We do not operate a server
Do It Up runs no backend for these apps. There is no sign-up, no account, no profile, and no login. Nothing you enter is sent to us, and we have no ability to see, retrieve, or delete your data — because we never receive it in the first place.
That is a statement about the app. Writing to us is different, and obviously so: a message you send reaches a mailbox we read. See if you write to us.
Entitlement, where it applies, is handled entirely by Google Play under Google’s own terms. We do not receive your payment details.
What is stored on your device
Hearth stores the following locally, on the device only:
| What | Why | How |
|---|---|---|
| Home Assistant address and access token | To connect to your home automation system | Encrypted — Android Keystore |
| IPTV provider address, username, password | To load your channels and guide | Encrypted — Android Keystore |
| Preferences — favourites, channel groups, watch history, theme, layout, hidden rooms | To keep the app set up the way you left it | Standard app storage |
| Programme guide cache | So the guide loads without re-downloading | Local database |
Credentials are held in Keystore-backed encrypted storage, so the stored file is ciphertext rather than plain text. This protects them at rest, on the device. It says nothing about how they travel to the service they belong to — see Providers without encryption below. It is also not a defence against someone with physical or administrative control of an unlocked device.
Automatic cloud backup is disabled for these apps, so your credentials are not copied into Google’s backup service.
Uninstalling the app removes everything above. There is no separate deletion request to make, because there is no copy anywhere else.
Who your device talks to
The app makes network connections only to services you have chosen or that the platform provides. None of them are operated by us.
Your Home Assistant server
The address is one you supply, usually on your own local network. Your access token is sent to it to authenticate, exactly as any Home Assistant client does. Your home data does not pass through us.
Your IPTV provider
The address and credentials are ones you supply. Your provider necessarily sees your requests — what you play and when — and handles that under their privacy policy, not this one.
Channel logos and artwork are frequently hosted on third-party content networks referenced by your provider’s playlist; loading them contacts those hosts directly. Some of those hosts offer no encryption, and the app loads pictures from them anyway rather than leaving the channel blank — so which logos your device fetches, and therefore which channels you are browsing, can be seen by anyone on your network. This applies to images only: everything else is held to the rule below.
The app always tries to reach your provider over an encrypted connection (HTTPS) first. Many IPTV providers do not offer one. If yours does not, the app will ask you before connecting, and will tell you what it means: over an unencrypted connection your provider username and password are sent in the clear — the Xtream protocol places them in the address of every request, including every stream — and what you are watching is visible to anyone on your network and to your internet service provider.
If you agree to that, the exception applies to that one provider address. Your Home Assistant connection and everything else are unaffected. Aside from the channel artwork described above, unencrypted connections elsewhere remain refused — and an unencrypted response that is not a picture is refused too. Connecting to a different provider asks again, and uninstalling the app removes it with everything else.
Voice search
Voice search uses Android’s built-in speech recognition. When you activate it, audio is handled by your device’s speech recognition provider — typically Google — under that provider’s privacy policy. We do not record, store, or receive audio. The microphone is active only while a voice search is running, and is released as soon as it returns a result or you dismiss it.
What we do not do
Permissions, and why each is needed
| Permission | Used for |
|---|---|
| Internet, network state | Reaching your Home Assistant server and IPTV provider |
| Microphone | Voice search only. Nothing else in the app uses the microphone — the audio visualiser shown for radio channels reads the audio Hearth is already playing, not the microphone |
| Display over other apps | Showing Home Assistant alerts on top of whatever is playing |
| Foreground service | Keeping that alert service running |
| Run at startup | Starting as your launcher when the device boots |
| Notifications | Showing app notifications |
| Accessibility service (optional) | Making the HOME button return to Hearth on devices that ignore the launcher setting, and turning the screen off from the Sleep control. You switch it on yourself in Android’s settings; the app runs without it |
The accessibility service cannot read your screen. It is declared without canRetrieveWindowContent — the capability that would let a service see the contents of other apps. It receives only the name of the app coming to the foreground, which is what tells it the HOME button was pressed, and nothing about what is on screen or what you type.
Location permission is not requested.
If you write to us
Everything above is about the app, and about a device we never hear from. This section is the other case: you sending us a message, which is the only way we come to hold anything about you at all.
We do not ask for it, there is no form to fill in, and nothing on our website collects it. What we have is what you chose to put in an email.
| What | Why | How long |
|---|---|---|
| Your email address | To reply — and, if you asked to test Hearth, to enrol you in the test | While the test runs, or while the conversation is useful |
| Whatever you tell us — which TV box you have, whether you run Home Assistant, what went wrong | To answer you, and to know what the app has to cope with | Kept with the message |
Whichever address you write to, the mail arrives in a mailbox we hold with a third-party email provider, as almost all mail does, and is read by us. It is not fed into a mailing list, a newsletter, a CRM, or any analytics, because none of those exist here.
Hearth is in closed testing, and access is granted by Google account rather than by download. If you ask to take part, the address you send us is entered into the tester list in Google Play Console — that is the mechanism Google provides, and there is no way to give you the app without it. Google handles that list under its own terms, as the operator of the store.
That is the whole of it. The address is used to grant access and to talk to you about the app, and for nothing else.
Ask at any time and we will take you off the list. Doing so ends your access to the test build — that is what being on the list is — and the address goes with it. When the closed test ends, the list is deleted.
Our website has no form, no account, and nothing to sign in to, and it runs no analytics.
Children
These apps are not directed at children, and the apps collect no personal information from users of any age. We do not knowingly seek information from a child by any other route either.
Changes
If this policy changes, the updated version is published at this address with a new date at the top. Material changes affecting how your information is handled will be reflected here before the corresponding app update ships.
Contact
Questions about this policy:
privacy@doitup.ca