v0.5.15 · Android · passive

OVERWATCH

A native Android app that passively detects surveillance around you. Open it, hit START, and a ring turns green → yellow → orange → red as the engine gets more sure there's a Flock Safety ALPR, an Axon body camera, or active police nearby. It only listens. It never transmits, probes, or jams.

OVERWATCH main screen: a live map inside a green "all clear" threat ring, centered on the user with a crosshair, and a STOP button.
0fused sources
0threat tiers
0packets sent
0releases

Passive defense only. Debug-signed APK — sideload; no Play Store. Read the README.

Fuses signal from
  • Bluetooth-LE + WiFi radio
  • DeFlock ALPR map
  • Waze police alerts
  • ADS-B aircraft
  • OpenStreetMap · Overpass

One tap. A live threat map.

While scanning, the circle becomes an OpenStreetMap centered on you, wrapped in a threat-color ring for the current tier and marked with a ⌖ crosshair. Every detection is a dot, color-coded by source — so each mark is self-explanatory. Lock the screen and the foreground notification keeps the tier live; the phone vibrates only when the threat escalates.

Detection-sources drill-down: BLE, WiFi, DeFlock, Waze and Commercial rows, each with a color tier dot and the observations that fired it.
1
Threat-color ring

The map is wrapped in the current tier's color — green, yellow, orange, or red — so you read your situation at a glance without opening anything.

2
Source-color dots

Flock / DeFlock cameras red · Waze police blue · aircraft violet · user position as a ⌖ crosshair. Tap any row for coordinates + a Maps deep-link.

3
Foreground notification

Rebuilt on every tier change — OVERWATCH • RED with the top detection's score. Priority bumps to HIGH on RED so the system surfaces it as a heads-up, screen locked or not.

4
Escalation-only haptics

A short pulse for YELLOW, double for ORANGE, escalating triple for RED — but only on upward transitions, so it never nags you while a threat lingers.

Six sensors, one score.

Every observation is scored 0–100 by the confidence engine; the on-screen tier is the max live score across all sources. Cross-source corroboration — a BLE hit and a DeFlock map match in the same spot — naturally pushes the tier higher than either alone.

📶

BLE — Bluetooth-LE

Vendor MAC OUIs (Axon, Flock Penguin / Raven, XUNTONG mfg id 0x09C8, "TN" serial pattern), Raven service UUIDs, and device-name patterns — plus 18 IEEE-verified vendor OUIs: ShotSpotter, WatchGuard, Verkada, Avigilon Alta readers, Axis body cams, FLIR and more, with police-exclusive vendors scoring ORANGE on sight. Iterates every manufacturer-data entry per advert — not just the first — so it doesn't miss a buried match.

✈️

Aircraft — eyes above

Police and surveillance aircraft overhead, from the free community ADS-B networks — used specifically because the commercial trackers filter law-enforcement flights at government request. Contacts are matched by ICAO address against a bundled registry of 1,971 US law-enforcement airframes, and scored by distance, altitude and orbit behaviour — because surveillance aircraft circle, and airliners don't. An unlisted aircraft loitering low and slow overhead still registers.

📡

WiFi

BSSID OUI prefixes for Flock infrastructure (31-prefix superset), the same 18 surveillance-vendor OUIs (WatchGuard in-car APs, Alta readers, WiFi cameras), and Flock-XXXX SSID patterns, polled every 35 s — just under the Android 11+ scan throttle.

🎥

DeFlock — ALPR map

Crowdsourced ALPR camera locations within range (200 m default) via the Overpass API (overpass.deflock.org → fallback overpass-api.de), with a 24 h on-disk cache and failure backoff. Refetches when you move > 1.5 km.

🚓

Waze — police alerts

Live user-reported POLICE alerts (default 500 m, ~45 min freshness). Waze's public map endpoint now 403s automated clients at Google's edge, so OVERWATCH offers two ways in and lets you choose. OpenWeb Ninja (default) reads their hosted feed at api.openwebninja.com using your own API key, pasted into Settings and stored encrypted in the Android Keystore — Waze never sees you, and each install bills to its own account (~$1–3/month). Direct speaks Waze's own app protocol over an anonymous account: free, keyless and live, but it sends a blurred position to a Google service on every poll, so it stays off until you turn it on. Nothing ships in the APK either way.

🏠

Commercial

Nearby consumer smart-home gear (Nest, Ring, Echo, Sonos, hidden cams) and camera-bearing smart glasses — Meta Ray-Ban / Oakley, Snap Spectacles, Vuzix, and HeyCyan-SDK frames like the Nilox Smart AI Glasses — as a secondary situational signal riding the BLE + WiFi scans. Glasses identifiers credit Nearby Glasses by Yves Jeanrenaud. Score-capped at ORANGE so a cluster of doorbells never reads as ALPR-grade certainty.

Four tiers. Highest live score wins.

< 40
GREEN

Nothing credible. Idle shows a muted gray ring so "all clear" reads differently from "not scanning."

40 – 69
YELLOW

A single weak indicator. Short vibration pulse on the way up.

70 – 84
ORANGE

High confidence — usually a hard radio hit or a close map match. Double pulse.

85 +
RED

Certain. Notification jumps to HIGH priority; escalating triple pulse.

The whole app, top to bottom.

No account, no onboarding, no cloud dashboard to configure — open it, hit START, and drill into any source. Three taps deep is as complex as it gets.

OVERWATCH main screen: a live map inside a green all-clear threat ring, centered on you with a crosshair, and a STOP button.
The threat ringA live map centered on you, wrapped in the current tier's color. Green reads “all clear” at a glance.
Detection-sources drill-down: BLE, WiFi, DeFlock, Waze and Commercial rows, each with a color tier dot and the observations that fired it.
Source drill-downTap the ring for every source, its live tier, and the exact observation that fired it.
Settings screen: per-source toggles and the encrypted Waze API key field.
SettingsToggle each source, tune proximity distances, and paste your own encrypted Waze API key.

Runs in your pocket, not the cloud.

🔇

Passive by design

OVERWATCH only listens — it never transmits, probes, jams, or interferes with any device or network. The Axon advertise/fuzz code from one of the reference projects is intentionally excluded. It reads the airwaves and public feeds; that's it.

🫧

Floating overlay

The same threat-ring map renders in a small draggable bubble over other apps (Settings → Display over other apps), so it stays with you while you use your phone.

🔐

Bring your own key

The Waze feed uses your OpenWeb Ninja key, encrypted via the Android Keystore and sent only to that one host. No shared credential, no secrets in the APK — and revoking it is your call.

🩺

Honest per-source health

The drill-down marks a source Source unreachable when its scanner couldn't reach its feed — a silent empty result and a real failure look different.

🗺

Your position, not your data

Location drives the proximity checks and the map on-device. No account, no telemetry, no analytics — the scans and feeds run and the results stay on your phone.

🛡

Situational awareness, not interference

OVERWATCH is a defensive, receive-only tool for knowing what's watching you — Flock ALPRs, Axon body cameras, and police presence — in the space you're already in. It does not touch, spoof, or disrupt anything. Know your local laws; use it responsibly.

Sideload in three steps.

Settings screen: per-source toggles (BLE, WiFi, DeFlock, Waze, Aircraft, Commercial) and the encrypted Waze API key field.
1 · download
  • Grab the latest debug-signed APK from Releases (currently v0.5.15).
2 · install
  • Sideload it — allow "install unknown apps" for your browser or files app, then open the APK.
3 · grant + start
  • Grant location + nearby-devices + notifications, toggle the sources you want, hit START.
  • Optional: paste your own OpenWeb Ninja API key in Settings for Waze police-report coverage.

Build from source, file issues, or read the internals: github.com/KaraZajac/OVERWATCH