CTRLbot IoT for Android
Privacy Policy
Last updated: July 25, 2026
CTRLbot IoT is designed primarily for local device control. The current version does not require a CTRLbot account and does not upload device configurations, credentials, commands, presets, or usage history to CTRLbot-operated servers. The current version also has no advertising, analytics, telemetry, or crash-reporting service.
Who we are
This Privacy Policy applies to CTRLbot IoT (package io.ctrlbot.iot), provided by CTRLbot.
Data stored on your device
The current version stores the information you enter or create, including device names and locations, network addresses and ports, connection settings, presets, switching configurations, credentials, SSH host keys, and app preferences. This information remains in the app's local storage unless you direct the app to communicate with a device or open a website.
Optional future services
CTRLbot may introduce optional account, backup, synchronization, or sharing services in the future. Before any such feature handles user data, CTRLbot will describe the information it collects or uploads, explain how that information is used, provide applicable user controls, and update this Privacy Policy. Credentials and SSH host keys will not be included in a future synchronization feature unless that handling is separately and explicitly disclosed.
Credential and host-key security
Usernames, passwords, and SSH host keys are encrypted at rest using Android Keystore-backed encrypted preferences. Credentials may be held briefly in memory while a connection is active; the in-memory credential cache expires after 15 minutes. CTRLbot IoT does not include credentials in its application logs.
Device communication
CTRLbot IoT uses network access to connect directly to the device addresses you configure. Depending on your selected protocol, this can include TCP, Telnet, SSH, or a Global Cache serial or IR endpoint. Authentication information is sent only to the device you configure when required for that connection. SSH encrypts its connection; Telnet and other plain-text device protocols do not. The app warns before using Telnet.
Websites and third parties
When you choose a CTRLbot, manufacturer, or product link, the app may load that site in an in-app browser or your external browser. The website can receive ordinary web-request information such as your IP address, user agent, and any data you choose to provide. Those sites operate under their own privacy policies. CTRLbot IoT does not add tracking to those requests and does not sell or share your locally stored app data with those sites or other third parties.
Permissions
INTERNET is used for device communication and for websites you choose to open. ACCESS_WIFI_STATE is used for network and connection features. The app does not request location, contacts, camera, microphone, storage, or advertising-ID permissions.
Retention and deletion
Local configuration data remains until you delete it, use Factory Reset, clear the app's storage, or uninstall the app. Stored credentials and SSH host keys can also be cleared separately from Privacy & Security. Android backup is disabled for CTRLbot IoT. Data received independently by a website or a device you control is governed by that third party or device and is not deleted by CTRLbot IoT.
Children
CTRLbot IoT is a professional device-control tool and is not directed to children under 13. The app does not knowingly collect personal information from children.
Changes to this policy
This policy may be updated when the app's features or data practices change. Before an account or cloud feature begins handling user data, the revised policy and its updated date will be included with an app update and published on this page.
Contact
Privacy questions can be submitted using the developer contact shown on the CTRLbot IoT Google Play listing.
Home