Privacy Policy
Hiclaro — hiclaro.app
Effective date: May 17, 2026
This Privacy Policy explains what data Hiclaro collects, why, and how it is handled across all components of the Hiclaro ecosystem: the public website (hiclaro.app), the Hiclaro mobile app, the Hiclaro desktop app, and the Hiclaro Linux distribution (designed for Raspberry Pi devices).
Hiclaro is designed around a local-first principle. We deliberately minimise data collection. Most of your data never leaves your own devices.
Hiclaro operates under Hungarian law and complies with the General Data Protection Regulation (GDPR), Regulation (EU) 2016/679.
1. Who We Are
Hiclaro is the data controller for data collected through the website and update infrastructure. For the purposes of GDPR, you may contact us at: legal@hiclaro.app
2. Data We Collect — Website (hiclaro.app)
2.1 Server Logs and IP Addresses
Our web server and rate-limiting infrastructure (including rate-limiting infrastructure) automatically log IP addresses as part of standard HTTP request handling. This occurs when you visit any page, submit a feedback form, upload a plugin, or download a file.
IP addresses are personal data under GDPR. We collect them solely for security and abuse prevention purposes. Server logs are retained for a maximum of 30 days and are then deleted automatically.
Legal basis: Legitimate interests (GDPR Art. 6(1)(f)) — specifically, protecting the platform from abuse and ensuring service availability.
2.2 Feedback Forms
When you submit a feedback form, we collect the content of your message. We do not ask for your name or email address. However, the content of your message may itself contain personal information if you choose to include it. We use feedback solely to improve the platform.
Legal basis: Legitimate interests (GDPR Art. 6(1)(f)).
2.3 Plugin Uploads — Plugin Developers
When you upload a plugin ZIP file to the Hiclaro plugin registry, we collect:
Your email address — used for platform communication relating to your plugin submissions, including approval or rejection notifications and any legal or technical matters arising from your plugin. It is never displayed publicly and is not used for marketing.
Your chosen display name — this is displayed publicly on your plugin listing in the registry.
The plugin ZIP file itself — stored on our servers for distribution through the registry.
You receive a token upon upload, which is the sole means of proving ownership of that plugin for future updates. This token is secret and personal to you. We do not use your email address to authenticate you — the token is your only credential.
Important: Plugin ZIP files may inadvertently contain personal data (such as hardcoded credentials or developer information embedded in code). We do not intentionally collect such data and we are not responsible for personal data you include in plugin files. Please review your plugin files before uploading.
Legal basis: Performance of a contract (GDPR Art. 6(1)(b)) — specifically, the Plugin Developer Agreement you accept at the time of upload.
Retention: Your email address and display name are retained for as long as your plugin remains listed in the registry. You may request deletion by contacting us at legal@hiclaro.app, subject to any overriding legal obligations.
3. Data We Collect — Applications
3.1 Local-First Architecture
The Hiclaro mobile app, desktop app, and Linux distribution (Raspberry Pi image) are designed to operate locally. Automation data, smart home device states, device credentials, and telemetry are stored on your own device or your Raspberry Pi — not on Hiclaro servers. We do not have access to this data.
3.2 Update Checks
All three applications periodically contact Hiclaro servers to check for updates and query the plugin registry. These requests result in standard server-side logging of your IP address and app version. This data is handled under the same terms as section 2.1 above.
3.3 Smart Home Device Communication
The applications communicate with smart home devices on your local network. This communication occurs entirely within your local network and does not pass through Hiclaro servers.
Credentials for your smart home devices are stored locally on your device or Raspberry Pi. Hiclaro does not store, transmit, or have access to these credentials.
3.4 Third-Party Cloud Services
Some smart home integrations optionally connect to the cloud services of third-party device manufacturers. When you use such integrations, your data flows directly between your device and that third-party service under their own privacy policy. Hiclaro is not involved in this data flow and is not responsible for third-party data practices.
Third-party cloud connectivity is always user-initiated — it requires credentials you provide for an account you hold with that third party.
3.5 Community Plugins
Third-party plugins installed through the Hiclaro plugin registry may collect or transmit data as described in their own documentation. Hiclaro does not control plugin behaviour once installed. Please review plugin documentation before installing. See Section 6 for more on our plugin ecosystem and its limitations.
4. Data We Do Not Collect
To be explicit, Hiclaro does not collect:
- Your name (except the display name voluntarily provided by plugin authors)
- Your email address (except from plugin authors for the purposes described above)
- Payment or financial information
- Location data
- Device identifiers beyond what appears in standard HTTP logs
- Your automation rules, device states, or smart home data
- Any data from your local network beyond update check requests
5. Cookies and Tracking
Hiclaro does not use advertising cookies, tracking pixels, or third-party analytics services. We do not use Google Analytics, Meta Pixel, or similar tools.
We may use strictly necessary session cookies for form functionality. These are not used to track you across sites or sessions.
6. Plugin Ecosystem
The Hiclaro plugin registry contains both first-party plugins developed by Hiclaro and community plugins submitted by third-party authors. Community plugins are reviewed by Hiclaro for basic technical standards before listing. However, we do not perform comprehensive security audits of plugin code and we cannot guarantee plugin behaviour.
By installing a community plugin, you acknowledge that it is provided by a third party, not by Hiclaro, and that Hiclaro is not responsible for data collected or actions performed by that plugin.
7. Your Rights Under GDPR
If you are located in the European Economic Area, you have rights under GDPR regarding your personal data. How those rights apply to Hiclaro depends on what data we hold about you.
If you have not uploaded a plugin
The only data we may hold about you is your IP address in transient server logs, retained for a maximum of 30 days. Because we have no way to link an IP address to an identified individual, we are unable to fulfil most GDPR rights requests for anonymous users. This is consistent with GDPR Article 11, which recognises that data controllers are not obliged to identify data subjects solely to fulfil rights requests. If your IP address has already been deleted as part of our standard 30-day retention cycle, there is no data remaining to act upon.
If you have uploaded a plugin
We hold your email address, display name, and plugin files. You may exercise the following rights in relation to this data:
- Right of access — you may request confirmation of what data we hold about you
- Right to rectification — you may ask us to correct your email address or display name
- Right to erasure — you may ask us to remove your plugin and associated data from the registry
- Right to restriction — you may ask us to limit processing in certain circumstances
- Right to object — you may object to processing based on legitimate interests
- Right to data portability — you may request your data in a structured format
To exercise any of these rights, contact us at legal@hiclaro.app. Because we have no account system or login credentials, we will ask you to verify your identity using your plugin ownership token. This is the only verification mechanism available to us by design. We cannot process rights requests we are unable to verify.
Right to lodge a complaint
Regardless of the above, you always have the right to lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH) at naih.hu.
8. Data Transfers
Hiclaro's servers are located within the European Union. We do not transfer personal data outside the EEA as part of our own operations. Third-party cloud services you connect to may operate outside the EEA under their own terms.
9. Data Retention
- Server logs (IP addresses): maximum 30 days
- Feedback form submissions: retained indefinitely for platform improvement purposes
- Plugin files: retained while listed in the registry
- Plugin author email and display name: retained while plugins remain in the registry
10. Security
We implement reasonable technical and organisational measures to protect data we hold. Plugin author emails are stored securely and are not exposed through any public interface. However, no system is perfectly secure, and we cannot guarantee absolute security.
11. Children
Hiclaro is not directed at children under the age of 16. We do not knowingly collect personal data from children.
12. Changes to This Policy
We may update this Privacy Policy as the platform evolves. Material changes will be announced on the website. The effective date at the top of this document reflects the most recent revision. Continued use of Hiclaro after changes constitutes acceptance of the updated policy.
13. Contact
For privacy-related questions or to exercise your rights, contact us at: legal@hiclaro.app
Governing authority: Hungarian National Authority for Data Protection and Freedom of Information (NAIH), naih.hu