Each QR or NFC checkpoint you scan is recorded with the time and your location at that moment.
- Account and employment details: your name, username, email address, phone number, role, and pay rate. Your agency enters these when it creates your account.
- A push notification token for your phone, issued by Google Firebase, so the server can send you shift alerts and messages.
From clients
If you are a client — a property owner or manager who logs in to see what is happening at your own sites — the app holds your account details (name, email address and phone number), any messages you send to the agency or its guards, any map markers you place on your own properties, and a push notification token for your phone. Clients are not location-tracked and are not recorded.
What the app does not collect
- No advertising identifier, no ad networks, no ad SDKs.
- No analytics SDK, no crash-reporting SDK, no third-party trackers of any kind.
- No location when you are not clocked in. On Android the app does not even hold the “background location” permission, so it cannot track you off shift. On iPhone, tracking likewise starts at clock-in and stops at clock-out.
- No face recognition, no biometric identification, and no automated or AI analysis of any footage.
- Nothing is sold, and nothing is shared with anyone for advertising.
Location tracking
When you clock in, the app starts following your position and keeps doing so for the length of the shift, including while the screen is off. On Android this runs as a foreground service with a persistent notification the whole time, so you can always see that tracking is on. On iPhone, the system shows its own location indicator while the app is using your location. When you clock out, tracking stops and no further positions are taken.
Your location is also used at clock-in itself: a site can have a geofence, and the app checks that you are inside it before it lets you clock in there.
Your track is visible to your agency’s administrators and supervisors, and — while you are on an active shift at a client’s site — to that client. See “Who can see what”.
Body-cam recording
The body cam is not always on. It records only when you press START, and it stops when you press STOP. It is meant for a specific incident or altercation, and a recording is typically a few minutes long. Nothing records automatically, and the app does not switch the camera on by itself.
While it is recording, the video and audio stream live to your agency’s server so a supervisor can watch. A local copy is also saved on the phone and uploaded afterward, so the agency gets a full-quality clip even if the live connection was poor.
People who are not users
A body-cam recording captures whoever is present — members of the public, visitors, the other party in an altercation. Those people are not users of the app, have no account, and have not agreed to anything on this page. Their image and voice end up in the recording all the same, and that recording is held by the agency and can be viewed by the people listed under “Who can see what”. Anyone who believes they appear in a recording should contact the agency whose guard made it.
The app does nothing to identify the people in a recording. There is no face detection, no face recognition, and no automated analysis of the footage. A recording is a video file and nothing more.
Who can see what
- Agency administrators and supervisors
- Everything: every guard’s live location and patrol history, every body-cam stream and clip, all incident reports, messages and checkpoint scans, and all account details.
- Clients
- Only what happened at their own sites: the guard’s live location while on an active shift there, the patrol history for that site, incident reports and daily activity reports for that site, and body-cam footage recorded at that property. Guards should understand this plainly: while you are working at a client’s site, your location trace and any body-cam footage you record there are visible to that client, who is your agency’s customer and not your employer.
- Guards
- Their own data. A guard cannot see another guard’s location, body-cam feed or recordings.
How long data is kept
These are the retention periods the server is configured with. They apply on the agency’s server, which the agency controls.
- Live-streamed body-cam recordings
- 7 days.
- Uploaded full-quality body-cam clips
- 30 days.
- GPS tracks, full resolution
- 90 days.
- GPS tracks, reduced resolution
- After 90 days the track is thinned to fewer points and kept in that reduced form until it is 2 years old, then deleted.
- Voice message clips
- The same window as patrol tracks.
- Login session
- A sign-in lasts 12 hours, after which you sign in again.
- Incident reports and their attachments
- These are business records and are kept by the agency for as long as it keeps its other records. They are not deleted on a timer.
- Account details
- Kept while the account exists. When an account is deactivated, its details stay with the agency’s employment records rather than being deleted.
Permissions and what they are for
Android and iPhone name and group these differently, but the reasons are the same. Items marked “Android only” have no equivalent on iPhone.
- Location (precise and approximate)
- Shift tracking, as described above, and the geofence check at clock-in. On Android the app asks for location while in use only and does not request background location. On iPhone the app needs location to keep working while the screen is off during a shift; it still only uses location between clock-in and clock-out.
- Camera
- The body cam, photos and video for incident reports, and scanning QR checkpoint codes.
- Microphone
- Body-cam audio, hold-to-talk voice messages, and audio attachments on incident reports. The microphone is only live while one of those is in progress.
- NFC
- Tapping the phone on an NFC checkpoint tag to record a scan.
- Notifications
- Shift alerts, messages from staff, and lone-worker check-in prompts. Also the persistent notification that shows while shift tracking or the body cam is running.
- Foreground service (location, camera, microphone) — Android only
- Lets shift tracking and body-cam recording keep running while the screen is off or you are in another app. This is what puts the persistent notification on screen.
- Ignore battery optimizations — Android only
- Stops Android from killing location tracking partway through a long shift to save power. Without this, tracks develop gaps.
- Vibrate — Android only
- Haptic feedback for alerts and successful scans.
- Internet and network state
- Talking to your agency’s server, and noticing when the connection drops so buffered data can be sent when it returns.
Third-party services
- Google Firebase Cloud Messaging
- Delivers push notifications. Google issues a token for your phone and relays the notifications through its service; on iPhone, Firebase hands them to Apple’s push service for the last step. The notification payloads are kept minimal; the content itself lives on the agency’s server.
- Map imagery
- Maps in the app use public-domain aerial photography from the US Department of Agriculture’s NAIP program, served by the USGS National Map. There is no commercial mapping provider, and no location data is sent to any map vendor — the app only fetches image tiles.
- The Fitz Systems organization-code directory
- The first time the app runs, it asks for your organization code and looks it up at fitz-systems.com to find your agency’s server address. That lookup carries the code and nothing else — not your name, login or location — and the directory does not keep a record of who looked up which code.
Everything else the app does, it does against your agency’s own server.
Recording laws vary by state
The app can be downloaded anywhere in the United States, and the rules on recording audio and video are different from state to state. Some states require only one party to a conversation to consent to recording; others require everyone. Some states also have their own rules on notifying employees about workplace monitoring.
Each agency is responsible for complying with the law where it operates, and for telling its staff how the app is used. Fitz Systems does not decide when the body cam is used, and nothing on this page should be read as a statement that any particular recording is lawful.
Deleting your data
There is no delete-my-account button in the app. Your account was issued by your employer, and the records the app produces — shift tracks, incident reports, recordings — are your employer’s business records, which an employee cannot remove on their own.
To request deletion, ask your agency. Its administrators can deactivate your account so it can no longer sign in. Because a guard’s shifts, hours and reports are employment and payroll records, an agency will generally keep them after an account is deactivated, for as long as employment, tax and other laws require, rather than delete them. Location tracks, body-cam footage and voice clips still expire on the schedule under “How long data is kept”. Clients should likewise ask the agency that gave them their login.
For questions about the app itself — what it collects, how it works, or this policy — contact Fitz Systems at the address below. We can explain how the app behaves, but we cannot delete data from a server we do not operate, and we cannot discuss an account with anyone but the agency that owns it.
Data stored on your device
The app keeps your login session, buffered positions waiting to upload, body-cam clips waiting to upload, and its settings in its own private storage on the phone. Other apps cannot read it, on either platform. Uninstalling GDF Connect removes all of it from the phone; it does not remove anything already sent to the agency’s server.
Children
GDF Connect is an employment tool for licensed security staff and their agencies. It is for adults only. Accounts are created by an agency administrator, and we do not knowingly collect information from anyone under 18.
Changes to this policy
If this policy changes, the updated version will be posted at this address with a new date at the top. Material changes will also be noted in the app’s store listings.
Contact
Questions about this policy or about the app: dev@fitz-systems.com
For anything about your own account or your own data, start with your agency — it holds the data, and we can only discuss an account with the agency that owns it.
Fitz Systems LLC · Cave Creek, Arizona, United States