PRIVACY

CTRLbot IoT for Android Last updated: August 1, 2026

CTRLbot IoT is designed primarily for local device control. The current version does not require a CTRLbot account and does not upload device configurations, credentials, commands, presets, or usage history to CTRLbot-operated servers. The one feature that sends anything off your device to CTRLbot is the optional CTRLbot AI assistant, described below. The current version has no advertising, analytics, telemetry, or crash-reporting service.

Who we are

This Privacy Policy applies to CTRLbot IoT (package io.ctrlbot.iot), provided by CTRLbot.

Data stored on your device

The current version stores the information you enter or create, including device names and locations, network addresses and ports, connection settings, presets, switching configurations, credentials, SSH host keys, and app preferences. This information remains in the app's local storage unless you direct the app to communicate with a device or open a website.

Optional future services

CTRLbot may introduce optional account, backup, synchronization, or sharing services in the future. Before any such feature handles user data, CTRLbot will describe the information it collects or uploads, explain how that information is used, provide applicable user controls, and update this Privacy Policy. Credentials and SSH host keys will not be included in a future synchronization feature unless that handling is separately and explicitly disclosed.

Credential and host-key security

Usernames, passwords, and SSH host keys are encrypted at rest using Android Keystore-backed encrypted preferences. Credentials may be held briefly in memory while a connection is active; the in-memory credential cache expires after 15 minutes. CTRLbot IoT does not include credentials in its application logs.

Device communication

CTRLbot IoT uses network access to connect directly to the device addresses you configure. Depending on your selected protocol, this can include TCP, Telnet, SSH, or a Global Cache serial or IR endpoint. Authentication information is sent only to the device you configure when required for that connection. SSH encrypts its connection; Telnet and other plain-text device protocols do not. The app warns before using Telnet.

CTRLbot AI assistant

CTRLbot IoT includes an optional AI assistant, opened from the CTRLbot menu. It is not required to configure, test, or operate equipment. Opening it loads https://ctrlbot.ai/ in an in-app browser, which identifies itself so the site serves CTRLbot IoT help content rather than the general public experience.

Questions you type there are sent over HTTPS to ctrlbot.ai, which is operated by CTRLbot, and are passed to a third-party AI model provider that generates the response on CTRLbot's behalf and under CTRLbot's instructions. Only the text you type is sent. The assistant has no access to your devices, connections, credentials, presets, switching configuration, or anything else the app stores.

There is no CTRLbot account and no user identifier. A conversation is held under a randomly generated session ID so that follow-up questions have context. That session expires automatically within one hour and is not linked to you, your device, or any earlier conversation. CTRLbot does not use these questions for advertising or for building user profiles.

Because the assistant is a general help tool, do not type customer names, credentials, network details, or other confidential information into it. If an answer is offensive or inaccurate, use the report control shown with the answer.

Websites and third parties

When you choose a CTRLbot, manufacturer, or product link, the app may load that site in an in-app browser or your external browser. The website can receive ordinary web-request information such as your IP address, user agent, and any data you choose to provide. Those sites operate under their own privacy policies. CTRLbot IoT does not add tracking to those requests and does not sell or share your locally stored app data with those sites or other third parties.

The same applies to CTRLbot's own pages: as with any website, the hosting and network providers that deliver ctrlbot.io and ctrlbot.ai receive ordinary web-request information such as IP address and user agent, which is used to deliver, secure, and troubleshoot the service. CTRLbot does not use it to identify you, determine your location, or build a profile.

Permissions

INTERNET is used for direct device communication and for websites you choose to open. The app does not request location, nearby-device, contacts, camera, microphone, storage, or advertising-ID permissions.

Retention and deletion

Local configuration data remains until you delete it, use Factory Reset, clear the app's storage, or uninstall the app. Stored credentials and SSH host keys can also be cleared separately from Privacy & Security. Android backup is disabled for CTRLbot IoT. Data received independently by a website or a device you control is governed by that third party or device and is not deleted by CTRLbot IoT.

CTRLbot AI conversations expire automatically within one hour and are not retained afterward. Because there is no account and no user identifier, CTRLbot cannot locate an individual person's past questions in order to delete them on request.

Children

CTRLbot IoT is a professional device-control tool and is not directed to children under 13. The app does not knowingly collect personal information from children.

Changes to this policy

This policy may be updated when the app's features or data practices change. Before an account or cloud feature begins handling user data, the revised policy and its updated date will be included with an app update and published on this page.

Contact

Privacy questions can be submitted using the developer contact shown on the CTRLbot IoT Google Play listing.