Privacy Policy
What the app does with your network
TV Remote talks directly to your TV over your local Wi-Fi network to discover it, pair with it, and send remote-control commands. Remote-control traffic never leaves your home network and never passes through our servers.
We do run one small server, but it exists only to receive the diagnostic reports described below. Those reports are not linked to your identity. The server never relays your raw remote-control traffic and does not receive pairing credentials. When diagnostics are on and a report is triggered, however, the report can include recent diagnostic log entries about control actions, including button names and app names or identifiers, as described below.
iOS will ask for the Local Network permission the first time you scan. To find your TV the app looks for AirPlay services on your network and briefly probes the TV control ports (8001, 3001, 3000, 8060) on your local subnet. It never builds or transmits an inventory of the other devices on your network.
What is stored on your device
The app stores a profile for each TV in its local database: the name and model the TV reports about itself, its IP address and port, its MAC address (used to send a wake-up packet so you can turn the TV on), and the TV's own device identifier. Pairing credentials - Samsung tokens and LG client keys - are stored separately in the iOS Keychain and are not synced to iCloud.
The app never uploads any of this. It stays on your iPhone and is removed when you delete the corresponding TV or uninstall the app (Keychain items may persist per standard iOS behavior until overwritten).
Diagnostics
Because we cannot test every TV model ourselves, the app can send a diagnostic report that is not linked to your identity when a TV fails to connect, or when the TV rejects a command you sent (for example a button it refuses in its current mode). Nothing is sent while the app is working normally: there is no usage tracking, no heartbeat, and no analytics of any kind.
What a report contains. The failure reason; the TV brand and connection protocol; your app version; your iOS version; your device model (for example "iPhone15,2"); the time of the failure; and the last 40 lines of the app's in-memory log, each shortened to 200 characters. Those lines can include recent button or key names and app-launch or app-list status, including app names or identifiers; they do not contain the text you type or raw command payloads. The app does not populate the report's optional TV vendor and model fields. Of the log lines, the server keeps only the 20 most recent and discards the rest on arrival.
What is removed or masked first. Before sending, the app removes exact known TV names, service names, hostnames, and device identifiers; strips common MAC-address formats, IPv6 addresses in full, compressed, or scoped link-local form, and long secret-looking strings of 20 characters or more; and masks exact IPv4 addresses down to their network (192.168.1.57 becomes 192.168.1.0/24). Connection code is designed never to write Samsung tokens, LG client keys, or pairing PINs into diagnostic logs; stripping long token-like values provides a second layer of protection. Short codes such as a 4-6 digit pairing PIN do not match that generic long-secret rule. Pattern matching cannot identify every unexpected piece of arbitrary free text, which is why connection logs use fixed phases and safe error fingerprints instead of raw system error descriptions.
Who receives it. A server we operate ourselves on Cloudflare, which stores the reports in a Cloudflare D1 database. No third-party analytics company is involved at any point. As with any request over the internet, Cloudflare's network necessarily sees the IP address your report is sent from. Our Worker uses that edge-provided IP address as a temporary per-IP abuse-control key, allowing up to 20 report requests per 60 seconds. The IP address is not added to the diagnostic report or stored in our D1 database.
How long it is kept. Reports become eligible for deletion 30 days after they reach the server. A scheduled job runs daily and removes reports older than 30 days, so a report may remain until the next daily run, for up to approximately 31 days in total. Because reports are not tied to a name or account, we cannot reliably locate one person's past reports for deletion during that period; they expire through the scheduled process.
How it is tagged. Each report carries a random identifier generated for this installation - not your name, not your Apple ID, and not any Apple device identifier. The app keeps a local copy and the server stores the identifier with each report, letting us group reports from the same installation during the retention period without identifying the person using it. Deleting the app discards the local copy, so a reinstall produces a new identifier that cannot be linked to the old one. This is the "Other Diagnostic Data (not linked to you, not used for tracking)" entry on the App Store privacy label.
Turning it on or off. When your iPhone's Region setting is set to the EEA or the UK, diagnostics start switched off - nothing is sent unless you turn them on yourself. With other Region settings they are on by default and you can turn them off at any time. The app uses this Region setting, not your physical location, to choose the initial default. Either way the switch is under Settings › Privacy & Diagnostics › Diagnostics, where the app also explains what a report contains. To be accurate rather than reassuring: with a Region setting outside the EEA/UK the app does not interrupt you with a first-launch notice about this, so a failure can be reported before you have read this page or opened that screen.
Microphone and dictation
The optional voice-input feature runs only while dictation is active, and only after you tap the mic button. Speech is turned into text by Apple's speech recognition, which decides on its own whether to do that on your device or on Apple's servers, under Apple's privacy policy. We never receive, store, or transmit your voice or the recognized text - it goes to the search field you send to your TV.
Advertising (free version only)
The free version shows ads - banners, occasional full-screen interstitials, and native ad cards - served by Google AdMob, which may mediate ads from partner networks we enable. To do this the AdMob SDK collects device information such as device identifiers (including, only if you allow App Tracking Transparency, the advertising identifier/IDFA) and ad-interaction data, under Google's privacy policy.
Your choices. Where required (for example in the EEA/UK) a consent form is shown before any ad is requested, and iOS asks separately for tracking permission (ATT). If you decline consent where it is required, the advertising SDK is never started at all and no ad is requested. Declining either prompt still lets you use every feature of the app - at most you simply get non-personalized ads. You can reopen your consent choices at any time in Settings → Privacy & Diagnostics → Ad Privacy Choices (the row appears where those choices apply). Ad networks receive standard request data; we ourselves receive none of it and run no ad servers.
Removing ads. The one-time Pro purchase removes every ad permanently. For Pro users the advertising SDK is not initialized at all, so none of the collection described above happens.
Purchases
The optional Pro upgrade is a one-time purchase. Payment is processed entirely by Apple through the App Store - we never see your payment details.
To validate the purchase and restore it across reinstalls, the app uses RevenueCat, a purchase-infrastructure service. What RevenueCat receives: the App Store purchase receipt and a randomly generated anonymous identifier - no name, no email, no account, nothing that identifies you. This is the "Purchase History (not linked to your identity)" entry on the App Store privacy label. It is never used for advertising or tracking.
Children
TV Remote is a general-audience utility and does not knowingly collect any information from anyone, including children.
Changes
If this policy ever changes (for example, if a future feature required any data), the new version will be posted at this address with a new effective date before the feature ships.
Contact
Questions? Email [email protected].