Privacy
TV Remote — Privacy Policy
What this app collects, why it collects it, and what you can ask us to delete.
Effective for TV Remote 2.0. Last updated: 9 September 2026.
TV Remote connects your phone or tablet to compatible TVs and receivers. This policy explains the information used for local controls, media sharing, optional AI routine planning, diagnostics and purchases. For privacy questions, email the support page or use our Support and feedback page.
Request deletion of TV Remote data
In TV Remote, open Settings → Privacy & data → Delete online account to request deletion of your anonymous Firebase account and all of its linked server installations and planning records. Keep the app open until deletion is confirmed. If the request cannot complete, it remains available to retry; an error is not a completed deletion. A retry never creates a replacement account. If your existing account cannot be verified before the server accepts the request, the app keeps the recovery information and explains that deletion has not started. Use Retry deletion or contact us for help.
You can also email the support page with the subject TV Remote data request to request access or deletion, including without using the app. Describe the data or installation concerned; we will explain any information needed to verify ownership. Do not send passwords, pairing codes, purchase tokens or payment-card details. You do not need to buy a subscription to make a privacy request.
Deletion removes the Firebase account and linked installation identities, usage and replay records. Limited keyed security fingerprints remain indefinitely; pseudonymous abuse and purchase-allowance records remain for up to 35 days, followed by hourly cleanup. The retention and provider limits are explained below. Local TVs and routines have separate Delete/Forget controls. Data deletion does not cancel an Apple or Google subscription.
TV controls and data on your device
The app discovers nearby devices and stores the TVs you choose, including their names, local addresses, protocol capabilities, rooms, favorites, optional wake addresses and pairing credentials. Saved routines, app/input favorites and preferences are also stored on your device. Discovery and ordinary remote commands travel directly to your TV on your local network. We do not send pairing credentials, local TV addresses, remote-control text or the contents of your TV screen to our AI service.
You can forget a TV and its saved pairing in TV settings, or delete an individual routine in Routines. Forgetting a TV in this app does not necessarily remove authorization stored by the TV itself; use your TV's paired-device settings when you also want to revoke that authorization. Your operating system may include local app data in its own device backup according to your device settings.
Selected media, screen sharing and audio
The app accesses photos, videos or files you select through system pickers. Local casting can temporarily serve selected files to your chosen receiver on the local network. URL casting gives the selected URL to the receiver, which contacts that media host. Media hosts and receiver vendors process those requests under their own policies. Temporary media access is revoked when the sharing session ends or its ownership is lost.
Live screen sharing starts only after the platform's capture consent. It can expose notifications and other visible information to the paired receiver; choose the content and receiver carefully and use Stop when done. Browser-assisted sharing uses a local pairing code and a temporary local stream. Screen frames are not sent to our backend or AI providers. Where offered on Android or iOS, optional app-playback audio forwards only audio that the source app and operating system permit; it does not use the microphone. Receiver audio support, platform restrictions and protected content can limit capture. If audio cannot play, video can continue without sound. The app stops owned capture and local serving when you stop or the session ends. Receiver devices may have their own recording features; we cannot erase copies you or a receiver independently make.
Microphone/speech permission is separate: if you choose dictation, the operating system's speech-recognition service processes your speech according to its settings and provider policy. Dictation is not continuous background listening. Denying optional capture, media or speech permissions does not prevent remote control with an active subscription.
Optional AI routine planning
Before AI planning, the app asks permission to send your written request and the available TV command names, app names/IDs and input names/IDs to our planning backend and to OpenRouter, which routes the request to an AI provider. Our current model routes use OpenAI and Google models through OpenRouter. Do not put confidential or sensitive information into your request. Screen contents, media, pairing keys and local network addresses are not included in the AI request. You review the proposed steps before running them; AI does not directly operate your TV.
Our backend does not persist prompt text, TV catalogs or returned plans. It requests OpenRouter endpoints that exclude training/data collection and require zero data retention, using data_collection=deny and zdr=true. It fails the request if a permitted result is unavailable; it does not relax that policy to obtain an answer. Provider security, billing and operational metadata are distinct from prompt/response content and are governed by the providers' policies. Read OpenRouter's data policy and zero data retention documentation. A plan you choose to save becomes a local routine on your device.
Online identity, security and retention
Planning uses Firebase anonymous authentication and App Check to protect the service. You do not create a password in TV Remote, but this still creates a Firebase user identifier. The app also creates a random installation ID and a signing key. Its private key stays in the device's protected storage and is not sent to our server. Our server stores the Firebase user ID, installation ID, public key, registered app ID and creation time to authenticate requests.
For rate limits, replay protection and cost control, the server records request IDs, operation/timing data, reserved AI cost, completion status and a keyed network-prefix fingerprint. The backend processes the request IP to derive that fingerprint. It does not intentionally store raw IP addresses in those planning database records. Hosting/security infrastructure may process connection metadata. Usage records expire after 35 days and are removed by the next hourly cleanup while the service is running; replay records expire after 3 minutes and are removed during requests or hourly cleanup.
In Settings → Privacy & data, Export planning data saves a JSON file of this installation's server identity, public key, usage and replay records to a location you choose. It never exports your private key. Protect that file because it contains identifiers. Delete online account retires every installation linked to your anonymous Firebase account and erases their planning records. It requests Firebase account deletion and checks that the user no longer exists before confirming completion. The app then signs out that identity and removes its private key. Retry deletion uses the retained key even after the Firebase account is gone; it creates no replacement account. Deletion removes the AI consent preference; future AI use requires permission again.
For narrowly scoped security reasons, deletion retains keyed installation/owner fingerprints and a public-key digest indefinitely so the retired identity cannot be recreated and exact-owner retries remain possible. Pseudonymous abuse/cost counters remain for at most 35 days followed by hourly cleanup, and deletion-retry nonces for 3 minutes followed by hourly cleanup. Those retained records do not contain the original installation ID, raw Firebase user ID, public key, prompt, TV catalog or generated plan after deletion completes. While provider deletion is unfinished, the Firebase UID remains only to complete that operation; use Retry deletion to finish. Deletion does not reset accrued AI limits or costs. Saved TVs and routines stay on this device. Store billing continues until you cancel through Manage subscription; you can delete the account immediately without canceling first. Separate purchase, support, diagnostic and media-service records have their own retention. Contact support for a broader request or if you no longer have the app; we verify authority before acting on other records.
Diagnostics and service providers
Firebase Analytics and Crashlytics help us measure app reliability and diagnose crashes. Depending on the SDK and platform, this includes app/device versions and installation identifiers, usage and purchase events, approximate location derived from connection information, crash traces and associated technical data. We do not request your precise device location for analytics. You can turn usage and crash diagnostics off in Settings. This stops future optional collection; it does not by itself delete records already held by the provider. Crash traces may include technical context, so do not submit sensitive information in a support report. We do not intentionally include media, AI requests, pairing keys or command text in analytics events. The app excludes Apple's advertising-identifier analytics component and Android's advertising-ID permission. Advertising storage, advertising user data and advertising personalization consent remain disabled when you enable optional diagnostics. Diagnostics do not enable cross-app advertising.
Firebase Authentication/App Check continue to operate when needed for secure online planning even if optional diagnostics are off. Google documents service-specific data handling and retention in Firebase privacy and security. Hosted onboarding, offers and legal pages are delivered through our app-specific Cloudflare-hosted website; those requests necessarily expose connection information to the hosting provider. We do not sell your personal data or use it for cross-app advertising.
Purchases and support
Apple App Store and Google Play process subscriptions and payments. TV Remote reads product/price information, purchase status and transaction identifiers needed to grant or restore features. We do not receive your card number. Store transaction and payment records are governed by the store's policies and legal obligations. Manage or cancel subscriptions through the store account; deleting app/planning data does not cancel them.
For paid AI access, the app sends a current App Store signed transaction or Google Play purchase token to our backend. The backend checks the subscription directly with the relevant store before using the AI provider. Store proofs are never sent to OpenRouter, logged or saved. We retain a keyed purchase identifier, linked renewal identifiers, verification time, active state and access expiry to order verification and prevent duplicated AI allowances across restores. These pseudonymous records expire 35 days after verification or associated usage, followed by hourly cleanup. Deleting installation data retains the accrued pseudonymous purchase allowance for this same limited period. A store outage does not authorize a new AI request from a cached subscription. Local feature access may continue for up to three days after verification, capped by the store expiry where supplied; a confirmed inactive read ends access.
If you contact support, we process the message and contact information you provide to respond and resolve your request. Send only information needed for support. You may request access, correction or deletion through the support link above, subject to verification and applicable retention obligations. The app is not designed to solicit personal information from children. If you believe a child supplied such information, contact us.
Your choices and policy changes
AI, media selection, dictation and screen/audio sharing are optional and have their own controls and consent. You can revoke system permissions in device settings, stop sharing, manage local data, turn diagnostics off, and request assistance with retained/provider data. Information may be processed outside your country by the listed providers. We use authenticated, encrypted connections for online planning; local TV protocols vary by TV and may not encrypt local commands or media, so use a trusted network.
We may update this policy when features or data practices change. The current version is available from Settings and our hosted setup/offer pages. Material new optional uses require the corresponding app consent.