Skip to content
Pocket Homelab
Get the app

Privacy

Pocket Homelab collects nothing. Credentials live in the device Keychain, requests go straight to your servers, and there is no analytics or advertising SDK.

On this page

Pocket Homelab is a client. It has no backend, no account system and no telemetry. This page describes what it does with your data; the in-app Privacy policy under Settings → Help & privacy is the authoritative version.

No data collection

  • There is no Pocket Homelab account and nothing to sign up for.
  • There is no analytics SDK, no advertising SDK and no cross-app tracking in the public app.
  • Your service credentials, documents, photos, media history and financial records are never sent to a developer-operated backend, because there is no such backend.
  • The public app does not register for push notifications.

Your credentials

Every URL, API key, token and app password you enter is stored in one item in the device Keychain, protected after first unlock. It is not synced to a server by the app.

  • The iPhone and the Mac keep separate Keychain items. Import your configuration once on each device.
  • Keychain items can survive uninstalling the app. Use Erase all settings first if you want them gone.
  • On Android, the configuration is encrypted with a key held in the Android Keystore, which cannot be exported. It is left out of Android’s cloud backup and device transfer, and uninstalling the app removes it.
  • Exported configuration files contain your credentials in plain text. Treat them like passwords.

Direct connections only

Requests go from your device straight to the servers you configure. There is no proxy and no relay.

  • Requests use an ephemeral session with no cookie jar and no shared cache, and bodies and headers are never logged.
  • A redirect to a different origin is refused, so a token can never be forwarded to another host.
  • Requests time out after about 8 seconds by default, and unreachable services fail on their own card without blocking the rest of the app.
  • Whether your servers are reachable, LAN, VPN, Tailscale, public HTTPS, is entirely your setup. The app never configures a VPN for you.

Permissions

Nothing is requested at launch. iOS and macOS ask only when you first use the feature:

Permission Used for
Camera Scanning a document into Paperless (iPhone), or checking your camera before joining a meeting (Mac).
Photo library Saving an Immich photo or video to your library.
Calendars Showing and managing events from your calendar accounts on Mac, and adding upcoming releases to a “Homelab media” calendar when you ask it to.
Local network Reaching services you configure on your LAN.
Notifications (badge) Showing the app badge count, if you turn it on.

Decline any of them and the rest of the app keeps working.

The Mac camera check starts only when you choose to join a meeting. It uses no microphone and records no video. Copy Photo to Clipboard captures a still only on request; the preview does not save photo files or keep a photo history. Closing the preview or joining releases the camera. The meeting itself opens in its app or browser, which manages its own camera and microphone access.

Data stored on the device

Cached images, offline snapshots, downloaded episodes and files, and the queue of changes waiting to sync. All of it can be removed with Clear local data, which keeps your credentials, or with Erase all settings, which does not.

Purchases

Pro is sold through Apple’s App Store using StoreKit. Apple handles the payment and tells the app whether an entitlement is active; the developer never sees your payment details. Purchases can be restored on any device signed in to the same Apple Account.

Third parties

The only network destinations are the servers you configure, plus Apple’s own services for purchases. The app sends nothing to the developer.

Not affiliated

Pocket Homelab is an independent client and is not affiliated with, endorsed by or sponsored by any of the services it supports. Use it only with services you run or are authorised to access.