Privacy Policy — Echidna Home
Echidna Home is a remote control for a Home Assistant instance you already own and operate.
What this app does with your data
Echidna Home connects directly to the Home Assistant instance you configure during setup, using a URL and access token you provide. Your Home Assistant URL and access token are stored only in your device's secure Keychain. Your floorplan layout, entity bindings, favourite colours, and notification rules are stored only in local files on your device.
Apart from the push token described under “Notifications” below, none of this information is ever sent to us or to any third party. The only place any of it is ever transmitted is to the Home Assistant instance you yourself configured — a server you own and control, not one we operate or have access to.
Optional sync
If you enable cross-device sync, your floorplan layout is written to and read from your own Home Assistant instance (as a sensor entity), so it can be shared between your own devices. This uses the same connection and credentials as above; no separate account or service is involved, and we have no access to this data.
Notifications
Your notification rules are evaluated against data from your own Home Assistant instance, and most alerts are generated and shown entirely on your device. If you create a notification rule, the app also enables delivery while it is closed. To do this it collects your device's Apple Push Notification token (the address Apple uses to deliver a push to your device) and sends it to a small relay server we operate, hosted on Cloudflare Workers. Your Home Assistant instance contacts that relay when one of your rules fires, and the relay asks Apple to notify your device.
The relay stores your push token, together with a random identifier generated by the app, for up to 180 days after your device last contacts it (refreshed each time you open the app). It is used only to deliver the notifications you asked for. The relay never receives the content of your notifications — only an opaque rule identifier; the wording you entered for each rule stays on your device. The push token is not linked to any name, email, or account (there is no account), is never used for advertising or tracking, and is never shared with any other party. If you create no notification rules, no push token is requested or sent.
Analytics and tracking
This app contains no analytics, advertising, or tracking software of any kind, and does not share data with any third party. The push token described above is the only data that reaches a server we operate.
Permissions
This app requests local-network access (to reach a Home Assistant instance on your home network) and notification permission. Notification permission covers both on-device alerts and, if you create a notification rule, Apple push notifications delivered while the app is closed. It does not request camera, microphone, location, or photo-library access.
Contact
Questions about this policy or your data: mike.moran@hamonindustries.com