PRIVACY POLICY

Your home stays home.Here is the rest.

Effective 22 September 2026. HA TV Dashboard is free, has no account and keeps no database of its users. This policy sets out the small amount of data that does leave your device, where it goes, and how to stop it.

The trust page covers the same ground in more practical detail, including what the app can do in your house and what has not been proven.

Who this applies to

This policy covers the HA TV Dashboard app for Android TV and Google TV, published on Google Play by Android Alliance.

The short version: the app is a companion to a Home Assistant instance you already run. Everything about your home stays between your TV and that instance. The only data that leaves your network is about the app itself: whether it crashed, and which of its features get used. The second of those can be switched off at Settings → App Config → Options → Allow analytics.

Your Home Assistant data

Entity names and states, camera feeds, dashboards, automations, calendar entries, weather and transit overlays — all of this is read from your Home Assistant instance and displayed on your TV.

None of it is sent anywhere else. There is no HA TV Dashboard server and no account. The app connects to your instance directly, over your own network or over an HTTPS address you provide.

There is no infrastructure on our side that could receive your home data.

Signing in

You are never asked to paste a Long-Lived Access Token, and the app never sees your Home Assistant password. Signing in opens Home Assistant's own login page, and Home Assistant returns a token once you have authenticated with it. This is the flow the official Home Assistant companion apps use.

  • A refresh token is stored on the device, so you are not signing in every time the TV wakes. It is exchanged for short-lived access tokens while you use the app.
  • The token is held on the device only. It is never sent to us.
  • You can revoke it at any time from Home Assistant, under Settings → People → your user → Security. Revoking signs the TV out immediately.

What the app does send

Two categories, both about the app rather than about you or your home, and both handled by Firebase, a Google service.

Crash reports always on

When the app crashes, Firebase Crashlytics records:

  • the stack trace: where in the app's own code the failure happened;
  • device model, Android version and app version;
  • a Crashlytics installation identifier, and the time of the crash.

It carries no entity names, no camera images or streams, no tokens, no dashboard contents and no Home Assistant address.

Purpose: fixing crashes. That includes ones that only happen on one make of TV box.

Usage analytics you can turn this off

Counts of which screens and features are opened, together with an app-instance identifier, and an approximate region derived from your IP address by Google. That identifier belongs to this app alone. It is not the Android Advertising ID and cannot be used to follow you elsewhere. Individual events are not tied to a name or an email address, because the app never asks for either.

Turn analytics off at Settings → App Config → Options → Allow analytics. It is on by default. Crash reporting cannot be turned off.

Purpose: deciding what to build next.

Google Play Services is also present, as it is in essentially every Android app, and handles installation, updates and platform functions under Google's own terms.

What the app does not do

  • No account. There is nothing to sign up for, so there is no name, email address or password on our side.
  • No advertising, and no advertising ID. The app carries no advertising of any kind. Collection of the Android Advertising ID is disabled, and nothing tracks you across other apps or sites.
  • No selling or sharing of data with data brokers or advertisers. The app is free and funded by voluntary support, so there is no revenue model that would involve it.
  • No precise location. The app does not request location permission. The approximate region Firebase derives from an IP address is the only geographic signal involved.
  • No marketing email. We have no address to send it to.
  • No screen reading. The optional Accessibility Service reads D-pad and hardware key events so a remote button can trigger an action. It does not read screen content.

Your choices

  • Turn analytics off at Settings → App Config → Options → Allow analytics. It is on by default, and crash reporting continues.
  • Revoke the TV's access to Home Assistant at any time, from Home Assistant. Consider giving the TV its own Home Assistant user with Local access only enabled, since the TV does not leave the house.
  • Decline the permissions. Both are optional in practice. Without overlay permission the popups and sidebar cannot draw; without the Accessibility Service, remote key actions do not work. Everything else still functions.
  • Uninstall. This ends all collection. Data already sent to Firebase is subject to Google's retention.
  • Ask. Email tv.dash@androidalliance.co.uk with any request about data the app has sent, and it will be answered.

Third parties and where data goes

Firebase is operated by Google, and data sent to it is processed on Google's infrastructure, which includes servers outside the United Kingdom and the European Economic Area. Google's own terms govern that processing.

Your Home Assistant instance is not a third party in this sense. It is your own server.

Retention

We hold no database of users, so there is nothing for us to retain. Crash reports and analytics events are retained by Google under Firebase's own retention settings and deleted on their schedule.

The token on your TV persists until you revoke it in Home Assistant, clear the app's data, or uninstall.

Children

The app is not directed at children under 13 and does not knowingly collect personal information from them. It requires a Home Assistant instance to be useful at all, which makes it an unlikely thing for a child to set up alone.

If you believe a child's information has been collected, email tv.dash@androidalliance.co.uk and it will be removed.

Security

  • On your own network, Home Assistant is commonly served over plain http:// and the app will connect that way. Traffic on your LAN is then unencrypted, as it is for any Home Assistant client in that setup, including a browser.
  • Remotely, the app requires https:// with a valid certificate. Self-signed certificates are refused.
  • Camera feeds follow whatever your camera or proxy provides.
  • Physical access is the real boundary. Anyone holding the remote can use whatever the app exposes; choosing which entity categories appear is the control you have.

No system is perfectly secure, and the app has not been independently audited. The trust page sets out the limits in more detail.

Changes to this policy

This policy will change as the app does. Material changes will be reflected here with a new effective date, and significant ones noted in the release notes.

Effective 22 September 2026. This replaces the previous policy dated 1 August 2024, which was a generic template and described collection and contact practices that did not match the app.

Contact

Questions about this policy, or about anything the app does with data: