Privacy Policy
Dzurinda Home Automation · last updated 12 September 2026
This policy covers a private, self-hosted home automation system used by one household. It is not a commercial service and has no users other than the members of that household. It collects nothing from visitors to this page.
Who this applies to
Only the household that runs the system. There is no sign-up, no account creation, and no way for anyone else to use it.
What data is handled
- Google account access. With the household's explicit consent, the system holds an OAuth token for the household's own Google account, limited to the Google Assistant SDK scope. It is used only to send text commands to that same Google account, such as asking it to start music on a speaker in the house.
- Spotify account access. OAuth tokens for the household's own Spotify accounts, used to show what is playing and to control playback on the household's own speakers.
- Home device state. Readings from devices in the house, such as temperatures, door and lock state, vacuum status and camera images.
Where it is stored
All of it stays on a server inside the home. Access tokens are written to local files readable only by the account that runs the software. Nothing is copied to any server we do not own.
What is not done with it
- It is not sold, rented or shared with anyone.
- It is not used for advertising, profiling or analytics.
- It is not sent to third parties except the services it belongs to, namely Google and Spotify, in order to carry out an action the household asked for.
- There are no trackers, cookies or analytics on this website.
Google user data
The only Google data used is an access token for the Google Assistant SDK scope, obtained through Google's standard consent screen. It is used solely to relay commands the household issues to its own Google account, and is stored locally on the home server. It is never transferred to anyone, and it is not used to build any profile.
Use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Retention and deletion
Tokens are kept only while the integration is in use and are deleted when it is removed. Device readings are kept for a short rolling window for graphs and then discarded.
Revoking access
Access can be withdrawn at any time, without contacting us, at myaccount.google.com/permissions for Google and spotify.com/account/apps for Spotify. Doing so immediately stops the system from acting on that account.
Children
The system is not directed at children and is not accessible outside the household.
Changes
If this policy changes, the date at the top of this page will change with it.