OneMote Privacy Policy
Effective date: 2026-08-03
Live URL: https://shakermm.github.io/privacy
OneMote (“the app”, “we”, “us”) controls smart TVs on your home WiFi network. This policy explains what the app does and does not collect.
What OneMote does
- Discovers Roku, Samsung, LG, Sony, Vizio, Android TV / Google TV, Fire TV, and Apple TV devices on your local WiFi network using standard device-discovery protocols (SSDP and Bonjour/mDNS).
- Sends remote-control commands (keypresses, app launches, input switching, and text you type) directly from your phone to your TV over your local network. These commands never pass through our servers — there are none.
- Casts photos and videos you pick, and mirrors your phone screen, directly from your phone to your TV over your local network. Your media is served straight to the TV and is never uploaded anywhere.
- Recognizes voice search and dictation on your phone using your device’s built-in speech recognition. Audio is never sent to our servers — there are none.
- Private listening (Roku only): when you turn on the headphone button, your Roku sends its own audio to your phone over your local network, where the app decodes it and plays it through your headphones. This audio flows from the TV to your phone only, is never recorded, stored, or written to disk, and never leaves your local network — it is discarded as it plays. Your phone’s microphone is not used for this feature. On Android, a foreground-service notification appears while it is playing so the audio can continue with the screen off; turning the feature off ends the stream immediately.
- Looks up movies and TV shows when you use the What to Watch search: the title you type is sent to third-party catalog services — TMDB (The Movie Database), TVmaze, Wikidata / Wikipedia, and Apple’s iTunes Search API — to fetch results, posters, ratings, and streaming availability. Only the title text you search is sent; no account, name, or advertising identifier is attached, and we run no servers that could store your searches.
- Stores your saved TVs (name, IP address, a brand-specific pairing token or key, and — if you use the optional “Advanced settings” editor for a TV — a manually-set IP/MAC address and a short private note you type) on your phone only, so you don’t have to pair again each time. The Advanced settings editor never sends anything anywhere on its own; it just changes what’s stored on your phone.
- Kid-safe handoff PIN: when you set a 4-digit PIN for Kid-safe mode, OneMote stores only a salted hash of that PIN on your phone. The PIN (and the active lock / volume counter) is never sent anywhere and is never included in a device backup export. Per-TV allowed-app lists for Kid-safe may ride along in personalization when you export; importing a backup never turns Kid-safe on automatically.
- Remembers, per TV, a short list of text you’ve recently sent from the on-screen keyboard (e.g. a search term or Wi-Fi password you typed) so you can send it again with one tap, stored on your phone only. You can turn off “Save to recents” before sending anything you don’t want remembered (on by default), and you can clear a TV’s list at any time from the keyboard sheet. This list is never transmitted anywhere except when you send an entry to your TV — with one exception, see Export below.
- Home-screen widget buttons work without opening the app. On both Android and iOS, tapping a widget button (volume, mute, play/pause, or a starred app tile) can send that command directly from your phone to your TV over your local network, without launching OneMote — the same as pressing that button inside the app. On iOS this direct-send path exists only for a subset of brands and commands (Roku, Sony, Vizio, Fire TV, Samsung, and LG, for the specific buttons each supports); everything else still opens the app first, the same as before this feature existed. Kid-safe handoff blocks this: while Kid-safe is active, widgets show a “Locked” face and no command is ever sent from a widget tap, on either platform.
- Apple Watch companion (iOS only): when you use the optional OneMote watch app, your paired iPhone sends a small device directory to the watch (TV names, which quick buttons each TV supports, and a last-known connection hint). This copy does not include TV addresses, pairing tokens, or any credentials — the watch never talks to your TV directly; every button tap sends a command to your iPhone, which then controls the TV the same way as a widget or quick action. While Kid-safe is active, the directory sent to the watch lists no sendable buttons. This data flows only between your iPhone and your paired Apple Watch via Apple’s WatchConnectivity; we have no servers involved.
- Wear OS companion (Android only): when you use the optional OneMote Wear app or Tile, your paired phone sends the same kind of small device directory to the watch (TV names, supported quick buttons, connection hint — no addresses, pairing tokens, or credentials). The watch never talks to your TV directly; every tap is relayed to your phone over Google’s Wear Data Layer, and the phone controls the TV. While Kid-safe is active, the directory lists no sendable buttons. This data persists on the paired Wear device as a Data Layer item until replaced; we have no servers involved.
- Lets you export your saved TVs to a file (Settings → Export devices) and share it however you choose — AirDrop, Messages, email, cloud storage — and import such a file back in. This only happens when you tap Export or Import; OneMote never sends this data anywhere on its own. Along with your saved TVs, the file carries your on-device personalization for those TVs (starred/recent channels, apps, and inputs; custom input labels; per-TV D-pad/touchpad preference; optional Kid-safe allowed-app lists) and your app-wide settings (theme/appearance, language, and your streaming watchlist) so restoring on a new phone brings these back too. You choose whether the exported file includes pairing tokens/keys (a toggle, on by default) — that same toggle also controls whether your recently-sent keyboard text (see above) is included, since it can contain things like typed passwords. If pairing tokens are included, whoever receives that file can control the TVs in it without re-pairing, so treat it like a key, not a plain settings file. The file never contains any purchase, ad-free, or promo-code state, and never contains a Kid-safe PIN hash or lock state, regardless of that toggle. Importing an older backup file (made before this file could carry personalization) still works — it just restores the TV list without the extra personalization.
- Share my TVs (pointer handoff): when you choose Share my TVs / Share this TV, OneMote can briefly serve a one-time backup of the selected TVs from your phone to another phone on the same local Wi‑Fi — nothing is written to a disk file for this flow, and the payload never goes through OneMote servers (there are none). The scannable link is an HTTPS page on this site whose URL fragment holds only a short LAN pointer and optional TV identity info (name, address, brand) — browsers do not send that fragment to GitHub Pages, so our hosting logs never see it. Pairing credentials are off by default; if you turn them on, whoever completes the handoff can control those TVs without re-pairing, same care as Export. If the phones are not on the same Wi‑Fi, the other phone may still add TV identities and pair normally. The code expires in about a minute or after one successful transfer.
Data we do NOT collect
- No accounts, no sign-up. OneMote has no login.
- No personal data leaves your device or your local network. TV control traffic stays on your WiFi.
- Your TV viewing habits and typed text are never read or transmitted to anyone — text you type on the remote is sent only to the TV you are controlling. The one on-device exception is the keyboard’s optional “recently sent” list described above (off by a per-send toggle, clearable any time) — that text stays on your phone and is never sent anywhere but your TV, unless you deliberately choose to include it in an exported backup file (see Export above), which only you can trigger. The only network exception is the What to Watch search described above: title lookups go to public catalog services, never to us, and are not linked to you.
- Photos, videos, mirrored screen content, voice audio, and private-listening TV audio never leave your local network and are never uploaded to any server. Private-listening audio is played and discarded — never recorded or saved.
Advertising
OneMote is free and supported by banner ads served by Google AdMob:
- We use Google’s User Messaging Platform (UMP) to request consent where required (e.g., under GDPR in the European Economic Area) and Apple’s App Tracking Transparency (ATT) prompt on iOS.
- If you decline ad tracking or consent, ads are non-personalized — and in regions where consent is legally required, we simply show no ads at all. No consent prompts are shown after you decline tracking.
- AdMob may use your device’s advertising identifier and approximate location to serve and measure ads only where you have granted permission and where local law allows. See Google’s privacy policy.
- Ads never appear over the remote controls, never interrupt a command, and never read your TV input.
- If you are offline or the ad fails to load, the ad space simply stays empty — every remote feature keeps working.
In-app purchases (tip jar)
OneMote offers an optional, never-prompted tip jar in Settings (three one-time amounts). If you choose to tip:
- The purchase is processed entirely by Apple (App Store) or Google (Play Billing) — your payment method, card details, and billing information go to Apple/Google, never to us. We have no servers to send them to.
- The only thing OneMote reads back from the store is the purchase result (which item you bought), used solely to unlock the corresponding perk on your phone — either permanently removing ads, or unlocking a couple of extra accent-color options. This is not linked to your name, email, or any account, because OneMote has none.
- A Restore Purchases action in Settings re-checks your purchase history with Apple/Google (e.g. after reinstalling) to restore what you already bought — this, too, only talks to Apple/Google, never to us.
- Tipping is entirely optional and never affects any remote-control feature — every brand and every function stays free either way.
Permissions used
| Permission |
Why |
| Local Network / multicast (iOS + Android) |
Find and talk to TVs on your WiFi |
| Internet |
Load banner ads and fetch What to Watch search results (title lookups only) |
| WiFi state |
Confirm you’re on WiFi before scanning |
| Microphone + Speech Recognition |
Voice search and dictation, only when you tap the mic — recognized on your phone, never sent to a server |
| Photo Library |
Only when you pick photos or videos to cast — served directly to your TV over your WiFi |
| Screen recording / capture |
Only when you start screen mirroring, and only after you accept your device’s own screen-capture confirmation. What’s captured is streamed straight to your TV over your WiFi and is never recorded, stored, or uploaded |
| Background audio / ongoing notification (Android) |
Keeps private-listening audio playing while your screen is off, and keeps screen mirroring running while you use other apps. A notification is shown for as long as it’s active, and it stops when you turn the feature off |
| Tracking (iOS ATT) |
Show relevant ads, only with your permission |
Data storage & security
- All device data is stored locally in your app’s private storage on the phone. Pairing tokens and client keys are LAN credentials, not user passwords, and stay on the device unless you deliberately export them (see Export/Import above).
- Widget buttons, so they can work without opening the app (see above), read a small, separate copy of some of this data — for the specific brands whose widget buttons can send directly (Roku, Sony, Vizio, Fire TV, Samsung, LG on iOS), that copy includes the TV’s address and, where that brand needs one, a single pairing token or key. This copy lives in a shared, app-private storage area the widget can read (an “App Group” on iOS; private app storage on Android) — it is still only readable by OneMote itself, never leaves your phone, and is never transmitted anywhere but to that TV over your local network. It never includes a private key or any long-term secret credential (those brands’ widget buttons always open the app instead). Other brands’ widget buttons, and the app on Android generally, never place any address or credential in this shared copy at all.
- Media you cast is served from a temporary local cache on your phone that is cleared automatically.
- Uninstalling OneMote deletes all stored data immediately.
Children’s privacy
OneMote is not directed at children under 13 and we do not knowingly collect their data. Ad requests are configured for non-child-directed audiences.
Your choices
- Re-open the consent form at any time in Settings → Ad privacy choices.
- Export, import, or remove all saved TVs in Settings → Devices.
- Reset your device’s advertising identifier or limit ad tracking from your OS privacy settings at any time.
Changes
We may update this policy; material changes will be reflected by the “Effective date” above and, where required, re-prompted via the consent flow.
Questions? Email admin@pharaohdigital.co.