Privacy and cookie policy

Effective from 4 October 2026

In short. The website has no ads, analytics, tracking or marketing cookies. The app runs in your Home Assistant and sends nothing to us — no accounts, no telemetry, no access to your home. The server keeps a technical log for 14 days, for security only.

1. Who is responsible for the data

The data controller is Harry Asar, HomeNetcloud.eu, Bulgaria. Contact: GitHub Discussions. More about us in the terms of use.

2. The website mega-dashboard.eu

Server log

When you open the website or the store (apps.mega-dashboard.eu), or download the app (images.mega-dashboard.eu), the server records: IP address, date and time, the page address, where you came from (referrer), your browser and device (user agent) and the response code.

  • Why: to run the website securely, stop attacks and abuse, and find errors.
  • Legal basis: legitimate interest (Article 6(1)(f) of the General Data Protection Regulation, GDPR).
  • Retention: 14 days, then it is deleted automatically.

Cloudflare

The website goes through Cloudflare's network, which delivers it fast and protects it from attacks. Cloudflare processes the IP address and technical request data on our behalf. Cloudflare may transfer data outside the EU (for example to the US) under the EU–US Data Privacy Framework and standard contractual clauses. More: Cloudflare's policy.

No analytics or ads

We don't use Google Analytics, pixels, ad networks, external fonts or embedded third-party scripts. The “Try the Studio” demo runs entirely in your browser and sends nothing.

3. Cookies and local storage

The website sets no cookies, which is why we don't show a consent banner.

  • md_lang (browser local storage): when you switch the language yourself, your browser remembers the choice (en or bg) to show the same language next time. The value is never sent to us. It is needed for a feature you asked for, so it doesn't require consent. It's removed when you clear the site's data in your browser.
  • __cf_bm and similar: Cloudflare may set a strictly necessary security cookie if a request looks suspicious (for example during an attack). It is used only for protection and lasts up to 30 minutes.

4. The app and the dashboard

  • Everything stays at home. Mega Dashboard runs in your Home Assistant and your browser. Your devices, rooms, pictures of your home, settings and save history stay in Home Assistant. We have no access to them.
  • No accounts, no telemetry. The app collects no statistics and sends no usage data.
  • Updates. When Home Assistant checks for a new version or downloads it, it connects to apps.mega-dashboard.eu and images.mega-dashboard.eu. These requests are part of the server log in section 2. The same applies when you pull the Docker image.
  • Token with Docker. On Home Assistant Container or Core you give the container a long-lived token. It stays on your machine and is only used to talk to your own Home Assistant — it never reaches us.
  • AI assistant (optional). If you turn it on, Home Assistant sends your questions and the information about your home needed to answer (device names and states and the assistant's instructions) directly to the provider you chose — OpenAI, Anthropic, Google or your own Ollama. We don't receive this data. The provider's policy applies. With Ollama on your own computer, nothing leaves your home.
  • Links. The dashboard may show links to the website or GitHub. They open only if you click them.

5. GitHub and Buy Me a Coffee

If you write on GitHub (Issues or Discussions) or donate through Buy Me a Coffee, your data is processed by them under their policies. We only see what you publish or share yourself — for example a name, a message and an amount. Texts on GitHub are public.

6. Who receives the data

We don't sell or give data to anyone. Only the providers that help run the website receive it: Cloudflare (delivery and protection) and the hosting of our server in the EU.

7. Your rights

You have the right to access your data, correct or delete it, restrict or object to its processing, and to data portability. To use them, contact us: GitHub Discussions. The server log holds no names and is deleted after 14 days, so sometimes we won't be able to tell which records are yours (Article 11 GDPR).

You can lodge a complaint with the Bulgarian Commission for Personal Data Protection (2 Prof. Tsvetan Lazarov Blvd., Sofia 1592) or the data protection authority where you live.

8. Children

The website is not intended for children under 16 and we don't knowingly collect data about them.

9. Security

The website works only over HTTPS. We keep as little data as possible, for as short as possible.

10. Changes

If this policy changes, we'll update the date above. We'll mention significant changes on the website.

See also the terms of use.