Privacy policy
HomePanel MR has no developer-operated account, analytics service, advertising service or cloud relay. It communicates directly with the Home Assistant server you select. Meta platform services, the public website and support email have separate processing described below.
1. Home Assistant connection and device information
The app processes your Home Assistant server address, authentication tokens, device and entity names, areas, supported actions and current states so that it can display and control your devices. Commands you choose are sent to your selected Home Assistant server. We do not receive a copy on a developer server.
Browser sign-in takes place on your Home Assistant server. HomePanel MR receives an authorization result and exchanges it for tokens. When you choose to remember the connection, tokens are encrypted in private app storage using an Android Keystore key. The server address and app preferences are stored locally. If you do not remember the connection, credentials are kept for the active session. Device states may reveal information about your home; your Home Assistant server and its integrations govern their own storage and onward processing.
The app can discover Home Assistant servers on your local network when you use discovery. HTTPS certificate validation is enabled. If you choose a local HTTP server, traffic to that server is not encrypted in transit; use it only on a trusted private network.
2. Room data, hand input and passthrough
With permission, HomePanel MR uses the room model and spatial anchors provided by Meta's operating system to place device controls. The app saves room and anchor identifiers, relative positions, orientation, sizes, device/entity identifiers and your labels in its private local storage. It processes head, hand and controller input to aim and interact. The app does not record motion histories, access raw camera images, record room video or upload room models or placements to a developer server.
Passthrough, room setup, tracking and system-managed spatial data are provided by Meta and subject to Meta's policies and device privacy controls. Denying spatial-data permission prevents room placement; you can still use the ordinary device-control window.
3. Meta platform services
The Store build uses Meta's Platform SDK to verify that your Meta account has access to the app. HomePanel MR does not request your profile, friends list or a Meta user ID. Meta may process account, purchase, device and diagnostic information under Meta's Privacy Policy. The app writes limited technical status messages to local Android system logs for troubleshooting; it does not intentionally log passwords, tokens, device names or spatial coordinates.
4. Support messages
If you contact hohiep102@gmail.com, we receive the email address, message and attachments you send. We use them to respond and troubleshoot. The mailbox uses Google's Gmail service. We keep correspondence only as needed to handle the request or meet applicable legal obligations. Do not send passwords, Home Assistant tokens or unnecessary private room images. You may request access, correction or deletion using the same address. We do not sell support messages or use them for advertising.
5. This website
This static website is hosted by Cloudflare Pages. Cloudflare may process request information such as IP address, requested page and time to deliver and protect the site; see Cloudflare's Privacy Policy. These pages contain no added analytics, advertising trackers, tracking cookies, embedded third-party video, accounts or contact forms. Following an external link uses that service's privacy practices. Hosting and email providers may process information outside your country.
6. Your controls and deletion
- Use Disconnect and forget in the Connection page to remove saved connection credentials. Browser-issued refresh tokens are revoked when the server is reachable; you can also revoke tokens in your Home Assistant profile. Long-lived tokens must be revoked in Home Assistant.
- Remove individual placements from the Placed page. Forgotten connections do not automatically erase saved placements.
- Clear app storage or uninstall to remove local credentials, placements and preferences. Android backup and app-data transfer are disabled. We cannot restore local data.
- Manage system room scans, permissions and Meta account or purchase records through Meta's settings. Removing the app does not delete your Home Assistant server data or Meta records.
- For support-email information or privacy rights, contact hohiep102@gmail.com. We may need enough information to verify a request belongs to you. You may have additional rights under applicable privacy laws, including contacting your data-protection authority.
7. Children and changes
The app does not ask for names, birthdays or contact details. Availability for account age groups is governed by Meta and the Store rating. A parent or guardian may contact us about information a child sent to support. We will update this page and its date when the app's data handling changes. This policy applies to HomePanel MR and this website.