Privacy Policy
In short
- No accounts, no ads, no analytics, no tracking.
- Your server's data travels only between your phone and your own server.
- Only two optional things ever reach us: alerts that are end-to-end encrypted so we cannot read them (if you use push notifications), and crash reports (if you turn them on).
1. Who we are
Homelab Pulse (“the app”) is developed by Aldaghir (“we”, “us”). It works together with the Homelab Pulse agent, a program you install on your own server. You can reach us at android@aldaghir.com.
2. Data between your phone and your server
The app talks directly to the agent on your server to show system metrics, storage and network figures, services and containers, logs, alerts and terminal sessions, and to apply the settings you choose. This data:
- travels directly between your phone and your server: on your local network over TLS, with your server's certificate pinned from the pairing code, or remotely through your own Cloudflare Tunnel and Cloudflare Access if you set them up (Cloudflare then handles that traffic under your Cloudflare account and Cloudflare's privacy policy);
- is never sent to us.
3. Data stored on your phone
- The servers you add: name, address, certificate fingerprint and the agent's features.
- Access tokens for your servers and, if you use them, Cloudflare Access credentials, encrypted with a key kept by the Android Keystore.
- A short cache of recent readings so the app opens quickly, and your settings.
This data is excluded from Android cloud backup and from device-to-device transfer. If you export a backup of your settings, the file is encrypted with a password you choose and stays wherever you save it. Removing a server, or uninstalling the app, deletes the related data from your phone.
4. Push notifications (optional)
If your phone has Google Play services and you add a server, the app registers with Firebase Cloud Messaging (FCM), a Google service, to receive alerts. Registering creates a push token and a Firebase installation identifier at Google. It does not happen before you add your first server, and the registration is deleted when you remove your last server.
The app gives the push token to your agent. When an alert fires, your agent encrypts it for your phone (X25519 and AES-256-GCM) and sends the sealed message, with the push token, to Pulse Relay, a small service we run that hands it to FCM. The relay cannot read your alerts, stores nothing, and does not log tokens, addresses or message contents. FCM then delivers the message under Google's privacy policy. You can run your own relay instead, or rely on Telegram alerts from your agent and not use push at all.
5. Crash reports (optional, off by default)
If you turn on “Send crash reports” in Settings, the app keeps a report when it crashes and sends it the next time it starts, through your own agent. A report contains the app and Android versions, the phone model, the types of the errors and where in the code they happened, and the error messages with addresses, host names, e-mail addresses and tokens removed.
Your agent writes the report to your server's system log and, when a relay is configured, forwards it to us. We use crash reports only to find and fix bugs. They stay in our relay's log for at most 7 days and are then deleted automatically. Nothing is recorded while the setting is off, and turning it off deletes any report still waiting on your phone.
6. Scanning a pairing code
The app reads pairing QR codes with Google code scanner, part of Google Play services. Google Play services handles the camera, the scan runs on your phone, and the app receives only the text of the code. Google may collect diagnostic data about the scanner's use, such as the device model, app version and performance figures, as described in Google's ML Kit data disclosure. You can type the code instead of scanning it.
7. Services you connect
Integrations you set up, such as Telegram, Cloudflare or Uptime Kuma, are run by your agent. Credentials you enter in the app go directly to your agent, which stores them encrypted on your server; they never reach us. Those services' own terms and privacy policies apply to them.
8. Permissions
- Internet and network state: to reach your server and choose between your local network and remote access.
- Wi-Fi multicast: to find agents on your local network.
- Notifications: to show alerts; asked for when needed.
- Biometrics: for the optional app lock. Android checks your fingerprint or face; the app never receives biometric data.
- Run at startup, foreground service and wake lock: added by Android libraries to deliver notifications and refresh widgets.
9. What we never do
We have no user accounts, show no ads and include no analytics or tracking libraries. We do not sell or share personal data, and we do not build profiles.
10. Children
The app is a tool for managing servers and is not directed at children under 13, or under the minimum age in your country.
11. Security
Every connection is encrypted with TLS, and your server's certificate is pinned on your phone. Secrets on the phone are encrypted with Android Keystore keys. The agent stores only hashes of device tokens and enforces a permission level for each device. No system is perfectly secure; if you find a vulnerability, please tell us at android@aldaghir.com.
12. Your choices
- Turn crash reports on or off at any time in Settings.
- Turn notifications off in Android settings. Removing a server unpairs your phone from it, so it stops sending you alerts.
- We keep no account or profile about you. The only data we hold are crash reports, which are deleted within 7 days. You are still welcome to contact us with any request.
13. Changes
We will post any change on this page with a new effective date, and mention important changes in the app's release notes.