Privacy Policy
What the app does with your network
TV Remote talks directly to your TV over your local Wi-Fi network to discover it, pair with it, and send remote-control commands. Remote-control traffic never leaves your home network and never passes through our servers.
We do run one small server, but it exists only to receive the anonymous diagnostic reports described below. It never receives your commands, your pairing credentials, or anything about what you watch.
iOS will ask for the Local Network permission the first time you scan. To find your TV the app looks for AirPlay services on your network and briefly probes the TV control ports (8001, 3001, 3000, 8060) on your local subnet. It never builds or transmits an inventory of the other devices on your network.
What is stored on your device
The app stores a profile for each TV in its local database: the name and model the TV reports about itself, its IP address and port, its MAC address (used to send a wake-up packet so you can turn the TV on), and the TV's own device identifier. Pairing credentials - Samsung tokens and LG client keys - are stored separately in the iOS Keychain and are not synced to iCloud.
The app never uploads any of this. It stays on your iPhone and is removed when you delete the corresponding TV or uninstall the app (Keychain items may persist per standard iOS behavior until overwritten).
Diagnostics
Because we cannot test every TV model ourselves, the app can send an anonymous diagnostic report when a TV fails to connect, or when the TV rejects a command you sent (for example a button it refuses in its current mode). Nothing is sent while the app is working normally: there is no usage tracking, no heartbeat, and no analytics of any kind.
What a report contains. The failure reason; the TV brand and protocol; the name and model the TV reports about itself; your app version; your iOS version; your device model (for example "iPhone15,2"); the time of the failure; and the last 40 lines of the app's in-memory log, each shortened to 200 characters. Of those, the server keeps only the 20 most recent lines and discards the rest on arrival.
What is removed first, and what is not. Before sending, the app strips long secret-looking strings of 20 characters or more - this is how Samsung tokens and LG client keys are removed - and masks IPv4 addresses down to their network (192.168.1.57 becomes 192.168.1.0/24). We would rather be precise than reassuring about the limits of that: IPv6 addresses and MAC addresses are not masked, short codes such as a 4-6 digit pairing PIN fall below the length threshold, and a TV's name is free text that is passed through as written. If you gave your TV a personal name on the TV itself, that name travels with the report.
Who receives it. A server we operate ourselves on Cloudflare, which stores the reports in a Cloudflare D1 database. No third-party analytics company is involved at any point. As with any request over the internet, Cloudflare's network necessarily sees the IP address your report is sent from; we do not store it alongside the report.
How long it is kept. Reports are deleted 30 days after they reach the server. A scheduled job runs daily and removes everything older, so nothing is retained beyond that window. Because a report carries nothing that links back to you, we have no way to locate and delete one person's past reports on request within that window - they simply expire.
How it is tagged. Each report carries a random identifier generated on this install and stored only on your device - not your name, not your Apple ID, and not any Apple device identifier. Deleting the app discards it, so a reinstall produces a new identifier that cannot be linked to the old one. This is the "Other Diagnostic Data (not linked to you, not used for tracking)" entry on the App Store privacy label.
Turning it off. Diagnostics are on by default. You can turn them off at any time under Settings › Privacy & Diagnostics › Diagnostics, and the same screen lets you read the log the app would send and explains in full what a report contains. To be accurate rather than reassuring: the app does not interrupt you with a first-launch notice about this, so a failure can be reported before you have read this page or opened that screen.
Microphone and dictation
The optional voice-input feature runs only while dictation is active, and only after you tap the mic button. Speech is turned into text by Apple's speech recognition, which decides on its own whether to do that on your device or on Apple's servers, under Apple's privacy policy. We never receive, store, or transmit your voice or the recognized text - it goes to the search field you send to your TV.
Purchases
The optional Pro upgrade is a one-time purchase. Payment is processed entirely by Apple through the App Store - we never see your payment details.
To validate the purchase and restore it across reinstalls, the app uses RevenueCat, a purchase-infrastructure service. What RevenueCat receives: the App Store purchase receipt and a randomly generated anonymous identifier - no name, no email, no account, nothing that identifies you. This is the "Purchase History (not linked to your identity)" entry on the App Store privacy label. It is never used for advertising or tracking.
Children
TV Remote is a general-audience utility and does not knowingly collect any information from anyone, including children.
Changes
If this policy ever changes (for example, if a future feature required any data), the new version will be posted at this address with a new effective date before the feature ships.
Contact
Questions? Email m@vietts.io.