Device Intelligence
How ZeroTrace AirLeak identifies the Bluetooth-LE devices, ecosystems and beacons around you.
A raw Bluetooth scan is just a list of addresses and numbers. AirLeak's job is to turn that into something you can actually read: this is an AirPods case, that is a Samsung SmartTag with its owner, those three are environmental sensors. It does that with a dedicated decoder for each ecosystem's advertising format, run against every advertisement AirLeak hears.
What it recognizes, by ecosystem
What it detects: Apple's Continuity protocol family, everything an iPhone, iPad, AirPods case or Find My accessory broadcasts over BLE.
What it identifies: Find My accessories and AirTags; AirPods, including case-lid open/closed and battery state; the "Nearby" continuity signals iOS devices constantly emit; other Apple accessory advertisements.
Privacy-relevant fields surfaced: Find My owner vs. separated state; AirPods lid and charge state; whether a nearby Apple device is showing itself as unlocked or on a call, a field Apple's Nearby signal exposes and AirLeak reads directly.
What it detects: Samsung's SmartTag advertising format.
What it identifies: SmartTag and SmartTag+ item finders.
Privacy-relevant fields surfaced: owner vs. separated state, read directly from the tag's broadcast, the same field that drives the smarttag_separated follow-me rule.
What it detects: Google Fast Pair accessory advertisements, and the Find My Device network (FMDN) beacon format carried over Eddystone.
What it identifies: Fast Pair headphones and accessories offering a pairing prompt; FMDN trackers, Android's answer to AirTag, identified as a tracker type even though FMDN rotates its identity for privacy.
Privacy-relevant fields surfaced: Fast Pair model identity where advertised; FMDN presence and tracker classification (rotating key, so no owner-level identity is exposed, by design of the protocol itself).
What it detects: Microsoft Swift Pair advertisements.
What it identifies: accessories offering themselves for quick pairing with a nearby Windows machine.
Privacy-relevant fields surfaced: device name and pairing-prompt metadata as broadcast; no persistent owner identity is exposed by the format.
What it detects: the four advertising formats behind almost every consumer item tracker: Tile, Chipolo, Samsung SmartTag and Google FMDN.
What it identifies: the tracker brand and, for Tile, Chipolo and SmartTag, a stable-enough signal to link repeated sightings to the same physical tag over time. Apple Find My and Google FMDN use rotating keys by design, so AirLeak labels them as trackers of that type without a persistent per-tag identity.
Privacy-relevant fields surfaced: tracker brand/type; owner/separated state where the format exposes it (SmartTag, Find My); a link confidence for whether repeated sightings are the same physical tag. Tracker identity always takes priority over any other classification, see Tracker detection.
What it detects: the open and semi-open beacon formats used by asset tags, environmental sensors and DIY/smart-home hardware, Eddystone, AltBeacon, RuuviTag, Xiaomi/Mi (MiBeacon and the common ATC custom-firmware variant), BTHome, plus exposure-notification and generic smart-home beacon layouts.
What it identifies: the beacon standard in use, and, for the sensor formats, the type of sensor (temperature/humidity, asset tag, proximity beacon).
Privacy-relevant fields surfaced: whatever the device broadcasts in the clear, commonly a beacon namespace/instance ID or the current sensor reading, this is public information by design of these formats, not something AirLeak extracts.
Naming, not guessing
For each device it hears, AirLeak layers up what it knows, the manufacturer that owns the signal, the kind of accessory it is, and any state the device chooses to broadcast, into a single readable identity in the app. Where a device advertises live state (an AirPods lid opening, a SmartTag that has been separated from its owner), AirLeak surfaces that too, so the entry is not just a name but a small live status.
Anything that does not match a known ecosystem or beacon format still gets a best-effort generic label built from what the advertisement contains, a manufacturer looked up from its Bluetooth company ID, a device type from its GATT appearance value, rather than being dropped or shown as a bare address.
Handling privacy addresses
Most current phones and many accessories rotate the Bluetooth address they broadcast every few minutes, on purpose, so they cannot be trailed by that address. AirLeak is built around this. Instead of trusting the address alone, it recognizes a device by the pattern of how it advertises, and stitches together the rotating addresses that clearly belong to the same device, cross-checking the device's private resolvable address where the protocol allows it. The practical result: a phone that changes its address every fifteen minutes shows up as one device you can follow over time, not a crowd of momentary strangers.
For how AirLeak specifically singles out item trackers, and why that gets special treatment, see Tracker detection.