Privacy Policy
Effective date: September 25, 2026
This Privacy Policy explains how the “Sanderson Home” application (the “App”), operated by Justin Sanderson (the “Operator”), accesses, uses, stores, and protects information obtained through Google APIs. The App is a personal, single-user integration. Its only user is the Operator, and it is used only with the Operator’s own Google account and devices.
1. Information the App accesses
- Google Nest device data via the Smart Device Management (SDM) API: device names, types, and status (such as temperature, humidity, thermostat mode and setpoints, connectivity, and camera or doorbell events and streams). The App also sends device control commands, such as changing a thermostat setpoint or mode.
- Basic Google account information: the basic profile and email address that Google OAuth sign-in provides, used only to authorize the App.
The App does not collect information about anyone other than the Operator.
2. How the information is used
The App uses this information only to show and control the Operator’s own Nest devices inside the Operator’s own Home Assistant installation, including dashboards and home automations. It is not used for any other purpose.
3. Storage and security
- OAuth access and refresh tokens, and device data, are stored locally on the Operator’s private Home Assistant server on the Operator’s home network.
- That server is not exposed to the public internet. The Operator reaches it only through a private, encrypted network (Tailscale).
- Tokens and device data are not sent to any third party. The only exchange is with Google itself, as the SDM API requires.
4. Sharing, sale, advertising, and analytics
- The App does not sell, rent, trade, or share any user data.
- The App does not show advertising and does not use data for advertising.
- The App uses no analytics, tracking, or profiling tools, and this website sets no cookies.
5. Google API Services User Data Policy (Limited Use)
The App’s use of information received from Google APIs, and its transfer of that information to any other app, will follow the Google API Services User Data Policy, including the Limited Use requirements. Specifically, Google user data is used only to provide the App’s user-facing features described above. It is not transferred to others except as needed to provide those features, to comply with applicable law, or as part of a merger or acquisition. It is not used for advertising. No human reads it except with the user’s consent, for security purposes, or to comply with applicable law.
6. Data retention and deletion
Tokens and device data are kept only as long as the Nest integration stays configured in the Operator’s Home Assistant. Removing the integration from Home Assistant deletes the stored tokens from the local server.
7. How to revoke access
You can revoke the App’s access to your Google account at any time. Go to Google Account › Security › Your connections to third-party apps & services (myaccount.google.com/connections), select the App, and remove its access. You can also revoke access from the Google Nest / Device Access partner connections settings.
8. Children’s privacy
The App is not directed at children and does not knowingly collect information from children.
9. Changes to this policy
If this policy changes, the updated version will be posted on this page with a new effective date.
10. Contact
Questions about this policy can be sent to the Operator, Justin Sanderson, through the Google account that owns the Google Cloud project for this App.