What this app can see,and what it can't.
HA TV Dashboard runs in your living room, connects to your house and asks for two permissions most apps never need. This page sets out what that means, including the limits.
What it connects to
There is no HA TV Dashboard server and no account. The app talks to your Home Assistant instance directly.
Over the life of a session the app opens connections to:
- Your Home Assistant instance: a WebSocket for live state and the REST API for actions. This is the only connection that carries anything about your home.
- Your cameras: directly, or through whatever already proxies them for Home Assistant, such as go2rtc.
- Google Play: for installing and updating the app, exactly as with any other app on the device.
- Firebase: crash reports, and usage analytics you can switch off in the app. Nothing about your home goes here. Detail below.
That is the whole list. Entities, camera feeds, dashboards and tokens go between the TV and your Home Assistant and nowhere else.
How signing in works
You never paste a Long-Lived Access Token into this app, and the app never sees your password. Signing in opens Home Assistant's own login page, and Home Assistant hands back a token once you have authenticated with it. This is the same flow the official Home Assistant companion apps use.
What is kept on the device:
- Your password is never handled by the app. It goes to Home Assistant's login page and nowhere else.
- A refresh token is held on the device, otherwise you would sign in every time the TV wakes. It is exchanged for short-lived access tokens as you use the app.
- You can revoke it at any time from Home Assistant, under Settings → People → your user → Security. Revoking it signs the TV out immediately.
Because the TV never leaves the house, consider a dedicated Home Assistant user for it, such as Television, with Local access only switched on. The TV then shows up separately from you in the logbook, and you can revoke it without signing yourself out.
What it can do in your house
HA TV Dashboard does not impose its own list of what may and may not be controlled. It can act on what your Home Assistant user can act on. Home Control shows lights, switches, climate, media players, cameras and person tracking, and an automation triggered from the TV can do anything that automation is allowed to do.
That is deliberate, and it makes the real security question who can pick up the remote. A TV lives in a shared room, and guests, children and anyone else in it can reach whatever the app exposes.
Two settings limit that:
- Choose what appears. Home Control lets you pick which entity categories are visible in the panel. Anything you leave out is not reachable from the sofa.
- Scope the user. The TV signs in as a Home Assistant user, so that user's permissions are the ceiling. A dedicated user is the cleanest way to draw the line.
If your setup includes locks, garage doors or an alarm and you would rather they were not one D-pad press away, leave those categories out of the panel.
The two permissions it asks for
Display over other apps
This is what draws the camera popups, the Home Control sidebar and notification banners on top of whatever is playing. Without it the app still runs, but nothing can appear over another app.
It is used to draw, not to read. No content from other apps is captured or inspected.
Accessibility Service optional
Android TV gives an app no other way to notice remote-control key presses while it is in the background. The service exists solely so a button on your remote can open Home Control or fire an action.
It never touches screen content. It reads D-pad and hardware key events only. It cannot see what is on screen or what you type.
If you do not use remote key actions, leave it off. Everything else keeps working.
Crash reports and analytics
The app sends two kinds of data about itself to Firebase, a Google service. Neither contains anything about your home.
Crash reports
When the app crashes, Crashlytics records the stack trace along with the device model, Android version and app version. That is how a crash on one make of TV box gets found and fixed.
Crash reports contain no entity names, camera feeds, tokens or dashboard contents.
Usage analytics you can turn this off
Counts of which screens and features get used, which decide where development time goes. An app-instance identifier is attached. The Android Advertising ID is not collected.
Turn it off at Settings → App Config → Options → Allow analytics. It is on by default. Crash reporting cannot be turned off.
Firebase is the only third party the app itself sends anything to.
Connections and encryption
- On your own network, Home Assistant is commonly served over plain
http://, and the app will connect that way. Traffic on your LAN is then unencrypted, as it is for every Home Assistant client in that setup, including a browser. - Remotely, the app requires
https://with a valid certificate. Self-signed certificates are refused. - Camera feeds follow whatever your camera or proxy provides. An RTSP feed on your LAN is usually unencrypted; that is a property of the camera, not of this app.
What Google Play says
The store listing carries a data safety section and a link to the privacy policy. The policy was updated on 22 September 2026. The data safety section still needs updating to declare crash reporting and analytics, and is being corrected with the next release.
Until then, treat this page and the privacy policy as the accurate description of what the app sends and where.
Why the app is closed source
The wiki, the blueprints, the issue tracker and the changelog are all public. The app's own source is not.
Small open-source apps get cloned. The pattern is well worn: someone takes the code, adds one feature, puts a price on it, and the original author is left maintaining the free version of their own work. Keeping the source closed is what lets every feature stay free and the project still be here next year.
You already rely on software that made the same call. Nabu Casa, which funds Home Assistant itself, is not open source. Neither is Philips Hue, or most of the ecosystem around it. Closed source is not the same as untrustworthy, but it does limit what you can check for yourself.
Closed source asks you to take something on trust. This page is the other half of that bargain: what the app connects to, what it can do in your house, and what has not been proven yet. The issue tracker, the changelog and the privacy policy are all public, and the claims here are specific enough to be wrong in public if they ever stop being true.
What isn't proven yet
These are the limits of what this page can promise.
- No independent security audit. Nobody outside the project has reviewed the code. There is no third-party report to point you at.
- You cannot verify the permission claims yourself. The statements above about the Accessibility Service and the overlay are accurate, but with the source closed you are taking them on trust.
- Local traffic is unencrypted when Home Assistant is served over plain HTTP on your network, as it usually is.
- Physical access is the real boundary. Anyone holding the remote can use whatever Home Control exposes. Choosing which categories appear is the control you have; there is no separate PIN on the panel.
If something here is out of date, please report it like any other bug.
Reporting something
Bugs, questions and feature requests are handled in the open:
For a security issue, or anything you would rather not raise in public, use a private channel instead so it can be fixed before it is visible.
Email goes straight to the developer, for sensitive issues or anything else.