Privacy policy
Cloud Sync is an optional service for HA Desktop Widget. It keeps the settings you choose to sync available across your computers. You can use the desktop app without Cloud Sync.
Information we handle
- When you sign in with Google or GitHub, we receive your verified email address and that provider's user ID. We use these to identify your Cloud Sync account. We do not receive your provider password.
- We store your synced profile and a revision number. A profile may include your widget appearance, Quick Access layout, alerts, and connection or media preferences. If you enable the app's profile encryption, the service stores the encrypted profile and cannot read its contents. Without it, the service can read the profile.
- We store a hash of each Cloud Sync session token, the device name supplied during sign-in, and session creation and last-use times. The app encrypts its local copy of the token using Electron's secure storage API.
- If you subscribe, we store your Stripe customer and subscription IDs, subscription status, and billing period information. Stripe handles payment details; Cloud Sync does not store your card number.
- Service providers may process network and account information needed to deliver Cloud Sync.
How we use it
We use this information to sign you in, sync your settings, prevent conflicting saves, determine whether your account can save changes, manage subscriptions, and respond to support or security issues. Google and GitHub sign-in is used for identity and email only. We do not use Google or GitHub account data for advertising.
Providers and sharing
Cloudflare hosts the Cloud Sync service and database. Google or GitHub provides sign-in, and Stripe processes subscriptions. We share information with these providers as needed for those functions. We may also disclose information when required by law or to protect the service and its users. Each provider may handle data under its own privacy policy.
Retention and your choices
Signing out removes that device's service session. A session also expires after 180 days without use. The app's Delete Account action first tries to cancel an active subscription. If cancellation fails, the account stays in place so billing is not left running without an account. After successful cancellation, the service deletes your identities, sessions, profile, and subscription record from its active database. Copies may remain temporarily in Cloudflare backup and recovery systems, and Stripe may retain payment records under its own legal obligations.
If your trial or subscription ends, you can still download your stored profile. Saving new changes requires an active entitlement. You can also use the app's free folder sync instead of Cloud Sync.
Security and requests
The service uses HTTPS, stores only hashes of service session tokens, and checks profile revisions before accepting changes. Optional profile encryption is available in the app. To request access, correction, account deletion help, or to report a privacy or security issue, email robertgordon761@gmail.com.
Changes
We will post changes to this page and update its effective date. We will give additional notice when required by applicable law.