Privacy policy
Last updated: 2 October 2026
Who is responsible
Anton Graichen-Hartl, Stacknoise Glinzendorferstraße 10, 2281 Raasdorf, Austria Email: anton.hartl@stacknoise.com
This policy covers the Android app “HAAC – HA Android Client” (package com.stacknoise.haac). HAAC is not affiliated with or endorsed by Home Assistant, the Open Home Foundation or Nabu Casa.
In short
HAAC does not send any data to the developer or to any third party. It has no user account with the developer, no analytics, no advertising and no tracking. All data stays on your phone or travels only between your phone and your own Home Assistant server.
What the app stores on your phone
The sign-in token of your Home Assistant account (the refresh token), encrypted with a key in the Android Keystore. Your password is used once to sign in at your Home Assistant server and is never stored.
The addresses and names of your Home Assistant instances, and the certificate key of a self-signed server you chose to trust.
Your homes, levels and rooms, the entities you placed in them with their local names and sizes, a copy of the schedules, the notification list, and your settings (for example the design).
This data is excluded from Android's cloud backup and device transfer. It is deleted when you remove an instance (the token is revoked at your server) or uninstall the app.
What the app sends, and where to
The app talks only to the Home Assistant servers whose addresses you entered or chose from the search in your network. It sends your sign-in and your commands (for example switching a device) and receives the states, history and schedules that your administrator shared with you through HAAC Bridge. Your Home Assistant administrator operates that server and is responsible for the data on it. The developer has no access.
Permissions
Internet and network state: to reach your Home Assistant server and to choose between its internal and external address.
Local network (Android 17 and newer): to find Home Assistant servers in your home network. The search runs only on your own network.
Biometrics (optional): fingerprint unlock is done by Android. The app only learns whether it succeeded and never sees fingerprint data.
Screens
Sign-in and settings screens are hidden from screenshots and from the recent-apps preview.
Google Play and GitHub
If you install from Google Play, Google processes data about the installation and, if you allow it, crash and performance reports under its own privacy policy; the developer sees only anonymous statistics in the Play Console. If you download the APK from GitHub, GitHub's privacy policy applies to the download.
Children
The app is not directed at children.
Your rights
Because the developer does not process personal data through the app, there is nothing stored with the developer to access, correct or delete. You can ask questions or file complaints at the contact above, or at your data protection authority (in Austria: the Datenschutzbehörde).
Changes
A changed policy is published on this page with a new date.