Privacy Policy
Effective date: October 6, 2026
This is a private, non-commercial website. It runs no advertising and no third-party analytics, and it does not sell or rent personal data.
Scope
This policy covers the private service operated by an individual for a single household and the household members and expressly authorized users who access it.
What is collected
- Account information — name, username, email address, and group membership, used to sign in and manage access.
- Authentication data — password hashes held by the self-hosted directory, and, for administrative users, a TOTP (two-factor) secret.
- Connected-service data — when a user connects a third-party account (for example, Google Calendar or Google Nest), the service stores the OAuth tokens needed to call that API on the user's behalf and accesses only the data the user authorized (for example, calendar events or thermostat status).
- Technical logs — usernames, IP addresses, and timestamps generated by the self-hosted services, for security and troubleshooting.
How it is used
Solely to operate the service for its users — for example, to authenticate logins and to run the features a user has connected. There is no advertising, profiling, or sale of data.
Google user data
jg555 Home Assistant accesses Google user data only when a user explicitly connects their own Google account, and only for the in-home features described on the home page:
- Google Calendar — read calendar events, to display them on the private home dashboard.
- Google Nest / Smart Device Management — read device status and send device commands, for in-home automation.
This data is used solely to provide those features to the connecting user. It is not sold, rented, or transferred to third parties; it is not used for advertising, profiling, or creditworthiness; and it is not read by any person except the user themselves, or where the user requests help or the law requires it.
jg555 Home Assistant's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Users can revoke access at any time from myaccount.google.com/permissions; disconnecting an account deletes the stored tokens.
Where it is stored
On the operator's own self-hosted servers. Credentials and OAuth tokens are protected by restricted file permissions and/or encryption at rest, and backups are encrypted.
Sharing
Data is not sold and is not shared with third parties, except:
- with the third-party APIs a user explicitly connects (for example, Google), as required to provide that feature; and
- where required by law.
Outbound email is delivered through a third-party mail provider.
Retention and deletion
Information is kept while an account is active. You may request deletion of your account and associated data by contacting us; disconnecting a third-party account revokes and deletes the stored tokens for it.
Children
The service is not directed to the general public and does not knowingly collect data from anyone outside the household; accounts are created by the operator only for household members and authorized users.
Changes
This policy may be updated at any time; the effective date above will change accordingly.
Contact
Privacy questions or deletion requests: admin@jg555.com.