Privacy Policy

What the gethome products do with your information: what stays on your own devices, the little that reaches us, and exactly what each AI feature sends, and where. It covers the website, the app for iPhone, gethome hub and gethome studio. In 15 sections: Who we are and what this covers; What reaches us; The app on your iPhone; The hub; Studio on your Mac; AI features; Other services the software contacts; Shared homes; Keeping and deleting your information; Your choices and rights; Security; Children; Where information is processed; Changes to this policy; Contact.

Last updated

The short version

  • There is no gethome account and no gethome cloud. Your homes live on your iPhone and on a hub you own, and nothing in them is sent to us.
  • No ads, no analytics, no tracking — not in the apps, not on the hub, not on this website.
  • AI features are the exception, and they’re your choice. Once you allow it, what you type, say or photograph for an AI feature goes to OpenAI or Anthropic, on an API key that you or your home’s owner provided. Exactly what each one sends.
  • In a home you share, the people you share it with see your name and what you did, and those with AI access can read the home’s conversations with the assistant.
  • If you send feedback from the app, we get what you wrote, which versions of the app, iOS and your hub you’re on, and an email address only if you ask us to reply. Exactly what it sends.

1. Who we are and what this covers

The gethome products are made by Georgii Galanin, an independent developer (“we”, “us”). We are responsible for the information described here that reaches us — which, as the rest of this policy explains, is very little.

This policy covers:

  • the website at gethome.me;
  • gethome for iPhone and its widgets (“the app”);
  • gethome hub, the software that runs a home from a computer you own, usually a Raspberry Pi (“the hub”);
  • gethome studio, the Mac app that sets hubs up and manages them (“Studio”).

Questions about this policy or about your information go to support@gethome.me.

2. What reaches us

The app, Studio and the hub send us nothing about you or your home on their own: no analytics, no usage data, no crash reports of our own, no copy of your home. What we receive is:

  • Standard web server logs. When you visit gethome.me, our server records your IP address, the page you asked for, the time and your browser’s user agent. We use them only to keep the site running and secure, which is our legitimate interest, and they’re deleted automatically, generally within a few weeks.
  • Studio’s check for a newer version. Once a day — unless you switch it off in Studio’s Settings — Studio asks gethome.me whether a newer version of Studio is out, and a new version, like the one you first downloaded, comes from gethome.me as well. Our server logs those requests as it logs a visit: your IP address, the time, and a user agent naming the version of Studio and of Sparkle, the updater it uses. Nothing else goes with them — no identifier for your Mac, and nothing about your hubs or your home.
  • Feedback you send from the app. When you press Send on the feedback form (Profile → Send feedback), the app sends our server what you wrote and whether it’s an idea or a problem, together with the app’s version, your iOS version, your iPhone’s model and the kind of home you have open — for a home on a hub, also the hub’s version and whether your iPhone could reach it. It never includes your home’s name or anything in it. Your email address is sent only if you turn on “Ask for a reply”, and we use it only to answer you. We keep feedback for as long as we need it to deal with what you told us, and a copy may also be emailed to our support inbox. Your IP address is held briefly in memory to stop anyone flooding the form. So that only the app can use the form, each message also carries a one-time token from Apple’s DeviceCheck service, which our server passes to Apple to confirm the message came from the gethome app on a real Apple device. The token tells us nothing about you or your iPhone; we don’t store it, and hold a fingerprint of it in memory for a day so it can’t be used twice.
  • Messages you send us. If you write to us, we keep the conversation for as long as we need it to help you.
  • What Apple shares with developers. If you’ve agreed on your iPhone to share analytics with app developers, Apple may give us crash reports and aggregated usage statistics for the app. Apple’s privacy policy covers that data, and it doesn’t identify you to us.

The website sets no cookies and loads no analytics, third-party scripts or third-party fonts. It remembers whether you picked the light or the dark theme in your browser’s local storage, and that never leaves your browser.

The website is hosted by DigitalOcean, which stores feedback and the logs on our behalf. We don’t sell personal information, share it for advertising or use it to build a profile of you.

3. The app on your iPhone

What the app knows about your homes stays on your iPhone and, for a home that runs on a hub, on that hub. On your iPhone it keeps:

  • the homes you’ve added, the order you’ve arranged things in, your name if you gave one, and your settings;
  • whether you’ve allowed AI features (see AI features);
  • the sign-in tokens for your hubs and, if you added one, your own OpenAI API key, both in the iOS Keychain;
  • device portraits: those drawn for homes that don’t have a hub, and copies of the ones your hub keeps;
  • a snapshot of your hub homes’ devices for the widgets to draw from, in storage shared only with the app’s own widgets.

Apple Home

If you bring in an Apple Home, the app reads it through Apple’s HomeKit framework so you can see and control your accessories. That information stays on your iPhone: it isn’t sent to us, it isn’t used for advertising or data mining, and it isn’t shared with anyone else. The one exception is one you ask for — when you have a portrait drawn for an Apple Home accessory without a photo, the kind of device it is (for example, “table lamp”) is sent to OpenAI to draw it.

What the app sends to your hub

When you join a hub, the app sends it the name you enter and your device’s name (on current versions of iOS, just its model, such as “iPhone”). After that it sends what you do in the home: commands to devices, names you give rooms and devices, your favorites, your messages to the assistant and the automations agent, the photos you choose for portraits and any AI keys you add. When you add a Matter accessory to a hub, it also sends your Wi-Fi network’s name and password so the accessory can join it; they’re passed on to the accessory and kept neither on your iPhone nor on the hub.

The app talks to your hub directly over your own network. Nothing is routed through us.

Permissions

  • Home (HomeKit) — to show and control an Apple Home you bring in.
  • Local network — to find your hub and talk to it.
  • Camera — to photograph a device for its portrait, and to scan pairing codes.
  • Microphone — only while you’re talking to the assistant out loud (see AI features). Nothing is recorded on your iPhone.

Choosing a photo from your library goes through Apple’s photo picker, which gives the app only the photo you pick. The widgets talk only to your hub, over your own network.

4. The hub

The hub runs on a computer you own, in your home. What it stores stays there: it doesn’t report to us, and we have no way to reach it. It keeps:

  • your home’s rooms, zones and devices, and each device’s current state;
  • the home’s members — the name each gave, their role and the devices they signed in from — with their sign-in tokens stored only as a one-way hash;
  • readings from sensors, such as temperature and power, for 7 days;
  • the home’s activity feed — what happened, and which member did it — for 30 days, up to 5,000 entries;
  • automations, their earlier versions, and a short record of when they ran;
  • conversations with the assistant and the automations agent, including what was said out loud (as text), for about two weeks;
  • a log of the last 250 AI tasks — what kind of task, which model ran it, what it cost and what it looked up — and, only if you switch it on, a copy of what device recognition exchanged with the AI provider, for 7 days;
  • device portraits until you delete them, with a note of who drew each one (the photos they’re drawn from aren’t kept);
  • your AI API keys, encrypted with a secret that never leaves the hub;
  • the name and password of the Wi-Fi network it was set up with, readable only by the hub, so it can hand them to Matter accessories;
  • its own system logs.

Whoever runs a hub — usually the person who set it up — is in charge of the information on it. Keeping and deleting your information explains how to clear it.

5. Studio on your Mac

Studio keeps on your Mac the hubs you’ve added and their sign-in tokens (in the macOS Keychain), the Raspberry Pis it has connected to, an SSH key it creates to install and update hubs, a note of each install in progress for up to 7 days, and — for hubs you watch — up to a week, or 20 MB per hub, of the device messages that hub carried. It suggests your Mac’s name as your name when it joins a hub, and you can change it.

When it prepares an SD card or installs over SSH, Studio writes to the card or the Raspberry Pi the Wi-Fi network name and key you entered, if any, and the public half of its SSH key. The Raspberry Pi’s password is used only to connect and is never saved. AI keys you enter in Studio go straight to your hub.

To keep itself up to date, Studio stores its two update settings with its preferences, and an update it has downloaded in its caches folder until it is installed. Apart from its daily check for a newer version (see What reaches us), Studio sends nothing to us.

6. AI features

The AI features are optional, and they are the one way information about your home leaves it.

You’re asked first

Before the app sends anything to an AI provider for the first time — your first message to the assistant or the automations agent, the first time you talk to it out loud, your first portrait — it says what will be sent and where, and waits for your answer. One answer covers every AI feature on that iPhone, and you can change it at any time in Home Settings → AI.

Whose key

We don’t run an AI service of our own. Every AI request is made with an API key that you, or your home’s owner, got from OpenAI or Anthropic and added to gethome. For a home on a hub, the key is kept on the hub and never leaves it, and the hub makes the requests — for a voice conversation, it opens the line your iPhone then talks over. For any other home, the key is kept in your iPhone’s Keychain and the requests come from your iPhone. Either way, the provider handles the request under its agreement with whoever owns the key — not with us — and bills them for it.

What each feature sends

The assistant

What is sent
What you type and the conversation so far, your name, the names of your home’s rooms, zones, devices, scenes and automations, and the state of the devices it needs to answer.
Where it goes
OpenAI or Anthropic, whichever the home is set up with — sent by the hub.

The automations agent

What is sent
What you type and the conversation so far, your home’s rooms and devices, and its automations, including the one you’re working on.
Where it goes
OpenAI or Anthropic — sent by the hub.

Talking out loud

What is sent
The sound of your voice, streamed straight from your iPhone while the conversation is open. To set it up, the hub gives OpenAI your name, the names of your rooms, devices and scenes, and the recent conversation. OpenAI returns a written transcript, which the hub keeps with the conversation, and what you asked for is then answered like a typed message.
Where it goes
OpenAI.

Device portraits

What is sent
The photo you take or choose — or, if you draw from scratch, only the kind of device it is.
Where it goes
OpenAI — sent by the hub for a home on a hub, and by your iPhone for any other home.

Device recognition

What is sent
When a Zigbee device the hub doesn’t know joins, its published description and a few of its recent readings — never a name and never anything else in your home. The provider may search the web for the device’s model, and the hub may read its documentation page. It can be switched off in Home Settings → AI.
Where it goes
OpenAI or Anthropic — sent by the hub.

At the provider

OpenAI and Anthropic handle what they receive under their own terms and privacy policies. Both say they don’t use data sent through their APIs to train their models by default, and keep it only for a limited time, mainly to detect abuse. Those details are theirs to set, so their own policies are the authority: OpenAI and Anthropic.

Connecting a voice conversation

To connect a voice conversation, your iPhone asks a public STUN server run by Google (stun.l.google.com) for its own public network address, so Google sees your IP address. No audio and nothing else goes to it.

7. Other services the software contacts

A few other services are contacted for the software to work. None of them receives anything about your home, but each sees your IP address when it’s contacted, and each has its own privacy policy.

  • Apple — the app is distributed through the App Store and uses Apple Home (HomeKit) on your iPhone. When you send feedback, our server also asks Apple’s DeviceCheck service whether the one-time token that came with it is genuine, and sends Apple nothing but that token.
  • Google — the STUN server used to connect voice conversations, above.
  • GitHub — Studio, and the hub when you open its software page, check GitHub for a newer version of the hub; installing or updating the hub downloads it from GitHub; and Zigbee2MQTT, which the hub uses for Zigbee devices, may check GitHub for firmware updates for them.
  • Node.js, npm and your operating system’s package mirrors — used when the hub is installed or updated.
  • The Zigbee2MQTT website — read by the hub while it recognizes a Zigbee device.

Links in the apps — to get an API key, to download Raspberry Pi Imager, or to update a Zigbee adapter — open in your browser.

8. Shared homes

A home on a hub can be shared, and sharing means the people in it see some of what you do. In a shared home:

  • members see your name and your role, and the activity feed says which member did what (a guest sees only their own entries);
  • members whose role includes AI — by default, owners and members — can read the home’s conversations with the assistant, including what was said out loud, and those who can manage automations can read the conversations with the automations agent;
  • each portrait records who drew it;
  • your favorites are yours, while names of rooms and devices belong to the home, and everyone sees the same ones.

An owner, or anyone whose role allows it, can remove a member. When you leave a home or are removed, your access ends straight away; entries that mention you age out of the activity feed and the conversations as described in The hub.

9. Keeping and deleting your information

  • On your iPhone. Remove a home in its Home Settings — Remove from gethome, or Leave this home for a home on a hub — to delete what the app kept about it, portraits included. Deleting the app deletes the rest; to be sure your own OpenAI key goes too, remove it in Home Settings → AI first, because iOS can keep Keychain items after an app is deleted.
  • On your hub. Members, devices, automations and portraits can be removed from the app by anyone whose role allows it; readings, activity and conversations age out on their own, as described in The hub. To erase everything, erase the card or disk the hub runs from.
  • In Studio. Forget This Hub removes a hub and its token. Deleting Studio, its folder in ~/Library/Application Support/gethome-studio, and its preferences and caches (com.galanin.gethome-studio in ~/Library/Preferences and ~/Library/Caches) removes the rest. The SSH key it added stays on your Raspberry Pi until you remove it or rewrite the card.
  • At the AI providers. What they received is kept under their policies, in the account that owns the key, and that account’s owner manages it with them.
  • With us. Feedback is kept for as long as we need it to deal with what you told us, and deleted sooner if you ask. Server logs are deleted automatically. To have us delete anything we hold, write to support@gethome.me.

10. Your choices and rights

You can stop AI features at any time in Home Settings → AI: stop this iPhone sending anything, remove a key, or switch device recognition off. What was already sent stays with the provider, but nothing more is sent.

Depending on where you live — including the European Economic Area, the United Kingdom and California — you may have the right to know what personal information we hold about you, to have it corrected or deleted, to object to or restrict how we use it, to receive a copy of it, and to withdraw your consent. We’ll answer within one month. You can also complain to your local data protection authority.

Most of your information is never held by us: it’s on your iPhone, your Mac and your hub, where you can see and delete it yourself, or with an AI provider, under the account of whoever owns the key. For anything we do hold, write to support@gethome.me.

If you live in California: we don’t sell or share personal information, we don’t use it for targeted advertising, and we won’t treat you differently for using your rights.

11. Security

The website is served only over HTTPS. The app and Studio keep sign-in tokens and keys in the iOS and macOS Keychain, and the hub keeps only a one-way hash of each sign-in token and encrypts AI keys.

The app, its widgets and Studio talk to your hub over your own network in plain HTTP, protected by your Wi-Fi’s encryption rather than their own. Use gethome on a network you trust, and don’t expose the hub to the internet — for example, by forwarding its ports on your router.

No system is perfectly secure. If you find a security problem, please tell us at support@gethome.me.

12. Children

The products aren’t directed at children under 13, and we don’t knowingly collect personal information from them. If you think a child has given us personal information — in feedback from the app, for example — write to us and we’ll delete it.

13. Where information is processed

Our website, and with it the feedback the app sends, runs on DigitalOcean servers, which may be in a country other than yours, including the United States; those transfers are covered by DigitalOcean’s standard data processing terms. What the app, Studio and the hub store stays on your own devices, and AI providers process requests where their own policies say.

14. Changes to this policy

If what the products do with information changes — for example, if remote access through a gethome service is added — we’ll update this policy before the change takes effect and change the date at the top. For significant changes, we’ll also say so on the website or in the apps.

15. Contact

Georgii Galanin
support@gethome.me