ÁramPilot · Energy Scout

Privacy Notice

How the ÁramPilot app, website and server process personal data.

Version: 2026-10-09 · Last updated: 9 October 2026 · SHA-256: 5999d32161e088e254341c61ad5a38ad76843b3de343a32dcbcbb06d2be3b524

At a glance

The ÁramPilot mobile app has no advertising, third-party analytics or crash-reporting SDK. Before separate optional consent, the website does not create campaign or visitor identifiers, read campaign parameters, load advertising measurement tags or send marketing events.

The native app may use only separately enabled first-party analytics. Consent can be withdrawn under Profile & Settings → Privacy & legal → Optional campaign measurement using the Withdraw consent button. Meta Pixel and Conversions API, Google Analytics 4, Google Ads and OpenAI Ads measurement belong only to separately consented web flows, not native advertising SDKs. We do not request access to contacts, photos or payment data and do not collect location data or mobile advertising IDs.

1. Controller and contact

Controller and developer: WIRE-HOLDER Kft., 2600 Vác, Görgey Artur utca 37., Hungary. Application: ÁramPilot. Privacy contact: info@arampilot.hu.

2. What data do we process?

Account and authentication: the optional ÁramPilot account's name, email and internal ID. The native form authenticates genuine email/password accounts through the HTTPS API. The password exists only in form/request memory, not local storage, analytics or URLs. The server processes salted scrypt password hashes and hashes and expiry of email-verification and password-reset tokens. After successful authentication, a random opaque session identifier is stored in SecureStore to restore valid sign-in on reopening. Registration and password reset open in a separate system browser, not an embedded WebView. Provider data and access/refresh tokens for separately supported OIDC flows remain server-side; mobile handoff uses short-lived hashed confirmation data.

Push: app-generated device identifier, Expo push token, platform, optional account link; notification preferences, thresholds, timezone, and notification history and delivery status (type, title, text, time, test flag, technical payload, success or failure).

Launch waitlist: voluntarily submitted email, consent time and signup source. We use the email for the launch notice and record signup order and the one-month Pro entitlement for the first 100 unique subscribers.

First-party analytics: only after separate campaign-measurement consent, random visitor, session and event IDs, platform and app interactions. Native events include session starts and go only to ÁramPilot's own API; the web may also process allowlisted page paths, referrer domains and campaign parameters. Analytics is not linked to accounts or emails. Native and browser decisions are separate and optional; without consent no such identifiers or events are sent. Native consent can be withdrawn under Profile & Settings → Privacy & legal → Optional campaign measurement using the Withdraw consent button. Successful local withdrawal removes consent and the local analytics identifier; further new event submissions require consent again. Events already initiated or sent cannot be recalled.

Web account acknowledgments: the versions, time and language of the separate mandatory Terms and Privacy Notice acceptances are stored with the account credential record. We also record the version and time of a separate, optional positive marketing-consent decision.

Google Analytics 4 (optional web analytics): only with valid campaign-measurement consent, we measure page views and the sign_up event for completed new web accounts. Google’s _ga and _ga_EFE5KF8N1S cookies may store random browser and session identifiers with an expiry of at most 14 days. We send only known page paths, validated campaign parameters and referring domains; we do not send our account IDs, names, email addresses or verification tokens. Google Signals and advertising personalization are disabled in the Analytics configuration.

Meta (optional web measurement): Pixel may measure page views; Pixel and Conversions API may measure a new successful waitlist signup. The server event may send Meta a one-way SHA-256 hash of the email, IP address, browser user agent, _fbp/_fbc identifiers, page URL and a random event ID. The shared event ID deduplicates browser and server measurements.

Google Ads (optional web measurement): Consent Mode v2 defaults to denied for advertising and analytics storage, ad user data and personalization. The browser tag loads only after valid consent. The browser “Account signup” conversion may be sent only after either a new email account’s first successful email verification or establishment of an authenticated session for a new browser-based OIDC account, and only when this browser has valid signed campaign-measurement consent. The event has a technical value of 1 HUF and uses a random, anonymous transaction_id. Waitlist signups and ordinary logins are not measured.

OpenAI Ads (optional web measurement): Pixel loads only with valid consent in that browser. After the first successful verification of a new email account, the server may send a Conversions API event based on the consent recorded at registration, even if verification occurs in another browser. The registration_completed event contains a random deduplication ID, timestamp and canonical page URL without query parameters; we do not send a name, email, email hash, IP address, browser identifier or verification token. Pixel and server use the same event ID.

Consumption data: optional annual, monthly and daily estimates, tariff-awareness flag, flexible loads and demo settings. With P1, Shelly or Home Assistant enabled: meter-point and external identifiers, name, timestamps, values, units, import/export/net direction, phase, source and freshness. For verifiable P1 billing evidence: operator and meter-point identifiers, customer type, measurement period, signature version and verification time.

Integrations and local data: provider, status, supplied HTTPS base URL, entity ID, meter label, error code and refresh time. A required provider access token may be stored encrypted on the server and is not returned to the app in plaintext. The device may keep language, theme, onboarding, device and notification preferences, local history, device ID and guest integration session data.

Operational logs: technical events, times, request paths, error categories and pseudonymous technical IDs for security and troubleshooting, not advertising or tracking.

3. Purposes and legal bases

Account, profile, device-link and consumption views serve performance of the service. Push notifications are sent only based on your choice and device permission; integrations use only a connection you initiate.

The waitlist launch notice and one-month Pro entitlement for the first 100 unique subscribers rely on voluntary signup; withdraw at info@arampilot.hu. First-party web analytics and Meta, Google Analytics 4, Google Ads and OpenAI Ads measurement rely on separate optional consent; refusal does not affect waitlist signup, registration or basic public price views.

Fraud prevention, authentication protection and troubleshooting are our legitimate interests; legally required retention and cooperation with authorities occur only where applicable.

4. Transfers and providers

Android Firebase Cloud Messaging and Firebase Installations may automatically process installation IDs and app/SDK metadata for delivery. This is not Firebase Analytics; denying notification permission alone does not disable SDK initialization. The app's Expo push registration requires permission and is available to guests. A separate pseudonymous integration session and device secret are also created for guests; these are not registered user accounts.

During the pre-save P1 check and later refreshes, an access token may be forwarded to your selected public HTTPS gateway; response readings, meter identifiers and timestamps go to the ÁramPilot server. HTTP and private endpoints are unsupported. Shelly and Home Assistant interfaces are locked in this release; their existing adapters can forward configuration, tokens and a Home Assistant entity ID to the selected endpoint. Sharing configuration serves app functionality only. Required account-verification and password-reset messages are forwarded by the email-delivery service.

Replit: infrastructure, PostgreSQL and OIDC sign-in. Expo: push tokens and forwarding. Firebase Cloud Messaging on Android and Apple Push Notification service on iOS may assist delivery.

Only with optional web consent: Meta Platforms Ireland Limited (Pixel/Conversions API), Google Ireland Limited (Analytics 4 and Ads tag) and OpenAI, L.L.C. (Ads Pixel); each may process received data under its own privacy terms.

We contact P1, Shelly and Home Assistant endpoints during user-initiated configuration checks or refreshes of user-supplied, enabled integrations. The access token goes in the Authorization header and, for Home Assistant, the entity ID may also appear in the URL; the connection may refresh on schedule and retry after errors.

Server-side market requests to ENTSO-E and exchange-rate sources intentionally include no account, push, integration or consumption data. Some providers may process data outside the EEA subject to appropriate safeguards, such as an adequacy decision or standard contractual clauses. We do not sell data or transfer it to data brokers.

5. Security

Production traffic uses HTTPS/TLS and integrations accept verified HTTPS endpoints. The server derives account ownership from the authenticated session, not a client-supplied ID. Provider credentials are stored with AES-256-GCM encryption; the API reports only their presence.

The mobile session remains in SecureStore and OIDC tokens on the server. Account deletion and account-owned writes use locks and transactions; ownership checks, short-lived handoffs and limited session lifetime protect access. No system is risk-free; report suspected incidents to the privacy contact.

6. Retention

The account session database lifetime is currently seven days, which successful token refresh may renew; mobile handoff is normally usable for at most five minutes. Versions, language and times of mandatory web document acknowledgments and positive marketing consent are in the account credential record and are deleted with the account. There is no separate consent archive or configured time-based retention rule.

We keep waitlist email until consent withdrawal or launch-notice delivery and short technical closure. Profile, integrations, readings, source settings, push devices and notification history have no single automatic expiry: we process them while the feature or purpose remains, or until integration/account deletion.

Deleting an integration removes its connection, credential, associated meter points, readings and evidence; the active source returns to manual. Logout removes only the current session and local token and unlinks the current push device: it does not delete the account, profile, measurements or past history. Unlinked technical device records may remain until cleanup.

After successful account deletion, the app clears its local data; uninstalling normally removes app storage under the operating system's rules. Security and operational logs may remain only as long as needed for protection, investigation or legal claims.

7. Logout and deletion

Logout in Settings is not account deletion. A P1, Shelly or Home Assistant integration can be removed separately, including its encrypted credential and associated readings.

Permanent account deletion requires sign-in and a separate final confirmation. One transaction removes the ÁramPilot account, profile, sessions and handoffs, account-linked push/notification data, integrations and credentials, meter points and readings, source settings and P1 billing evidence. Delete account and data.

Deletion does not delete the external Replit/OIDC account or original data in your own P1, Shelly and Home Assistant systems. Only data needed for law, legal claims or demonstrable security obligations may remain in backups, logs or a separate legal record, and is not used for another purpose.

8. Your rights

Subject to applicable law, you may request access, correction, deletion, restriction and portability; object to processing based on legitimate interest and withdraw consent at any time. Identity verification may be needed before fulfilling a request. Contact info@arampilot.hu; complain to the NAIH.

Web campaign measurement can be refused or withdrawn in campaign measurement settings. The decision is stored locally in your browser. Withdrawal removes local campaign identifiers and queued events and stops further first-party, Meta, Google Analytics, Google Ads and OpenAI measurement; previously sent events cannot be recalled.

9. Data not collected and children

Current app features do not collect precise or approximate location, contacts, photos or video, audio recordings, payment data, mobile advertising ID, browsing history or message contents. There is no third-party mobile analytics or crash-reporting SDK. ÁramPilot is not intended specifically for children.

10. Changes

We update this notice when the service or applicable law changes. The current version is available on the public ÁramPilot site.