Homelab Pulse العربية

Privacy Policy

Effective 10 October 2026

In short

  • No accounts, no ads, no analytics, no tracking.
  • Your server's data travels only between your phone and your own server.
  • Only two optional things ever reach us: alerts that are end-to-end encrypted so we cannot read them (if you use push notifications), and crash reports (if you turn them on).

1. Who we are

Homelab Pulse (“the app”) is developed by Aldaghir (“we”, “us”). It works together with the Homelab Pulse agent, a program you install on your own server. You can reach us at android@aldaghir.com.

2. Data between your phone and your server

The app talks directly to the agent on your server to show system metrics, storage and network figures, services and containers, logs, alerts and terminal sessions, and to apply the settings you choose. This data:

3. Data stored on your phone

This data is excluded from Android cloud backup and from device-to-device transfer. If you export a backup of your settings, the file is encrypted with a password you choose and stays wherever you save it. Removing a server, or uninstalling the app, deletes the related data from your phone.

4. Push notifications (optional)

If your phone has Google Play services and you add a server, the app registers with Firebase Cloud Messaging (FCM), a Google service, to receive alerts. Registering creates a push token and a Firebase installation identifier at Google. It does not happen before you add your first server, and the registration is deleted when you remove your last server.

The app gives the push token to your agent. When an alert fires, your agent encrypts it for your phone (X25519 and AES-256-GCM) and sends the sealed message, with the push token, to Pulse Relay, a small service we run that hands it to FCM. The relay cannot read your alerts, stores nothing, and does not log tokens, addresses or message contents. FCM then delivers the message under Google's privacy policy. You can run your own relay instead, or rely on Telegram alerts from your agent and not use push at all.

5. Crash reports (optional, off by default)

If you turn on “Send crash reports” in Settings, the app keeps a report when it crashes and sends it the next time it starts, through your own agent. A report contains the app and Android versions, the phone model, the types of the errors and where in the code they happened, and the error messages with addresses, host names, e-mail addresses and tokens removed.

Your agent writes the report to your server's system log and, when a relay is configured, forwards it to us. We use crash reports only to find and fix bugs. They stay in our relay's log for at most 7 days and are then deleted automatically. Nothing is recorded while the setting is off, and turning it off deletes any report still waiting on your phone.

6. Scanning a pairing code

The app reads pairing QR codes with Google code scanner, part of Google Play services. Google Play services handles the camera, the scan runs on your phone, and the app receives only the text of the code. Google may collect diagnostic data about the scanner's use, such as the device model, app version and performance figures, as described in Google's ML Kit data disclosure. You can type the code instead of scanning it.

7. Services you connect

Integrations you set up, such as Telegram, Cloudflare or Uptime Kuma, are run by your agent. Credentials you enter in the app go directly to your agent, which stores them encrypted on your server; they never reach us. Those services' own terms and privacy policies apply to them.

8. Permissions

9. What we never do

We have no user accounts, show no ads and include no analytics or tracking libraries. We do not sell or share personal data, and we do not build profiles.

10. Children

The app is a tool for managing servers and is not directed at children under 13, or under the minimum age in your country.

11. Security

Every connection is encrypted with TLS, and your server's certificate is pinned on your phone. Secrets on the phone are encrypted with Android Keystore keys. The agent stores only hashes of device tokens and enforces a permission level for each device. No system is perfectly secure; if you find a vulnerability, please tell us at android@aldaghir.com.

12. Your choices

13. Changes

We will post any change on this page with a new effective date, and mention important changes in the app's release notes.

14. Contact

android@aldaghir.com