# HAAC

> HAAC is a native Android app for Home Assistant: the admin shares single devices with each user, with schedules, history and no tracking. Open source.

Home Assistant for the whole family. Everyone sees only what was shared with them.

HAAC is a native Android app for Home Assistant. The admin shares single switches, sensors and climate devices with each user, and everyone builds their own home from them, with places, levels and rooms.

## Specifications

- Version: 0.3.1 (sideload APK)
- Platform: Android 9 or newer
- Server: Home Assistant 2026.9 + HAAC Bridge
- Devices: switch · sensor · climate
- Languages: German, English
- Design: Sage, light and dark
- License: Apache 2.0, Open Source
- Tracking: none

## Links

- [Download v0.3.1](https://github.com/stacknoise/haac-android/releases/latest)
- [GitHub](https://github.com/stacknoise/haac-android)

## How it works

The bridge decides what gets through.

Home Assistant has no per-entity permissions. The official Companion App therefore shows every user everything they can reach: every socket, every sensor, every heater.

With HAAC Bridge the admin decides, user by user, what the app may show and control. A user who is not configured sees nothing.

Home Assistant with five devices, behind it the HAAC Bridge. Anna gets two devices, the guest one, a user who is not configured none.

## Features

### Sharing per user

The admin decides in the Home Assistant UI or in YAML who sees which devices: whole domains, single entities and wildcards, each with excludes. The default is: nothing.

Tags: Deny by default, Wildcards, Excludes

### Your own home

Places, levels and rooms right on the phone, tiles in three sizes with drag and drop and local names that never change Home Assistant. Imported from the Home Assistant areas if you like.

Tags: 1×1 · 2×1 · 2×2, 16 icons, Import

### Control

Switches right on the tile, climate devices with a dial, HVAC mode, fan and target range. Live states over a persistent connection that reconnects by itself after a network change.

Tags: switch, sensor, climate

### Schedules

“Every weekday at 06:45 turn the light on”, also at sunrise or sunset. Schedules run in the bridge on the server, so they work with the app closed or the phone off.

Tags: Weekdays, Sunrise/sunset, Server-side

### History and notifications

Charts for 24 hours, 7 days or a custom period. A list reports new or removed devices, paused schedules and errors, each with a plain-language message and an error code.

Tags: Statistics, Timeline, HAAC-…

### Secure by design

Only the refresh token is stored, encrypted in the Android Keystore. Fingerprint unlock, certificate pinning for self-signed servers, no analytics, no ads, no tracking.

Tags: Keystore, Biometrics, No tracking

## Components

### HAAC (Android · Kotlin)

The app on the phone. Builds places, levels and rooms, shows tiles, history and notifications. Talks only to the bridge, never to Home Assistant's generic APIs.

- [stacknoise/haac-android](https://github.com/stacknoise/haac-android)

### HAAC Bridge (Home Assistant · Python)

The integration on the server, installed through HACS. Filters per user, sets the target of every command itself and runs the schedules.

- [stacknoise/haac-bridge](https://github.com/stacknoise/haac-bridge)

## Installation

- 1 · HACS → Custom repositories
  `https://github.com/stacknoise/haac-bridge (Integration)`
- 2 · Settings → Devices & services → HAAC Bridge → Configure
- 3 · Download and verify the APK
  `sha256sum haac-v0.3.1-sideload.apk`

## Screenshots

- Rooms
- Places
- Edit layout
- Add entities
- New schedule
- Sign in

## FAQ

### Is this a real Home Assistant permission?

No. HAAC limits what the app shows and controls. Someone holding a user's token can still use Home Assistant's standard API. So create a dedicated non-admin user for each person.

### Is HAAC on Google Play?

Not yet. Version 0.3.1 is available as a signed APK on GitHub Releases, with a SHA-256 checksum next to it.

### Can I try the app without a server?

Yes. “Try the demo” on the first screen opens an instance with sample data, without a network or a login.

### What data does the app collect?

None for me or any third party. The app talks only to your own Home Assistant server. The details are in the app's privacy policy.

_HAAC is not affiliated with or endorsed by Home Assistant, the Open Home Foundation or Nabu Casa._

## App privacy policy

Last updated: 2 October 2026 · https://www.stacknoise.com/en/haac/privacy/

### Who is responsible

Anton Graichen-Hartl, Stacknoise  
Glinzendorferstraße 10, 2281 Raasdorf, Austria  
Email: anton.hartl@stacknoise.com

This policy covers the Android app “HAAC – HA Android Client” (package com.stacknoise.haac). HAAC is not affiliated with or endorsed by Home Assistant, the Open Home Foundation or Nabu Casa.

### In short

HAAC does not send any data to the developer or to any third party. It has no user account with the developer, no analytics, no advertising and no tracking. All data stays on your phone or travels only between your phone and your own Home Assistant server.

### What the app stores on your phone

The sign-in token of your Home Assistant account (the refresh token), encrypted with a key in the Android Keystore. Your password is used once to sign in at your Home Assistant server and is never stored.

The addresses and names of your Home Assistant instances, and the certificate key of a self-signed server you chose to trust.

Your homes, levels and rooms, the entities you placed in them with their local names and sizes, a copy of the schedules, the notification list, and your settings (for example the design).

This data is excluded from Android's cloud backup and device transfer. It is deleted when you remove an instance (the token is revoked at your server) or uninstall the app.

### What the app sends, and where to

The app talks only to the Home Assistant servers whose addresses you entered or chose from the search in your network. It sends your sign-in and your commands (for example switching a device) and receives the states, history and schedules that your administrator shared with you through HAAC Bridge. Your Home Assistant administrator operates that server and is responsible for the data on it. The developer has no access.

### Permissions

Internet and network state: to reach your Home Assistant server and to choose between its internal and external address.

Local network (Android 17 and newer): to find Home Assistant servers in your home network. The search runs only on your own network.

Biometrics (optional): fingerprint unlock is done by Android. The app only learns whether it succeeded and never sees fingerprint data.

### Screens

Sign-in and settings screens are hidden from screenshots and from the recent-apps preview.

### Google Play and GitHub

If you install from Google Play, Google processes data about the installation and, if you allow it, crash and performance reports under its own privacy policy; the developer sees only anonymous statistics in the Play Console. If you download the APK from GitHub, GitHub's privacy policy applies to the download.

### Children

The app is not directed at children.

### Your rights

Because the developer does not process personal data through the app, there is nothing stored with the developer to access, correct or delete. You can ask questions or file complaints at the contact above, or at your data protection authority (in Austria: the Datenschutzbehörde).

### Changes

A changed policy is published on this page with a new date.

## Contact

- Developer: Anton Graichen-Hartl, Stacknoise (https://www.stacknoise.com/en/)
- E-Mail: anton.hartl@stacknoise.com
- GitHub: https://github.com/stacknoise
- Web page: https://www.stacknoise.com/en/haac/
- Deutsche Version: https://www.stacknoise.com/haac.md
