Privacy Policy
Home HVAC Monitor · Last updated: September 20, 2026
Home HVAC Monitor (“the application”) is private home-automation software written and operated by Jason Bakos (“the owner”) for use in the owner’s own home. It is not a public service, has no sign-up or customer accounts, and is used only by its owner. This policy explains exactly what Google/Nest data the application accesses, how they are stored and used, and how they can be deleted.
1. Who this policy covers
The application has a single user: its owner, who authorizes access to the owner’s own Google account and Nest thermostats. No one else can sign in, and the application does not collect data from members of the public. This website (the static pages you are reading) collects no personal information, sets no cookies, runs no analytics, and loads no third-party resources. Like any web host, the static hosting service may keep ordinary access logs (such as IP address and time of request) of visits to these pages; no thermostat or Google user data are stored on this website.
2. Google user data the application accesses
API and scope
The application uses Google’s Smart Device Management (SDM) API, and requests exactly one OAuth scope:
https://www.googleapis.com/auth/sdm.service– access to the Nest devices the owner chooses to share with the application through Google’s Nest device-access consent screen.
No other Google OAuth scope is requested. The application does not access the owner’s email, contacts, calendar, photos, files, profile information, or location, and it does not access cameras, doorbells, microphones, or video.
Read-only use
The application only reads data: it requests the device list at start-up to find the two configured thermostats, requests each thermostat’s current state about once per minute, and receives change-event messages. It contains no code that sends commands to a device and never changes a setpoint, mode, fan setting, or any other device setting. Information returned about any other device is discarded and not stored.
Data collected
| Data | Details |
|---|---|
| Temperature | Ambient temperature measured by each thermostat |
| Humidity | Ambient relative humidity measured by each thermostat |
| Setpoints | Cooling and heating target temperatures |
| HVAC operating state | Whether the system is off, heating, or cooling; heating/cooling run time and duty cycle are derived from this |
| Thermostat mode | For example heat, cool, heat-cool, or off |
| Connectivity | Whether each thermostat is online |
| Fan timer mode | Whether the fan timer is on or off |
| Device and event identifiers | Google-issued device resource names/IDs and event or message IDs, plus timestamps, and the owner’s own zone labels (“upstairs” and “downstairs”). The complete event message received from Google is stored as delivered, so it may also contain other identifiers Google includes in event messages, such as an opaque user identifier. |
Temperature and HVAC run-time patterns can indirectly indicate when a home is occupied, so the owner treats these data as private.
How the data are obtained
- Polling: once per minute, the application asks the SDM API for the current state of each thermostat.
- Events: Google delivers thermostat change events through a Google Cloud Pub/Sub subscription in the owner’s own Google Cloud project, which the application reads.
- Owner’s own history export: the owner has also loaded historical thermostat runtime records (interval times, indoor temperature, heating/cooling time, target temperatures, and outdoor temperature) from a Google Takeout export of the owner’s own account. These were exported and imported manually by the owner and are not obtained through OAuth.
3. How the data are used
The data are used only for the owner’s personal HVAC monitoring, diagnostics, historical analysis, and performance characterization. This includes charting temperature, setpoint, and run time; measuring how quickly each zone’s temperature responds while cooling or heating; comparing zones under similar conditions; and noticing changes over time, such as after equipment service. The results are shown on a private dashboard operated by the owner, for the owner’s own use.
The application computes statistical summaries and baselines of the owner’s own HVAC performance from the owner’s own data. It does not use Google user data to develop, improve, or train generalized artificial-intelligence or machine-learning models, and it does not use the data for advertising, marketing, profiling, credit or insurance decisions, or any purpose unrelated to monitoring the owner’s home HVAC systems.
4. Where and how the data are stored
- Private home server. Collected data are stored in a SQLite database on a computer in the owner’s home that the owner operates. The application does not send the data to any cloud database, analytics service, or data processor.
- Credentials. The OAuth client secret and refresh token are kept in a local file readable only by the account that runs the application. Short-lived access tokens are held in memory only. All communication with Google APIs uses HTTPS.
- Derived files and backups. Summary files generated for the owner’s dashboard, and occasional manual backup copies of the database, are kept on the owner’s own systems.
- Logs. Operating-system logs on the server may briefly include recent readings.
- Google-side transport. Event messages wait in the owner’s Google Cloud Pub/Sub subscription until the application receives them; that transient storage is provided by Google.
5. Sharing, disclosure, and sale
Google user data are not sold and are not used for advertising, including retargeting or interest-based advertising. They are not shared with or transferred to third parties for their own purposes. The only parties that touch the data or the application are:
- Google, which is the source of the data and provides the Pub/Sub message delivery inside the owner’s own Google Cloud project.
- Open-Meteo (a public weather service), which receives a request for outdoor weather containing only approximate, city-level coordinates from the application’s configuration. No thermostat data or Google user data are included in that request.
- The owner’s development and analysis tools. When the owner develops or troubleshoots the software, query results or excerpts of the stored data (for example temperatures and HVAC on/off times) may be viewed in tools the owner uses, including AI-assisted coding tools, at the owner’s direction and only to help the owner analyze the owner’s own data. This is the owner’s own use of the owner’s own data; it is not a disclosure to any other user or customer, and those tools are governed by the owner’s own account terms with them.
- Legal requirements. Data could be disclosed if the owner were legally required to do so.
6. Google API Services User Data Policy – Limited Use
Home HVAC Monitor’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- Google user data are used only to provide and improve the application’s user-facing HVAC monitoring and analysis features for the owner.
- Google user data are not transferred to others except at the owner’s direction as described in Section 5, as needed for security or abuse prevention, or to comply with applicable law.
- Google user data are not used or transferred for serving advertisements, and are not sold.
- Humans do not read the data except the owner viewing the owner’s own data, where needed for security or abuse investigation, or where required by law.
- Google user data are not used to develop, improve, or train generalized AI or machine-learning models.
7. Retention and deletion
The application does not automatically delete collected data. It keeps the full history of thermostat readings and event messages, because long-term history is the purpose of the application, until the owner deletes them. Because the application has a single owner, the owner controls deletion directly:
- Delete stored data: the owner can delete the database, its backup copies, and generated summary files at any time.
- Stop collection and revoke access: the owner can stop the application and remove its access in the Google Account’s third-party access settings (or by removing the Device Access authorization). After access is revoked, the application can no longer retrieve new data. Data already collected remain on the owner’s systems until the owner deletes them.
- Delete credentials: deleting the local credentials file removes the application’s stored ability to access Google APIs.
If you believe the application holds information about you (for example, you live in the home) and want it deleted, contact the owner using the address below.
8. Children
The application is not directed to children and does not knowingly collect information from children.
9. Changes to this policy
If the application’s data practices change, this page will be updated and the “Last updated” date above will change. The application will not use Google user data in a way materially different from this policy without updating it first.
10. Contact
Questions or requests about this policy or the application’s data can be sent to the owner, Jason Bakos, at jason.bakos@gmail.com.