1. Who controls your data
Kazenagi Home is operated by the Kazenagi project operator (“Kazenagi”, “we”, “us”). For privacy questions or requests, contact [email protected]. This policy applies to the public website, Home Portal, central cloud service and connected Kazenagi Link devices.
2. Data we collect
Account and identity data
- Your email address, display name, internal account identifier, email-verification state and a securely hashed password when you use email sign-in.
- If you use or link Google Sign-In: Google’s stable account subject identifier (
sub), verified email address and basic name information needed to create or connect your Kazenagi account. We do not request access to Gmail, Google Drive, contacts or calendars, and we do not store a Google password or Google API refresh token. - Home invitations, membership and role information, room associations, linked sign-in methods and account-security events.
Home, device and environmental data
- Home and room names, time zone, an address or place search you submit, and the resulting latitude and longitude used for local weather and opt-in location-aware features.
- Device identifiers, names, model/profile information, connection state, firmware and operational status.
- Air-conditioner state, target settings, schedules, manual overrides, dry-out jobs, commands, confirmations and execution results.
- Time-stamped environmental readings reported by a connected device, such as temperature and, where supported, humidity and air pressure, together with the operating mode needed to present history.
Technical and communications data
If you opt into Geofencing in the Android App, the phone uses background location even when the App is closed or not in use to determine whether it is near the selected Home. It sends only home, away or unknown, an installation identifier, a sequence counter and a report time to Kazenagi. We do not receive the phone's GPS coordinates or a route history. Google Play services supplies the on-device location/geofence service under Google's terms. The latest report replaces the previous report; room-level status and resulting automation actions may be visible to authorised Home members. Stopping sharing, signing out or revoking location permission stops new location observations; old reports expire to unknown. You can also stop your own registered phone from Home settings.
For an App- or Web-initiated remote Wi-Fi update, that client encrypts the Wi-Fi name, password and optional IP settings for the selected controller. Central relays the encrypted message and records the job outcome; it does not decrypt or store the Wi-Fi password in plaintext. The Web client uses a separate browser-generated maintenance key that is not exportable; signing out revokes its server binding and removes the local key. Encrypted job payloads are cleared when the job finishes or expires. Outcome metadata follows the configured activity-record retention period. The controller separately reports its current network diagnostics, such as Wi-Fi name and IP address, to authorised Home members.
- Essential session records, authentication events, request times and limited infrastructure logs used to operate, diagnose and secure the service. Hosting or network infrastructure may process an IP address and browser/network metadata.
- Verification, password-reset, email-change, invitation and support communications, including delivery status.
- Browser preferences stored locally for theme, language and the last selected Home.
3. How and why we use data
We use the data above to provide the service you request: create and secure accounts; authenticate users; organise Homes, rooms, people and devices; display live and historical status; send and confirm controls; run cloud schedules and dry-out jobs; provide local weather; deliver invitations and account emails; provide support; prevent abuse; diagnose faults; and comply with law.
Where applicable, processing is based on performing our service agreement with you, your consent or deliberate request (including choosing Google Sign-In or entering a location), our legitimate interests in operating and securing the service, and compliance with legal obligations. We do not use personal data for third-party advertising, sell it, or make decisions producing legal or similarly significant effects through profiling.
4. Google user data
Google Sign-In
Google Identity Services is used only to authenticate you and, when you choose, link a Google identity to an existing Kazenagi account. A linked identity is matched by Google’s stable sub, not merely by email. Google-derived data is used only for account access, security and the user-facing features described here. It is not sold, used for advertising, or shared with data brokers. If our use of Google user data changes materially, we will update this policy and seek any consent required before using it for the new purpose.
Google Home Cloud-to-cloud
If you explicitly link Kazenagi to Google Home, Kazenagi and Google exchange only the information needed to discover, display, control and keep your selected devices up to date. This may include:
- an opaque Kazenagi agent-user identifier, account-link status, granted scope and the Home/device selections that you control;
- short-lived authorization codes and Kazenagi OAuth access and refresh credentials exchanged to complete and maintain the link; Kazenagi stores one-way hashes rather than the raw credential values;
- selected device identifiers, names, room assignments, device types, traits, capabilities, device model and firmware version;
- confirmed current online availability, operating mode, target temperature, current room temperature, optional current humidity and fan setting used for Google Home QUERY and Report State;
- commands sent through Google Home and their durable acceptance or execution status used for EXECUTE; and
- limited request, synchronization, delivery and error metadata needed for SYNC, Request Sync, Report State, unlinking, security, retry and support.
Google Home linking does not give Google your Kazenagi password or Kazenagi’s Google service-account private key, nor access to your Gmail, Google Drive, contacts or calendars. We do not send unselected devices, your precise Home address or historical environmental readings to Google Home. Google processes information it receives under Google’s own privacy terms. Kazenagi uses this exchange only to provide the Google Home features you request, protect the link and diagnose delivery.
5. Cookies and local storage
Kazenagi uses a strictly necessary, secure HTTP-only refresh-session cookie to keep you signed in. Short-lived access credentials are held in browser memory. Theme, language and last-Home preferences are stored in local storage. If you use Web remote Wi-Fi maintenance, the browser stores a non-exportable device-bound maintenance key in IndexedDB and Central stores only its public-key binding; signing out revokes and removes it. We currently do not use advertising cookies or third-party behavioural analytics. You can clear browser storage, but doing so may sign you out, reset preferences or require a new maintenance identity.
6. When data is shared
We disclose only what is reasonably necessary to:
- other authorised members of the same Home, according to their role;
- Google Identity Services for the sign-in flow you initiate;
- Google Home and HomeGraph when you explicitly link the integration, limited to the selected-device, confirmed-state, command and synchronization information described in section 4;
- the configured email-delivery provider (such as Mailgun or an encrypted SMTP provider) to send transactional messages;
- Open-Meteo and Nominatim/OpenStreetMap services to resolve a location query and retrieve weather using a location or coordinates;
- hosting, database, storage, network and security providers acting for us under appropriate safeguards;
- authorities or other parties when required by law, needed to protect rights and safety, or involved in a reorganisation with appropriate notice and safeguards.
Service providers may process data in countries outside your own. Where transfer rules apply, we use an appropriate lawful mechanism and limit the data transferred to what the relevant service needs.
7. Retention and deletion
Account, Home and device data is generally kept while the relevant account or Home remains active. Authentication audit events are normally retained for up to 90 days. Expired or revoked refresh-session records are normally removed after a further 7 days. Expired verification, reset and pairing credentials are normally removed after a further 30 days, and expired Home invitations after a further 365 days. Environmental history is normally retained for up to 365 days: recent readings remain as individual reports, older readings become hourly and then daily summaries that retain the real minimum, maximum, average and sample count for each metric. Completed command, schedule, dry-out and OTA activity is retained for up to 730 days; privileged administration, OTA and cloud-entitlement audit evidence for up to seven years. Deletion and compaction run in bounded batches and remain subject to backup rotation and legal preservation requirements.
You can delete your Kazenagi account from Settings after transferring or deleting any Home for which you are the sole owner. Deletion removes active sign-in identities, ordinary sessions and memberships, revokes active credentials, and de-identifies remaining account/audit references where the service supports that lifecycle. Residual copies may remain temporarily in protected backups until normal rotation and will not be used for ordinary service operation.
For Google Home, revoked account-link, Home-grant and device-selection metadata and one-way hashes of revoked OAuth tokens may be retained to enforce revocation, prevent token reuse, preserve ownership and security history, and support safe reauthorization. Completed or superseded Google Home delivery records are normally retained for 30 days; dead-letter delivery records and agent-user deletion audit tombstones are normally retained for up to 730 days; related cloud audit events are normally retained for up to seven years. Related expired or consumed authorization-code records containing a one-way code hash, user ID, redirect URI, granted scope, issued/expiry/consumed times and the selected Home/device consent snapshot, and revoked link, grant, selection and token-hash records currently have no shorter automatic deletion period. They may remain after unlinking or Kazenagi account deletion, subject to access controls, backup rotation and applicable legal deletion requirements.
8. Your choices and rights
The Portal and App let you update your name and email, change or set a password, download a machine-readable account export including accessible recent and summarised environmental history, and delete your account. You can choose not to use Google Sign-In and use email sign-in instead. To request access, correction, deletion, restriction, portability, objection, or help unlinking Google where applicable, email [email protected]. We may need to verify your identity and must protect other Home members’ rights. You may also complain to the data-protection authority that applies to you.
You can globally unlink Kazenagi in the Google Home app. This revokes the entire Google Home account link and its active Kazenagi OAuth credentials for all Homes under that link, and stops future device synchronization, state reporting and commands. In Kazenagi settings, you can instead disconnect a single Home. That revokes only that Home’s grant and device selections; if other Homes remain authorised, the overall account link and its credentials remain active for them. Authorization-code consent snapshots, revoked metadata, token hashes, delivery records and audit records may remain as described in section 7. To manage information already held by Google, use the controls provided in your Google Account and Google Home.
9. Security
We use measures designed to protect data, including HTTPS/WSS transport, hashed passwords and credentials, short-lived signed access tokens, rotating HTTP-only refresh sessions, role-based Home permissions and encrypted storage for configured email-provider secrets. No system is completely secure; please use a unique password, protect your devices and notify us if you suspect unauthorised access.
10. Children
Kazenagi is not directed to children under 13, or below any higher minimum age required where they live. A minor may use a Home only with the permission and supervision required by applicable law. Do not submit a child’s personal data unless you are authorised to do so.
11. Changes
We may update this policy as the service, providers or law changes. We will change the “Last updated” date and provide additional notice when a material change requires it.